Satellite portable station data encryption authentication method and system

By integrating power amplifier harmonics and environmental noise to generate dynamic keys in a satellite portable station, and optimizing network switching by combining link stability and spatiotemporal parameters, the security and continuity issues in data transmission in satellite portable stations are solved, achieving high-security and low-latency communication protection.

CN120264274BActive Publication Date: 2025-11-11JIANGSU ANRUIXUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510616721.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-11-11
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

Existing satellite portable stations face challenges in data transmission security, including key leakage, identity forgery, and communication interruptions caused by improper network switching. They are particularly vulnerable to data transmission in complex electromagnetic environments and multi-satellite network switching scenarios.

Method used

A key generation technology that integrates power amplifier harmonics and environmental noise is adopted, combined with a pre-distribution mechanism that links link stability and spatiotemporal parameters to generate dynamic key parameters. Data encryption is achieved through multi-level encryption and obfuscation processing, thereby optimizing network resource allocation and authentication processes.

Benefits of technology

It effectively resists static key attacks, ensures the security and continuity of communication, reduces network switching latency, prevents device cloning and location spoofing, and adapts to highly mobile applications in complex electromagnetic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120264274B_ABST
    Figure CN120264274B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for encrypting and authenticating data from a portable satellite station, belonging to the field of wireless communication network security technology. It includes collecting nonlinear harmonic spectrum data of the satellite terminal's power amplifier and frequency domain energy distribution data of environmental noise, performing XOR obfuscation processing to generate dynamic key parameters; generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; and extracting the target network session key parameters when the signal quality parameters of the satellite network drop to a preset switching threshold, and encrypting and transmitting uplink data by combining the dynamic key parameters and the cross-network authentication pre-distribution parameters. This invention employs a fusion key generation technology based on power amplifier harmonics and environmental noise, and a pre-distribution mechanism that links link stability with spatiotemporal parameters, enabling high-security, low-latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication network security technology, and in particular to a method and system for encrypting and authenticating data from a satellite portable station. Background Technology

[0002] As a core device for modern emergency communications and remote area networking, the security of satellite portable stations relies heavily on the encryption and authentication mechanisms of the wireless link. Current technologies generally employ satellite data protection schemes based on fixed key negotiation, combined with terminal identification codes for network access control. However, with the upgrading of wireless network attack methods, traditional methods face serious challenges from key leakage and identity forgery.

[0003] Currently, session key matching during multi-satellite network handover is mainly achieved through a pre-configured key pool. Link quality is determined by the received signal strength, and key switching is triggered when the signal attenuates to a preset threshold. In addition, some improved technologies introduce terminal hardware signatures as static identifiers, and enhance security by periodically updating the key policy.

[0004] However, static key generation mechanisms cannot effectively resist spectrum analysis attacks targeting fixed encryption rules; link switching relies on a single signal strength indicator, leading to a mismatch between switching decisions and network load conditions; and terminal identity is decoupled from the physical environment, making it easy to reverse engineer and generate fake terminals. Summary of the Invention

[0005] To address the aforementioned issues, this invention provides a method and system for encrypting and authenticating data from a portable satellite station. The method and system employ a key generation technique that integrates power amplifier harmonics and environmental noise, as well as a pre-distribution mechanism that links link stability with spatiotemporal parameters. This enables high-security, low-latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios.

[0006] The above objectives can be achieved through the following approach:

[0007] A satellite portable station data encryption and authentication method and system includes: collecting power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data from a satellite terminal; performing XOR obfuscation processing on the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters; generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; sending a pre-authentication data packet containing the dynamic key parameters and the cross-network authentication pre-distribution parameters to a multi-network control center through the currently effective satellite link; when the signal quality parameters of the satellite network drop to a preset switching threshold, extracting target network session key parameters from a pre-stored backup link key pool; encrypting uplink data using the target network session key parameters and the pre-authentication data packet to obtain encrypted communication data, which is then sent through the target satellite link.

[0008] Optionally, the acquisition of power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of the satellite terminal includes: during the satellite power amplifier startup phase, continuously acquiring multiple harmonic amplitude sequences within a preset frequency band through a preset spectrum analysis module, and calculating amplitude difference data; performing chaotic phase mapping processing on the amplitude difference data to generate terminal fingerprint parameters; and hash-binding the terminal fingerprint parameters with coordinate parameters obtained through the BeiDou positioning module to form power amplifier nonlinear harmonic spectrum data.

[0009] Optionally, the acquisition of power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of the satellite terminal further includes: real-time acquisition of interference signal spectrum data of a preset frequency band through the receiving link of a flat panel antenna; performing multi-order discrete Fourier transform on the interference signal spectrum data to extract the primary frequency energy distribution data of the preset subharmonics; calculating the information entropy value of the primary frequency energy distribution data to generate the environmental noise frequency domain energy distribution data.

[0010] Optionally, generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network includes: obtaining the chip signal-to-noise ratio (SNR) parameter and link delay spread parameter of the current satellite link; inputting the chip SNR parameter and link delay spread parameter into a preset stability evaluation model, and outputting link switching priority parameters according to the preset satellite link stability threshold; and generating cross-network authentication pre-distribution parameters according to the preset ad hoc network node distribution density parameter and the link switching priority parameter.

[0011] Optionally, sending the pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center through the currently effective satellite link includes: encrypting the dynamic key parameters using a quantum key distribution algorithm to generate a first-level encrypted payload; performing chaotic obfuscation on the cross-network authentication pre-distribution parameters and BeiDou positioning parameters to generate a second-level obfuscated payload; and performing data fragmentation and reassembly of the first-level encrypted payload and the second-level obfuscated payload to form the pre-authentication data packet.

[0012] Optionally, the step of extracting the target network session key parameters from the pre-stored backup link key pool includes: obtaining a set of candidate keys in the pre-stored backup link key pool that match the current BeiDou coordinate parameters; selecting the optimal candidate key based on the correlation calculation results between the key validity parameters of the candidate key set and the information entropy value of the main frequency energy distribution data; and performing secondary obfuscation verification on the optimal candidate key through the multiple harmonic amplitude sequence to generate the target network session key parameters.

[0013] Optionally, the step of encrypting the uplink data using the target network session key parameters and the pre-authenticated data packet to obtain encrypted communication data includes: encrypting production control data using a preset lightweight LDPC encoding and dynamic key parameter combination to generate a first-level encrypted data frame; processing video surveillance data using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology to generate a second-level encrypted data frame; and performing time-division multiplexing encoding on the first-level encrypted data frame and the second-level encrypted data frame to form encrypted communication data.

[0014] Optionally, the process of processing video surveillance data using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology includes: performing time-frequency block processing on the input video stream and extracting the DC component parameters of each block; generating a random permutation matrix based on the dynamic key parameters and performing frequency domain scrambling on the video blocks; and logically cross-concatenating the scrambled blocks with the BeiDou timestamp parameters to generate compressed video data segments.

