AI-based satellite communication encryption strategy dynamic optimization method and system
The AI-driven optimization of satellite communication encryption through spatiotemporal graph convolution networks and quantum-resistant key distribution addresses inefficiencies in dynamic satellite networks, reducing reconstruction delay and signaling overhead while enhancing security against quantum threats.
Patent Information
- Application Number
- CN202510637834.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-07-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the low-orbit satellite constellation scenario, the contradiction between key management efficiency and security caused by dynamic topological changes is prominent. The existing methods are difficult to adapt to the network state in real time, and lack the dynamic upgrade mechanism of encryption algorithms, so they cannot effectively deal with quantum computing threats and cross-protocol layer attacks.
Using AI-based methods, multicast member connection probability is predicted through spatiotemporal graph convolution network, multicast key tree structure is dynamically optimized, quantum dynamic key distribution is achieved in combination with quantum attack threat evaluation, and model parameters are optimized through closed-loop verification mechanism to achieve coordinated improvement of key update efficiency and security protection.
Significantly reduce key reconstruction delay and signaling overhead, enhance the ability to resist quantum computing attacks, improve cross-protocol layer collaborative protection, and solve the problem of insufficient adaptability of traditional solutions in dynamic topology scenarios.
Smart Images

Figure CN120321645A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of satellite communication, and particularly relates to a method and system for dynamically optimizing satellite communication encryption strategies based on AI. Background Art
[0002] In the field of satellite multicast communication, especially in the scenario of low-earth orbit satellite constellations, the contradiction between key management efficiency and security caused by dynamic topology changes has become increasingly prominent. Traditional multicast key management schemes rely on static logical key tree structures. When satellite nodes or ground terminals frequently switch due to high-speed movement, it is necessary to fully update the affected key branches, resulting in a large amount of communication bandwidth occupied by key update signaling.
[0003] Existing improvement schemes attempt to achieve key pre-distribution through member location prediction. However, due to the dynamicity of satellite orbits and the randomness of user access, it is difficult for the preset key tree depth and topology binding relationship to adapt to the actual network state in real time, and there are still problems such as excessive key reconstruction delay and redundant update paths.
[0004] Meanwhile, in the context of the gradually emerging threat of quantum computing, existing methods lack a dynamic upgrade mechanism for encryption algorithms, and it is difficult to balance security strength and resource consumption with fixed key lengths and encapsulation modes.
[0005] In addition, the isolated operation of physical layer and application layer encryption strategies enables attackers to implement man-in-the-middle attacks through cross-protocol layer vulnerabilities.
[0006] Therefore, there is an urgent need for an intelligent encryption strategy that can real-time sense the network state, dynamically optimize the key structure, and cooperate with quantum-resistant protection to address security challenges in high-dynamic satellite communication environments. Summary of the Invention
[0007] Based on this, it is necessary to provide a method and system for dynamically optimizing satellite communication encryption strategies based on AI for the above technical problems.
[0008] In the first aspect, the present application provides a method for dynamically optimizing satellite communication encryption strategies based on AI, including:
[0009] S1: Collect the status data of satellite multicast members, and generate a spatio-temporal topology graph based on the status data; wherein, the spatio-temporal topology graph is a graph structure model including satellite node positions, communication links, and time slices;
[0010] S2: Based on the spatio-temporal topology graph, perform multicast member behavior prediction through a spatio-temporal graph convolutional network to generate a member connection probability matrix; wherein, the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution;
[0011] S3: Dynamically generate a multicast key tree structure with the minimum reconstruction cost according to the member connection probability matrix, where the minimum reconstruction cost is a weighted optimization metric that comprehensively considers the key tree depth, update path length, and storage overhead;
[0012] S4: Based on the quantum attack threat assessment result, perform quantum-resistant dynamic key distribution on the multicast key tree structure; wherein, the quantum-resistant dynamic key distribution is a process of switching to a quantum cryptographic algorithm according to the quantum attack threat assessment result;
[0013] S5: Evaluate the key update performance through multi-index closed-loop verification to obtain a performance evaluation result; generate a model tuning instruction based on the performance evaluation result to update the spatio-temporal graph convolutional network.
[0014] In a second aspect, the present application also provides an AI-based dynamic optimization system for satellite communication encryption strategies, including:
[0015] A data collection and modeling module, configured to collect the status data of satellite multicast members and generate a spatio-temporal topology graph based on the status data; wherein, the spatio-temporal topology graph is a graph structure model that includes satellite node positions, communication links, and time slices;
[0016] A behavior prediction module, configured to perform multicast member behavior prediction through a spatio-temporal graph convolutional network based on the spatio-temporal topology graph to generate a member connection probability matrix; wherein, the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution;
[0017] A key tree optimization module, configured to dynamically generate a multicast key tree structure with the minimum reconstruction cost according to the member connection probability matrix, where the minimum reconstruction cost is a weighted optimization metric that comprehensively considers the key tree depth, update path length, and storage overhead;
[0018] A key distribution module, configured to perform quantum-resistant dynamic key distribution on the multicast key tree structure based on the quantum attack threat assessment result; wherein, the quantum-resistant dynamic key distribution is a process of switching to a quantum cryptographic algorithm according to the quantum attack threat assessment result;
[0019] A performance evaluation and tuning module, configured to evaluate the key update performance through multi-index closed-loop verification to obtain a performance evaluation result; generate a model tuning instruction based on the performance evaluation result to update the spatio-temporal graph convolutional network.
[0020] In a third aspect, the present application also provides a computer device, including a memory and a processor, where the memory stores a computer program, and the processor implements an AI-based dynamic optimization method for satellite communication encryption strategies as described in the first aspect when executing the computer program.
[0021] In a fourth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a method for dynamically optimizing an AI-based satellite communication encryption policy as described in the first aspect.
[0022] The above-mentioned method and system for dynamically optimizing an AI-based satellite communication encryption policy collect dynamic topology data of satellite multicast members to construct a spatio-temporal network model, use a spatio-temporal graph convolutional network to predict member connection behaviors and generate a probability matrix, dynamically optimize the depth of the multicast key tree structure and the key distribution path based on the prediction results, realize the adaptive switching of post-quantum cryptographic algorithms in combination with quantum attack threat assessment, and continuously optimize model parameters through a closed-loop verification mechanism. Finally, the collaborative improvement of key update efficiency and security protection ability is achieved in the high-dynamic environment of satellite communication, significantly reducing key reconstruction latency and signaling overhead, while enhancing the anti-quantum computing attack and cross-protocol layer collaborative protection capabilities, effectively solving the problem of insufficient adaptability of traditional static key management schemes in dynamic topology scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a schematic flowchart of a method for dynamically optimizing an AI-based satellite communication encryption policy provided by the present invention;
[0025] Figure 2 It is a schematic structural diagram of a system for dynamically optimizing an AI-based satellite communication encryption policy provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] In order to make the objectives, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0027] Refer to Figure 1 , which shows a schematic flowchart of a method for dynamically optimizing an AI-based satellite communication encryption policy provided by the present application. The method includes the following steps:
[0028] S1: Collect the status data of satellite multicast members and generate a spatio-temporal topology graph based on the status data; wherein, the spatio-temporal topology graph is a graph structure model including satellite node positions, communication links, and time slices.
