Satellite secure communication method and system

By using elliptic curve algorithms to generate dynamic parameters in satellite communication systems, combined with multi-layer hashing, DNA sequence encoding, and chaos theory, dynamic key updates and covert transmission are achieved, solving the security and covertness issues of satellite communication systems and improving the system's protection capabilities.

CN121037106BActive Publication Date: 2026-03-20WEBRAY TECH BEIJING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

Existing satellite communication systems are inadequate in terms of key management, algorithm strength, and resistance to quantum computing attacks. They cannot adapt to dynamic changes in satellite orbits and lack effective covert transmission mechanisms, making them vulnerable to eavesdropping and interference.

Method used

The algorithm uses elliptic curves to generate dynamic parameters, and combines multi-layer hashing, DNA sequence encoding, biocryptography, chaos theory and neural networks to achieve dynamic key updates and covert transmission. It also constructs a multi-layer protection system through frequency domain spread spectrum steganography and neural network decoding verification.

Benefits of technology

It significantly increases the difficulty of cracking, ensures the timeliness and uniqueness of the key, and enables the biometric camouflage and covert transmission of encrypted data, effectively avoiding electronic reconnaissance and interference.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121037106B_ABST
    Figure CN121037106B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose a satellite secure communication method and system. The satellite secure communication method comprises: generating dynamic parameters of an elliptic curve equation according to satellite communication information, obtaining an initial shared key pair based on an elliptic curve algorithm, dynamic parameters and a key exchange protocol; obtaining a session-level encryption key through a multi-layer hash operation and a timestamp synchronization mechanism based on the initial shared key pair; obtaining biological feature encryption data through DNA sequence encoding and biological cryptography conversion algorithm based on the session-level encryption key; obtaining a high-dimensional chaotic encryption package through chaotic mapping disturbance and fractal geometry transformation processing based on the biological feature encryption data; obtaining a covert transmission data stream through frequency domain spread spectrum steganography and neural network decoding verification based on the high-dimensional chaotic encryption package; and dynamically updating the initial shared key pair through a key rotation strategy based on communication cycle monitoring. The method can realize high security, strong concealment and reliable protection capability of satellite communication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of satellite communication security, in particular to a satellite secure communication method and system. BACKGROUND

[0002] With the rapid development of aerospace technology, satellite communication plays an increasingly important role in national security, disaster monitoring, resource exploration and other fields. However, due to the open and broadcast nature of satellite communication, it is vulnerable to eavesdropping, interference and tampering.

[0003] Traditional satellite communication security technology mainly relies on static keys and single encryption algorithms such as AES, RSA, etc. These methods have obvious shortcomings in key management, algorithm strength and resistance to quantum computing attacks. In particular, the static key mechanism cannot adapt to the dynamic changes of satellite orbits, and once the key is leaked, the security of the entire communication system will collapse.

[0004] In the prior art, satellite communication encryption usually uses pre-shared key method, which requires satellites and ground stations to pre-store a large amount of key materials, not only increasing the management complexity, but also unable to realize real-time key update. At the same time, the traditional encryption method lacks effective covert transmission mechanism, even if the data is encrypted, the communication behavior itself is easy to be detected and located.

[0005] The most relevant prior art is the satellite communication encryption system based on elliptic curve, but this kind of system usually uses fixed curve parameters and single level encryption mechanism, which is difficult to cope with advanced persistent threats. The technical solution of combining elliptic curve algorithm with multiple encryption, biometric cryptography and chaos theory to build a multi-level protection system has not been reported.

[0006] Therefore, there is an urgent need for a satellite secure communication method and system that can dynamically adjust encryption parameters according to satellite orbit, integrate multiple encryption technologies, realize covert transmission, and have self-adaptive protection capability. SUMMARY

[0007] Therefore, the purpose of the present application is to provide a satellite secure communication method and system, which realizes high security, strong concealment and reliable protection capability of satellite communication.

[0008] In the first aspect, the present application provides a satellite secure communication method, which adopts the following technical solution:

[0009] The satellite secure communication method comprises the following steps:

[0010] According to the satellite communication related information, the dynamic parameters of the elliptic curve equation are generated, and based on the elliptic curve algorithm, the dynamic parameters and the key exchange protocol, the initial shared key pair is obtained;

[0011] obtaining a session-level encryption key through multi-layer hash operation and timestamp synchronization mechanism based on the initial shared key pair;

[0012] obtaining biometric encryption data through DNA sequence encoding and bio-cryptography conversion algorithm based on the session-level encryption key;

[0013] obtaining high-dimensional chaotic encryption package through chaotic mapping disturbance and fractal geometry transformation processing based on the biometric encryption data;

[0014] obtaining covert transmission data stream through frequency domain spread spectrum steganography and neural network decoding verification based on the high-dimensional chaotic encryption package;

[0015] updating the initial shared key pair dynamically through key rotation strategy based on communication cycle monitoring.

[0016] Optionally, according to satellite communication related information, dynamic parameters of an elliptic curve equation are generated, and an initial shared key pair is obtained based on an elliptic curve algorithm, dynamic parameters and a key exchange protocol, including:

[0017] Based on the current orbital position coordinates of the satellite and the GPS timestamp of the ground station, a set of dynamic parameters of the elliptic curve equation are calculated, including the a and b coefficients of the curve and the modulus p of the finite field;

[0018] Based on the dynamic parameters, an elliptic curve Diffie-Hellman key exchange protocol is executed, and the satellite and the ground station each generate a private key on the dynamic elliptic curve and calculate the corresponding public key;

[0019] The public keys are exchanged through the satellite communication link and combined with the respective private keys to calculate a 256-bit initial shared key K1 and a current orbital period identifier T1.

[0020] Optionally, based on the initial shared key pair, a session-level encryption key is obtained through multi-layer hash operation and timestamp synchronization mechanism, including:

[0021] Based on the initial shared key K1, the orbital period identifier T1 and the GPS timestamp, a time parameter vector is constructed in combination with satellite orbital period information;

[0022] Based on the time parameter vector, a 512-bit session-level encryption key K2 with time effectiveness and the corresponding timestamp hash value are derived through multi-round hash function calculation, each round using a different hash algorithm and adding a satellite orbital lap counter.

