A lightweight method for encrypting and decrypting satellite constellation measurement and control instructions

By using nonlinear transformed S-boxes to generate real keys in orbit satellite constellations, the problem of limited-time key storage and update of on-orbit satellite resources is solved, and lightweight key storage and simplified key update process is realized.

CN119450463BActive Publication Date: 2025-05-16CHANGGUANG SATELLITE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411633119.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-05-16
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

Due to limited resources, in-orbit satellites cannot effectively store and update keys, resulting in too large storage demand for keystores when the constellation scale increases and cannot meet the demand.

Method used

A lightweight satellite constellation measurement and control instruction encryption method is adopted, and the satellite identification index and key identification index are transformed using a nonlinear transformed S box on the sending end and the receiving end to generate a real key, thereby realizing efficient storage and updating of the key.

Benefits of technology

It realizes lightweight key storage for on-orbit satellites, reduces the storage requirements of key stores, simplifies the key update process, and reduces resource usage while ensuring security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119450463B_ABST
    Figure CN119450463B_ABST
Patent Text Reader

Abstract

The present invention relates to a lightweight satellite constellation measurement and control instruction encryption and decryption method, and relates to the technical field of satellite communication security strategy, including the following steps: at the transmitting end, according to the target satellite of the current communication, the satellite identification index i of the target satellite and the key identification index j of the designated key are selected; the satellite identification index i and the key identification index j are respectively transmitted to the S box of the nonlinear transformation for transformation, and the satellite identification parameter I and the key identification parameter J are obtained; the satellite identification parameter I and the key identification parameter J are XORed to obtain the real key K; at the receiving end, the target satellite of the current communication obtains the key identification parameter J used by the current instruction according to the key identification index j existing in the transmission data; the real key K is obtained from the satellite identification parameter I and the key identification parameter J, and the instruction is decrypted. The method of the present invention can realize lightweight key storage, and solve the problem of key storage of on-orbit satellites under limited resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of satellite communication security strategies, and in particular to a lightweight satellite constellation measurement and control instruction encryption and decryption method. Background Art

[0002] With the rapid development of China's commercial aerospace, the number of in-orbit satellites of various commercial aerospace companies has increased year by year, and the satellites of most aerospace companies have been networked by themselves to form a large-scale satellite constellation. In addition, with the continuous maturity of inter-satellite communication technology, communications between satellites are becoming more and more frequent. On the one hand, inter-satellite links have the characteristics of open links, long transmission distances, wide transmission ranges, and poor channel reliability. Therefore, they are vulnerable to eavesdropping attacks, tampering attacks, forgery attacks and other attacks; on the other hand, the security components of satellites are generally built based on FPGA architecture, and their on-board resources are relatively limited. When the size of the constellation gradually increases, the number of keys used by the entire constellation increases rapidly, so it cannot meet the use needs of subsequent satellites.

[0003] The Security Working Group of the Space Data System Advisory Committee proposed relevant standards based on the security needs of spacecraft in 2012 based on the encryption and authentication algorithms in the space network, and highlighted relevant standards for the communication protocol of the space link layer in 2015. Under this standard, the communication security of satellites can be guaranteed, but the space and time complexity is relatively high. At the same time, since the inter-satellite communication network of China's commercial satellites is under construction, no relevant standards have been formulated.

[0004] Traditional satellite constellation key library model such as Figure 1 As shown. Figure 1 In the traditional satellite constellation key library design shown, when a satellite receives encrypted communication instructions from other satellites in the constellation, it first reads the satellite identifier to determine which satellite is communicating with it, and then reads the key identifier to determine which specific key the satellite uses for encryption and decryption operations.

[0005] In the key library of any satellite, it also stores the initial key information of all satellites that need to communicate with it. Assuming that each satellite uses 255 keys in its entire life cycle, if there are 200 satellites in the satellite constellation, there are 51,000 keys actually stored on each satellite. Because the key is sensitive information, triple-module redundancy technology is often used when storing it in FPGA, that is, the actual storage space occupied is three times the original space occupied. When the number of satellites increases significantly, their inherent hardware devices often cannot support the storage of huge key libraries. Summary of the invention

[0006] The present invention aims to solve the technical problem in the prior art that on-orbit satellites cannot efficiently store keys and securely update keys under limited resources, and to provide a lightweight satellite constellation measurement and control instruction encryption and decryption method.

[0007] In order to solve the above technical problems, the technical solutions of the present invention are as follows:

[0008] A lightweight satellite constellation measurement and control instruction encryption and decryption method comprises the following steps:

[0009] At the transmitting end, according to the target satellite of the current communication, the satellite identification index i of the target satellite and the key identification index j of the specified key are selected; the satellite identification index i and the key identification index j are respectively transmitted to the S-box of the nonlinear transformation for transformation to obtain the satellite identification parameter I and the key identification parameter J; the satellite identification parameter I and the key identification parameter J are XORed to obtain the real key K;

[0010] At the receiving end, the target satellite currently communicating obtains the key identification parameter J used by the current instruction based on the key identification index j in the transmitted data; the real key K is obtained from the satellite identification parameter I and the key identification parameter J to decrypt the instruction.

[0011] In the above technical solution, the satellite identification parameter I is 16 bytes, the key identification parameter J is 16 bytes, and the real key K is 16 bytes.

[0012] In the above technical solution, the S box is constructed based on the random bits of pi.

[0013] In the above technical solution, the S box complies with the MD2 standard.

[0014] In the above technical solution, the number of satellite keys is 255.

