A Satellite Internet Traffic Security Protection Method and System
By generating the first chaotic key sequence and constructing the traffic security score, adaptively selecting the encryption algorithm to encrypt the satellite Internet traffic data, solving the problem of fixed encryption algorithms in the prior art, and realizing dynamic response to complex security threats and real-time security assessment.
Patent Information
- Application Number
- CN202510450548.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing satellite Internet traffic security protection methods rely on fixed encryption algorithms, lack dynamics and flexibility, are difficult to deal with complex security threats, and are unable to evaluate and respond to external perturbation parameters and communication link traffic status in the satellite Internet in real time.
By acquiring the track characteristic parameters and external disturbance parameters, a first chaotic key sequence is generated, and multiple risk coefficients are constructed based on the traffic status information collected by the ground terminal in real time to generate a traffic safety score. The encryption algorithm is adaptively selected according to the traffic security score, and the traffic data of the communication link is encrypted using the session key derived from the first chaotic key sequence.
It improves the complexity and security of keys, enhances the security protection capabilities of satellite Internet traffic, realizes real-time monitoring and encryption of communication traffic, and ensures the security of satellite Internet traffic data.
Smart Images

Figure CN119997005B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to a method and system for satellite Internet traffic security protection. Background Art
[0002] Traditional satellite Internet traffic security protection methods mostly rely on traditional encryption technologies. These technologies usually perform encryption processing based on fixed encryption algorithms, lacking dynamics and flexibility, and are difficult to cope with complex security threats. In addition, existing methods also lack a real-time evaluation and response mechanism for continuously changing external disturbance parameters (such as electromagnetic interference and satellite orbit changes) and communication link traffic status in the satellite Internet, which easily leads to limited security of satellite Internet traffic.
[0003] Therefore, a method and system for satellite Internet traffic security protection are proposed. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and system for satellite Internet traffic security protection. The present invention obtains orbital characteristic parameters and external disturbance parameters, and generates a first chaotic key sequence. Based on the traffic status information collected in real time by ground terminals, signal tampering risk coefficients, identity spoofing risk coefficients, data integrity risk coefficients, traffic behavior anomaly risk coefficients, and key leakage risk coefficients are constructed, and then a traffic security score is generated. Based on the traffic security score, an encryption algorithm is adaptively selected, and the traffic data of the communication link is encrypted using the session key derived from the first chaotic key sequence. The present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A method for satellite Internet traffic security protection, comprising:
[0007] S1. Obtain the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite. Based on the orbital characteristic parameters and external disturbance parameters, take the hash values of the two as the initial values of the chaotic mapping, and generate a coupling sequence by coupling iteration of the Logistic mapping and the Henon mapping, and obtain the first chaotic key sequence according to the coupling sequence;
[0008] S2. Based on the traffic status information of the communication link between the ground terminal and each orbital satellite collected in real time, and construct signal tampering risk coefficients, identity spoofing risk coefficients, data integrity risk coefficients, traffic behavior anomaly risk coefficients, and key leakage risk coefficients according to the traffic status information; and construct a traffic security score based on these five risk coefficients;
[0009] S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link using the session key derived from the encryption algorithm and the first chaotic key sequence.
[0010] Preferably, the orbital characteristic parameters include the orbital inclination, perigee altitude, yaw angle, and satellite velocity vector; the external disturbance parameters include the satellite orbit change amount, satellite attitude control error, and external electromagnetic interference intensity; the traffic state information includes physical layer traffic state information, network layer traffic state information, and security layer traffic state information; the physical layer traffic state information includes the signal strength attenuation exponent, dynamic bit error rate, and Doppler frequency shift stability coefficient; the network layer traffic state information includes the packet loss rate fluctuation coefficient, traffic rate anomaly degree, and packet size distribution entropy; the security layer traffic state information includes the dynamic hash collision rate and the two-factor authentication failure rate.