[0029] Specifically, for obtaining satellite node status data, the satellite's own navigation system and communication system can be used to obtain the satellite's position information (such as longitude, latitude, altitude), velocity vector (magnitude and direction of velocity), attitude information (pitch angle, yaw angle, roll angle), and the status of communication links (such as signal strength, bandwidth utilization, bit error rate, etc.). These data can reflect the real-time position and communication capabilities of the satellite in orbit.
[0030] For obtaining ground terminal status data, the ground terminal can use its own positioning module (such as GPS, Beidou, etc.) to obtain position information and feedback it to the satellite system through the communication module. At the same time, the ground terminal also provides its own communication requirements (such as data transmission rate requirements, communication service types, etc.) for the satellite system to perform reasonable resource allocation and key management.
[0031] For obtaining network topology data, the topological structure information of the satellite constellation can be collected, including the connection relationship of communication links between satellites, and parameters such as link delay and bandwidth. These data help to construct an accurate spatio-temporal topology map, reflecting the architecture and communication characteristics of the entire satellite communication network.
[0032] In addition to the real-time collected data, historical status data can also be collected for analyzing the motion patterns and communication behavior rules of satellites and ground terminals. At the same time, combined with external data such as weather forecasts and space environment monitoring, environmental factors that may affect satellite communication can be predicted, such as interference from solar activities on communication links.
[0033] For constructing the graph structure model, satellite nodes and ground terminals can be used as nodes in the graph, and communication links as edges to construct a spatio-temporal topology graph. Each node contains information such as the identifier, position, and status of the satellite or ground terminal, and the edge contains parameters of the communication link, such as bandwidth, delay, and signal quality.
[0034] Slice the spatio-temporal topology graph by time, and each time slice represents the network status at a specific time point or time period. In this way, the dynamic changes of satellites and ground terminals, as well as the time-varying characteristics of communication links, can be captured. For example, slicing can be performed at second-level, minute-level, or finer time granularity, which can be specifically determined according to the real-time performance and accuracy requirements of the satellite communication system.
[0035] Fuse various types of collected status data into the spatio-temporal topology graph, and continuously update the graph structure and parameters according to real-time data. Adopt data fusion algorithms such as Kalman filtering and particle filtering to estimate and correct information such as the position and speed of satellites and ground terminals, and improve the accuracy of the spatio-temporal topology graph. At the same time, use technologies such as graph databases to store and manage the spatio-temporal topology graph, and support efficient query and update operations to meet the requirements of satellite communication systems for real-time performance and reliability.
[0036] S2: Based on the spatio-temporal topology graph, perform multicast member behavior prediction through a spatio-temporal graph convolutional network to generate a member connection probability matrix; among them, the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution.
[0037] Specifically, in the graph structure, the spatial relationship between satellite nodes and ground terminals is represented by an adjacency matrix. The spatial convolution operation updates the feature representation of the current node by aggregating the information of neighboring nodes. For example, for a satellite node, its neighboring nodes may include satellites in adjacent orbits and ground terminals within the communication range. Through spatial convolution, the spatial dependence relationship between nodes can be captured, such as the impact of the quality of communication links on data transmission.
[0038] Temporal convolution is used to process time series data in the spatio-temporal topology graph. One-dimensional convolution operations are adopted to perform convolution on the node features on the time slices to capture the changing trends of node states over time. For example, through temporal convolution, the changing rules of the positions of satellite nodes at different time points and the fluctuations of the communication requirements of ground terminals over time can be analyzed.
[0039] Combine spatial convolution and temporal convolution to construct a spatio-temporal graph convolutional network. At each layer of the network, first perform a spatial convolution operation to aggregate the spatial information of neighboring nodes, and then perform a temporal convolution operation to capture the changing patterns in the time series. Through a multi-layer network structure, gradually extract the high-level spatio-temporal features of the nodes to provide richer information for multicast member behavior prediction.
[0040] Input the spatio-temporal topology graph into the spatio-temporal graph convolutional network, and the network automatically learns the spatio-temporal feature representation of the nodes. These features include the changing trends of the positions of satellites and ground terminals, the stability of communication links, and the changes in data transmission requirements. Through feature extraction, the complex spatio-temporal topology graph can be transformed into a low-dimensional feature vector for subsequent prediction tasks.
[0041] Based on the learned node features, a membership connection probability matrix is generated through an output layer (such as a fully connected layer). The elements of the matrix represent the probability that a multicast member (satellite node or ground terminal) remains connected within a specific future time window. For example, for a ground terminal, its connection probability may be affected by factors such as its movement trajectory, communication service type, and satellite orbital position. Through probability prediction, the change in the connection status of multicast members can be understood in advance, providing a basis for the dynamic adjustment of the key management strategy.
[0042] S3: Dynamically generate a multicast key tree structure with the minimum reconstruction cost according to the membership connection probability matrix, where the minimum reconstruction cost is a weighted optimization metric that comprehensively considers the key tree depth, update path length, and storage overhead.
[0043] Specifically, the depth of the key tree affects the complexity and security of key management. A deeper key tree structure may lead to a longer key update path, increasing the latency and communication overhead of key updates. Therefore, when constructing a multicast key tree, consider how to control the depth of the tree to minimize the complexity of key updates while ensuring security.
[0044] The update path length refers to the path length required to pass from the root node to the affected leaf node during the key update process. A shorter update path can reduce the transmission latency and bandwidth occupancy of key update signaling. By optimizing the update path length, the efficiency of key updates can be improved to adapt to the highly dynamic characteristics of satellite communication networks.
[0045] The storage overhead includes the storage space required for satellite nodes and ground terminals to store key information. In resource-constrained satellite systems, reducing the storage overhead is crucial for improving the overall performance of the system. Therefore, when generating a multicast key tree, comprehensively consider the structural design of the key tree to reduce the storage requirements.
[0046] According to the initial membership connection probability matrix, use a traditional multicast key tree construction algorithm (such as the logical key tree algorithm) to generate an initial multicast key tree structure. The initial key tree organizes multicast members into a tree structure, where the root node holds the keys of all members, the leaf nodes hold the keys of individual members, and the intermediate nodes hold the keys of subtrees.
[0047] As the membership connection probability matrix is updated (based on the real-time spatio-temporal topology map and the prediction results of the spatio-temporal graph convolutional network), the multicast key tree is dynamically adjusted. When it is predicted that the connection probability of some multicast members is low, they can be removed from the key tree in advance or their positions in the tree can be adjusted to reduce the cost of key reconstruction. For example, for a ground terminal that is about to leave the multicast group, the corresponding leaf node can be removed from the key tree in advance, and the keys of the subtree can be reallocated to avoid large-scale key update operations when the member actually leaves.
[0048] Use optimization algorithms (such as genetic algorithms, simulated annealing algorithms, etc.) to search for the multicast key tree structure with the minimum reconstruction cost. During the optimization process, take the minimum reconstruction cost as the optimization objective function, and through iterative calculations and adjustments, find the key tree structure that meets the requirements of security and efficiency. At the same time, consider the scalability of the key tree so that it can quickly adapt to the new network state when the number of multicast members changes.
[0049] S4: Based on the results of quantum attack threat assessment, perform quantum-resistant dynamic key distribution for the multicast key tree structure; where the quantum-resistant dynamic key distribution is the process of switching to a quantum cryptography algorithm according to the results of quantum attack threat assessment.
