Measurement, operation and control cooperative management method and device and communication equipment

By realizing the coordinated management of the on-satellite control module in the satellite measurement and operation control system, and switching states in response to effective switching instructions, the risk of being attacked and exploited when working abnormally is solved, and the reliability and security of the system are improved.

CN120200648APending Publication Date: 2025-06-24TSINGHUA UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510314171.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, when the satellite measurement and operation control system works abnormally in a dense state, there is a risk of being exploited by the attacker, so that the attacker can turn the satellite in a dense state that works normally into a clear state, resulting in the measurement and operation control system being exposed to an unencrypted environment, seriously threatening the security of the spacecraft information.

Method used

A collaborative management method for measuring, operation and control is provided. When the first star control module is in an abnormal state, it responds to an effective switching command sent from the second star control module or the first ground control module corresponding to the first star control module, and responds based on the effective switching command to switch the state of the first star control module, so that when an abnormality occurs on the star control module, it can independently restore to a controllable state through the effective switching command.

Benefits of technology

By collaborating on the first satellite control module and the second satellite control module, when one of the parties has an abnormality, the other party can assist it in restoring it to a clear state. When both the first satellite control module and the second satellite control module are in an abnormality, it can independently recover to a clear state, improving the reliability and security of the satellite measurement and operation control system and ensuring the safe operation and maintenance of high-value space assets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200648A_ABST
    Figure CN120200648A_ABST
Patent Text Reader

Abstract

The invention relates to a test, operation and control cooperative management method and device and communication equipment. The method is applied to the field of measurement and control of various spacecrafts. The method comprises the steps of responding to an effective switching instruction; based on the effective switching instruction, the state of the first on-satellite management and control module is switched, and the state comprises a bright state or a secret state; the effective switching instruction is sent by at least one of the second on-satellite management and control module, a first on-satellite encryption and decryption unit in the first on-satellite management and control module and a first ground management and control module corresponding to the first on-satellite management and control module when the first on-satellite management and control module is in an abnormal state. A multi-recovery mechanism of inter-module cooperative control, intra-module autonomous detection and satellite-ground emergency intervention is constructed, so that the first on-satellite management and control module can be converted into a bright state from an abnormal secret state under the control of the second on-satellite management and control module, the first on-satellite management and control module and the first ground management and control module, and the reliability and the safety of the detection, operation and control system are improved; and safe operation and maintenance of high-value space assets are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of satellite measurement, operation, and control security, and particularly to a collaborative management method, device, and communication equipment for measurement, operation, and control. Background Art

[0002] During the on-orbit operation of a satellite in space, the ground measurement and control module and the operation and control module respectively interact with the satellite platform and payload for telemetry and telecommand data through two independent wireless links for measurement and control and operation and control. Due to the extremely high cost of space assets and the significant security threats of telemetry eavesdropping and telecommand spoofing caused by the open nature of wireless links, it is essential to adopt a secure measurement, operation, and control management method. Different from the ground encryption and decryption module, the on-board encryption and decryption module is affected by the harsh space environment (such as high-energy particle irradiation, extreme temperature changes, etc.), and the probability of anomalies increases significantly. At the same time, once a failure occurs in the on-board module, it cannot be remotely repaired, resulting in the serious risk that telemetry data cannot be parsed and telecommand instructions cannot be responded to.

[0003] In related technologies, in order to ensure the reliability of the measurement, operation, and control system, a secure exit (switch to the clear state) mechanism for satellites with abnormal secure operation (that is, the measurement, operation, and control system of the satellite is in the secure state while the encryption and decryption module fails) is proposed. However, related technologies have the risk of being exploited by attackers, enabling attackers to switch a satellite with normal secure operation to the clear state, resulting in the measurement, operation, and control system operating in an unencrypted environment, seriously threatening the information security of spacecraft. Summary of the Invention

[0004] Based on this, it is necessary to provide a collaborative management method, device, and communication equipment for measurement, operation, and control that can balance security and reliability in view of the above technical problems.

[0005] In a first aspect, the present application provides a collaborative management method for measurement, operation, and control, which is applied to a first on-board clear / secure state management unit in a first on-board management module in a satellite system. The satellite system further includes a second on-board management module, including:

[0006] Receiving a switching instruction;

[0007] Determining whether the switching instruction is valid;

[0008] If the switching instruction is a valid switching instruction, then in response to the valid switching instruction, based on the valid switching instruction, switch the state of the first on-board management module, where the state includes the clear state or the secure state; the valid switching instruction is sent by at least one of the second on-board management module, the first on-board encryption and decryption unit in the first on-board management module, and the first ground management module corresponding to the first on-board management module when the first on-board management module is in an abnormal state.

[0009] In one embodiment, the response valid switching instruction includes:

[0010] Responding to the valid switching instruction sent by the second on - satellite management and control module, where the valid switching instruction is generated by the second on - satellite management and control module based on the received first switching instruction that meets the preset security conditions, and the first switching instruction is sent by the second ground management and control module corresponding to the second on - satellite management and control module after receiving the first abnormal prompt information; the first abnormal prompt information is sent by the first ground management and control module to the second ground management and control module after detecting the first abnormal signal of the first on - satellite encryption and decryption unit.

[0011] In one embodiment, the second on - satellite management and control module includes a second on - satellite encryption and decryption unit, and the method further includes:

[0012] Receiving a second switching instruction sent by the first ground management and control module, where the second switching instruction is sent by the first ground management and control module after receiving the second abnormal prompt information, and the second abnormal prompt information is sent by the second ground management and control module corresponding to the second on - satellite management and control module to the first ground management and control module after detecting the second abnormal signal of the second on - satellite encryption and decryption unit;

[0013] When the second switching instruction meets the preset security conditions, determining the second switching instruction as the valid switching instruction, and sending the valid switching instruction to the second on - satellite management and control module, so that the second on - satellite management and control module switches the state of the second on - satellite management and control module based on the valid switching instruction.

[0014] In one embodiment, the first on - satellite management and control module is an on - satellite measurement and control management and control module, and the first on - satellite clear - and - secret state management unit is a measurement and control clear - and - secret state management unit. If the switching instruction is a valid switching instruction, then responding to the valid switching instruction and switching the state of the first on - satellite management and control module based on the valid switching instruction includes:

[0015] If the delayed switching instruction meets the preset delay condition, then determining the delayed switching instruction as the valid switching instruction, where the delayed switching instruction is sent by the ground measurement and control module corresponding to the on - satellite measurement and control management and control module to the measurement and control clear - and - secret state management unit when the on - satellite measurement and control management and control module is in the secret state;

[0016] If the duration of receiving the valid switching instruction meets the delay time of the delayed switching instruction, then responding to the valid switching instruction and switching the state of the on - satellite measurement and control management and control module from the secret state to the clear state based on the valid switching instruction.

[0017] In one embodiment, the method further includes:

[0018] Determine the valid time range of the delayed handover instruction based on the reception time of the delayed handover instruction, the delay time of the delayed handover instruction, and the maximum system response time;

[0019] If the delay time is greater than a preset window threshold and the valid time range of the delayed handover instruction is within a preset measurement and control arc segment, it is determined that the delayed handover instruction meets the preset delay condition.

[0020] In one embodiment, the method further includes:

[0021] Send encrypted telemetry information to the first ground control module based on the delayed handover instruction, so that the first ground control module determines whether the delayed handover instruction meets the legal conditions based on the encrypted telemetry information, and sends an encrypted revocation instruction to the measurement and control encryption and decryption state management unit when the legal conditions are not met;

[0022] Receive the encrypted revocation instruction and interrupt the response to the delayed handover instruction based on the encrypted revocation instruction.

[0023] In one embodiment, the method further includes;

[0024] If no valid control instruction is received within a preset duration, switch the state of the first on-board control module from encrypted state to clear state, where the valid control instruction is a control instruction sent by the first ground control module corresponding to the first on-board encryption and decryption state management unit to the first on-board encryption and decryption state management unit.

[0025] In one embodiment, the responding to the valid handover instruction and switching the state of the first on-board control module based on the valid handover instruction includes:

[0026] If a third abnormal signal of the first on-board encryption and decryption unit of the first on-board control module is received, determine the third abnormal signal as a valid handover instruction, and switch the state of the first on-board control module from encrypted state to clear state based on the valid handover instruction.

[0027] In a second aspect, the present application further provides a measurement, operation, and control collaborative management device, which is applied to the first on-board encryption and decryption state management unit. The first on-board encryption and decryption state management unit is in the first on-board control module included in the satellite system, and the satellite system further includes a second on-board control module. The device includes:

[0028] A receiving module, configured to receive a handover instruction;

[0029] A judgment module, configured to judge whether the handover instruction is valid;

[0030] A switching module, configured to, if the switching instruction is a valid switching instruction, respond to the valid switching instruction and switch the state of the first on-board management and control module based on the valid switching instruction, where the state includes a clear state or a secret state; the valid switching instruction is sent by at least one of the second on-board management and control module, the first encryption / decryption unit in the first on-board management and control module, and the first ground management and control module corresponding to the first on-board management and control module when the first encryption / decryption unit in the first on-board management and control module is in an abnormal state.

