Satellite signal tamper-proofing method and system

Through Hadamma integrated segment algorithm and grayscale correlation analysis combined with dynamic key technology, the block processing path of satellite signals is dynamically adjusted, solving the problems of insufficient block regular exposure and static threshold adaptability in the existing technology, and improving the tamper identification and blocking capabilities of satellite signals.

CN120201418BActive Publication Date: 2025-08-22GOLDEN SHIELD TESTING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510686601.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-22
Estimated Expiration
2045-05-27

AI Technical Summary

Technical Problem

In the existing satellite signal tamper-proof technology, there is a lack of dynamic adjustment of the block length and encryption path. Attackers can analyze the blocking rules and key periods through long-term traffic monitoring, resulting in a decrease in tamper-proof strength. The static threshold judgment is insufficient in complex channel environments, which is prone to false alarms or leaks of keys.

Method used

The Hadamma integrated segment algorithm is used to generate a segment block index table, combine the satellite real-time position and timestamp, calculate the correlation degree through the grayscale correlation analysis model, dynamically generate jump segment block processing paths, and use dynamic key parameter groups to perform byte-byte XOR and complement mapping, generate a re-encrypted key group, and update the key in real time to block tampering.

Benefits of technology

It realizes dynamic adjustment of blocking mode to avoid attackers’ speculation of frame structure, improves the tampering identification and blocking capabilities of satellite signals in complex channel environments, enhances the real-time update capability of keys, and prevents key multiplexing attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201418B_ABST
    Figure CN120201418B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of communication security technology, specifically a satellite signal anti-tampering method and system, comprising the following steps: obtaining a current communication data frame through a satellite orbit number, a real-time position vector, and a timestamp, inputting the data frame into a Hadamard integral segment algorithm to perform non-equal length segment block cutting, generating a segment block index table, and recording the starting address bit, segment block length value, and initial weight bit value. In the present invention, the data frame is cut into non-equal lengths through a Hadamard integral segment algorithm, a segment block index table is generated, and the weight bit value is recorded. Based on a master key group, a subkey and an XOR parameter are extracted to perform a logical rotation, a dynamic jump path is constructed, the correlation degree of the shielded area is calculated by combining satellite coordinates and timestamps, the risk coefficient is quantified to locate the risk segment block, a dynamic key is called to generate a re-encryption key through double linear perturbation, and byte-by-byte XOR and complement mapping are used to strengthen local protection, thereby forming a closed-loop mechanism of dynamic cutting, path generation, risk perception, and key update.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security technology, and in particular to a satellite signal tamper-proofing method and system. Background Art

[0002] The field of communication security technology includes various technologies that protect information from unauthorized access, tampering, destruction or monitoring during transmission, exchange and storage. The core content of this technology field includes communication encryption, identity authentication, data integrity verification, anti-tampering mechanisms, anti-interference transmission and key management. Communication security is widely used in multiple scenarios such as wireless communications, the Internet, the Internet of Things, satellite communications, etc., and is the basis for building a trusted network environment and protecting data security. Systematically speaking, the development of this technology field focuses on the dual security assurance mechanism of the protocol layer and the channel layer, combined with the response technology for various attack models of information in the transmission path, to ensure the authenticity and consistency of communication content in physical links, network paths and application interactions.

[0003] Among them, the satellite signal anti-tampering method refers to a communication security technology based on encryption and verification mechanisms adopted in satellite communication systems to prevent signals from being maliciously tampered with during transmission. The technical matters targeted by this patent subject mainly include the verification of data integrity in the satellite signal transmission path, the authentication mechanism of the signal source, and the encryption processing of the transmission content under a specific communication protocol. The specific methods include digital signature processing of uplink and downlink signals, identity verification of the communicating parties through key matching, and the introduction of hash functions to verify the consistency of original data and received data, so as to identify and block tampering during signal transmission. This technology is usually embedded in the satellite communication data frame in the form of a protocol encapsulation layer, and a tamper-proof communication process is constructed through distributed authentication codes and multi-round verification logic.

[0004] Existing technologies rely on fixed blocks and static key sequences, and lack dynamic adjustment of block lengths and encryption paths. Attackers can analyze block patterns and key periods through long-term traffic monitoring, reducing anti-tampering strength. Traditional data integrity verification uses one-way hashing or centralized authentication, which does not incorporate dynamic satellite position parameters. When the signal naturally attenuates due to orbital drift or obstruction, it is easy to misjudge normal fluctuations as tampering. Existing anti-tampering logic is mainly based on protocol layer encapsulation, and does not integrate real-time environmental parameters such as physical layer channel shielding and multipath effects. As a result, risk assessment and encryption strategies cannot be adaptively adjusted according to channel status. For example, when satellites communicate across polar regions, fixed verification thresholds may frequently trigger false alarms due to ionospheric interference. In addition, traditional methods have a fixed processing path for data frames. Attackers can reverse-engineer the encryption logic by intercepting multiple sets of data, posing a risk of systemic key leakage. Summary of the Invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a satellite signal anti-tampering method and system.

[0006] In order to achieve the above object, the present invention adopts the following technical solution: a satellite signal anti-tampering method, comprising the following steps:

[0007] S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-equal length segment cutting, generate a segment block index table, and record the starting address bit, segment block length value and initial weight bit value;

[0008] S2: Based on the master synchronization key group, the subkey sequence from bit N to bit N+M is extracted as the offset parameter, the last K bits are extracted as the shift XOR parameter, an XOR operation is performed on the index bit values ​​of multiple items in the segment index table, and a logical rotation operation is performed on the operation results to generate a skip segment processing path;

[0009] S3: Based on the satellite three-axis coordinate parameters and timestamp sequence, the jumping segment block processing path is input into the grayscale correlation analysis model to calculate the correlation between the segment block time window and the masking interval. The segment block is determined to be in a tampering risk state based on the correlation threshold, and the tampering risk coefficient and risk segment block set are output.

[0010] As a further solution of the present invention, the jumping segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier; the tampering risk coefficient includes a correlation threshold, a risk quantification value, and a period determination mark; and the risk segment block set includes a risk segment block number, a time window label, and a priority identifier.

[0011] As a further solution of the present invention, the matrix generation rule in the Hadamard integral segment algorithm is: when the data frame length is an odd number, the data frame length is rounded up to the nearest integer. And truncate the effective bits to construct a Hadamard orthogonal basis matrix with an order of half the length of the truncated data frame;

[0012] 、 The value of is determined dynamically by taking the modulo operation of the total number of segments based on the hash value of the satellite orbit number;

[0013] The correlation threshold is obtained by optimizing the historical tampering dataset based on the gradient descent method, and its value range is .

