Satellite communication management system and electronic device

By using a key management and encryption system to identify and encrypt satellite telemetry and control messages, the problem of message leakage and tampering in satellite communication systems is solved, and secure and reliable satellite communication management is achieved.

CN120264271BActive Publication Date: 2025-11-18TIANJIN TIANDAHAI TAISHUAN TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510495808.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-11-18
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

Satellite communication systems are vulnerable to attacks, resulting in a high risk of satellite telemetry and control messages being leaked, tampered with, or destroyed during transmission.

Method used

A key management system and an encryption system are adopted. Through the user interface, system platform and data support layer, encryption and decryption algorithms are provided to generate, distribute and update keys, identify satellite telemetry and control message types and perform corresponding encryption or decryption processing, and use frame leader headers and error control fields for identification to ensure the security of messages during transmission.

Benefits of technology

It reduces the risk of satellite telemetry and control messages being leaked, tampered with, or destroyed during transmission, improves communication security, and does not require significant modifications to existing ground station equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264271B_ABST
    Figure CN120264271B_ABST
Patent Text Reader

Abstract

The application provides a satellite communication management system and electronic equipment, and relates to the technical field of satellite communication. The system comprises a key management system and an encryption system. The key management system comprises a user interaction interface, a system platform and a data support layer. The system platform comprises an encryption application interface and a business logic processing module. The encryption application interface is used for providing encryption and decryption algorithms. The data support layer is used for storing system data information including key information. The user interaction interface is used for receiving operation instructions and calling the business logic processing module to update the system data information. The encryption system is used for calling the encryption application interface and performing encryption or decryption processing on satellite measurement and control messages sent by a ground station according to the key information, so as to send the processed messages to the ground station. The system at least provides a technical scheme capable of reducing the risk of leakage, tampering or damage of satellite measurement and control messages in the transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of satellite communication, and in particular to a satellite communication management system and an electronic device. BACKGROUND

[0002] With the rapid development of satellite communication, satellite network technology has been widely used in military, commercial and other fields. In a satellite communication system, a communication link mainly includes an uplink in which a ground station sends information to a satellite, a downlink in which the satellite sends information to the ground station, and an inter-satellite link in which different satellites exchange information. Due to the long communication link, large delay, complex system and other characteristics, the satellite communication system is vulnerable to attacks.

[0003] For satellite measurement and control, whether it is a military communication satellite or a commercial communication satellite, satellite orbit and attitude data, control and attitude adjustment data have very high confidentiality requirements. If the satellite measurement and control message is intercepted or tampered with, the satellite will be directly controlled remotely, causing problems such as deviation from the orbit or even loss of tracking.

[0004] Therefore, how to manage satellite communication to reduce the risk of satellite measurement and control messages being leaked, tampered with or destroyed during transmission is a problem to be solved. SUMMARY

[0005] The present application provides a satellite communication management system and an electronic device, which at least provides a technical solution that can reduce the risk of satellite measurement and control messages being leaked, tampered with or destroyed during transmission.

[0006] Other characteristics and advantages of the present application will become apparent from the following detailed description, or will be learned by practice of the present application.

[0007] According to one aspect of the present application, a satellite communication management system is provided, comprising: a key management system and an encryption system, the key management system comprising a user interaction interface, a system platform and a data support layer, the system platform comprising an encryption application interface and a business logic processing module, the encryption application interface being configured to provide encryption and decryption algorithms; the data support layer being configured to store system data information including key information; the user interaction interface being configured to receive operation instructions, and to call the business logic processing module to update the system data information; the encryption system being configured to call the encryption application interface, and to encrypt or decrypt satellite measurement and control messages sent by a ground station according to the key information, so as to send the processed messages to the ground station.

[0008] Through the user interaction interface, the administrator can call the business logic processing module to update the key information and other contents stored in the system, and through the encryption system, satellite TT&C messages sent by the ground station can be encrypted or decrypted, so that the satellite TT&C messages between the satellite and the ground station can be in an encrypted state, thereby reducing the risk of leakage, tampering or damage of the satellite TT&C messages in the transmission process.

[0009] In some embodiments, the user interaction interface includes an administrator management sub-interface, a key management sub-interface, an injector management sub-interface, a data management sub-interface, and a log management sub-interface; the business logic processing module is configured to provide administrator management logic, key management logic, injector management logic, data management logic, and log management logic; and the data support layer is configured to store an administrator information table, a key information table recording the key information, an injector information table, a data backup information table, an event log table, an administrator log table, a satellite device log table, and a satellite device information table.

[0010] By configuring multiple sub-interfaces, multiple management logics, and multiple tables, the functionality of the system can be enhanced, thereby facilitating better management of satellite communication.

[0011] In some embodiments, the key management logic includes key generation logic, key storage logic, and key distribution logic; the key management sub-interface is configured to receive a key generation operation instruction to facilitate calling the key generation logic and the key storage logic to generate and store a key; and the key management sub-interface is further configured to receive a key distribution operation instruction to facilitate calling the key distribution logic to distribute the key to a satellite through the ground station.

