Satellite portable station data encryption authentication method and system

By integrating amplifier harmonics and environmental noise in satellite portable stations to generate dynamic keys, combining link stability and spatiotemporal parameters to optimize network switching, the problems caused by static keys and a single signal strength indicator are solved, and communication protection with high security and low latency are achieved.

CN120264274AActive Publication Date: 2025-07-04JIANGSU ANRUIXUN INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510616721.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-07-04
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

The data transmission security of existing satellite portable stations relies on the static key generation mechanism and cannot effectively resist spectrum analysis attacks. Link switching relies on a single signal strength indicator to improperly allocate network resources, terminal identity identification is prone to forgery, and cannot adapt to complex electromagnetic environments and multi-satellite network switching scenarios.

Method used

The fusion key generation technology of amplifier harmonics and environmental noise is adopted, combined with the pre-distribution mechanism that links link stability and spatiotemporal parameters, dynamic key parameters are generated through exclusive or obfuscation processing, and the Beidou positioning module is used to bind the device identity, optimize network resource allocation and switch to the backup link when the signal quality decreases.

Benefits of technology

It realizes high-security and low-latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios, dynamic keys prevent replay attacks, and terminal identity cannot be forged to ensure communication continuity and interception resistance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264274A_ABST
    Figure CN120264274A_ABST
Patent Text Reader

Abstract

The invention discloses a satellite portable station data encryption authentication method and system, and belongs to the technical field of wireless communication network security, and the method comprises the steps: collecting power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of a satellite terminal, and carrying out the XOR confusion processing, and generating a dynamic key parameter; generating a cross-network authentication pre-distribution parameter based on a preset satellite link stability threshold and the signal quality parameter of the current satellite network; and when the signal quality parameter of the satellite network is reduced to a preset switching threshold, extracting a target network session key parameter, and encrypting and sending uplink data in combination with the dynamic key parameter and the cross-network authentication pre-distribution parameter. According to the invention, a power amplifier harmonic wave and environmental noise fusion key generation technology and a link stability and space-time parameter linkage pre-distribution mechanism are adopted, so that high-safety and low-delay communication protection can be realized in a complex electromagnetic environment and a multi-satellite network switching scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless communication network security, and in particular to a method and system for data encryption and authentication of a satellite portable station. Background Art

[0002] As a core device for modern emergency communication and networking in remote areas, the data transmission security of a satellite portable station highly depends on the encryption and authentication mechanism of the wireless link. The existing technologies generally adopt a satellite data protection scheme based on fixed key negotiation and combine terminal identification codes to implement network access control. With the upgrading of wireless network attack means, the traditional methods face severe challenges of key leakage and identity forgery.

[0003] Currently, a key pool is mainly pre-set to achieve session key matching during multi-satellite network switching, and the received signal strength of satellite signals is used to judge the link quality. When the signal attenuates to a preset threshold, key switching is triggered. In addition, some improved technologies introduce terminal hardware feature codes as static identity identifiers and improve the security strength by regularly updating the key strategy.

[0004] However, the static key generation mechanism cannot effectively resist spectrum analysis attacks against fixed encryption rules; the link switching depends on a single signal strength index, resulting in a mismatch between the switching decision and the network load condition; the terminal identity identifier is decoupled from the physical environment and is easily reverse-engineered and replicated to generate a disguised terminal. Summary of the Invention

[0005] To solve the above problems, the present invention provides a method and system for data encryption and authentication of a satellite portable station, which adopts a fusion key generation technology of power amplifier harmonics and environmental noise and a pre-distribution mechanism of link stability and spatio-temporal parameter linkage, and can achieve high-security and low-latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios.

[0006] The above object can be achieved by the following solutions:

[0007] A method and system for data encryption and authentication of a satellite portable station, including collecting the power amplifier non-linear harmonic spectrum data and environmental noise frequency domain energy distribution data of a satellite terminal; performing an exclusive-or confusion process on the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters; generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; sending a pre-authentication data packet including the dynamic key parameters and the cross-network authentication pre-distribution parameters to a multi-network control center through the current effective satellite link; when the signal quality parameters of the satellite network drop to a preset switching threshold, extracting target network session key parameters from a pre-stored backup link key pool; encrypting the uplink data using the target network session key parameters and the pre-authentication data packet to obtain encrypted communication data and sending it through the target satellite link.

[0008] Optionally, the collecting the power amplifier non-linear harmonic spectrum data and environmental noise frequency domain energy distribution data of the satellite terminal includes: in the satellite power amplifier startup stage, continuously collecting multiple harmonic amplitude sequences within a preset frequency band through a preset spectrum analysis module, and calculating the amplitude difference data; performing a chaotic phase mapping process on the amplitude difference data to generate terminal fingerprint parameters; performing a hash binding on the terminal fingerprint parameters and the coordinate parameters obtained through a Beidou positioning module to form the power amplifier non-linear harmonic spectrum data.

[0009] Optionally, the collecting the power amplifier non-linear harmonic spectrum data and environmental noise frequency domain energy distribution data of the satellite terminal further includes: capturing the interference signal spectrum data within a preset frequency band in real time through the receiving link of a flat antenna; performing a multi-order discrete Fourier transform on the interference signal spectrum data to extract the main frequency energy distribution data of a preset sub-harmonic; calculating the information entropy value of the main frequency energy distribution data to generate the environmental noise frequency domain energy distribution data.

[0010] Optionally, the generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network includes: obtaining the chip signal-to-noise ratio parameter and the link delay spread parameter of the current satellite link; inputting the chip signal-to-noise ratio parameter and the link delay spread parameter into a preset stability evaluation model, and outputting a link switching priority parameter according to the preset satellite link stability threshold; generating cross-network authentication pre-distribution parameters according to a preset self-organizing network node distribution density parameter and the link switching priority parameter.

[0011] Optionally, the pre - authentication data packet sent to the multi - network control center through the current valid satellite link and containing the dynamic key parameters and cross - network authentication pre - distribution parameters includes: encrypting the dynamic key parameters using the quantum key distribution algorithm to generate a first - level encrypted payload; performing chaotic confusion on the cross - network authentication pre - distribution parameters and Beidou positioning parameters to generate a second - level confused payload; and performing data sharding and recombination on the first - level encrypted payload and the second - level confused payload to form a pre - authentication data packet.

[0012] Optionally, the extracting of the target network session key parameters from the pre - stored backup link key pool includes: obtaining a candidate key set in the pre - stored backup link key pool that matches the current Beidou coordinate parameters; screening out the optimal candidate key based on the correlation calculation result between the key aging parameter of the candidate key set and the information entropy value of the main frequency energy distribution data; and performing secondary confusion verification on the optimal candidate key through the multiple - harmonic amplitude sequence to generate the target network session key parameters.

[0013] Optionally, the encrypting of the uplink data using the target network session key parameters and the pre - authentication data packet to obtain the encrypted communication data includes: encrypting the production control data using a preset lightweight LDPC coding and dynamic key parameter combination to generate a first - level encrypted data frame; processing the video surveillance data using a frequency - domain scrambling compression algorithm and a chaotic watermark embedding technique to generate a second - level encrypted data frame; and performing time - division multiplexing coding on the first - level encrypted data frame and the second - level encrypted data frame to form the encrypted communication data.