[0014] As a further solution of the present invention, the steps for obtaining the skipping segment block processing path are specifically as follows:

[0015] S201: Based on the master synchronization key group, locate the Nth starting bit, intercept the continuous M-bit binary sequence, convert the binary sequence into a decimal value, extract the last K-bit binary sequence of the master synchronization key group, convert it into a hexadecimal value, and generate an offset parameter and an XOR parameter;

[0016] The value of is the integer part of the logarithm 2 of the total number of segments in the segment index table, that is, ;

[0017] S202: Call the index bit value in the segment index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the XOR parameter, perform the XOR operation on each bit, shift the operation result left by K bits, truncate the last M bits of the binary sequence, convert it into a decimal value, and generate the processing path coefficient;

[0018] S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the total number of segments and blocks on the addition result, map the remainder to the index bit value of the segment and block index table, rearrange the segment and block index bits in the order of the remainder, and generate a skipping segment and block processing path.

[0019] As a further embodiment of the present invention, the method further comprises:

[0020] S4: Call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform perturbation operation on the key shift parameter through the double linear mapping function, generate a re-encryption key group, and perform byte-by-byte XOR, logical shift and complement mapping operations on the risk segment block set.

[0021] As a further solution of the present invention, the re-encryption key group includes the perturbed displacement parameters, the XOR operation sequence, and the complement mapping rule;

[0022] The dynamic key parameter group is generated by the master synchronization key group through the nonlinear transformation of the elliptic curve, satisfying ,in As the base point, is a random integer, is a prime number.

[0023] As a further solution of the present invention, the steps for obtaining the re-encryption key group are specifically as follows:

[0024] S401: Call the dynamic key parameter group in the master synchronization key group, extract the tampering risk coefficient as a weight factor, multiply each parameter item in the dynamic key parameter group by the weight factor, calculate the modulus feature of the product as the first linear transformation input, perform a first round of linear superposition on the key displacement parameter based on the modulus feature, and perform a second linear transformation with the square value of the weight factor to generate a perturbation key vector;

[0025] Modulus characteristics through Galois fields Irreducible polynomials of Computational generation;

[0026] S402: Based on the perturbation key vector, traverse the byte stream of each segment block in the risk segment block set, extract the binary value of each byte in the segment block byte stream, perform an XOR operation on the byte value and the corresponding byte of the perturbation key vector, and perform a left or right shift operation on the XOR result according to the parity bit state of the current byte of the perturbation key vector to generate an intermediate encrypted segment block;

[0027] S403: For the intermediate encrypted segments, extract the two's complement mapping reference value for each byte, locate the mapping rule in the two's complement mapping table based on the reference value, perform bit-level superposition on the byte data and the mapping rule, and combine the superposition results of all segments to generate a re-encryption key group;

[0028] The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying ,in is the raw bytes, is the Hamming weight.

[0029] A satellite signal anti-tampering system is provided, which is used to implement the above-mentioned satellite signal anti-tampering method. The system includes:

[0030] The frame segment cutting module is used to obtain the communication data frame through the satellite orbit number and the real-time position vector, input the communication data frame into the Hadamard integral segment algorithm to perform non-equal length segment block cutting, generate a segment block index table, record the starting address bit, segment block length value and initial weight bit value, and pass the segment block index table to the key path generation module;

[0031] A key path generation module is configured to extract the subkey sequence from the Nth to the N+Mth bits from the master synchronization key group as an offset parameter, extract the last K bits as a shift XOR parameter, perform an XOR operation on the starting address bit and the initial weight bit value in the segment block index table, and input the XOR operation into a logic rotation function to generate a skip segment block processing path, and pass the skip segment block processing path to the risk assessment module;

[0032] The risk assessment module is used to input the jump-type segment processing path into the grayscale correlation analysis model through the satellite three-axis coordinate parameters and the timestamp sequence, calculate the correlation between the segment time window and the masking interval, determine whether the segment is in a tampering risk state based on a preset correlation threshold, output the tampering risk coefficient and the risk segment set, and pass the tampering risk coefficient and the risk segment set to the dynamic encryption module;

[0033] The dynamic encryption module is used to call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform perturbation operation on the key shift parameter through the double linear mapping function to generate a re-encryption key group, and perform byte-by-byte exclusive OR and logical shift operations on the risk segment block set, and pass the re-encryption key group to the satellite communication link for data encapsulation.

[0034] Compared with the prior art, the advantages and positive effects of the present invention are:

[0035] In this invention, the Hadamard integral segmentation algorithm is used to perform unequal-length segmentation on data frames, generating a segment index table and recording weighted bit values. This breaks the fixed segmentation pattern, making it difficult for attackers to infer the complete frame structure from intercepted fragments. Based on the master key group, subkey sequences and XOR parameters are extracted, and logical rotation operations are performed on the index bit values ​​to construct a dynamic jump processing path, avoiding the regularity exposed by traditional sequential encryption. Combining real-time satellite coordinates and timestamp sequences, a grayscale correlation model is used to calculate the correlation between segment time windows and obscured areas, quantifying the tampering risk factor and locating risky segments. This addresses the limited adaptability of static threshold judgment in complex channel environments. A dynamic key parameter group is then perturbed through a dual linear mapping to generate a re-encryption key, enabling real-time key updates based on channel status and preventing key reuse attacks. Byte-by-byte XOR and complement mapping are used to re-encrypt risky segments, strengthening local protection while maintaining overall transmission efficiency. These steps form a closed-loop dynamic segmentation-path generation-risk perception-key update mechanism, enhancing the real-time identification and blocking capabilities of multi-dimensional satellite signal tampering attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is a schematic diagram of the workflow of the present invention;

[0037] Figure 2 Flowchart of the steps for obtaining the segment block index table of the present invention;

[0038] Figure 3 A flow chart of the steps for obtaining a skip-type segment processing path according to the present invention;

[0039] Figure 4 Flowchart of the steps for obtaining the tampering risk coefficient and the risk segment block set of the present invention;

[0040] Figure 5 This is a flow chart of the steps for obtaining the re-encryption key group of the present invention. DETAILED DESCRIPTION

[0041] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0042] In the description of the present invention, it should be understood that the terms "length," "width," "up," "down," "front," "back," "left," "right," "vertical," "horizontal," "top," "bottom," "inside," "outside," and the like, indicating positions or relationships, are based on the positions or relationships shown in the accompanying drawings and are intended only to facilitate the description of the present invention and simplify the description. They do not indicate or imply that the devices or elements referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limiting the present invention. Furthermore, in the description of the present invention, "plurality" means two or more, unless otherwise expressly and specifically defined.

[0043] Example 1: Please refer to Figure 1 The present invention provides a technical solution: a satellite signal anti-tampering method, comprising the following steps:

[0044] S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-equal length segment cutting, generate a segment block index table, and record the starting address bit, segment block length value and initial weight bit value;

[0045] S2: Based on the master synchronization key group, the subkey sequence from bit N to bit N+M is extracted as the offset parameter, the last K bits are extracted as the shift XOR parameter, an XOR operation is performed on the index bit values ​​of multiple items in the segment index table, and a logical rotation operation is performed on the operation results to generate a skip segment processing path;

[0046] S3: Based on the satellite three-axis coordinate parameters and timestamp sequence, the jump segment processing path is input into the grayscale correlation analysis model to calculate the correlation between the segment time window and the masking interval. Based on the correlation threshold, it is determined whether the segment is in a tampering risk state, and the tampering risk coefficient and risk segment set are output.

