Satellite internet traffic security protection method and system

By generating the first chaotic key sequence and constructing the traffic security score, the adaptive selection encryption algorithm encrypts the satellite Internet traffic data, solving the problem of fixed encryption algorithms in the traditional method, and improving the security and encryption flexibility of satellite Internet traffic.

CN119997005AActive Publication Date: 2025-05-13GOLDEN SHIELD TESTING TECH CO LTD

Patent Information

Application Number
CN202510450548.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-05-13
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

Traditional satellite Internet traffic security protection methods rely on fixed encryption algorithms, lack dynamics and flexibility, are difficult to deal with complex security threats, and lack real-time evaluation and response mechanisms for external perturbation parameters and communication link traffic status, resulting in limited security of satellite Internet traffic.

Method used

By acquiring the track characteristic parameters and external disturbance parameters, a first chaotic key sequence is generated, and multiple risk coefficients are constructed based on the traffic status information collected by the ground terminal in real time to generate a traffic safety score. The encryption algorithm is adaptively selected according to the traffic security score, and the traffic data of the communication link is encrypted using the session key derived from the first chaotic key sequence.

Benefits of technology

It improves the complexity and security of keys, enhances the security protection capabilities of satellite Internet traffic, and improves the encryption flexibility and security of satellite Internet traffic data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119997005A_ABST
    Figure CN119997005A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a satellite internet traffic security protection method and system, and the method comprises the steps: obtaining an orbit characteristic parameter and an external disturbance parameter, and generating a first chaotic key sequence; the method comprises the following steps: constructing a signal tampering risk coefficient, an identity camouflage risk coefficient, a data integrity risk coefficient, a traffic behavior abnormity risk coefficient and a key leakage risk coefficient based on traffic state information collected by a ground terminal in real time, and further generating a traffic safety score; and adaptively selecting an encryption algorithm based on the traffic security score, and encrypting traffic data of the communication link by using a session key derived from the first chaotic key sequence. According to the invention, the communication traffic can be monitored and encrypted in real time, and the security of the satellite internet traffic data is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a satellite Internet traffic security protection method and system. Background Art

[0002] Traditional satellite Internet traffic security protection methods mostly rely on traditional encryption technologies, which are usually based on fixed encryption algorithms for encryption processing, lack dynamics and flexibility, and are difficult to cope with complex security threats. In addition, existing methods also lack real-time evaluation and response mechanisms for the ever-changing external disturbance parameters in satellite Internet (such as electromagnetic interference and satellite orbit changes) and communication link traffic status, which can easily lead to limited security of satellite Internet traffic.

[0003] To this end, a satellite Internet traffic security protection method and system are proposed. Summary of the invention

[0004] The purpose of the present invention is to provide a satellite Internet traffic security protection method and system. The present invention obtains orbital characteristic parameters and external disturbance parameters and generates a first chaotic key sequence; based on the traffic status information collected in real time by the ground terminal, a signal tampering risk coefficient, an identity disguise risk coefficient, a data integrity risk coefficient, a traffic behavior abnormality risk coefficient and a key leakage risk coefficient are constructed to generate a traffic security score; based on the traffic security score, an encryption algorithm is adaptively selected, and the traffic data of the communication link is encrypted using a session key derived from the first chaotic key sequence; the present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.

[0005] To achieve the above object, the present invention provides the following technical solutions: A satellite Internet traffic security protection method, comprising: S1. Obtaining the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, using the hash values ​​of the two as the initial values ​​of the chaotic mapping, and using the coupled iteration of the Logistic mapping and the Henon mapping to generate the coupling sequence, and obtaining the first chaotic key sequence according to the coupling sequence; S2. Based on the real-time collection of traffic status information of the communication links between the ground terminal and each orbiting satellite, the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor are constructed according to the traffic status information; and the traffic security score is constructed based on these five risk factors; S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link based on the encryption algorithm and a session key derived from the first chaotic key sequence.

[0006] Preferably, the orbital characteristic parameters include orbital inclination, perigee altitude, yaw angle and satellite velocity vector; the external disturbance parameters include satellite orbit change, satellite attitude control error and external electromagnetic interference intensity; the traffic status information includes physical layer traffic status information, network layer traffic status information and security layer traffic status information; the physical layer traffic status information includes signal strength attenuation index, dynamic bit error rate and Doppler frequency shift stability coefficient; the network layer traffic status information includes packet loss rate fluctuation coefficient, traffic rate abnormality and data packet size distribution entropy; the security layer traffic status information includes dynamic hash conflict rate and two-factor authentication failure rate.

