Satellite internet data packet verification method and device
By adopting a network layer data packet verification mechanism based on verification code in the satellite Internet, the problem of large overhead of data packet verification and communication in the satellite Internet is solved, and effective security verification and filtering of data packets is realized, and the overall security of the system is improved.
Patent Information
- Application Number
- CN202510196188.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
AI Technical Summary
In the satellite Internet, data packet verification computing, communication or storage overhead is high, and it is not very deployable, making it difficult to effectively prevent security risks such as DDoS attacks.
The network layer data packet verification, filtering and statistics mechanism is adopted based on verification code, and the key module, verification module and statistics module are configured through gateways, terminals and proxy routing nodes to dynamically generate and verify verification codes to ensure the security of data packets.
Effectively filter external malicious traffic, ensure the source and authenticity of data packets, reduce the computing and communication overhead of data packet verification in the satellite Internet, and improve the security and deployability of the system.
Smart Images

Figure CN120049946A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite communications, and in particular to a satellite Internet data grouping verification device and method. Background Art
[0002] The Internet has the characteristics of "simple core and complex edge". Routing nodes at the network layer mainly forward data packets according to the destination IP address and perform simple QoS processing, without verifying the source of data packets, which brings security risks such as DDoS attacks to the network. Especially in satellite Internet, satellite frequency and power resources are limited, and routing nodes located on satellites are extremely vulnerable to attacks by malicious users. A data packet verification technology is needed to verify each data packet, ensure that external malicious traffic "cannot enter", and internal traffic from satellite Internet terminals can be "controlled".
[0003] In response to the above-mentioned problem of authenticity verification of satellite Internet data packets, there are currently two main solutions. One is the strategy of binding IP addresses and MAC addresses in the access network, such as SAVI, but this strategy cannot guarantee that users outside the access network can forge IP addresses; the other is that the source adds a verification code to each data packet, such as OPT, ICING, EPIC, PPV, MASK, Atomos, etc., to ensure that the intermediate routing nodes can verify the data packets. However, due to the large computational overhead required for the routing nodes on the satellite to perform verification, the long verification code brings a large communication overhead, and the satellite routing node path changes dynamically. It is difficult for the terminal to predict the satellite routing node path, and the receiving end needs to cooperate. The deployability is not strong and it is difficult to apply to satellite Internet.
[0004] After searching, the application publication number CN114679303B is a source address verification method and device for satellite Internet. The method includes: determining the user status information that needs to be transferred when the access device is switched; sending the user status information to the user terminal of the initial access device; when the access device is switched, using the user status information in the user terminal and the new access device to coordinate the binding state transfer, so as to realize the transfer of the user status information from the initial access device to the anchor binding state table of the new access device via the user terminal; based on the user status information in the anchor binding state table, the source address of the network data message of the user terminal is verified to ensure the authenticity of the source address of the message. The method provided by the present invention sends the user status information to the user terminal for maintenance, and when the access device is switched, the user terminal and the new access device on the network side are linked to complete the binding state transfer, which reduces the state transfer overhead when switching satellites and improves the source address verification performance.