[0014] Optionally, the processing of the video surveillance data using a frequency - domain scrambling compression algorithm and a chaotic watermark embedding technique includes: performing time - frequency block processing on the input video stream to extract the DC component parameters of each block; generating a random permutation matrix based on the dynamic key parameters and performing frequency - domain rotation scrambling on the video blocks; and performing logical cross - splicing on the scrambled blocks and the Beidou timestamp parameters to generate a compressed video data segment.

[0015] Optionally, the method further includes: monitoring the bit error rate parameter and the power amplifier temperature parameter of the target satellite link; when the bit error rate parameter exceeds a preset safety threshold or the power amplifier temperature parameter exceeds a preset working range, triggering a preset physical - layer fusing module to destroy the current key pool; and re - initiating a dynamic key synchronization request based on the Beidou coordinate parameters before destruction and the multiple - harmonic amplitude sequence.

[0016] Based on the same inventive concept, the present invention also provides a satellite portable station data encryption and authentication system, which includes: an environment perception module for collecting the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data of the satellite terminal; a dynamic key generation module for performing exclusive OR confusion processing on the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters; a link evaluation module for generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; a pre-authentication distribution module for sending a pre-authentication data packet containing the dynamic key parameters and the cross-network authentication pre-distribution parameters to a multi-network control center through the current valid satellite link; a handover execution module for extracting target network session key parameters from a pre-stored standby link key pool when the signal quality parameters of the satellite network drop to a preset handover threshold; and a data encryption module for encrypting the uplink data using the target network session key parameters and the pre-authentication data packet to obtain encrypted communication data and sending it through the target satellite link.

[0017] Compared with the prior art, the present invention has the following advantages:

[0018] 1. The present invention generates a dynamic key by fusing the power amplifier non-linear harmonics and the environmental noise spectrum characteristics of the satellite terminal in real time, which can effectively resist replay attacks and brute-force cracking under the static key distribution mode; the physical layer feature dependence of the dynamic key makes the key generation process have hardware uniqueness and environmental randomness, and even if a single element is leaked, the complete key cannot be reconstructed.

[0019] 2. By jointly analyzing the satellite link stability threshold and the signal quality parameters to generate cross-network authentication pre-distribution parameters, the network resource allocation mechanism during multi-network handover is optimized; this technology significantly reduces the authentication delay caused by network handover, ensures that the pre-authentication preparation of critical service data is completed before the link deteriorates, and guarantees the communication continuity in cross-border roaming scenarios.

[0020] 3. Adopting the hash binding technology of physical layer harmonic characteristics and Beidou spatio-temporal parameters to achieve the non-forgeability of the terminal identity and geographical location; this method can prevent device cloning attacks and illegal location access without the need for a dedicated security module, and is suitable for highly mobile application scenarios such as emergency rescue.

[0021] 4. Based on the spatio-temporal related screening mechanism of the standby link key pool, combined with the second harmonic confusion verification, it ensures the security and real-time performance of the session key during link handover; by dynamically matching the key aging and the electromagnetic environment entropy value, the anti-interception ability of the key and the network disaster recovery efficiency are improved synchronously.

[0022] Other features and advantages of the present invention will be set forth in the following description, and in part will be obvious from the description, or may be learned by practice of the present invention. The objectives and other advantages of the present invention may be realized and attained by the structure particularly pointed out in the specification, claims as well as the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0024] Figure 1 is a schematic flowchart of a method for data encryption and authentication of a satellite portable station according to an embodiment of the present invention.

[0025] Figure 2 is a timing diagram of the harmonic amplitude of the power amplifier according to an embodiment of the present invention.

[0026] Figure 3 is a schematic structural diagram of a pre-authentication data packet according to an embodiment of the present invention.

[0027] Figure 4 is a safety fuse monitoring curve diagram according to an embodiment of the present invention.

[0028] Figure 5 is a schematic structural diagram of a satellite portable station data encryption and authentication system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0030] Refer to Figure 1 , an embodiment of the present invention provides a method for data encryption and authentication of a satellite portable station, which adopts a fusion key generation technology of power amplifier harmonics and environmental noise, and a pre-distribution mechanism of link stability and spatio-temporal parameter linkage, and can achieve high-security and low-latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios.

[0031] The specific steps of the method in this embodiment are as follows:

[0032] Collect the power amplifier non - linear harmonic spectrum data and environmental noise frequency - domain energy distribution data of the satellite terminal;

[0033] Perform XOR confusion processing on the power amplifier non - linear harmonic spectrum data and the environmental noise frequency - domain energy distribution data to generate dynamic key parameters;

[0034] Specifically, first align the two types of data by frequency points, perform bit - by - bit XOR operation. Cover the differences with gradient masks and insert pseudo - random sequences at the same frequency points. Before the XOR processing, perform the Mersenne Twister algorithm on the noise energy data to generate a 128 - bit random perturbation factor. Among them, the XOR confusion processing realizes the irreversible fusion of spectrum features and noise features through logical asymmetric operations; the dynamic key parameters are temporary encryption factors with time sensitivity.

[0035] Generate cross - network authentication pre - distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network;

[0036] Send a pre - authentication data packet containing the dynamic key parameters and cross - network authentication pre - distribution parameters to the multi - network control center through the current valid satellite link;

[0037] When the signal quality parameters of the satellite network drop to the preset switching threshold, extract the target network session key parameters from the pre - stored backup link key pool;

[0038] Use the target network session key parameters and the pre - authentication data packet to encrypt the uplink data, obtain the encrypted communication data and send it through the target satellite link.

[0039] The present invention constructs a dynamic encryption system by collecting physical layer features in real - time. The power amplifier harmonics and electromagnetic noise are fused to generate a high - entropy key, and the link quality dynamically triggers a security enhancement mechanism. Attackers cannot crack the key through fixed rules because the device features and environmental parameters change in real - time; the pre - distribution parameters optimize network resource allocation during cross - network switching and reduce authentication delay; the hardware - level fusing and Beidou time - space binding ensure the anti - physical - cracking of the key system, which is applicable to communication scenarios with high mobility and strong interference. For example, when the device is hijacked, the key is automatically destroyed, and the legitimate terminal can quickly reconstruct a secure link through Beidou positioning.

[0040] Optionally, the collecting the power amplifier non - linear harmonic spectrum data and environmental noise frequency - domain energy distribution data of the satellite terminal includes:

[0041] In the startup stage of the satellite power amplifier, continuously collect multiple harmonic amplitude sequences within a preset frequency band through a preset spectrum analysis module, and calculate the amplitude difference data;

[0042] Specifically, after the power amplifier is started, the spectrum analysis module continuously scans the amplitude data of the third harmonics (fundamental wave, third harmonic, fifth harmonic) in the 2.4 - 2.4835 GHz frequency band at intervals of 10 ms. Through sampling by the high-speed ADC module, the peak differences of the amplitudes corresponding to each frequency point are recorded. The non-symmetric sliding window is used to filter out instantaneous interference, and three groups of continuous periodic amplitude sequences are retained. For the amplitude difference ΔA' of the harmonics k , there is:

[0043] ΔA' k =max[ΔA k (t)] - min[(t)],

[0044] where max is the maximum value function, min is the minimum value function, and ΔA k (t) is the amplitude sampling sequence of the harmonic varying with time, where when k = 1, it represents the fundamental wave, when k = 2, it represents the third harmonic, and when k = 3, it represents the fifth harmonic. Among them, the spectrum analysis module is a radio frequency signal quantization device with an adaptive frequency band selection function; the amplitude difference data of the harmonic components is the difference value of the amplitude fluctuations of different frequency signals caused by the inherent nonlinear distortion of the power amplifier.

