A satellite data secure transmission method based on intersatellite link

By encrypting, decomposing and chasing the data in satellite data transmission, the problem of insufficient security in inter-satellite link data transmission is solved, and flexible data transmission and efficient security guarantees are achieved.

CN119450458BActive Publication Date: 2025-06-06CHANGGUANG SATELLITE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411632484.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-06-06
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

The prior art is difficult to effectively ensure the security of data when satellites transmit data through inter-satellite links, especially when facing eavesdropping, tampering and forgery attacks.

Method used

By encrypting and decomposing the data into multiple ciphertext data fragments at the sending end, and processing them using random numbers and chaotic sequences during the transmission process, the data is securely transmitted in the inter-star link. The receiver verifies data integrity and restores the original data by decrypting and restoring the data fragment.

Benefits of technology

Improves the flexibility of inter-star link communication, while ensuring the secure transmission of data, preventing attackers from obtaining data through sniffing or exhaustive attacks. The scrambling operation significantly increases the attacker's time complexity and makes data transmission more secure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119450458B_ABST
    Figure CN119450458B_ABST
Patent Text Reader

Abstract

The present invention relates to a satellite data security transmission method based on an intersatellite link, which is used for a user end to transmit encrypted data through an intersatellite link, and a receiving end to process the data after receiving the data, comprising the following steps: a sending end A and a receiving end B agree on a symmetric key E in advance, and encrypt original plaintext data C by using the symmetric key E; the sending end A decomposes the ciphertext data S into N ciphertext data fragments; the sending end A selects a random number R; the sending end A converts SR1, SR2, ..., SR N The satellite data security transmission method based on intersatellite link of the present invention is to perform a sequence scrambling operation. i It is transmitted in time-sharing mode through intersatellite links. Its transmission time and transmission path are not fixed, so it is difficult for attackers to obtain all data fragments by sniffing. When attackers do not obtain all data fragments, they cannot restore the data fragments to complete data S, and thus cannot decrypt them into plaintext data C.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of satellite communication security technology, and in particular to a satellite data security transmission method based on an inter-satellite link. Background Art

[0002] Intersatellite communication links are an important means of achieving space communication or ranging between satellites. On the one hand, intersatellite communication links play a key role in building a satellite backbone network with global coverage, realizing global satellite control, and improving the system's anti-destruction, autonomy, mobility and flexibility. With the development of technology, laser communication has become an important means of next-generation satellite communication and navigation due to its high speed, high bandwidth, and high security. On the other hand, it has the characteristics of open links, long transmission distances, wide transmission ranges, and poor channel reliability, so it is vulnerable to eavesdropping attacks, tampering attacks, forgery attacks, and other attacks.

[0003] The Security Working Group of the Space Data System Advisory Committee proposed relevant standards based on the security needs of spacecraft in 2012 based on the encryption and authentication algorithms in the space network, and proposed relevant standards for the communication protocol of the space link layer in 2015. Under this standard, the communication security of satellites can be guaranteed, but the space and time complexity is relatively high. At the same time, since the inter-satellite communication network of China's commercial satellites is under construction, no relevant standards have been formulated. Summary of the invention

[0004] The present invention aims to solve the technical problems in the prior art and provides a satellite data security transmission method based on an inter-satellite link.

[0005] In order to solve the above technical problems, the technical solutions of the present invention are as follows:

[0006] A satellite data security transmission method based on an inter-satellite link is applicable to a sending end A sending data C to a receiving end B after forwarding it through an intermediate end M based on an inter-satellite link;

[0007] The satellite data secure transmission method comprises the following steps:

[0008] Step 1: The sender A and the receiver B agree on a symmetric key E in advance, and encrypt the original plaintext data C using the symmetric key E to obtain the ciphertext data S = E(C);

[0009] Step 2: The sender A decomposes the ciphertext data S into N ciphertext data fragments, S = S 1 +S 2 +…S N ;

[0010] Step 3: The sender A selects a random number R and calculates SR 1 =S 1⊕R、SR 2 =S 2 ⊕S 1 ,…SR N =S N ⊕S N-1 , where the symbol ⊕ represents the bitwise XOR operation;

[0011] Step 4: Sending end A sends SR 1 , SR 2 ,…,SR N Perform a sequence scrambling operation to obtain SR' 1 SR' 2 ,…,SR' N , and retain the scrambled sequence K;

[0012] Step 5: The sender A obtains S N The HASH value h, random number R, scrambled sequence K and S N The HASH value h is combined as additional information T, using the public key PK of the receiving end B B Encrypt and get PK B (T);