[0047] S4: Call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform perturbation operation on the key shift parameter through the double linear mapping function, generate a re-encryption key group, and perform byte-by-byte XOR, logical shift and complement mapping operations on the risk segment block set.

[0048] The jumping segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier. The tampering risk coefficient includes a correlation threshold, a risk quantification value, and a period determination mark. The risk segment block set includes a risk segment block number, a time window label, and a priority identifier. The re-encryption key group includes the displacement parameter after disturbance, the XOR operation order, and the complement mapping rule.

[0049] The matrix generation rule in the Hadamard integral segment algorithm is: when the data frame length is an odd number, round the data frame length up to the nearest integer. And truncate the effective bits to construct a Hadamard orthogonal basis matrix with an order of half the length of the truncated data frame;

[0050] 、 The value of is determined dynamically by taking the modulo operation of the total number of segments based on the hash value of the satellite orbit number;

[0051] The correlation threshold is obtained by optimizing the historical tampering dataset based on the gradient descent method, and its value range is ;

[0052] The dynamic key parameter group is generated by the master synchronization key group through the nonlinear transformation of the elliptic curve, satisfying ,in As the base point, is a random integer, is a prime number.

[0053] See also Figure 2 , the specific steps for obtaining the segment block index table are:

[0054] S101: Obtain the real-time position vector and timestamp corresponding to the satellite orbit number, extract the binary communication data stream through the satellite communication link parsing protocol, parse the start byte and end byte fields in the protocol frame header identifier, locate the valid data segment based on the field length and checksum verification result, intercept the continuous data segment after the frame header identifier, and generate a communication data frame;

[0055] First, the system obtains the orbital number of a specific satellite and queries the current real-time position vector and corresponding timestamp information of the satellite based on this number. The precise position vector recorded by a communication relay satellite with the orbital number "CN_SAT_COMM_07" at 10:00:00.000 on May 8, 2025, at Universal Coordinated Time (UTC) is The next record point is at 10:00:00.120 UTC time on May 8, 2025, and its position vector is updated to This data is collected by the satellite's own sensors and transmitted via downlink.

[0056] Next, the original binary communication data stream is extracted through the satellite communication link parsing protocol. The satellite communication link follows an internally defined binary transmission protocol, which specifies the encapsulation structure of the data frame in detail. Specifically, the start of the frame is marked by a 2-byte fixed identifier "0xBEEF", followed by a 2-byte data segment length field to indicate the number of bytes of the subsequent valid data segment. The data segment is followed by a 1-byte cyclic redundancy check code (CRC-8). Finally, the end of the frame is marked by a 2-byte end identifier "0xCAFE". An actual received binary data stream fragment may be: "...0xBEEF00201A2B3C4D...5E6F7G8HCRCVAL0xCAFE...", where "0x0020" indicates that the data segment contains 32 bytes. The system parses this data stream strictly according to the protocol: first search and locate the starting byte sequence "0xBE" and "0xEF" to confirm the start of the frame, then read the two bytes "0x00" and "0x20" that follow, and combine them to get a data segment length of 32 bytes. The system then extracts the valid data of these 32 bytes, for example, the data is: "0x112233445566778899AABBCCDDEEFF00102030405060708090A0B0C0D0E0F", then read the 1-byte checksum and set it to "0x5B". The system uses the standard CRC-8 algorithm (for example, using the polynomial ) calculates the extracted 32-byte data segment and obtains a checksum. If the calculated result is also "0x5B", the check passes. Finally, the system checks whether there are end identifiers "0xCA" and "0xFE" at the end of the data segment. After all are confirmed to be correct, the 32-byte continuous data segment (i.e. "0x1122...0E0F") is completely intercepted to generate a communication data frame, which is the basic unit of subsequent processing.

[0057] S102: Invoke the matrix generation rule in the Hadamard integral segment algorithm to construct a Hadamard orthogonal basis matrix with an order of half the data frame length, convert the binary sequence of the communication data frame into a decimal numerical vector, perform element-by-element multiplication with the matrix row vector and accumulate the sum, calculate the standard deviation of adjacent accumulated values, and determine the segment block boundaries based on the mutation points where the standard deviation change rate exceeds a preset threshold. Count the number of bits between the boundaries as the length value to generate segment block segmentation parameters;

[0058] The conversion method of decimal numerical vector is: convert the binary sequence into 8-bit segments Normalized values ​​satisfy ,in is a binary bit value;

[0059] The communication data frame generated according to S101 is 32 bytes long and converted into a bit stream is bit, the system calls the matrix generation rule in the Hadamard integral segment algorithm to construct a Hadamard orthogonal basis matrix with an order of half the length of the data frame. Therefore, the order of the Hadamard matrix is , the system generates a The standard Hadamard matrix , all of whose elements are or .

[0060] Then, the aforementioned 256-bit communication data frame binary sequence, specifically the sequence "0001000100100010…11101111" (here showing the binary form of one byte at the beginning and one byte at the end), is converted into a decimal value vector. The conversion rule is: divide this binary sequence into segments of 8 bits each, convert each segment (one byte) into a decimal integer from 0 to 255, and then convert the integer into a decimal integer using the formula Perform normalization processing, where is the value of the corresponding bit (0 or 1), so that each normalized value Between 0.0 and 1.0, for example, the first byte "00010001" has a decimal value of 17, and its normalized value is , the decimal value of the second byte "00100010" is 34, and its normalized value is , and so on, eventually forming a vector containing 256 normalized decimal values .

[0061] Since the Hadamard matrix The row vector length is 128, and the data vector The length is 256, so the data vector Split into two sub-vectors of length 128: and , the system compares these two sub-vectors with the Hadamard matrix Every row vector of (in Perform element-by-element multiplication from 1 to 128 and accumulate the product results to obtain two accumulated value sequences and ,in (X is A or B).

[0062] The system then calculates these two cumulative value sequences and The standard deviation of the adjacent cumulative values ​​in , specifically, for the sequence ,calculate , ,…, , and obtain a standard deviation sequence , also for generate Then, the boundaries of the segments are determined based on the mutation points where the rate of change of these standard deviation sequences exceeds a preset threshold. The setting is based on the statistical analysis of the standard deviation change rate at the boundaries of stable data segments and known segments in a large amount of historical communication data. In stable data segments, the standard deviation change rate is usually maintained in a low range, such as 0.05 to 0.20. However, at the boundaries of segments where the data content or structure changes, this change rate will increase significantly, generally in the range of 0.60 to 1.20. In order to effectively distinguish between the two and reduce misjudgment, Set it to a value that can provide good discrimination. The calculation process is as follows: collect 1000 samples of the standard deviation change rate of the stable segment and the boundary point. The mean of the stable segment samples is 0.12, the standard deviation is 0.04, the mean of the boundary point samples is 0.90, and the standard deviation is 0.10. Set is the mean of the stable segment + 5 times the standard deviation, that is, , and this value is much lower than the boundary point mean -3 times the standard deviation ( ), take the middle value In actual calculation, if the current standard deviation is , the previous standard deviation is ( ), then the rate of change ,when When the time point Mark as a potential segment block boundary. By this method, multiple boundary points are identified in the entire 256-bit data frame, such as , , The system identifies the mutation points at the bit positions, which are the boundaries of the segments. The system counts the number of bits between these boundaries as the length of the corresponding segments. For example, the length of the first segment is 64 bits, and the length of the second segment is bits, the third segment length is bits, the last segment length is bits, and finally generates the segment segmentation parameters containing the starting offset and length information of each segment.