[0012] Generating, updating, and distributing keys using the satellite communication management system can reduce the complexity of the operation of the ground station, and by distributing the keys, the freshness of the keys in the satellite can be maintained, thereby reducing the risk of key leakage and improving the security of satellite TT&C messages encrypted using the highly fresh keys in the transmission process.

[0013] In some embodiments, the encryption system includes a message identification unit configured to identify the type of satellite TT&C messages sent from the ground station; a message decryption unit configured to, when the type is telemetry ciphertext, call the encryption application interface to decrypt the satellite TT&C messages, so as to send the decrypted telemetry messages obtained by decryption to the ground station; and a message encryption unit configured to, when the type is telecontrol plaintext, call the encryption application interface to encrypt the satellite TT&C messages according to the key information, so as to send the encrypted telecontrol messages obtained by encryption to the ground station.

[0014] By judging the type of the satellite TT&C message after obtaining the satellite TT&C message, and by decrypting the satellite TT&C message when the type is telemetry ciphertext and by encrypting the satellite TT&C message when the type is telecontrol plaintext, the telemetry message transmitted from the satellite to the ground station and the telecontrol message transmitted from the ground station to the satellite are both in the encrypted state, thereby reducing the risk of leakage, tampering or damage of the satellite TT&C message (telemetry message and telecontrol message) in the transmission process.

[0015] In some embodiments, the type of the satellite TT&C message is telemetry message or telecontrol message, the frame header of the telemetry message includes a first field, the frame header of the telecontrol message includes a second field, the first field and the second field are both used to indicate the plaintext / ciphertext state of the message; a message identifying unit is configured to determine the type of the satellite TT&C message; when the type of the satellite TT&C message is telemetry message, the plaintext / ciphertext state of the satellite TT&C message is determined according to the content of the first field to obtain a first result, and when the first result is ciphertext, it is determined that the type of the satellite TT&C message is telemetry ciphertext; when the type of the satellite TT&C message is telecontrol message, the plaintext / ciphertext state of the satellite TT&C message is determined according to the content of the second field to obtain a second result, and when the second result is plaintext, it is determined that the type of the satellite TT&C message is telecontrol plaintext.

[0016] The first field or the second field added in the frame header provides a way to indicate the type of the satellite TT&C message, thereby facilitating the additional setting of a satellite communication control system outside the ground station to assist the ground station in managing the key and in encrypting / decrypting the satellite TT&C message, so as to ensure the security of the satellite TT&C message interaction between the ground station and the satellite and avoid complicating the ground station. Further, the existing ground station can be improved without making great changes to the existing ground station.

[0017] In some embodiments, when the type of the satellite TT&C message is telecontrol plaintext, the satellite TT&C message includes a frame header, a frame data field and an error control field; the frame header includes a second field, the frame data field includes a data field and a password field; the message encryption unit is configured to obtain a first key and corresponding decryption information from the key information, call the encryption application interface to encrypt the content in the data field according to the first key, and insert the decryption information into the password field, the decryption information being used to assist in decrypting the encrypted telecontrol message; the content of the second field is modified so that the modified content indicates that the message has been encrypted; the check code of the frame header and the frame data field is calculated and inserted into the error control field.

[0018] The frame data field of the remote control message is divided into data and password fields, decryption information is inserted into the password field, and the original error control field in the remote control message is used to write a check code, so that encryption of the remote control plaintext is realized without affecting the original function of the remote control plaintext and without further increasing the length of the message.

[0019] In some embodiments, when the type of the satellite TT&C message is telemetry ciphertext, the satellite TT&C message comprises a frame header, an insertion field, a frame data field and an error control field; the frame header comprises a first field, the insertion field comprises a password field and a key telemetry and fixed telemetry field; the content of the password field comprises decryption information; the content of the error control field comprises a check code; the message decryption unit is configured to call the encryption application interface and decrypt the content of the key telemetry and fixed telemetry field and the content of the frame data field according to the decryption information; calculate the check code of the content of the frame header, the insertion field and the frame data field after decryption, and compare the calculation result with the check code included in the error control field, and complete decryption when the comparison result is the same.

[0020] The insertion field of the telemetry message is divided into a password field and a key telemetry and fixed telemetry field, decryption information is inserted into the password field, and the original error control field in the telemetry message is used to write a check code, so that encryption and decryption of the telemetry plaintext are realized without affecting the original function of the telemetry message and without further increasing the length of the message, which is beneficial to improving the original telemetry message and has low improvement difficulty.

[0021] In some embodiments, the key information comprises a key state, and the key state comprises unused; the key distribution logic comprises: sending a request distribution key signaling to the ground station; receiving a remote control message fed back by the ground station in response to the distribution key signaling, the remote control message comprising a frame header, a frame data field and an error control field, the frame header comprising a second field, the frame data field comprising a data field and a password field, the content of the second field indicating that the type of the remote control message is a key distribution type remote control plaintext; obtaining a plurality of keys, a second key and corresponding decryption information in the state of unused from the key information; modifying the content of the data field to the plurality of keys; calling the encryption application interface to encrypt the content in the data field according to the second key, and inserting the decryption information into the password field; calculating the check code of the frame header and the frame data field, and inserting the check code into the error control field to obtain a key distribution remote control message; sending the key distribution remote control message to the ground station, so that the ground station forwards the key distribution remote control message to the satellite.