[0005] Differences between this patent and this application: 1. Different application scenarios: The comparative document is an extension of the SAVI mechanism, applied to the scenario of direct connection between the terminal and the satellite, limited to access network verification. In this application, the proxy routing node and the terminal are logically connected, and can verify all proxy routing nodes and terminals that establish a verification relationship with the gateway, such as connecting multiple user access satellites to the Internet through a large earth station; 2. Different verification methods: In the comparative document, the user terminal and the access satellite are bound based on status information. After binding, the source address of the network data packet of the user terminal is directly verified based on the user status information in the anchor point binding status table, without dynamically generating a verification code in the actually transmitted data packet for verification. In this application, for each data packet of the proxy routing node or terminal, the gateway verifies it based on the verification code dynamically generated based on the packet header, with higher security; 3. Different verification entities: The comparative document verifies on the on-board device with direct terminal connection. This application verifies through the gateway, which can be an on-board device (when the terminal is directly connected to the satellite), or can be deployed in a large earth station on the ground (when the large earth station is directly connected to the satellite), with a more flexible verification method and can reduce the state transfer overhead when switching satellites; In addition, in this application, the proxy routing node and the terminal can also verify the traffic from the satellite Internet gateway to provide protection for the proxy routing node and the terminal. Summary of the Invention
[0006] The present invention aims to solve the problems existing in the prior art such as large verification calculation, communication or storage overhead of satellite Internet data packets, and poor deployability, and proposes a network layer data packet verification, filtering and statistical mechanism based on verification codes, which is particularly suitable for security verification during data packet transmission in satellite Internet. The technical solution of the present invention is as follows:
[0007] A satellite Internet data packet verification device. The satellite Internet includes multiple gateways, each gateway being a top-level routing node. There are multiple levels of sub-routing nodes under each gateway. The sub-routing nodes are connected to terminals or proxy routing nodes from outside the satellite Internet. The sub-routing nodes only have the routing and forwarding functions of ordinary nodes. The gateways, terminals, and proxy routing nodes are all configured with key modules to implement symmetric key management between nodes and logically adjacent nodes. That is, a dynamic symmetric key is maintained through a pairwise negotiation method between the terminal or proxy routing node and the gateway. The terminal and proxy routing node are also configured with verification modules to implement key acquisition, verification code calculation, data packet filtering, and verification code update operations. The terminal and proxy routing node are also configured with statistical modules to implement traffic negotiation and statistical operations between nodes. For data packets sent from the terminal or proxy routing node to the satellite Internet, each terminal or proxy routing node adds a verification code to the data packets it sends based on the gateway connected to it. Each gateway verifies the verification code. After successful verification, the gateway deletes the verification code and restores it to a normal IP data packet, and transmits the data packet to the satellite Internet. After failure, the data packet is filtered. The statistical module counts the number of data packets between each node. For data packets from the satellite Internet, the gateway adds a verification code, and the terminal or proxy routing node verifies it. The verification process is the same as that of the data packet verification process sent to the satellite Internet. After successful verification by the proxy routing node, the verification code is deleted and restored to a normal IP data packet.
[0008] Further, the terminal or proxy routing node calculates the verification code according to the symmetric key of the logically connected gateway node, including the key number and the verification code generated for the gateway node, and the hash value calculated based on the packet header and part of the payload (the recommended calculation formula is CRC32), and sends the data packet to the neighbor node.
[0009] Further, the generation of the verification code adopts the following formula:
[0010] M = MAC key (H(PH) || key_no || IP_src)(1)
[0011] Where MAC key (.) is to calculate the verification code through the key key, H(PH) is the hash generated from the data packet header and part of the payload. The data packet header takes the header of the IP packet except TTL, and the payload takes the first byte. H(.) represents the hash operation. IP_src is the IP address of the node generating the verification code. M takes 64 bits.
[0012] Further, after receiving data packets from terminals and proxy routing nodes, the gateway node first determines whether the gateway address IP_gate in the data packet header is the same as its own gateway address. If not, the data packet is filtered. If it is the same, the verification code calculation and data packet filtering are completed according to the symmetric key with the terminal and the proxy routing node. After the verification code calculation, a new verification code M' is obtained based on the HASH, IP_src, and key_no in the packet header, and the key key obtained according to IP_src and key_no, and M' is compared with M. If M = M', the verification is successful; otherwise, the verification fails.
[0013] Further, the statistics module sets two counters for each neighbor node in the control plane, respectively counting the successful and failed packet counts. After successful verification, the successful packet counter C1_fi from this node is recorded in the statistics module. After verification fails, the data packet is filtered, and the failed packet counter C2_fi from this node is recorded in the statistics module.
[0014] A packet verification method based on the device according to any one of the above, comprising the following steps:
[0015] Step 1, the satellite Internet has one or more gateways, each gateway is connected to one or more sub-routing nodes, each sub-routing node can be connected to sub-routing nodes, terminals, and proxy routing nodes, and the proxy routing node is connected to the remaining nodes outside the satellite Internet; the sub-routing node realizes the packet forwarding function, the proxy routing node can be connected to traditional Internet terminals, and the proxy routing node is a sub-routing node of the satellite Internet, compatible with un-updated satellite Internet terminals;
[0016] Step 2, the terminal or the proxy routing node calculates the verification code according to the symmetric key with the logically connected gateway node, initializes the data packet header, including the key number, the verification code generated for the gateway node, and the hash value calculated according to the packet header and part of the payload, and sends the data packet to the neighbor node. The sub-routing node is responsible for forwarding the data packet.