[0007] Preferably, the initial value is: in, and represents the initial value of the chaotic map; It means taking the first 8 bits; Indicates taking the last 8 digits; It represents the orbital inclination, which reflects the angle between the satellite orbit plane and the Earth's equatorial plane; Indicates the perigee altitude; represents the satellite velocity vector; Represents the satellite attitude control error; Indicates the strength of external electromagnetic interference; Indicates the change in satellite orbit, reflecting the deviation of the orbit affected by external forces; The coupling formula is: in, represents the value of the coupling sequence at step n; Represents the state variable value under the Logistic mapping sequence at the nth step; represents the value of the x state variable under the Henon mapping sequence at the nth step; represents the coupling coefficient.

[0008] Preferably, the first chaotic key sequence is: in, Represents the first chaotic key sequence.

[0009] Preferably, the traffic safety score is: in, Indicates the traffic safety score; Indicates Risk factor; and They represent the risk factor of signal tampering, the risk factor of identity disguise, the risk factor of data integrity, the risk factor of abnormal traffic behavior, and the risk factor of key leakage respectively; Indicates The weight of the risk factor.

[0010] Preferably, the adaptive selection of encryption algorithm based on traffic security score includes: When traffic safety score , select AES-128 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select AES-256 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.

[0011] A satellite Internet traffic security protection system, the system is used to execute any one of the satellite Internet traffic security protection methods described above, comprising: The orbit data acquisition and key generation module is used to obtain the orbit characteristic parameters and external disturbance parameters of the current orbit satellite through the attitude control system and navigation system of each orbit satellite; based on the orbit characteristic parameters and external disturbance parameters, the hash values ​​of the two are used as the initial values ​​of the chaotic map, and the coupling sequence is generated by coupling iteration of the Logistic map and the Henon map, and the first chaotic key sequence is obtained according to the coupling sequence; The traffic status monitoring and risk assessment module is used to collect the traffic status information of the communication links between the ground terminal and each orbiting satellite in real time, and construct the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor based on the traffic status information; and construct the traffic security score based on these five risk factors; The dynamic encryption module is used to adaptively select an encryption algorithm based on a traffic security score, and encrypt traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence.

[0012] Compared with the prior art, the present invention has the following beneficial effects: 1. The present invention obtains orbital characteristic parameters and external disturbance parameters of an orbiting satellite, and uses their hash values ​​as the initial values ​​of a chaotic map, and combines Logistic mapping and Henon mapping for coupled iteration to generate a first chaotic key sequence; by generating the first chaotic key sequence based on satellite orbital characteristics and external disturbance parameters, the complexity and security of the key can be effectively improved, and the security protection capability of satellite Internet traffic can be effectively increased, thereby facilitating the improvement of the security of satellite Internet traffic.

[0013] 2. The present invention collects the traffic status information of the communication link between the ground and the orbiting satellite in real time, and constructs five risk factors based on multi-dimensional data of the physical layer, network layer and security layer, including signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor, and constructs a traffic security score. Through real-time monitoring and comprehensive evaluation of the traffic status, the security protection capability of satellite Internet traffic is effectively increased, which is conducive to improving the security of satellite Internet traffic.