[0045] Perform chaotic phase mapping processing on the amplitude difference data to generate terminal fingerprint parameters;

[0046] Specifically, normalize the amplitude difference data and input it into the hybrid chaotic system. The hybrid chaotic system adopts an improved Logistic-Tent double mapping model:

[0047]

[0048] where x n is the amplitude difference after normalization for the nth iteration. Among them, the initial input data x0 is the amplitude difference after normalization, y n is the state variable of the Tent mapping for the nth iteration, independent of the amplitude difference data. Among them, the initial state variable y0 is usually randomly initialized, μ is the Logistic mapping bifurcation parameter, λ is the coupling coefficient, and γ is the phase adjustment factor. After 100 iterations, according to the state of the chaotic attractor, select the quantization value of the phase angle as the 16-bit binary sequence of the terminal fingerprint parameter. For the phase angle θ, there is:

[0049]

[0050] where arctan is the arctangent function. Among them, the chaotic phase mapping processing is a method that uses a nonlinear dynamic system to transform the amplitude sequence into an irreversible phase feature; the terminal fingerprint parameter is the unique device identifier reflecting the nonlinear characteristics of the power amplifier.

[0051] Hash-bind the terminal fingerprint parameters with the coordinate parameters obtained by the Beidou positioning module to form the power amplifier non-linear harmonic spectrum data.

[0052] Specifically, read the longitude Lon and latitude Lat output by the Beidou module, convert them to 32-bit integers, and then perform a circular shift operation. For the geographical location code GeoCode, there is:

[0053] GeoCode = (Lon << 16) | (Lat & 0xFFFF),

[0054] In the formula, << 16 represents a 16-bit left shift operation, clearing the high 16 bits of the longitude integer value and retaining the low 16 bits as longitude information. & 0xFFFF represents a bitwise AND operation, extracting the low 16 bits of the latitude integer value, and the mask 0xFFFF corresponds to 16 binary 1s. Finally, the high 16 bits of GeoCode are the longitude, and the low 16 bits are the latitude, such as 0x123456CDEF. After performing a bitwise exclusive OR operation on the terminal fingerprint parameters and GeoCode, a 256-bit hash value is generated through the SHA-256 algorithm, and the first 128 bits are intercepted as the core feature code of the power amplifier non-linear harmonic spectrum data. Among them, hash binding realizes the irreversible fusion of device features and geographical locations through a cryptographic hash function; the power amplifier non-linear harmonic spectrum data is an encrypted basic parameter with both device fingerprint attributes and geographical space attributes.

[0055] Exemplarily, when a certain model of satellite terminal is started in a region with an altitude of 5000m in Tibet, as Figure 2 shown, the spectrum analysis module measures the amplitude differences of the third harmonics: the fundamental wave ΔA'1 = 15dBm, the third harmonic ΔA'2 = 8dBm, and the fifth harmonic ΔA'3 = 12dBm. Normalize the sequence [15, 8, 12] to [0.682, 0.364, 0.545], input it into the chaotic system, assume μ = 3.92, λ = 0.15, γ = 0.7, and after iteration, the phase angle obtained is 1.254rad, which is converted to the binary fingerprint 0100111101011101. The Beidou coordinates are taken as E90°32'15" (90321500), N29°40'18" (29401800), and the synthesized geographical location code GeoCode = 0x5A5F3C44. The exclusive OR value of the fingerprint and GeoCode is processed through SHA-256 to generate 0x8E3D…A9C2, and the first 128 bits are intercepted as the final spectrum data to obtain the power amplifier non-linear harmonic spectrum data.

[0056] By binding the physical layer harmonic characteristics and geographical location, an irreproducible device identity is established. Since the fingerprint contains the non-linear characteristics of the hardware, it has the ability to resist cloning attacks; relying on the dynamic binding of Beidou coordinates, it has the ability to prevent location spoofing; the hashing process ensures that the data cannot be reversed, and it has the characteristic of high entropy value. For example, in the border patrol scenario, even if the device is illegally moved, the authentication will fail due to the geographical coordinate deviation, effectively preventing device camouflage.

[0057] Optionally, the collection of the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data of the satellite terminal further includes:

[0058] Real-time capture of the interference signal spectrum data in the preset frequency band through the receiving link of the planar antenna;

[0059] Specifically, the orthogonally polarized receiving unit of the planar antenna collects radio frequency signals in the 1.7 - 1.8 GHz frequency band at a sampling rate of 800 MHz, adjusts the dynamic range through a programmable gain amplifier, and uses a band-pass filter to suppress out-of-band noise. The captured time-domain signal is weighted by a window function and then sent to the fast capture buffer to form an interference signal frame sequence with a length of 1024 points. Among them, the receiving link of the planar antenna is a high-sensitivity signal receiving channel supporting the dual circular polarization mode; the interference signal spectrum data is the digital signal frequency domain energy distribution characterization after analog-to-digital conversion.

[0060] Perform multi-order discrete Fourier transform on the interference signal spectrum data to extract the main frequency energy distribution data of the preset sub-harmonics;

[0061] Specifically, perform third-order discrete Fourier transform processing on each frame of signal. The first-order DFT calculates the full-band amplitude spectrum and identifies the set of candidate frequency points higher than the threshold of -90 dBm; the second-order DFT focuses on the ±2 MHz sub-bands in the set of candidate frequency points for 4096-point fine analysis to obtain the accurate energy values of the candidate frequency points; the third-order DFT performs principal component analysis after normalizing the accurate energy values of the candidate frequency points and screens the frequency points with an energy ratio greater than 0.15. Extract the energy distribution data at the third harmonic frequency points to generate a 128-dimensional main frequency energy vector. Among them, the multi-order discrete Fourier transform is a signal processing process for gradually refining the frequency domain analysis; the main frequency energy distribution data is a set of quantization parameters characterizing the energy aggregation characteristics of the interference signal.

[0062] Calculate the information entropy value of the main frequency energy distribution data to generate the environmental noise frequency domain energy distribution data.

[0063] Specifically, perform probabilistic processing on the main frequency energy vector. For the i-th main frequency energy probability p i , there is:

[0064]

[0065] where E i is the main frequency energy vector of the i-th dimension, and E all is the sum of 128-dimensional main frequency energy vectors. Next, calculate the frequency domain information entropy H, as follows:

[0066]

[0067] where ∈ is the safety factor to prevent zero value overflow. Concatenate the frequency domain information entropy and the main frequency position index into 192-bit environmental noise frequency domain energy distribution data. Among them, the information entropy value is a statistical feature measuring the dispersion degree of spectrum energy; the environmental noise frequency domain energy distribution data is an encryption parameter reflecting the complexity of the current electromagnetic environment.