[0050] Specifically, evaluate the current development level of quantum computing technology and the potential quantum computing power. Consider factors such as the number of qubits, the accuracy of quantum gate operations, and the efficiency of quantum algorithms, and analyze the degree of threat that attackers may pose to the satellite communication encryption system using quantum computing technology. For example, with the increase in the number of qubits and the improvement of quantum algorithms, some traditional public key encryption algorithms (such as RSA, ECC, etc.) may face the risk of being cracked.
[0051] Conduct a vulnerability analysis of the encryption algorithms used in the existing multicast key tree structure. Evaluate the security of the encryption algorithms in the quantum computing environment, such as whether the key length is sufficient to resist quantum attacks and whether the mathematical basis of the encryption algorithms is easily cracked by quantum algorithms. For example, encryption algorithms based on integer factorization or elliptic curve discrete logarithm problems may no longer be secure in the face of quantum computing and need to be upgraded in a timely manner.
[0052] According to the results of quantum computing power and encryption algorithm vulnerability analysis, divide the quantum attack threats into different levels. For example, the threat levels can be divided into low, medium, and high levels, corresponding to different degrees of quantum attack risks. According to the threat levels, formulate corresponding quantum-resistant dynamic key distribution strategies to ensure that the key management of the satellite communication system can effectively resist quantum attacks under different security threats.
[0053] According to the results of quantum attack threat assessment, select appropriate post-quantum cryptography algorithms (such as lattice-based cryptography algorithms, hash-based cryptography algorithms, multivariate polynomial-based cryptography algorithms, etc.) as the encryption algorithms for key distribution. Post-quantum cryptography algorithms should have the ability to resist quantum computing attacks, while also taking into account computational efficiency and communication overhead. For example, between satellite nodes with high security requirements and relatively sufficient computing resources, lattice-based cryptography algorithms can be used; while in the scenario of satellite communication between resource-constrained ground terminals, lightweight post-quantum cryptography algorithms such as hash-based signature algorithms can be selected.
[0054] Design the specific process of quantum-resistant dynamic key distribution. Based on the multicast key tree structure, redefine the steps and protocols of key distribution according to the characteristics of post-quantum cryptographic algorithms. For example, during the key update process, the satellite node, acting as the root node, generates a new root key using a post-quantum cryptographic algorithm and distributes the updated key to the child nodes through a secure channel. After receiving the updated key, the child nodes use the corresponding post-quantum cryptographic algorithm for verification and decryption to update the local key information. Meanwhile, consider the fault tolerance mechanism and identity authentication during the key distribution process to prevent illegal node access and key tampering.
[0055] Establish a dynamic switching mechanism for the key distribution algorithm. When the result of the quantum attack threat assessment changes, it can promptly switch from the traditional key distribution algorithm to a post-quantum cryptographic algorithm or switch between different post-quantum cryptographic algorithms to adapt to the changing quantum computing threat environment. The dynamic switching mechanism should ensure the smoothness and security of the switching process, avoiding vulnerabilities in key management or service interruptions during the switching process. For example, through version control and gradual updates, the key distribution algorithm can be switched without affecting the existing communication services.
[0056] S5: Evaluate the key update performance through multi-index closed-loop verification to obtain the performance evaluation result; generate model tuning instructions based on the performance evaluation result to update the spatio-temporal graph convolutional network.
[0057] Specifically, measure the time interval from the initiation of the key update operation to the successful reception and application of the new key by the multicast members. This includes the time consumed in each link such as key generation, distribution, transmission, verification, and decryption. The key update delay directly affects the real-time performance of the satellite communication system. Especially in the scenario of a high-dynamic low-Earth orbit satellite constellation, an overly long update delay may lead to communication interruption or data leakage.
[0058] Statistically analyze the communication bandwidth resources occupied during the key update process. This includes the size and transmission frequency of the key update signaling and its impact on the normal communication data stream. Excessive communication bandwidth occupancy will increase the load of the satellite communication system and reduce communication efficiency. Therefore, it needs to be effectively controlled during the key management process.
[0059] Evaluate the anti-attack ability of the key, including the entropy value of the key, the probability of key leakage, and the security strength against quantum attacks. Through simulation attack experiments and mathematical analysis methods, quantitatively evaluate the security of the key to ensure that the key can effectively resist various attack threats in a complex network environment.
[0060] Monitor the computing resources (such as CPU usage, memory occupancy) and storage resources (such as the size of the key storage space) consumed by the monitoring satellite nodes and ground terminals during the key management process. In a satellite system with limited resources, reducing system resource consumption is of great significance for improving the overall performance and stability of the system.
[0061] During the actual operation of the satellite communication system, real-time collection of key update performance data is carried out through monitoring tools and logging functions. These data include specific values of key update latency, communication bandwidth occupancy, key security-related parameters, and system resource consumption, etc. At the same time, preprocess the collected data, such as data cleaning, outlier handling, etc., to ensure the accuracy and reliability of the data.
[0062] Compare the collected performance data with preset performance thresholds or target values to evaluate whether the key update performance meets the system requirements. If the performance indicators exceed the threshold range, it indicates that there are problems with the current key management strategy and adjustments are needed. The evaluation results are transmitted to the model tuning module through a feedback mechanism as the basis for generating model tuning instructions. The closed-loop verification process continues, forming a closed-loop performance optimization loop, continuously promoting the improvement and perfection of the key management strategy.
[0063] Based on the performance evaluation results, analyze the deficiencies of the spatio-temporal graph convolutional network in predicting multicast member behavior. For example, if the key update latency is too high, it may be due to inaccurate prediction of member connection probabilities, resulting in frequent reconstruction of the key tree structure. To address these issues, generate specific model tuning instructions, such as adjusting network hyperparameters (learning rate, convolutional kernel size, number of network layers, etc.), increasing the amount of training data, optimizing the loss function, etc. The tuning instructions aim to guide the improvement direction of the spatio-temporal graph convolutional network and improve its prediction accuracy and adaptability.
[0064] According to the model tuning instructions, perform update operations on the spatio-temporal graph convolutional network. This can include retraining the network model, fine-tuning network parameters, expanding the network structure, etc. During the update process, use new training data (such as the latest spatio-temporal topology graph and member connection probability matrix) to train the network, optimize the network's weight and bias parameters, enabling it to better capture the spatio-temporal characteristics of the satellite communication network and improve the accuracy of multicast member behavior prediction. At the same time, verify and test the updated network to ensure that its performance meets the requirements and deploy it in the actual system to enhance the dynamic optimization ability of the key management strategy.
[0065] The above-mentioned dynamic optimization method for satellite communication encryption strategy based on AI constructs a spatio-temporal network model by collecting dynamic topology data of satellite multicast members, uses a spatio-temporal graph convolutional network to predict member connection behaviors and generate a probability matrix, dynamically optimizes the depth of the multicast key tree structure and the key distribution path based on the prediction results, realizes the adaptive switching of post-quantum cryptography algorithms in combination with quantum attack threat assessment, and continuously tunes model parameters through a closed-loop verification mechanism. Finally, it achieves the collaborative improvement of key update efficiency and security protection ability in the high-dynamic environment of satellite communication, significantly reduces key reconstruction latency and signaling overhead, while enhancing the anti-quantum computing attack and cross-protocol layer collaborative protection capabilities, and effectively solves the problem of insufficient adaptability of traditional static key management schemes in dynamic topology scenarios.
[0066] In an optional embodiment, S1 includes the following steps:
[0067] S11: Obtain the orbital parameters and real-time position coordinates of the multicast members through the inter-satellite link, perform motion vector calculations on the orbital parameters and real-time position coordinates to generate satellite node motion vectors, where the motion vector is a vector containing radial velocity and angular velocity.