[0022] The second field is further used to divide the remote control plaintext into the key distribution type remote control plaintext, which increases the functionality of the second field and avoids adding an extra field to identify the key distribution type remote control plaintext. In addition, the remote control message carries a plurality of unused keys, which are encrypted and sent to the satellite, making the key distribution more secure, avoiding the leakage of the key in the distribution stage, and improving the security of satellite encrypted communication.

[0023] In some embodiments, the length of the first field is not less than 2 bits and / or the length of the second field is not less than 2 bits.

[0024] According to another aspect of the present application, an electronic device is provided, which is configured with a satellite communication management system such as described in any one of the above embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0025] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application. It is to be expressly understood, however, that the drawings are included herein for illustrative purposes only and do not represent a limitation of the application. Those of ordinary skill in the art will readily recognize a wide variety of alternative

[0026] Figure 1 FIG. 1 shows a schematic diagram of a satellite communication management system in an embodiment of the present application;

[0027] Figure 2 FIG. 2 shows a schematic diagram of a structure of a remote control message in an embodiment of the present application;

[0028] Figure 3 FIG. 3 shows a schematic diagram of a structure of a telemetry message in an embodiment of the present application;

[0029] Figure 4 FIG. 4 shows a schematic diagram of a satellite communication management system in another embodiment of the present application. DETAILED DESCRIPTION

[0030] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations may, however, be implemented in many different forms and should not be construed as limited to the implementations set forth herein; rather, these implementations are provided so that this disclosure will be thorough and complete, and will fully convey the scope of example implementations to those skilled in the art. Features described in the description, structures, or characteristics may be combined in any suitable manner in one or more implementations.

[0031] Furthermore, the accompanying drawings are merely illustrative of this application and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0032] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations.

[0033] To facilitate understanding, before introducing the embodiments of this application, the following explanations are provided for several terms involved in the embodiments of this application:

[0034] Satellite telemetry and control messages: a general term for telemetry and remote control messages in satellite communication. They can be telemetry messages, remote control messages, or encrypted telemetry or remote control messages.

[0035] Telemetry messages: used to transmit measurement data from remote devices (such as satellites, spacecraft, drones, etc.) to ground stations or control centers (hereinafter referred to as ground stations), and are usually sent from remote devices to ground stations;

[0036] Remote control message: Used to send control commands from the ground station to remote equipment in order to achieve remote control of the equipment;

[0037] Telemetry ciphertext: The encrypted telemetry message;

[0038] Decrypting Telemetry Messages: Telemetry Messages

[0039] Remote control plaintext: telemetry message;

[0040] Encrypted remote control message: The encrypted remote control message.

[0041] Key distribution type remote control plaintext: Remote control messages used for key distribution.

[0042] like Figure 1 As shown, the satellite communication management system in this embodiment may include a key management system 1 and an encryption system 2. The key management system 1 includes a user interface 11, a system platform 12 and a data support layer 13. The system platform 12 includes an encryption application interface 121 and a business logic processing module 123.

[0043] Among them, the encryption application interface 121 is used to provide encryption and decryption algorithms.

[0044] Data support layer 13 is used to store system data information, including key information.

[0045] User interface 11 is used to receive operation instructions and call business logic processing module 123 to update system data information.

[0046] Encryption system 2 is used to call encryption application interface 121 and encrypt or decrypt satellite telemetry and control messages sent from the ground station according to key information, so as to send the processed messages to the ground station.

[0047] Through the user interface, administrators can call the business logic processing module to update the key information and other content stored in the system. The encryption system can encrypt or decrypt the satellite telemetry and control messages sent from the ground station, thereby ensuring that the satellite telemetry and control messages between the satellite and the ground station are encrypted, thus reducing the risk of the satellite telemetry and control messages being leaked, tampered with or destroyed during transmission.

[0048] The specific encryption and decryption algorithms provided by the encryption application interface 121 can be varied, and the embodiments of this application do not impose any limitations. For example, symmetric encryption and decryption algorithms, asymmetric encryption and decryption algorithms, hash algorithms, etc.

[0049] The embodiments of this application do not limit the specific information included in the key information. For example, key information may include the key, decryption information, key status, generation time, etc.

[0050] The embodiments of this application do not limit the specific business logic included in the business logic processing module 123. The business logic processing module is mainly used to handle user management, key management, and peripheral device management. For example, the business logic processing module provides administrator management logic, key management logic, injector management logic, data management logic, and log management logic, etc.

[0051] Accordingly, the user interface 11 includes an administrator management sub-interface, a key management sub-interface, an injector management sub-interface, a data management sub-interface, and a log management sub-interface.