[0068] Exemplarily, when a central satellite station encounters subway wireless interference, the flat antenna captures signals in the 1.75 GHz frequency band. After third-order DFT analysis, 3 main frequency points are identified as 1.752 GHz (-81 dBm), 1.754 GHz (-78 dBm), and 1.758 GHz (-83 dBm) respectively; calculate the normalized energy ratios to be 0.32, 0.41, and 0.27 respectively, all greater than 0.15, meeting the conditions; the entropy value of the third harmonic energy vector is calculated to be H = 2.57 bit, and combined with the frequency point index to generate hexadecimal noise data 0xA3D1F7…; this data dynamically reflects the change of interference characteristics caused by the change of the subway path.

[0069] Extract the noise feature information entropy through multi-level frequency domain analysis to construct a dynamic environment fingerprint. It has the real-time nature of environmental perception and can capture the change of transient electromagnetic interference; it has the unpredictability of spectrum characteristics, relying on the natural random characteristics of signal energy distribution; it has the ability to resist spectrum analysis attacks because the noise parameters are strongly correlated with the physical environment. This makes it impossible to reverse-derive the encryption parameters through fixed frequency point scanning, ensuring the anti-interception ability of communication data. This technology enables the key generation to have environmental self-adaptability and enhances the survivability of the system in complex electromagnetic environments.

[0070] Optionally, generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network includes:

[0071] Obtain the chip signal-to-noise ratio parameter and the link delay spread parameter of the current satellite link;

[0072] Specifically, the correlator module of the spread spectrum receiver captures the chip waveform after despreading in real time, calculates the ratio of its peak power to the noise floor, and obtains the chip signal-to-noise ratio parameter. For the chip signal-to-noise ratio parameter SNR chip :

[0073]

[0074] where P peakis the mean square value of the maximum amplitude of the relevant peaks, P noise is the average noise power during the signal-free period, δ ref is the device calibration coefficient, and lg is the logarithmic function with base 10. The link delay spread parameter is calculated from the phase differences of the multipath components of the received signal. For the link delay spread parameter τ rms , there is:

[0075]

[0076] where τ m is the delay of the m-th path, a m is the amplitude of the m-th path, M is the total number of resolvable multipaths, is the power-weighted average of the multipath delays and serves as the reference point for the delay spread. Among them, the chip signal-to-noise ratio parameter is a time-domain quantization index reflecting the signal demodulation quality; the link delay spread parameter is a channel eigenvalue characterizing the multipath propagation effect.

[0077] Input the chip signal-to-noise ratio parameter and the link delay spread parameter into a preset stability evaluation model, and output a link switching priority parameter according to a preset satellite link stability threshold;

[0078] Specifically, the stability evaluation model uses a logarithmic linear regression equation to calculate the stability evaluation value. For the stability evaluation value P wp , there is:

[0079]

[0080] where α is the adjustment coefficient of the chip signal-to-noise ratio parameter, which can be taken as 0.35, and β is the adjustment coefficient of the link delay spread parameter, which can be taken as 0.62. Two satellite link stability thresholds can be set, which are 60 and 80 respectively. For the link switching priority parameter P level , there is:

[0081]

[0082] Among them, the stability evaluation model is a decision function trained based on historical link state data; the link switching priority parameter is a normalized evaluation value quantifying the link reliability.

[0083] Generate cross-network authentication pre-distribution parameters according to a preset ad-hoc network node distribution density parameter and the link switching priority parameter.

[0084] Specifically, obtain the number N of active ad-hoc network nodes within a radius of 5 km through Beidou messages, and calculate the ad-hoc network node distribution density. For the ad-hoc network node distribution density parameter D fm , there is:

[0085]

[0086] where π is the ratio of a circle's circumference to its diameter. Calculate the intermediate value of the pre-distribution parameter using the self-organizing network node distribution density parameter. For the intermediate value F of the pre-distribution parameter yc , there is:

[0087] F yc = P level * Log2(D fm + 1),

[0088] After quantizing the intermediate value F of the pre-distribution parameter yc to the 8-bit range, it is combined with the current satellite number to form a 16-bit cross-network authentication pre-distribution parameter.

[0089] Exemplarily, when a drilling platform performs satellite link switching, it measures that SMR chip = -94 dBm, τ rms = 480 ms. Substitute into the formula to calculate P wp = 0.35×ln(6)+0.62×(1000 / 480)≈1.91; Since 1.91 is less than 60, therefore the number of self-organizing network nodes N within 5 km around is 3. Calculate F yc = 0.01×log2(0.0382 + 1)≈0.0056, quantized to 8-bit is 0x01, satellite number 0xA5, to obtain the cross-network authentication pre-distribution parameter 0xA501. When multipath expansion intensifies due to harsh conditions, the link degradation is identified in advance through the stability evaluation model, and low-priority pre-distribution parameters are generated in combination with sparse node density to guide the control center to preferentially allocate resources to satellites in high-density areas, avoiding data loss caused by link interruption.

[0090] Optionally, the sending of the pre-authentication data packet containing the dynamic key parameter and the cross-network authentication pre-distribution parameter to the multi-network control center through the current valid satellite link includes:

[0091] Encrypt the dynamic key parameter using the quantum key distribution algorithm to generate a first-level encrypted payload;

[0092] Specifically, a simplified variant of the BB84 protocol is adopted to implement quantum key distribution, and the polarization basis selection sequence is transmitted through the classical channel. First, the 256-bit dynamic key is divided into 32-byte blocks, and each byte is converted into the polarization states of 8 photons (randomly assigned 0°, 45°, 90°, 135°); secondly, a random basis selection sequence with a length of 32 bytes is generated and sent synchronously with the polarization state sequence; then the receiving end filters the quantum states of the matching basis according to the random basis selection sequence, and generates a shared key after error rate detection (threshold ≤ 5%); finally, the original dynamic key is encrypted by XOR using the shared key to form a first-level encrypted payload. Among them, the quantum key distribution algorithm encryption is a key negotiation mechanism based on photon polarization state exchange; the first-level encrypted payload is a ciphertext data unit protected by the characteristics of the quantum channel.

[0093] Perform chaotic confusion on the cross-network authentication pre-distribution parameters and the Beidou positioning parameters to generate a second-level confusion payload;

[0094] Specifically, the Lorenz chaotic system is used to generate a confusion sequence. For the differential equation group in the Lorenz chaotic system, there are:

[0095]

[0096] In the formula, X is the main sequence parameter, and its initial value is set by the decimal part of the longitude. Y is the auxiliary sequence parameter, and its initial value is set by the decimal part of the latitude. Z is the security parameter, and its initial value can be set to 25, σ, ρ, are control coefficients. When numerically solving, take σ = 10, ρ = 28, After 500 iterations, take the last 23 bits of the main sequence parameter at this time and circularly fill them to 32 bits as the confusion mask, and perform a circular shift exclusive OR operation with the cross-network authentication parameter to obtain the second-level confusion payload.