[0017] Step 3, after receiving data packets from terminals and proxy routing nodes, the gateway node first determines whether the gateway address IP_gate in the data packet header is the same as its own gateway address. If not, the data packet is filtered. If it is the same, the verification code calculation and data packet filtering are completed according to the symmetric key with the terminal and the proxy routing node;
[0018] Step 4, before forwarding the successfully verified data packet, the gateway node deletes the newly added data packet header and forwards the data in the form of a normal IP data packet.
[0019] Step 5, receiving process: The gateway node receives data packets from satellite nodes, calculates the verification code using the key of the proxy routing node or terminal node connected logically, adds a data packet header to the data packets, and sends them to the proxy routing node or terminal node connected logically; the sub-routing node forwards the packets normally.
[0020] Step 6: After receiving the data packets, the proxy routing node and the terminal node calculate the verification code according to the data packet header information, verify the data packets. After successful verification, transmit the data packets and increment the successful packet counter C1_fi in the statistics module; after failed verification, filter the data packets and record the failed packet counter C2_fi from this node in the statistics module.
[0021] Step 7: After successful verification of the received data packets, the proxy routing node removes the added data packet header and restores it to a normal IP data packet for transmission.
[0022] Step 8: At regular time intervals TI, the proxy routing node or the terminal node negotiates the upper limit thresholds Th_C1_fi and Th_C2_fi of the data packets with the logically connected gateway node. When exceeding the thresholds, send a warning message to the neighbor node, and the administrator makes corresponding handling according to the warning message.
[0023] Further, the generation of the verification code in Step 2 adopts the following formula:
[0024] M = MAC key (H(PH) || key_no || IP_src) (1)
[0025] where MAC key (.) is to calculate the verification code through the key key, H(PH) is the hash generated from the data packet header and part of the payload. The data packet header takes the header of the IP packet except TTL, the payload takes the first byte, H(.) represents the hash operation, IP_src is the IP address of the node generating the verification code, and M takes 64 bits.
[0026] Further, the format of the data packet header for verification is: (flag, key_no, IP_gate, IP_src, H, M), where flag indicates that this is a packet header that needs to be verified by logically adjacent nodes (gateway node or terminal, proxy routing node), key_no indicates the key number, IP_gate indicates the gateway address, IP_src indicates the IP address for generating the verification code (32-bit number in the IPv6 network), H is the hash generated according to the data packet header and part of the payload, and M is the verification code.
[0027] A storage medium stores a computer program internally. When the computer program is read by a processor, it executes the packet verification method described in any one of the above.
[0028] The advantages and beneficial effects of the present invention are as follows:
[0029] The present invention preferably solves the problem of data packet security verification in satellite Internet, can more effectively ensure the security of the data packet transmission process, and realizes traceable communication.
[0030] (1) Verify the verification code of each packet at the network layer through the gateway to ensure filtering of external malicious traffic;
[0031] (2) Based on the statistics of malicious and normal traffic after data packet verification, ensure that the gateway takes reasonable measures for protection when the traffic exceeds the threshold range (specific measures do not belong to the protection points of this invention patent).
[0032] The innovation points of the present invention are mainly reflected in the following steps, as well as the effects and reasons that are not easily thought of brought by these steps:
[0033] Innovation Step 1: Combination of key management and verification code calculation
[0034] - Effect: By establishing a dynamic symmetric key management mechanism among the gateway, terminal and proxy routing node, and generating a verification code in combination with this key, fine-grained security verification can be realized for data packets at the network layer. This can not only effectively filter external malicious traffic, but also strictly manage internal traffic to ensure the source and authenticity of data packets.
[0035] - Reason not easily thought of: Traditional security verification mostly focuses on the access layer or application layer, and the security mechanisms at the network layer are less considered. Introducing key management and verification code calculation into the network layer and making it dynamically adapt to the characteristics of satellite Internet requires in-depth understanding and innovative thinking of the network architecture and security mechanisms.