[0052] User interface 11 adopts a multi-menu switching mode, which includes a main menu and multiple sub-menus. Each sub-menu corresponds to a sub-interface. The main menu is used to display the entry points of each sub-menu, and the sub-menus are used to display the corresponding sub-interfaces. Based on the user's click on the main menu or sub-menu, the interface determines whether to display the corresponding main interface or sub-interface.

[0053] In one embodiment, the user interface further includes a status display area for displaying the current operation status and system running status in real time.

[0054] In one embodiment, the data support layer stores an administrator information table, a key information table that records the key information, an injector information table, a data backup information table, an event log table, an administrator log table, a satellite equipment log table, and a satellite equipment information table.

[0055] By configuring multiple sub-interfaces, multiple management logics, and multiple tables, the system's functionality can be enhanced, thereby facilitating better management of satellite communications.

[0056] For example, administrators can operate through the administrator management sub-interface to call the corresponding administrator management logic to update the content in the administrator information table. The update methods can be modification, addition, deletion, etc.

[0057] In one embodiment, the key management logic includes key generation logic, key storage logic, and key distribution logic.

[0058] The key management sub-interface is used to receive key generation operation instructions, so as to call the key generation logic and key storage logic to generate and store keys; the key management sub-interface is also used to receive key distribution operation instructions, so as to call the key distribution logic to distribute keys to satellites through ground stations.

[0059] Both key generation and key distribution instructions can be generated by the administrator when performing operations in the key management sub-interface.

[0060] In one embodiment, the administrator table stores administrator account information, permission information, and login records; the event log table records various events during system operation; the key information table stores keys, decryption information, key status, generation time, etc.; the satellite equipment information table stores satellite equipment model, status, and maintenance records; the data backup information table records data backup time, backup content, and backup status; the administrator log table records administrator operations and operation time; and the satellite equipment log table records satellite equipment operating status and fault information.

[0061] By using a satellite communication management system to generate, update, and distribute keys, the complexity of ground station operations can be reduced. Furthermore, by distributing keys, the freshness of keys in the satellite can be maintained, thereby reducing the risk of key leakage and improving the security of satellite telemetry and control messages encrypted with these fresh keys during transmission.

[0062] In one embodiment, the satellite communication management system interacts with the injector via a USB (Universal Serial Bus) interface, and the injector interacts with the satellite (the onboard cryptographic device in the satellite) via an RS422 (a serial communication interface standard belonging to the differential signal transmission protocol) interface.

[0063] After receiving the key distribution operation command in the key management sub-interface, the key distribution logic can be invoked to retrieve multiple keys with an unused status from the key information and send these keys to the injector via the USB interface. The injector then sends these keys to the satellite via the RS422 interface.

[0064] In another embodiment, the key information includes a key status, which includes "unused". The key distribution logic includes: sending a request to distribute a key signaling message to the ground station; receiving a remote control message from the ground station in response to the key distribution signaling message, such as... Figure 2 As shown, the remote control message includes a frame leader header, a frame data field, and an error control field. The frame leader header includes a second field, and the frame data field includes a data field and a password field. The content of the second field indicates that the remote control message type is a key distribution type remote control plaintext. Multiple unused keys, a second key, and corresponding decryption information are obtained from the key information. The content of the data field is modified to include the multiple keys. The encryption application interface is called to encrypt the content in the data field according to the second key, and the decryption information is inserted into the password field. The checksum of the frame leader header and the frame data field is calculated, and the checksum is inserted into the error control field to obtain the key distribution remote control message. The key distribution remote control message is sent to the ground station so that the ground station can forward the key distribution remote control message to the satellite.

[0065] The second key and its corresponding decryption information are any one of the unused keys and its corresponding decryption information, excluding the multiple unused keys in the key information.

[0066] For example, if the second field is 2 bits long, then the content of the second field can be one of four possibilities: 00, 01, 10, or 11. Any one of these three values ​​can be used to indicate that the remote control message is a key distribution type remote control plaintext. For example, if the content of the second field is 10, then the remote control message is a key distribution type remote control plaintext.

[0067] The second field is used to further categorize remote control plaintext into key distribution type remote control plaintext, increasing the functionality of the second field and avoiding the need for additional fields to identify key distribution type remote control plaintext. Furthermore, by using multiple unused keys carried in the remote control message and encrypting them before sending them to the satellite, key distribution becomes more secure, preventing key leakage during the distribution stage and improving the security of satellite encrypted communication.

[0068] In one embodiment, the encryption system includes: a message identification unit, a message decryption unit, and a message encryption unit.

[0069] The message identification unit is used to identify the type of satellite telemetry and control message sent from the ground station.

[0070] The message decryption unit is used to call the encrypted application interface to decrypt the satellite telemetry and control message when the type is telemetry ciphertext, so as to send the decrypted telemetry message to the ground station.

[0071] The message encryption unit is used to call the encryption application interface when the type is remote control plaintext, and encrypt the satellite telemetry and control message according to the key information, so as to send the encrypted remote control message to the ground station.