[0013] Step 6: The sender A will use the public key PK of the receiver B B Encrypted additional information PK B (T) and the encrypted and scrambled data segment SR' 1 SR' 2 ,…,SR' N As communication data, it is sent to the receiving end B through the intersatellite link. The receiving end B collects the additional information T sent by the sending end A and the encrypted and scrambled data fragment SR' 1 SR' 2 ,…,SR' N ;

[0014] Step 7: When the receiver B collects all the data fragments SR' 1 SR' 2 ,…,SR' N With the encrypted additional information PK B (T) and then use your own private key SK B PK B (T) is decrypted to obtain T, and then the random number R, scrambled sequence K and S are obtained. N HASH value h;

[0015] Step 8: Receiver B collects all encrypted and scrambled data segments SR' 1 SR' 2 ,…,SR' N , and scramble the sequence K to SR'1 SR' 2 ,…,SR' N Restore and get SR 1 , SR 2 ,…,SR N ;

[0016] Step 9: At the receiving end B, according to SR 1 =S 1 ⊕R, R and SR 1 , get S 1 =SR 1 ⊕R, find S 1 Value; According to SR 2 =S 2 ⊕S 1 …SR N =S N ⊕S N-1 , find S 2 , S 3 ,…,S N The value of

[0017] Step 10: Calculate S at the receiving end B N The HASH value h' is compared with h to determine whether they are consistent.

[0018] Step 11: Receiver B sends data segment S 1 , S 2 ,…,S N Splice into complete ciphertext data S;

[0019] Step 12: The receiving end B decrypts the ciphertext data S based on the pre-agreed symmetric key E to obtain the final plaintext data C=E(S).

[0020] In the above technical solution, in step 4, the scrambling sequence K can transform SR' 1 SR' 2 ,…,SR' N Restore to SR 1 , SR 2 ,…,SR N .

[0021] In the above technical solution, in step 10, if h' is consistent with h, then all data segments SR' are identified. 1 SR' 2 ,…,SR' N The data integrity is not compromised.

[0022] In the above technical solution, in step 6, the data segment SR' 1 SR' 2 ,…,SR'N The order and format of the communication data transmitted to the receiving end B are not limited.

[0023] The present invention has the following beneficial effects:

[0024] The satellite data security transmission method based on inter-satellite links of the present invention improves the flexibility of inter-satellite link communication while ensuring the secure transmission of data by decomposing large data through inter-satellite links.

[0025] In the satellite data security transmission method based on the intersatellite link of the present invention, assuming that the attacker has cracked the symmetric key E, he can decrypt the ciphertext data S into the plaintext data C, but since he can only know the PK by sniffing in the intersatellite link, B (T) and partial data fragments SR i , it cannot know the private key SK of the receiver B B , and thus the scrambled sequence K and the random number R cannot be known, and the scrambled data cannot be restored.

[0026] The satellite data security transmission method based on intersatellite link of the present invention is to prevent data fragmentation SR i It is transmitted in time-sharing mode through intersatellite links. Its transmission time and transmission path are not fixed, so it is difficult for attackers to obtain all data fragments by sniffing. When attackers do not obtain all data fragments, they cannot restore the data fragments to complete data S, and thus cannot decrypt them into plaintext data C.

[0027] The satellite data security transmission method based on intersatellite links of the present invention can detect all the data fragments even for a single link transmission. Since the fragments themselves are processed by scrambling, an exhaustive attack is required to restore the original fragment order. When the number of data fragments reaches 35, the number of exhaustive attacks exceeds 2^128. When the number of data fragments reaches 58, the number of exhaustive attacks exceeds 2^256. Its time complexity is higher than the time complexity O(2^128) of the traditional encryption algorithm. N ), so the scrambling operation can effectively avoid exhaustive attacks.

[0028] The satellite data security transmission method based on the intersatellite link of the present invention does not need to decrypt all the data after receiving all the data fragments, but only needs to perform bitwise XOR operation to obtain S N , and then obtain S N The HASH value h' is obtained to verify whether the data has been tampered with, reducing the computational complexity of the receiving end. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0030] Figure 1 The present invention is a flow chart of the sending end of the satellite data security transmission method based on the inter-satellite link.

[0031] Figure 2 The present invention is a flow chart of a receiving end in a satellite data secure transmission method based on an inter-satellite link. DETAILED DESCRIPTION

[0032] The inventive concept of the present invention is: the satellite data security transmission method based on inter-satellite links of the present invention, based on the objective development and display requirements of communication satellite networks, effectively solves the problem of safe and reliable data transmission by satellites through inter-satellite links.