[0068] Specifically, utilize the inter-satellite link between satellites to achieve data communication between satellite nodes. Through the link transmission protocol, regularly send and receive information packets containing orbital parameters and real-time position coordinates. The orbital parameters include Keplerian orbital elements such as the satellite's orbital altitude, orbital inclination, right ascension of the ascending node, and orbital eccentricity, which can accurately describe the orbital shape and position of the satellite. The real-time position coordinates are obtained through the satellite's on-board navigation system (such as GPS, Beidou, etc.) and represent the precise position of the satellite at a certain moment in the form of three-dimensional space coordinates (x, y, z).
[0069] At the receiving satellite node, parse and preprocess the data obtained through the inter-satellite link. Check the integrity and accuracy of the data, and remove abnormal data points and error information. At the same time, uniformly convert data in different formats and units into the standard format within the system for subsequent calculation and processing.
[0070] According to the satellite's orbital parameters and real-time position coordinates, use Kepler's laws and the satellite dynamics model to calculate the radial velocity of the satellite in the orbit. The radial velocity represents the velocity component of the satellite along the orbital radius direction and reflects the approaching or receding trend of the satellite in the orbit. The calculation method includes calculating the time derivative of the satellite position and deriving it in combination with the geometric relationship of the orbital parameters.
[0071] Based on the orbital altitude of the satellite and Kepler's third law, calculate the angular velocity of the satellite. The angular velocity describes how fast the satellite rotates around the Earth and is an important parameter of the satellite's motion state. By accurately calculating the angular velocity, the position change of the satellite in the orbit can be predicted, providing basic data for the subsequent construction of the spatio-temporal topology map.
[0072] Combine the calculated radial velocity and angular velocity into a motion vector, which comprehensively describes the motion direction and speed magnitude of the satellite node in the orbit. As an important feature of the satellite node state, the motion vector will play a key role in the subsequent construction of the spatio-temporal topology map and the prediction of multicast member behavior.
[0073] S12: Receive the access status data of the user terminal reported by the ground gateway, extract features from the access status data, and generate signal strength features and access time window features. Among them, the access time window feature is the prediction result of the time interval during which the user terminal can communicate.
[0074] Specifically, as a bridge between the satellite communication system and the ground user terminal, the ground gateway is responsible for collecting the access status data of the user terminal and reporting it to the satellite system. The reported data includes the identification, location information, communication status, signal strength, etc. of the user terminal. These data are transmitted through the ground communication network to the satellite ground control center, and then forwarded by the control center to the relevant satellite nodes.
[0075] The satellite node parses the data reported by the ground gateway received, extracts the useful information from it. Store the parsed data according to the preset structure and format for subsequent feature extraction and analysis. The storage structure may include forms such as database tables and data files to ensure the orderliness and accessibility of the data.
[0076] Extract the signal strength information of the user terminal from the access status data as the signal strength feature. The signal strength reflects the quality of the communication link between the user terminal and the satellite and is usually expressed in the form of received signal power or signal-to-noise ratio, etc. Conduct statistical analysis on the signal strength data, such as calculating the average value, maximum value, minimum value, etc., and extract the characteristic parameters that can represent the signal strength change trend.
[0077] Based on the access time record of the user terminal, use time series analysis and prediction algorithms to generate the access time window feature. The access time window feature represents the prediction result of the time interval during which the user terminal can communicate in a specific future time period. For example, by analyzing the historical access time pattern of the user terminal, predict its active time window in the next few hours or days, providing a basis for the subsequent dynamic adjustment of the multicast key tree structure.
[0078] S13: Perform fusion processing on the satellite node motion vectors, signal strength features, access time window features, and channel error rate data to construct a spatio-temporal topology graph G = (V, E, T); where the node v i ∈V represents the i-th multicast member, and the edge e ij ∈E represents the communication link between the node v i and the node v j , and the time slice T is divided according to the satellite ephemeris.
[0079] Specifically, fuse the satellite node motion vectors generated in step S11, the signal strength features and access time window features extracted in step S12, and the channel error rate data. Adopt data fusion algorithms such as weighted average and Kalman filtering to integrate these data from different sources and describing different aspects of characteristics into a unified data set. During the fusion process, consider the weights and correlations of each data to ensure that the fusion result can accurately reflect the overall state of the satellite communication network.
[0080] Perform calibration and supplementary processing on the fused data to eliminate noise and errors in the data and fill in missing data points. Use methods such as data interpolation and machine learning to repair incomplete or inaccurate data and improve the quality and reliability of the data.
[0081] Based on the fused data, construct a spatio-temporal topology graph. The nodes in the graph represent the i-th multicast member (including satellite nodes and user terminals), and the edges represent the communication links between the nodes. The weight of the communication link can be determined by parameters such as signal strength and error rate, reflecting the quality and reliability of the link.
[0082] Perform time slice division according to the satellite ephemeris. The satellite ephemeris provides the precise position and time information of the satellite in orbit. Divide the time into multiple slices according to the ephemeris, and each slice represents a specific time period. Record the status of the multicast members and the communication link conditions within each time slice to form the time dimension of the spatio-temporal topology graph.
[0083] As the satellite nodes move and the access status of the user terminals changes, update the structure and parameters of the spatio-temporal topology graph in real time. By monitoring the system state changes, trigger the update operation of the graph structure to ensure that the spatio-temporal topology graph can dynamically reflect the actual situation of the satellite communication network. Adopt an efficient graph update algorithm such as incremental graph update to reduce the computational complexity and resource consumption during the update process.
[0084] In an alternative embodiment, S2 includes the following steps:
[0085] S21: Perform spatial convolution processing on the spatio-temporal topology graph to extract the relative motion features between satellite nodes; generate a spatial feature tensor based on the relative motion features; wherein, the relative motion features include the elevation change rate and the distance change rate between satellite nodes.
[0086] Specifically, use a pre-designed convolution kernel to perform spatial convolution processing on the spatio-temporal topology graph. The size and shape of the convolution kernel are determined according to the scale and topological structure characteristics of the satellite communication network to ensure that the local spatial features between satellite nodes can be effectively captured. In the convolution operation, the convolution kernel slides on the nodes and edges of the graph, performing linear combination and non-linear transformation on the feature vectors of the nodes to extract the relative motion features between satellite nodes.
[0087] Through the spatial convolution operation, focus on extracting relative motion features such as the elevation change rate and the distance change rate between satellite nodes. The elevation change rate reflects the change speed of the relative position between satellites in the vertical direction, and the distance change rate represents the change of the relative distance between satellites over time. These features can accurately describe the dynamic relationship of satellite nodes in space and provide a basis for predicting the behavior of multicast group members in the future.
[0088] Integrate the extracted relative motion features between satellite nodes and construct a spatial feature tensor according to certain rules and dimensions. The dimension design of the tensor considers factors such as the number of satellite nodes, the type of features, and the time series to comprehensively represent the spatial features of the satellite communication network. For example, one dimension of the tensor can represent different satellite nodes, another dimension represents different relative motion features, and the last dimension represents the time series, thus forming a three-dimensional spatial feature tensor.
[0089] S22: Perform temporal convolution processing on the spatio-temporal topology graph to analyze the periodicity of the access patterns of satellite multicast group members and generate time series prediction results; wherein, the periodicity is the time interval rule of the recurrence of the satellite coverage area.