[0072] By first determining the type of the satellite telemetry and control message after obtaining it, and then decrypting the message when it is telemetry encrypted and encrypting it when it is remote control plaintext, the telemetry messages transmitted from the satellite to the ground station and the remote control messages transmitted from the ground station to the satellite are both encrypted. This reduces the risk of the satellite telemetry and control messages (telemetry messages and remote control messages) being leaked, tampered with, or damaged during transmission.

[0073] Among them, the message type of satellite telemetry and control messages is telemetry message or remote control message.

[0074] In one embodiment, the frame header of a telemetry message includes a first field, and the frame header of a remote control message includes a second field. Both the first and second fields can be used to indicate the plaintext / ciphertext status of the message. Plaintext / ciphertext status refers to whether the message is plaintext or ciphertext. In this case, the message identification unit is used to determine the message type of the satellite telemetry and control message; when the message type is a telemetry message, it determines the plaintext / ciphertext status of the satellite telemetry and control message based on the content of the first field, obtaining a first result; and if the first result is ciphertext, it determines the type of the satellite telemetry and control message as telemetry ciphertext; when the message type is a remote control message, it determines the plaintext / ciphertext status of the satellite telemetry and control message based on the content of the second field, obtaining a second result; and if the second result is plaintext, it determines the type of the satellite telemetry and control message as remote control plaintext.

[0075] The embodiments of this application do not limit how the message type of a satellite telemetry and control message is determined. For example, the message type of a satellite telemetry and control message can be determined directly through the structure of the frame leader header of the satellite telemetry and control message. As another example, the message type of a satellite telemetry and control message can also be determined through the structure of the entire satellite telemetry and control message.

[0076] Once the message type of the satellite telemetry and control message is determined, the content of the first or second field can be read according to the pre-set processing logic, and the encryption status of the satellite telemetry and control message can be determined based on the content of the first or second field.

[0077] In one embodiment, the length of the first field is not less than 2 bits and / or the length of the content of the second field is not less than 2 bits.

[0078] Two bits can represent four combinations: "00", "01", "10" and "11", while only two combinations are needed to indicate whether the message is encrypted or unencrypted. Based on this, the length of the first field and / or the second field is still limited to no less than two bits, which allows the first field to have better scalability. In addition to being used to represent combinations of encryption and decryption status, it can also be used to represent other information, such as indicating that the type of remote control message is key distribution type remote control plaintext.

[0079] The embodiments of this application do not limit when the contents of the first and second fields indicate that the message is encrypted and when they indicate that the message is not encrypted.

[0080] For example, the length of the first field and the second field is 2 bits, and "00" indicates that the message is not encrypted, and "11" indicates that the message is encrypted.

[0081] Adding a first or second field to the frame header provides a way to identify the message type of satellite telemetry and control messages. This facilitates the establishment of an additional satellite communication and control system outside the ground station to assist the ground station in key management and encryption / decryption of the identified satellite telemetry and control messages. This ensures the security of satellite telemetry and control message exchange between the ground station and the satellite while avoiding complicating the ground station. Furthermore, it facilitates the improvement of existing ground stations without requiring major modifications.

[0082] In one embodiment, such as Figure 3 As shown, when the satellite telemetry and control message type is telemetry encrypted, the satellite telemetry and control message includes a frame leader header, an insertion field, a frame data field, and an error control field. The frame leader header includes a first field, the insertion field includes a password field and key telemetry and fixed telemetry fields, the password field contains decryption information, and the error control field contains a checksum. In this case, the message decryption unit calls the encryption application interface and decrypts the contents of the key telemetry and fixed telemetry fields and the frame data field according to the decryption information; it calculates the checksum of the contents of the decrypted frame leader header, insertion field, and frame data field, compares the calculation result with the checksum included in the error control field, and completes decryption if the comparison results are the same.

[0083] The embodiments in this application do not limit the methods for decrypting satellite telemetry and control messages. Decryption can be performed according to the encryption method of the satellite telemetry and control messages.

[0084] In one embodiment, for telemetry messages, the encrypted portion includes the contents of key telemetry and fixed telemetry fields, as well as the contents of the frame data field. The error control field includes a checksum, which is calculated by the satellite based on the contents of the frame header, insertion field, and frame data field.

[0085] The decryption information is used to assist in decrypting telemetry ciphertext.

[0086] The embodiments of this application do not limit how to decrypt the contents of the key telemetry and fixed telemetry fields and the contents of the frame data field based on the decryption information.

[0087] In one embodiment, the key information table includes a first dynamic decryption table, which includes a key number and its corresponding key. The decryption information includes key number information and a first part of key information. The decryption information is obtained by reading the information in the cryptographic field. According to the preset structure of the decryption information, the key number information and the first part of key information can be separated.

[0088] For example, the decrypted information consists of 26 bytes, where the first 2 bytes represent the key number information and the last 24 bytes represent the first part of the key. Based on the structure of this decrypted information, the encryption server can separate the 2-byte key number information and the 24-byte first part of the key information.

[0089] Subsequently, the message decryption unit can obtain the key number based on the key number information, and query the first dynamic decryption table based on the key number to obtain the key corresponding to the key number, and use the obtained key as the second part key. The message decryption unit can also obtain the first part key based on the first part key information, for example, the first part key information is the first part key; or, for example, the message decryption unit processes the first part key information according to preset processing logic to obtain the first part key.