[0015] Optionally, the method further includes: monitoring the bit error rate parameter and power amplifier temperature parameter of the target satellite link; when the bit error rate parameter exceeds a preset security threshold, or the power amplifier temperature parameter exceeds a preset operating range, triggering a preset physical layer fuse module to destroy the current key pool; and re-initiating a dynamic key synchronization request based on the BeiDou coordinate parameters before destruction and the multiple harmonic amplitude sequence.

[0016] Based on the same inventive concept, this invention also provides a satellite portable station data encryption and authentication system, the system comprising: an environmental perception module for collecting power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of a satellite terminal; a dynamic key generation module for performing XOR obfuscation processing on the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters; a link evaluation module for generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network; a pre-authentication distribution module for sending a pre-authentication data packet containing the dynamic key parameters and the cross-network authentication pre-distribution parameters to a multi-network control center through the currently effective satellite link; a switching execution module for extracting target network session key parameters from a pre-stored backup link key pool when the signal quality parameters of the satellite network drop to a preset switching threshold; and a data encryption module for encrypting uplink data using the target network session key parameters and the pre-authentication data packet to obtain encrypted communication data and sending it through the target satellite link.

[0017] Compared with the prior art, the present invention has the following advantages:

[0018] 1. This invention generates a dynamic key by real-time fusion of the nonlinear harmonics of the power amplifier of the satellite terminal and the spectral characteristics of environmental noise, which can effectively resist replay attacks and brute-force cracking under the static key distribution mode; the physical layer feature dependency of the dynamic key makes the key generation process hardware unique and environmental random, so even if a single element is leaked, the complete key cannot be reconstructed.

[0019] 2. By jointly analyzing satellite link stability thresholds and signal quality parameters, cross-network authentication pre-distribution parameters are generated, optimizing the network resource allocation mechanism during multi-network handover. This technology significantly reduces authentication delays caused by network handover, ensuring that critical business data completes pre-authentication preparation before link degradation, and guaranteeing communication continuity in cross-border roaming scenarios.

[0020] 3. By employing hash binding technology of physical layer harmonic features and BeiDou spatiotemporal parameters, the terminal identity and geographical location are made unforgeable. This method can prevent device cloning attacks and unauthorized location access without the need for a dedicated security module, making it suitable for highly mobile application scenarios such as emergency rescue.

[0021] 4. Based on the spatiotemporal correlation filtering mechanism of the backup link key pool, combined with second harmonic obfuscation verification, the security and real-time performance of session keys during link switching are ensured; through dynamic matching of key validity and electromagnetic environment entropy, the anti-interception capability of keys and network disaster recovery efficiency are improved simultaneously.

[0022] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description

[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a flowchart illustrating a satellite portable station data encryption and authentication method according to an embodiment of the present invention.

[0025] Figure 2 This is a timing diagram of the harmonic amplitude of the power amplifier according to an embodiment of the present invention.

[0026] Figure 3 This is a schematic diagram of the structure of the pre-authentication data packet according to an embodiment of the present invention.

[0027] Figure 4 This is a safety circuit breaker monitoring curve diagram according to an embodiment of the present invention.

[0028] Figure 5 This is a schematic diagram of the structure of a satellite portable station data encryption and authentication system according to an embodiment of the present invention. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] Reference Figure 1 One embodiment of the present invention proposes a data encryption and authentication method for satellite portable stations. It adopts a key generation technology that integrates power amplifier harmonics and environmental noise, and a pre-distribution mechanism that links link stability and spatiotemporal parameters. This method can achieve high security and low latency communication protection in complex electromagnetic environments and multi-satellite network switching scenarios.

[0031] The method described in this embodiment specifically includes:

[0032] Collect nonlinear harmonic spectrum data of the power amplifier and frequency domain energy distribution data of environmental noise from the satellite terminal;

[0033] The power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data are XORed and scrambled to generate dynamic key parameters.

[0034] Specifically, the two types of data are first aligned by frequency point, and a bit-by-bit XOR operation is performed. Differences are covered with gradient masks, and pseudo-random sequences are inserted for the same frequency points. Before the XOR processing, the Mason slew algorithm is performed on the noise energy data to generate a 128-bit random perturbation factor. The XOR obfuscation process achieves irreversible fusion of spectral features and noise features through logical asymmetric operations; the dynamic key parameter is a time-sensitive temporary encryption factor.

[0035] Based on the preset satellite link stability threshold and the signal quality parameters of the current satellite network, cross-network authentication pre-distribution parameters are generated.

[0036] Send a pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center through the currently effective satellite link;

[0037] When the signal quality parameters of the satellite network drop to a preset switching threshold, the target network session key parameters are extracted from the pre-stored backup link key pool.

[0038] The uplink data is encrypted using the target network session key parameters and the pre-authenticated data packet to obtain encrypted communication data, which is then transmitted via the target satellite link.

[0039] This invention constructs a dynamic encryption system by real-time acquisition of physical layer features. Power amplifier harmonics and electromagnetic noise are fused to generate a high-entropy key, and link quality dynamically triggers security enhancement mechanisms. Attackers cannot crack the key using fixed rules because device characteristics and environmental parameters change in real time. Pre-distributed parameters optimize network resource allocation and reduce authentication latency during cross-network handover. Hardware-level circuit breaking and BeiDou spatiotemporal binding ensure the key system resists physical attacks, making it suitable for highly mobile and highly interference-prone communication scenarios. For example, if a device is hijacked, the key is automatically destroyed, while a legitimate terminal can quickly rebuild a secure link using BeiDou positioning.

[0040] Optionally, the power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data of the acquisition satellite terminal include:

[0041] During the satellite power amplifier startup phase, the preset spectrum analysis module continuously collects multiple harmonic amplitude sequences within the preset frequency band and calculates the amplitude difference data.

[0042] Specifically, after the power amplifier starts, the spectrum analysis module continuously scans the amplitude data of the third harmonic (fundamental, third, and fifth harmonic) within the 2.4-2.4835GHz frequency band at 10ms intervals. The peak difference of the amplitude at each frequency point is recorded by sampling through a high-speed ADC module. Instantaneous interference is filtered using an asymmetric sliding window, retaining three sets of continuous periodic amplitude sequences, including the amplitude differences of the harmonics. ,have:

[0043] ,

[0044] In the formula, To find the maximum value function, To find the minimum value function, This is a sampling sequence of harmonic amplitudes varying over time, where k=1 represents the fundamental frequency, k=2 represents the third harmonic, and k=3 represents the fifth harmonic. The spectrum analysis module is a radio frequency signal quantization device with adaptive bandwidth selection; the harmonic component amplitude difference data represents the amplitude fluctuation difference of signals at different frequencies caused by the inherent nonlinear distortion of the power amplifier.