[0031] In a third aspect, the present application further provides a communication device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0032] Receive a switching instruction;

[0033] Determine whether the switching instruction is valid;

[0034] If the switching instruction is a valid switching instruction, respond to the valid switching instruction and switch the state of the first on-board management and control module based on the valid switching instruction, where the state includes a clear state or a secret state; the valid switching instruction is sent by at least one of the second on-board management and control module, the first encryption / decryption unit in the first on-board management and control module, and the first ground management and control module corresponding to the first on-board management and control module when the first encryption / decryption unit in the first on-board management and control module is in an abnormal state.

[0035] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0036] Receive a switching instruction;

[0037] Determine whether the switching instruction is valid;

[0038] If the switching instruction is a valid switching instruction, respond to the valid switching instruction and switch the state of the first on-board management and control module based on the valid switching instruction, where the state includes a clear state or a secret state; the valid switching instruction is sent by at least one of the second on-board management and control module, the first encryption / decryption unit in the first on-board management and control module, and the first ground management and control module corresponding to the first on-board management and control module when the first encryption / decryption unit in the first on-board management and control module is in an abnormal state.

[0039] In a fifth aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0040] Receive a switching instruction;

[0041] Determine whether the switching instruction is valid;

[0042] If the switching instruction is a valid switching instruction, respond to the valid switching instruction, and based on the valid switching instruction, switch the state of the first on-board management and control module, where the state includes the clear state or the encrypted state; the valid switching instruction is sent by at least one of the second on-board management and control module, the first on-board encryption and decryption unit in the first on-board management and control module, and the first ground management and control module corresponding to the first on-board management and control module when the first on-board encryption and decryption unit in the first on-board management and control module is in an abnormal state.

[0043] The above measurement, operation and control collaborative management method, device and communication equipment, when the first on-board management and control module is in an abnormal state, respond to the valid switching instruction sent from the second on-board management and control module or the first ground management and control module corresponding to the first on-board management and control module, and respond based on the valid switching instruction to switch the state of the first on-board management and control module. Even when the on-board management and control module is abnormal, it can be independently restored to a controllable state through the valid switching instruction. By collaboratively managing the first on-board management and control module and the second on-board management and control module, when one of them is abnormal, the other can assist it to restore to the clear state, or when both the first on-board management and control module and the second on-board management and control module are in an abnormal state, it can be independently restored to the clear state, improving the reliability of the satellite measurement, operation and control system. By constructing a multiple recovery mechanism of inter-module collaborative control, intra-module autonomous detection, and space-ground emergency intervention, the first on-board management and control module can be switched from the abnormal encrypted state to the clear state under the control of the second on-board management and control module, the first on-board management and control module, and the first ground management and control module, improving the reliability and security of the measurement, operation and control system, and ensuring the safe operation and maintenance of high-value space assets. Description of the Drawings

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0045] Figure 1 It is a schematic structural diagram of a satellite system in an embodiment;

[0046] Figure 2 It is a schematic flowchart of a measurement, operation and control collaborative management method in an embodiment;

[0047] Figure 3 It is a schematic diagram of the collaborative relationship between the on-board measurement and control management and control module and the on-board operation and control management and control module in an embodiment;

[0048] Figure 4 Schematic diagram of the response mode of a satellite with abnormal operation in the encrypted state to a delayed switching instruction in an embodiment;

[0049] Figure 5 Schematic diagram of the response mode of a satellite with normal operation in the encrypted state to a delayed switching instruction in an embodiment;

[0050] Figure 6 Schematic diagram of the structure of a satellite system in an embodiment;

[0051] Figure 7 Schematic diagram of the on - satellite processing flow when measuring and controlling the clear and encrypted states in an embodiment;

[0052] Figure 8 Schematic diagram of the on - satellite processing flow of the operation and control clear and encrypted states in an embodiment;

[0053] Figure 9 Schematic diagram of the event tree analysis under the clear - to - encrypted mechanism of the measurement and control system in an embodiment;

[0054] Figure 10 Schematic diagram of the event tree analysis under the clear - to - encrypted mechanism of the operation and control system in an embodiment;

[0055] Figure 11 Block diagram of the structure of the measurement, operation, and control collaborative management device in an embodiment. Detailed implementation manners

[0056] In order to make the purpose, technical solutions, and advantages of this application clearer, the following further details this application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.

[0057] The measurement, operation, and control collaborative management method provided by the embodiments of this application can be applied to a satellite system as shown in Figure 1 , and this system at least includes: a first on - satellite management and control module, a second on - satellite management and control module, and a first ground management and control module corresponding to the first on - satellite management and control module. The first on - satellite management and control module at least includes a first on - satellite clear and encrypted state management unit and a first on - satellite encryption and decryption unit.

[0058] Among them, the first on - satellite management and control module can transmit information with the first ground management and control module and the second on - satellite management and control module through the first on - satellite clear and encrypted state management unit. Information can be transmitted between the first on - satellite clear and encrypted state management unit and the first on - satellite encryption and decryption unit in the first on - satellite management module. The first on - satellite clear and encrypted state management unit can perform state switching between the clear state and the encrypted state according to the received valid switching instruction.

[0059] For example, the first on-board control module can be an on-board TT&C control module or an on-board operation control module, and the second on-board control module can be an on-board TT&C control module or an on-board operation control module. When the first on-board control module is an on-board TT&C control module, the second on-board control module is an on-board operation control module; when the first on-board control module is an on-board operation control module, the second on-board control module is an on-board TT&C control module.

[0060] In an exemplary embodiment, as Figure 2 shown, Figure 2 a flowchart of a method for collaborative measurement, operation, and control management is provided. Taking the first on-board plaintext / ciphertext state management unit in the first on-board control module in Figure 1 as an example for illustration. Among them:

[0061] Step 201: Receive a switching instruction.

[0062] Specifically, the first on-board plaintext / ciphertext state management unit can receive the switching instruction sent by the first ground control module corresponding to the first on-board control module, can also receive the switching instruction sent by the second on-board control module, and can also receive the switching instruction sent by the first on-board encryption / decryption unit.

[0063] Step 202: Determine whether the switching instruction is valid.

[0064] Specifically, the first on-board plaintext / ciphertext state management unit can determine whether the received switching instruction is valid. When the first on-board plaintext / ciphertext state management unit receives the switching instruction sent by the first ground control module corresponding to the first on-board control module, the first on-board plaintext / ciphertext state management unit can determine whether the switching instruction is valid according to whether the switching instruction meets the preset delay condition. When the first on-board plaintext / ciphertext state management unit receives the switching instruction sent by the second on-board control module, the first on-board plaintext / ciphertext state management unit can determine whether the switching instruction is a valid instruction according to whether the switching instruction is sent by the second on-board control module. When the switching instruction received by the first on-board plaintext / ciphertext state management unit is sent by the first on-board encryption / decryption unit, the first on-board plaintext / ciphertext state management unit can determine whether the switching instruction is a valid instruction according to whether the switching instruction is an abnormal signal of the first on-board encryption / decryption unit.

[0065] Step 203: If the switching instruction is a valid switching instruction, then respond to the valid switching instruction and switch the state of the first on-board control module based on the valid switching instruction.

[0066] Among them, the first on-board control module can be an on-board TT&C control module or an on-board operation control module. The state of the valid switching instruction can be in a secret state or a clear state. The state of the first on-board control module can include a clear state or a secret state. The clear state can mean that the data transmitted between the satellite and the ground is sent in plaintext without encryption. The secret state can mean that the data transmitted between the satellite and the ground is encrypted and sent in ciphertext. The valid switching instruction is sent by the second on-board control module or the first ground control module corresponding to the first on-board control module when the first on-board control is in an abnormal state. The valid switching instruction is sent by at least one of the second on-board control module, the first on-board encryption / decryption unit in the first on-board control module, and the first ground control module corresponding to the first on-board control module when the first on-board control module is in an abnormal state.

[0067] Specifically, if the first on-board control module is an on-board TT&C control module, the first on-board clear / secret state management unit is a TT&C clear / secret state management unit, the first on-board encryption / decryption unit is a TT&C encryption / decryption unit, and the first ground control module can be a ground TT&C module. The TT&C clear / secret state management unit can respond to the valid switching instruction sent by the ground TT&C module corresponding to the on-board TT&C control module or the on-board operation control module, and can also respond to the abnormal signal sent by the on-board encryption / decryption unit in the on-board TT&C control module, and determine the abnormal signal as the valid switching instruction. The TT&C clear / secret state management unit can, based on the valid switching instruction, switch the state of the on-board TT&C control module from the clear state to the secret state or from the secret state to the clear state. The specific way of switching the state is related to the type of the valid switching instruction.

[0068] If the first on-board control module is an on-board operation control module, the first on-board clear / secret state management unit is an operation control clear / secret state management unit, the first on-board encryption / decryption unit is an operation control encryption / decryption unit, and the first ground control module can be a ground operation control module. The operation control clear / secret state management unit can respond to the valid switching instruction sent by the ground operation control module corresponding to the on-board operation control module or the on-board TT&C control module, and can also respond to the abnormal signal sent by the on-board security unit in the on-board operation control module, and determine the abnormal signal as the valid switching instruction. The operation control clear / secret state management unit can, based on the valid switching instruction, switch the state of the operation control module from the clear state to the secret state or from the secret state to the clear state. The specific way of switching the state is related to the type of the valid switching instruction.