[0015] The present invention has the following beneficial effects:

[0016] Compared with traditional key storage solutions, the lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention can realize lightweight key storage, and solves the problem of key storage for on-orbit satellites under limited resources.

[0017] The lightweight satellite constellation tracking and control instruction encryption and decryption method of the present invention only needs to change or delete the current satellite identification index parameter, that is, an index value, for key update and destruction of a specific satellite, without adding an additional key library, thereby reducing the amount of data injected by the satellite program.

[0018] Compared with the key library update operation, the lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention is unable to deduce the actually used key information from the updated satellite identification index value. Therefore, the index value update instruction can be directly injected on-orbit without the need for additional encryption injection operation, which greatly simplifies the on-orbit satellite key update process while ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0020] Figure 1 Schematic diagram of the traditional satellite constellation key library model.

[0021] Figure 2 It is a schematic diagram of a lightweight satellite constellation key library mode of the lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention.

[0022] Figure 3 The present invention is a flowchart of a lightweight key generation method for the lightweight satellite constellation measurement and control instruction encryption and decryption method.

[0023] Figure 4 A schematic diagram of a random S-box example. DETAILED DESCRIPTION

[0024] The inventive concept of the present invention is:

[0025] The lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention is used for efficient key storage and secure key update of on-orbit satellites under limited resource conditions. Based on the objective development and display requirements of communication satellite networks, the present invention effectively solves the problem of safe and reliable data transmission by satellites through intersatellite links.

[0026] The present invention is described in detail below with reference to the accompanying drawings.

[0027] The lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention, the satellite key library is as follows Figure 2 As shown. Figure 2 In the example, only two index values ​​need to be stored in a single satellite, namely the satellite identification index and the key identification index. The length of the index value is the same as the key length, both of which are 16 bytes. Assuming that the satellite key is 255 and the number of satellites is 200, the total number of index values ​​is 455, which is far less than Figure 1 The solution in the prior art shown requires the storage of 51,000 keys.

[0028] The lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention, the actual key generation method is as follows Figure 3 shown.

[0029] At the sending end, according to the target satellite of the current communication, the satellite identification index i of the target satellite and the key identification index j of the specified key are selected, and the satellite identification index i and the key identification index j are respectively transmitted to the S box of the nonlinear transformation for transformation to obtain a 16-byte satellite identification parameter I and a 16-byte key identification parameter J. The satellite identification parameter I and the key identification parameter J are XORed to obtain the 16-byte real key K.

[0030] At the receiving end, the satellite obtains the key identification parameter J used by the current instruction based on the key identification index j in the transmitted data. Since the satellite is performing decryption, it must use its own satellite identification parameter I. The 16-byte real key K can be obtained from the satellite identification parameter I and the key identification parameter J, and then the instruction can be decrypted.

[0031] The specific construction of the S-box can refer to the MD2 (Message Digest Algorithm 2) related standards. It is constructed based on the random bits of pi. The specific process will not be repeated here. A random S-box (Substitution-box) example is as follows Figure 4 shown.

[0032] Compared with traditional key storage solutions, the lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention can realize lightweight key storage, and solves the problem of key storage for on-orbit satellites under limited resources.

[0033] The lightweight satellite constellation tracking and control instruction encryption and decryption method of the present invention only needs to change or delete the current satellite identification index parameter, that is, an index value, for key update and destruction of a specific satellite, without adding an additional key library, thereby reducing the amount of data injected by the satellite program.

[0034] Compared with the key library update operation, the lightweight satellite constellation measurement and control instruction encryption and decryption method of the present invention is unable to deduce the actually used key information from the updated satellite identification index value. Therefore, the index value update instruction can be directly injected on-orbit without the need for additional encryption injection operation, which greatly simplifies the on-orbit satellite key update process while ensuring security.

[0035] Obviously, the above embodiments are merely examples for the purpose of clear explanation, and are not intended to limit the implementation methods. For those skilled in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the implementation methods here. The obvious changes or modifications derived therefrom are still within the scope of protection of the invention.

Claims

1. A lightweight satellite constellation measurement and control instruction encryption and decryption method, characterized in that: The following steps are involved: At the sending end, according to the target satellite of the current communication, the satellite identification index i of the target satellite and the key identification index j of the designated key are selected; The satellite identification index i and the key identification index j are respectively transmitted to the S-box of nonlinear transformation for transformation to obtain the satellite identification parameter I and the key identification parameter J; the satellite identification parameter I and the key identification parameter J are XORed to obtain the real key K; At the receiving end, the target satellite currently communicating obtains the key identification parameter J used by the current instruction based on the key identification index j in the transmitted data; the real key K is obtained from the satellite identification parameter I and the key identification parameter J to decrypt the instruction.

2. The lightweight satellite constellation measurement and control instruction encryption and decryption method according to claim 1 is characterized in that: The satellite identification parameter I is 16 bytes, the key identification parameter J is 16 bytes, and the real key K is 16 bytes.

3. The lightweight satellite constellation measurement and control instruction encryption and decryption method according to claim 1 is characterized in that: The S-box is constructed based on random bits of pi.

4. The lightweight satellite constellation measurement and control instruction encryption and decryption method according to claim 1 is characterized in that: The S box complies with the MD2 standard.

5. The lightweight satellite constellation measurement and control instruction encryption and decryption method according to any one of claims 1 to 4, characterized in that: The satellite key is 255.

Citation Information

Patent Citations

  • Information processing method and device, computer equipment and medium

    CN112966289A

  • Enhanced inter-satellite networking authentication method based on location key

    CN114828005A