[0023] Optionally, based on the initial shared key K1, the orbital period identifier T1 and the GPS timestamp, a time parameter vector is constructed in combination with satellite orbital period information, including:

[0024] The initial shared key K1 is grouped into 4 sub-key vectors of 64 bits;

[0025] The track period identifier T1 is converted into 32-bit binary data, and the period identifier vector of 64 bits is obtained by bit extension or repetition padding;

[0026] The second and millisecond time information of the GPS timestamp is extracted to form a 64-bit timestamp vector;

[0027] The perigee, apogee, orbital inclination and orbital period of the current satellite orbit are obtained and quantized into a 128-bit orbit feature vector;

[0028] The above vectors are linearly combined according to the predefined weight coefficients to construct a 288-bit time parameter vector containing time synchronization information and orbit dynamic characteristics;

[0029] Optionally, based on the session-level encryption key, biological feature encryption data is obtained through DNA sequence encoding and biological cryptography conversion algorithm, including:

[0030] The session-level encryption key is re-encoded according to the genetic code to obtain binary data;

[0031] The binary data is mapped to a sequence combination of four DNA bases, and the insertion positions of the regulatory sequence, intron and exon structure in the sequence combination are determined according to the timestamp hash value;

[0032] The sequence combination is error-corrected through biological redundancy mechanism to obtain a DNA encoding sequence of 2048 base pairs in length and a biological feature check code.

[0033] Optionally, based on the biological feature encryption data, a high-dimensional chaotic encryption package is obtained through chaotic mapping disturbance and fractal geometric transformation processing, including:

[0034] The pseudo-random characteristics of the deterministic chaotic system are used to dynamically rearrange and disturb the DNA encoding sequence on the chaotic orbit;

[0035] The DNA encoding sequence after dynamic rearrangement and disturbance is mapped to a multi-dimensional fractal space, and the DNA encoding sequence is distributed in the macroscopic level, mesoscopic level and microscopic level through the self-similarity and recursive characteristics of fractals;

[0036] The biological feature check code is used as a fractal parameter seed, the space is distributed according to the main fractal mode in the macroscopic level, the substructure is divided according to the local characteristics of the DNA encoding sequence in the mesoscopic level, and the accurate coordinates of each base in the multi-dimensional space are determined in the microscopic level, to obtain a high-dimensional chaotic encryption package containing 4096-dimensional vector data and fractal reconstruction parameters.

[0037] Optionally, based on the high-dimensional chaotic encryption package, a hidden transmission data stream is obtained through frequency domain spread spectrum steganography and neural network decoding verification, including:

[0038] The encrypted data in the chaotic encryption package is embedded into the frequency spectrum of the satellite telemetry carrier signal after frequency domain transformation;

[0039] The spread spectrum technology is used to disperse the energy of the telemetry carrier signal into a wide frequency band range, so that it presents the characteristics of background noise;

[0040] The frequency spectrum of the satellite telemetry carrier signal is subjected to multi-layer feature extraction and pattern recognition through a deep convolutional neural network, so as to obtain a specific data pattern hidden in the frequency spectrum;

[0041] The DNA encoding sequence is recovered by spatial inverse transformation using fractal reconstruction parameters;

[0042] The recovered DNA encoding sequence is subjected to time series decoding and data integrity verification through a recurrent neural network, so as to obtain a hidden transmission data stream and a neural network verification identifier.

[0043] Optionally, based on communication cycle monitoring, the initial shared key pair is dynamically updated through a key rotation strategy, including:

[0044] When the orbit period change, data transmission anomaly or neural network verification identifier verification failure is detected, the initial shared key pair is regenerated.

[0045] Optionally, the satellite secure communication method further includes:

[0046] The security state of the current communication environment is evaluated in real time by monitoring the satellite communication mode, signal characteristics and decoding success rate;

[0047] When an anomaly is detected, a security state report and a next round encryption parameter seed are obtained, and a backup satellite communication channel is started;

[0048] Based on the security state report and the next round encryption parameter seed, the dynamic parameters of the elliptic curve equation are automatically adjusted.

[0049] In a second aspect, the embodiments of the present disclosure further provide a satellite secure communication system, which adopts the following technical scheme:

[0050] The satellite secure communication system includes:

[0051] An elliptic curve key generation module is configured to generate dynamic parameters of an elliptic curve equation according to satellite communication related information, and obtain an initial shared key pair based on an elliptic curve algorithm, the dynamic parameters and a key exchange protocol;

[0052] A session key processing module is configured to obtain a session-level encryption key through multi-layer hash operation and timestamp synchronization mechanism based on the initial shared key pair.

[0053] A biological feature encoding module is configured to obtain biological feature encryption data through DNA sequence encoding and biological cryptography conversion algorithm based on the session-level encryption key.

[0054] A chaotic encryption processing module is configured to obtain a high-dimensional chaotic encryption package through chaotic mapping disturbance and fractal geometry transformation processing based on the biological feature encryption data.

[0055] A covert transmission module is configured to obtain a covert transmission data stream through frequency domain spread spectrum steganography and neural network decoding verification based on the high-dimensional chaotic encryption package.

[0056] A key update module is configured to dynamically update the initial shared key pair through a key rotation strategy based on communication cycle monitoring.

[0057] The satellite secure communication method provided by the present application has the following advantages:

[0058] Through the elliptic curve parameter dynamic change mechanism, different curve parameters are used for each communication, which significantly improves the cracking difficulty; the timestamp synchronization multi-layer encryption system is combined with the satellite orbit period to realize automatic key update, ensuring the timeliness and uniqueness of the key; the DNA sequence encoding is combined with the chaos theory to realize biological camouflage and high non-linear transformation of the encrypted data; through the frequency domain steganography and neural network verification mechanism, the encrypted data is realized to be covertly transmitted and intelligently identified, effectively avoiding electronic reconnaissance and interference.

[0059] The above description is only a summary of the technical solutions of the present application, in order to more clearly understand the technical means of the present application, the content of the specification can be implemented, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following preferred embodiments are described in detail below, and the accompanying drawings are described as follows. BRIEF DESCRIPTION OF DRAWINGS

[0060] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application, and those skilled in the art can obtain other drawings according to these drawings without creating any creative labor.

[0061] Figure 1 The flow chart of the satellite secure communication method provided by the embodiments of the present application;

[0062] Figure 2 The principle block diagram of the satellite secure communication system provided by the embodiments of the present application. DETAILED DESCRIPTION

[0063] The embodiments of the present disclosure will be described in detail below with reference to the drawings.

[0064] It should be apparent that the following describes the embodiments of the present disclosure through specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all. The present disclosure can also be implemented or applied by other different specific embodiments, and various modifications or changes can be made to the details in the specification without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present disclosure.