[0011] Preferably, the initial value is: Where, And Represents the initial value of the chaotic map; Represents taking the first 8 bits; Represents taking the last 8 bits; Represents the orbital inclination, reflecting the angle between the satellite orbit plane and the Earth's equatorial plane; Represents the perigee altitude; Represents the satellite velocity vector; Represents the satellite attitude control error; Represents the external electromagnetic interference intensity; Represents the satellite orbit change amount, reflecting the offset of the orbit affected by external forces;
[0012] The coupling formula is: Where, Represents the value of the coupling sequence at the nth step; Represents the state variable value under the Logistic map sequence at the nth step; Represents the x state variable value under the Henon map sequence at the nth step; Represents the coupling coefficient.
[0013] Preferably, the first chaotic key sequence is: Where, Represents the first chaotic key sequence.
[0014] Preferably, the traffic security score is: Where, Represents the traffic security score; Represents the th risk coefficient; And respectively represent the signal tampering risk coefficient, identity disguise risk coefficient, data integrity risk coefficient, traffic behavior anomaly risk coefficient, and key leakage risk coefficient; represents the weight of the
[0015] Preferably, the encryption algorithm adaptively selected based on the traffic security score includes:
[0016] When the traffic security score , select the AES-128 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the AES-256 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.
[0017] A satellite Internet traffic security protection system, the system is used to execute any one of the described satellite Internet traffic security protection methods, including:
[0018] An orbital data acquisition and key generation module, used to obtain the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, use the hash values of the two as the initial value of the chaotic mapping, and use the coupled iteration of the Logistic mapping and the Henon mapping to generate a coupled sequence, and obtain the first chaotic key sequence according to the coupled sequence;
[0019] A traffic state monitoring and risk assessment module, used to collect the traffic state information of the communication link between the ground terminal and each orbital satellite in real time, and construct a signal tampering risk coefficient, identity disguise risk coefficient, data integrity risk coefficient, traffic behavior anomaly risk coefficient, and key leakage risk coefficient based on the traffic state information; and construct a traffic security score based on these five risk coefficients;
[0020] A dynamic encryption module, used to adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link based on the encryption algorithm and the session key derived from the first chaotic key sequence.
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] 1. The present invention obtains the orbital characteristic parameters and external perturbation parameters of an orbital satellite, uses their hash values as the initial values of chaotic mapping, and performs coupled iteration by combining the Logistic mapping and the Henon mapping to generate a first chaotic key sequence. The first chaotic key sequence generated based on the satellite orbital characteristics and external perturbation parameters can effectively improve the complexity and security of the key, effectively enhance the security protection ability of satellite Internet traffic, and thus is conducive to improving the security of satellite Internet traffic.
[0023] 2. The present invention constructs five risk coefficients, including a signal tampering risk coefficient, an identity spoofing risk coefficient, a data integrity risk coefficient, a traffic behavior anomaly risk coefficient, and a key leakage risk coefficient, based on the multi-dimensional data of the physical layer, network layer, and security layer by collecting the traffic status information of the communication link between the ground and the orbital satellite in real time, and constructs a traffic security score. By monitoring and comprehensively evaluating the traffic status in real time, the security protection ability of satellite Internet traffic is effectively enhanced, and thus it is conducive to improving the security of satellite Internet traffic.