[0014] 3. The present invention adaptively selects an encryption algorithm based on a traffic security score, and encrypts the traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, thereby facilitating the improvement of the security of satellite Internet traffic. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 A schematic diagram of a flow chart of a satellite Internet traffic security protection method provided by an embodiment of the present invention; Figure 2 A schematic structural diagram of a satellite Internet traffic security protection system provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0016] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0017] Embodiment 1 In order to improve the security of satellite Internet traffic, a satellite Internet traffic security protection method is applied. Figure 1 A schematic flow chart of a satellite Internet traffic security protection method provided by an embodiment of the present invention includes: S1. Obtaining the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, using the hash values ​​of the two as the initial values ​​of the chaotic mapping, and using the coupled iteration of the Logistic mapping and the Henon mapping to generate the coupling sequence, and obtaining the first chaotic key sequence according to the coupling sequence; Furthermore, the orbit characteristic parameters include orbit inclination, perigee height, yaw angle and satellite velocity vector; the external disturbance parameters include satellite orbit change, satellite attitude control error and external electromagnetic interference intensity; Furthermore, the initial value is: in, and represents the initial value of the chaotic map; It means taking the first 8 bits; Indicates taking the last 8 digits; It represents the orbital inclination, which reflects the angle between the satellite orbit plane and the Earth's equatorial plane; Indicates the perigee altitude; represents the satellite velocity vector; Represents the satellite attitude control error; Indicates the strength of external electromagnetic interference; Indicates the change in satellite orbit, reflecting the deviation of the orbit affected by external forces; The coupling formula is: in, represents the value of the coupling sequence at step n; Represents the state variable value under the Logistic mapping sequence at the nth step; represents the value of the x state variable under the Henon mapping sequence at the nth step; represents the coupling coefficient.

[0018] Furthermore, the Logistic mapping sequence derivation formula is: in, Represents the state variable value under the Logistic mapping sequence at the n+1th step; represents the first chaos parameter; Furthermore, the Henon sequence derivation formula is: in, represents the value of the x state variable under the Henon mapping sequence at the n+1th step; represents the value of the y state variable under the Henon mapping sequence at the n+1th step; represents the value of the y state variable under the Henon mapping sequence at the nth step; and Indicates control parameters; Furthermore, the first chaotic key sequence is: in, Represents the first chaotic key sequence. This embodiment obtains the orbital characteristic parameters and external disturbance parameters of the orbiting satellite, and uses the hash value as the initial value of the chaotic map, and combines the Logistic map and the Henon map for coupled iteration to generate the first chaotic key sequence; by generating the first chaotic key sequence based on the satellite orbital characteristics and the external disturbance parameters, the complexity and security of the key can be effectively improved, and the security protection capability of the satellite Internet traffic can be effectively increased, thereby facilitating the improvement of the security of the satellite Internet traffic.

[0019] S2. Based on the real-time collection of traffic status information of the communication links between the ground terminal and each orbiting satellite, the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor are constructed according to the traffic status information; and the traffic security score is constructed based on these five risk factors; The traffic status information includes physical layer traffic status information, network layer traffic status information and security layer traffic status information; the physical layer traffic status information includes the number of damaged data packets, signal strength attenuation index, dynamic bit error rate and Doppler frequency shift stability coefficient; the network layer traffic status information includes packet loss rate fluctuation coefficient, traffic rate anomaly and data packet size distribution entropy; the security layer traffic status information includes dynamic hash collision rate and two-factor authentication failure rate and key reuse times; Furthermore, the signal strength attenuation index is: in, Indicates the signal strength attenuation index; Indicates real-time signal power; Indicates the theoretical maximum power; The dynamic bit error rate is represented by the absolute value of the deviation between the instantaneous bit error rate and the historical bit error rate baseline, reflecting the impact of burst interference on communication quality; the dynamic bit error rate is: in, Indicates the dynamic bit error rate; Indicates the real-time bit error rate of the ground terminal; Indicates the historical bit error rate baseline; The Doppler frequency shift stability coefficient is expressed by the ratio of the frequency shift standard deviation to the carrier center frequency, and is used to quantify the frequency fluctuation caused by the high-speed motion of the satellite; the Doppler frequency shift stability coefficient is: in, represents the Doppler shift stability coefficient; Represents the standard deviation of the Doppler frequency shift sequence measured by the ground terminal; Represents the nominal carrier frequency measured by the ground terminal; The packet loss rate fluctuation coefficient is represented by the ratio of the short-term packet loss rate variance to the long-term mean; the traffic rate anomaly is represented by the Mahalanobis distance between the traffic rate and the historical pattern, which is used to detect burst traffic attacks; the traffic rate anomaly is: in, Indicates the abnormality of flow rate; Indicates the real-time rate of the flow; Indicates the mean historical traffic rate; represents the covariance matrix; The data packet size distribution entropy quantifies the randomness of the data packet size through Shannon entropy, which is used to identify abnormal packet distribution; the data packet size distribution entropy is: in, represents the entropy of packet size distribution; represents the probability of packet size category; The dynamic hash collision rate is expressed by the ratio of the number of hash verification failures per unit time to the total number of encryption sessions, reflecting the risk of data tampering; the two-factor authentication failure rate is expressed by the ratio of the number of two-factor identity authentication failures to the total number of all authentication interactions in the ground terminal; Furthermore, the signal tampering risk factor is: in, Indicates the signal tampering risk factor; Indicates the signal strength attenuation index; Indicates the dynamic bit error rate; and Signal tampering risk influences weight; The identity disguise risk factor is: in, Indicates the risk factor of identity disguise; represents the dynamic hash collision rate; Indicates the impact weight of identity disguise risk; Furthermore, the data integrity risk factor is: in, Indicates the data integrity risk factor; Indicates the number of damaged packets detected according to the physical layer; represents the entropy of packet size distribution; Indicates the total number of packets; Furthermore, the risk factor of abnormal traffic behavior is: in, Indicates the risk factor of abnormal traffic behavior; Indicates the abnormality of flow rate; Indicates the packet loss rate fluctuation coefficient; represents the Doppler shift stability coefficient; Furthermore, the risk factor of key leakage is: in, Indicates the risk factor of key leakage; Indicates the number of sessions in which the key derived from the chaotic key sequence is reused in the system record; Indicates the total number of communication sessions initiated from the ground terminal; Furthermore, the traffic safety score is: in, Indicates the traffic safety score; Indicates Risk factor; and They represent the risk factor of signal tampering, the risk factor of identity disguise, the risk factor of data integrity, the risk factor of abnormal traffic behavior, and the risk factor of key leakage respectively; Indicates The weight of the risk factor.