[0045] The amplitude difference data is subjected to chaotic phase mapping processing to generate terminal fingerprint parameters;

[0046] Specifically, the amplitude difference data is normalized and input into the hybrid chaotic system, which employs an improved Logistic-Tent dual-mapping model.

[0047] ;

[0048] ;

[0049] In the formula, The normalized amplitude difference is the difference after the nth iteration, where the initial input data... The difference in amplitude after normalization. The state variables of the Tent map in the nth iteration are independent of the magnitude difference data, where the initial state variable is... Typically initialized randomly. For Logistic mapping branch parameters, The coupling coefficient is... This is the phase adjustment factor. After 100 iterations, based on the chaotic attractor state, the quantized value of the phase angle is selected as the 16-bit binary sequence of the terminal fingerprint parameters. For the phase angle... ,have:

[0050] ,

[0051] In the formula, The arctangent function is used. Chaotic phase mapping is a method that uses nonlinear dynamics to transform amplitude sequences into irreversible phase characteristics; the terminal fingerprint parameter is a unique device identifier reflecting the nonlinear characteristics of the power amplifier.

[0052] The terminal fingerprint parameters are hashed and bound to the coordinate parameters obtained through the BeiDou positioning module to form the nonlinear harmonic spectrum data of the amplifier.

[0053] Specifically, the longitude (Lon) and latitude (Lat) output by the BeiDou module are read, converted to 32-bit integers, and then subjected to a circular shift operation for geographic location encoding. ,have:

[0054] ,

[0055] In the formula, This indicates a left shift operation of 16 bits, which clears the high 16 bits of the longitude integer value to zero, while retaining the low 16 bits as longitude information. This indicates a bitwise AND operation, extracting the lower 16 bits of the latitude integer value. The mask 0xFFFF corresponds to 16 ones in binary. The final GeoCode has the high 16 bits representing longitude and the low 16 bits representing latitude, such as 0x123456CDEF. The terminal fingerprint parameters are XORed with the GeoCode, and a 256-bit hash value is generated using the SHA-256 algorithm. The first 128 bits are extracted as the core feature code for the power amplifier's nonlinear harmonic spectrum data. The hash binding achieves an irreversible fusion of device characteristics and geographical location through a cryptographic hash function; the power amplifier's nonlinear harmonic spectrum data is a fundamental encrypted parameter possessing both device fingerprint and geospatial attributes.

[0056] For example, when a certain type of satellite terminal is activated in an area with an altitude of 5000m, such as Figure 2 As shown, the spectrum analysis module measured the difference in the amplitude of the third harmonic: fundamental wave Third harmonic Fifth harmonic The sequence [15, 8, 12] is normalized to [0.682, 0.364, 0.545] and input into a chaotic system. Assume... , , After iteration, the phase angle is obtained as 1.254 rad, which is converted into a binary fingerprint of 0100111101011101. The BeiDou coordinates are taken as E90°32'15" (90321500) and N29°40'18" (29401800), and the geolocation code GeoCode is synthesized as 0x5A5F3C44. The XOR value of the fingerprint and GeoCode is processed by SHA-256 to generate 0x8E3D…A9C2. The first 128 bits are truncated as the final spectrum data to obtain the power amplifier nonlinear harmonic spectrum data.

[0057] By combining physical layer harmonic characteristics with geographic location, an uncopyable device identity is established. Because fingerprints contain hardware nonlinear characteristics, they are resistant to cloning attacks; dynamic binding based on BeiDou coordinates provides protection against location spoofing; and the hashing process ensures data is irreversible, exhibiting high entropy. For example, in border patrol scenarios, even if the device is illegally moved, geographic coordinate deviation will cause authentication failure, effectively preventing device spoofing.

[0058] Optionally, the acquisition of power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data from the satellite terminal further includes:

[0059] The interference signal spectrum data of the preset frequency band is captured in real time through the receiving link of the flat panel antenna;

[0060] Specifically, the orthogonal polarization receiving unit of the flat panel antenna acquires radio frequency signals in the 1.7-1.8 GHz frequency band at a sampling rate of 800 MHz. The dynamic range is adjusted by a programmable gain amplifier, and a bandpass filter is used to suppress out-of-band noise. The acquired time-domain signal is weighted by a window function and then fed into a fast acquisition buffer, forming a 1024-point interference signal frame sequence. The receiving link of the flat panel antenna is a high-sensitivity signal receiving channel supporting dual circular polarization mode; the interference signal spectrum data is a digital signal frequency domain energy distribution representation after analog-to-digital conversion.

[0061] Perform multi-order discrete Fourier transform on the spectrum data of the interference signal to extract the main frequency energy distribution data of the preset subharmonics;

[0062] Specifically, a third-order Discrete Fourier Transform (DFT) is performed on each frame of signal. The first-order DFT calculates the amplitude spectrum across the entire frequency band, identifying a set of candidate frequencies above a threshold of -90 dBm. The second-order DFT focuses on the ±2 MHz sub-band within the candidate frequency set, performing a refined analysis of 4096 points to obtain the precise energy values ​​of the candidate frequencies. The third-order DFT normalizes the precise energy values ​​of the candidate frequencies and then performs principal component analysis to filter frequencies with an energy percentage greater than 0.15. Energy distribution data at the third harmonic frequency is extracted to generate a 128-dimensional dominant frequency energy vector. The multi-order Discrete Fourier Transform is a signal processing flow that progressively refines the frequency domain analysis; the dominant frequency energy distribution data is a set of quantized parameters characterizing the energy accumulation features of the interference signal.

[0063] Calculate the information entropy value of the dominant frequency energy distribution data to generate the environmental noise frequency domain energy distribution data.

[0064] Specifically, the dominant frequency energy vector is probabilistically processed, and the probability of the i-th dominant frequency energy is... ,have:

[0065] ,

[0066] In the formula, Let i be the i-th dimension of the dominant frequency energy vector. This is the sum of the 128-dimensional dominant frequency energy vectors. Next, the frequency domain information entropy is calculated. ,have:

[0067] ,

[0068] In the formula, To ensure safety and prevent zero-value overflow, the frequency domain information entropy and the dominant frequency position index are concatenated to form 192-bit environmental noise frequency domain energy distribution data. Here, the information entropy value is a statistical characteristic measuring the degree of spectral energy dispersion; the environmental noise frequency domain energy distribution data is an encrypted parameter reflecting the complexity of the current electromagnetic environment.

