Dual-computer hot backup satellite-borne cryptographic device, primary / backup switching method, satellite and communication system

By adopting a single-board dual-machine hot standby hardware architecture and a shared memory design, autonomous master-slave switching of spaceborne cryptographic devices is realized, solving the problems of high complexity and increased power consumption in existing technologies, and improving reliability and real-time performance.

CN119276328BActive Publication Date: 2025-12-19XINGTANG TELECOMM TECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310827162.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-06
Publication Date
2025-12-19
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

The existing reliability design mechanism of onboard cryptographic equipment has problems of high complexity and increased power consumption. The dual-machine hot standby method increases the complexity of satellite payload implementation, while the dual-machine cold standby method will cause short-term interruption during the switchover between primary and backup.

Method used

The system adopts a single-board dual-machine hot standby hardware architecture. The cryptographic modules A and B are controlled to switch between primary and backup via a unidirectional signal line. They share the RAM chip to store status information. Only the primary machine provides business encryption and decryption services, while the backup machine monitors the status of the primary machine and performs data synchronization during the switch.

Benefits of technology

The system enables autonomous switching between primary and backup cryptographic modules, reducing the design complexity and power consumption of satellite payloads and improving reliability and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276328B_ABST
    Figure CN119276328B_ABST
Patent Text Reader

Abstract

The application relates to a dual-machine hot backup satellite-borne cryptographic device, a master-slave switching method, a satellite and a communication system, wherein the dual-machine hot backup satellite-borne cryptographic device adopts a single-board dual-machine hot backup hardware architecture; the device comprises a cryptographic module A and a cryptographic module B which are mutually master-slave, and a RAM chip which is shared memory of the cryptographic module A and the cryptographic module B; two one-way signal lines are connected between the cryptographic module A and the cryptographic module B, one of the two one-way signal lines transmits master-slave signals of the cryptographic module A from the cryptographic module A to the cryptographic module B, and the other one-way signal line transmits master-slave signals of the cryptographic module B from the cryptographic module B to the cryptographic module A, and the master-slave signals are used for autonomous switching of the dual-machine hot backup; and the RAM chip is used for storing state information required for master-slave switching. The application improves the reliability of satellite load service cryptographic processing.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of low-orbit satellite mobile communication, and particularly relates to a dual-machine hot backup satellite on-board cryptographic device, a master-slave switching method, a satellite and a communication system. BACKGROUND

[0002] The reliability of the satellite on-board cryptographic device directly affects the service performance and stability of the satellite payload. At present, the dual-machine hot backup or dual-machine cold backup working mode is generally used in the industry to improve the reliability of the satellite on-board cryptographic device, and both modes have certain deficiencies.

[0003] In the dual-machine hot backup mode, two satellite on-board cryptographic devices work independently and provide cryptographic services to the outside, and the satellite payload needs to judge the master-slave machine according to the working state of the satellite on-board cryptographic device and select one output as the processing result. This design not only requires the satellite payload to maintain the master-slave machine state of the satellite on-board cryptographic device, but also requires the satellite payload to send the business data to be encrypted or decrypted to the two satellite on-board cryptographic devices at the same time, and select the two outputs of the encryption and decryption processing, which increases the complexity and power consumption of the satellite payload implementation.

[0004] In the dual-machine cold backup mode, only the master of the satellite on-board cryptographic device provides cryptographic services to the outside, and the backup of the satellite on-board cryptographic device is not powered on. When the master fails, the satellite payload powers on the backup, and the backup replaces the master to provide cryptographic services. During the master-slave switching process of the satellite on-board cryptographic device, the satellite payload will be interrupted for a short time, and will not be able to resume normal operation until the backup is switched to the master.

[0005] Therefore, the reliability design mechanism of the satellite on-board cryptographic device in the prior art still needs to be further improved. SUMMARY

[0006] In view of the above analysis, the application aims to disclose a dual-machine hot backup satellite on-board cryptographic device, a master-slave switching method, a satellite and a communication system, which improve the reliability of the satellite payload business cryptographic processing.