[0063] S103: Based on the segment starting offset in the segment segmentation parameter, calculate the hexadecimal address bit according to the 8-bit per byte rule, divide the segment length value by 8 and round up to get the byte value, extract the Hadamard orthogonal basis matrix row index value and map it to the weight coefficient, integrate the address bit, byte value and weight coefficient into a structured table to obtain the segment index table.

[0064] The segment segmentation parameters generated in step S102 include the starting offset and length of each segment. The starting offset of the first segment is defined as 0 bits, and its length is 64 bits; the starting offset of the second segment is 64 bits, and its length is 56 bits; the starting offset of the third segment is 120 bits, and its length is 72 bits; the starting offset of the fourth segment is 192 bits, and its length is 64 bits. The system converts these starting offsets in bits into hexadecimal address bits according to the rule of 8 bits per byte. The starting offset of the first segment is 0 bits, and its byte offset is Byte, the hexadecimal address is "0x0000", the starting offset of the second segment block is 64 bits, and the byte offset is Byte, the hexadecimal address is "0x0008", the starting offset of the third segment block is 120 bits, and the byte offset is Byte, the hexadecimal address is "0x000F", the starting offset of the fourth segment block is 192 bits, and the byte offset is byte, the hexadecimal address is "0x0018".

[0065] At the same time, divide the length value of each segment (in bits) by 8 and round up to get the value in bytes. The first segment length is 64 bits, and the number of bytes is Bytes, the second segment length is 56 bits, the number of bytes is Bytes, the third segment length is 72 bits, the number of bytes is Bytes, the fourth segment length is 64 bits, the number of bytes is byte.

[0066] Next, the system extracts the row index values ​​of the Hadamard orthogonal basis matrix used in step S102 and maps these row index values ​​(or specific basis vector characteristics associated with the segmentation process) to corresponding weight coefficients The setting of the weight coefficient is intended to reflect the contribution of the corresponding Hadamard basis vector in decomposing the segment block signal or its sensitivity to the segment block data pattern. The specific setting process is: for the Hadamard basis vector with the strongest association with a segment block (for example, the basis vector that plays a decisive role in determining the segment block boundary in the integral segment algorithm, or the basis vector with the largest inner product with the segment block data content), calculate the absolute value of its inner product with the data segment , the system maintains a maximum absolute value of the inner product observed in a large number of typical data analyses (For example, ), then the weight coefficient and ensure that its value is in Within the interval (if the calculated value exceeds 1, it is taken as 1), for the first segment, if the absolute value of the inner product calculated by the strongest associated Hadamard basis vector (row index is 5) is 127.5, then its weight coefficient , for the second segment block (associated row index 12), the absolute value of the inner product is 110.0, then , for the third segment block (associated row index 30), the absolute value of the inner product is 136.5, then , for the fourth segment block (associated row index 67), the absolute value of the inner product is 120.0, then .

[0067] Finally, the system integrates the unique number of each segment block, the calculated hexadecimal starting address, the byte value length, and the mapped weight coefficient into a structured table to form a segment block index table.

[0068] Table 1 Segment block index table

[0069] ;

[0070] As shown in Table 1, this table is a specific example of a segment block index table generated according to step S103. It contains information about four segment blocks. Each entry lists the segment block's unique number, its hexadecimal starting address in the original 32-byte data frame, its length in bytes, and a weight coefficient value between 0 and 1. Assume that the total number of segments in the segment block index table in subsequent processing is 60.

[0071] See also Figure 3 ,The specific steps for obtaining the jump segment block processing path are:

[0072] S201: Based on the master synchronization key group, locate the Nth starting bit, intercept the continuous M-bit binary sequence, convert the binary sequence into a decimal value, extract the last K-bit binary sequence of the master synchronization key group, convert it into a hexadecimal value, and generate an offset parameter and an XOR parameter;

[0073] The value of is the integer part of the logarithm 2 of the total number of segments in the segment index table, that is, ;

[0074] The system first accesses the preset master synchronization key group, which is a fixed binary sequence set to "111111101101101110010111010100110000111011001010100001100100001000011111101101110010111010101001100001110110010101000011001000010001" (this is a 24-byte, 192-bit example).

[0075] parameter The value of is determined by the total number of segments in the segment block index table, which is 60 (following the extended example of Table 1). Based on this, the system locates the 5th bit of the master synchronization key group as the starting bit (bit counting starts from 0, that is, the 6th bit of the master synchronization key group, the original key sequence is "111111101101...", the bold part is the 5th bit).

[0076] The system starts from the 5th starting bit and intercepts the continuous A binary sequence of bits, setting parameters bits, so the intercepted 16-bit sequence is "1101101110010111" (corresponding to hexadecimal 0xDB97). Convert this 16-bit binary sequence "1101101110010111" to decimal value, that is .

[0077] At the same time, the system extracts the key at the end of the master synchronization key group. Bit binary sequence, set parameters The last 8 bits of the master synchronization key group are “00010001” (corresponding to the last part of the key sequence “…0011001000010001”), which is converted into a hexadecimal value, namely “0x11”.

[0078] Thus, the offset parameter (decimal value 56215) and the XOR parameter (hexadecimal value "0x11") are generated.

[0079] S202: Call the index bit value in the segment index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the XOR parameter, perform the XOR operation on each bit, shift the operation result left by K bits, truncate the last M bits of the binary sequence, convert it into a decimal value, and generate the processing path coefficient;

[0080] The index bit value in the segment index table (as shown in Table 1, the total number of segments is 60) generated by the system call S103, where the index bit value is the segment block number. Taking segment block number 1 as an example, its index bit value is 1. This index bit value 1 is converted into a fixed-length binary bit stream, and it is set to uniformly use 8-bit binary representation, then the 8-bit binary of 1 is "00000001".

[0081] The binary bit stream "00000001" is aligned with the bit width (8 bits) of the XOR parameter "0x11" generated in S201 (its 8-bit binary value is "00010001"). After confirming that the bit widths are consistent, the XOR operation is performed bit by bit: The result of the operation is binary "00010000" (that is, hexadecimal 0x10).

[0082] Then, the result of this operation "00010000" is logically shifted left. Bit operations, where (From S201), executed in a 16-bit operation space (high bit shift out, low bit filled with 0), "0000000000010000" is shifted left 8 bits to get "0001000000000000".