[0097] Exemplarily, at this time, the cross-network authentication pre-distribution parameter is obtained as 16-bit binary data, such as 0xA501; the decimal formats of the longitude (Lon) and latitude (Lat) in the Beidou positioning parameter are obtained, such as Lon = 120.7352°, Lat = 31.2896°; extract the decimal parts of the longitude and latitude and normalize them to floating-point numbers to obtain the initial main sequence parameter X0 = 0.7352 * 40 - 20 = 9.408, obtain the initial auxiliary sequence parameter Y0 = 0.2896 * 30 - 10 = -1.312, and the initial security parameter Z0 = 25; use the fourth-order Runge-Kutta method to iterate 500 steps, with a step size of 0.01, and the control coefficient values are σ = 10, ρ = 28, After 500 iterations, the sequence values of the main sequence parameters are obtained as [9.408, 9.412,..., 12.573], a total of 500 floating-point numbers. Take the main sequence parameter 12.573 at the 500th step, convert it to an IEEE754 single-precision floating-point number (32 bits), and extract the last 23 bits of the mantissa, such as the mantissa 0011100011010111100010100 for 0x4a3d70a4. Circularly fill the 23-bit mantissa to 32 bits to generate Mask = 00111000110101111000101000011100. Determine the number of displacement bits as 61 mod 32 = 29 according to the first byte value of Mask, such as 0x3D = 61. The cross-network authentication pre-distribution parameter 0xA501 = 1010010100000001 is circularly shifted right by 29 bits to become: 00000000000000001010010100000001. XOR the shifted data block with Mask bit by bit to obtain the secondary obfuscation payload. For example, if the cross-network authentication pre-distribution parameter becomes 0x0000A501 after displacement and Mask is 0x8E3D70A4, then the secondary obfuscation payload = 0x0000A501 XOR 0x8E3D70A4 = 0x8E3DD5A5. Through dynamic chaos and geographical binding, lightweight strong obfuscation is achieved to meet the low-latency and high-security requirements of satellite links.

[0098] Perform data sharding and recombination on the primary encrypted payload and the secondary obfuscation payload to form a pre-authentication data packet.

[0099] Specifically, as Figure 3 shown in the pre-authentication data packet structure, shard by 64 bytes. After sharding the primary payload, insert Hamming code redundancy bits, adding 4-bit checks for every 16 bytes; append a timestamp flag to the shards of the secondary payload, the last 16 bits of the UTC microsecond value; the recombination strategy adopts an interleaved arrangement mode, with odd-numbered shards taken from the primary payload marked 0xA5 and even-numbered shards taken from the secondary payload marked 0x5A; add a 2-byte synchronization code 0xFF01 to the shard header and append a CRC-16 check code at the end to finally form a pre-authentication data packet. Among them, data sharding and recombination is a data encapsulation method with spatio-temporal identification; the pre-authentication data packet is a transport protocol data unit containing multiple protection mechanisms.

[0100] Exemplarily, the dynamic key is 0x7E3A...D9C4, the Beidou coordinates are E101°12.3456', N25°03.7890', the shared key 0x9B...F2 is generated in the quantum key distribution phase, and the first-level payload after encryption is 0xE5...0D; the initial main sequence parameter of the Lorenz chaotic system is 0.3456, the initial auxiliary sequence parameter is 0.7890, and the confusion mask 0x8D...7F is obtained after iteration; the pre-distributed parameter for cross-network authentication is 0xA51C, and the second-level payload 0x26...93 is obtained by XOR with the mask; after fragmentation and recombination, the pre-authentication packet structure is [FF01][A5|E5..][5A|26..][A5|D0..][5A|93..][CRC160xC3A9]. Quantum encryption is used to ensure the anti-eavesdropping property of key transmission, chaotic confusion realizes the inseparability of parameters and location information, and the interleaved fragmentation design enables the packet to still parse the payload when partially damaged, verifying the robust communication ability in complex electromagnetic environments and scenarios with unstable links.

[0101] Optionally, the extracting the target network session key parameters from the pre-stored backup link key pool includes:

[0102] Obtaining a candidate key set that matches the current Beidou coordinate parameters in the pre-stored backup link key pool;

[0103] Specifically, reading the integer-degree value Lon of the longitude output by the Beidou positioning module int and the integer-degree value Lat of the latitude int , using the nine-grid space segmentation algorithm, mapping the current coordinates to the 3×3 grid code GridCode. Each key record in the key pool stores a GeoRange field that contains the central coordinates (Lon key , Lat key ) and the radius R key (±0.5° range). If it satisfies:

[0104]

[0105] Then it is determined to be a match. After screening out the key records covering the current grid, the corresponding key parameters are extracted to form a candidate key set. Among them, the backup link key pool is a pre-generated regional key set; the candidate key set is a key subset that meets the geographical matching conditions.

[0106] Based on the calculation result of the correlation between the key aging parameter of the candidate key set and the information entropy value of the main frequency energy distribution data, the optimal candidate key is screened out;

[0107] Specifically, calculate the Pearson correlation coefficient between the key aging parameter, i.e., the number of minutes from the generation time to the current time, and the information entropy value of the main frequency energy distribution data. For the Pearson correlation coefficient r, there is:

[0108]

[0109] In the formula, T j is the aging parameter of the j-th candidate key, is the average value of all candidate key aging parameters, H j is the information entropy value of the main frequency energy distribution data corresponding to the j-th candidate key, is the average value of the information entropy values of all candidate keys. Retain the keys with |r|>0.7, sort them in reverse chronological order, and perform weighted scoring on the top 3 keys. For the score Score, there is:

[0110]

[0111] In the formula, T' is the aging parameter of the current candidate key, T max is the maximum aging parameter in the candidate key set, H' is the information entropy value of the current candidate key, H max is the maximum information entropy value in the candidate key set. Select the highest score as the optimal candidate key, a is the aging parameter adjustment coefficient, and b is the information entropy value adjustment coefficient. Among them, the key aging parameter is a time decay factor describing the key life cycle; the correlation calculation is a statistical method for measuring the correlation between key effectiveness and environmental noise.

[0112] Perform secondary confusion verification on the optimal candidate key through the multiple harmonic amplitude sequence to generate the target network session key parameter.

[0113] Specifically, read the multiple harmonic amplitudes of the current power amplifier and convert them into hexadecimal values to obtain the sequence [A1, A2, A3]; construct a non-linear confusion function and calculate the intermediate result parameter of the target network session key parameter. For the intermediate result parameter K final , there is:

[0114]

[0115] In the formula, K opt is the optimal candidate key, A1 is the hexadecimal value of the fundamental wave amplitude, A2 is the hexadecimal value of the third harmonic amplitude, and A3 is the hexadecimal value of the fifth harmonic amplitude. Perform 256 rounds of SHA-3 hash operations on the intermediate result parameter and intercept the first 128 bits as the final key. At the same time, verify that the last 8 bits of the hash value match the Beidou second pulse count value. If it fails, select the sub-optimal key for degradation. Among them, the secondary confusion verification is a post-processing mechanism for enhancing key security based on physical layer characteristics.