[0007] The application discloses a dual-machine hot backup satellite on-board cryptographic device, which adopts a single-board dual-machine hot backup hardware architecture; comprising: a cryptographic module A and a cryptographic module B which are mutually master-slave and have completely same software and hardware configurations, and a RAM chip which is shared memory of the cryptographic module A and the cryptographic module B;

[0008] The cryptographic module A and the cryptographic module B work in a dual-machine hot backup mode, wherein the cryptographic module in the master state provides business encryption and decryption services, and the cryptographic module in the backup state stands by and monitors the master state;

[0009] The two one-way signal lines are connected between the password module A and the password module B, one of which transmits the main / standby signal of the password module A from the password module A to the password module B, and the other transmits the main / standby signal of the password module B from the password module B to the password module A; according to the main / standby signals transmitted on the two one-way signal lines, the main / standby switching control is performed between the password modules, so that the self-switching of the dual-computer hot backup is realized.

[0010] The RAM chip is used for storing the state information required by the main / standby switching; the password module in the host state writes data into the RAM chip; when the main / standby switching occurs, the password module newly switched into the host reads data from the RAM chip for data synchronization.

[0011] Further, the password module A comprises a service port A and a management and control port A connected with the satellite payload, and the password module B comprises a service port B and a management and control port B connected with the satellite payload.

[0012] The service port is used for transmitting service information between the satellite payload, and the management and control port is used for receiving the management and control instruction of the satellite payload and reporting the working state to the satellite payload in a timely manner.

[0013] Further, the satellite payload receives the main / standby working state through the management and control interface, determines the main / standby state of the two password modules according to the received main / standby working state, and only calls the password module in the host state to perform the encryption and decryption processing on the service data; the satellite payload does not send any service data to the password module in the standby state.

[0014] Further, according to the power-on sequence or the predefined password module priority, the password module in the normal state is selected to work in the host state, and the other password module is selected to work in the standby state.

[0015] Further, in the encryption and decryption process, when the password module in the host state detects that the self-working state is abnormal, the main / standby switching to the standby state is performed, the main / standby signal is pulled low, the local main / standby signal transmitted through the one-way signal line is used to inform the password module in the standby state, and the abnormal working state is reported to the satellite payload through the management and control interface; after the password module in the standby state monitors that the password module in the host state is abnormal, the main / standby switching to the host state is performed, the main / standby signal is pulled high, the local main / standby signal transmitted through the one-way signal line is used to inform the opposite end that the local switching is the host state, the local working state is reported to the satellite payload through the management and control interface, the service data of the satellite payload is received from the service interface, the state information is read from the RAM chip to complete the data synchronization, and the data encryption and decryption processing is continued.

[0016] The application further discloses a main / standby switching method of the dual-computer hot backup satellite-borne password device.

[0017] After power on, according to the preset conditions of the master and backup, the self-checking result of the password module and whether it is the first start, the states of the two password modules are set as master or backup respectively; the master and backup control signals of each other are transmitted between the master and backup;

[0018] Before the master and backup switching, the password module in the master state writes the data required for the business encryption and decryption processing into the shared RAM chip while providing the business encryption and decryption service; the password module in the backup state monitors the master and backup signal sent by the password module in the master state;

[0019] When the master and backup switching, the password module in the master state judges the exception while providing the business encryption and decryption service, pulls down the master and backup signal of the local machine, sets the state as backup, and reports the fault state to the satellite payload; the password module in the backup state pulls up the master and backup signal of the local machine after monitoring the pulled down master and backup signal of the master, sets the state as master, reports the working state to the satellite payload, receives the business data sent by the satellite payload through the business interface of the local machine, and reads the state information from the RAM chip to complete the data synchronization;

[0020] After the master and backup switching, the password module switched to the master state writes the data required for the business encryption and decryption processing into the shared RAM chip while providing the business encryption and decryption service; the password module switched to the backup state waits for the reset instruction initiated by the satellite payload and then restarts.

[0021] Further, the working flow of the satellite payload business information for encryption and decryption processing when the password module switches from the master state to the backup state, including:

[0022] (1) the password module of the local end preset as master is started to complete the initialization and self-checking after the start;

[0023] (2) judging whether the self-checking is wrong; if yes, pulling down the master and backup signal of the local machine, setting the state as backup, sending the master and backup signal of the local machine to the password module of the opposite end preset as backup through the unidirectional signal line, and reporting the self-checking error state to the satellite payload through the control interface regularly; if no, entering the next step;

[0024] (3) judging whether it is the first start; if yes, indicating that no encryption and decryption processing exception has occurred, pulling up the master and backup signal of the local machine, setting the state as master, sending the master and backup signal of the local machine to the password module of the opposite end through the unidirectional signal line, reporting the telemetry state to the satellite payload through the control interface regularly, and jumping to step (5); if no, entering the next step;