[0083] Finally, the last digit is intercepted from the result "0001000000000000" after left shift. bit binary sequence, where (from S201), i.e., intercept the entire "0001000000000000" and convert it into a decimal value. , which is the processing path coefficient generated for the original index bit value 1. The same calculation process is performed for each index bit value (1 to 60) in the segment block index table to obtain the respective processing path coefficients.

[0084] S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the total number of segments and blocks on the addition result, map the remainder to the index bit value of the segment and block index table, rearrange the segment and block index bits in the order of the remainder, and generate a skipping segment and block processing path.

[0085] Add the offset parameter (56215) obtained in S201 to the processing path coefficient calculated for the specific original index bit value in S202. For the original index bit value 1, the processing path coefficient is 4096. The result of adding the two is .

[0086] The total number of segments is modulo the sum of the blocks, which is 60 (from S201). ), then : The remainder is 11.

[0087] The system maps this remainder 11 to the index bit value of the segment block index table, which means that in the new skip processing path, the segment block originally processed in the first order is now processed in the order represented by index 11. The calculation steps S202 and S203 are performed on all 60 original index bit values ​​(1, 2, ..., 60) in the segment block index table to obtain a sequence of 60 new index bit values. The order of this sequence defines the skip segment block processing path. For example, if the original index 1 is mapped to the new index 11, the original index 2 is mapped to the new index 45 after calculation, the original index 3 is mapped to the new index 2, and so on. The final skip segment block processing path is , replacing the original sequential processing path .

[0088] See also Figure 4 ,The specific steps for obtaining the tampering risk coefficient and risk segment block set are:

[0089] S301: Based on the satellite three-axis coordinate parameters and the timestamp sequence, detect the interval mutation points between adjacent timestamps in the jump segment processing path, use the mutation points as the time window boundaries, cut the segments at a fixed step size, and generate a segment time window sequence;

[0090] Based on the jump-type segment processing path generated in S203, the system retrieves the satellite three-axis coordinate parameters (X, Y, Z, unit: km) and the corresponding timestamp sequence (unit: second, accurate to millisecond) corresponding to each segment in the path, and obtains a time-ordered coordinate and timestamp data set: timestamp sequence Coordinate sequence The specific values ​​are: , , , , (The time interval changes here) , , .

[0091] The system detects whether there is a mutation point between adjacent timestamps in this path and calculates the interval between each adjacent timestamp: , , (significantly larger than the preceding interval), , , the mutation judgment standard is: when a certain time interval Both conditions are met at the same time: 1) greater than the previous valid time interval of times, 2) Itself is greater than a minimum reference interval , then it is believed that and Between (or marked points ) There is a mutation. Parameters The setting of refers to the fluctuation of the timestamp interval under normal communication conditions. Under normal circumstances, The ratio of is usually between 0.8 and 1.2 with a small fluctuation. To ensure that the real transmission interruption or delay caused by the interval mutation rather than the normal scheduling jitter can be detected, The value is set to 3.0, the minimum base interval Set to (twice the normal maximum interval) to filter out small interval changes that do not constitute the meaning of window segmentation. In the above data, , . , this value is greater than ,and Greater than , so in and Between (marked points ) is determined as a time interval mutation point.

[0092] The system uses these identified mutation points as the natural boundaries of the time window and combines them with a fixed step size (set to twice the interval between two sampling points in normal circumstances) to cut the data segments and generate a sequence of segment time windows. The first window W1 contains arrive Data (duration ), because in A mutation is detected at , W1 ends here, and the second window W2 starts from the first timestamp immediately after the mutation Start, including Data (duration ). Window W1 data: Window W2 data: .

[0093] S302: Calling the grayscale correlation analysis model to extract the three-axis coordinate parameters of each window in the segment time window sequence, calculating the change rate of the coordinate parameters of adjacent timestamps within the window, synchronously extracting the coordinate data of the corresponding timestamps in the masked interval, calculating the difference in time series synchronization between the two, and performing cumulative integral difference analysis on the difference sequence using the gray absolute correlation algorithm to generate a correlation matrix;

[0094] The calculation formula of the grey absolute correlation algorithm is:

[0095] ;

[0096] in is the coordinate change rate of the segment time window, is the coordinate change rate of the masking interval;

[0097] The system calls the grayscale correlation analysis model to process the segment time window sequence generated by S301 and analyzes the data in each window. Take window W1 as an example, which contains data points The system calculates the rate of change of the three-axis coordinate parameters between adjacent time stamps in this window to form a reference sequence . X-axis coordinate change rate :

[0098] ;

[0099] ;

[0100] Therefore, the X-axis reference sequence of window W1 is (Unit: km / s). Similarly, calculate the rate of change of the Y and Z axes:

[0101] Y-axis:

[0102] ;

[0103] ;

[0104] ;

[0105] Z-axis:

[0106] ;

[0107] ;

[0108] .

[0109] At the same time, the system extracts satellite coordinate data corresponding to the timestamp in a theoretical "shielding interval" (or ideal state without interference) that is predefined or predicted by the model, and calculates its rate of change to form a comparison sequence. The comparison sequence data is derived from the predicted values ​​of the satellite orbit dynamics model under the assumption of no signal interference or tampering. For the two time sub-segments of window W1, the predicted X-axis coordinate change rate sequence is (unit km / s), Y axis is , the Z axis is .

[0110] The system uses the grey absolute correlation algorithm Comparing these two sequences ( and ) of the timing synchronization difference, before applying this formula, in order to ensure the comparability of each item and eliminate the influence of the absolute value size, all the change rate values ​​( and ) are obtained by dividing by a reference rate of change Perform unit-free processing so that the constant '1' in the formula and the processed rate of change value can be compared on the same scale. The conversion rule is: if the original rate of change is , then the unitless value used in the formula is ,For example, Change to a unitless value of 0.50. Take the first comparison point on the X axis For example: after denormalization: , .

[0111] ;

[0112] The second comparison point on the X axis : After decomposition: , .

[0113] ;

[0114] X-axis average correlation of window W1 ;

[0115] Similarly, the calculations are performed for the Y and Z axes: : ;

[0116] ;

[0117] Y-axis : ;

[0118] ;

[0119] ;

[0120] Z-axis : ;

[0121] ;

[0122] Z-axis : ;

[0123] ;

[0124] ;

[0125] Comprehensive correlation of window W1 is the arithmetic mean of the average correlation of the three axes:

[0126] ;

[0127] This calculation is performed for all time windows, forming a sequence containing the comprehensive correlation values ​​for each window, namely the correlation matrix (here, a one-dimensional vector). The formula is beneficial in that, by comprehensively considering the values ​​and differences of the reference and comparison sequences at corresponding points, it can quantitatively assess the degree of morphological similarity between the two time series. Even if there are slight deviations in their absolute values, it can effectively reflect the consistency of their dynamic trends.

[0128] Table 2 Satellite coordinate change rate and correlation calculation example

[0129] ;

[0130] As shown in Table 2, the table lists the data and results of the gray absolute correlation calculation for the X-axis coordinate change rate of window W1 (after unit-free processing) in step S302, including the change rate of the reference sequence, the change rate of the comparison sequence, and the calculated point-by-point correlation.