[0090] Then, the message decryption unit generates a decryption key using the first part key and the second part key according to the preset processing method, and then uses the decryption key to decrypt the contents of the key telemetry and fixed telemetry fields and the contents of the frame data field.

[0091] In another embodiment, the decryption information includes key information. The message decryption unit can process the key information according to a preset processing method to obtain a decryption key, and then use the decryption key to decrypt the contents of the key telemetry and fixed telemetry fields and the contents of the frame data field.

[0092] In one embodiment, the satellite and the satellite communication management system have an agreed-upon encryption and decryption method, and the message decryption unit can directly decrypt the telemetry ciphertext.

[0093] By dividing the insertion field of the telemetry message into a cryptographic field and key telemetry and fixed telemetry fields, inserting decryption information into the cryptographic field, and using the original error control field in the telemetry message to write the check code, the encryption and decryption of the telemetry plaintext can be achieved without affecting the original function of the telemetry message and without further increasing the message length. This is beneficial for improving the original telemetry message and the improvement is easy.

[0094] In one embodiment, such as Figure 2 As shown, when the satellite telemetry and control message type is remote control plaintext, the satellite telemetry and control message includes a frame master header, a frame data field, and an error control field; the frame master header includes a second field, and the frame data field includes a data field and a password field. In this case, the message encryption unit is used to obtain the first key and the corresponding decryption information from the key information, call the encryption application interface to encrypt the content in the data field according to the first key, and insert the decryption information into the password field. The decryption information is used to assist in decrypting the encrypted remote control message; the content of the second field is modified so that the modified content indicates that the message has been encrypted; the checksum of the frame master header and the frame data field is calculated, and the checksum is inserted into the error control field.

[0095] In one embodiment, the key information table further includes a first dynamic encryption table, which includes multiple keys for encrypting remote control messages and decryption information corresponding to each key; or, the first dynamic encryption table includes multiple keys for encrypting remote control messages and key information corresponding to each key for generating decryption information. After obtaining the key information, the message encryption unit can generate decryption information based on the key information. After obtaining a key from the first dynamic encryption table, the message encryption unit uses that key as the first key.

[0096] In one embodiment, the decryption information includes key number information and a third part of key information. For details on how the key number information and the third part of key information help the satellite decrypt remote control ciphertext, please refer to the decryption process of the message decryption unit described above.

[0097] In another embodiment, the decryption information includes key information. For details on how the key information helps the satellite decrypt remote control ciphertext, please refer to the process of the message decryption unit decrypting telemetry ciphertext described above.

[0098] In one embodiment, the satellite and the satellite communication management system have an agreed-upon encryption and decryption method, and the message encryption unit can directly encrypt the remote control plaintext.

[0099] For example, if the content of the second field in the remote control plaintext is "00", then "00" will be changed to "11" to indicate that the message is encrypted.

[0100] The embodiments of this application do not limit the method used to calculate the checksums for the frame leader header and frame data fields. For example, the method used to calculate the checksum is to calculate the CRC (Cyclic Redundancy Check) checksum.

[0101] By dividing the frame data field of the remote control message into a data and a password field, inserting the decryption information into the password field, and using the original error control field in the remote control message to write the check code, the encryption of the remote control plaintext is achieved without affecting the original function of the remote control plaintext and without further increasing the message length. This is beneficial for improving the original remote control message and the improvement is easy.

[0102] In one embodiment, the satellite communication management system interacts with the PCI-E cryptographic card via the PCI-E (Peripheral Component Interconnect Express) bus.

[0103] When encryption system 2 encrypts satellite telemetry and control messages, it can send the content to be encrypted in the satellite telemetry and control messages to the PCI-E cryptographic card for encryption via the PCI-E bus.

[0104] In one embodiment of this application, the electronic device may include the satellite communication management system of any of the above embodiments.

[0105] In one embodiment, such as Figure 4 As shown, a satellite communication management system may include: a user interface, a system platform, a data support layer, and an operating environment.

[0106] The user interface is used to enable information exchange between users and the system, and includes modules for administrator management, key management, injector management, data management, and log management.

[0107] The system platform includes an encryption application interface and a business logic processing module. The encryption application interface is configured to provide cryptographic services using symmetric encryption and decryption algorithms, asymmetric encryption and decryption algorithms, and hash algorithms.

[0108] The business logic processing module is used to handle user management, key management and peripheral device management, and interacts with the cryptographic card through the PCI-E bus and with the cryptographic resource injector through the USB interface.

[0109] The data support layer includes an administrator table for storing administrator information, an event log table for recording operation events, a key information table for storing key status, a satellite device information table for managing satellite device information, a data backup information table, an administrator log table, and a satellite device log table.

[0110] The operating environment, including the hardware and software environments, provides secure and stable operating conditions for the data support layer and system platform.

[0111] The satellite communication management system, through the generation, distribution, updating, destruction, and status management of keys, combined with access control and security auditing functions, achieves encryption and protection against eavesdropping and tampering of satellite communication data.