[0024] 3. The present invention adaptively selects an encryption algorithm based on the traffic security score, and encrypts the traffic data of the communication link with a session key derived from the encryption algorithm and the first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, and thus is conducive to improving the security of satellite Internet traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is a schematic flow chart of a method for protecting the security of satellite Internet traffic provided by an embodiment of the present invention;
[0026] Figure 2 is a schematic structural diagram of a system for protecting the security of satellite Internet traffic provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0028] Embodiment 1
[0029] To improve the security of satellite Internet traffic, a method for protecting the security of satellite Internet traffic is applied. Referring to Figure 1 a schematic flow chart of a method for protecting the security of satellite Internet traffic provided by an embodiment of the present invention, which includes:
[0030] S1. Obtain the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, use the hash values of the two as the initial values of the chaotic mapping, and generate a coupling sequence through the coupled iteration of the Logistic mapping and the Henon mapping, and obtain the first chaotic key sequence according to the coupling sequence;
[0031] Further, the orbital characteristic parameters include the orbital inclination, the perigee altitude, the yaw angle, and the satellite velocity vector; the external disturbance parameters include the satellite orbit change amount, the satellite attitude control error, and the external electromagnetic interference intensity;
[0032] Further, the initial value is: Wherein, and represent the initial value of the chaotic mapping; represents taking the first 8 bits; represents taking the last 8 bits; represents the orbital inclination, reflecting the angle between the satellite orbit plane and the Earth's equatorial plane; represents the perigee altitude; represents the satellite velocity vector; represents the satellite attitude control error; represents the external electromagnetic interference intensity; represents the satellite orbit change amount, reflecting the offset of the orbit affected by external forces;
[0033] The coupling formula is: Wherein, represents the value of the coupling sequence at the nth step; represents the state variable value under the Logistic mapping sequence at the nth step; represents the x state variable value under the Henon mapping sequence at the nth step; represents the coupling coefficient.
[0034] Further, the derivation formula of the Logistic mapping sequence is: Wherein, represents the state variable value under the Logistic mapping sequence at the (n + 1)th step; represents the first chaotic parameter;
[0035] Further, the Henon sequence derivation formula is: Wherein, represents the x state variable value under the Henon mapping sequence at the (n + 1)th step; represents the y state variable value under the Henon mapping sequence at the (n + 1)th step; represents the value of the y state variable in the Henon mapping sequence at the nth step; and represents the control parameter;
[0036] Furthermore, the first chaotic key sequence is: where represents the first chaotic key sequence. In this embodiment, by obtaining the orbital characteristic parameters and external perturbation parameters of the orbital satellite and using their hash values as the initial values of the chaotic mapping, and combining the Logistic mapping and the Henon mapping for coupled iteration, a first chaotic key sequence is generated; the first chaotic key sequence generated based on the satellite orbital characteristics and external perturbation parameters can effectively improve the complexity and security of the key, effectively increase the security protection ability of satellite Internet traffic, and thus is beneficial to enhancing the security of satellite Internet traffic.
[0037] S2. Based on the ground terminal, real-time collect the traffic state information of the communication links with each orbital satellite, and construct a signal tampering risk coefficient, an identity disguise risk coefficient, a data integrity risk coefficient, a traffic behavior anomaly risk coefficient, and a key leakage risk coefficient according to the traffic state information; and construct a traffic security score based on these five risk coefficients;
[0038] The traffic state information includes physical layer traffic state information, network layer traffic state information, and security layer traffic state information; the physical layer traffic state information includes the number of damaged data packets, the signal strength attenuation index, the dynamic bit error rate, and the Doppler frequency shift stability coefficient; the network layer traffic state information includes the packet loss rate fluctuation coefficient, the traffic rate anomaly degree, and the data packet size distribution entropy; the security layer traffic state information includes the dynamic hash collision rate, the two-factor authentication failure rate, and the key reuse times;
[0039] Furthermore, the signal strength attenuation index is: where represents the signal strength attenuation index; represents the real-time signal power; represents the theoretical maximum power;
[0040] The dynamic bit error rate is represented by the absolute value of the deviation between the instantaneous bit error rate and the historical bit error rate baseline, reflecting the impact of burst interference on the communication quality; the dynamic bit error rate is: where represents the dynamic bit error rate; represents the real-time bit error rate of the ground terminal; represents the historical bit error rate baseline;
[0041] The Doppler frequency shift stability coefficient is represented by the ratio of the frequency shift standard deviation to the carrier center frequency and is used to quantify the frequency fluctuations caused by the high-speed movement of the satellite; the Doppler frequency shift stability coefficient is: Where, represents the Doppler frequency shift stability coefficient; represents the standard deviation of the Doppler frequency shift sequence measured by the ground terminal; represents the nominal carrier frequency measured by the ground terminal;
[0042] The packet loss rate fluctuation coefficient is represented by the ratio of the short-term packet loss rate variance to the long-term mean; the traffic rate anomaly is represented by the Mahalanobis distance between the traffic rate and the historical pattern and is used to detect burst traffic attacks; the traffic rate anomaly is: Where, represents the traffic rate anomaly; represents the real-time traffic rate; represents the historical traffic rate mean; represents the covariance matrix;
[0043] The packet size distribution entropy quantifies the randomness of the packet size through Shannon entropy and is used to identify abnormal packet distributions; the packet size distribution entropy is: Where, represents the packet size distribution entropy; represents the packet size category probability;
[0044] The dynamic hash collision rate is represented by the ratio of the number of hash verification failures per unit time to the total number of encryption sessions, reflecting the risk of data tampering; the two-factor authentication failure rate is represented by the ratio of the number of two-factor identity authentication failures to the total number of all authentication interactions in the ground terminal.