[0069] The above measurement, operation, and control collaborative management method responds to a valid switching instruction sent from the second on-satellite control module or the first ground control module corresponding to the first on-satellite control module when the first on-satellite control module is in an abnormal state, and responds based on the valid switching instruction to switch the state of the first on-satellite control module. Even when the on-satellite control module is abnormal, it can be independently restored to a controllable state through the valid switching instruction. By collaboratively managing the first on-satellite control module and the second on-satellite control module, when one of them is abnormal, the other can assist it in restoring to the normal state, or when both the first on-satellite control module and the second on-satellite control module are abnormal, it can be independently restored to the normal state, improving the reliability of the satellite measurement, operation, and control system. Moreover, responding to the valid switching instruction can prevent attackers from switching the normal encrypted measurement, operation, and control to the normal state, ensuring the security of the satellite system and guaranteeing the secure operation and maintenance of high-value space assets.

[0070] In an exemplary embodiment, the specific implementation process of "responding to the valid switching instruction" in step 203 may include:

[0071] Responding to the valid switching instruction sent by the second on-satellite control module.

[0072] Wherein, the satellite system further includes a second on-satellite control module, and the first on-satellite control module includes a first on-satellite encryption / decryption unit; the valid switching instruction is generated by the second on-satellite control module based on the received first switching instruction that meets the preset security conditions, and the first switching instruction is sent by the second ground control module corresponding to the second on-satellite control module after receiving the first abnormal prompt information; the first abnormal prompt information is sent by the first ground control module corresponding to the first on-satellite control module to the second ground control module after detecting the first abnormal signal of the first on-satellite encryption / decryption unit. The preset security conditions may be that the first switching instruction is sent by the second on-satellite control unit to the first on-satellite normal / encrypted state management unit, and the first switching instruction may be generated when the second on-satellite control module is in a normal encrypted operating state.

[0073] The first on-satellite control module may be an on-satellite measurement and control management module or an on-satellite operation and control management module, and the second on-satellite control module may be an on-satellite measurement and control management module or an on-satellite operation and control management module. When the first on-satellite control module is an on-satellite measurement and control management module, the second on-satellite control module is an on-satellite operation and control management module, and when the first on-satellite control module is an on-satellite operation and control management module, the second on-satellite control module is an on-satellite measurement and control management module.

[0074] Specifically, when the first on-board control module is the on-board TT&C control module and the second on-board control module is the on-board operation control module, when the first on-board encryption / decryption unit (TT&C encryption / decryption unit) of the on-board TT&C control module malfunctions and the TT&C plaintext / ciphertext state management unit of the on-board TT&C control module does not detect the malfunction of the TT&C encryption / decryption unit, at this time, the first ground control module (ground TT&C module) can determine that the on-board TT&C control module is in the ciphertext state based on the identifier of the received telemetry data, and determine the first abnormal signal of the TT&C encryption / decryption unit based on the telemetry data. The ground TT&C module can send the first abnormal signal as the first abnormal prompt message to the second ground control module (ground operation control module). The ground operation control module can send the first switching instruction to the on-board operation control module based on the first abnormal prompt message, and the on-board operation control module can verify the first switching instruction based on the preset safety conditions. If the first switching instruction meets the requirements of signal legality and the on-board operation control module is in the ciphertext state, it is determined that the first switching instruction is a valid switching instruction that meets the preset safety conditions and is sent to the on-board TT&C control module. The TT&C plaintext / ciphertext state management unit can respond to the valid switching instruction and switch the state of the on-board TT&C control module from the ciphertext state to the plaintext state based on the valid switching instruction.

[0075] When the first on-board control module is the on-board operation control module and the second on-board control module is the on-board TT&C control module, when the first on-board encryption / decryption unit (operation control encryption / decryption unit) of the on-board operation control module malfunctions and the operation control plaintext / ciphertext state management unit of the on-board operation control module does not detect the malfunction of the operation control encryption / decryption unit, at this time, the first ground control module (ground operation control module) can determine that the on-board operation control module is in the ciphertext state based on the identifier of the received telemetry data, and determine the first abnormal signal of the operation control encryption / decryption unit based on the telemetry data. If the on-board TT&C control module is in the ciphertext state, the ground operation control module can send the first abnormal signal as the first abnormal prompt message to the second ground control module (ground TT&C module). The ground TT&C module can send the first switching instruction to the on-board TT&C control module based on the first abnormal prompt message, and the on-board TT&C control module can verify the first switching instruction based on the preset safety conditions. If the first switching instruction meets the requirements of signal legality and the on-board operation control module is in the ciphertext state, it is determined that the first switching instruction is a valid switching instruction that meets the preset safety conditions and is sent to the on-board operation control module. The operation control plaintext / ciphertext state management unit can receive the valid switching instruction and switch the state of the on-board operation control module from the ciphertext state to the plaintext state based on the valid switching instruction.

[0076] Exemplarily, the first on-board clear-secret state management unit of the first on-board control module does not detect an abnormality in the first on-board encryption / decryption unit. However, the first ground control module can determine from the received telemetry data that the situation where the first on-board encryption / decryption unit has an abnormality can be that the heartbeat of the first on-board encryption / decryption unit is normal, but normal encryption / decryption cannot be achieved. For example, the first on-board encryption / decryption unit being in an abnormal situation but not being detected by the first on-board control module can include the following two cases. The first case can be that the first on-board encryption / decryption unit reads the key incorrectly, resulting in the first ground control module still using the original key for decryption, leading to inability to decrypt normally, while the heartbeat of the first on-board encryption / decryption unit is normal at this time. The second case may also be that the first on-board encryption / decryption unit is affected by a single particle during the decryption process. Although the key is correct, it cannot correctly decrypt the data, resulting in the legitimate remote control instruction being discarded by the platform integrated electronic computer, etc. Specific limitations are not made here.

[0077] In addition, the specific process for the second on-board control module to determine whether the received first switching instruction meets the preset security conditions can be as follows: Determine that the second on-board control unit is in the secret state. The second on-board clear-secret state management unit of the second on-board control module can send the first switching instruction to the second on-board encryption / decryption unit. The second on-board encryption / decryption unit can decrypt the first switching instruction according to the preset key to obtain the decrypted first switching instruction, and send the decrypted first switching instruction to the second on-board clear-secret state management unit. The second on-board clear-secret state management unit can determine whether the first switching instruction is a legitimate instruction. The second on-board clear-secret state management unit can determine whether the first switching instruction meets the preset security conditions according to whether the first switching instruction is a legitimate instruction. For example, if the first switching instruction is successfully decrypted, the second on-board encryption / decryption unit can determine that the first switching instruction is legitimate.

[0078] Exemplarily, when the first on-board control module is the on-board TT&C control module, the second on-board control module is the on-board operation control module, and the number of the effective switching instruction in this embodiment can be C-JZ3. When the first on-board control module is the on-board operation control module, the second on-board control module is the on-board TT&C control module, and the number of the effective switching instruction in this embodiment can be Y-JZ3.

[0079] As Figure 3 shown, Figure 3 is a schematic diagram of the cooperation relationship between the on-board TT&C control module and the on-board operation control module provided by an embodiment. The on-board TT&C and the on-board operation control can achieve the switching between the clear state and the secret state through cooperation.

[0080] In this embodiment, a clear-secret state switching mechanism is designed through the collaborative relationship among measurement, operation, and control, enabling the satellite system to effectively address security threats posed by attackers. Meanwhile, the impact of abnormal encryption and decryption functions on the satellite on system reliability is minimized, thereby enhancing the security and reliability of the system.

[0081] In an exemplary embodiment, the measurement, operation, and control collaborative management method further includes:

[0082] Receiving a second switching instruction sent by the first ground control module.

[0083] Among them, the second on-satellite control module includes a second on-satellite encryption and decryption unit. The second switching instruction is sent by the first ground control module after receiving the second abnormal prompt information, and the second abnormal prompt information is sent by the second ground control module to the first ground control module after detecting a second abnormal signal of the second on-satellite encryption and decryption unit; when the second switching instruction meets the preset security conditions, it is determined that the second switching instruction is a valid switching instruction, and the valid switching instruction is sent to the second on-satellite control module, so that the second on-satellite control module switches the state of the second on-satellite control module based on the valid switching instruction.

[0084] Specifically, when the first on-satellite control module is the on-satellite measurement and control module and the second on-satellite control module is the on-satellite operation and control module, when an abnormality occurs in the first on-satellite encryption and decryption unit (measurement and control encryption and decryption unit) of the on-satellite measurement and control module and the measurement and control clear-secret state management unit of the on-satellite measurement and control module does not detect the abnormality of the measurement and control encryption and decryption unit, at this time, the first ground control module (ground measurement and control module) can determine that the on-satellite measurement and control module is in the secret state according to the identifier of the received telemetry data, and determine the second abnormal signal of the measurement and control encryption and decryption unit according to the telemetry data. The ground measurement and control module can send the second abnormal signal as the second abnormal prompt information to the second ground control module (ground operation and control module). The ground operation and control module can send the second switching instruction to the on-satellite operation and control module based on the second abnormal prompt information. The on-satellite operation and control module can verify the second switching instruction based on the preset security conditions. If the second switching instruction meets the requirements of signal legality and the on-satellite operation and control module is in the secret state, it is determined that the second switching instruction that meets the preset security conditions is a valid switching instruction and sent to the on-satellite measurement and control module. The on-satellite measurement and control module can receive the valid switching instruction and switch the state of the on-satellite measurement and control module from the secret state to the clear state based on the valid switching instruction.