[0069] For example, when a central satellite station encounters wireless interference from a subway, its flat panel antenna captures a 1.75GHz signal. After third-order DFT analysis, three main frequency points are identified as 1.752GHz (-81dBm), 1.754GHz (-78dBm), and 1.758GHz (-83dBm). The normalized energy proportions are calculated to be 0.32, 0.41, and 0.27, respectively, all greater than 0.15, satisfying the condition. The third harmonic energy vector entropy value is calculated to be H=2.57bit, which is combined with the frequency point index to generate hexadecimal noise data 0xA3D1F7…. This data dynamically reflects the changes in interference characteristics caused by changes in the subway path.

[0070] By extracting noise feature entropy through multi-level frequency domain analysis, a dynamic environmental fingerprint is constructed. It possesses real-time environmental awareness, capable of capturing transient electromagnetic interference changes; it exhibits unpredictable spectral characteristics, relying on the natural randomness of signal energy distribution; and it possesses resistance to spectral analysis attacks due to the strong correlation between noise parameters and the physical environment. This makes it impossible to reverse-engineer encryption parameters through fixed-frequency scanning, ensuring the anti-interception capability of communication data. This technology enables environmentally adaptive key generation, enhancing system survivability in complex electromagnetic environments.

[0071] Optionally, generating cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network includes:

[0072] Obtain the chip signal-to-noise ratio parameters and link delay spread parameters of the current satellite link;

[0073] Specifically, the correlator module of the spread spectrum receiver captures the despread chip waveform in real time, calculates its peak power to noise floor ratio, and obtains the chip signal-to-noise ratio (SNR) parameter. ,have:

[0074] ,

[0075] In the formula, This represents the squared mean of the maximum amplitude of the relevant peaks. This represents the average noise power during periods without signal. For equipment calibration coefficients, It is a logarithmic function to base 10. The link delay spread parameter is calculated using the phase difference of the multipath components of the received signal. (The last sentence appears to be incomplete and possibly refers to a different parameter.) ,have:

[0076] ,

[0077] In the formula, For the time delay of the m-th path, Let M be the amplitude of the m-th path, and M be the total number of resolvable multipaths. The power-weighted average of the multipath delay is used as the reference point for delay spread. The chip signal-to-noise ratio (SNR) parameter is a time-domain quantization indicator reflecting the signal demodulation quality; the link delay spread parameter is a channel characteristic value characterizing the multipath propagation effect.

[0078] The chip signal-to-noise ratio parameter and the link delay spread parameter are input into a preset stability evaluation model, and the link switching priority parameter is output according to the preset satellite link stability threshold.

[0079] Specifically, the stability assessment model uses a logarithmic linear regression equation to calculate the stability assessment value. For the stability assessment value... ,have:

[0080] ,

[0081] In the formula, This is an adjustment factor for the chip signal-to-noise ratio parameter, which can be set to 0.35. The adjustment factor for the link delay spread parameter can be set to 0.62. Two satellite link stability thresholds can be set, 60 and 80 respectively, for the link handover priority parameter. ,have:

[0082] ,

[0083] Among them, the stability assessment model is a decision function trained based on historical link status data; the link switching priority parameter is a normalized assessment value that quantifies link reliability.

[0084] Based on the preset self-organizing network node distribution density parameters and the link switching priority parameters, cross-network authentication pre-distribution parameters are generated.

[0085] Specifically, the number N of active self-organizing network nodes within a 5km radius is obtained through BeiDou messages, and the self-organizing network node distribution density is calculated. For the self-organizing network node distribution density parameter... ,have:

[0086] ,

[0087] In the formula, π represents the mathematical constant pi. The intermediate values ​​of the pre-distribution parameters are calculated using the self-organizing network node distribution density parameters. For the intermediate values ​​of the pre-distribution parameters... ,have:

[0088] ,

[0089] intermediate value of pre-distributed parameters After being quantized to an 8-bit range, it is combined with the current satellite number to form a 16-bit cross-network authentication pre-distribution parameter.

[0090] For example, when a drilling platform switches satellite links, it measures... , Substituting into the formula, we get Because 1.91 is less than 60, therefore The number of self-organizing network nodes within a 5km radius is N=3. Calculate... , The value is quantized to 8 bits, resulting in 0x01, with the satellite number 0xA5, yielding the cross-network authentication pre-distribution parameter 0xA501. In adverse conditions that exacerbate multipath propagation, a stability assessment model is used to identify link degradation in advance. Combined with sparse node density, low-priority pre-distribution parameters are generated to guide the control center to prioritize resource allocation to satellites in high-density areas, thus avoiding data loss caused by link interruptions.

[0091] Optionally, sending a pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center via the currently valid satellite link includes:

[0092] The dynamic key parameters are encrypted using a quantum key distribution algorithm to generate a first-level encrypted payload;

[0093] Specifically, a simplified variant of the BB84 protocol is used to implement quantum key distribution, transmitting the polarization basis selection sequence through a classical channel. First, the 256-bit dynamic key is divided into 32-byte blocks, with each byte converted into a polarization state of 8 photons (randomly assigned at 0°, 45°, 90°, and 135°). Second, a random basis selection sequence of 32 bytes is generated and transmitted synchronously with the polarization state sequence. Next, the receiving end filters the quantum states matching the basis vectors based on the random basis selection sequence, and generates a shared key after passing a bit error rate test (threshold ≤ 5%). Finally, the shared key is used to perform XOR encryption on the original dynamic key, forming the first-level encrypted payload. The quantum key distribution algorithm uses a key negotiation mechanism based on photon polarization state exchange; the first-level encrypted payload is a ciphertext data unit protected by the characteristics of the quantum channel.

[0094] The cross-network authentication pre-distribution parameters are chaotically confused with the BeiDou positioning parameters to generate a secondary confusion payload;

[0095] Specifically, the Lorenz chaotic system is used to generate confused sequences. For the system of differential equations in the Lorenz chaotic system, we have:

[0096] ,

[0097] ,

[0098] ,

[0099] In the formula, The primary sequence parameter is initialized using the decimal part of the longitude. As auxiliary sequence parameters, their initial values ​​are set using the decimal part of the latitude. For safety reasons, the initial value can be set to 25. , , These are control coefficients, taken during numerical solution. , , After 500 iterations, the last 23 bits of the main sequence parameter are cyclically padded to 32 bits to form an obfuscation mask. This mask is then subjected to a cyclic shift XOR operation with the cross-network authentication parameter to obtain the secondary obfuscation payload.