[0036] Innovation Step 2: Generation and verification method of verification code
[0037] - Effect: Generate a verification code using a specific formula and verify it at the network layer, which can ensure the security of data packets during the transmission process. The 64-bit verification code length and the use of specific fields in the packet header make the verification process both accurate and efficient.
[0038] - Reason not easily thought of: In satellite Internet, resources are limited, and the computing and communication overheads need to be strictly controlled. Designing a verification code generation and verification mechanism that is both secure and can reduce overheads requires finding a balance between security and resource consumption, which is usually not easily directly thought of.
[0039] Innovation Step 3: Introduction of the Statistical Module
[0040] - Effect: The statistical module can not only record the communication situations between different nodes, but also issue warnings in a timely manner when the abnormal traffic exceeds the threshold, helping the administrator to take measures to prevent potential attacks.
[0041] - Reason for being not easily thought of: In security verification, the combination of statistical and traffic control mechanisms is not common. Combining the statistical module with the verification mechanism requires in-depth understanding and analysis of network traffic, as well as the design of a fast response mechanism for abnormal traffic, which is challenging both technically and in implementation.
[0042] Innovation Step 4: Intelligent Filtering and Data Recovery of the Gateway Node
[0043] - Effect: The gateway node is not only a verification point for data grouping, but can also intelligently filter malicious traffic according to the verification results, and at the same time restore the data packets with successful verification to the normal IP format, ensuring the efficiency and security of data transmission.
[0044] - Reason for being not easily thought of: In the specific scenario of satellite Internet, it is required that the gateway node has highly intelligent filtering and recovery functions. It is necessary to ensure security while avoiding data loss and transmission delay. This design idea not only requires a profound understanding of network protocols, but also an accurate grasp of the particularity of satellite communication, so it is not easily thought of directly.
[0045] In summary, the innovation points of the present invention lie in the combination of dynamic symmetric key management, verification code verification at the network layer and statistical monitoring mechanism, and a set of efficient and secure data packet verification scheme is designed for the special requirements of satellite Internet. These innovation points are difficult and challenging in technical implementation, so they are not easily thought of directly. Brief Description of the Drawings
[0046] Figure 1 is a schematic connection diagram of a satellite Internet gateway (deployable on the satellite or on the ground), sub-router nodes, terminals and proxy router nodes provided by the present invention;
[0047] Figure 2 is a schematic diagram of the node modules of the gateway and terminals (proxy router nodes);
[0048] Figure 3 is the processing flow of sending and receiving traffic;
[0049] Figure 4 is a schematic diagram of the newly added packet header. Detailed Embodiments
[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and detailedly described in conjunction with the accompanying drawings in the embodiments of the present invention. The described embodiments are only a part of the embodiments of the present invention.
[0051] The technical solution for the present invention to solve the above technical problems is as follows:
[0052] The method of the present invention includes: The satellite Internet includes multiple gateways (the gateways can be deployed on the ground or on the satellite), each gateway is a top-level routing node, and there are multiple levels of sub-routing nodes under each gateway. The sub-routing nodes are connected to terminals or proxy routing nodes from outside the satellite Internet (as Figure 1 shown). The gateways, terminals, and proxy routing nodes include a key module, a verification module, and a statistics module (as Figure 2 shown). The sub-routing nodes only have the routing forwarding function of ordinary nodes. For the data packets sent from the terminal (proxy routing node) to the satellite Internet, each terminal (proxy routing node) adds a verification code to the data packets it sends based on the gateway (logical connection) connected to it. Each gateway verifies the verification code. After successful verification, the gateway deletes the verification code, restores it to a normal IP data packet, and transmits the data packet to the satellite Internet. After failure, the data packet is filtered; the statistics module counts the number of data packets between nodes. For the data packets from the satellite Internet, the gateway adds a verification code, and the terminal (proxy routing node) verifies it. The verification process is the same as the verification process of the data packets sent to the satellite Internet. After successful verification by the proxy routing node, the verification code is deleted, and it is restored to a normal IP data packet. The processing flow of each node is as Figure 3 shown.