[0085] When the first on-board control module is the on-board operation and control management module and the second on-board control module is the on-board TT&C management module, when the encryption / decryption unit (operation and control encryption / decryption unit) on the first satellite of the on-board operation and control management module has an abnormality and the operation and control plaintext / ciphertext state management unit of the on-board operation and control management module does not detect the abnormality of the operation and control encryption / decryption unit, at this time, the first ground control module (ground operation and control module) can determine that the on-board operation and control management module is in the ciphertext state according to the identifier of the received telemetry data, and determine the second abnormal signal of the operation and control encryption / decryption unit according to the telemetry data. If the on-board TT&C management module is in the ciphertext state, the ground operation and control module can send the second abnormal signal to the second ground control module (ground TT&C module) as the second abnormal prompt information. The ground TT&C module can send the second switching instruction to the on-board TT&C management module based on the second abnormal prompt information, and the on-board TT&C management module can verify the second switching instruction based on the preset security conditions. If the second switching instruction meets the signal legality and the on-board operation and control management module is in the ciphertext state, it is determined that the second switching instruction is a valid switching instruction that meets the preset security conditions and sent to the on-board operation and control management module. The on-board operation and control management module can receive the valid switching instruction and switch the state of the operation and control management module in the on-board operation and control management module from the ciphertext state to the plaintext state based on the valid switching instruction.

[0086] In this embodiment, by designing the plaintext / ciphertext state switching mechanism through the cooperation relationship between TT&C and operation and control, the satellite system can effectively cope with the security threats brought by attackers, and at the same time minimize the impact of the abnormality of the on-board encryption / decryption function on the system reliability, thereby improving the security and reliability of the system.

[0087] In an exemplary embodiment, the specific implementation process of step 203 "If the switching instruction is a valid switching instruction, then respond to the valid switching instruction and switch the state of the first on-board control module based on the valid switching instruction" may include:

[0088] If the delayed switching instruction meets the preset delay condition, then determine the delayed switching instruction as a valid switching instruction; if the duration of receiving the valid switching instruction meets the delay time of the delayed switching instruction, then switch the state of the on-board TT&C management module from the ciphertext state to the plaintext state based on the valid switching instruction.

[0089] Among them, the first on-board control and management module is the on-board TT&C control and management module, and the on-board TT&C control and management module includes a TT&C clear / secret state management unit and a TT&C encryption / decryption unit. The first on-board clear / secret state management unit is the TT&C clear / secret state management unit. The delay switching instruction can be a delay-to-clear instruction, and this instruction can include the delay duration for the instruction to take effect. The preset delay condition can be that the delay duration meets the preset duration requirement, and the effective duration of this instruction is within the TT&C arc segment. The TT&C arc segment can be the time range when the ground TT&C module can observe the satellite during the satellite's on-orbit flight. The second on-board control and management module not being in the secret state can include the second on-board control and management module being in the clear state or in an abnormal state. The delay switching instruction is sent by the ground TT&C module corresponding to the on-board TT&C control and management module to the TT&C clear / secret state management unit when the on-board TT&C control and management module is in the secret state.

[0090] Specifically, when the on-board TT&C control and management module is in the secret state, the ground TT&C module can send a delay switching instruction to the on-board TT&C control and management module. The TT&C encryption / decryption management unit can receive the delay switching instruction sent by the ground TT&C module corresponding to the on-board TT&C control and management module. If the delay duration of this delay switching instruction meets the preset duration requirement and the effective duration of this instruction is within the TT&C arc segment, it is determined that this delay instruction meets the preset delay condition, and then this delay switching instruction is determined as a valid switching instruction; if the duration of receiving the valid switching instruction meets the delay time of the delay switching instruction, the state of the on-board TT&C control and management module in the on-board TT&C control and management module is switched from the secret state to the clear state based on the valid switching instruction.

[0091] In addition, when the on-board TT&C control and management module is in an abnormal secret state, the TT&C encryption / decryption unit is in an abnormal state, the TT&C clear / secret state management unit does not detect an abnormal state, and the second on-board control and management module is not in the secret state (abnormal secret state or clear state), the ground TT&C module can send a delay switching instruction to the on-board TT&C control and management module. The on-board TT&C control and management module can receive the delay switching instruction.

[0092] Figure 4 It is a schematic diagram of the response method of a satellite in an abnormal secret state operation provided by an embodiment to a delay switching instruction. In the figure, T0 is the moment when the delay switching instruction is received, and N is the delay duration specified by the delay switching instruction. T0 + N is the moment when the duration of receiving the valid switching instruction meets the delay time of the delay switching instruction.

[0093] The serial number of this valid switching instruction can be C-JZ4.

[0094] In this embodiment, when the measurement and control encryption / decryption unit is in an abnormal state, the measurement and control plaintext / ciphertext state management unit does not detect an abnormal state, and the second on-board control module is not in the ciphertext state, sending a delay switching instruction to the on-board measurement and control management module can make the abnormal ciphertext on-board measurement and control management module be controlled to turn plaintext, improving the reliability of the system.

[0095] In an exemplary embodiment, the measurement, operation, and control collaborative management method further includes:

[0096] Based on the reception time of the delay switching instruction, the delay time of the delay switching instruction, and the maximum system response time, determine the valid time range of the delay switching instruction; if the delay time is greater than a preset window threshold, and the valid time range of the delay switching instruction is within a preset measurement and control arc segment, it is determined that the delay switching instruction meets the preset delay condition.

[0097] Among them, the maximum system response time can be determined based on the maximum value of the minimum time required to judge the satellite state according to the telemetry measurement and the minimum time required to send key remote control instructions such as attitude and orbit control and thermal control.

[0098] Specifically, the on-board measurement and control management module can calculate the sum value of the reception time T0 of the delay switching instruction and the delay time N of the delay switching instruction, and calculate the sum value of the reception time T0 of the delay switching instruction, the delay time N of the delay switching instruction, and the maximum system response time W, and determine that the time range from T0 + N to T0 + N + W is the valid time range of the delay switching instruction. If the delay time N is greater than the preset window threshold M, and the valid time range of the delay switching instruction is within the preset measurement and control arc segment, the on-board measurement and control management module determines that the delay switching instruction meets the preset delay condition.

[0099] In addition, if the delay time N is less than or equal to the preset window threshold M, the on-board measurement and control management module does not respond to this delay switching instruction. If the valid time range of the delay switching instruction is not within the preset measurement and control arc segment, the on-board measurement and control management module maintains the ciphertext state and does not respond to this delay-to-plaintext instruction.

[0100] The on-board measurement and control management module can also send a status report (ciphertext telemetry data) to the ground measurement and control module, and the ground measurement and control module can determine the legality of the delay-to-plaintext instruction based on the status.

[0101] In this embodiment, by determining that the delay time N is greater than or equal to the preset window threshold M, and the valid time range of the delay switching instruction is within the preset measurement and control arc segment, it is determined that the delay time is valid, improving the reliability of the system.

[0102] In an exemplary embodiment, the measurement, operation, and control collaborative management method further includes:

[0103] Send encrypted telemetry information to the first ground control module based on the delay switching instruction, so that the first ground control module judges whether the delay switching instruction meets the legal conditions based on the encrypted telemetry information, and if it does not meet the legal conditions, send an encrypted revocation instruction to the TT&C cleartext and ciphertext management unit; receive the encrypted revocation instruction, and interrupt the response to the delay switching instruction based on the encrypted revocation instruction.

[0104] Among them, the encrypted telemetry information may include the status of the on-board TT&C control module.

[0105] Specifically, the TT&C cleartext and ciphertext management unit may send encrypted telemetry information to the ground TT&C module based on the delay switching instruction. The ground TT&C module may decrypt the encrypted telemetry information based on a preset key to obtain the telemetry information. The ground TT&C module may judge whether the telemetry information is sent by itself to the TT&C cleartext and ciphertext management unit. If the telemetry information is not sent by itself to the TT&C cleartext and ciphertext management unit, it is determined that the telemetry information does not meet the legal conditions, and an encrypted revocation instruction (encrypted remote control) is sent to the TT&C cleartext and ciphertext management unit and an alarm is triggered. The TT&C cleartext and ciphertext management unit may send the received encrypted revocation instruction to the TT&C encryption and decryption unit of the on-board TT&C control module. The TT&C encryption and decryption unit may decrypt the encrypted revocation instruction to obtain the revocation instruction. The TT&C cleartext and ciphertext management unit may interrupt the response to the delay switching instruction based on the revocation instruction.

[0106] At this time, the on-board TT&C control module may be in a normal state of encrypted operation.

[0107] Figure 5 It is a schematic diagram of the response method of a satellite in a normal state of encrypted operation to a delay switching instruction in an embodiment. The delay switching instruction may be sent by an attacker.

[0108] In this embodiment, the legality of the delay switching instruction is verified by the ground TT&C module to prevent attacks by attackers. Moreover, the switching instruction of the delay switching instruction is set with N≥M, which extends the reaction time of the ground TT&C module and improves the reliability of the system.

[0109] In an exemplary embodiment, the measurement, operation and control collaborative management method further includes;

[0110] If no valid control instruction is received within a preset duration, the state of the first on-board control module is switched from encrypted state to cleartext state.