[0100] For example, at this point, the cross-network authentication pre-distribution parameters, i.e., 16-bit binary data, such as 0xA501, are obtained; the decimal format of the longitude (Lon) and latitude (Lat) in the BeiDou positioning parameters are obtained, such as Lon=120.7352°, Lat=31.2896°; the decimal parts of the longitude and latitude are extracted and normalized to floating-point numbers to obtain the initial master sequence parameters. To obtain the initial auxiliary sequence parameters Initial security parameters The fourth-order Runge-Kutta method was used for 500 iterations with a step size of 0.01, and the control coefficient was set to [value missing]. , , After 500 iterations, the sequence values ​​of the main sequence parameters are obtained. There are a total of 500 floating-point numbers. Take the main sequence parameter 12.573 from step 500, convert it to an IEEE 754 single-precision floating-point number (32 bits), and extract the last 23 bits (e.g., 0x4a3d70a4, mantissa 0011100011010111100010100). Cyclicly fill the 23-bit mantissa into the 32-bit array to generate Mask = 00111000110101111000101000011100. Based on the first byte value of Mask (e.g., 0x3D = 61), determine the number of bits to shift. The cross-network authentication pre-distribution parameter 0xA501 = 1010010100000001, circularly shifted right by 29 bits, becomes: 00000000000000001010010100000001. The shifted data block is then XORed with the Mask bitwise to obtain the second-level obfuscation payload. For example, if the shifted cross-network authentication pre-distribution parameter becomes 0x0000A501 and the Mask is 0x8E3D70A4, then... By combining dynamic chaos with geographic binding, lightweight strong obfuscation is achieved, meeting the low latency and high security requirements of satellite links.

[0101] The first-level encryption payload and the second-level obfuscation payload are fragmented and reassembled to form a pre-authenticated data packet.

[0102] Specifically, such as Figure 3 The pre-authentication data packet structure shown is fragmented into 64-byte segments. After the primary payload fragments are segmented, Hamming code redundancy bits are inserted, and 4 check bits are added every 16 bytes. Secondary payload fragments are appended with a timestamp flag, with the last 16 bits of the UTC microsecond value. The reassembly strategy uses an interleaved arrangement mode; odd-numbered fragments are taken from the primary payload flag 0xA5, and even-numbered fragments are taken from the secondary payload flag 0x5A. A 2-byte synchronization code 0xFF01 is added to the fragment header, and a CRC-16 checksum is appended to the tail, ultimately forming the pre-authentication data packet. The data fragmentation and reassembly uses a data encapsulation method with spatiotemporal identification; the pre-authentication data packet is a transmission protocol data unit containing multiple protection mechanisms.

[0103] For example, the dynamic key is 0x7E3A...D9C4, with BeiDou coordinates E101°12.3456', N25°03.7890'. The shared key generated during the quantum key distribution stage is 0x9B...F2, and the encrypted first-level payload is 0xE5...0D. The initial master sequence parameter of the Lorenz chaotic system is 0.3456, and the initial auxiliary sequence parameter is 0.7890. After iteration, the confusion mask is 0x8D...7F. The cross-network authentication pre-distribution parameter is 0xA51C, which is XORed with the mask to obtain the second-level payload 0x26...93. After fragmentation and reassembly, the pre-authentication data packet structure is as follows: Quantum encryption ensures the resistance to eavesdropping in key transmission, chaotic confusion ensures the inseparability of parameters and location information, and interleaved fragmentation design enables the payload to be parsed even when data packets are partially damaged, verifying robust communication capabilities in complex electromagnetic environments and unstable link scenarios.

[0104] Optionally, extracting the target network session key parameters from the pre-stored backup link key pool includes:

[0105] Obtain the set of candidate keys that match the current BeiDou coordinate parameters from the pre-stored backup link key pool;

[0106] Specifically, read the integer degree values ​​of longitude output by the BeiDou positioning module. Integer degrees in latitude Using a nine-square grid spatial partitioning algorithm, the current coordinates are mapped to a 3×3 grid code (GridCode). The GeoRange field stored in each key record in the key pool contains the center coordinates. With radius (Within ±0.5° range), if the following conditions are met:

[0107] ,

[0108] If a match is found, the key records covering the current grid are selected, and the corresponding key parameters are extracted to form a candidate key set. The backup link key pool is a pre-generated regional key set; the candidate key set is a subset of keys that meet the geographical matching criteria.

[0109] Based on the correlation calculation results between the key validity parameters of the candidate key set and the information entropy value of the main frequency energy distribution data, the optimal candidate key is selected.

[0110] Specifically, calculate the Pearson correlation coefficient between each key's timeliness parameter (the number of minutes from generation time to the current time) and the information entropy value of the main frequency energy distribution data. ,have:

[0111] ,

[0112] In the formula, Let be the timeliness parameter for the j-th candidate key. This is the average of the timeliness parameters for all candidate keys. Let the entropy value of the main frequency energy distribution data corresponding to the j-th candidate key be denoted as . This is the average of the entropy values ​​of all candidate keys. (Reserved) The keys are arranged in reverse chronological order. The first three keys are weighted and scored. For the scores... ,have:

[0113] ,

[0114] In the formula, This is the expiration parameter for the current candidate key. This is the maximum timeliness parameter in the candidate key set. The information entropy value of the current candidate key. The highest information entropy value in the candidate key set is selected. The highest score is chosen as the optimal candidate key. For adjusting the timeliness parameter, This is the information entropy adjustment coefficient. The key validity parameter is a time decay factor describing the key's lifespan; the correlation calculation is a statistical method for measuring the correlation between key validity and environmental noise.

[0115] The optimal candidate key is subjected to secondary obfuscation verification through the multiple harmonic amplitude sequences to generate the target network session key parameters.

[0116] Specifically, the amplitude values ​​of multiple harmonics of the current power amplifier are read and converted into hexadecimal values ​​to obtain the sequence. Construct a nonlinear confusion function to calculate intermediate result parameters of the target network session key parameters. ,have:

[0117] ,

[0118] In the formula, This is the optimal candidate key. This is the hexadecimal value of the fundamental frequency amplitude. This is the hexadecimal value of the third harmonic amplitude. The value is the hexadecimal value of the fifth harmonic amplitude. A SHA-3 polling hash operation is performed 256 times on the intermediate result parameter, and the first 128 bits are truncated as the final key. Simultaneously, the last 8 bits of the hash value are verified to match the BeiDou second pulse count value; if this fails, a suboptimal key is selected. The secondary obfuscation verification is a post-processing mechanism based on physical layer features to enhance key security.

[0119] For example, assuming the current power amplifier's third harmonic amplitude is converted to hexadecimal, the resulting sequence is... The optimal candidate key is 0x1A2B3C4D. The intermediate result parameters are calculated using a nonlinear confusion function. A hash of 0x1AD09771 is performed for 256 rounds, assuming the result is 0x5F3C...A1B2. The first 128 bits, i.e., the first 16 bytes of 0x5F3C...A1B2, are extracted as a candidate key. The last 8 bits of the hash, 0xB2, do not match the BeiDou second pulse count value of 0x78, triggering a downgrade to select a suboptimal key. Through the above process, combining physical layer characteristics (third harmonic) and time reference (BeiDou second pulse), a highly secure session key is generated, ensuring the key's timeliness and replay resistance.