[0053] To achieve the purpose of the present invention, the technical solutions adopted include the following steps:
[0054] Step 1, the satellite Internet has one or more gateways, each gateway is connected to one or more sub-routing nodes, each sub-routing node can be connected to sub-routing nodes, terminals, and proxy routing nodes, and the proxy routing node is connected to the remaining nodes outside the satellite Internet. The gateways, terminals, and proxy routing nodes include a key module, a verification module, and a statistics module;
[0055] Configure a key module in the gateways, terminals, and proxy routing nodes to implement symmetric key management between nodes and logically adjacent nodes. That is, a pairwise negotiation method is adopted between the terminal (proxy routing node) and the gateway to maintain a dynamic symmetric key;
[0056] Configure a verification module in the terminals and proxy routing nodes to implement operations such as key acquisition, verification code calculation, data packet filtering, and verification code update;
[0057] Configure a statistics module in the terminals and proxy routing nodes to implement operations such as traffic negotiation and statistics between nodes.
[0058] The sub - routing node implements the packet forwarding function and can adopt protection methods such as SAVI, which is not within the scope of this patent protection; the proxy - routing node can be connected to traditional Internet terminals. The proxy - routing node is a sub - routing node of the satellite Internet and is compatible with un - updated satellite Internet terminals. The authentication method between the proxy - routing node and the terminal is not within the scope of this patent protection.
[0059] Step 2, the terminal (proxy - routing node) calculates the verification code according to the symmetric key of the network gateway node logically connected to it, initializes the data packet header as shown in Figure 4 below, including the key number, the verification code generated for the network gateway node, and the hash value calculated based on the packet header and part of the payload, and sends the data packet to the neighbor node;
[0060] The verification code is generated using the following formula:
[0061] M = MAC key (H(PH)||key_no||IP_src) (1)
[0062] where MAC key (.) is used to calculate the verification code through the key key, and can adopt forms such as AES, CRC, etc., which is not limited in this application. H(PH) is the hash generated from the data packet header and part of the payload (in this application, the data packet header takes the header of the IP packet except TTL, and the payload takes the first byte). H(.) represents the hash operation. IP_src is the IP address of the node generating the verification code. M takes 64 bits in this application.
[0063] The sub - routing node is responsible for forwarding data packets.
[0064] Step 3, after receiving the data packets from the terminal and the proxy - routing node, the network gateway node first determines whether the gateway address IP_gate in the data packet header is consistent with its own gateway address. If not, it filters the data packet; if it is consistent, it completes the verification code calculation and data packet filtering according to the symmetric key with the terminal and the proxy - routing node;
[0065] The verification code is calculated according to formula (1), the HASH, IP_src, and key_no in the packet header, and the key key obtained according to IP_src and key_no, to obtain a new verification code M'. Then, M' is compared with M. If M = M', the verification is successful; otherwise, the verification fails;
[0066] The statistics module sets two counters for each neighbor node in the control plane; separately counts the successful and failed packet counts; after successful verification, records the successful packet counter C1_fi from this node in the statistics module; after verification fails, filters this data packet and records the failed packet counter C2_fi from this node in the statistics module.
[0067] Step 4, before the gateway node forwards the successfully verified data packet, deletes the newly added data packet header and forwards the data in the form of a normal IP data packet.
[0068] Step 5, receiving process: when the gateway node receives a data packet from a satellite node, calculates the verification code using the key of the proxy routing node or terminal node logically connected, adds a data packet header as shown in Figure 4 and sends it to the proxy routing node or terminal node logically connected; the sub-routing node forwards the packet normally;
[0069] Adding the packet header as shown in Figure 4 The verification code generation process uses formula (1).
[0070] Step 6, after the proxy routing node and the terminal node receive the data packet, calculate the verification code according to the data packet header information, verify the data packet. After successful verification, transmit this data packet and increment the successful packet counter C1_fi count in the statistics module; after verification fails, filter this data packet and record the failed packet counter C2_fi from this node in the statistics module;
[0071] The verification code generation, verification, and the operations of the statistics module are the same as in Step 3.
[0072] Step 7, after the proxy routing node successfully verifies the received data packet, removes the added data packet header and restores it to a normal IP data packet for transmission.