[0045] Furthermore, the signal tampering risk coefficient is: Where, represents the signal tampering risk coefficient; represents the signal strength attenuation exponent; represents the dynamic bit error rate; and the signal tampering risk impact weight;
[0046] The identity spoofing risk coefficient is: Where, represents the identity spoofing risk coefficient; represents the dynamic hash collision rate; represents the identity spoofing risk impact weight;
[0047] Furthermore, the data integrity risk coefficient is: Where, Represents the data integrity risk coefficient; Represents the number of damaged data packets detected according to the physical layer; Represents the entropy of the data packet size distribution; Represents the total number of data packets;
[0048] Furthermore, the traffic behavior anomaly risk coefficient is: Wherein, Represents the traffic behavior anomaly risk coefficient; Represents the traffic rate anomaly degree; Represents the packet loss rate fluctuation coefficient; Represents the Doppler frequency shift stability coefficient;
[0049] Furthermore, the key leakage risk coefficient is: Wherein, Represents the key leakage risk coefficient; Represents the number of sessions in which the keys derived from the chaotic key sequence are reused in the system record; Represents the total number of communication sessions initiated from the ground terminal;
[0050] Furthermore, the traffic security score is: Wherein, Represents the traffic security score; Represents the th risk coefficient; And Respectively represent the signal tampering risk coefficient, the identity spoofing risk coefficient, the data integrity risk coefficient, the traffic behavior anomaly risk coefficient and the key leakage risk coefficient; Represents the th weight of the risk coefficient.
[0051] Preferably, the encryption algorithm adaptively selected based on the traffic security score includes:
[0052] When the traffic security score , select the AES-128 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the AES-256 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.
[0053] In this embodiment, by collecting the traffic status information of the communication link between the ground and the orbital satellite in real time, and based on multi-dimensional data of the physical layer, network layer and security layer, five risk coefficients are constructed, including signal tampering risk coefficient, identity spoofing risk coefficient, data integrity risk coefficient, traffic behavior anomaly risk coefficient and key leakage risk coefficient, and a traffic security score is constructed. Through the real-time monitoring and comprehensive evaluation of the traffic status, the security protection ability of satellite Internet traffic is effectively enhanced, which is beneficial to improving the security of satellite Internet traffic.
[0054] S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link with the session key derived from the encryption algorithm and the first chaotic key sequence.
[0055] To verify the effectiveness of a satellite Internet traffic security protection method provided by this embodiment, the traffic security data between the actual ground terminal and a single orbital satellite is compared, including Method 1, Method 2 and Method 3; Method 1 is a satellite Internet traffic security protection method provided by this embodiment, Method 2 does not consider the first chaotic key sequence on the basis of Method 1; Method 2 does not consider the traffic security score on the basis of Method 1; The specific comparison data includes data tampering rate, identity spoofing recognition accuracy rate and password cracking rate; The specific data is shown in Table 1 as follows;
[0056] Table 1 Comparison Table of Different Methods
[0057] Method Data tampering rate Identity disguise recognition accuracy rate Password cracking rate Method 1 0.1% 98.5% 0.12% Method 2 1% 89% 1.1% Method 3 1.5% 86% 2.1%
[0058] As can be seen from Table 1, a satellite Internet traffic security protection method provided by this embodiment has remarkable effectiveness, can effectively prevent data tampering, effectively identify spoofed data and can avoid password cracking; The security is improved.