[0090] Specifically, perform temporal convolution processing on the spatio-temporal topology graph and use a one-dimensional convolution kernel to perform convolution operations on the features of the nodes along the time axis. The size of the temporal convolution kernel is determined according to the interval of time slices and the time window requirements of the prediction task to capture the local correlation and periodicity of the access patterns of satellite multicast group members in time.
[0091] Through the temporal convolution operation, analyze the periodicity of the access patterns of satellite multicast group members. Focus on identifying the time interval rules of the recurrence of the satellite coverage area, such as the time period when the satellite passes through the same area, the peak and trough periods of user terminal access, etc. These periodic rules can help predict the future access behavior of satellite multicast group members and provide a basis for the dynamic adjustment of the key management strategy.
[0092] Based on the results of temporal convolution processing, a time series prediction model is constructed. The model can adopt recurrent neural network structures such as long short-term memory network (LSTM), gated recurrent unit (GRU), or a hybrid architecture combining convolutional neural network (CNN) and recurrent neural network to adapt to the time series characteristics and complex non-linear relationships of satellite communication data. The model is trained using historical data to optimize its parameters so that it can accurately predict the access patterns of satellite multicast members.
[0093] The trained time series prediction model predicts the access status of satellite multicast members in multiple future time slices, generating time series prediction results. The prediction results include information such as the access probability and access duration of multicast members in each time slice, providing data support for the subsequent generation of the member connection probability matrix.
[0094] S23: Calculate the attention weights for the spatial feature tensor and the time series prediction results to generate the satellite node importance weight distribution, where the satellite node importance weight distribution is a probability value matrix reflecting the connection stability of satellite multicast members.
[0095] Specifically, take the spatial feature tensor and the time series prediction results as inputs and apply the attention mechanism to calculate the attention weights. The attention mechanism determines the weights for different satellite nodes and features by learning the correlation and importance among the input features. Specifically, by calculating the similarity or correlation between the query vector, key vector, and value vector, the attention of each node and feature in the current context is determined.
[0096] Based on the calculation results of the attention mechanism, obtain the original weight values for each satellite node and feature. Then, normalize these weight values to meet the requirements of probability distribution, that is, the weight values are between 0 and 1, and the sum of all weight values is 1. The normalization method can use the softmax function or other appropriate normalization techniques to ensure the rationality and effectiveness of the weight distribution.
[0097] Based on the normalized attention weights, construct the satellite node importance weight distribution. This distribution is represented in the form of a probability value matrix, where the rows of the matrix correspond to different satellite nodes, and the columns correspond to different time slices or other feature dimensions. The value of each element represents the connection stability probability of the corresponding satellite node at a specific time or feature, reflecting the importance and reliability of the satellite node in multicast communication.
[0098] Analyze the importance weight distribution of the generated satellite nodes, and identify the key satellite nodes with high connection stability and great impact on multicast communication. These key nodes will be given more attention and resource allocation in the subsequent generation of the key tree structure and the formulation of the key management strategy to ensure the security and stability of multicast communication.
[0099] S24: Based on the node importance weight distribution, calculate and generate the initial member connection probability matrix for multiple future time slices through matrix multiplication.
[0100] Specifically, based on the satellite node importance weight distribution, perform matrix multiplication calculation with the time series prediction results. Through matrix multiplication operation, combine the importance weights of satellite nodes with the predicted access patterns, comprehensively consider the spatial and temporal characteristics of satellite nodes, and generate the initial member connection probability matrix for multiple future time slices.
[0101] The rows of the initial member connection probability matrix represent different multicast members (satellite nodes and user terminals), and the columns represent future time slices. Each element value in the matrix represents the probability that the corresponding multicast member remains connected within a specific time slice, and this probability value is jointly determined by the satellite node importance weight and the time series prediction results, reflecting the comprehensive prediction of the connection status of multicast members.
[0102] S25: Conduct orthogonality verification on the initial member connection probability matrix to generate the corrected member connection probability matrix.
[0103] Specifically, to ensure the rationality and effectiveness of the initial member connection probability matrix, conduct orthogonality verification on it. The orthogonality criterion is determined according to the properties of the probability matrix and the actual requirements of multicast communication. For example, it is required that the row vectors or column vectors of the matrix satisfy certain orthogonality conditions to avoid excessive correlation or conflict in the probability distributions between different multicast members or time slices.
[0104] Verify the initial member connection probability matrix according to the set orthogonality criterion. If the matrix does not meet the orthogonality requirements, the matrix needs to be adjusted and corrected. The adjustment method can adopt an orthogonalization algorithm, such as the Gram - Schmidt orthogonalization method, to orthogonalize the row vectors or column vectors of the matrix to make it meet the orthogonality conditions.
[0105] The initial member connection probability matrix after orthogonality verification and adjustment is the corrected member connection probability matrix. On the basis of maintaining the rationality of the probability distribution, this matrix further optimizes the representation of the multicast member connection probability, making it more in line with the actual operation of the satellite communication system and the requirements of the key management strategy.
[0106] The corrected member connection probability matrix will serve as an important basis for the subsequent dynamic generation of the multicast key tree structure, guiding the construction and update of the key tree. At the same time, the generation process and results of the matrix will also be fed back to the training and optimization of the spatiotemporal graph convolutional network, providing data support for the continuous improvement of the network model, forming a closed-loop optimization system, and continuously improving the dynamic optimization capability of satellite communication encryption strategies.
[0107] In an optional embodiment, S3 includes the following steps:
[0108] S31: Perform threshold screening on the member connection probability matrix to generate a stable member candidate set; wherein the threshold screening is to retain satellite nodes whose connection probability is greater than a preset threshold.
[0109] Specifically, a preset threshold of the connection probability is set according to the actual operation requirements and security policies of the satellite communication system. The determination of the threshold comprehensively considers factors such as the stability requirements of multicast communication, the frequency limit of key updates, and the allocation of system resources. For example, in a scenario with high requirements for communication stability, a higher threshold can be set to ensure that only satellite nodes with a higher connection probability can enter the stable member candidate set.
[0110] Each element in the member connection probability matrix is compared one by one, and satellite nodes with connection probability greater than the preset threshold are screened out to form a stable member candidate set. During the screening process, efficient array operations and conditional judgment algorithms are used to ensure the speed and accuracy of the screening operation. At the same time, the identification, location and other related attributes of the screened satellite nodes are recorded for subsequent geographic location clustering operations.
[0111] S32: geographically clustering the multicast members according to the stable member candidate set to generate satellite member clusters, wherein the geographically clustering is to group satellites in the same orbital plane into the same cluster.
[0112] Specifically, different orbital planes are determined according to the orbital design and deployment plan of the satellite constellation. Each orbital plane corresponds to specific orbital parameters, such as orbital altitude, orbital inclination, right ascension of ascending node, etc. Satellites in the same orbital plane have similar orbital characteristics, which facilitates unified management and scheduling.
[0113] The satellite nodes in the stable member candidate set are classified and clustered according to the orbital plane to which they belong. By comparing the orbital parameters and location information of the satellite nodes, the satellites in the same orbital plane are classified into the same cluster to generate multiple satellite member clusters. In the clustering process, data clustering algorithms such as K-means and DBSCAN are used, combined with the geographical location characteristics of the satellites, to ensure the accuracy and rationality of the clustering results.