[0025] (4) For the non-first start, it indicates that the local has occurred encryption and decryption processing exception, and needs to set whether the local is the master state according to the master-slave state sent by the password module of the opposite end; if the master-slave state sent by the opposite end is low, indicating that the opposite end is the slave, then the local master-slave signal is pulled high, the state is set to the master, and the local master-slave signal is sent to the opposite end through the unidirectional signal line, and the working state is reported to the satellite payload through the management interface, and jumps to step (5); if the master-slave state sent by the opposite end is high, indicating that the opposite end is the master, then the local master-slave signal is pulled low, the state is set to the slave, and the local master-slave signal is sent to the opposite end through the unidirectional signal line, and then step (4) is repeated to monitor the master-slave signal sent by the opposite end;

[0026] (5) In the master state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly transmits the service data which does not need to be encrypted and decrypted, and sends the service data which needs to be encrypted and decrypted to the satellite payload after completing the encryption and decryption processing and state synchronization;

[0027] (6) It is judged whether the encryption and decryption processing is abnormal; no, then return to step (5); yes, then the local master-slave signal is pulled low, the state is set to the slave, and the local master-slave signal is sent to the opposite end through the unidirectional signal line, the telemetry state is immediately reported to the satellite payload, and the satellite payload initiates the reset command after waiting for the reset command to restart.

[0028] Further, the working process of the satellite payload's service information for encryption and decryption processing when the password module switches from the slave state to the master state, includes:

[0029] (1) The local preset slave is started after completing the initialization and self-checking;

[0030] (2) It is judged whether the self-checking is incorrect; yes, then the local master-slave signal is pulled low, the state is set to the slave, and the local master-slave signal is sent to the opposite end through the unidirectional signal line; and the self-checking error state is reported to the satellite payload through the management interface; no, then the next step is entered;

[0031] (3) If the self-checking is correct, then the local master-slave state is set according to the master-slave state sent by the opposite end; if the opposite end is the master, then the local master-slave signal is pulled low, the state is set to the slave, and the local master-slave signal is sent to the opposite end through the unidirectional signal line; if the opposite end is the slave, then the local master-slave signal is pulled high, the state is set to the master, and the local master-slave signal is sent to the opposite end through the unidirectional signal line; and the telemetry state is reported to the satellite payload through the management interface, and jumps to step (4);

[0032] (4) In the host state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly transmits the service data which does not need to be encrypted and decrypted, and sends the service data which needs to be encrypted and decrypted to the satellite payload after completing the encryption and decryption processing and state synchronization;

[0033] (5) It is judged whether the encryption and decryption processing is abnormal, if not, returning to (4), if yes, the local master and standby signals are pulled low, the state is set to standby, the local master and standby signals are sent to the opposite end through the one-way signal line, the working state is immediately reported to the satellite payload, and the satellite payload initiates the reset instruction to restart.

[0034] The application further discloses an access network satellite, which comprises a satellite payload, a satellite-borne password device, a routing and switching device, an inter-satellite communication unit and a feeder communication unit; the satellite-borne password device is the dual-machine hot-standby satellite-borne password device as described above.

[0035] The application further discloses a satellite communication system, which comprises an access network satellite, a space-based bearing network, a ground gateway station and a ground core network; the access network satellite is the access network satellite as described above;

[0036] The access network satellites are connected through inter-satellite links to build a space-based bearing network; the space-based bearing network and the ground gateway station are connected through inter-satellite and ground links to jointly realize the routing and forwarding of inter-satellite and inter-satellite data, and provide an NG interface connection for the communication between the satellite access network and the ground core network; the ground core network adopts a 5G system core network to realize user management and service management.

[0037] The application can realize one of the following beneficial effects:

[0038] The dual-machine hot-standby satellite-borne password device, the master and standby switching method, the satellite and the dual-machine hot-standby satellite-borne password device in the communication system disclosed by the application adopt a single-board dual-machine hot-standby design method, and the password module master and standby machines support autonomous switching. The password module master and standby machines do not need to send heartbeat information to each other, only the signal is used to synchronize the master and standby machine states, the shared memory is used to synchronize the security context and the working state, the data in the shared memory is designed with a triple modular redundancy to improve the reliability, the real-time performance is high, and the reliability is strong. Only the password module master machine works, the standby machine only reports the working state, and the satellite payload only needs to send data to the password module master machine and receive the processing result, so that the design complexity and working power consumption of the satellite payload can be effectively reduced. BRIEF DESCRIPTION OF DRAWINGS