[0059] In this embodiment, an encryption algorithm is adaptively selected based on the traffic security score, and the traffic data of the communication link is encrypted with the session key derived from the encryption algorithm and the first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, thus being beneficial to improving the security of satellite Internet traffic.
[0060] In this embodiment, by obtaining orbital characteristic parameters and external disturbance parameters, a first chaotic key sequence is generated; based on the traffic status information collected in real time by the ground terminal, a signal tampering risk coefficient, an identity spoofing risk coefficient, a data integrity risk coefficient, a traffic behavior anomaly risk coefficient, and a key leakage risk coefficient are constructed, and then a traffic security score is generated; based on the traffic security score, an encryption algorithm is adaptively selected, and the traffic data of the communication link is encrypted using the session key derived from the first chaotic key sequence; the present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.
[0061] Embodiment 2
[0062] To improve the security of satellite Internet traffic, a satellite Internet traffic security protection system is applied. Referring to Figure 2 which is a schematic structural diagram of a satellite Internet traffic security protection system provided by an embodiment of the present invention, including:
[0063] A satellite Internet traffic security protection system, including:
[0064] An orbital data acquisition and key generation module, configured to obtain the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, the hash values of the two are used as the initial value of the chaotic mapping, and a coupled sequence is generated by the coupled iteration of the Logistic mapping and the Henon mapping, and a first chaotic key sequence is obtained according to the coupled sequence;
[0065] Further, the orbital characteristic parameters include orbital inclination, perigee altitude, yaw angle, and satellite velocity vector; the external disturbance parameters include satellite orbit change amount, satellite attitude control error, and external electromagnetic interference intensity;
[0066] Further, the initial value is: Wherein, and represent the initial value of the chaotic mapping; represents taking the first 8 bits; represents taking the last 8 bits; represents the orbital inclination, reflecting the angle between the satellite orbit plane and the Earth's equatorial plane; represents the perigee altitude; represents the satellite velocity vector; represents the satellite attitude control error; represents the external electromagnetic interference intensity; represents the satellite orbit change amount, reflecting the offset of the orbit affected by external forces;
[0067] The coupling formula is: Wherein, Denotes the value of the coupling sequence at the n-th step; Denotes the state variable value under the Logistic mapping sequence at the n-th step; Denotes the x state variable value under the Henon mapping sequence at the n-th step; Denotes the coupling coefficient.
[0068] Furthermore, the derivation formula of the Logistic mapping sequence is: where Denotes the state variable value under the Logistic mapping sequence at the (n + 1)-th step; Denotes the first chaotic parameter;
[0069] Furthermore, the derivation formula of the Henon sequence is: where Denotes the x state variable value under the Henon mapping sequence at the (n + 1)-th step; Denotes the y state variable value under the Henon mapping sequence at the (n + 1)-th step; Denotes the y state variable value under the Henon mapping sequence at the n-th step; and Denotes the control parameter;
[0070] Furthermore, the first chaotic key sequence is: where Denotes the first chaotic key sequence. In this embodiment, by obtaining the orbital characteristic parameters and external perturbation parameters of the orbital satellite, and using their hash values as the initial values of the chaotic mapping, and combining the Logistic mapping and the Henon mapping for coupled iteration, a first chaotic key sequence is generated; through the first chaotic key sequence generated based on the satellite orbital characteristics and external perturbation parameters, the complexity and security of the key can be effectively improved, and the security protection ability of satellite Internet traffic can be effectively increased, thus being conducive to enhancing the security of satellite Internet traffic. The traffic status monitoring and risk assessment module is used to collect in real time the traffic status information of the communication links with each orbital satellite based on the ground terminal, and construct a signal tampering risk coefficient, an identity spoofing risk coefficient, a data integrity risk coefficient, a traffic behavior anomaly risk coefficient, and a key leakage risk coefficient according to the traffic status information; and construct a traffic security score based on these five risk coefficients;