[0111] Among them, the valid control instruction is a control instruction sent by the first ground control module corresponding to the first on-board control module to the first on-board cleartext and ciphertext management unit. For example, the control instruction may include attitude and orbit control instructions, mission execution instructions, navigation and telemetry instructions, etc. The preset duration is related to the period of the satellite orbit.

[0112] Specifically, the first satellite's plaintext and ciphertext state management unit can determine whether the received control instruction can be decrypted successfully by the first satellite's encryption and decryption unit. If the control instruction can be decrypted successfully, it is determined that the control instruction is legal and is an effective control instruction. The first satellite's plaintext and ciphertext state management unit can start timing from the moment when the previous effective control instruction was received. If the elapsed time is greater than or equal to the preset duration, it is determined that no effective control instruction has been received within the preset duration. For example, the preset duration can be 48 hours or 72 hours. If no effective control instruction is received within the preset duration, the state of the first satellite's control and management module is switched from the ciphertext state to the plaintext state.

[0113] The first satellite's control and management module can be the satellite's TT&C control and management module or the satellite's operation control and management module. When the first satellite's control and management module is the satellite's TT&C control and management module, the second satellite's control and management module is the satellite's operation control and management module; when the first satellite's control and management module is the satellite's operation control and management module, the second satellite's control and management module is the satellite's TT&C control and management module.

[0114] Exemplarily, when the first satellite's control and management module is the satellite's TT&C control and management module and the second satellite's control and management module is the satellite's operation control and management module, when the TT&C is in the ciphertext state, if the TT&C plaintext and ciphertext state management unit C1 does not receive any valid remote control instructions within the set time range (e.g., 48 hours, this time is related to the orbital period), then it automatically switches to the plaintext state. After the ground TT&C module C0 receives the telemetry, it knows from the plaintext and ciphertext flag that the TT&C has switched to the plaintext state, and subsequent remote controls will all use the plaintext state. The number of this instruction can be C-JZ5.

[0115] When the first satellite's control and management module is the satellite's operation control and management module and the second satellite's control and management module is the satellite's TT&C control and management module, when the operation control is in the ciphertext state, if the operation control plaintext and ciphertext state management unit Y1 does not receive any valid remote control instructions within the set time range (e.g., 72 hours, this time is related to the orbital period), then it automatically switches to the plaintext state. The number of this instruction can be Y-JZ5.

[0116] Moreover, to prevent attackers from exploiting this automatic switch to the plaintext instruction, when the TT&C (or operation control) is in the ciphertext state, the ground TT&C module (ground operation control module) needs to send remote control instructions regularly (this period needs to be less than the set time range) to reset the cumulative time record of the satellite's TT&C control and management module (satellite's operation control and management module) for no valid remote control instructions, so that the satellite's TT&C control and management module (satellite's operation control and management module) will not switch to the plaintext state.

[0117] In this embodiment, when the on-satellite TT&C control and management module or the on-satellite operation control and management module in the satellite system has not received a valid switching instruction for a long time, the on-satellite TT&C control and management module or the on-satellite operation control and management module can be switched from the encrypted state to the plaintext state, providing guarantee in case of system anomalies and improving the reliability and security of the system.

[0118] In an exemplary embodiment, the specific implementation process of step 203, "Respond to the valid switching instruction and switch the state of the first on-satellite control and management module based on the valid switching instruction", may include:

[0119] If the third abnormal signal of the first on-satellite encryption and decryption unit of the first on-satellite control and management module is received, the third abnormal signal is determined as the valid switching instruction, and the valid switching instruction is responded to, and based on the valid switching instruction, the state of the first on-satellite control and management module is switched from the encrypted state to the plaintext state.

[0120] Specifically, there is a heartbeat mechanism between the first on-satellite encryption and decryption unit and the first on-satellite plaintext and ciphertext management unit of the first on-satellite control and management module. The first on-satellite encryption and decryption unit detects its own state within a preset period and reports its own state value to the first on-satellite plaintext and ciphertext management unit in the form of a heartbeat at a certain period. When the first on-satellite plaintext and ciphertext management unit discovers that the state of the first on-satellite encryption and decryption unit is abnormal from the heartbeat information, the third abnormal signal is determined as the valid switching instruction, and based on the valid switching instruction, the state of the on-satellite control and management module is switched from the encrypted state to the plaintext state.

[0121] A test response mechanism is maintained between the first on-satellite encryption and decryption unit and the first on-satellite plaintext and ciphertext management unit. The first on-satellite plaintext and ciphertext management unit regularly initiates an encryption and decryption function test to the first on-satellite encryption and decryption unit, that is, the first on-satellite plaintext and ciphertext management unit sends a test plaintext (or ciphertext) with a known ciphertext (or plaintext) result. The first on-satellite encryption and decryption unit encrypts the test plaintext (or decrypts the test ciphertext) and returns the result to the first on-satellite plaintext and ciphertext management unit for verification. If it does not meet the expectation, it indicates that the current state of the first on-satellite encryption and decryption unit is abnormal, and the first on-satellite plaintext and ciphertext management unit will be switched from the encrypted state to the plaintext state.

[0122] Exemplarily, a heartbeat mechanism is maintained between the measurement and control encryption / decryption unit C2 and the measurement and control plaintext / ciphertext state management unit C1. C2 periodically detects its own state and reports the state to C1 in the form of a periodic heartbeat. When C1 discovers an abnormal state of C2 from the heartbeat information, it switches the measurement and control from the ciphertext state to the plaintext state. A test response mechanism is maintained between C2 and C1. C1 periodically initiates an encryption / decryption function test to C2, that is, C1 sends a test plaintext (or ciphertext) with a known ciphertext (or plaintext) result. C2 encrypts the test plaintext (or decrypts the test ciphertext) and returns the result to C1 for verification. If it does not meet the expectation, it indicates that the current state of C2 is abnormal, and C1 switches the measurement and control from the ciphertext state to the plaintext state. The number of this instruction can be C-JZ2.

[0123] A heartbeat mechanism is maintained between the operation control encryption / decryption unit Y2 and the operation control plaintext / ciphertext state management unit Y1. Y2 periodically detects its own state and reports the state to Y1 in the form of a periodic heartbeat. When Y1 discovers an abnormal state of Y2 from the heartbeat information, it switches the operation control from the ciphertext state to the plaintext state. A test response mechanism is maintained between Y2 and Y1. Y1 periodically initiates an encryption / decryption function test to Y2, that is, Y1 sends a test plaintext (or ciphertext) with a known ciphertext (or plaintext) result. Y2 encrypts the test plaintext (or decrypts the test ciphertext) and returns the result to Y1 for verification. If it does not meet the expectation, it indicates that the current state of Y2 is abnormal, and Y1 switches the operation control from the ciphertext state to the plaintext state. The number of this instruction can be Y-JZ2.

[0124] In this embodiment, by detecting an abnormality in the encryption / decryption unit on the first satellite and promptly switching the state of the measurement and control or operation control, the security and reliability of the system are ensured.

[0125] In one embodiment, the measurement and operation control collaborative management method further includes:

[0126] Receiving the state switching information of the first ground control module corresponding to the on-satellite control module of the first satellite. If the state switching information meets the preset security conditions, the state switching information is determined as a valid switching instruction, and the state of the on-satellite control module of the first satellite is switched based on the valid switching instruction.

[0127] Specifically, when the on-satellite control module of the first satellite is the on-satellite measurement and control module and the on-satellite control module of the first satellite is in the ciphertext state, receiving the state switching information of the ground measurement and control module, sending the state switching information to the measurement and control encryption / decryption unit, and the measurement and control encryption / decryption unit decrypts the state switching information to obtain the decrypted state switching information. If the decrypted state switching information is legal, the decrypted state switching information is determined as a valid switching instruction, and the state of the on-satellite measurement and control module is switched from the ciphertext state to the plaintext state based on the valid switching instruction. Exemplarily, the number of this valid switching instruction can be C-JZ1.

[0128] When the on - satellite control and measurement management module on the first satellite is the on - satellite TT&C control and management module and the on - satellite TT&C control and management module is in the clear state, it receives the status switching information from the ground TT&C module, determines that the status switching information is a valid switching instruction, and based on the valid switching instruction, changes the status of the on - satellite TT&C control and management module from the clear state to the encrypted state. Exemplarily, the number of this valid switching instruction can be C - JZ0.

[0129] When the on - satellite control and measurement management module on the first satellite is the on - satellite operation control management module and the on - satellite operation control module is in the encrypted state, it receives the status switching information from the ground operation control module, sends the status switching information to the operation control encryption and decryption unit. The operation control encryption and decryption unit decrypts the status switching information to obtain the decrypted status switching information. If the decrypted status switching information is legal, it determines that the decrypted status switching information is a valid switching instruction, and based on the valid switching instruction, changes the status of the on - satellite operation control management module from the encrypted state to the clear state. Exemplarily, the number of this valid switching instruction can be Y - JZ1.

[0130] When the on - satellite control and measurement management module on the first satellite is the on - satellite operation control management module and the on - satellite operation control module is in the clear state, it receives the status switching information from the ground operation control module, determines that the status switching information is a valid switching instruction, and based on the valid switching instruction, changes the status of the on - satellite operation control management module from the clear state to the encrypted state. Exemplarily, the number of this valid switching instruction can be Y - JZ0.