[0131] S303: Traverse the correlation value of each window in the correlation matrix, compare the value with the tampering judgment threshold, record the window index below the threshold, count the proportion of the index number and extract the corresponding segment block number, and generate the tampering risk coefficient and risk segment block set.

[0132] The system traverses the comprehensive correlation value of each window in the correlation sequence calculated in S302. Assume that the comprehensive correlation of window W1 is 0.9891, the comprehensive correlation of window W2 is 0.7850 after similar calculation, and the comprehensive correlation of window W3 is 0.9725. And so on. The total correlation value is The correlation value of the window.

[0133] The system compares these correlation values ​​with a preset tampering judgment threshold one by one For comparison, this The setting is based on statistical analysis of a large amount of historical data: The real data segments without interference under the mature satellite path are assembled and their correlation with the ideal orbit model prediction is calculated to obtain a normal distribution with a mean of , the standard deviation is , and then collect A group of data segments known to be slightly to moderately interfered or simulated tampered are calculated, and their correlation is obtained to obtain another distribution with a mean of , the standard deviation is ,In order to effectively distinguish normal data from potential risk data, and control the false positive rate and missed negative rate, Set in the critical area of ​​the two distributions, the specific value is ,at the same time, , comprehensive consideration, choose As a decision threshold, this threshold is higher than the correlation degree of most disturbed data and lower than the correlation degree of most normal data.

[0134] The correlation degree of window W1 is 0.9891 and Compare, , it is judged to be normal; the correlation degree of window W2 is 0.7850 and Compare, , judged as risk, record the index of window W2; compare the correlation degree 0.9725 of window W3 with Compare, , judged to be normal. The system counts all In the window, the correlation is lower than Assuming that in addition to W2, the correlation of two windows W8 and W15 is also lower than 0.920, a total of 3 windows are marked as risk windows, and the indexes of these windows are recorded.

[0135] Based on this, the system calculates the tampering risk factor, which is defined as the ratio of the number of windows below the threshold to the total number of windows, that is, This 0.15 represents the tampering risk coefficient obtained in this analysis. The system also extracts the original segment block numbers corresponding to these risk windows (the mapping between segments and windows was established when generating the time window in S301). This forms a risk segment block set. Assuming that window W2 corresponds to segment block DB015, window W8 corresponds to segment block DB042, and window W15 corresponds to segment block DB058, the risk segment block set is {DB015, DB042, DB058}. This result indicates that the data in these three segments differs significantly from expected satellite behavior, indicating a high degree of suspicion of tampering or interference.

[0136] See also Figure 5 , the specific steps for obtaining the encryption key group are:

[0137] S401: Call the dynamic key parameter group in the master synchronization key group, extract the tampering risk coefficient as a weight factor, multiply each parameter item in the dynamic key parameter group by the weight factor, calculate the modulus feature of the product as the first linear transformation input, perform a first round of linear superposition on the key displacement parameter based on the modulus feature, and perform a second linear transformation with the square value of the weight factor to generate a perturbation key vector;

[0138] Modulus characteristics through Galois fields Irreducible polynomials of Computational generation;

[0139] The system calls a dynamic key parameter group stored in the master synchronization key group (from S201), which contains several integer parameter items, set as: The system extracts the tampering risk coefficient calculated in S303 as a weighting factor.

[0140] Combine each parameter item in the dynamic key parameter group with this weight factor Multiply them together to get the weighted parameters: ;

[0141] ;

[0142] ;

[0143] For subsequent Galois field operations, these floating-point results are rounded (floored): , , .

[0144] The system calculates the modulus characteristics of these weighted parameters (in integer form), which are calculated by using the Galois field The operation generation within, the selected irreducible polynomial is (standard AES polynomial), As a polynomial The coefficient of ,exist Calculate the value of this polynomial (for example, consider 22, 12, 31 as domain elements and perform corresponding domain multiplication and addition), and obtain an 8-bit modulus feature after the operation , specific calculation , here represent multiplication, stands for exclusive OR (i.e. Addition). Let the result of the operation be (decimal 163).

[0145] The system uses a preset key shift parameter vector , its length The same as the length of the perturbation key vector to be generated, set (Length is 8). Based on the modulus feature Key shift parameters Each element of Perform the first round of linear superposition, and the transformation rule is , where the system constant .right :

[0146] ;

[0147] right :

[0148] ;

[0149] ...(and so on to get ).

[0150] Then, the displacement parameters after the first round of transformation are With weight factor The square value of is transformed into the second linear transformation to generate the final perturbation key vector Elements of , the square value of the weight factor is , to make it participate in integer arithmetic, multiply it by a scaling factor of 1000 and round it: ;

[0151] The second linear transformation rule is , where the system constant .right :

[0152] ;

[0153] right :

[0154] ;

[0155] right :

[0156] ;

[0157] right :

[0158] ;

[0159] right :

[0160] ;

[0161] right :

[0162] ;

[0163] right :

[0164] ;

[0165] right :

[0166] ;

[0167] The final generated perturbation key vector is (decimal byte value).

[0168] Table 3 Example of the perturbation key vector generation process

[0169] ;

[0170] As shown in Table 3, the table summarizes the steps in step S401 to generate the perturbation key vector The calculation process of some key parameters shows the weighted processing of dynamic parameters, the introduction of modular features of comprehensive calculation, and some intermediate values ​​and final results of two rounds of linear transformation.

[0171] S402: Based on the perturbation key vector, traverse the byte stream of each segment block in the risk segment block set, extract the binary value of each byte in the segment block byte stream, perform an XOR operation on the byte value and the corresponding byte of the perturbation key vector, and perform a left or right shift operation on the XOR result according to the parity bit state of the current byte of the perturbation key vector to generate an intermediate encrypted segment block;

[0172] The system uses the perturbation key vector generated by S401 (length is 8 bytes), traverse each segment block in the risk segment block set {DB015, DB042, DB058} determined in S303, take the risk segment block DB015 as an example, its original byte stream (extracted from the corresponding position of the original communication data frame) is set to (Assume that the length of DB015 is 8 bytes, which is the same as the perturbation key vector; if they are not equal, the perturbation key vector is recycled or aligned according to specific rules).

[0173] The system extracts each byte in the byte stream of segment block DB015 and compares its binary value with the perturbation key vector The corresponding byte of the perturbed key vector is XORed (if the segment length is greater than the key vector length, the key vector is recycled), and then the XOR result is cyclically shifted according to the parity state of the least significant bit (LSB) of the current byte of the perturbed key vector. The rule is: if If the LSB of is 0 (even number), the XOR result is shifted left 1 bit; if the LSB is 1 (odd number), the XOR result is shifted right 1 bit.

[0174] For the first byte of segment block DB015 (decimal 26): corresponds to the perturbation key byte (Binary ). XOR operation: (0xA4). , whose LSB is 0 (even), so the XOR result 164 ( ) Circularly shift left by 1 bit: (0x49). The first byte of the middle encrypted segment block is 0x49.