[0039] The accompanying drawings are only used for the purpose of illustrating specific embodiments and are not considered as limiting the application, and in the whole drawings, the same reference signs represent the same parts;

[0040] Figure 1A connection schematic block diagram of a dual-hardware hot backup satellite-borne cryptographic device in an embodiment of the present application is shown in the figure;

[0041] Figure 2 A flow chart of a master-slave switching method of a dual-hardware hot backup satellite-borne cryptographic device in an embodiment of the present application is shown in the figure;

[0042] Figure 3 A flow chart of a switching method of a cryptographic module from a master state to a slave state in an embodiment of the present application is shown in the figure;

[0043] Figure 4 A flow chart of a switching method of a cryptographic module from a slave state to a master state in an embodiment of the present application is shown in the figure;

[0044] Figure 5 A connection schematic block diagram of an access network satellite in an embodiment of the present application is shown in the figure;

[0045] Figure 6 A connection schematic block diagram of a satellite communication system in an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION

[0046] The preferred embodiments of the present application will be described in detail below with reference to the drawings, in which the drawings constitute a part of this application and illustrate the principles of the present application together with the embodiments of the present application.

[0047] Embodiment One

[0048] One embodiment of the present application discloses a dual-hardware hot backup satellite-borne cryptographic device, as shown in the figure, which adopts a single-board dual-hardware hot backup hardware architecture; comprising: a cryptographic module A and a cryptographic module B which are mutually master-slave, and a RAM chip which is a shared memory of the cryptographic module A and the cryptographic module B; Figure 1

[0049] The software and hardware configurations of the cryptographic module A and the cryptographic module B are completely the same, and the two cryptographic modules work in a dual-hardware hot backup mode, wherein the cryptographic module in a master state provides business encryption and decryption services, and the cryptographic module in a slave state stands by and monitors the master state;

[0050] Two one-way signal lines are connected between the cryptographic module A and the cryptographic module B, one of which transmits the master-slave signal of the cryptographic module A from the cryptographic module A to the cryptographic module B, and the other of which transmits the master-slave signal of the cryptographic module B from the cryptographic module B to the cryptographic module A; according to the master-slave signals transmitted on the two one-way signal lines, the master-slave switching control is performed between the two cryptographic modules, and the autonomous switching of the dual-hardware hot backup is realized;

[0051] The RAM chip is used for storing the state information required for the master-slave switching; the cryptographic module in the master state writes data into the RAM chip; when the master-slave switching occurs, the cryptographic module newly switched into the master state reads data from the RAM chip, so as to realize the data synchronization. ​

[0052] Specifically, the state information required for the master-slave switching stored in the RAM chip includes synchronization security context and working state data; and the data in the RAM chip adopts a triple modular redundancy design.

[0053] In the embodiment, the password module master and the password module backup do not need to send heartbeat information to each other, and only the signal is used to synchronize the master-slave state, the shared memory is used to synchronize the security context and the working state, the data in the shared memory adopts a triple modular redundancy design to improve the reliability, the real-time performance is high, and the reliability is strong.

[0054] Specifically, the password module A includes a service port A and a management and control port A connected with the satellite payload; and the password module B includes a service port B and a management and control port B connected with the satellite payload.

[0055] The service port is used to transmit service information between the password module and the satellite payload, the management and control port is used to receive the management and control instruction of the satellite payload, and the working state is reported to the satellite payload in a timely manner.

[0056] The service interface of the password module is used to transmit service information between the password module and the satellite payload.

[0057] The management and control interface is used to receive the management and control instruction of the satellite payload, and the working state is reported to the satellite payload in a timely manner.

[0058] The satellite payload receives the working state of the master and the backup through the management and control interface, determines the master and the backup of the two password modules according to the received working state of the master and the backup, and only calls the password module in the master state to perform encryption and decryption processing on the service data; the satellite payload does not send any service data to the password module in the backup state.

[0059] In the embodiment, only the password module master works, the password module backup only reports the working state, and the satellite payload only needs to send data to the password module master and receive the processing result, so that the design complexity and the working power consumption of the satellite payload can be effectively reduced.

[0060] During the working of the dual-machine hot backup satellite-borne password device, according to the power-on sequence or the predefined password module priority, the password module in the normal state is selected to work in the master state, and the other password module is made to work in the backup state.