[0114] S33: Dynamically select the key tree infrastructure based on the number of members in the satellite member cluster to generate a binary tree or B+ tree structure. Here, dynamic selection means enabling the B+ tree structure when the number of members exceeds a preset quantity.
[0115] Specifically, count the number of members in each satellite member cluster and compare it with a preset quantity threshold. The preset quantity threshold is determined based on the performance characteristics of the key tree structure and system resource limitations, aiming to balance the complexity of the key tree and management efficiency. For example, when the number of members is small, the binary tree structure may be more concise and efficient; while when the number of members is large, the B+ tree structure can provide better scalability and query performance.
[0116] Based on the result of the comparison of the number of members, dynamically select the key tree infrastructure. When the number of members does not exceed the preset quantity, generate a binary tree structure; when the number of members exceeds the preset quantity, enable the B+ tree structure. During the process of generating the tree structure, initialize the nodes, branches, and related parameters of the tree to prepare for subsequent key distribution and management operations.
[0117] S34: Perform multi-objective optimization on the depth, update path length, and storage overhead of the satellite member cluster to generate a Pareto-optimal key tree structure as the multicast key tree structure.
[0118] Specifically, clarify multiple objectives for optimizing the key tree structure, including minimizing the depth of the key tree, minimizing the update path length, and minimizing the storage overhead. There are often trade-off relationships among these objectives. For example, reducing the depth of the key tree may increase the storage overhead. Therefore, a multi-objective optimization method is needed to make a comprehensive trade-off and find the balance point among the objectives.
[0119] Adopt multi-objective optimization algorithms such as genetic algorithms and particle swarm optimization algorithms to search for and optimize the key tree structure of the satellite member cluster. During the optimization process, using Pareto optimality as the criterion, screen out a group of candidate key tree structure solutions that perform well in each optimization objective. By comparing and evaluating the performance indicators of these candidate solutions, finally determine the Pareto-optimal solution as the multicast key tree structure.
[0120] Verify the generated Pareto-optimal key tree structure to ensure that it meets the security and efficiency requirements of the satellite communication system. The verification content includes aspects such as the correctness of key updates, the stability of the key tree, and the reasonableness of resource consumption. The verified Pareto-optimal key tree structure will be directly applied to the satellite communication encryption strategy to guide key distribution, update, and management operations, improving the overall performance and reliability of the system.
[0121] In an alternative embodiment, S4 includes the following steps:
[0122] S41: Generate local group keys and a global group key based on the multicast key tree structure, where the global group key is used to encrypt the local group keys.
[0123] Specifically, deeply analyze the hierarchical relationship of the multicast key tree structure, the paths from the root node to the leaf nodes, and the key dependencies of each node. The root node, as the holder of the global group key, is responsible for generating and managing the global group key; the intermediate nodes and leaf nodes generate corresponding local group keys and member keys according to the tree structure.
[0124] Generate the global group key at the root node based on a secure random number generation algorithm. The length and encryption strength of the global group key are determined according to the current security requirements and the results of quantum attack threat assessment to ensure its ability to effectively resist potential attack threats. The global group key is used to encrypt the local group keys to ensure the security of the local group keys during transmission and storage.
[0125] At the intermediate nodes of the multicast key tree, generate local group keys according to the satellite member clusters and subtree structures to which they belong. The generation of local group keys takes into account factors such as the number of members within the subtree, communication patterns, and security requirements, and uses symmetric encryption algorithms or asymmetric encryption algorithms to generate keys with appropriate key lengths and lifecycles. The local group keys are used to encrypt multicast data to ensure that members within the same local group can correctly decrypt and receive the data.
[0126] S42: Analyze the key request frequency data of the multicast key tree structure using an LSTM network to generate a quantum attack threat level as the result of quantum attack threat assessment, where the quantum attack threat level is a risk level divided according to the sudden increase multiple of the request frequency of the key request frequency data.
[0127] Specifically, construct a neural network structure including an input layer, an LSTM layer, and an output layer. The input layer receives the key request frequency data of the multicast key tree structure, and after data preprocessing and feature extraction, it is input into the LSTM layer. The LSTM layer can effectively process time series data and capture the time dependence and change trends in the key request frequency data. The output layer generates the quantum attack threat level according to the output of the LSTM layer.
[0128] Collect historical key request frequency data and corresponding quantum attack event labels as the training dataset. Perform preprocessing operations such as cleaning and normalization on the dataset, and then divide it into a training set and a test set. Use the training set to train the LSTM network, adjust the network parameters through an optimization algorithm (such as the Adam optimization algorithm), and minimize the error between the prediction result and the true label. During the training process, monitor the performance metrics of the model (such as accuracy, recall rate, F1 value, etc.) to ensure that the model has good generalization ability and prediction performance.
[0129] According to the multiple of sudden increase in the request frequency of the key request frequency data, formulate the classification criteria for the quantum attack threat level. For example, the multiple of sudden increase in the request frequency is divided into three levels: low risk (1-2 times), medium risk (2-5 times), and high risk (more than 5 times). When the multiple of sudden increase in the request frequency predicted by the LSTM network falls into different intervals, different quantum attack threat levels are generated correspondingly, providing a decision-making basis for subsequent quantum-resistant dynamic key distribution.
[0130] S43: When the quantum attack threat level exceeds the preset level threshold, switch the global group key encapsulation algorithm of the multicast key tree structure to the FrodoKEM-1344 algorithm.
[0131] Specifically, continuously monitor the quantum attack threat level generated by the LSTM network to obtain the current threat status in real time. Through the set threshold judgment mechanism, when the quantum attack threat level exceeds the preset level threshold, trigger the switching operation of the global group key encapsulation algorithm.
[0132] When the switching condition is met, switch the global group key encapsulation algorithm of the multicast key tree structure from the currently used algorithm to the FrodoKEM-1344 algorithm. As a post-quantum cryptography algorithm, the FrodoKEM-1344 algorithm has the characteristic of resisting quantum computing attacks and can provide higher security in the quantum computing environment. During the switching process, ensure a smooth transition between the old and new algorithms to avoid interruption or impact on the existing multicast communication and key management system.
[0133] S44: Based on the member connection probability matrix, generate and pre-distribute the local group key ciphertext for the next time slice at the satellite edge node, where the pre-distribution is to transmit the encrypted local group key to the satellite edge node before the key takes effect.
[0134] Specifically, based on the member connection probability matrix, predict the connection status and key requirements of the satellite edge nodes in the next time slice. According to the prediction results, formulate the pre-distribution strategy for the local group key ciphertext, and determine the range of satellite edge nodes that need to be pre-distributed, the pre-distribution time window, and the format and encryption method of the ciphertext, etc.
[0135] At the satellite edge node, generate the local group key ciphertext for the next time slice according to the pre-distribution strategy. During the generation process, use the current encryption algorithm (such as symmetric encryption algorithm or asymmetric encryption algorithm) to encrypt the local group key to ensure the security of the ciphertext during transmission. Then, transmit the encrypted local group key ciphertext to the target satellite edge node through the satellite communication link to achieve the pre-distribution of the key. The pre-distribution operation is completed before the key takes effect, so that the satellite edge node can obtain and decrypt it in time when the key is needed.
[0136] S45: Through the satellite-ground cooperation mechanism, the terminal obtains the pre-distributed local group key ciphertext based on the key distribution path of the multicast key tree structure during satellite handover.