[0175] The second byte of segment block DB015 (63 in decimal): corresponds to the perturbation key byte (Binary ). XOR operation: (0xFA). , whose LSB is 1 (odd number), so the XOR result 250 ( ) Circularly shift right by 1 bit: (0x7D). The second byte of the middle encrypted segment block is 0x7D.

[0176] The third byte of segment block DB015 (decimal 136): corresponds to the perturbation key byte (Binary ). XOR operation: (0x34). , whose LSB is 0 (even), so the XOR result 52 ( ) Circularly shift left by 1 bit: (0x68). The third byte of the middle encrypted segment block is 0x68.

[0177] Similarly, all bytes of DB015 and all bytes of other segments (DB042, DB058) in the risk segment set are processed, and all processed bytes are combined in the original order to form their respective intermediate encrypted segments. For example, the intermediate encrypted segment generated by segment DB015 .

[0178] S403: For the intermediate encrypted segments, extract the two's complement mapping reference value for each byte, locate the mapping rule in the two's complement mapping table based on the reference value, perform bit-level superposition on the byte data and the mapping rule, and combine the superposition results of all segments to generate a re-encryption key group;

[0179] The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying ,in is the raw bytes, is the Hamming weight.

[0180] The system processes the byte stream of each intermediate encrypted segment block generated in S402, and processes the intermediate encrypted segment block The first byte of For example.

[0181] The system extracts the two's complement mapping reference value of the byte In this embodiment, the complement mapping reference value directly takes the byte value itself, that is, .

[0182] According to this benchmark Locate the mapping rule in a dynamically generated complement mapping table, which is generated in conjunction with the dynamic key parameter group in S401. The parity of the Hamming weight (HammingWeight) is related. First, the binary representation of each parameter and its Hamming weight are calculated: , , , Total Hamming weight. Since the total Hamming weight 10 is an even number, the system selects or generates a set of two's complement mapping tables designed for even Hamming weights. This mapping table maps the base value (0x00-0xFF) to a specific 8-bit mapping rule byte . A fragment of is defined as follows (just an example): - Base value range [0x00-0x0F] -> mapping rule -Base value range [0x10-0x1F]->mapping rules -Base value range [0x40-0x4F]->mapping rules - ... (covering the entire range 0x00-0xFF).

[0183] For the benchmark value , which falls in the range [0x40-0x4F], check The table gets the corresponding mapping rules .

[0184] The system encrypts the byte data of the intermediate segment block The mapping rules found Perform bit-level superposition, where the bit-level superposition operation is defined as an XOR operation, according to the formula (Here is the middle encrypted byte, is the final re-encrypted byte): re-encrypted byte .

[0185] Intermediate encrypted blocks All other bytes ( , ,…) and all intermediate encrypted bytes of other risk segments (DB042, DB058) perform the same “extract reference value -> look up table to obtain mapping rules -> bit-level overlay” operation.

[0186] The byte sequence obtained after the final superposition of all risky segments is combined according to their original segment order and the byte order within the segments to form the final re-encryption key group. This key group is a continuous string of bytes containing the original risky data segments after multiple encryption transformations, and is used for subsequent security applications or to replace the original risky data. In this method, the complement mapping table is dynamically generated or selected based on the Hamming weight parity of the dynamic key parameter group, ensuring the variability of the mapping rules themselves and enhancing security.

[0187] A satellite signal anti-tampering system is provided, which is used to implement the above-mentioned satellite signal anti-tampering method. The system includes:

[0188] The frame segment cutting module is used to obtain the communication data frame through the satellite orbit number and the real-time position vector, input the communication data frame into the Hadamard integral segment algorithm to perform non-equal length segment block cutting, generate a segment block index table, record the starting address bit, segment block length value and initial weight bit value, and pass the segment block index table to the key path generation module;

[0189] A key path generation module is configured to extract the subkey sequence from the Nth to the N+Mth bits from the master synchronization key group as an offset parameter, extract the last K bits as a shift XOR parameter, perform an XOR operation on the starting address bit and the initial weight bit value in the segment block index table, and input the XOR operation into a logic rotation function to generate a skip segment block processing path, and pass the skip segment block processing path to the risk assessment module;

[0190] The risk assessment module is used to input the jump-type segment processing path into the grayscale correlation analysis model through the satellite three-axis coordinate parameters and the timestamp sequence, calculate the correlation between the segment time window and the masking interval, determine whether the segment is in a tampering risk state based on a preset correlation threshold, output the tampering risk coefficient and the risk segment set, and pass the tampering risk coefficient and the risk segment set to the dynamic encryption module;

[0191] The dynamic encryption module is used to call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform perturbation operation on the key shift parameter through the double linear mapping function to generate a re-encryption key group, and perform byte-by-byte exclusive OR and logical shift operations on the risk segment block set, and pass the re-encryption key group to the satellite communication link for data encapsulation.

[0192] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.