[0116] Exemplarily, assume that the hexadecimal values of the third harmonic amplitudes of the current power amplifier are obtained, resulting in the sequence [0x00FF, 0x00AB, 0x003C]. The optimal candidate key is 0x1A2B3C4D, and the intermediate result parameters are calculated through a non-linear confusion function. Perform 256 rounds of hashing on 0x1AD09771. Assume the result is 0x5F3C...A1B2; intercept the first 128 bits, that is, the first 16 bytes of 0x5F3C...A1B2 as the candidate key. The last 8 bits of the hash, 0xB2, do not match the Beidou second pulse count value 0x78, triggering a downgrade to select the sub-optimal key. Through the above process, combining the physical layer characteristics (third harmonic) and the time reference (Beidou second pulse), a session key with high security is generated, and the timeliness and anti-replay ability of the key are ensured.

[0117] Optionally, encrypting the uplink data using the target network session key parameters and the pre-authentication data packet, the encrypted communication data obtained includes:

[0118] Encrypt the production control data using a preset lightweight LDPC coding and dynamic key parameter combination to generate a first-level encrypted data frame;

[0119] Specifically, input the production control data into a lightweight LDPC encoder. First, construct a sparse parity-check matrix for linear error correction coding, and then perform a bitwise exclusive OR operation with the dynamic key parameters to achieve double encryption. The lightweight LDPC coding is a linear error correction code suitable for low-power devices, and low-complexity coding of data and redundant bits is achieved through a sparse parity-check matrix; the dynamic key parameters are time-varying encryption factors generated based on power amplifier harmonics and environmental noise; the bitwise exclusive OR operation is a bit-by-bit logical operation to achieve data confusion and encryption synchronization processing.

[0120] Exemplarily, the production control data is a hexadecimal sequence [0x120xA50x3F]. Use the parity-check matrix [[1,0,0,1],[0,1,1,0],[1,1,0,1]] for coding, and the generated redundant data 0x12A53F is encoded as 0x12A53F7C. The dynamic key parameter is 0x9B2D, and the exclusive OR operation with it results in the first-level encrypted data frame 0x819B7243. This processing simultaneously realizes the dual functions of error correction and encryption, and data can be recovered even if there are burst interferences in the channel.

[0121] Process the video surveillance data using a frequency-domain scrambling compression algorithm and a chaotic watermark embedding technique to generate a second-level encrypted data frame;

[0122] Specifically, the video stream is divided into 8x8 blocks for discrete cosine transform. After extracting the frequency domain coefficients, the positions of the AC components are permuted using the chaotic sequence generated by the dynamic key parameters. The DC component is concatenated with the Beidou timestamp to generate a watermark, which is embedded into the least significant bit. The frequency domain scrambling compression algorithm realizes data unreadability through the randomization of the frequency domain coefficient positions; the chaotic watermark embedding technology uses a chaotic system to generate unpredictable marking information.

[0123] The first-level encrypted data frame and the second-level encrypted data frame are multiplexed by time division to form encrypted communication data.

[0124] Specifically, a time division multiplexer is used to alternately insert the data frame content at a ratio of 1:3. After every 32 bytes of first-level data, 96 bytes of second-level data are inserted, and the synchronization header 0xFFEE is inserted and CRC-16 checksum is appended. The time division multiplexing coding is a coding method that realizes the mixed transmission of multi-service data through time slot division; the CRC-16 checksum is a cyclic redundancy check algorithm used to detect transmission errors.

[0125] Exemplarily, the length of the first-level encrypted data frame is 128 bytes, and the length of the second-level encrypted data frame is 384 bytes. The encoded communication data is: [FFEE][First-level data block 0 - 31][Second-level data block 0 - 95][CRC16_1], [FFEE][First-level data 32 - 63][Second-level data 96 - 191][CRC16_2]. This structure ensures the priority transmission of key production data, the full utilization of bandwidth for video data, and the integrity guaranteed by CRC checksum.

[0126] Exemplarily, the sensor data (temperature 28.5°C, pressure 15 MPa) of a drilling platform is encoded by lightweight LDPC to generate a data block 0x4D2A...B1, which is XORed with the dynamic key 0x9B2D to get 0xD6F7...9C. At the same time, the video blocks captured by the camera are scrambled in the frequency domain, and the original DCT matrix [156, -45, 32...] is scrambled to [-22, 156, 89...], and the last byte 0xC7 of the Beidou timestamp is embedded. After multiplexing coding, a complete communication data packet including a synchronization header, double payloads, and CRC is generated. The production data is protected by double protection of error correction and dynamic confusion, enhancing the anti-channel interference ability; after the frequency domain structure of the video data is randomized, it prevents the restoration of the picture, and the binding of the watermark and the timestamp can trace the source of tampering; the time division multiplexing takes into account the real-time nature of control instructions and the continuity of video transmission.

[0127] Optionally, the processing of the video surveillance data using the frequency domain scrambling compression algorithm and the chaotic watermark embedding technology includes:

[0128] Perform time-frequency block processing on the input video stream and extract the DC component parameters of each block;

[0129] Specifically, time-frequency block processing is a video segmentation method that simultaneously considers time windows and frequency domain partitioning, and extracts features through a spatio-temporal combination method; the discrete cosine transform is an orthogonal transform algorithm that converts spatial domain signals into frequency domain energy distributions; the DC component parameter is a quantization index that reflects the overall brightness average value of an image block and has time domain stability characteristics. The video stream is divided into time domain blocks with 8 consecutive frames as a group, and each frame is segmented into 8×8 pixel frequency domain blocks. Each block performs a discrete cosine transform (DCT) to obtain 64 frequency domain coefficients, where the first coefficient is the DC component and the remaining 63 are AC components. The DC components of all blocks are extracted and normalized to integer values between 0 and 255 to form a parameter set.

[0130] Exemplarily, the gray values of an 8×8 pixel block in the 5th frame of the video stream are as follows:

[0131]

[0132] The coefficient in the first row and first column (DC component) after DCT operation is 1064, and the normalized integer value is 106. The absolute values of the remaining 63 AC components are at most 120 and at least 1.2.

[0133] Based on the dynamic key parameter, a random permutation matrix is generated to perform frequency domain rotation scrambling on the video blocks;

[0134] Specifically, the Logistic chaotic map is used to generate a permutation sequence:

[0135] c n+1 = d * c n *(1 - c n ),

[0136] In the formula, c n is the chaotic sequence value input for the (n + 1)-th iteration, c n+1 is the chaotic sequence value output for the (n + 1)-th iteration, d is the bifurcation parameter, taking 3.99, and the initial input chaotic sequence value c0 is converted from the first 4 bytes of the dynamic key into a decimal between 0 and 1. 63 random numbers are generated by iteration, and the sequence numbers after sorting form the AC component permutation matrix. The original AC components are rearranged according to the new sequence numbers, and the DC component remains in place.

[0137] Exemplarily, the dynamic key is 0x8E3D70A4, and the first 4 bytes are converted to decimal 237,045,252, with the normalized initial value 0.237045252. 63 chaotic values are generated by iteration and sorted to obtain the permutation sequence: [45, 12, 7,..., 32]. The original AC components AC1, AC2,..., AC63 are rearranged in this order to AC45, AC12, AC7... AC32.

[0138] Perform logical cross - splicing on the scrambled blocks and Beidou timestamp parameters to generate a compressed video data segment.