[0120] Optionally, the step of encrypting the uplink data using the target network session key parameters and the pre-authenticated data packet to obtain encrypted communication data includes:

[0121] Production control data is encrypted using a combination of preset lightweight LDPC encoding and dynamic key parameters to generate a first-level encrypted data frame;

[0122] Specifically, production control data is input into a lightweight LDPC encoder. First, a sparse parity check matrix is ​​constructed for linear error correction encoding. Then, a bitwise XOR operation is performed with the dynamic key parameters to achieve double encryption. The lightweight LDPC encoding is a linear error correction code suitable for low-power devices, achieving low-complexity encoding of data and redundant bits through a sparse parity check matrix. The dynamic key parameters are time-varying encryption factors generated based on power amplifier harmonics and environmental noise. The bitwise XOR operation is a bit-by-bit logical operation that achieves simultaneous data obfuscation and encryption.

[0123] For example, production control data is a hexadecimal sequence [0x120xA50x3F], encoded using a parity check matrix [[1,0,0,1],[0,1,1,0],[1,1,0,1]], generating redundant data 0x12A53F encoded as 0x12A53F7C. The dynamic key parameter is 0x9B2D, which, when XORed with it, yields a first-level encrypted data frame 0x819B7243. This process simultaneously achieves error correction and encryption, allowing data recovery even in the event of sudden channel interference.

[0124] The video surveillance data is processed using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology to generate a two-level encrypted data frame;

[0125] Specifically, the video stream is divided into 8x8 blocks and subjected to discrete cosine transform. After extracting the frequency domain coefficients, the positions of the AC components are replaced using a chaotic sequence generated by dynamic key parameters. The DC component is concatenated with the BeiDou timestamp to generate a watermark, which is then embedded in the least significant bit. The frequency domain scrambling compression algorithm achieves data unreadableness by randomizing the positions of the frequency domain coefficients; the chaotic watermark embedding technology utilizes a chaotic system to generate unpredictable marking information.

[0126] The first-level encrypted data frame and the second-level encrypted data frame are time-division multiplexed to form encrypted communication data.

[0127] Specifically, a time-division multiplexer is used to alternately insert data frame content at a 1:3 ratio. 96 bytes of secondary data are inserted after every 32 bytes of primary data, along with a synchronization header of 0xFFEE and a CRC-16 checksum. Time-division multiplexing encoding is a method of achieving mixed transmission of multi-service data through time-slicing; the CRC-16 checksum is a cyclic redundancy check algorithm used to detect transmission errors.

[0128] For example, the first-level encrypted data frame is 128 bytes long, and the second-level encrypted data frame is 384 bytes long. The encoded communication data is: [FFEE][first-level data block 0-31][second-level data block 0-95][CRC16_1], [FFEE][first-level data 32-63][second-level data 96-191][CRC16_2]. This structure ensures that critical production data is transmitted first, video data makes full use of bandwidth, and CRC check ensures integrity.

[0129] For example, sensor data (temperature 28.5°C, pressure 15MPa) from a drilling platform is encoded using lightweight LDPC to generate data blocks of 0x4D2A...B1, which are then XORed with a dynamic key 0x9B2D to obtain 0xD6F7...9C. Simultaneously, video blocks captured by cameras are scrambled in the frequency domain, changing the original DCT matrix [156, -45, 32...] to [-22, 156, 89...], and embedding the last byte of the BeiDou timestamp 0xC7. After multiplexing and encoding, a complete communication data packet containing a synchronization header, dual payloads, and CRC is generated. Production data undergoes dual protection through error correction and dynamic obfuscation, enhancing its resistance to channel interference; randomization of the video data's frequency domain structure prevents image restoration; watermarks and timestamps are bound together to trace the source of tampering; time-division multiplexing balances the real-time nature of control commands with the continuity of video transmission.

[0130] Optionally, the processing of video surveillance data using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology includes:

[0131] The input video stream is divided into time-frequency blocks, and the DC component parameters of each block are extracted.

[0132] Specifically, time-frequency block processing is a video segmentation method that simultaneously considers time windows and frequency domain division, extracting features through a spatiotemporal combination approach; Discrete Cosine Transform (DCT) is an orthogonal transform algorithm that converts spatial domain signals into frequency domain energy distributions; DC component parameters are quantization indicators reflecting the overall average brightness of image blocks and possess temporal stability. The video stream is divided into time-domain blocks of 8 consecutive frames, and each frame is further divided into 8×8 pixel frequency-domain blocks. A Discrete Cosine Transform (DCT) is performed on each block to obtain 64 frequency-domain coefficients, where the first coefficient is the DC component and the remaining 63 are AC components. The DC components of all blocks are extracted and normalized to integer values ​​between 0 and 255 to form a parameter set.

[0133] For example, the grayscale value of an 8×8 pixel block in the 5th frame of the video stream is:

[0134] ,

[0135] After DCT calculation, the coefficient (DC component) in the first row and first column is 1064, which is 106 after normalization. The absolute values ​​of the remaining 63 AC components range from a maximum of 120 to a minimum of 1.2.

[0136] A random permutation matrix is ​​generated based on the dynamic key parameters, and the video blocks are scrambled in the frequency domain.

[0137] Specifically, the permutation sequence is generated using the Logistic chaotic mapping:

[0138] ,

[0139] In the formula, The chaotic sequence value is the input for the (n+1)th iteration. This is the chaotic sequence value output in the (n+1)th iteration. The branch parameter is set to 3.99, representing the initial input chaotic sequence value. The first 4 bytes of the dynamic key are converted into decimals between 0 and 1. 63 random numbers are generated iteratively, and their sorted indices form an AC component permutation matrix. The original AC components are rearranged according to the new indices, while the DC components remain in their original positions.

[0140] For example, the dynamic key is 0x8E3D70A4. The first 4 bytes are converted to decimal 237,045,252, and the normalized initial value is 0.237045252. After iteratively generating 63 chaotic values ​​and sorting them, the permutation order is obtained: [45,12,7,...,32]. The original AC components AC1, AC2,...,AC63 are rearranged in this order to AC45, AC12, AC7...AC32.

[0141] The scrambled segments are logically cross-stitched with the BeiDou timestamp parameters to generate compressed video data segments.

[0142] Specifically, the Coordinated Universal Time (UTC) timestamp, accurate to microseconds, output from the BeiDou module is read and split into high 32 bits (date plus hour) and low 32 bits (minutes plus microseconds). This is then combined with the scrambled DC component using a bit-crossing process. For odd-numbered bytes, the high 4 bits of the DC component are concatenated with the low 4 bits of the timestamp; for even-numbered bytes, the high 4 bits of the timestamp are concatenated with the low 4 bits of the DC component, forming a 64-byte compressed data block. Redundant AC components are discarded. This logical cross-combination is an operation that achieves data obfuscation and spatiotemporal binding through bit rearrangement. The BeiDou timestamp parameter is a high-precision time identifier based on satellite time synchronization, possessing anti-counterfeiting characteristics. The compressed video data segment is an encrypted data unit that removes spatial redundancy while enhancing temporal characteristics.