[0065] As shown in the method for satellite secure communication provided by the present application, the method comprises the following steps: Figure 1

[0066] Step S1: generating dynamic parameters of an elliptic curve equation according to satellite communication related information, obtaining an initial shared key pair based on an elliptic curve algorithm, dynamic parameters and a key exchange protocol;

[0067] The dynamic parameters of the elliptic curve equation are generated according to the satellite communication related information, and the initial shared key pair is obtained, which specifically comprises:

[0068] Step S1.1, based on the current orbit position coordinates of the satellite and the GPS timestamp of the ground station, a set of dynamic parameters of the elliptic curve equation are calculated, the dynamic parameters including the a, b coefficients of the curve and the modulus p of the finite field;

[0069] Exemplarily, when the Beidou navigation satellite passes over the east longitude m and the north latitude n at the first Beijing time, the ground command center and the satellite simultaneously calculate the elliptic curve parameters according to this accurate space-time coordinate. Assuming that the satellite orbit height is h and the orbit inclination is θ at this time, these parameters are input into the predetermined generating function to obtain a and b in the elliptic curve equation y2=x3+ax+b, and the modulus p of the finite field.

[0070] Step S1.2, based on the dynamic parameters, performing an elliptic curve Diffie-Hellman key exchange protocol, the satellite and the ground station each generate a private key on the dynamic elliptic curve and calculate the corresponding public key;

[0071] ​Exemplarily, the two parties perform a key exchange based on a dynamically generated elliptic curve, the ground station generates a private key dA, and the satellite generates a private key dB. The ground station calculates its public key QA = dA·G, where G is a base point on the elliptic curve. The satellite calculates its public key QB = dB·G.

[0072] Step S1.3, exchange the public keys through the satellite communication link and combine the respective private keys to calculate an initial shared key K1 of 256 bits and a current orbit period identifier T1.

[0073] Exemplarily, the ground station sends QA to the satellite through the uplink, and the satellite sends QB to the ground station through the downlink. The ground station calculates the shared key point K = dA·QB = (k x ,k y ), and the satellite calculates the shared key point K = dB·QA, obtaining the same result. The two parties perform a SHA-256 hash operation on the value of k x to obtain an initial shared key K1 of 256 bits, and an orbit period identifier T1 is calculated according to the current orbit period.

[0074] Step 2: based on the initial shared key pair, obtain a session-level encryption key through a multi-layer hash operation and a timestamp synchronization mechanism;

[0075] Based on the initial shared key pair, obtain a session-level encryption key through a multi-layer hash operation and a timestamp synchronization mechanism, including:

[0076] Step S2.1, based on the initial shared key K1, the orbit period identifier T1, and the GPS timestamp, construct a time parameter vector in combination with satellite orbit period information;

[0077] Specifically, the specific steps of constructing the time parameter vector include: grouping the initial shared key K1 into 4 sub-key vectors according to 64 bits; converting the orbit period identifier T1 into 32-bit binary data, and obtaining a 64-bit period identifier vector through bit extension or repeated padding; extracting the second and millisecond time information of the GPS timestamp to form a 64-bit timestamp vector; obtaining the perigee, apogee, orbit inclination, and orbit period of the current satellite orbit and quantizing them into a 128-bit orbit feature vector; linearly combining the above vectors according to predefined weight coefficients to construct a 288-bit time parameter vector containing time synchronization information and orbit dynamic characteristics.

[0078] Step S2.2, based on the time parameter vector, calculate a 512-bit session-level encryption key K2 with time effectiveness and a corresponding timestamp hash value through multiple rounds of hash functions, each round using a different hash algorithm and adding a satellite orbit lap counter.

[0079] After obtaining the initial shared key K1, it is transformed into a session-level encryption key K2 with stronger randomness and time validity through multi-layer hash operations. This process involves three rounds of different hash algorithms, each introducing different time and orbit-related parameters. First, the initial shared key K1 is combined with the current GPS timestamp and orbit period identifier T1 to construct an input vector containing time synchronization information. Then, an intermediate result is generated through the first round of SHA-256 hash calculation. In the second round, the combination of the intermediate result and satellite orbit period information is processed using the SHA-3 algorithm. Finally, in the third round, the BLAKE2 algorithm is applied to process the combination of the previous round result and the satellite orbit lap counter, finally generating a 512-bit session-level encryption key K2 and the corresponding timestamp hash value. This multi-layer hash strategy provides double protection: on the one hand, the use of different hash algorithms in cascade enhances the computational complexity, so that even if an attacker obtains the output of a certain layer, he cannot reverse the initial input; on the other hand, the introduction of time stamp and orbit information makes the key have strict time validity, only valid within a certain time window, greatly reducing the operation time of the attacker. At the same time, this mechanism also ensures that the satellite and ground station can generate the same session key synchronously without additional communication, avoiding possible security vulnerabilities in the key synchronization process.

[0080] For example, assume that a satellite and a ground command center need to establish a secure communication link to transmit high-resolution reconnaissance images. The satellite operates in a sun-synchronous orbit at an altitude of 700 kilometers, with an inclination of 98.2 degrees and an orbit period of 98.8 minutes (5928 seconds). The current satellite is completing the 1267th orbit, and the current UTC time is 2024-03-18 09:15:27.386 (Unix timestamp 1710755727.386).

[0081] (1) Assume that the following initial parameters have been obtained through the elliptic curve key exchange in the previous step:

[0082] The initial shared key K1 is:

[0083] 0xE7D1B3A2F4C8975613D9E0F28B7C6A594D82F1E0C3B7A95D4F6E2C0A1B9D8E7 (256-bit hexadecimal number);

[0084] The track period identifier T1 = 0x172C8 (hexadecimal representation of the current track number 1267); GPS timestamp = 1710755727.386 (Unix timestamp accurate to milliseconds); track period = 5928 (seconds); satellite current orbit parameters: perigee height = 693.5 km, apogee height = 706.8 km, orbit inclination = 98.2 degrees, orbit eccentricity = 0.00095.

[0085] (2) Group the initial shared key K1 by 64 bits to form 4 sub-key vectors:

[0086] K1[0] = 0xE7D1B3A2F4C89756 (the most significant 64 bits)

[0087] K1[1] = 0x13D9E0F28B7C6A59

[0088] K1[2] = 0x4D82F1E0C3B7A95D

[0089] K1[3] = 0x4F6E2C0A1B9D8E7 (the least significant 64 bits)

[0090] (3) Expand the track period identifier T1 (0x172C8) to 64 bits:

[0091] T = 0x000000000000172C8 (extended to 64 bits by filling 0 in the high bits)

[0092] Extract the second and millisecond information from the GPS timestamp to build a 64-bit timestamp vector:

[0093] The second part is 1710755727, converted to binary as 110011111110000011000111011111, and the millisecond part is 386, converted to binary as 110000010. After combination and padding, the hexadecimal representation is 0x65F83C7F182, which is extended to 64 bits to get TS = 0x000000065F83C7F182.