[0071] The traffic status information includes physical layer traffic status information, network layer traffic status information, and security layer traffic status information; the physical layer traffic status information includes the number of damaged data packets, signal strength attenuation index, dynamic bit error rate, and Doppler shift stability coefficient; the network layer traffic status information includes the packet loss rate fluctuation coefficient, traffic rate anomaly degree, and data packet size distribution entropy; the security layer traffic status information includes the dynamic hash collision rate, two-factor authentication failure rate, and key reuse times;
[0072] Further, the signal strength attenuation index is: Wherein, represents the signal strength attenuation index; represents the real-time signal power; represents the theoretical maximum power;
[0073] The dynamic bit error rate is represented by the absolute value of the deviation between the instantaneous bit error rate and the historical bit error rate baseline, reflecting the impact of burst interference on communication quality; the dynamic bit error rate is: Wherein, represents the dynamic bit error rate; represents the real-time bit error rate of the ground terminal; represents the historical bit error rate baseline;
[0074] The Doppler shift stability coefficient is represented by the ratio of the frequency shift standard deviation to the carrier center frequency, and is used to quantify the frequency fluctuation caused by the high-speed movement of the satellite; the Doppler shift stability coefficient is: Wherein, represents the Doppler shift stability coefficient; represents the standard deviation of the Doppler shift sequence measured by the ground terminal; represents the nominal carrier frequency measured by the ground terminal;
[0075] The packet loss rate fluctuation coefficient is represented by the ratio of the short-term packet loss rate variance to the long-term mean; the traffic rate anomaly degree is represented by the Mahalanobis distance between the traffic rate and the historical pattern, and is used to detect burst traffic attacks; the traffic rate anomaly degree is: Wherein, represents the traffic rate anomaly degree; represents the real-time traffic rate; represents the historical traffic rate mean; represents the covariance matrix;
[0076] The data packet size distribution entropy quantifies the randomness of the data packet size through Shannon entropy, and is used to identify abnormal packet distributions; the data packet size distribution entropy is: Wherein, represents the data packet size distribution entropy; represents the data packet size category probability;
[0077] The dynamic hash collision rate is represented by the ratio of the number of hash verification failures per unit time to the total number of encryption sessions, reflecting the risk of data tampering; the two-factor authentication failure rate is represented by the ratio of the number of two-factor authentication failures to the total number of all authentication interactions in the ground terminal;
[0078] Furthermore, the signal tampering risk coefficient is: wherein, represents the signal tampering risk coefficient; represents the signal strength attenuation exponent; represents the dynamic bit error rate; and the signal tampering risk impact weight;
[0079] The identity spoofing risk coefficient is: wherein, represents the identity spoofing risk coefficient; represents the dynamic hash collision rate; represents the identity spoofing risk impact weight;
[0080] Furthermore, the data integrity risk coefficient is: wherein, represents the data integrity risk coefficient; represents the number of damaged data packets detected according to the physical layer; represents the packet size distribution entropy; represents the total number of data packets;
[0081] Furthermore, the traffic behavior anomaly risk coefficient is: wherein, represents the traffic behavior anomaly risk coefficient; represents the traffic rate anomaly degree; represents the packet loss rate fluctuation coefficient; represents the Doppler frequency shift stability coefficient;
[0082] Furthermore, the key leakage risk coefficient is: wherein, represents the key leakage risk coefficient; represents the number of sessions in which the keys derived from the chaotic key sequence are reused in the system record; represents the total number of communication sessions initiated from the ground terminal;
[0083] Furthermore, the traffic security score is: wherein, represents the traffic security score; represents the th risk coefficient; and respectively represent the signal tampering risk coefficient, identity spoofing risk coefficient, data integrity risk coefficient, traffic behavior anomaly risk coefficient, and key leakage risk coefficient; represents the th weight of the risk coefficient.