[0137] Specifically, according to the key distribution path of the multicast key tree structure, a reasonable key acquisition path is planned for the terminal during satellite handover. The path planning takes into account factors such as the handover delay between satellites, the communication link quality, and the mobility of the terminal to ensure that the terminal can quickly and reliably obtain the pre-distributed local group key ciphertext.
[0138] During the satellite handover process, the terminal sends a key acquisition request to the satellite node where it is currently located according to the planned key distribution path. After receiving the request, the satellite node transmits the corresponding local group key ciphertext to the terminal based on the multicast key tree structure and the pre-distributed key information. After receiving the ciphertext, the terminal decrypts the ciphertext using the decryption key stored locally (such as the global group key or member key) to obtain the available local group key, thereby realizing the continuous acquisition of keys and the seamless handover of multicast communication. The entire process ensures that the terminal can obtain the required keys in a timely and accurate manner during satellite handover through the satellite-ground cooperation mechanism, maintaining the security and stability of multicast communication.
[0139] The above-mentioned dynamic optimization method for satellite communication encryption strategy based on AI constructs a spatio-temporal network model by collecting the dynamic topology and security threat data of satellite multicast members in real time, uses the spatio-temporal graph convolutional network to accurately predict the member connection behavior and generate a probability matrix, dynamically optimizes the key tree depth and update path based on the prediction results to minimize the reconstruction cost, combines the quantum attack threat assessment model to adaptively switch to the quantum encryption algorithm after handover, and continuously optimizes the model parameters through the closed-loop verification mechanism. Finally, it realizes the dynamic balance of the key management efficiency and security protection ability in the satellite communication environment, significantly improves the adaptability of the encryption strategy to high-dynamic topologies and new attacks, effectively solves the technical bottlenecks of traditional solutions in key update delay, quantum attack defense, and cross-layer collaborative encryption, and provides an efficient and reliable security guarantee for large-scale satellite multicast communication.
[0140] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of the steps or stages in other steps or other steps.
[0141] Based on the same inventive concept, an embodiment of the present application further provides a system for implementing the above-mentioned AI-based satellite communication encryption policy dynamic optimization method. The implementation solution provided by this system to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the AI-based satellite communication encryption policy dynamic optimization system provided below can refer to the limitations on an AI-based satellite communication encryption policy dynamic optimization method in the above text, and will not be repeated here.
[0142] In an exemplary embodiment, as Figure 2 shown, an AI-based satellite communication encryption policy dynamic optimization system 20 is provided, including:
[0143] A data acquisition and modeling module 21, configured to acquire the status data of satellite multicast members and generate a spatio-temporal topology graph based on the status data; wherein, the spatio-temporal topology graph is a graph structure model including satellite node positions, communication links, and time slices.
[0144] A behavior prediction module 22, configured to perform multicast member behavior prediction through a spatio-temporal graph convolutional network based on the spatio-temporal topology graph and generate a member connection probability matrix; wherein, the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution.
[0145] A key tree optimization module 23, configured to dynamically generate a multicast key tree structure with the minimum reconstruction cost according to the member connection probability matrix, wherein the minimum reconstruction cost is a weighted optimization index that comprehensively considers the key tree depth, update path length, and storage overhead.
[0146] A key distribution module 24, configured to perform quantum-resistant dynamic key distribution on the multicast key tree structure based on the quantum attack threat assessment result; wherein, the quantum-resistant dynamic key distribution is a process of switching to a quantum cryptography algorithm according to the quantum attack threat assessment result.
[0147] A performance evaluation and tuning module 25, which is used to evaluate the key update performance through multi-metric closed-loop verification to obtain a performance evaluation result; and generate a model tuning instruction based on the performance evaluation result to update the spatio-temporal graph convolutional network.
[0148] Optionally, the data acquisition and modeling module 21 includes:
[0149] A motion vector calculation unit 211, which is used to obtain the orbital parameters and real-time position coordinates of multicast members through an inter-satellite link, perform motion vector calculation on the orbital parameters and real-time position coordinates, and generate a satellite node motion vector, where the motion vector is a vector containing radial velocity and angular velocity.
[0150] An access state feature extraction unit 212, which is used to receive the access state data of user terminals reported by a ground gateway, extract features from the access state data, and generate a signal strength feature and an access time window feature, where the access time window feature is a prediction result of the time interval during which a user terminal can communicate.
[0151] A spatio-temporal topology construction unit 213, which is used to perform fusion processing on the satellite node motion vector, signal strength feature, access time window feature, and channel error rate data to construct a spatio-temporal topology graph G=(v, E, T); where the node v i ∈V represents the i-th multicast member, and the edge e ij ∈E represents the communication link between the node v i and the node v j , and the time slice T is divided according to the satellite ephemeris.
[0152] Optionally, the behavior prediction module 22 includes:
[0153] A spatial feature extraction unit 221, which is used to perform spatial convolution processing on the spatio-temporal topology graph to extract the relative motion features between satellite nodes; generate a spatial feature tensor based on the relative motion features; where the relative motion features include the elevation rate of change and the distance rate of change between satellite nodes.
[0154] A time feature analysis unit 222, which is used to perform time convolution processing on the spatio-temporal topology graph to analyze the periodicity of the access patterns of satellite multicast members and generate a time series prediction result; where the periodicity is the time interval rule for the recurrence of the satellite coverage area.
[0155] A node weight calculation unit 223, which is used to calculate the attention weights for the spatial feature tensor and the time series prediction result to generate the importance weight distribution of satellite nodes, where the importance weight distribution of satellite nodes is a probability value matrix reflecting the connection stability of satellite multicast members.
[0156] A probability matrix generation unit 224, configured to calculate and generate an initial member connection probability matrix for multiple future time slices through matrix multiplication based on the node importance weight distribution.
[0157] A probability matrix correction unit 225, configured to perform orthogonality verification on the initial member connection probability matrix to generate a corrected member connection probability matrix.
[0158] Optionally, the key tree optimization module 23 includes:
[0159] A stable member screening unit 231, configured to perform threshold screening on the member connection probability matrix to generate a stable member candidate set; wherein, the threshold screening is to retain satellite nodes with connection probabilities greater than a preset threshold.
[0160] A member clustering unit 232, configured to perform geographical location clustering on multicast members according to the stable member candidate set to generate satellite member clusters, wherein the geographical location clustering is to group satellites on the same orbital plane into the same cluster.
[0161] A tree structure selection unit 233, configured to dynamically select a key tree infrastructure based on the number of members in the satellite member cluster to generate a binary tree or B+ tree structure, wherein the dynamic selection is to enable the B+ tree structure when the number of members exceeds a preset number.
[0162] A multi-objective optimization unit 234, configured to perform multi-objective optimization on the depth, update path length, and storage overhead of the satellite member cluster to generate a Pareto optimal key tree structure as the multicast key tree structure.
[0163] Optionally, the key distribution module 24 includes:
[0164] A key generation unit 241, configured to generate a local group key and a global group key based on the multicast key tree structure; wherein, the global group key is used to encrypt the local group key.
[0165] A threat assessment unit 242, configured to perform LSTM network analysis on the key request frequency data of the multicast key tree structure to generate a quantum attack threat level as the quantum attack threat assessment result; wherein, the quantum attack threat level is a risk level divided according to the multiple of the sudden increase in the request frequency of the key request frequency data.