[0094] (4) Quantize the current satellite orbit parameters to build a 128-bit orbit feature vector:

[0095] Perigee height (693.5 km) = 6935 (accurate to 0.1 km, binary 1101100010111); apogee height (706.8 km) = 7068 (accurate to 0.1 km, binary 1101110011100); orbit inclination (98.2 degrees) = 982 (accurate to 0.1 degrees, binary 1111010110); orbit eccentricity (0.00095) = 95 (accurate to 10-5 , binary 1011111); Orbit Period (5928 seconds) = 5928 (binary 1011100101000); add appropriate spacing and pad the combined binary sequence to extend to 128 bits, convert to hexadecimal: O = 0x1B17373C7E4E51728B2C00.

[0096] (5) Linear combination of the above vectors using predefined weight coefficients.

[0097] Assume the following weight coefficients are used: w1=0.3; w2=0.2; w3=0.15; w4=0.1; w5=0.05; w6=0.1; w7=0.1.

[0098] Calculate the time parameter vector TPV by weighted XOR combination:

[0099] TPV = w1·K1[0] ⊕ w2·K1[1]⊕ w3·K1[2] ⊕ w4·K1[3]⊕ w5·T ⊕ w6·TS ⊕ w7·O, where ⊕ denotes bitwise XOR operation.

[0100] After complex bit operations, obtain the 288-bit time parameter vector TPV:

[0101] 0xA7F2D1C4B385926E47D9E1F38B2C6A984D56F1A0C3B2A95E4F7E5C1A6B3D8E7F2C4B6A8D1E3F5

[0102] (6) Multi-round hash calculation

[0103] Using the time parameter vector TPV as input, calculate the session-level encryption key K2 through three rounds of different hash algorithms.

[0104] The first round of hash uses the SHA-256 algorithm, with the input being the time parameter vector TPV, and the output being a 256-bit intermediate result H1: H1=SHA-256(TPV)

[0105] H1=0x8D2E4F3C1A7B6D5E9F0C8A7B6D5E4F3C2D1E0F1E2D3C4B5A6978C9D8E7F6A5B4

[0106] The second round of hash uses the SHA3-256 algorithm, with the input being the combination of H1 and the orbit period (5928 seconds), and the output being a 256-bit intermediate result H2:

[0107] Input = H1 || Orbit Period (binary representation)

[0108] Input is:

[0109] 0x8D2E4F3C1A7B6D5E9F0C8A7B6D5E4F3C2D1E0F1E2D3C4B5A6978C9D8E7F6A5B41011100101000

[0110] H2 = input to SHA3-256

[0111] H2 = 0x2C4B6A8D1E3F5C7B9A2E4D6F8A1C3E5D7F9B1D3E5F7A9C1B3D5F7

[0112] The third round of hashing uses the BLAKE2b algorithm with an input of H2 combined with the satellite orbit number counter (1267) and an output of a 512-bit session-level encryption key K2:

[0113] Input = H2 || Orbit Number (binary representation)

[0114] Input is:

[0115] 0x2C4B6A8D1E3F5C7B9A2E4D6F8A1C3E5D7F9B1D3E5F7A9C1B3D5F7A9C1E3D5F710011110101000

[0116] K2 = BLAKE2b-512-bit input

[0117] K2 = 0xF4E3D2C1B0A9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA987654321

[0118] (7) A timestamp hash value TV corresponding to the session key = SHA-256(Timestamp || K2 first 128 bits)

[0119] TV = 0x7B8A9C6D5E4F3A2B1C8D7E6F5A4B3C2D9E8F7A6B5C4D3E2F1A0B9C8D7E6F5A4.

[0120] Step S3: Obtain biometric encryption data through DNA sequence encoding and bio-cryptography conversion algorithm based on the session-level encryption key;

[0121] Obtain biometric encryption data through DNA sequence encoding and bio-cryptography conversion algorithm based on the session-level encryption key, comprising:

[0122] Step S3.1, re-encode the session-level encryption key according to the rules of genetic code to obtain binary data;

[0123] Step S3.2, map the binary data to a sequence combination of four DNA bases, and determine the insertion positions of the regulatory sequence, intron and exon structure in the sequence combination according to the timestamp hash value;

[0124] Step S3.3, correct errors in the sequence combination through biological redundancy mechanism to obtain a DNA encoding sequence of 2048 base pairs in length and a biometric check code.

[0125] Illustratively, the satellite and the ground command center have obtained a 512-bit session-level encryption key K2 and a timestamp hash value TV through multi-layer hash operation in advance. First, the 512-bit binary string of the session-level encryption key K2 is translated into 256 bases by two bits according to the mapping "00→A, 01→T, 10→G, 11→C", obtaining a naked sequence such as CCTAGCAATGACCTGACTAACGTACGTAGCAA…TAGCAATCGGTACGAT. Then, using the first 32 bits TV1, the middle 32 bits TV2, the last 32 bits TV3, and the remaining 32 bits TV4 as a pseudo-random source, the promoter sequence TATAAA, 5'UTR (16 bases), 75-base exon sequence, 78-base intron sequence (GT…AG), 165-base exon sequence, 73-base intron sequence, terminator sequence AATAAA, and other eukaryotic gene structures are inserted into the sequence, expanding the 256 bases to about 500 bases and presenting a complete transcription unit.

[0126] For further damage resistance, three mechanisms of codon synonymous redundancy, parallel multi-path replication, and CRC check are used: key sites use synonymous codon repetition; data blocks are stored twice at multiple places in the sequence according to TV; and a special mapped check substring is inserted every 200 bases.

[0127] Finally, the overall DNA sequence length is expanded to 2048 base pairs, obtaining a DNA encoding sequence, and appending a 64-base biometric check code obtained from HMAC-SHA256(DNA sequence, TV) at the end.

[0128] Step S4: Based on the biometric encryption data, obtain a high-dimensional chaotic encryption package through chaotic mapping disturbance and fractal geometric transformation processing;

[0129] Based on the biometric encryption data, obtain a high-dimensional chaotic encryption package through chaotic mapping disturbance and fractal geometric transformation processing, comprising:

[0130] Step S4.1, utilize the pseudo-random characteristics of the deterministic chaotic system to dynamically rearrange and disturb the DNA encoding sequence on the chaotic orbit;

[0131] Step S4.2, map the DNA encoding sequence after dynamic rearrangement and disturbance to a multi-dimensional fractal space, and distribute the DNA encoding sequence in macroscopic, mesoscopic and microscopic levels through the self-similarity and recursive characteristics of fractals;

[0132] Step S4.3, utilize the biometric verification code as a fractal parameter seed, distribute in space according to the main fractal pattern at the macroscopic level, divide substructures according to the local characteristics of the DNA encoding sequence at the mesoscopic level, and determine the precise coordinates of each base in the multi-dimensional space at the microscopic level, to obtain a high-dimensional chaotic encryption package containing 4096-dimensional vector data and fractal reconstruction parameters.