[0143] For example, the BeiDou timestamp UTC2023-09-15T14:30:45.123456 is converted to hexadecimal 0x07E7090F002B23C0. After scrambling, the DC component is 0x6A. Interleaving the odd-numbered bits (0x6, high four bits 0110) with the low four bits (0xC0) yields 0x6. Conversely, interleaving the even-numbered bits (0x07, high four bits 0xA, low four bits 1010) yields 0x7A. The final compressed block is [0x6C, 0x7A, ...], with a total length of 64 bytes.

[0144] For example, a monitoring system acquires a 1920×1080 video stream, selects the top left corner of the 100th frame as an 8×8 block for processing, extracts the DC component value 0x92 after DCT transformation, generates a chaotic sequence using a dynamic key 0x5F3C, and after permutation, the AC component order is [52,8,3...]. The BeiDou timestamp 0x07E7090F002B23C0 is interleaved with the DC component to obtain the data header 0x9F7C. When transmitted to the satellite terminal, attackers cannot recover the original image, and a timestamp deviation exceeding 2 microseconds triggers verification failure. The video content completely loses its spatial continuity after frequency domain scrambling, making it unreadable by conventional players; the BeiDou timestamp is deeply bound to the data block, and illegal tampering or replay attacks are immediately identified due to time stamp mismatch; logical cross-splitting preserves the core features of the image while avoiding complete data exposure, meeting the confidentiality and integrity requirements of video surveillance in high-security scenarios such as ports.

[0145] Optionally, the method further includes:

[0146] Monitor the bit error rate parameters and power amplifier temperature parameters of the target satellite link;

[0147] Specifically, the bit error rate (BER) of the demodulated signal is statistically analyzed in real time by the satellite baseband processing unit. The percentage of erroneous bits per second out of the total transmitted bits is calculated and recorded as the BER parameter. Temperature data is collected once per second by a thermal sensor within the power amplifier module and compared with a preset threshold range. The BER parameter is a direct quantitative indicator of the communication link transmission quality, reflecting the degree of signal interference. The power amplifier temperature parameter is a physical monitoring value of the high-frequency power amplifier's operating status; excessively high temperatures may cause device failure or safety risks. The monitoring operation is a combined operation of periodic data acquisition and real-time threshold determination.

[0148] For example, the satellite link transmission rate is 2Mbps, and 10,000 bits are received within a 10-millisecond period, with 12 bits being errors. The bit error rate (BER) is calculated to be 0.12%. The power amplifier temperature sensor currently reads 68°C, and the preset safe operating range is -20°C to 75°C. The temperature is determined to be within the limit, but if the BER exceeds the threshold of 0.15%, subsequent operations will be triggered.

[0149] When the bit error rate parameter exceeds a preset security threshold, or the power amplifier temperature parameter exceeds a preset operating range, a preset physical layer fuse module is triggered to destroy the current key pool;

[0150] Specifically, such as Figure 4 As shown, the preset security threshold is a bit error rate of 0.1%-0.2% (adaptively adjusted according to the modulation method), and the preset operating temperature range of the power amplifier is -20°C to 75°C. If any limit is exceeded, the physical layer fuse module sends a high-voltage pulse signal to the key storage chip to perform a physical erase of the flash memory blocks. During the erase process, each byte of the key pool storage address is overwritten with 0xFF, and the hardware fuse flag is permanently set to 0, blocking subsequent key reading operations.

[0151] Based on the BeiDou coordinate parameters before destruction and the multiple harmonic amplitude sequence, a dynamic key synchronization request is re-initiated.

[0152] Specifically, the last valid BeiDou longitude and latitude coordinates (e.g., E110.2536°, N25.7845°) before the key pool is destroyed are combined with the most recent harmonic characteristics of the power amplifier (e.g., fundamental amplitude 15dBm, third harmonic phase difference 30°) to generate a 128-bit synchronization seed. A synchronization request frame is sent through the satellite control channel. The frame structure includes a 2-byte frame header identifier (e.g., 0xAA55), an 8-byte BeiDou coordinate encryption value (e.g., AES-ECB encryption), a 32-bit timestamp (e.g., UTC second-level time), and a 4-byte harmonic characteristic hash value (e.g., SHA-256 truncated).

[0153] For example, during a typhoon, strong interference caused the satellite link error rate to surge to 0.3% (threshold 0.2%), and the equipment temperature rose to 82°C due to heat dissipation failure. This triggered the circuit breaker module to destroy the key pool. The last valid BeiDou coordinates E122.78°, N18.25°, along with harmonic characteristics (fundamental frequency 22dBm, third harmonic phase difference 45°), were used to generate a synchronization seed. The control center verified that the location was within the predetermined area, regenerated and distributed the dynamic key, and restored encrypted communication capabilities. In harsh environments, link anomalies automatically trigger the key protection mechanism; physical-level circuit breaking ensures that attackers cannot extract valid keys. The synchronization mechanism based on the last valid location and hardware characteristics prevents unauthorized key reuse in mobile scenarios and ensures authorized devices can quickly restore communication.

[0154] Based on the same inventive concept, such as Figure 5 As shown, the present invention also provides a satellite portable station data encryption and authentication system, the system comprising:

[0155] The environmental sensing module is used to collect nonlinear harmonic spectrum data of the power amplifier and frequency domain energy distribution data of environmental noise from the satellite terminal.

[0156] The dynamic key generation module is used to perform XOR scrambling on the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters.

[0157] The link evaluation module is used to generate cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network.

[0158] The pre-authentication distribution module is used to send a pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center through the currently valid satellite link;

[0159] The switching execution module is used to extract the target network session key parameters from the pre-stored backup link key pool when the signal quality parameters of the satellite network drop to a preset switching threshold.

[0160] The data encryption module is used to encrypt the uplink data using the target network session key parameters and the pre-authenticated data packet, and then send the encrypted communication data through the target satellite link.

[0161] It should be noted that the formulas described above, through the principle of dimensional consistency and mathematical standardization methods (such as normalization, dimensionless parameter conversion, or unit system unification), can translate physical quantities with different properties into unitless standard values ​​or parameters that can be superimposed in the same dimension. This eliminates the interference of different dimensions on the computational logic, allowing the formulas to retain the original data distribution characteristics while possessing mathematical rationality and adaptability to objective laws. These are conventional technical methods and will not be elaborated further. The electrical connections between the various units described above do not necessarily represent direct or indirect connections; any indirect connection method is applicable to the embodiments of this invention as long as it achieves the purpose of this invention. The above descriptions are merely exemplary embodiments of this invention and should not be construed as limiting the scope of this invention.