[0033] The present invention is described in detail below with reference to the accompanying drawings.

[0034] The satellite data security transmission method based on intersatellite links of the present invention is used for a user end to transmit encrypted data through the intersatellite links, and a receiving end to process the data after receiving it.

[0035] Regarding interval division: The model is divided into three parts: the transmitter A, the intersatellite link, and the receiver B. Its purpose is for the transmitter A to send data C to the receiver B after forwarding it through the intermediate terminal M based on the intersatellite link. During this period, the attacker and the intermediate terminal M cannot know the content of the data C, thereby completing the confidential communication process between satellites.

[0036] The satellite data secure transmission method based on intersatellite links of the present invention comprises the following steps:

[0037] The sending end A and the receiving end B agree on a symmetric key E in advance, and encrypt the original plaintext data C using the symmetric key E, that is, S=E(C).

[0038] The sender A decomposes the ciphertext data S into N ciphertext data fragments, that is, S = S 1 +S 2 +…S N .

[0039] The sender A selects a random number R and calculates SR 1 =S 1 ⊕R、SR 2 =S 2 ⊕S 1 ,…SR N =S N ⊕S N-1 , where the symbol ⊕ represents the bitwise exclusive OR operation.

[0040] The sender A sends SR 1 , SR 2 ,…,SR NPerform a sequence scrambling operation to obtain SR' 1 SR' 2 ,…,SR' N , and keep the scrambled sequence K. Through the scrambled sequence K, SR' 1 SR' 2 ,…,SR' N Restore to SR 1 , SR 2 ,…,SR N .

[0041] The sender A obtains S N The HASH value h, random number R, scrambled sequence K and S N The HASH value h is combined as additional information T, using the public key PK of the receiving end B B Encrypt and get PK B (T).

[0042] The sender A will use the public key PK of the receiver B B Encrypted additional information PK B (T) and the encrypted and scrambled data segment SR' 1 SR' 2 ,…,SR' N As communication data, it can be sent to the receiving end B through the intersatellite link in any order and in any form. The receiving end B collects the additional information T sent by the sending end A and the encrypted and scrambled data fragment SR' 1 SR' 2 ,…,SR' N .

[0043] When the receiving end B collects all the data fragments SR' 1 SR' 2 ,…,SR' N With the encrypted additional information PK B (T) and then use your own private key SK B PK B (T) is decrypted to obtain T, and then the random number R, scrambled sequence K and S are obtained. N The HASH value h.

[0044] Receiver B collects all encrypted and scrambled data fragments SR' 1 SR' 2 ,…,SR' N , and scramble the sequence K to SR' 1 SR' 2 ,…,SR' N Restore and get SR 1 , SR2 ,…,SR N .

[0045] At the receiving end B, due to SR 1 =S 1 ⊕R, R and SR 1 Known, we can get S 1 =SR 1 ⊕R, and then find S 1 value, and due to SR 2 =S 2 ⊕S 1 …SR N =S N ⊕S N-1 , and then obtain S 2 , S 3 ,…,S N The value of .

[0046] S calculated at the receiving end B N The HASH value h' is compared with h to see if they are consistent. N To obtain, and to seek S N Need to know all data fragments SR' 1 SR' 2 ,…,SR' N Therefore, if h' is consistent with h, all data segments SR' can be identified 1 SR' 2 ,…,SR' N The data integrity is not compromised.

[0047] Receiver B sends data segment S 1 , S 2 ,…,S N Concatenate into complete ciphertext data S.

[0048] The receiving end B decrypts the ciphertext data S based on the pre-agreed symmetric key E, that is, C=E(S), thereby obtaining the final plaintext data C.

[0049] The satellite data security transmission method based on inter-satellite links of the present invention improves the flexibility of inter-satellite link communication while ensuring the secure transmission of data by decomposing large data through inter-satellite links.

[0050] In the satellite data security transmission method based on the intersatellite link of the present invention, assuming that the attacker has cracked the symmetric key E, he can decrypt the ciphertext data S into the plaintext data C, but since he can only know the PK by sniffing in the intersatellite link, B (T) and partial data fragments SR i , it cannot know the private key SK of the receiver BB , and thus the scrambled sequence K and the random number R cannot be known, and the scrambled data cannot be restored.

[0051] The satellite data security transmission method based on intersatellite link of the present invention is to prevent data fragmentation SR i It is transmitted in time-sharing mode through intersatellite links. Its transmission time and transmission path are not fixed, so it is difficult for attackers to obtain all data fragments by sniffing. When attackers do not obtain all data fragments, they cannot restore the data fragments to complete data S, and thus cannot decrypt them into plaintext data C.