[0020] Preferably, the adaptive selection of encryption algorithm based on traffic security score includes: When traffic safety score , select AES-128 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select AES-256 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.

[0021] This embodiment collects the traffic status information of the communication link between the ground and the orbiting satellite in real time, and constructs five risk factors based on multi-dimensional data of the physical layer, network layer and security layer, including the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor, and constructs a traffic security score. Through real-time monitoring and comprehensive evaluation of the traffic status, the security protection capability of satellite Internet traffic is effectively increased, which is conducive to improving the security of satellite Internet traffic.

[0022] S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link based on the encryption algorithm and a session key derived from the first chaotic key sequence.

[0023] In order to verify the effectiveness of a satellite Internet traffic security protection method provided by this embodiment, the traffic security data between the actual ground terminal and a single orbital satellite are compared, including method 1, method 2 and method 3; method 1 is a satellite Internet traffic security protection method provided by this embodiment, and method 2 is based on method 1 without considering the first chaotic key sequence; method 2 is based on method 1 without considering the traffic security score; specific comparison data include data tampering rate, identity disguise recognition accuracy rate and password cracking rate; as shown in Table 1; Table 1 Comparison of different methods method Data tampering rate Identity disguise recognition accuracy Password cracking rate Method 1 0.1% 98.5% 0.12% Method 2 1% 89% 1.1% Method 3 1.5% 86% 2.1% It can be seen from Table 1 that the satellite Internet traffic security protection method provided in this embodiment has significant effectiveness, can effectively prevent data tampering, effectively identify disguised data, and avoid passwords from being cracked; and improves security.

[0024] This embodiment adaptively selects an encryption algorithm based on a traffic security score, and encrypts the traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, thereby facilitating the improvement of the security of satellite Internet traffic.

[0025] This embodiment obtains orbital characteristic parameters and external disturbance parameters and generates a first chaotic key sequence; constructs a signal tampering risk coefficient, an identity disguise risk coefficient, a data integrity risk coefficient, a traffic behavior abnormality risk coefficient and a key leakage risk coefficient based on the traffic status information collected in real time by the ground terminal, and then generates a traffic security score; adaptively selects an encryption algorithm based on the traffic security score, and uses the session key derived from the first chaotic key sequence to encrypt the traffic data of the communication link; the present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.