[0133] First, select multiple classic chaotic mapping systems such as Logistic mapping, Henon mapping and Lorenz system, take the numerical representation of the DNA sequence as the initial condition, and generate chaotic orbits through thousands of iterations.

[0134] Then, reorder and permute the DNA sequence according to the numerical values on the chaotic orbit, destroying any statistical regularity and correlation in the sequence.

[0135] Then, map the DNA sequence disturbed by chaos to a multi-dimensional fractal space. Fractal geometry is known for its self-similarity and infinite detail characteristics, and these characteristics are used to expand one-dimensional DNA sequence data to high-dimensional space. Specifically, fractal generation algorithms such as Iterated Function System (IFS) or L-system are used to distribute DNA sequences in multi-dimensional space with fractal structure. This mapping is multi-level: at the macro level, the entire data block is distributed in space according to the main fractal pattern (such as Mandelbrot set, Julia set or Koch snowflake); at the mesoscopic level, each part of the data block is divided into substructures according to similar but slightly changed fractal rules; at the microscopic level, a single DNA base determines its precise coordinates in high-dimensional space according to local fractal characteristics.

[0136] Then, the biometric verification code is used as the fractal parameter seed to control the entire fractal transformation process. Different bit segments of the verification code are used to adjust key parameters of the fractal algorithm, such as iteration depth, fractal dimension, scaling factor, etc. This parameterized design ensures that even if the same fractal algorithm is used, different data will produce completely different fractal structures, greatly enhancing the security of the system.

[0137] After these three steps of processing, a high-dimensional chaotic encryption package containing 4096-dimensional vector data and fractal parameters for subsequent reconstruction is finally generated. This complex mathematical transformation makes the encrypted data exhibit extremely high complexity and unpredictability. In theory, without the exact initial parameters and algorithm details, even the most powerful supercomputer cannot reverse the original data within an acceptable time.

[0138] Exemplarily, first, the entire 2048 bp DNA coding sequence is divided into 512 4-bp microblocks, each of which is mapped to a real number between 0-0.4 according to the weights A→0.1, T→0.2, G→0.3, and C→0.4. Then, the first 16 bp of the biometric verification code is used to derive the exact initial values of the Logistic, Henon, and Lorenz chaotic systems: for the Logistic system, r is fixed at 3.99, and x0 is weighted by the first 4 values to be 0.4321; for the Henon system, a and b are maintained at 1.4 and 0.3, and x0 and y0 are calculated from the middle 8 bases to be 0.3142 and 0.2718; for the Lorenz system, σ, ρ, and β are taken as the classic 10, 28, and 8 / 3, and the three-dimensional initial values are derived from the last 8 bases to be 0.5123, 0.2891, and 0.1472. The system then iterates each chaotic orbit for 2048 steps, rearranges the 512 microblocks using the numerical size of the Logistic sequence, and replaces each base with the sum of the Henon and Lorenz outputs according to the 0-3 disturbance level: 0 remains, 1 circularly shifts, 2 shifts every other position, and 3 swaps diagonally. Finally, the new DNA string "CCTAGCAATTATA…" is disturbed into "GCACTGTATCA…"

[0139] Next, the entire string is projected into a high-dimensional IFS fractal space: first, 6 two-dimensional affine transformations are used to generate a Sierpinski base, and then 64 verification code bases are used to map 16 4×4 matrices, which are recursively expanded into 256 256-dimensional transformations, finally forming a super-high fractal framework of 4096 dimensions.

[0140] 2048 bases are positioned according to three-layer rules: 16 main blocks of 128-bp are selected as main branches according to SHA-256 feature values; each main block is further divided into 8 sub-blocks of 16-bp, and sub-structures are selected according to base count modulo 8; and each base is further calculated for (x, y, z, …) coordinates according to its type and index, and is upgraded to 4096 dimensions through Fourier-wavelet-feature polynomial three-layer expansion. All coordinates, branch indexes, transformation selection vectors, and high-dimensional feature vectors are packaged into a 16 MB "high-dimensional chaotic encryption package", and are accompanied by 2 KB fractal reconstruction parameters (IFS matrix, seed, mapping rule, projection matrix, and anti-chaos parameters).

[0141] Step 5: Based on the high-dimensional chaotic encryption package, a hidden transmission data stream is obtained through frequency domain spread spectrum steganography and neural network decoding verification.

[0142] Based on the high-dimensional chaotic encryption package, a hidden transmission data stream is obtained through frequency domain spread spectrum steganography and neural network decoding verification, including:

[0143] Step S5.1, after the encrypted data in the chaotic encryption package is transformed through the frequency domain, it is embedded into the frequency spectrum of the satellite telemetry carrier signal.

[0144] Step S5.2, the energy of the telemetry carrier signal is dispersed into a wide frequency band range using spread spectrum technology, so that it presents the characteristics of background noise.

[0145] Step S5.3, through a deep convolutional neural network, multi-layer feature extraction and pattern recognition are performed on the frequency spectrum of the satellite telemetry carrier signal to obtain a specific data pattern hidden in the frequency spectrum.

[0146] Step S5.4, spatial inverse transformation is performed using fractal reconstruction parameters to restore the DNA encoding sequence.

[0147] Step S5.5, the restored DNA encoding sequence is decoded in time sequence through a recurrent neural network and the data integrity is verified to obtain a hidden transmission data stream and a neural network verification identifier.

[0148] After high-dimensional chaotic encryption is completed, the encrypted data is hidden in normal satellite communication through a series of signal processing techniques to realize hidden transmission at the physical layer.

[0149] First, the data in the high-dimensional chaotic encryption package is converted from the time domain to the frequency domain through frequency domain transformation methods such as fast Fourier transform (FFT) or wavelet transform.

[0150] Then, a part of the spectrum of the satellite's normal telemetry carrier signal with relatively flat energy distribution is selected, and the converted encrypted data is embedded in it at a very low energy level. This frequency domain embedding is highly subtle, with the amplitude of the encrypted data controlled to be below 1 / 100 of the normal signal amplitude, making it difficult to be discovered in spectral analysis.

[0151] Secondly, the Direct Sequence Spread Spectrum (DSSS) or Frequency Hopping Spread Spectrum (FHSS) technology is used to disperse the energy of the carrier signal embedded with encrypted data into a wider frequency band range. For example, a 10 MHz bandwidth signal originally concentrated around 2.4 GHz can be expanded to a 100 MHz bandwidth range through spread spectrum. This spread spectrum processing reduces the power spectral density of the signal to below the background noise level (usually below -140 dBm / Hz), making it indistinguishable from natural background noise in spectral analysis.