[0131] In one embodiment, as Figure 6 shown, the satellite system may specifically include an on - satellite TT&C control and management module, an on - satellite operation control management module, a ground TT&C module C0 corresponding to the on - satellite TT&C control and management module, and a ground operation control module Y0 corresponding to the on - satellite operation control management module. The on - satellite TT&C control and management module may include a TT&C clear - encrypted state management unit C1, a TT&C encryption and decryption unit C2, and a TT&C processing unit C3. The on - satellite operation control management module may include an operation control clear - encrypted state management unit Y1, an operation control encryption and decryption unit Y2, and an operation control processing unit Y3. The on - satellite TT&C control and management module may be set on the satellite platform, and the on - satellite operation control management module may be set on the satellite payload.

[0132] Among them, the topological structure of the satellite system is a double - star type. The TT&C clear - encrypted state management unit C1 and the operation control clear - encrypted state management unit Y1 form two connected central nodes. The TT&C encryption and decryption unit C2 and the operation control encryption and decryption unit Y2 form edge nodes. The TT&C processing unit C3 and the operation control processing unit Y3 form edge nodes. The ground TT&C module C0 and the ground operation control module Y0 form edge nodes.

[0133] The central nodes C1 and Y1 of the dual-star type are connected, and have the ability of real-time information interaction, so as to realize the conversion of the measurement and control in the abnormal state to the clear state through the encrypted operation control, and the conversion of the operation control in the abnormal state to the clear state through the encrypted measurement and control. C1 and Y1 respectively independently call the measurement and control and operation control encryption and decryption units C2 and Y2 to complete the measurement and control and operation control encryption and decryption functions. C1 has the function of real-time detection of C2, so as to realize that when C2 is abnormal, C1 can automatically convert the on-star measurement and control from the encrypted state to the clear state. Y1 has the function of real-time detection of Y2, so as to realize that when Y2 is abnormal, Y1 can automatically convert the on-star operation control management module from the encrypted state to the clear state. C1 and Y1 respectively independently call the measurement and control and operation control processing units C3 and Y3 to complete the on-star telemetry and telecommand data processing; C1 and Y1 respectively independently complete the data interaction of telemetry and telecommand with the ground measurement and operation and operation control modules C0 and Y0 through the wireless link. The ground measurement and control module C0 and the ground operation control module Y0 can also carry out data transmission.

[0134] C3 (or Y3) is used to generate telemetry data and send the telemetry data to C1 (or Y1), and is also used to receive the clear-state telecommand data from C1 (or Y1) and process the clear-state telecommand data.

[0135] C2 (or Y2) is used to encrypt and decrypt the telecommand data or telemetry data containing the encrypted state flag, and forward the processed telecommand data or telemetry data to C1 (or Y1) and can judge the legality of the telecommand data. If the telecommand data is illegal, it will be directly discarded.

[0136] As Figure 7 shown, Figure 7 is the schematic diagram of the on-star processing flow when the measurement and control is in the clear and encrypted states. As Figure 8 shown, Figure 8 is the schematic diagram of the on-star processing flow when the operation control is in the clear and encrypted states. C1 (or Y1) is used to receive the telecommand data sent by C0 (or Y0), and judge whether it is necessary to call C2 (or Y2) for decryption according to the current recorded measurement and control (or operation control) clear and encrypted state. If it is in the encrypted state, the telecommand data will be sent to C2 (or Y2) for decryption to obtain the clear-state telecommand data, and the clear-state telecommand data will be sent to C3 (or Y3); if it is in the clear state, the telecommand data will be directly sent to C3 (or Y3). C1 (or Y1) is also used to receive the telemetry data sent by C3 (or Y3), and judge whether it is necessary to call C2 (or Y2) for encryption according to the current recorded measurement and control (or operation control) clear and encrypted state. If it is in the encrypted state, the telemetry data will be sent to C2 (or Y2) for encryption to obtain the encrypted telemetry data, and the encrypted telemetry data will be sent to C0 (or Y0); if it is in the clear state, the telemetry data will be directly sent to C0 (or Y0).

[0137] When C1 is in the encrypted state, if the received operation control transition to the clear instruction on C0 is a legal encrypted measurement and control instruction, C1 sends the operation control transition to the clear instruction to Y1 through the connection with Y1, so that Y1 transitions from encrypted operation control to clear operation control. When Y1 is in the encrypted state, if the received operation control transition to the clear instruction on Y0 is a legal encrypted measurement and control instruction, Y1 sends the operation control transition to the clear instruction to C1 through the connection with C1, so that C1 transitions from encrypted operation control to clear operation control.

[0138] Specifically, between C2 and C0, the encryption and decryption of the telemetry and remote control data transmitted on the measurement and control link can be completed through methods such as pre-setting shared keys, public-private key encryption and decryption. C2 is called by C1 to realize the decryption of the platform remote control data and the encryption of the platform telemetry data. C0 completes the encryption of the platform remote control data and the decryption of the platform telemetry data. For example, the pre-set shared key can be that before the satellite leaves the factory, C2 and C0 pre-share the same key K0 for the encryption and decryption of the measurement and control data. Public-private key encryption and decryption can be that C2 pre-sets a pair of public-private keys (P0, Q0) and C0 pre-sets a pair of public-private keys (P0’, Q0’), Q0’ is stored in C2, and Q0 is stored in C0. C2 needs to ensure the confidentiality of P0, and C0 needs to ensure the confidentiality of P0’. During on-orbit operation, C2 encrypts the downlink telemetry using Q0’, and after C0 receives the telemetry, it decrypts it using P0’; C0 encrypts the uplink remote control using Q0, and after C2 receives the remote control, it decrypts it using P0.

[0139] Between Y2 and Y0, the encryption and decryption of the telemetry and remote control data transmitted on the measurement and control link can be realized through methods such as pre-setting shared keys, public-private key encryption and decryption. Y2 is called by Y1 to realize the decryption of the payload remote control data and the encryption of the payload telemetry data. Y0 completes the encryption of the payload remote control data and the decryption of the payload telemetry data. For example, the pre-set shared key can be that before the satellite leaves the factory, Y2 and Y0 pre-share the same key K1 for the encryption and decryption of the operation control data. Public-private key encryption and decryption can be that before the satellite leaves the factory, Y2 pre-sets a pair of public-private keys (P1, Q1) and Y0 pre-sets a pair of public-private keys (P1’, Q1’), Q1’ is stored in Y2, and Q1 is stored in Y0. Y2 needs to ensure the confidentiality of P1, and Y0 needs to ensure the confidentiality of P1’. During on-orbit operation, Y2 encrypts the downlink telemetry using Q1’, and after Y0 receives the telemetry, it decrypts it using P1’; Y0 encrypts the uplink remote control using Q1, and after Y2 receives the remote control, it decrypts it using P1.

[0140] In the operation, measurement and control clear / encrypted state switching system (satellite system) of this embodiment, the decoupling of the measurement and operation control system and the encryption and decryption system is realized, providing a physical implementation basis for the encrypted state exit mechanism in the case of abnormal encryption and decryption system. C1 and Y1 maintain communication with each other, further supporting the encrypted state exit mechanism for the coordination of measurement and control and operation control.

[0141] In one embodiment, C1 is responsible for measuring and controlling the clear and encrypted state management, including a clear-to-encrypted mechanism C-JZ0 and five encrypted-to-clear mechanisms C-JZ1, C-JZ2, C-JZ3, C-JZ4, and C-JZ5; among them, C-JZ0 and C-JZ1 are the basic mechanisms during the normal conversion of the clear and encrypted states; C-JZ5 is a backup mechanism to prevent abnormal encrypted state measurement and control from being unable to switch to the clear state; C-JZ2 is an on-satellite automatic trigger mechanism, which is automatically triggered by the satellite system according to preset conditions; C-JZ3 and C-JZ4 are on-satellite controlled trigger mechanisms, which are triggered by uploading ground commands.

[0142] The usage method and priority are that when both C-JZ1 and C-JZ2 fail, C-JZ3 is preferentially executed; if C-JZ3 does not meet the trigger conditions, then C-JZ4 is executed; if C-JZ4 also does not meet the trigger conditions, then wait for C-JZ5 to be automatically triggered.

[0143] Since the satellite requires high reliability for measurement and control and can operate independently of the operation control, compared with the operation control, the measurement and control clear-encrypted conversion method introduces a delay switching instruction (C-JZ4), so that abnormal encrypted state measurement and control can be controlled to switch to the clear state.

[0144] In one embodiment, Y1 is responsible for the operation control clear and encrypted state management, including a clear-to-encrypted mechanism Y-JZ0 and four encrypted-to-clear mechanisms Y-JZ1, Y-JZ2, Y-JZ3, and Y-JZ5.

[0145] Among them, Y-JZ0 and Y-JZ1 are the basic mechanisms during the normal conversion of the clear and encrypted states; Y-JZ5 is a backup mechanism to prevent abnormal encrypted state operation control from being unable to switch to the clear state; Y-JZ2 is an on-satellite automatic trigger mechanism, which is automatically triggered by the satellite system according to preset conditions; C-JZ3 is an on-satellite controlled trigger mechanism, which is triggered by uploading ground commands; the usage method and priority are that when both Y-JZ1 and Y-JZ2 fail, Y-JZ3 is executed; if Y-JZ3 does not meet the trigger conditions, then wait for Y-JZ5 to be automatically triggered.