[0052] The satellite data security transmission method based on intersatellite links of the present invention can detect all the data fragments even for a single link transmission. Since the fragments themselves are processed by scrambling, an exhaustive attack is required to restore the original fragment order. When the number of data fragments reaches 35, the number of exhaustive attacks exceeds 2^128. When the number of data fragments reaches 58, the number of exhaustive attacks exceeds 2^256. Its time complexity is higher than the time complexity O(2^128) of the traditional encryption algorithm. N ), so the scrambling operation can effectively avoid exhaustive attacks.

[0053] The satellite data security transmission method based on the intersatellite link of the present invention does not need to decrypt all the data after receiving all the data fragments, but only needs to perform bitwise XOR operation to obtain S N , and then obtain S N The HASH value h' is obtained to verify whether the data has been tampered with, reducing the computational complexity of the receiving end.

[0054] Obviously, the above embodiments are merely examples for the purpose of clear explanation, and are not intended to limit the implementation methods. For those skilled in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the implementation methods here. The obvious changes or modifications derived therefrom are still within the scope of protection of the invention.

Claims

1. A satellite data secure transmission method based on an intersatellite link, characterized in that: Applicable to the sending end A sending data C to the receiving end B after forwarding it through the intermediate end M based on the intersatellite link; The satellite data secure transmission method comprises the following steps: Step 1: The sender A and the receiver B agree on a symmetric key E in advance, and encrypt the original plaintext data C using the symmetric key E to obtain the ciphertext data S = E(C); Step 2: The sender A decomposes the ciphertext data S into N ciphertext data fragments, S = S1 + S2 + ... S N ; Step 3: The sender A selects a random number R and calculates SR1 = S1⊕R, SR2 = S2⊕S1, …SR N =S N ⊕S N-1 , where the symbol ⊕ represents the bitwise XOR operation; Step 4: The sender A sends SR1, SR2, ..., SR N Perform a sequential scrambling operation to obtain SR'1, SR'2, ..., SR' N , and retain the scrambled sequence K; Step 5: The sender A obtains S N The HASH value h, random number R, scrambled sequence K and S N The HASH value h is combined as additional information T, using the public key PK of the receiving end B B Encrypt and get PK B (T); Step 6: The sender A will use the public key PK of the receiver B B Encrypted additional information PK B (T) and the encrypted and scrambled data segments SR'1, SR'2, ..., SR' N As communication data, it is sent to the receiving end B through the intersatellite link. The receiving end B collects the encrypted additional information PK sent by the sending end A. B (T) and the encrypted and scrambled data segments SR'1, SR'2, ..., SR' N ; Step 7: When the receiving end B collects all the data segments SR'1, SR'2, ..., SR' N With the encrypted additional information PK B (T) and then use your own private key SK B PK B (T) is decrypted to obtain T, and then the random number R, scrambled sequence K and S are obtained. N HASH value h; Step 8: Receiver B collects all encrypted and scrambled data segments SR'1, SR'2, ..., SR' N , and scramble the sequence K to SR'1, SR'2, ..., SR' N Restore to get SR1, SR2, ..., SR N ; Step 9: At the receiving end B, according to SR1=S1⊕R, R and SR1, we get S1=SR1⊕R, and find the value of S1; according to SR2=S2⊕S1, …SR N =S N ⊕S N-1 , and obtain S2, S3, …, S N The value of Step 10: Calculate S at the receiving end B N The HASH value h' is compared with h to determine whether they are consistent. Step 11: Receiver B sends data segments S1, S2, ..., S N Splice into complete ciphertext data S; Step 12: The receiving end B decrypts the ciphertext data S based on the pre-agreed symmetric key E to obtain the final plaintext data C=E(S).

2. The satellite data secure transmission method based on intersatellite links according to claim 1, characterized in that: In step 4, the scrambling sequence K can transform SR'1, SR'2, ..., SR' N Restore to SR1, SR2, ..., SR N .

3. The satellite data secure transmission method based on intersatellite links according to claim 1, characterized in that: In step 10, if h' is consistent with h, then all data segments SR'1, SR'2, ..., SR' N The data integrity is not compromised.

4. The satellite data secure transmission method based on intersatellite links according to claim 1, characterized in that: In step 6, data segments SR'1, SR'2, ..., SR' N The order and format of the communication data transmitted to the receiving end B are not limited.

Citation Information

Patent Citations

  • Data transmission method and system based on fragment confusion

    CN118282605A

  • Satellite proxy re-encryption communication system based on all-no conversion

    CN118555567A