[0061] In the process of encryption and decryption, when the cryptographic module in the host state detects that its work is abnormal, the host and backup switching to the backup state is performed, the host and backup signal is pulled low, the local host and backup signal transmitted through the unidirectional signal line informs the cryptographic module in the backup state, and the abnormal working state is reported to the satellite payload through the management and control interface; after the cryptographic module in the backup state monitors that the cryptographic module in the host state works abnormally, the host and backup switching to the host state is performed, the host and backup signal is pulled high, the local host and backup signal transmitted through the unidirectional signal line informs the opposite end machine that the local switching is the host state, the local working state is reported to the host state through the management and control interface, the service data of the satellite payload is received from the service interface, the state information is read from the RAM chip to complete data synchronization, and the data encryption and decryption processing is continued.

[0062] In summary, the dual-machine hot backup satellite cryptographic device disclosed in the embodiment adopts a single-board dual-machine hot backup design mode, and the cryptographic module supports autonomous switching between the host and backup machines. The cryptographic module does not need to send heartbeat information to each other between the host and backup machines, only the signal is used to synchronize the host and backup machine states, the shared memory is used to synchronize the security context and working state, the data in the shared memory is designed in a triple modular redundancy mode to improve reliability, real-time performance is high, and reliability is strong. Only the cryptographic module host works, the backup machine only reports the working state, and the satellite payload only needs to send data to the cryptographic module host and receive the processing result, so that the design complexity and working power consumption of the satellite payload can be effectively reduced.

[0063] Embodiment two

[0064] One embodiment of the application discloses a host and backup switching method of a dual-machine hot backup satellite cryptographic device, as shown in Figure 2 The method comprises the following steps:

[0065] After power-on, according to preset conditions of the host and backup machines, the self-checking result of the cryptographic module and whether it is started for the first time, the states of the two cryptographic modules are set as the host or the backup; the host and backup control signals of each other are transmitted between the host and backup machines;

[0066] The preset conditions of the host and backup machines are that the cryptographic modules are preset as the host and backup according to the power-on sequence; or the cryptographic modules are preset as the host and backup according to the predefined priority of the cryptographic modules; for example, the cryptographic module A is predefined as the host, and the cryptographic module B is predefined as the backup.

[0067] Before the host and backup switching, the cryptographic module in the host state writes the data required for the business encryption and decryption processing into the shared RAM chip while performing the business encryption and decryption service; the cryptographic module in the backup state monitors the host and backup signal sent by the cryptographic module in the host state;

[0068] When the master-slave switching occurs, the password module in the master state judges the abnormality in the service encryption and decryption, pulls down the local master-slave signal, sets the state as the backup, and reports the failure state to the satellite load; the password module in the backup state monitors the pulled-down master-slave signal of the master, pulls up the local master-slave signal, sets the state as the master, reports the working state to the satellite load, receives the service data sent by the satellite load through the local service interface, and reads the state information from the RAM chip to complete the data synchronization;

[0069] After the master-slave switching, the password module switched to the master state performs the service encryption and decryption service and writes the data required for the service encryption and decryption into the shared RAM chip at the same time, and the password module switched to the backup state waits for the reset instruction initiated by the satellite load and then restarts.

[0070] More specifically, the working flow of the satellite load service information for the encryption and decryption processing when the password module is switched from the master state to the backup state, as shown in Figure 3 , includes:

[0071] (1) the password module preset as the master at the local end is started to complete the initialization and self-checking;

[0072] (2) whether the self-checking is incorrect is judged; if yes, the local master-slave signal is pulled down, the state is set as the backup, the local master-slave signal is sent to the password module preset as the backup at the opposite end through the unidirectional signal line, and the self-checking error state is reported to the satellite load through the management and control interface at regular intervals; if no, the next step is entered;

[0073] (3) whether it is the first start is judged; if yes, it indicates that the encryption and decryption processing abnormality has not occurred, the local master-slave signal is pulled up, the state is set as the master, the local master-slave signal is sent to the password module at the opposite end through the unidirectional signal line, the telemetry state is reported to the satellite load through the management and control interface at regular intervals, and the step (5) is jumped to; if no, the next step is entered;

[0074] (4) for the non-first start, it indicates that the encryption and decryption processing abnormality has occurred at the local end, and whether the local end is the master state needs to be set according to the master-slave state sent by the password module at the opposite end; if the master-slave state sent by the opposite end is low, it indicates that the opposite end is the backup, the local master-slave signal is pulled up, the state is set as the master, the local master-slave signal is sent to the opposite end through the unidirectional signal line, the working state is reported to the satellite load through the management and control interface at regular intervals, and the step (5) is jumped to; if the master-slave state sent by the opposite end is high, it indicates that the opposite end is the master, the local master-slave signal is pulled down, the state is set as the backup, the local master-slave signal is sent to the opposite end through the unidirectional signal line, and then the step (4) is repeated to monitor the master-slave signal sent by the opposite end;