[0073] Step 8, at regular time intervals TI, the proxy routing node (terminal node) negotiates the upper limit thresholds Th_C1_fi and Th_C2_fi of the data packets with the logically connected gateway node. When exceeding this threshold, sends a warning message to this neighbor node, and the administrator makes corresponding handling according to the warning message. This handling is not within the scope of protection of this patent.
[0074] The following describes two specific embodiments for illustration, aiming to show the actual application methods and effects of the present invention in satellite Internet:
[0075] Embodiment 1: Verification of data packet transmission in satellite Internet
[0076] Scenario setting
[0077] - Assume a satellite Internet system that includes a ground gateway GW1 and multiple sub-routing nodes S1, S2, S3, connecting the terminal node T1 and the proxy routing node AR1.
[0078] - The terminal node T1 and the proxy routing node AR1 are respectively connected to traditional Internet nodes and need to send data packets to the satellite Internet.
[0079] Implementation steps
[0080] 1. Key configuration and management: Configure key modules on GW1, T1, and AR1 to implement the negotiation and management of dynamic symmetric keys. T1 and GW1, AR1 and GW1 maintain their respective dynamic symmetric keys through pairwise negotiation.
[0081] 2. Data packet sending and verification: When T1 or AR1 wants to send a data packet to the satellite Internet, they calculate the verification code M according to the dynamic symmetric key with GW1 and add M to the data packet header to form a new data packet. The data packet is forwarded through S1, S2, S3 to GW1.
[0082] 3. Gateway verification and filtering: After receiving the data packet, GW1 recalculates the verification code M' according to the dynamic symmetric key with T1 or AR1. If M is consistent with M', the verification is successful. GW1 deletes the verification code M and related header information, restores the data packet to a normal IP data packet, and then forwards it to the satellite network. If M is not consistent with M', the verification fails, and GW1 filters the data packet without any forwarding.
[0083] 4. Traffic statistics and anomaly detection: The statistical module of GW1 records the verification results of each data packet from T1 and AR1, including the success counter C1_fi and the failure counter C2_fi. If within a certain time interval TI, C2_fi exceeds the negotiated threshold Th_C2_fi, GW1 will send a warning message to T1 or AR1, and the latter can perform corresponding security checks or adjust the sending strategy according to the warning message.
[0084] Implementation effects
[0085] - Example 1 shows the application of the present invention in data packet sending verification, effectively preventing the intrusion of malicious external traffic. At the same time, through dynamic key update and verification code calculation, the security and efficiency of data packet verification are improved.
[0086] - Through the intelligent filtering of the gateway node, the consumption of satellite resources by invalid or malicious data packets is reduced, and the communication quality and security of the satellite Internet are improved.
[0087] - The application of the statistical module enables the gateway node to detect and respond to potential attacks or abnormal traffic in a timely manner, enhancing the overall defense capability of the system.
[0088] Embodiment 2: Verification of Data Packet Reception in Satellite Internet
[0089] Scenario Setting
[0090] - In this embodiment, a satellite Internet system is also used, including GW1, S1, S2, S3, T1, and AR1.
[0091] - The data packet is sent from the satellite network node SN1 to GW1, and then forwarded by GW1 to T1 or AR1.
[0092] Implementation Steps
[0093] 1. Receiving Data Packet and Generating Verification Code: SN1 sends a data packet to GW1. GW1 calculates the verification code M according to the dynamic symmetric key of the logically connected T1 or AR1, adds it to the data packet header, and then forwards it to T1 or AR1.
[0094] 2. Verification by Terminal or Proxy Routing Node: After receiving the data packet, T1 or AR1 recalculates the verification code M' using the dynamic symmetric key with GW1 and compares it with M. If M is consistent with M', the verification is successful, and T1 or AR1 deletes the verification code and related header information, restoring the data packet to a normal IP data packet; if M is inconsistent with M', the verification fails, and T1 or AR1 filters the data packet.
[0095] 3. Traffic Statistics and Anomaly Detection: The statistical modules of T1 and AR1 record the verification results of the data packets received from GW1. If within the TI time, the failure counter C2_fi exceeds the negotiated threshold Th_C2_fi, T1 or AR1 will send a warning message to GW1, indicating that there may be an anomaly or attack, and GW1 can take corresponding security measures accordingly.