[0026] Embodiment 2 In order to improve the security of satellite Internet traffic, a satellite Internet traffic security protection system was applied. Figure 2 A schematic structural diagram of a satellite Internet traffic security protection system provided by an embodiment of the present invention includes: A satellite Internet traffic security protection system, comprising: The orbit data acquisition and key generation module is used to obtain the orbit characteristic parameters and external disturbance parameters of the current orbit satellite through the attitude control system and navigation system of each orbit satellite; based on the orbit characteristic parameters and external disturbance parameters, the hash values ​​of the two are used as the initial values ​​of the chaotic map, and the coupling sequence is generated by coupling iteration of the Logistic map and the Henon map, and the first chaotic key sequence is obtained according to the coupling sequence; Furthermore, the orbit characteristic parameters include orbit inclination, perigee height, yaw angle and satellite velocity vector; the external disturbance parameters include satellite orbit change, satellite attitude control error and external electromagnetic interference intensity; Furthermore, the initial value is: in, and represents the initial value of the chaotic map; It means taking the first 8 bits; Indicates taking the last 8 digits; It represents the orbital inclination, which reflects the angle between the satellite orbit plane and the Earth's equatorial plane; Indicates the perigee altitude; represents the satellite velocity vector; Represents the satellite attitude control error; Indicates the strength of external electromagnetic interference; Indicates the change in satellite orbit, reflecting the deviation of the orbit affected by external forces; The coupling formula is: in, represents the value of the coupling sequence at step n; Represents the state variable value under the Logistic mapping sequence at the nth step; represents the value of the x state variable under the Henon mapping sequence at the nth step; represents the coupling coefficient.

[0027] Furthermore, the Logistic mapping sequence derivation formula is: in, Represents the state variable value under the Logistic mapping sequence at the n+1th step; represents the first chaos parameter; Furthermore, the Henon sequence derivation formula is: in, represents the value of the x state variable under the Henon mapping sequence at the n+1th step; represents the value of the y state variable under the Henon mapping sequence at the n+1th step; represents the value of the y state variable under the Henon mapping sequence at the nth step; and Indicates control parameters; Furthermore, the first chaotic key sequence is: in, Represents the first chaotic key sequence. This embodiment obtains the orbital characteristic parameters and external disturbance parameters of the orbiting satellite, and uses its hash value as the initial value of the chaotic map, and combines the Logistic map and the Henon map for coupled iteration to generate the first chaotic key sequence; by generating the first chaotic key sequence based on the satellite orbital characteristics and external disturbance parameters, it is possible to effectively improve the complexity and security of the key, and effectively increase the security protection capability of the satellite Internet traffic, thereby helping to improve the security of the satellite Internet traffic. The traffic state monitoring and risk assessment module is used to collect the traffic state information of the communication link between each orbiting satellite in real time based on the ground terminal, and construct a signal tampering risk coefficient, an identity disguise risk coefficient, a data integrity risk coefficient, a traffic behavior abnormality risk coefficient and a key leakage risk coefficient according to the traffic state information; and construct a traffic security score based on these five risk coefficients; The traffic status information includes physical layer traffic status information, network layer traffic status information and security layer traffic status information; the physical layer traffic status information includes the number of damaged data packets, signal strength attenuation index, dynamic bit error rate and Doppler frequency shift stability coefficient; the network layer traffic status information includes packet loss rate fluctuation coefficient, traffic rate anomaly and data packet size distribution entropy; the security layer traffic status information includes dynamic hash collision rate and two-factor authentication failure rate and key reuse times; Furthermore, the signal strength attenuation index is: in, Indicates the signal strength attenuation index; Indicates real-time signal power; Indicates the theoretical maximum power; The dynamic bit error rate is represented by the absolute value of the deviation between the instantaneous bit error rate and the historical bit error rate baseline, reflecting the impact of burst interference on communication quality; the dynamic bit error rate is: in, Indicates the dynamic bit error rate; Indicates the real-time bit error rate of the ground terminal; Indicates the historical bit error rate baseline; The Doppler frequency shift stability coefficient is expressed by the ratio of the frequency shift standard deviation to the carrier center frequency, and is used to quantify the frequency fluctuation caused by the high-speed motion of the satellite; the Doppler frequency shift stability coefficient is: in, represents the Doppler shift stability coefficient; Represents the standard deviation of the Doppler frequency shift sequence measured by the ground terminal; Represents the nominal carrier frequency measured by the ground terminal; The packet loss rate fluctuation coefficient is represented by the ratio of the short-term packet loss rate variance to the long-term mean; the traffic rate anomaly is represented by the Mahalanobis distance between the traffic rate and the historical pattern, which is used to detect burst traffic attacks; the traffic rate anomaly is: in, Indicates the abnormality of flow rate; Indicates the real-time rate of the flow; Indicates the mean historical traffic rate; represents the covariance matrix; The data packet size distribution entropy quantifies the randomness of the data packet size through Shannon entropy, which is used to identify abnormal packet distribution; the data packet size distribution entropy is: in, represents the entropy of packet size distribution; represents the probability of packet size category; The dynamic hash collision rate is expressed by the ratio of the number of hash verification failures per unit time to the total number of encryption sessions, reflecting the risk of data tampering; the two-factor authentication failure rate is expressed by the ratio of the number of two-factor identity authentication failures to the total number of all authentication interactions in the ground terminal; Furthermore, the signal tampering risk factor is: in, Indicates the signal tampering risk factor; Indicates the signal strength attenuation index; Indicates the dynamic bit error rate; and Signal tampering risk influences weight; The identity disguise risk factor is: in, Indicates the risk factor of identity disguise; represents the dynamic hash collision rate; Indicates the impact weight of identity disguise risk; Furthermore, the data integrity risk factor is: in, Indicates the data integrity risk factor; Indicates the number of damaged packets detected according to the physical layer; represents the entropy of packet size distribution; Indicates the total number of packets; Furthermore, the risk factor of abnormal traffic behavior is: in, Indicates the risk factor of abnormal traffic behavior; Indicates the abnormality of flow rate; Indicates the packet loss rate fluctuation coefficient; represents the Doppler shift stability coefficient; Furthermore, the risk factor of key leakage is: in, Indicates the risk factor of key leakage; Indicates the number of sessions in which the key derived from the chaotic key sequence is reused in the system record; Indicates the total number of communication sessions initiated from the ground terminal; Furthermore, the traffic safety score is: in, Indicates the traffic safety score; Indicates Risk factor; and They represent the risk factor of signal tampering, the risk factor of identity disguise, the risk factor of data integrity, the risk factor of abnormal traffic behavior, and the risk factor of key leakage respectively; Indicates The weight of the risk factor.