[0075] (5) In the host state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly sends out the service data which does not need to be processed by encryption and decryption, and sends the service data which needs to be processed by encryption and decryption to the satellite payload after completing the encryption and decryption processing and state synchronization;

[0076] (6) It is judged whether the encryption and decryption processing is abnormal; if not, it returns to (5); if yes, the local master-slave signal is pulled low, the state is set to the backup machine, the local master-slave signal is sent to the opposite end through the unidirectional signal line, the working state is immediately reported to the satellite payload, and the restart is waited after the reset instruction is initiated by the satellite payload.

[0077] More specifically, the working process of the satellite payload's service information processed by encryption and decryption when the password module switches from the backup machine state to the host state, as shown in Figure 4 , includes:

[0078] (1) The initialization and self-checking are completed after the preset of the local end is started as the backup machine;

[0079] (2) It is judged whether the self-checking is incorrect; if yes, the local master-slave signal is pulled low, the state is set to the backup machine, the local master-slave signal is sent to the password module of the opposite end which is preset as the host through the unidirectional signal line, and the self-checking error state is reported to the satellite payload through the management and control interface; if not, it enters the next step;

[0080] (3) If the opposite end is the host, the local master-slave signal is pulled low, the state is set to the backup machine, and the local master-slave signal is sent to the opposite end through the unidirectional signal line; if the opposite end is the backup machine, the local master-slave signal is pulled high, the state is set to the host, and the local master-slave signal is sent to the opposite end through the unidirectional signal line; and the working state is reported to the satellite payload through the management and control interface, and jumps to step (4);

[0081] (4) In the host state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly sends out the service data which does not need to be processed by encryption and decryption, and sends the service data which needs to be processed by encryption and decryption to the satellite payload after completing the encryption and decryption processing and state synchronization;

[0082] (5) It is judged whether the encryption and decryption processing is abnormal; if not, it returns to (4); if yes, the local master-slave signal is pulled low, the state is set to the backup machine, and the local master-slave signal is sent to the opposite end through the unidirectional signal line, the working state is immediately reported to the satellite payload, and the restart is waited after the reset instruction is initiated by the satellite payload.

[0083] Embodiment Three

[0084] One embodiment of the present application discloses an access network satellite, as shown in Figure 5As shown, including satellite payload (gNB), on-board cryptographic device, routing exchange device, inter-satellite communication unit, feeder communication unit and other functional units;

[0085] Among them, the satellite payload, routing exchange device, inter-satellite communication unit and feeder communication unit all adopt the existing devices and technologies disclosed in the prior art capable of realizing the satellite terminal network access function, realizing the random access and mobility management of the satellite communication terminal.

[0086] Among them, the satellite payload realizes the function of the communication base station;

[0087] The routing exchange unit realizes the routing exchange of the satellite payload, the inter-satellite communication unit, the feeder communication unit and other functional units;

[0088] The inter-satellite communication unit is used to establish an inter-satellite link between access network satellites to build a space-based bearer network;

[0089] The feeder communication unit is used to realize the feeder and communication functions of each component unit in the access network satellite;

[0090] Other functional units are necessary functional units for the access network satellite to realize the satellite terminal network access function;

[0091] The on-board cryptographic device is the dual-machine hot backup on-board cryptographic device as described in Embodiment One;

[0092] The dual-machine hot backup on-board cryptographic device provides dual-machine hot backup encryption and decryption processing services for the access network satellite, improving the reliability of the satellite payload business password processing.

[0093] In this embodiment, the specific technical features and beneficial effects of the dual-machine hot backup on-board cryptographic device are the same as those disclosed in Embodiment One, please refer to, here will not be repeated.

[0094] Embodiment Four

[0095] One embodiment of the present application discloses a satellite communication system, as shown in Figure 6 As shown, including access network satellite, space-based bearer network, ground gateway station and ground core network;

[0096] Among them, the access network satellite is the access network satellite with dual-machine hot backup on-board cryptographic device as described in Embodiment Three; the satellite payload (gNB) of the access network satellite provides control information and service information encryption and decryption services.