[0112] Users interact with the password key management system through an interactive interface, such as inputting key management information and issuing key management operations. The key management system then presents the operation results through the interactive interface, allowing users to view, analyze, and understand the system's operating results and status.

[0113] In one embodiment, the system platform further includes a network communication module. The network communication module is responsible for enabling external data network communication, such as acquiring satellite telemetry and control messages to be transmitted and transmitting the processed satellite telemetry and control messages to the receiving end.

[0114] User management includes creating a super administrator, initializing the system, and creating other administrators. The super administrator creation prompt occurs the first time the password and key management system is run. Once a super administrator is successfully created, the key management system will no longer provide this function. System initialization is primarily responsible for initializing the uninitialized password and key management system. The initialization process includes system login and distributing administrator information to the key management system. Creating other administrators facilitates a hierarchical management mechanism for the key management system. It first allows users to select and create different administrators, and then assigns them permissions within the maximum scope of their respective administrator types.

[0115] Key management encompasses various operational operations related to working keys, including key generation, destruction, distribution, updating, and viewing. Key management primarily focuses on managing pre-built working keys at ground stations; for ease of management, methods such as key numbering can be employed.

[0116] 1) Record the working key status

[0117] The working key is stored in the system and may be in one of the following states:

[0118] ①Unconfigured state: An unconfigured key refers to a key that has not been configured but has been generated and stored in the system.

[0119] ② Already in use: A key that is already in use means that the key has been assigned to the corresponding satellite system.

[0120] ③ Not generated: The key for the current key number has not yet been generated.

[0121] ④ Unknown state: An unknown state key means that the key number is in an abnormal state due to some kind of error, and human intervention is required.

[0122] 2) Generation of working keys

[0123] The cryptographic key management system provides a key generation function, which supports generating a set of symmetric keys based on key numbers, or generating multiple sets of keys based on a range of key numbers.

[0124] 3) Working key update

[0125] The working key update function updates the corresponding key when it is not yet assigned. Working key updates are only supported in the unassigned state. If the working key has already been assigned to a satellite, updates are not allowed.

[0126] 4) Working key distribution

[0127] The cryptographic key management system automatically distributes working keys according to the workflow.

[0128] 5) Working key injection

[0129] The cryptographic key management system requires injecting the key into the injector by selecting a key file.

[0130] 6) Destroying the working key

[0131] The key management system should provide users with the function of destroying the key. Key destruction means destroying the key corresponding to the key number. Destruction can only be successful when the corresponding key is in an unused state.

[0132] 7) Check the working key status

[0133] The cryptographic key management system supports querying the status of working keys, returning whether the working key has been injected into the key resource injector and the current key number of the corresponding working key.

[0134] Electronic device management includes key resource injector management, which involves managing the key resource injector and viewing its operational status. Key resource injector management can include:

[0135] 1) Working key injection

[0136] The cryptographic key management system requires injecting the key into the injector by selecting a key file.

[0137] 2) Working key update

[0138] The working key update function updates the corresponding key when the key resource has not been injected into a satellite. Working key updates only support the state where no satellite has been injected. If a satellite has been injected, the system will not allow working key updates.

[0139] 3) Destruction of working key

[0140] The password key management system needs to provide users with the function of destroying this key. Key destruction means destroying the key corresponding to the key number. Destruction can only be successful if the corresponding key has not been injected into the satellite.

[0141] 4) Check the injector status

[0142] The cryptographic key management system supports querying the status of the injector and returns whether the resources in the injector have been injected into the satellite platform.

[0143] In one embodiment, the data layer is the database of the satellite communication system, providing the necessary information, data, and other resources to each subsystem of the satellite communication system.

[0144] The password key management system database stores data including administrator-related information, event log information, key information, satellite device information, and data backup information. Different tables are used in the database to store this information: the administrator table, the event log table, the key information table, the satellite device information table, and the data backup information table. To illustrate the relationship structure between the databases, an administrator log table and a satellite device log table are added.

[0145] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the appended claims.