[0096] Implementation Effects
[0097] - Embodiment 2 demonstrates the application of the present invention in data packet reception verification, ensuring the security of data transmission from the satellite network to the ground terminal.
[0098] - By verifying data packets at the receiving end, it is possible to further detect and prevent the spread of internal malicious traffic, improving the overall security of the satellite Internet.
[0099] - The two-way application of the statistical module is not only effective in monitoring abnormal traffic at the sending end but also at the receiving end, enhancing the robustness and self-adaptability of the entire system.
[0100] Through these two specific embodiments, we can clearly see the specific applications and effects of the present invention in the aspects of network layer data packet verification, filtering, and statistical mechanisms, as well as how to improve the security and efficiency of data transmission in the special scenario of satellite Internet.
[0101] The points that the present invention intends to protect are:
[0102] (1) Set up key, verification, and statistical modules at the satellite Internet gateway, terminal, and proxy routing node;
[0103] (2) Between the gateway and the logically connected terminal nodes (proxy routing nodes), based on the verification code, implement packet-level verification and malicious packet filtering at the network layer;
[0104] The gateway, terminal, and proxy routing node count the number of successful and failed packets, and based on the statistical figures, send an alarm message when the negotiated threshold between nodes is exceeded.
[0105] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions.
[0106] Computer-readable media includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD), or other optical storage, magnetic cassette tapes, magnetic disk storage, or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0107] It should also be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity, or device comprising a series of elements not only includes those elements but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, commodity, or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, commodity, or device comprising the element.
[0108] The above embodiments should be understood as only illustrative of the present invention and not limiting the scope of protection of the present invention. After reading the content described in the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent changes and modifications also fall within the scope defined by the claims of the present invention.
Claims
1. A satellite Internet data packet verification device, wherein the satellite Internet includes multiple gateways, each gateway is a top-level routing node, and each gateway has multiple levels of sub-routing nodes below it. The sub-routing nodes are connected to terminals or proxy routing nodes from outside the satellite Internet. The sub-routing nodes only have the routing forwarding function of ordinary nodes, characterized in that: The gateway, terminal and proxy routing node are all configured with a key module to implement symmetric key management of nodes and logically adjacent nodes; that is, the terminal or proxy routing node and the gateway adopt a two-to-two negotiation method to maintain a dynamic symmetric key; the terminal and proxy routing node are also configured with a verification module to implement key acquisition, verification code calculation, data packet filtering, and verification code update operations; the terminal and proxy routing node are also configured with a statistical module to implement traffic negotiation and statistical operations between nodes; For data packets sent from a terminal or proxy routing node to the satellite Internet, each terminal or proxy routing node adds a verification code to the data packet sent by itself based on the gateway connected to it, and each gateway verifies the verification code. After successful verification, the gateway deletes the verification code, restores to a normal IP data packet, and transmits the data packet to the satellite Internet. After failure, the data packet is filtered; The statistics module counts the number of data packets between each node; The data packets from the satellite Internet are added with a verification code by the gateway and verified by the terminal or proxy routing node. The verification process is the same as the verification process for data packets sent to the satellite Internet. After the proxy routing node successfully verifies, the verification code is deleted and the data packets are restored to normal IP data packets.
2. A satellite Internet data packet verification device according to claim 1, characterized in that: The terminal or proxy routing node calculates the verification code based on the symmetric key of the logically connected gateway node, including the key number and the verification code generated for the gateway node, calculates the hash value based on the packet header and part of the load, uses CRC32 as the hash operation method, and sends the data packet to the neighboring node.
3. A satellite Internet data packet verification device according to claim 2, characterized in that: The verification code is generated using the following formula: M=MAC key (H(PH)||key_no||IP_src) (1) MAC key (.) is the verification code calculation using the key key, H(PH) is the hash generated by the data packet header and part of the payload, the data packet header is the IP packet header except TTL, the payload is the first byte, H(.) represents the hash operation, CRC32 is used as the hash operation method, IP_src is the IP address of the node that generates the verification code, and M is 64 bits.