[0139] Specifically, read the Coordinated Universal Time (UTC) timestamp output by the Beidou module accurate to microseconds, and split it into the high 32 bits (date plus hours) and the low 32 bits (minutes plus microseconds). Perform odd - even bit cross - merging with the scrambled DC component. For odd - numbered bytes, take the high 4 bits of the DC component and splice the low 4 bits of the timestamp; for even - numbered bytes, take the high 4 bits of the timestamp and splice the low 4 bits of the DC component to form a 64 - byte compressed data block, discarding the redundant AC component. Logical cross - splicing is an operation that realizes data confusion and spatio - temporal binding through bit - level recombination. The Beidou timestamp parameter is a high - precision time identifier based on satellite timekeeping and has the characteristic of anti - forgery. The compressed video data segment is an encrypted data unit that removes spatial redundancy and strengthens time features at the same time.

[0140] Exemplarily, the Beidou timestamp UTC2023 - 09 - 15T14:30:45.123456 is converted to hexadecimal 0x07E7090F002B23C0, and the scrambled DC component is 0x6A. The cross - splicing result for odd - numbered bits is that the high four bits 0110 of 0x6 are spliced with the low four bits 0xC0 of the timestamp to get 0x6, and for even - numbered bits, the high four bits 0x07 of the timestamp are spliced with the low four bits 1010 of 0xA to get 0x7A. The final compressed block is [0x6C, 0x7A,...], with a total length of 64 bytes.

[0141] Exemplarily, a certain monitoring system collects a 1920×1080 video stream, selects the upper - left 8×8 block of the 100th frame for processing. After DCT transformation, the DC component value 0x92 is extracted, and a chaotic sequence is generated with the dynamic key 0x5F3C. After permutation, the order of the AC components is [52, 8, 3,...]; the cross - splicing of the Beidou timestamp 0x07E7090F002B23C0 and the DC component results in the data header 0x9F7C. When transmitted to the satellite terminal, the attacker cannot restore the original image, and a verification failure is triggered if the timestamp deviation exceeds 2 microseconds. After frequency - domain scrambling, the video content completely loses spatial continuity and cannot be parsed by a conventional player; the Beidou timestamp is deeply bound to the data block, and illegal tampering or replay attacks are immediately recognized due to timestamp mismatch; logical cross - splicing not only retains the core features of the image but also avoids the exposure of complete data, meeting the confidentiality and integrity requirements of video monitoring in high - security scenarios such as ports.

[0142] Optionally, the method further includes:

[0143] Monitor the bit error rate parameter and the power amplifier temperature parameter of the target satellite link;

[0144] Specifically, the satellite baseband processing unit calculates the bit error rate of the demodulated signal in real time, calculates the percentage of the number of bit errors in the total number of transmitted bits within each 10-millisecond period, and records it as the bit error rate parameter. The temperature data is collected by the thermal sensor in the power amplifier module at a frequency of once per second and compared with the preset threshold range. The bit error rate parameter is a direct quantitative indicator of the transmission quality of the communication link and reflects the degree of signal interference. The power amplifier temperature parameter is a physical monitoring value of the operating state of the high-frequency power amplifier. Excessive temperature may cause device failure or safety risks. The monitoring action is a composite operation of periodic data collection and real-time threshold determination.

[0145] Exemplarily, the satellite link transmission rate is 2 Mbps. In a certain 10-millisecond period, 10,000 bits are received, and 12 of them are in error. The bit error rate parameter is calculated as 0.12%. The current reading of the power amplifier temperature sensor is 68 °C, and the preset safe operating range is from -20 °C to 75 °C. It is determined that the temperature is not exceeded, but if the bit error rate exceeds the threshold of 0.15%, subsequent operations will be triggered.

[0146] When the bit error rate parameter exceeds the preset safety threshold, or the power amplifier temperature parameter exceeds the preset operating range, the preset physical layer fuse module is triggered to destroy the current key pool; specifically, as Figure 4 shown, the preset safety threshold is a bit error rate of 0.1% - 0.2% (adaptively adjusted according to the modulation method), and the preset operating range of the power amplifier temperature is from -20 °C to 75 °C. When any one exceeds the limit, the physical layer fuse module sends a high-voltage pulse signal to the key storage chip to perform physical erasure of the flash memory block. The erasure process ensures that each byte of the key pool storage address is overwritten with 0xFF, and the hardware fuse identification bit is permanently set to 0, blocking subsequent key reading operations.

[0147] Based on the Beidou coordinate parameters before destruction and the multiple harmonic amplitude sequences, a dynamic key synchronization request is re-initiated.

[0148] Specifically, the Beidou longitude and latitude coordinates of the last effective positioning before the key pool is destroyed (such as E110.2536°, N25.7845°) and the most recent harmonic characteristics of the power amplifier (such as the fundamental wave amplitude of 15 dBm and the phase difference of the third harmonic of 30°) are combined to generate a 128-bit synchronization seed. A synchronization request frame is sent through the satellite control channel. The frame structure includes a 2-byte frame header identifier such as 0xAA55, an 8-byte encrypted Beidou coordinate value such as AES-ECB encryption, a 32-bit timestamp such as UTC second-level time, and a 4-byte harmonic characteristic hash value such as SHA-256 truncation.

[0149] Exemplarily, when encountering strong interference during a typhoon passing by, the bit error rate of the satellite link surges to 0.3% (threshold 0.2%), and the device temperature rises to 82°C due to heat dissipation failure. The fuse module is triggered to destroy the key pool, and the Beidou's last valid coordinates E122.78°, N18.25° and the harmonic characteristics (fundamental wave 22dBm, third harmonic phase difference 45°) are used to generate a synchronization seed. The control center verifies that the location is within the predetermined area, regenerates and distributes a dynamic key, and restores the encrypted communication capability. The key protection mechanism is automatically triggered when the link is abnormal in a harsh environment, and physical-level fusing ensures that attackers cannot extract valid keys; the synchronization mechanism based on the last legal location and hardware characteristics can prevent the illegal reuse of keys in a mobile scenario and ensure that authorized devices can quickly resume communication.

[0150] Based on the same inventive concept, as Figure 5 shown, the present invention also provides a satellite portable station data encryption and authentication system, and the system includes:

[0151] An environment perception module, configured to collect the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data of the satellite terminal;

[0152] A dynamic key generation module, configured to perform an exclusive OR confusion process on the power amplifier non-linear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters;

[0153] A link evaluation module, configured to generate cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network;

[0154] A pre-authentication distribution module, configured to send a pre-authentication data packet including the dynamic key parameters and the cross-network authentication pre-distribution parameters to a multi-network control center through the current valid satellite link;

[0155] A switching execution module, configured to extract target network session key parameters from a pre-stored backup link key pool when the signal quality parameters of the satellite network drop to a preset switching threshold;

[0156] A data encryption module, configured to encrypt the uplink data using the target network session key parameters and the pre-authentication data packet to obtain encrypted communication data and send it through the target satellite link.

[0157] It should be noted that for the formulas mentioned above, through the principle of dimensional consistency and mathematical standardization means (such as normalization processing, dimensionless parameter conversion, or unit system unification), physical quantities with different attributes can be translated into unitless standard values or superimposable parameters of the same dimension, so as to eliminate the interference of different dimensions on the operation logic, and make the formulas have mathematical operation rationality and objective law adaptability while retaining the characteristics of the original data distribution. This is a conventional technical means and will not be elaborated here. The electrical connections between the above-mentioned various units do not necessarily mean direct connection of the circuits. Indirect connection methods can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above-mentioned are only exemplary embodiments of the present invention, and the scope of the present invention cannot be limited thereby.