[0146] In one embodiment, setting the measurement and control related instructions of the above embodiment, the impact on the measurement and control security is shown in Table 1. The analysis of the impact of the above one clear-to-encrypted mechanism and five encrypted-to-clear mechanisms on the reliability and security of the measurement and operation control system is shown in the following table. All six mechanisms can ensure the security of the measurement and control system.

[0147] Table 1 Impact of the measurement and control clear-encrypted conversion mechanism on the security of the measurement and control system

[0148]

[0149] In one embodiment, the impact of the operation control related instructions of the above embodiment on the operation control security is shown in Table 2. The impact analysis of the above 1 kind of clear-to-secret mechanism and 4 kinds of secret-to-clear mechanisms on the reliability and security of the operation control system is shown in the following table. All 5 mechanisms can ensure the security of the operation control system.

[0150] Table 2 Impact of the operation control clear-secret conversion mechanism on the security of the operation control system

[0151]

[0152] In one embodiment, the measurement method for improving the reliability of the satellite measurement and operation control system by multiple mechanisms within a group specifically includes the following steps:

[0153] Establish an event tree from the secret state to the clear state; calculate the probabilities of each event within the event tree; based on the probabilities of each event within the event tree, calculate the contribution value of different mechanisms within the group to the reduction of the effective probability of the guaranteed strategy.

[0154] As Figure 9 shown, according to the 5 kinds of secret-to-clear mechanisms of the measurement and control system listed from C-JZ1 to C-JZ5 in Table 1, an event tree of the measurement and control system from the secret state to the clear state can be drawn. Define a set of random variables , assuming that the measurement and control is in the secret state at this time, that is, Pr (measurement and control is in the secret state) = 1.

[0155] Among them, eC1 = 0 represents the event of "measurement and control is in the secret state and C2 is normal", and eC1 = 1 represents the event of "measurement and control is in the secret state and C2 is abnormal", then Pr(eC1 = 0)+ Pr(eC1 = 1)=1.

[0156] Among them, eC2 = 0 represents the event of "C2 is abnormal and C1 detects that C2 is abnormal", and eC2 = 1 represents the event of "C2 is abnormal and C1 does not detect that C2 is abnormal", then according to the definition, Pr(eC2 = 0)+ Pr(eC2 = 1)= Pr(eC1 = 1).

[0157] Among them, eC3 = 0 represents the event of "operation control is in the normal secret state and eC2 = 1", and eC3 = 1 represents the event of "operation control is in the clear state or abnormal secret state and eC2 = 1", then according to the definition, Pr(eC3 = 0)+ Pr(eC3 = 1)= Pr(eC2 = 1).

[0158] Among them, eC4 = 0 represents the event of "N≥M in the delayed clear-to-secret instruction and eC3 = 1", and eC3 = 1 represents the event of "N≥M in the delayed clear-to-secret instruction and eC3 = 1", then according to the definition, Pr(eC4 = 0)+ Pr(eC4 = 1)= Pr(eC3 = 1).

[0159] Among them, eC5 = 0 represents the event that "[T0 + N, T0 + N + W] is within the measurement and control arc segment and eC4 = 1", and eC3 = 1 represents the event that "[T0 + N, T0 + N + W] is not within the measurement and control arc segment and eC4 = 1". Then, according to the definition, Pr(eC5 = 0) + Pr(eC5 = 1) = Pr(eC4 = 1).

[0160] Finally, eC6 = 0, 1, 2 represent the three events of "immediate transition of encrypted measurement and control to plaintext", "delayed N - hour fast transition of encrypted measurement and control to plaintext", and "slow transition of encrypted measurement and control to plaintext according to the guaranteed time" respectively. Then, according to the definition, Pr(eC6 = 0) + Pr(eC6 = 1) + Pr(eC6 = 2) = 1.

[0161] As Figure 10 shown, according to the 4 encrypted - to - plaintext mechanisms of the operation and control system listed from Y - JZ1 to Y - JZ5 in Table 2, the event tree of the operation and control system from the encrypted state to the plaintext state can be drawn. Define a set of random variables , . Assume that the operation and control is in the encrypted state at this time, that is, Pr(operation and control is in the encrypted state) = 1.

[0162] Among them, eY1 = 0 represents the event that "the operation and control is in the encrypted state and Y2 is normal", and eY1 = 1 represents the event that "the operation and control is in the encrypted state and Y2 is abnormal". Then, Pr(eY1 = 0) + Pr(eY1 = 1) = 1.

[0163] Among them, eY2 = 0 represents the event that "Y2 is abnormal and the abnormality is detected by Y1", and eY2 = 1 represents the event that "Y2 is abnormal and the abnormality is not detected by Y1". Then, according to the definition, Pr(eY2 = 0) + Pr(eY2 = 1) = Pr(eY1 = 1).

[0164] Among them, eY3 = 0 represents the event that "the measurement and control is in the normal encrypted state and eY2 = 1", and eY3 = 1 represents the event that "the measurement and control is in the plaintext state or abnormal encrypted state and eY2 = 1". Then, according to the definition, Pr(eY3 = 0) + Pr(eY3 = 1) = Pr(eY2 = 1).

[0165] Finally, eY6 = 0, 1, 2 represent the three basic events of "immediate transition of encrypted operation and control to plaintext", "delayed N - hour fast transition of encrypted operation and control to plaintext", and "slow transition of encrypted operation and control to plaintext according to the guaranteed time" respectively. Then, according to the definition, Pr(eY6 = 0) + Pr(eY6 = 1) + Pr(eY6 = 2) = 1.

[0166] Since the measurement and control abnormality and the operation and control abnormality are independent, Pr(eC3 = 0) = Pr(eY1 = 0) Pr(eC2 = 1).

[0167] According to the above - mentioned definition, the probabilities of the occurrence of the three basic events can be calculated:

[0168] Pr(eC6 = 0) = Pr(eC1 = 0) + Pr(eC2 = 0) + Pr(eC3 = 0);

[0169] Pr(eC6 = 1) = Pr(eC5 = 0);

[0170] Pr(eC6 = 2) = Pr(eC5 = 1) + Pr(eC4 = 1);

[0171] From the perspective of measurement and control reliability, the event eC6 = 0 corresponds to a highly reliable state, and the encrypted measurement and control can immediately switch to the clear state; the event eC6 = 1 corresponds to a reliable state, and the encrypted measurement and control can switch to the clear state after a short delay; while the event eC6 = 2 is an unreliable state, and the encrypted measurement and control needs to bear the huge risk of no effective telemetry and remote control for a long time.

[0172] In this embodiment Figure 9 The three optional mechanisms C-JZ2, C-JZ3, and C-JZ4 proposed can all reduce the probability of the event eC6 = 2 corresponding to the unreliable state, thereby increasing the measurement and control reliability.

[0173] Mechanism C-JZ2 can reduce the probability of eC6 = 2 occurring by Pr(eC2 = 0); mechanism C-JZ3 can reduce the probability of eC6 = 2 occurring by Pr(eC3 = 0); mechanism C-JZ4 can reduce the probability of eC6 = 2 occurring by Pr(eC5 = 0);

[0174] Since the operation control anomaly and the measurement and control anomaly are independent, Pr(eY3 = 0) = Pr(eC1 = 0) Pr(eY2 = 1).

[0175] According to the above definitions, the probabilities of the three basic events occurring can be calculated:

[0176] Pr(eY6 = 0) = Pr(eY1 = 0) + Pr(eY2 = 0) + Pr(eY3 = 0);

[0177] Pr(eY6 = 2) = Pr(eY3 = 1);

[0178] From the perspective of operation control reliability, the event eY6 = 0 corresponds to a highly reliable state, and the encrypted operation control can immediately switch to the clear state; the event eC6 = 2 is an unreliable state, and the encrypted operation control needs to bear the huge risk of no effective telemetry and remote control for a long time.

[0179] This embodiment Figure 10 The two optional mechanisms Y-JZ2 and Y-JZ3 proposed can both reduce the probability of the event eY6 = 2 corresponding to the unreliable state, thereby increasing the operation control reliability.

[0180] Mechanism Y-JZ2 can reduce the probability of eY6=2 occurring to Pr(eY2=0); mechanism Y-JZ3 can reduce the probability of eY6=2 occurring to Pr(eY3=0).

[0181] In this embodiment, it includes real-time anomaly detection mechanisms for measurement, transportation, control, encryption, and decryption functions (C-JZ2 and Y-JZ2), a confidential state exit mechanism for measurement, transportation, and control collaboration (C-JZ3 and Y-JZ3), a guaranteed plaintext conversion mechanism for measurement, transportation, and control (C-JZ5 and Y-JZ5), and a delayed plaintext conversion instruction for measurement and control in the clear state (C-JZ4), effectively enhancing the reliability of measurement, transportation, and control. C-JZ4 introduces a delay and a measurement and control arc segment discrimination mechanism, which can effectively prevent attackers from using this mechanism to convert normal confidential measurement and control to plaintext; attackers cannot use the mechanisms of this embodiment to convert normal confidential states to plaintext, thus ensuring the security of the measurement, transportation, and control system.

[0182] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0183] Based on the same inventive concept, the embodiments of the present application also provide a measurement, transportation, and control collaboration management device for implementing the above-mentioned measurement, transportation, and control collaboration management method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the following measurement, transportation, and control collaboration management device can refer to the limitations on the measurement, transportation, and control collaboration management method in the above text, and will not be repeated here.