4. A satellite Internet data packet verification device according to claim 3, characterized in that: After the gateway node receives the data packet from the terminal and the proxy routing node, it first determines whether the gateway address IP_gate in the data packet header is consistent with the local gateway address. If not, the data packet is filtered; if consistent, the verification code is calculated and the data packet is filtered according to the symmetric key with the terminal and the proxy routing node; after the verification code is calculated, a new verification code M' is obtained according to the packet header HASH, IP_src and key_no, and the key key obtained according to IP_src and key_no, and M' is compared with M. If M=M', the verification is successful, otherwise the verification fails.
5. A satellite Internet data packet verification device according to claim 3, characterized in that: The statistical module sets two counters for each neighbor node on the control plane; counts the successful and failed packet counts respectively; after successful verification, records the successful packet counter C1_fi from the node in the statistical module; after failed verification, filters the data packet, and records the failed packet counter C2_fi from the node in the statistical module.
6. A group verification method based on the device according to any one of claims 1 to 5, characterized in that: The following steps are involved: Step 1: The satellite Internet has one or more gateways, each gateway is connected to one or more sub-routing nodes, each sub-routing node can be connected to a sub-routing node, a terminal, and a proxy routing node, and the proxy routing node is connected to the remaining nodes outside the satellite Internet; the sub-routing node implements a packet forwarding function, the proxy routing node can be connected to a traditional Internet terminal, and the proxy routing node is a satellite Internet sub-routing node, which is compatible with unupdated satellite Internet terminals; Step 2, the terminal or proxy routing node calculates the verification code based on the symmetric key of the logically connected gateway node, initializes the data packet header, including the key number, and the verification code generated for the gateway node, the hash value calculated based on the packet header and part of the load, and sends the data packet to the neighboring node; the child routing node is responsible for forwarding the data packet. Step 3: After receiving the data packet from the terminal and the proxy routing node, the gateway node first determines whether the gateway address IP_gate in the data packet header is consistent with the local gateway address. If not, the data packet is filtered; if consistent, the verification code is calculated and the data packet is filtered according to the symmetric key with the terminal and the proxy routing node; Step 4: Before forwarding the successfully verified data packet, the gateway node deletes the newly added data packet header and implements data forwarding with normal IP data packets. Step 5, receiving process, the gateway node receives the data packet from the satellite node, calculates the verification code using the key of the logically connected proxy routing node or terminal node, adds a data packet header to the data packet, and sends it to the logically connected proxy routing node or terminal node; The sub-routing node forwards packets normally; Step 6, after receiving the data packet, the proxy routing node and the terminal node calculate the verification code according to the header information of the data packet, verify the data packet, transmit the data packet after successful verification, and increase the successful packet counter C1_fi in the statistical module; after verification fails, filter the data packet, and record the failed packet counter C2_fi from the node in the statistical module; Step 7, the proxy routing node removes the added data packet header after successful verification of the received data packet, and restores it to a normal IP data packet for transmission; Step 8: At a certain time interval TI, the proxy routing node or terminal node negotiates with the logically connected gateway node the upper threshold Th_C1_fi and Th_C2_fi of the data packet. When the threshold is exceeded, a warning message is sent to the neighboring node, and the administrator takes corresponding measures based on the warning message.
7. The group verification method according to claim 6, characterized in that: The verification code in step 2 is generated using the following formula: M=MAC key (H(PH)||key_no||IP_src) (1) MAC key (.) is the verification code calculation using the key key, H(PH) is the hash generated by the data packet header and part of the payload, the data packet header is the IP packet header except TTL, the payload is the first byte, H(.) represents the hash operation, IP_src is the IP address of the node that generates the verification code, and M is 64 bits.
8. The group verification method according to claim 6, characterized in that: The format of the data packet header used for verification is: (flag, key_no, IP_gate, IP_src, H, M), where flag indicates that this is a packet header that needs to be verified by the neighboring node, key_no indicates the key number, IP_gate indicates the gateway address, IP_src indicates the IP address for making the verification code (a 32-bit number in the IPv6 network), H is the hash generated based on the data packet header and part of the payload, and M is the verification code.
9. A storage medium storing a computer program, characterized in that: When the computer program is read by a processor, the group verification method described in any one of claims 6 to 8 is executed.