[0028] Preferably, the adaptive selection of encryption algorithm based on traffic security score includes: When traffic safety score , select AES-128 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select AES-256 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.

[0029] This embodiment collects the traffic status information of the communication link between the ground and the orbiting satellite in real time, and constructs five risk factors based on multi-dimensional data of the physical layer, network layer and security layer, including the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor, and constructs a traffic security score. Through real-time monitoring and comprehensive evaluation of the traffic status, the security protection capability of satellite Internet traffic is effectively increased, which is conducive to improving the security of satellite Internet traffic.

[0030] A dynamic encryption module, used for adaptively selecting an encryption algorithm based on a traffic security score, and encrypting traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence; In order to verify the effectiveness of a satellite Internet traffic security protection system provided by this embodiment, the traffic security data between the actual ground terminal and a single orbital satellite are compared, including system 1, system 2 and system 3; system 1 is a satellite Internet traffic security protection system provided by this embodiment, and system 2 is based on system 1 without considering the first chaotic key sequence; system 2 is based on system 1 without considering the traffic security score; specific comparison data include data tampering rate, identity disguise recognition accuracy rate and password cracking rate; as shown in Table 2; Table 2 Comparison of different systems system Data tampering rate Identity disguise recognition accuracy Password cracking rate System 1 0.2% 99.5% 0.1% System 2 1.5% 88% 2.1% System 3 2.5% 87% 1.8% It can be seen from Table 2 that the satellite Internet traffic security protection system provided by this embodiment has significant effectiveness, can effectively prevent data tampering, effectively identify disguised data, and avoid passwords from being cracked; and improves security.

[0031] This embodiment adaptively selects an encryption algorithm based on a traffic security score, and encrypts the traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, thereby facilitating the improvement of the security of satellite Internet traffic.

[0032] This embodiment obtains orbital characteristic parameters and external disturbance parameters and generates a first chaotic key sequence; constructs a signal tampering risk coefficient, an identity disguise risk coefficient, a data integrity risk coefficient, a traffic behavior abnormality risk coefficient and a key leakage risk coefficient based on the traffic status information collected in real time by the ground terminal, and then generates a traffic security score; adaptively selects an encryption algorithm based on the traffic security score, and uses the session key derived from the first chaotic key sequence to encrypt the traffic data of the communication link; the present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.