[0097] Each access network satellite is connected through an inter-satellite link to build a space-based bearer network; the space-based bearer network and the ground gateway station are connected through a satellite-ground feeder link; the space-based bearer network and the gateway station jointly realize the routing and forwarding of inter-satellite and satellite-ground data, provide NG interface connection between the satellite access network and the ground core network, and transmit control plane signaling and user plane data.

[0098] The ground core network adopts a 5G system core network to implement user management and service management; the ground core network can include 5G core networks of multiple operators; the 5G core network of each operator performs user management and service management on the satellite communication terminal of the operator; the core networks are logically isolated to ensure the safety of user information and service information of each operator.

[0099] The above merely describes the preferred embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application.

Claims

1. A dual hot-standby spaceborne cryptographic device, characterized in that, Adopt single board double machine hot backup hardware architecture;Including: the software and hardware configuration of the mutually main backup password module A and password module B are completely same, and the RAM chip shared with password module A and password module B as memory; Password module A and password module B work in the mode of double machine hot backup, wherein the password module in the host state provides business encryption and decryption services, and the password module in the standby state monitors the host state; There are two one-way signal lines between password module A and password module B, one of which transmits the main backup signal of password module A from password module A to password module B, and the other transmits the main backup signal of password module B from password module B to password module A;According to the main backup signal transmitted on the two one-way signal lines, the main backup switching control between the password modules is realized, and the autonomous switching of double machine hot backup is realized; The RAM chip is used to store the state information required for main backup switching;Data is written into the RAM chip by the password module in the host state;When main backup switching occurs, the password module switched to the host reads data from the RAM chip for data synchronization; Password module A includes business port A and control port A connected with satellite payload;Password module B includes business port B and control port B connected with satellite payload; The business port is used for transmitting business information between the satellite payload, and the control port is used for receiving control instructions of the satellite payload and reporting working status to the satellite payload; During encryption and decryption process, when the password module in the host state detects that itself works abnormally, it performs main backup switching to the standby state, the main backup signal is pulled down, the local main backup signal transmitted through the one-way signal line informs the password module in the standby state, and the abnormal working state is reported to the satellite payload through the control interface;After the password module in the standby state monitors that the password module in the host state works abnormally, it performs main backup switching to the host state, the main backup signal is pulled up, the local main backup signal transmitted through the one-way signal line informs the opposite end machine that the local machine is switched to the host state, the local working state is reported to the host state through the control interface, the business data of the satellite payload is received from the business interface, the state information is read from the RAM chip to complete data synchronization, and the data encryption and decryption processing is continued.

2. The double machine hot backup satellite borne cryptographic device according to claim 1, wherein The satellite payload receives the main and standby machine working states through the control interface, and determines the main and standby states of the two password modules according to the received main and standby machine working states; The satellite payload only calls the password module in the host state to perform encryption and decryption processing on the business data, and does not send any business data to the password module in the standby state.

3. The double machine hot backup satellite borne cryptographic device according to claim 1, wherein According to the power-on sequence or the predefined password module priority, the password module with normal state is selected to work in the host state, and the other password module works in the standby state.

4. A method for switching the master and backup of a dual hot-standby spaceborne cryptographic device according to any one of claims 1-3, characterized in that, The method comprises the following steps: After power on, according to the preset conditions of the master and backup, the self-checking result of the password module and whether it is the first start, the states of the two password modules are set as master or backup respectively; the master and backup control signals are transmitted between the master and backup; Before the master and backup switching, the password module in the master state writes the data required for the business encryption and decryption processing into the shared RAM chip while providing the business encryption and decryption service; the password module in the backup state monitors the master and backup signal sent by the password module in the master state; When the master and backup switching, the password module in the master state judges the abnormality in the business encryption and decryption service, pulls down the master and backup signal of the local machine, sets the state as backup, and reports the fault state to the satellite payload; after monitoring the pulled-down master and backup signal of the master, the password module in the backup state pulls up the master and backup signal of the local machine, sets the state as master, reports the working state to the satellite payload, receives the business data sent by the satellite payload through the local business interface, and reads the state information from the RAM chip to complete the data synchronization; After the master and backup switching, the password module switched to the master state writes the data required for the business encryption and decryption processing into the shared RAM chip while providing the business encryption and decryption service; the password module switched to the backup state waits for the reset instruction initiated by the satellite payload and then restarts.