[0184] In an exemplary embodiment, as Figure 11 shown, a measurement, transportation, and control collaboration management device 110 is provided, which is applied to the first on-board plaintext and ciphertext management unit. The first on-board plaintext and ciphertext management unit is in the first on-board management module included in the satellite system. The satellite system also includes a second on-board management module, including: a receiving module 1101, a judging module 1102, and a switching module 1103, where:

[0185] The receiving module 1101 is used to receive a switching instruction;

[0186] A judgment module 1102, configured to judge whether a switching instruction is valid;

[0187] A switching module 1103, configured to, if the switching instruction is a valid switching instruction, respond to the valid switching instruction and switch the state of the first on-board management and control module based on the valid switching instruction, where the state includes a clear state or a secret state; the valid switching instruction is sent by at least one of a second on-board management and control module, a first encryption / decryption unit in the first on-board management and control module, and a first ground management and control module corresponding to the first on-board management and control module when the first encryption / decryption unit in the first on-board management and control module is in an abnormal state.

[0188] In one embodiment, the switching module 1103 is specifically configured to respond to the valid switching instruction sent by the second on-board management and control module, where the valid switching instruction is generated by the second on-board management and control module based on a first switching instruction that meets a preset security condition, and the first switching instruction is sent by a second ground management and control module corresponding to the second on-board management and control module after receiving a first abnormal prompt message; the first abnormal prompt message is sent by the first ground management and control module to the second ground management and control module after detecting a first abnormal signal of the first encryption / decryption unit.

[0189] In one embodiment, the switching module 1103 is further configured to receive a second switching instruction sent by the first ground management and control module, where the second switching instruction is sent by the first ground management and control module after receiving a second abnormal prompt message, and the second abnormal prompt message is sent by a second ground management and control module corresponding to the second on-board management and control module after detecting a second abnormal signal of a second encryption / decryption unit;

[0190] When the second switching instruction meets the preset security condition, determine the second switching instruction as the valid switching instruction and send the valid switching instruction to the second on-board management and control module, so that the second on-board management and control module switches the state of the second on-board management and control module based on the valid switching instruction.

[0191] In one embodiment, the switching module 1103 is specifically configured to, when the on-board measurement and control management and control module is in the secret state, receive a delayed switching instruction sent by a ground measurement and control module corresponding to the on-board measurement and control management and control module;

[0192] If the delayed switching instruction meets a preset delay condition, determine the delayed switching instruction as the valid switching instruction;

[0193] If the duration of receiving the valid switching instruction meets the delay time of the delayed switching instruction, respond to the valid switching instruction and switch the state of the on-board measurement and control management and control module from the secret state to the clear state based on the valid switching instruction.

[0194] In one embodiment, the switching module 1103 is further configured to determine a valid time range of the delay switching instruction based on the reception time of the delay switching instruction, the delay time of the delay switching instruction, and the maximum system response time;

[0195] If the delay time is greater than a preset window threshold and the valid time range of the delay switching instruction is within a preset measurement and control arc segment, it is determined that the delay switching instruction meets the preset delay condition.

[0196] In one embodiment, the switching module 1103 is further configured to send encrypted telemetry information to the first ground control module based on the delay switching instruction, so that the first ground control module determines whether the delay switching instruction meets the legal condition based on the encrypted telemetry information, and sends an encrypted cancellation instruction to the measurement and control clear / encrypted state management unit when the legal condition is not met;

[0197] Receive the encrypted cancellation instruction and interrupt the response to the delay switching instruction based on the encrypted cancellation instruction.

[0198] In one embodiment, the switching module 1103 is further configured to switch the state of the first on-board control module from the encrypted state to the clear state if no valid control instruction is received within a preset duration, where the valid control instruction is a control instruction sent by the first ground control module corresponding to the first on-board clear / encrypted state management unit to the first on-board clear / encrypted state management unit.

[0199] In one embodiment, the switching module 1103 is specifically configured to, if a third abnormal signal of the first on-board encryption / decryption unit of the first on-board control module is received, determine the third abnormal signal as a valid switching instruction, and based on the valid switching instruction, switch the state of the on-board control module from the encrypted state to the clear state.

[0200] Each module in the above measurement, operation, and control collaborative management device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the communication device in hardware form or independent of the processor, or stored in the memory in the communication device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0201] In one embodiment, a communication device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0202] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0203] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the steps in the above method embodiments.

[0204] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0205] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0206] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0207] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.

Claims

1. A measurement, operation and control collaborative management method, characterized in that: Applied to a first on-board clear and secret state management unit, the first on-board clear and secret state management unit is in a first on-board control and management module included in a satellite system, the satellite system further includes a second on-board control and management module, the method includes: receiving a switching instruction; Determining whether the switching instruction is valid; If the switching instruction is a valid switching instruction, then respond to the valid switching instruction, and based on the valid switching instruction, switch the state of the first on-board control module, the state including the open state or the secret state; the valid switching instruction is sent by at least one of the second on-board control module, the first on-board encryption and decryption unit in the first on-board control module, and the first ground control module corresponding to the first on-board control module when the first on-board encryption and decryption unit in the first on-board control module is in an abnormal state.

2. The method according to claim 1, characterized in that The responding to the valid switching instruction comprises: Respond to a valid switching instruction sent by the second on-board control module, wherein the valid switching instruction is generated by the second on-board control module based on the received first switching instruction that meets preset safety conditions, and the first switching instruction is sent by the second ground control module corresponding to the second on-board control module after receiving the first abnormal prompt information; the first abnormal prompt information is sent to the second ground control module after the first ground control module detects the first abnormal signal of the first on-board encryption and decryption unit.

3. The method according to claim 1, characterized in that The second on-board control module includes a second on-board encryption and decryption unit, and the method further includes: receiving a second switching instruction sent by the first ground control module, where the second switching instruction is sent by the first ground control module after receiving second abnormal prompt information, where the second abnormal prompt information is sent to the first ground control module by a second ground control module corresponding to the second on-board control module after detecting a second abnormal signal of a second on-board encryption and decryption unit; When the second switching instruction meets the preset safety conditions, the second switching instruction is determined to be the valid switching instruction, and the valid switching instruction is sent to the second on-board control module, so that the second on-board control module switches the state of the second on-board control module based on the valid switching instruction.

4. The method according to claim 2, characterized in that: The first on-board control module is an on-board measurement and control control module, the first on-board open and closed state management unit is a measurement and control open and closed state management unit, and if the switching instruction is a valid switching instruction, responding to the valid switching instruction, and switching the state of the first on-board control module based on the valid switching instruction, includes: If the delayed switching instruction satisfies the preset delay condition, the delayed switching instruction is determined as a valid switching instruction, and the delayed switching instruction is sent by the ground measurement and control module corresponding to the on-board measurement and control control module to the measurement and control secret state management unit when the on-board measurement and control control module is in a secret state; If the duration of receiving the effective switching instruction meets the delay time of the delayed switching instruction, the effective switching instruction is responded to, and the state of the on-board measurement, control and management module is switched from a dense state to a clear state based on the effective switching instruction.

5. The method according to claim 4, characterized in that The method further comprises: Determining a valid time range of the delayed switching instruction based on a reception time of the delayed switching instruction, a delay time of the delayed switching instruction, and a maximum system response time; If the delay time is greater than a preset window threshold and the effective time range of the delayed switching instruction is within a preset measurement and control arc segment, it is determined that the delayed switching instruction meets the preset delay condition.

6. The method according to claim 4, characterized in that The method further comprises: Sending confidential telemetry information to the first ground control module based on the delayed switching instruction, so that the first ground control module determines whether the delayed switching instruction meets legal conditions based on the confidential telemetry information, and sends a confidential revocation instruction to the measurement and control confidential management unit if the legal conditions are not met; The secret state revocation instruction is received, and based on the secret state revocation instruction, an interrupt response is given to the delayed switching instruction.

7. The method according to claim 1, characterized in that The method further comprises: If no valid control instruction is received within the preset time, the state of the first on-board control module will be switched from a dense state to an open state. The valid control instruction is a control instruction sent by the first ground control module corresponding to the first on-board dense or open state management unit to the first on-board dense or open state management unit.

8. The method according to claim 1, characterized in that The step of responding to the effective switching instruction and switching the state of the first onboard control module based on the effective switching instruction includes: If a third abnormal signal is received from the first on-board encryption and decryption unit of the first on-board control module, the third abnormal signal is determined as a valid switching instruction, and based on the valid switching instruction, the state of the first on-board control module is switched from a encrypted state to a clear state.

9. A measurement, operation and control collaborative management device, characterized in that: Applied to a first on-board clear and secret state management unit, the first on-board clear and secret state management unit is in a first on-board control module included in a satellite system, the satellite system also includes a second on-board control module, the device includes: A receiving module, used for receiving a switching instruction; A judging module, used to judge whether the switching instruction is valid; A switching module is used to respond to the valid switching instruction if the switching instruction is a valid switching instruction, and switch the state of the first on-board control module based on the valid switching instruction, wherein the state includes a clear state or a secret state; the valid switching instruction is sent by at least one of the second on-board control module, the first on-board encryption and decryption unit in the first on-board control module, and the first ground control module corresponding to the first on-board control module when the first on-board encryption and decryption unit in the first on-board control module is in an abnormal state.

10. A communication device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.