Claims

1. A satellite signal anti-tampering method, characterized in that: The following steps are involved: S1: Obtain the current communication data frame through the satellite orbit number, real-time position vector and timestamp, input the data frame into the Hadamard integral segment algorithm to perform non-equal length segment cutting, generate a segment block index table, and record the starting address bit, segment block length value and initial weight bit value; The matrix generation rule in the Hadamard integral segment algorithm is: when the data frame length is an odd number, round the data frame length up to the nearest integer. And truncate the effective bits to construct a Hadamard orthogonal basis matrix with an order of half the length of the truncated data frame; 、 The value of is determined dynamically by taking the modulo operation of the total number of segments based on the hash value of the satellite orbit number; The correlation threshold is obtained by optimizing the historical tampering dataset based on the gradient descent method, and its value range is ; The steps for obtaining the segment block index table are specifically as follows: S101: Obtain the real-time position vector and timestamp corresponding to the satellite orbit number, extract the binary communication data stream through the satellite communication link parsing protocol, parse the start byte and end byte fields in the protocol frame header identifier, locate the valid data segment based on the field length and checksum verification result, intercept the continuous data segment after the frame header identifier, and generate a communication data frame; S102: Invoking the matrix generation rule in the Hadamard integral segment algorithm, constructing a Hadamard orthogonal basis matrix with an order of half the data frame length, converting the binary sequence of the communication data frame into a decimal numerical vector, performing element-by-element multiplication with the matrix row vector and accumulating the sum, calculating the standard deviation of adjacent accumulated values, and determining the segment block boundary based on the mutation point where the standard deviation change rate exceeds a preset threshold, counting the number of bits between the boundaries as the length value, and generating the segment block segmentation parameter; The conversion method of the decimal value vector is: convert the binary sequence into 8-bit segments Normalized values ​​satisfy ,in is a binary bit value; S103: Based on the segment start offset in the segment segmentation parameter, calculate the hexadecimal address bit according to the 8-bit per byte rule, divide the segment length value by 8 and round up to obtain a byte value, extract the row index value of the Hadamard orthogonal basis matrix and map it to a weight coefficient, integrate the address bit, byte value and weight coefficient into a structured table to obtain a segment index table; S2: Based on the master synchronization key group, extract the subkey sequence from the Nth to the N+Mth bits as the offset parameter, extract the last K bits as the shift XOR parameter, perform an XOR operation on the index bit values ​​of multiple items in the segment block index table, and perform a logical rotation operation on the operation results to generate a skip segment block processing path; The steps for obtaining the skip-type segment block processing path are specifically as follows: S201: Based on the master synchronization key group, locate the Nth starting bit, intercept the continuous M-bit binary sequence, convert the binary sequence into a decimal value, extract the last K-bit binary sequence of the master synchronization key group, convert it into a hexadecimal value, and generate an offset parameter and an XOR parameter; described The value of is the integer part of the logarithm 2 of the total number of segments in the segment index table, that is, ; S202: Call the index bit value in the segment index table, convert each index bit value into a binary bit stream, align the hexadecimal bit width of the XOR parameter, perform the XOR operation on each bit, shift the operation result left by K bits, truncate the last M bits of the binary sequence, convert the result into a decimal value, and generate a processing path coefficient; S203: Add the offset parameter to the processing path coefficient, perform a modulo operation on the sum of the total number of segments and blocks, map the remainder to the index bit value of the segment and block index table, rearrange the segment and block index bits in the order of the remainder, and generate a skipping segment and block processing path; S3: Based on the satellite three-axis coordinate parameters and the timestamp sequence, the skipping segment processing path is input into the grayscale correlation analysis model to calculate the correlation between the segment time window and the masking interval. Based on the correlation threshold, it is determined whether the segment is in a tampering risk state, and the tampering risk coefficient and the risk segment set are output. The steps for obtaining the tampering risk coefficient and the risk segment block set are specifically as follows: S301: Based on the satellite three-axis coordinate parameters and the timestamp sequence, detect the interval mutation points between adjacent timestamps in the jump segment processing path, use the mutation points as the time window boundaries, cut the segments at a fixed step size, and generate a segment time window sequence; S302: Calling a grayscale correlation analysis model to extract the three-axis coordinate parameters of each window in the segment time window sequence, calculating the rate of change of the coordinate parameters between adjacent timestamps within the window, synchronously extracting the coordinate data of the corresponding timestamps in the masked interval, calculating the difference in time series synchronization between the two, and performing cumulative integral difference analysis on the difference sequence using a gray absolute correlation algorithm to generate a correlation matrix; The calculation formula of the grey absolute correlation algorithm is: ; in is the coordinate change rate of the segment time window, is the coordinate change rate of the masking interval; S303: traverse the correlation value of each window in the correlation matrix, compare the value with the tampering judgment threshold, record the window index below the threshold, count the proportion of the index number and extract the corresponding segment block number, and generate a tampering risk coefficient and a risk segment block set.

2. The satellite signal anti-tampering method according to claim 1, characterized in that: The jumping segment block processing path includes a dynamic index bit, a rotation offset, and a segment block sequence identifier; the tampering risk coefficient includes a correlation threshold, a risk quantification value, and a period determination mark; and the risk segment block set includes a risk segment block number, a time window label, and a priority identifier.

3. The satellite signal anti-tampering method according to claim 1, characterized in that: The method further comprises: S4: Call the dynamic key parameter group in the main synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key displacement parameter through a double linear mapping function, generate a re-encryption key group, and perform byte-by-byte XOR, logical displacement and complement mapping operations on the risk segment block set.

4. The satellite signal anti-tampering method according to claim 3, characterized in that: The re-encryption key group includes the perturbed displacement parameters, XOR operation order, and complement mapping rules; The dynamic key parameter group is generated by the master synchronization key group through the nonlinear transformation of the elliptic curve, satisfying ,in As the base point, is a random integer, is a prime number.

5. The satellite signal anti-tampering method according to claim 3, characterized in that: The steps for obtaining the re-encryption key group are specifically as follows: S401: calling the dynamic key parameter group in the master synchronization key group, extracting the tampering risk coefficient as a weight factor, multiplying each parameter item in the dynamic key parameter group by the weight factor, calculating the modulus feature of the product as the first linear transformation input, performing a first round of linear superposition on the key displacement parameter based on the modulus feature, and performing a second linear transformation with the square value of the weight factor to generate a perturbation key vector; The modular characteristics are characterized by Galois fields Irreducible polynomials of Computational generation; S402: Based on the perturbation key vector, traverse the byte stream of each segment block in the risk segment block set, extract the binary value of each byte in the segment block byte stream, perform an XOR operation on the byte value and the corresponding byte of the perturbation key vector, and perform a left or right shift operation on the XOR result according to the parity bit state of the current byte of the perturbation key vector to generate an intermediate encrypted segment block; S403: For the intermediate encrypted segments, extract the two's complement mapping reference value for each byte, locate the mapping rule in the two's complement mapping table based on the reference value, perform bit-level superposition on the byte data and the mapping rule, merge the superposition results of all segments, and generate a re-encryption key group; The complement mapping table is dynamically generated according to the Hamming weight parity of the dynamic key parameter group, satisfying ,in is the raw bytes, is the Hamming weight.

6. A satellite signal anti-tampering system, characterized in that: The system is used to implement the satellite signal anti-tampering method according to any one of claims 1 to 5, and the system includes: a frame segment cutting module, configured to obtain a communication data frame using a satellite orbit number and a real-time position vector, input the communication data frame into a Hadamard integral segment algorithm to perform non-equal length segment cutting, generate a segment block index table, record the starting address bit, segment block length value, and initial weight bit value, and pass the segment block index table to the key path generation module; a key path generation module, configured to extract a subkey sequence from the Nth to the N+Mth bits from the master synchronization key group as an offset parameter, extract the last K bits as a shift XOR parameter, perform an XOR operation on the starting address bit and the initial weight bit value in the segment block index table, and input the XOR operation into a logic rotation function to generate a skip segment block processing path, and transmit the skip segment block processing path to the risk determination module; a risk determination module, configured to input the jump-type segment block processing path into a grayscale correlation analysis model using satellite three-axis coordinate parameters and a timestamp sequence, calculate the correlation between the segment block time window and the masking interval, determine whether the segment block is in a tampering risk state based on a preset correlation threshold, output a tampering risk coefficient and a risk segment block set, and transmit the tampering risk coefficient and the risk segment block set to a dynamic encryption module; The dynamic encryption module is used to call the dynamic key parameter group in the master synchronization key group, combine the tampering risk coefficient, perform a perturbation operation on the key shift parameter through a dual linear mapping function to generate a re-encryption key group, perform byte-by-byte exclusive OR and logical shift operations on the risk segment block set, and transmit the re-encryption key group to the satellite communication link for data encapsulation.

Citation Information

Patent Citations

  • Data transmission method and system based on Beidou satellite

    CN118300672A

  • Aviation data bus signal encryption method and system based on FPGA

    CN119420580A