[0152] Then, at the receiving end, a deep convolutional neural network (CNN) is deployed to process the received signal to identify specific data patterns from seemingly random noise. Specifically, a deep CNN architecture similar to ResNet or DenseNet is used, combined with an attention mechanism, to perform multi-layer feature extraction and pattern recognition on the spectrum of the received signal, to accurately detect and extract encrypted data hidden in the spectrum.

[0153] Then, using the fractal reconstruction parameters generated at the sending end, the extracted encrypted data is subjected to spatial inverse transformation to restore the DNA encoding sequence before the chaotic mapping. This step actually reverses the chaotic mapping and fractal transformation process, and requires accurate parameters to complete correctly.

[0154] Finally, a recurrent neural network (RNN) or long short-term memory network (LSTM) is used to perform temporal decoding on the restored DNA encoding sequence, and the integrity of the data is verified through a biometric feature verification code.

[0155] Exemplarily, first, the 16 MB high-dimensional chaotic encryption package is cut into 512 32 KB small blocks, each block is subjected to 8192-point FFT to obtain 16 384 complex frequency points and is disassembled into amplitude / phase; then 512 of the 500 10 kHz subbands are selected as embedding containers using the low 9 bits of the TV pseudo-random. When embedding, the data amplitude is compressed to 3%-5% of the subband energy, and a Logistic chaotic sequence is used to perturb the phase of each subband by ±0.02π, so that the overall spectrum only shows a barely perceptible 0.13 dB fluctuation within a 5 MHz bandwidth.

[0156] Again, use 1023-bit Gold code to do DSSS: after multiplying data bits and spread spectrum code, the power spectrum density is pulled to-75 dBm / Hz, and the shape is consistent with the thermal noise curve, and any non-cooperative receiver will misjudge it as the bottom noise.

[0157] After the ground station receives the 2.2 GHz QPSK stream, it first scans the 5 MHz bandwidth in real time using a sliding 8192-point FFT, and sends the power spectrum to the offline trained 3-layer CNN: the convolution kernel 7-5-3 extracts the 256-dimensional feature signature in the "pseudo noise" level by level, and outputs the confidence vector and the 256-point template derived from TV for cosine similarity detection.

[0158] If the similarity is higher than 0.85, it is determined that the sub-band contains the secret, and the frequency domain amplitude and phase are extracted to restore the 32KB data block by inverse FFT. After 512 blocks are recovered, the integrity is checked by SHA3-512, and the spatial inverse transformation is performed by fractal reconstruction parameters to reduce the 4096-dimensional point cloud to 2048 bp DNA sequence layer by layer, and finally decoded by 2-layer LSTM (128+256 units) sliding window, skipping biological structures such as TATAAA, GT…AG, and mapping each 64 bp window back to 8-bit binary stream;

[0159] After all the bit streams are recombined, calculate HMAC-SHA256 as the neural network verification identifier.

[0160] Step S6: Based on the communication cycle monitoring, the initial shared key pair is dynamically updated through the key rotation strategy. Based on the communication cycle monitoring, the initial shared key pair is dynamically updated through the key rotation strategy, including: when detecting orbit period change, data transmission anomaly or neural network verification identifier verification failure, the initial shared key pair is re-generated.

[0161] The present application defines three types of key events as the condition for triggering key regeneration:

[0162] First, the orbit period changes. When the satellite completes a complete orbit period or the orbit parameters change significantly (such as the orbit height, inclination or eccentricity changes more than the preset threshold), the key update process will be automatically triggered. This update mechanism based on physical state change ensures that the key is synchronized with the current orbit state of the satellite, enhancing the time and space correlation of the key.

[0163] Secondly, data transmission anomalies are monitored. Continuous monitoring of communication quality indicators such as signal strength, bit error rate, decoding success rate, etc. When these indicators show significant abnormalities (such as decoding success rate suddenly drops from normal 99% to below 90%), it is judged that there may be interference or attack, and the key update process is triggered immediately. This dynamic response based on communication quality ensures that the system can quickly adjust the defense strategy when facing interference or attack.

[0164] Finally, the neural network verification identification verification fails. The receiving end's neural network generates a verification identification in the decoding process, which should match the expected value. If verification fails continuously for multiple times, it is judged that there may be unauthorized decoding attempts or data tampering, and the key update is triggered immediately and may switch to a backup communication channel. This security response based on verification results provides an additional protection layer, effectively preventing man-in-the-middle attacks and data tampering.

[0165] When any of the trigger conditions is met, the elliptic curve parameter generation and key exchange process is re-executed to generate a new initial shared key pair.

[0166] The satellite secure communication method of the present application further comprises: by monitoring the satellite communication mode, signal characteristics and decoding success rate, the security state of the current communication environment is evaluated in real time; when an anomaly is detected, a security state report and a next round of encryption parameter seed are obtained, and a backup satellite communication channel is started; based on the security state report and the next round of encryption parameter seed, the dynamic parameters of the elliptic curve equation are automatically adjusted.

[0167] Firstly, through multi-dimensional real-time monitoring, the security state of the current communication environment is comprehensively evaluated. Specifically, three types of key indicators are monitored: communication mode indicators (such as data flow mode, communication frequency and duration, etc.), signal characteristic indicators (such as signal strength, signal-to-noise ratio, spectral characteristics, etc.), and decoding success rate indicators (including the success rate and error distribution of each layer decoding, etc.). These indicators are analyzed comprehensively by complex security state evaluation algorithms to generate real-time security threat scores, reflecting the security level of the current communication environment.

[0168] Secondly, when an anomaly is detected, a detailed security state report and a next round of encryption parameter seed are generated immediately, and pre-set emergency response measures are started. The security state report contains information such as the type, severity, possible source and recommended protection measures of the anomaly. At the same time, a new parameter seed with high entropy value is generated for the generation of next round encryption parameters. Most importantly, according to the nature and severity of the anomaly, the corresponding emergency measures are automatically started, such as switching to a backup satellite communication channel (which may be a different frequency band or modulation method), starting a stronger anti-interference mode, or activating a special security transmission protocol.

[0169] Finally, based on the security state report and the new parameter seed, the dynamic parameters of the elliptic curve equation and the overall encryption strategy are automatically adjusted. This adjustment is comprehensive, including not only the basic elliptic curve parameters but also the selection of the hash algorithm, the mapping rules of DNA encoding, the parameter settings of the chaotic system, and the configuration of the neural network. Through this comprehensive adjustment, the most effective protection strategy can be customized for specific threat types, greatly improving the ability to resist targeted attacks.