[0033] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A satellite Internet traffic security protection method, characterized in that: include: S1. Obtaining the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, using the hash values ​​of the two as the initial values ​​of the chaotic mapping, and using the coupled iteration of the Logistic mapping and the Henon mapping to generate the coupling sequence, and obtaining the first chaotic key sequence according to the coupling sequence; S2. Based on the real-time collection of traffic status information of the communication link between the ground terminal and each orbiting satellite, the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor are constructed according to the traffic status information; And construct a traffic safety score based on these five risk factors; S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link based on the encryption algorithm and a session key derived from the first chaotic key sequence.

2. A satellite Internet traffic security protection method according to claim 1, characterized in that: The orbit characteristic parameters include orbit inclination, perigee height, yaw angle and satellite velocity vector; the external disturbance parameters include satellite orbit change, satellite attitude control error and external electromagnetic interference intensity; the flow status information includes physical layer flow status information, network layer flow status information and security layer flow status information; The physical layer traffic status information includes a signal strength attenuation index, a dynamic bit error rate, and a Doppler frequency shift stability coefficient; The network layer traffic status information includes packet loss rate fluctuation coefficient, traffic rate anomaly degree and data packet size distribution entropy; Security layer traffic status information includes dynamic hash collision rate and two-factor authentication failure rate.

3. A satellite Internet traffic security protection method according to claim 1, characterized in that: The initial value is: in, and represents the initial value of the chaotic map; It means taking the first 8 bits; Indicates taking the last 8 digits; It represents the orbital inclination, which reflects the angle between the satellite orbit plane and the Earth's equatorial plane; Indicates the perigee altitude; represents the satellite velocity vector; Represents the satellite attitude control error; Indicates the strength of external electromagnetic interference; Indicates the change in satellite orbit, reflecting the deviation of the orbit affected by external forces; The coupling formula is: in, represents the value of the coupling sequence at step n; Represents the state variable value under the Logistic mapping sequence at the nth step; represents the value of the x state variable under the Henon mapping sequence at the nth step; represents the coupling coefficient.

4. A satellite Internet traffic security protection method according to claim 1, characterized in that: The first chaotic key sequence is: in, Represents the first chaotic key sequence.

5. A satellite Internet traffic security protection method according to claim 1, characterized in that: The traffic safety scores are: in, Indicates the traffic safety score; Indicates Risk factor; and They represent the risk factor of signal tampering, the risk factor of identity disguise, the risk factor of data integrity, the risk factor of abnormal traffic behavior, and the risk factor of key leakage respectively; Indicates The weight of the risk factor.

6. A satellite Internet traffic security protection method according to claim 1, characterized in that: The adaptive selection of encryption algorithm based on traffic security score includes: When traffic safety score , select AES-128 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select AES-256 encryption algorithm, the key is obtained by processing the first chaotic key sequence; when the traffic security score , select SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.

7. A satellite Internet traffic security protection system, the system being used to execute a satellite Internet traffic security protection method according to any one of claims 1 to 6, characterized in that: include: The orbit data acquisition and key generation module is used to obtain the orbit characteristic parameters and external disturbance parameters of the current orbit satellite through the attitude control system and navigation system of each orbit satellite; based on the orbit characteristic parameters and external disturbance parameters, the hash values ​​of the two are used as the initial values ​​of the chaotic map, and the coupling sequence is generated by the coupling iteration of the Logistic map and the Henon map, and the first chaotic key sequence is obtained according to the coupling sequence; The traffic status monitoring and risk assessment module is used to collect the traffic status information of the communication links between the ground terminal and each orbiting satellite in real time, and construct the signal tampering risk coefficient, identity disguise risk coefficient, data integrity risk coefficient, traffic behavior abnormality risk coefficient and key leakage risk coefficient according to the traffic status information; And construct a traffic safety score based on these five risk factors; The dynamic encryption module is used to adaptively select an encryption algorithm based on a traffic security score, and encrypt traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence.

Citation Information

Patent Citations

  • Dynamic S box generation method and test system based on spatiotemporal chaotic system

    CN119602926A

  • Method and Apparatus for Global Navigation Satellite System Spoofing Detection using An Anti-spoofing Message

    KR101758554B1

Cited By

  • Satellite signal tamper-proofing method and system

    CN120201418A