[0158] That is, any equivalent changes and modifications made in accordance with the teachings of the present invention still fall within the scope covered by the present invention. After considering the specification and the disclosure of the practical truth, those skilled in the art will easily think of other implementation schemes of the present invention. This application aims to cover any variations, uses, or adaptive changes of the present invention, and these variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not recorded in the present invention.

Claims

1. A method for data encryption and authentication of a satellite portable station, characterized in that, The method includes: Collecting the power amplifier non - linear harmonic spectrum data and the environmental noise frequency - domain energy distribution data of the satellite terminal; Performing an exclusive - OR confusion process on the power amplifier non - linear harmonic spectrum data and the environmental noise frequency - domain energy distribution data to generate dynamic key parameters; Generating cross - network authentication pre - distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; Sending a pre - authentication data packet containing the dynamic key parameters and the cross - network authentication pre - distribution parameters to a multi - network control center through the current valid satellite link; When the signal quality parameters of the satellite network drop to a preset switching threshold, extracting target network session key parameters from a pre - stored backup link key pool; Encrypting the uplink data using the target network session key parameters and the pre - authentication data packet to obtain encrypted communication data and sending it through the target satellite link.

2. The data encryption and authentication method of a satellite portable station according to claim 1, characterized in that, The collecting the power amplifier non - linear harmonic spectrum data and the environmental noise frequency - domain energy distribution data of the satellite terminal includes: In the startup phase of the satellite power amplifier, continuously collecting multiple harmonic amplitude sequences within a preset frequency band through a preset spectrum analysis module, and calculating the amplitude difference data; Performing a chaotic phase mapping process on the amplitude difference data to generate terminal fingerprint parameters; Performing a hash binding on the terminal fingerprint parameters and the coordinate parameters obtained through a Beidou positioning module to form the power amplifier non - linear harmonic spectrum data.

3. The satellite portable station data encryption and authentication method according to claim 2, wherein The collecting the power amplifier non - linear harmonic spectrum data and the environmental noise frequency - domain energy distribution data of the satellite terminal further includes: Real - time capturing the interference signal spectrum data of a preset frequency band through the receiving link of a flat antenna; Performing a multi - order discrete Fourier transform on the interference signal spectrum data to extract the main - frequency energy distribution data of preset sub - harmonics; Calculating the information entropy value of the main - frequency energy distribution data to generate the environmental noise frequency - domain energy distribution data.

4. The satellite portable station data encryption and authentication method according to claim 1, wherein The generating cross - network authentication pre - distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network includes: Obtaining the chip signal - to - noise ratio parameter and the link delay spread parameter of the current satellite link; Inputting the chip signal - to - noise ratio parameter and the link delay spread parameter into a preset stability evaluation model, and outputting a link switching priority parameter according to the preset satellite link stability threshold; Generating cross - network authentication pre - distribution parameters according to a preset self - organizing network node distribution density parameter and the link switching priority parameter.

5. A method for encrypting and authenticating satellite portable station data according to claim 4, characterized in that, The sending a pre - authentication data packet containing the dynamic key parameters and the cross - network authentication pre - distribution parameters to a multi - network control center through the current valid satellite link includes: Encrypting the dynamic key parameters using a quantum key distribution algorithm to generate a first - level encrypted payload; Performing chaotic confusion on the cross - network authentication pre - distribution parameters and the Beidou positioning parameters to generate a second - level confusion payload; Performing data sharding and recombination on the first - level encrypted payload and the second - level confusion payload to form a pre - authentication data packet.

6. A method for encrypting and authenticating satellite portable station data according to claim 3, characterized in that, The extracting target network session key parameters from a pre - stored backup link key pool includes: Obtaining a candidate key set that matches the current Beidou coordinate parameters in the pre - stored backup link key pool; Based on the correlation calculation result between the key aging parameter of the candidate key set and the information entropy value of the main frequency energy distribution data, the optimal candidate key is selected; The optimal candidate key is verified by the multiple harmonic amplitude sequence for secondary confusion to generate the target network session key parameter.

7. A method for encrypting and authenticating satellite portable station data according to claim 6, characterized in that, The encrypted communication data obtained by encrypting the uplink data with the target network session key parameter and the pre-authentication data packet includes: The production control data is encrypted by a preset lightweight LDPC coding and dynamic key parameter combination to generate a first-level encrypted data frame; The video surveillance data is processed by a frequency domain scrambling compression algorithm and a chaotic watermark embedding technology to generate a second-level encrypted data frame; The first-level encrypted data frame and the second-level encrypted data frame are multiplexed by time division to form the encrypted communication data.

8. A method for data encryption and authentication of a satellite portable station according to claim 7, characterized in that, The processing of the video surveillance data by the frequency domain scrambling compression algorithm and the chaotic watermark embedding technology includes: The input video stream is processed by time-frequency block division to extract the DC component parameters of each block; A random permutation matrix is generated based on the dynamic key parameter to perform frequency domain rotation scrambling on the video blocks; The scrambled blocks are logically cross-stitched with the Beidou timestamp parameter to generate a compressed video data segment.

9. A method for data encryption and authentication of a satellite portable station according to claim 2, characterized in that, The method further includes: Monitoring the bit error rate parameter and the power amplifier temperature parameter of the target satellite link; When the bit error rate parameter exceeds the preset safety threshold, or the power amplifier temperature parameter exceeds the preset working range, triggering a preset physical layer fusing module to destroy the current key pool; Based on the Beidou coordinate parameter before destruction and the multiple harmonic amplitude sequence, a dynamic key synchronization request is re-initiated.

10. A satellite portable station data encryption and authentication system, which is applied to the satellite portable station data encryption and authentication method described in any one of claims 1-9, and is characterized in that, The system includes: An environment perception module for collecting the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data of the satellite terminal; A dynamic key generation module for performing exclusive OR confusion processing on the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters; A link evaluation module for generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; A pre-authentication distribution module for sending a pre-authentication data packet containing the dynamic key parameter and the cross-network authentication pre-distribution parameter to the multi-network control center through the current effective satellite link; A switching execution module for extracting the target network session key parameter from the pre-stored backup link key pool when the signal quality parameter of the satellite network drops to the preset switching threshold; A data encryption module for encrypting the uplink data with the target network session key parameter and the pre-authentication data packet, obtaining the encrypted communication data and sending it through the target satellite link.

Citation Information

Patent Citations

  • Satellite switching authentication method for low earth orbit satellite network

    CN116056080A

  • Security encryption communication method and system based on quantum key management

    CN119316138A

  • Internet of Things cooperative sensing method based on encryption protection

    CN119545335A

  • Internet of things information transmission method and system in low earth orbit satellite Internet of things

    CN119814128A

  • Broadband cognitive radio communication method and system, device, and storage medium

    WO2023029723A1

Cited By

  • Wireless communication encryption authentication method and system for inspection robot

    CN120659047A

  • Wireless encryption 5G security router

    CN120812578A

  • Satellite safety communication method and system

    CN121037106A

  • Satellite secure communication method and system

    CN121037106B