[0166] An algorithm switching unit 243, configured to switch the global group key encapsulation algorithm of the multicast key tree structure to the FrodoKEM-1344 algorithm when the quantum attack threat level exceeds a preset level threshold.
[0167] A key pre-distribution unit 244 is configured to generate and pre-distribute the ciphertext of the local group key for the next time slice at the satellite edge node based on the member connection probability matrix, where the pre-distribution is to transmit the encrypted local group key to the satellite edge node before the key becomes effective.
[0168] A key acquisition cooperation unit 245 is configured to enable the terminal to obtain the pre-distributed ciphertext of the local group key during satellite handover through a satellite-ground cooperation mechanism based on the key distribution path of the multicast key tree structure.
[0169] Embodiments of the present application also provide a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the steps in the foregoing method embodiments are implemented.
[0170] Embodiments of the present application also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the foregoing method embodiments are implemented.
[0171] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can refer to the partial descriptions of the method embodiments. The device embodiments described above are only illustrative. The components described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present disclosure solution. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0172] The above embodiments only represent several implementation manners of the embodiments of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the application embodiments. It should be noted that for those of ordinary skill in the art, without departing from the concept of the embodiments of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the embodiments of the present application.
Claims
1. A method for dynamically optimizing an AI-based satellite communication encryption strategy, characterized in that The method includes: S1: Collect the status data of satellite multicast members, and generate a spatio-temporal topology graph based on the status data; wherein, the spatio-temporal topology graph is a graph structure model including satellite node positions, communication links, and time slices; S2: Based on the spatio-temporal topology graph, perform multicast member behavior prediction through a spatio-temporal graph convolutional network to generate a member connection probability matrix; wherein, the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution; S3: Dynamically generate a multicast key tree structure with the minimum reconstruction cost according to the member connection probability matrix, wherein the minimum reconstruction cost is a weighted optimization metric that comprehensively considers the key tree depth, update path length, and storage overhead; S4: Based on the quantum attack threat assessment result, perform quantum-resistant dynamic key distribution on the multicast key tree structure; wherein, the quantum-resistant dynamic key distribution is a process of switching to a quantum cryptographic algorithm according to the quantum attack threat assessment result; S5: Evaluate the key update performance through multi-index closed-loop verification to obtain a performance evaluation result; generate a model tuning instruction based on the performance evaluation result to update the spatio-temporal graph convolutional network.
2. The method according to claim 1, characterized in that, The S1 includes: S11: Obtain the orbital parameters and real-time position coordinates of the multicast members through inter-satellite links, calculate the motion vectors of the orbital parameters and real-time position coordinates to generate satellite node motion vectors, wherein the motion vectors are vectors including radial velocity and angular velocity; S12: Receive the access status data of user terminals reported by the ground gateway, extract features from the access status data to generate signal strength features and access time window features, wherein the access time window feature is the prediction result of the time interval during which the user terminal can communicate; S13: Fuse the satellite node motion vectors, signal strength features, access time window features, and channel bit error rate data to construct a spatio-temporal topology graph G=(V, E, T); where the node v i ∈V represents the i-th multicast member, and the edge e ij ∈E represents the communication link between the node v i and the node v j . The time slice T is divided according to the satellite ephemeris.
3. The method according to claim 1, wherein The S2 includes: S21: Perform spatial convolution processing on the spatio-temporal topology graph to extract the relative motion features between satellite nodes; generate a spatial feature tensor based on the relative motion features; wherein, the relative motion features include the elevation change rate and distance change rate between satellite nodes; S22: Perform temporal convolution processing on the spatio-temporal topology graph to analyze the periodicity of the access patterns of the satellite multicast members and generate a time series prediction result; wherein, the periodicity is the time interval rule of satellite coverage area recurrence; S23: Calculate the attention weight of the spatial feature tensor and the time series prediction result to generate the importance weight distribution of satellite nodes, wherein the importance weight distribution of satellite nodes is a probability value matrix reflecting the connection stability of the satellite multicast members; S24: Based on the importance weight distribution of the nodes, calculate and generate an initial member connection probability matrix for multiple future time slices through matrix multiplication; S25: Perform orthogonality verification on the initial member connection probability matrix to generate the corrected member connection probability matrix.
4. The method according to claim 1, characterized in that, The S3 includes: S31: Perform threshold screening on the member connection probability matrix to generate a stable member candidate set; wherein, the threshold screening is to retain satellite nodes with a connection probability greater than a preset threshold; S32: Cluster the multicast members based on the stable member candidate set to generate satellite member clusters, where the geographical location clustering is to group satellites in the same orbital plane into the same cluster; S33: Dynamically select a key tree infrastructure based on the number of members in the satellite member cluster to generate a binary tree or B+ tree structure, where the dynamic selection is to enable the B+ tree structure when the number of members exceeds a preset number; S34: Perform multi-objective optimization on the depth, update path length, and storage overhead of the satellite member cluster to generate a Pareto optimal key tree structure as the multicast key tree structure.
5. The method according to any one of claims 1 to 4, characterized in that, The S4 includes: S41: Generate local group keys and global group keys based on the multicast key tree structure; where the global group key is used to encrypt the local group key; S42: Analyze the key request frequency data of the multicast key tree structure through an LSTM network to generate a quantum attack threat level as the quantum attack threat assessment result; where the quantum attack threat level is a risk level divided according to the sudden increase multiple of the request frequency of the key request frequency data; S43: When the quantum attack threat level exceeds a preset level threshold, switch the global group key encapsulation algorithm of the multicast key tree structure to the FrodoKEM-1344 algorithm; S44: Based on the member connection probability matrix, generate and pre-distribute the ciphertext of the local group key for the next time slice at the satellite edge node, where the pre-distribution is to transmit the encrypted local group key to the satellite edge node before the key becomes effective; S45: Through the satellite-ground cooperation mechanism, enable the terminal to obtain the pre-distributed local group key ciphertext when the satellite switches based on the key distribution path of the multicast key tree structure.
6. An AI-based dynamic optimization system for satellite communication encryption strategy, characterized in that, The system includes: A data collection and modeling module for collecting the status data of satellite multicast members and generating a spatio-temporal topology map based on the status data; where the spatio-temporal topology map is a graph structure model including satellite node positions, communication links, and time slices; A behavior prediction module for predicting the behavior of multicast members through a spatio-temporal graph convolutional network based on the spatio-temporal topology map to generate a member connection probability matrix; where the spatio-temporal graph convolutional network is a deep learning model that fuses spatial convolution and temporal convolution; A key tree optimization module for dynamically generating a multicast key tree structure with the minimum reconstruction cost according to the member connection probability matrix, where the minimum reconstruction cost is a weighted optimization metric that comprehensively considers the key tree depth, update path length, and storage overhead; A key distribution module for performing quantum-resistant dynamic key distribution on the multicast key tree structure based on the quantum attack threat assessment result; where the quantum-resistant dynamic key distribution is a process of switching to a post-quantum cryptography algorithm according to the quantum attack threat assessment result; A performance evaluation and tuning module for evaluating the key update performance through multi-metric closed-loop verification to obtain a performance evaluation result; generating a model tuning instruction based on the performance evaluation result to update the spatio-temporal graph convolutional network.
7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 5 is implemented.
Citation Information
Cited By
Communication protocol security verification method based on quantum key distribution
CN120498689A
Key dynamic activity maintaining method and device for complex power network topology
CN121125172A
Post-quantum cryptography security networking and data protection device for space-based orbit data center
CN122001581A