[0170] This adaptive protection mechanism enables the system to have "self-learning" and "memory" capabilities similar to the biological immune system, allowing it to learn from each security incident and continuously improve its threat identification model and response strategy, forming "immunological memory" for similar attack patterns and responding more quickly and effectively to similar threats in the future.

[0171] For example, if the decoding success rate suddenly drops from the normal 99.7% to 78.3% and the signal-to-noise ratio of the communication link is found to have decreased by 6dB, a security state report is immediately generated, with the threat level set to "moderate", indicating that the system may be subject to targeted interference. A new encryption parameter seed 0xF7E6D5C4B3A29180 is automatically generated, and the communication is switched from the X-band (8GHz) to the backup Ka-band (26GHz) channel. After receiving the switching instruction, the ground station completes the frequency band conversion within 3 seconds and recalculates the elliptic curve parameters based on the new seed: a changes from 0x7B2C to 0xD4E9, b changes from 0x3A5F to 0x8C1D, and the modulus p changes from 2 256 -189 to 2 256 -267.

[0172] As Figure 2 shown, the application also provides a satellite security communication system, comprising:

[0173] An elliptic curve key generation module 10 is configured to generate dynamic parameters of an elliptic curve equation based on satellite communication-related information, and obtain an initial shared key pair based on an elliptic curve algorithm, dynamic parameters, and a key exchange protocol.

[0174] A session key processing module 20 is configured to obtain a session-level encryption key through multi-layer hash operation and timestamp synchronization mechanism based on the initial shared key pair.

[0175] A biological feature encoding module 30 is configured to obtain biological feature encryption data through DNA sequence encoding and biological cryptography conversion algorithm based on the session-level encryption key.

[0176] A chaotic encryption processing module 40 is configured to obtain high-dimensional chaotic encryption packages through chaotic mapping disturbance and fractal geometric transformation processing based on the biological feature encryption data.

[0177] The hidden transmission module 50 is used for obtaining a hidden transmission data stream based on the high-dimensional chaotic encryption package through frequency domain spread spectrum steganography and neural network decoding verification.

[0178] The key update module 60 is used for dynamically updating the initial shared key pair through a key rotation strategy based on communication cycle monitoring.

[0179] Through the elliptic curve parameter dynamic change mechanism, different curve parameters are used for each communication, which significantly improves the cracking difficulty; the time stamp synchronous multi-layer encryption system is used in combination with the satellite orbit period to realize automatic key update, so as to ensure the timeliness and uniqueness of the key; the DNA sequence coding is combined with the chaos theory to realize biological camouflage and high non-linear transformation of the encrypted data; through the frequency domain steganography and the neural network verification mechanism, the hidden transmission and intelligent identification of the encrypted data are realized, and electronic reconnaissance and interference are effectively avoided.

[0180] Specifically, the application dynamically generates elliptic curve parameters based on the real-time satellite orbit position and accurate time stamp. This means that each communication is actually based on different mathematical models, so even if the attacker successfully cracks the communication at a certain time, the information is of no help for the next communication.

[0181] After obtaining the initial shared key, it is not directly used for encryption, but is used as a seed to calculate the final session-level encryption key through three different hash algorithms. Each layer of hash calculation introduces different time-related parameters and orbit information, ensuring that the generated session-level encryption key has strong timeliness and uniqueness.

[0182] The binary key data is mapped to a DNA sequence composed of A, T, C and G four bases, and the promoter, terminator and intron structure commonly used in biology are added, so that the encrypted data cannot be distinguished from the real biological gene fragments in appearance.

[0183] Through the chaos theory and fractal geometry, the data is deeply transformed, the DNA coding sequence is used as the initial value of the chaotic system, and after thousands of iterations, a completely unpredictable chaotic orbit is generated.

[0184] At the same time, the data is also mapped to a high-dimensional fractal space, and the self-similarity and infinite detail characteristics of the fractal are used to distribute the data on the macro, meso and micro levels. This multi-dimensional mathematical transformation makes the encrypted data have extremely high complexity, and even if the attacker masters the algorithm, without the accurate initial parameters, the original data cannot be reversely deduced.

[0185] The encrypted data is embedded in the normal telemetry signal of the satellite through frequency domain transform, and spread spectrum technology is used to disperse the signal energy into a wide frequency band range. This makes the encrypted communication indistinguishable from the background noise in the frequency spectrum, with a power spectral density as low as -140 dBm / Hz, which is almost impossible to be detected by conventional electronic reconnaissance equipment.

[0186] Detailed description of the present embodiment can refer to the corresponding description in the foregoing embodiments, which will not be repeated here.

[0187] The above describes the basic principles of the present disclosure in combination with specific embodiments, but it should be pointed out that the advantages, advantages, effects and the like mentioned in the present disclosure are only examples and not limitations, and these advantages, advantages, effects and the like cannot be considered as the must-have of each embodiment of the present disclosure. In addition, the above specific details are only for the purpose of example and for the purpose of understanding, and the above details do not limit the present disclosure to the must-use of the above specific details to realize.

[0188] The above description has been given for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain modifications, alterations, changes, additions and sub-combinations thereof.

Claims

1. A satellite secure communication method, characterized in that, Includes the following steps: Based on satellite communication information, dynamic parameters of the elliptic curve equation are generated. Based on the elliptic curve algorithm, dynamic parameters, and key exchange protocol, an initial shared key pair is obtained. Based on the initial shared key pair, a session-level encryption key is obtained through multi-layer hash operations and a timestamp synchronization mechanism; Based on the session-level encryption key, biometric encrypted data is obtained through DNA sequence encoding and biocryptographic conversion algorithms; Based on the biometric encrypted data, a high-dimensional chaotic encryption packet is obtained through chaotic mapping perturbation and fractal geometric transformation. Based on the high-dimensional chaotic encryption packet, the covertly transmitted data stream is obtained through frequency domain spread spectrum steganography and neural network decoding verification. Based on communication cycle monitoring, the initial shared key pair is dynamically updated through a key rotation strategy; Based on satellite communication information, dynamic parameters for the elliptic curve equation are generated. Based on the elliptic curve algorithm, dynamic parameters, and key exchange protocol, an initial shared key pair is obtained, including: Based on the satellite's current orbital position coordinates and the ground station's GPS timestamp, a set of dynamic parameters for the elliptic curve equation are calculated. The dynamic parameters include the curve's a and b coefficients and the modulus p of the finite field. Based on the dynamic parameters, the elliptic curve Diffie-Hellman key exchange protocol is executed, and the satellite and the ground station each generate private keys on the dynamic elliptic curve and calculate the corresponding public keys. By exchanging public keys through the satellite communication link and combining them with their respective private keys, a 256-bit initial shared key K1 and a current orbital period identifier T1 are calculated.