[0084] Preferably, the encryption algorithm adaptively selected based on the traffic security score includes:
[0085] When the traffic security score , select the AES-128 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the AES-256 encryption algorithm, and the key is obtained by processing the first chaotic key sequence; when the traffic security score , select the SM4 encryption algorithm, and the key is obtained by processing the first chaotic key sequence.
[0086] In this embodiment, by collecting the traffic status information of the communication link between the ground and the orbital satellite in real time, five risk coefficients are constructed based on multi-dimensional data of the physical layer, network layer, and security layer, including the signal tampering risk coefficient, identity spoofing risk coefficient, data integrity risk coefficient, traffic behavior anomaly risk coefficient, and key leakage risk coefficient, and a traffic security score is constructed. Through the real-time monitoring and comprehensive evaluation of the traffic status, the security protection ability of satellite Internet traffic is effectively increased, which is beneficial to improving the security of satellite Internet traffic.
[0087] The dynamic encryption module is used to adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link with the session key derived from the encryption algorithm and the first chaotic key sequence;
[0088] In order to verify the effectiveness of a satellite Internet traffic security protection system provided in this embodiment, the traffic security data between the actual ground terminal and a single orbital satellite is compared, including System 1, System 2, and System 3; System 1 is a satellite Internet traffic security protection system provided in this embodiment, System 2 does not consider the first chaotic key sequence on the basis of System 1; System 2 does not consider the traffic security score on the basis of System 1; the specific comparison data includes the data tampering rate, identity spoofing recognition accuracy rate, and password cracking rate; specifically as shown in Table 2;
[0089] Table 2 Comparison table of different systems
[0090] System Data tampering rate Identity disguise recognition accuracy rate Password cracking rate System 1 0.2% 99.5% 0.1% System 2 1.5% 88% 2.1% System 3 2.5% 87% 1.8%
[0091] As can be seen from Table 2, a satellite Internet traffic security protection system provided by this embodiment has remarkable effectiveness, can effectively prevent data tampering, effectively identify camouflaged data, and can avoid password cracking; thus improving security.
[0092] This embodiment adaptively selects an encryption algorithm based on traffic security scores, and encrypts the traffic data of the communication link using a session key derived from the encryption algorithm and the first chaotic key sequence, which can effectively improve the flexibility of satellite Internet traffic data encryption, thus being conducive to enhancing the security of satellite Internet traffic.
[0093] This embodiment obtains orbital characteristic parameters and external perturbation parameters, and generates a first chaotic key sequence; constructs signal tampering risk coefficients, identity camouflage risk coefficients, data integrity risk coefficients, traffic behavior anomaly risk coefficients, and key leakage risk coefficients based on the traffic status information collected by the ground terminal in real time, and then generates traffic security scores; adaptively selects an encryption algorithm based on the traffic security scores, and encrypts the traffic data of the communication link using a session key derived from the first chaotic key sequence; the present invention can monitor and encrypt communication traffic in real time to ensure the security of satellite Internet traffic data.
[0094] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A satellite Internet traffic security protection method, characterized in that: include: S1. Obtaining the orbital characteristic parameters and external disturbance parameters of the current orbital satellite through the attitude control system and navigation system of each orbital satellite; based on the orbital characteristic parameters and external disturbance parameters, using the hash values of the two as the initial values of the chaotic mapping, and using the coupled iteration of the Logistic mapping and the Henon mapping to generate the coupling sequence, and obtaining the first chaotic key sequence according to the coupling sequence; S2. Based on the real-time collection of traffic status information of the communication link between the ground terminal and each orbiting satellite, the signal tampering risk factor, identity disguise risk factor, data integrity risk factor, traffic behavior abnormality risk factor and key leakage risk factor are constructed according to the traffic status information; And construct a traffic safety score based on these five risk factors; S3. Adaptively select an encryption algorithm based on the traffic security score, and encrypt the traffic data of the communication link based on the encryption algorithm and a session key derived from the first chaotic key sequence.