Claims

1. A satellite communication management system, characterized in that, include: A key management system and an encryption system, wherein the key management system includes a user interface, a system platform and a data support layer, and the system platform includes an encryption application interface and a business logic processing module; The encryption application interface is used to provide encryption and decryption algorithms; The data support layer is used to store system data information, including key information; The user interface is used to receive operation instructions and call the business logic processing module to update the system data information. The encryption system is used to call the encryption application interface and encrypt or decrypt the satellite telemetry and control messages sent from the ground station according to the key information, so as to send the processed messages to the ground station. The encryption system includes: a message identification unit, a message decryption unit, and a message encryption unit; The message identification unit is used to identify the type of satellite telemetry and control message sent from the ground station; the message decryption unit is used to call the encryption application interface to decrypt the satellite telemetry and control message when the type is telemetry encrypted message, so as to send the decrypted telemetry message to the ground station. When the satellite telemetry and control message is of the telemetry encrypted type, the satellite telemetry and control message includes a frame leader header, an insertion field, a frame data field, and an error control field; the frame leader header includes a first field, the insertion field includes a cryptographic field and key telemetry and fixed telemetry fields; the cryptographic field includes decryption information; the error control field includes a checksum. The message decryption unit is used to call the encryption application interface and decrypt the contents of the key telemetry and fixed telemetry fields and the contents of the frame data field according to the decryption information; calculate the check codes of the contents of the frame header, insertion field and frame data field after decryption, compare the calculation results with the check codes included in the error control field, and complete the decryption if the comparison results are the same. The key information table includes a first dynamic decryption table, which includes a key number and the corresponding key; the decryption information includes key number information and a first part of key information. The message decryption unit is configured to obtain a key number based on the key number information, query a first dynamic decryption table based on the key number to obtain the key corresponding to the key number, and use the obtained key as a second part key; obtain a first part key based on the first part key information; generate a decryption key using the first part key and the second part key according to a preset processing method; and decrypt the contents of the key telemetry and fixed telemetry fields and the contents of the frame data field using the decryption key.

2. The satellite communication management system according to claim 1, characterized in that, The user interface includes an administrator management sub-interface, a key management sub-interface, an injector management sub-interface, a data management sub-interface, and a log management sub-interface. The business logic processing module is used to provide administrator management logic, key management logic, injector management logic, data management logic, and log management logic; The data support layer is used to store the administrator information table, the key information table that records the key information, the injector information table, the data backup information table, the event log table, the administrator log table, the satellite equipment log table, and the satellite equipment information table.

3. The satellite communication management system according to claim 2, characterized in that, The key management logic includes key generation logic, key storage logic, and key distribution logic; The key management sub-interface is used to receive key generation operation instructions, so as to call the key generation logic and the key storage logic to generate and store the key; The key management sub-interface is also used to receive key distribution operation instructions, so as to invoke the key distribution logic and distribute the key to the satellite through the ground station.

4. The satellite communication management system according to claim 1, characterized in that, The message encryption unit is used to call the encryption application interface when the type is remote control plaintext, and encrypt the satellite telemetry and control message according to the key information, so as to send the encrypted remote control message to the ground station.

5. The satellite communication management system according to claim 4, characterized in that, The satellite telemetry and control message is of the telemetry message or remote control message type. The frame leader header of the telemetry message includes a first field, and the frame leader header of the remote control message includes a second field. Both the first field and the second field are used to indicate the explicit / confidential status of the message. A message identification unit is used to determine the message type of the satellite telemetry and control message; When the message type is a telemetry message, the plaintext / encrypted state of the satellite telemetry and control message is determined based on the content of the first field to obtain a first result. If the first result is encrypted, the type of the satellite telemetry and control message is determined to be telemetry encrypted. When the message type is a remote control message, the plaintext / encrypted state of the satellite telemetry and control message is determined based on the content of the second field to obtain a second result. If the second result is plaintext, the type of the satellite telemetry and control message is determined to be remote control plaintext.

6. The satellite communication management system according to claim 4, characterized in that, When the satellite telemetry and control message is of the type of remote control plaintext, the satellite telemetry and control message includes a frame leader header, a frame data field, and an error control field; the frame leader header includes a second field, and the frame data field includes a data field and a password field. The message encryption unit is used to obtain a first key and corresponding decryption information from the key information, call the encryption application interface to encrypt the content in the data field according to the first key, and insert the decryption information into the password field. The decryption information is used to assist in decrypting the encrypted remote control message. The content of the second field is modified so that the modified content indicates that the message has been encrypted; Calculate the checksum of the frame leader header and the frame data field, and insert the checksum into the error control field.

7. The satellite communication management system according to claim 3, characterized in that, The key information includes the key status, which includes unused key status; The key distribution logic includes: sending a request for key distribution signaling to the ground station; receiving a remote control message from the ground station in response to the key distribution signaling, the remote control message including a frame leader header, a frame data field, and an error control field, the frame leader header including a second field, the frame data field including a data field and a cryptographic field, the content of the second field indicating that the type of the remote control message is key distribution type remote control plaintext; obtaining multiple keys in an unused state, a second key, and corresponding decryption information from the key information; modifying the content of the data field to the multiple keys; calling the encryption application interface to encrypt the content in the data field according to the second key, and inserting the decryption information into the cryptographic field; calculating the checksum of the frame leader header and the frame data field, and inserting the checksum into the error control field to obtain the key distribution remote control message; and sending the key distribution remote control message to the ground station so that the ground station can forward the key distribution remote control message to the satellite.

8. The satellite communication management system according to claim 5, characterized in that, The length of the first field is not less than 2 bits and / or the length of the second field is not less than 2 bits.

9. An electronic device, characterized in that, It is equipped with a satellite communication management system as described in any one of claims 1-8 above.

Citation Information

Patent Citations

  • A multifunctional measurement and control and data distribution terminal for improving the real-time performance of data transmission

    CN109067451A

  • Satellite measurement and control system, method, device, equipment and medium

    CN115333609A

  • Communication device based on Beidou satellite communication technology

    CN118249889A