2. The satellite secure communication method according to claim 1, characterized in that, Based on the initial shared key pair, a session-level encryption key is obtained through multi-layer hash operations and a timestamp synchronization mechanism, including: Based on the initial shared key K1, the orbital period identifier T1, and the GPS timestamp, a time parameter vector is constructed by combining the satellite orbital period information; Based on the time parameter vector, a 512-bit session-level encryption key K2 with time validity is derived layer by layer through multiple rounds of hash function calculation, each round using a different hash algorithm and incorporating a satellite orbit count counter. The corresponding timestamp hash value is also derived.

3. The satellite secure communication method according to claim 2, characterized in that, Based on the initial shared key K1, the orbital period identifier T1, and the GPS timestamp, a time parameter vector is constructed by combining the satellite orbital period information, including: The initial shared key K1 is divided into 4 sub-key vectors by 64-bit blocks; The orbital period identifier T1 is converted into 32-bit binary data, and then a 64-bit period identifier vector is obtained by bit extension or repeated padding. Extract the second-level and millisecond-level time information from the GPS timestamp to form a 64-bit timestamp vector; Obtain the current satellite's perigee, apogee, orbital inclination, and orbital period, and quantize them into a 128-bit orbital feature vector; The vectors are linearly combined according to predefined weight coefficients to construct a 288-bit time parameter vector containing time synchronization information and orbital dynamic characteristics.

4. The satellite secure communication method according to claim 2, characterized in that, Based on the session-level encryption key, biometric encrypted data is obtained through DNA sequence encoding and bio-cryptographic conversion algorithms, including: The session-level encryption key is re-encoded according to the rules of genetic code to obtain binary data; Binary data is mapped to a sequence combination of four DNA bases, and the insertion positions of regulatory sequences, introns, and exons in the sequence combination are determined based on the timestamp hash value. Error correction of sequence combinations was performed using biological redundancy mechanisms to obtain a DNA coding sequence of 2048 base pairs and a biometric check code.

5. The satellite secure communication method according to claim 4, characterized in that, Based on the aforementioned biometric encrypted data, a high-dimensional chaotic encryption package is obtained through chaotic mapping perturbation and fractal geometric transformation processing, including: By utilizing the pseudo-random properties of deterministic chaotic systems, DNA coding sequences are dynamically rearranged and perturbed on chaotic orbits; The dynamically rearranged and perturbed DNA coding sequences are mapped into a multidimensional fractal space. Through the self-similarity and recursive properties of fractals, the DNA coding sequences are distributed at the macroscopic, mesoscopic and microscopic levels. Using biometric check codes as fractal parameter seeds, spatial distribution is performed according to the principal fractal pattern at the macroscopic level, substructure division is performed based on the local features of the DNA coding sequence at the mesoscopic level, and the precise coordinates of each base in multidimensional space are determined at the microscopic level, resulting in a high-dimensional chaotic encryption package containing 4096-dimensional vector data and fractal reconstruction parameters.

6. The satellite secure communication method according to claim 5, characterized in that, Based on the aforementioned high-dimensional chaotic encryption packet, a covertly transmitted data stream is obtained through frequency domain spread spectrum steganography and neural network decoding verification, including: The encrypted data in the chaotic encryption packet is embedded into the spectrum of the satellite telemetry carrier signal after frequency domain transformation; Spread spectrum technology is used to disperse the energy of telemetry carrier signals over a wide frequency band, making them exhibit background noise characteristics. By using a deep convolutional neural network to perform multi-layer feature extraction and pattern recognition on the spectrum of satellite telemetry carrier signals, specific data patterns hidden in the spectrum can be obtained. Using fractal reconstruction parameters, spatial inverse transformation is performed to recover the DNA coding sequence; The recovered DNA coding sequence is temporally decoded and data integrity is verified by using a recurrent neural network to obtain the covert transmission data stream and neural network verification identifier.

7. The satellite secure communication method according to claim 6, characterized in that, Based on communication cycle monitoring, the initial shared key pair is dynamically updated through a key rotation strategy, including: When a change in orbital period, abnormal data transmission, or failure of neural network verification identifier verification is detected, the initial shared key pair is regenerated.

8. The satellite secure communication method according to claim 6, characterized in that, Also includes: By monitoring satellite communication modes, signal characteristics, and decoding success rates, the security status of the current communication environment can be assessed in real time. When an anomaly is detected, a security status report and the next round of encryption parameter seed are obtained, and the backup satellite communication channel is activated; Based on the security status report and the next round of encryption parameter seed, the dynamic parameters of the elliptic curve equation are automatically adjusted.

9. A satellite secure communication system, characterized in that, include: The elliptic curve key generation module is used to generate dynamic parameters of the elliptic curve equation based on satellite communication-related information, and obtain an initial shared key pair based on the elliptic curve algorithm, dynamic parameters, and key exchange protocol. The session key processing module is used to obtain a session-level encryption key based on the initial shared key pair through multi-layer hash operations and a timestamp synchronization mechanism; The biometric encoding module is used to obtain encrypted biometric data based on the session-level encryption key through DNA sequence encoding and biometric cryptography conversion algorithms; The chaotic encryption processing module is used to encrypt data based on the biometric features and obtain a high-dimensional chaotic encryption package through chaotic mapping perturbation and fractal geometric transformation. The covert transmission module is used to obtain the covert transmission data stream based on the high-dimensional chaotic encryption packet through frequency domain spread spectrum steganography and neural network decoding verification. The key update module is used to dynamically update the initial shared key pair based on communication cycle monitoring and a key rotation strategy. Based on satellite communication information, dynamic parameters for the elliptic curve equation are generated. Based on the elliptic curve algorithm, dynamic parameters, and key exchange protocol, an initial shared key pair is obtained, including: Based on the satellite's current orbital position coordinates and the ground station's GPS timestamp, a set of dynamic parameters for the elliptic curve equation are calculated. The dynamic parameters include the curve's a and b coefficients and the modulus p of the finite field. Based on the dynamic parameters, the elliptic curve Diffie-Hellman key exchange protocol is executed, and the satellite and the ground station each generate private keys on the dynamic elliptic curve and calculate the corresponding public keys. By exchanging public keys through the satellite communication link and combining them with their respective private keys, a 256-bit initial shared key K1 and a current orbital period identifier T1 are calculated.

Citation Information

Patent Citations

  • Satellite signal tamper-proofing method and system

    CN120201418A

  • Satellite portable station data encryption authentication method and system

    CN120264274A