2. A satellite Internet traffic security protection method according to claim 1, characterized in that: The orbit characteristic parameters include orbit inclination, perigee height, yaw angle and satellite velocity vector; the external disturbance parameters include satellite orbit change, satellite attitude control error and external electromagnetic interference intensity; the flow status information includes physical layer flow status information, network layer flow status information and security layer flow status information; The physical layer traffic status information includes a signal strength attenuation index, a dynamic bit error rate, and a Doppler frequency shift stability coefficient; The network layer traffic status information includes packet loss rate fluctuation coefficient, traffic rate anomaly degree and data packet size distribution entropy; Security layer traffic status information includes dynamic hash collision rate and two-factor authentication failure rate.
3. A satellite Internet traffic security protection method according to claim 1, characterized in that: The initial value is: in, and represents the initial value of the chaotic map; Indicates from In the 256-bit hash result obtained after the operation, take the first 8 bits of the hash result; Indicates from In the 256-bit hash result obtained after the operation, take the last 8 bits of the hash result; It represents the orbital inclination, which reflects the angle between the satellite orbit plane and the Earth's equatorial plane; Indicates the perigee altitude; represents the satellite velocity vector; Represents the satellite attitude control error; Indicates the strength of external electromagnetic interference; Indicates the change in satellite orbit, reflecting the deviation of the orbit affected by external forces; The coupling formula is: in, represents the value of the coupling sequence at step n; Represents the state variable value under the Logistic mapping sequence at the nth step; represents the value of the x state variable under the Henon mapping sequence at the nth step; represents the coupling coefficient.
4. A satellite Internet traffic security protection method according to claim 1, characterized in that: The first chaotic key sequence is: in, Represents the first chaotic key sequence.
5. A satellite Internet traffic security protection method according to claim 1, characterized in that: The traffic safety scores are: in, Indicates the traffic safety score; Indicates Risk factor; and They represent the risk factor of signal tampering, the risk factor of identity disguise, the risk factor of data integrity, the risk factor of abnormal traffic behavior, and the risk factor of key leakage respectively; Indicates The weight of the risk factor.
6. A satellite Internet traffic security protection method according to claim 1, characterized in that: The adaptive selection of encryption algorithm based on traffic security score includes: When traffic safety score , select AES-128 encryption algorithm, and the session key is obtained by processing the first chaotic key sequence; when the traffic security score , select the ChaCha20-Poly1305 encryption algorithm, and the session key is obtained by processing the first chaotic key sequence; when the traffic security score , select AES-256 encryption algorithm, and the session key is obtained by processing the first chaotic key sequence; when the traffic security score , select SM4 encryption algorithm, and the session key is obtained by processing the first chaotic key sequence.
7. A satellite Internet traffic security protection system, the system being used to execute a satellite Internet traffic security protection method according to any one of claims 1 to 6, characterized in that: include: The orbit data acquisition and key generation module is used to obtain the orbit characteristic parameters and external disturbance parameters of the current orbit satellite through the attitude control system and navigation system of each orbit satellite; based on the orbit characteristic parameters and external disturbance parameters, the hash values of the two are used as the initial values of the chaotic map, and the coupling sequence is generated by coupling iteration of the Logistic map and the Henon map, and the first chaotic key sequence is obtained according to the coupling sequence; The traffic status monitoring and risk assessment module is used to collect the traffic status information of the communication links between the ground terminal and each orbiting satellite in real time, and construct the signal tampering risk coefficient, identity disguise risk coefficient, data integrity risk coefficient, traffic behavior abnormality risk coefficient and key leakage risk coefficient according to the traffic status information; And construct a traffic safety score based on these five risk factors; The dynamic encryption module is used to adaptively select an encryption algorithm based on a traffic security score, and encrypt traffic data of the communication link based on the encryption algorithm and a session key derived from a first chaotic key sequence.
Citation Information
Patent Citations
Dynamic S box generation method and test system based on spatiotemporal chaotic system
CN119602926A
Method and Apparatus for Global Navigation Satellite System Spoofing Detection using An Anti-spoofing Message
KR101758554B1