5. The method of Claim 4, wherein, The working flow of the satellite payload business information for encryption and decryption processing when the password module switches from the master state to the backup state, including: (1) the password module of the local end preset as master starts after the initialization and self-checking are completed; (2) judging whether the self-checking is wrong; if yes, pulling down the master and backup signal of the local machine, setting the state as backup, sending the master and backup signal of the local machine to the password module of the opposite end preset as backup through the unidirectional signal line, and reporting the self-checking error state to the satellite payload through the management and control interface regularly; if no, going to the next step; (3) judging whether it is the first start; if yes, indicating that no encryption and decryption processing abnormality has occurred, pulling up the master and backup signal of the local machine, setting the state as master, sending the master and backup signal of the local machine to the password module of the opposite end through the unidirectional signal line, reporting the telemetry state to the satellite payload through the management and control interface regularly, and jumping to step (5); if no, going to the next step; (4) for the non-first start, indicating that the local machine has once occurred encryption and decryption processing abnormality, and the master state of the local machine needs to be set according to the master and backup state sent by the password module of the opposite end; if the master and backup state sent by the opposite end is low, indicating that the opposite end is backup, pulling up the master and backup signal of the local machine, setting the state as master, sending the master and backup signal of the local machine to the opposite end through the unidirectional signal line, reporting the working state to the satellite payload through the management and control interface regularly, and jumping to step (5); if the master and backup state sent by the opposite end is high, indicating that the opposite end is master, pulling down the master and backup signal of the local machine, setting the state as backup, sending the master and backup signal of the local machine to the opposite end through the unidirectional signal line, and then repeating step (4) to monitor the master and backup signal sent by the opposite end; (5) In the host state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly transmits the service data which does not need to be encrypted and decrypted, and sends the service data which needs to be encrypted and decrypted to the satellite payload after completing the encryption and decryption processing and state synchronization; (6) Whether the encryption and decryption processing is abnormal is judged; if not, step (5) is returned; if yes, the local master and standby signal is pulled low, the state is set to standby, the local master and standby signal is sent to the opposite end through the one-way signal line, the working state is immediately reported to the satellite payload, and the satellite payload initiates a reset instruction to restart after waiting.

6. The method of Claim 4, wherein, The working process of the satellite payload's service information for encryption and decryption processing when the password module switches from the standby state to the host state includes: (1) After the local preset standby is started, initialization and self-checking are completed; (2) Whether the self-checking is incorrect is judged; if yes, the local master and standby signal is pulled low, the state is set to standby, the local master and standby signal is sent to the opposite end through the one-way signal line, and the self-checking error state is reported to the satellite payload through the management and control interface; if not, the next step is entered; (3) If the self-checking is correct, whether the local is a standby state is set according to the master and standby state sent by the opposite end; if the opposite end is a host, the local master and standby signal is pulled low, the state is set to standby, and the local master and standby signal is sent to the opposite end through the one-way signal line; if the opposite end is a standby, the local master and standby signal is pulled high, the state is set to host, and the local master and standby signal is sent to the opposite end through the one-way signal line; and the working state is reported to the satellite payload through the management and control interface, and step (4) is jumped to; (4) In the host state, the password module continuously receives the service information sent by the satellite payload through the service interface, directly transmits the service data which does not need to be encrypted and decrypted, and sends the service data which needs to be encrypted and decrypted to the satellite payload after completing the encryption and decryption processing and state synchronization; (5) Whether the encryption and decryption processing is abnormal is judged; if not, step (4) is returned; if yes, the local master and standby signal is pulled low, the state is set to standby, the local master and standby signal is sent to the opposite end through the one-way signal line, the working state is immediately reported to the satellite payload, and the satellite payload initiates a reset instruction to restart after waiting.

7. An access network satellite, comprising: The satellite payload, the on-board password device, the routing and switching device, the inter-satellite communication unit and the feeder communication unit are characterized in that the on-board password device is the dual-machine hot-standby on-board password device according to any one of claims 1-3.

8. A satellite communication system comprising: The access network satellite, the space-based bearer network, the ground gateway station and the ground core network are characterized in that the access network satellite is the access network satellite according to claim 7; The access network satellites construct the space-based bearer network through the inter-satellite link; the space-based bearer network and the ground gateway station construct the inter-satellite and ground link, jointly realize the routing and forwarding of the inter-satellite and ground data, and provide the NG interface connection for the communication between the satellite access network and the ground core network; the ground core network adopts the 5G system core network to realize user management and service management.

Citation Information

Patent Citations

  • Dual-machine hot-standby method for virtual machines, dual-machine hot-standby management server and system

    CN105159798A

  • A method for processing the hot standby state of two enciphering and decrypting machines on a satellite

    CN109086610A