[0162] All equivalent changes and modifications made in accordance with the teachings of this invention are still within the scope of this invention. Those skilled in the art will readily conceive of other embodiments of this invention upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this invention that follow the general principles of this invention and include common knowledge or conventional techniques in the art not described herein.

Claims

1. A method for encrypting and authenticating data from a portable satellite station, characterized in that, The method includes: Collect nonlinear harmonic spectrum data of the power amplifier and frequency domain energy distribution data of environmental noise from the satellite terminal; The power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data are XORed and scrambled to generate dynamic key parameters. Based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network, cross-network authentication pre-distribution parameters are generated. This generation includes: obtaining the chip signal-to-noise ratio (SNR) parameter and link delay spread parameter of the current satellite link; inputting the SNR parameter and link delay spread parameter into a preset stability evaluation model; and outputting link switching priority parameters according to the preset satellite link stability threshold; and generating cross-network authentication pre-distribution parameters based on preset ad hoc network node distribution density parameters and the link switching priority parameters. Send a pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center through the current effective satellite link; including encrypting the dynamic key parameters using a quantum key distribution algorithm to generate a first-level encrypted payload; chaotically obfuscating the cross-network authentication pre-distribution parameters with BeiDou positioning parameters to generate a second-level obfuscated payload; and fragmenting and reassembling the first-level encrypted payload and the second-level obfuscated payload to form the pre-authentication data packet; When the signal quality parameters of the satellite network drop to a preset switching threshold, the target network session key parameters are extracted from the pre-stored backup link key pool. The uplink data is encrypted using the target network session key parameters and the pre-authenticated data packet to obtain encrypted communication data, which is then transmitted via the target satellite link.

2. The satellite portable station data encryption and authentication method according to claim 1, characterized in that, The power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data acquired by the satellite terminal include: During the satellite power amplifier startup phase, the preset spectrum analysis module continuously collects multiple harmonic amplitude sequences within the preset frequency band and calculates the amplitude difference data. The amplitude difference data is subjected to chaotic phase mapping processing to generate terminal fingerprint parameters; The terminal fingerprint parameters are hashed and bound to the coordinate parameters obtained through the BeiDou positioning module to form the nonlinear harmonic spectrum data of the amplifier.

3. The satellite portable station data encryption and authentication method according to claim 2, characterized in that, The power amplifier nonlinear harmonic spectrum data and environmental noise frequency domain energy distribution data acquired by the satellite terminal also include: The interference signal spectrum data of the preset frequency band is captured in real time through the receiving link of the flat panel antenna; Perform multi-order discrete Fourier transform on the spectrum data of the interference signal to extract the main frequency energy distribution data of the preset subharmonics; Calculate the information entropy value of the dominant frequency energy distribution data to generate the environmental noise frequency domain energy distribution data.

4. The satellite portable station data encryption and authentication method according to claim 3, characterized in that, The extraction of target network session key parameters from the pre-stored backup link key pool includes: Obtain the set of candidate keys that match the current BeiDou coordinate parameters from the pre-stored backup link key pool; Based on the correlation calculation results between the key validity parameters of the candidate key set and the information entropy value of the main frequency energy distribution data, the optimal candidate key is selected. The optimal candidate key is subjected to secondary obfuscation verification through the multiple harmonic amplitude sequences to generate the target network session key parameters.

5. The satellite portable station data encryption and authentication method according to claim 4, characterized in that, The process of encrypting the uplink data using the target network session key parameters and the pre-authenticated data packet to obtain the encrypted communication data includes: Production control data is encrypted using a combination of preset lightweight LDPC encoding and dynamic key parameters to generate a first-level encrypted data frame; The video surveillance data is processed using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology to generate a two-level encrypted data frame; The first-level encrypted data frame and the second-level encrypted data frame are time-division multiplexed to form encrypted communication data.

6. The satellite portable station data encryption and authentication method according to claim 5, characterized in that, The process of processing video surveillance data using a frequency domain scrambling compression algorithm and chaotic watermark embedding technology includes: The input video stream is divided into time-frequency blocks, and the DC component parameters of each block are extracted. A random permutation matrix is ​​generated based on the dynamic key parameters, and the video blocks are scrambled in the frequency domain. The scrambled segments are logically cross-stitched with the BeiDou timestamp parameters to generate compressed video data segments.

7. The satellite portable station data encryption and authentication method according to claim 2, characterized in that, The method further includes: Monitor the bit error rate parameters and power amplifier temperature parameters of the target satellite link; When the bit error rate parameter exceeds a preset security threshold, or the power amplifier temperature parameter exceeds a preset operating range, a preset physical layer fuse module is triggered to destroy the current key pool. Based on the BeiDou coordinate parameters before destruction and the multiple harmonic amplitude sequence, a dynamic key synchronization request is re-initiated.

8. A satellite portable station data encryption and authentication system, applied to the satellite portable station data encryption and authentication method as described in any one of claims 1-7, characterized in that, The system includes: The environmental sensing module is used to collect nonlinear harmonic spectrum data of the power amplifier and frequency domain energy distribution data of environmental noise from the satellite terminal. The dynamic key generation module is used to perform XOR scrambling on the power amplifier nonlinear harmonic spectrum data and the environmental noise frequency domain energy distribution data to generate dynamic key parameters. The link evaluation module is used to generate cross-network authentication pre-distribution parameters based on a preset satellite link stability threshold and the signal quality parameters of the current satellite network. This generation includes: obtaining the chip signal-to-noise ratio (SNR) parameter and link delay spread parameter of the current satellite link; inputting the SNR parameter and link delay spread parameter into a preset stability evaluation model; outputting link switching priority parameters according to the preset satellite link stability threshold; and generating cross-network authentication pre-distribution parameters based on preset ad hoc network node distribution density parameters and the link switching priority parameters. The pre-authentication distribution module is used to send a pre-authentication data packet containing the dynamic key parameters and cross-network authentication pre-distribution parameters to the multi-network control center through the currently effective satellite link; including encrypting the dynamic key parameters using a quantum key distribution algorithm to generate a first-level encrypted payload; chaotically obfuscating the cross-network authentication pre-distribution parameters with BeiDou positioning parameters to generate a second-level obfuscated payload; and fragmenting and reassembling the first-level encrypted payload and the second-level obfuscated payload to form a pre-authentication data packet; The switching execution module is used to extract the target network session key parameters from the pre-stored backup link key pool when the signal quality parameters of the satellite network drop to a preset switching threshold. The data encryption module is used to encrypt the uplink data using the target network session key parameters and the pre-authenticated data packet, and then send the encrypted communication data through the target satellite link.

Citation Information

Patent Citations

  • Satellite switching authentication method for low earth orbit satellite network

    CN116056080A

  • Security encryption communication method and system based on quantum key management

    CN119316138A