Satellite communication frame structure security enhancement method and system based on dynamic fragmentation embedding

By using a dynamic fragmentation embedding method, the control information of satellite communication frames is fragmented and LDPC error correction coding is performed. The fragmented information is then embedded into the QPSK symbol phase in the data field. Combined with quantum key encryption, this solves the problem of the satellite communication frame structure being vulnerable to attack, achieving high security and real-time performance while reducing the cost of modification.

CN121864166APending Publication Date: 2026-04-14XIAN SPACE STAR TECH IND GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-31
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

The existing satellite communication frame structure is vulnerable to attackers who can identify frame header patterns through pattern matching, leading to the risk of key leakage. Furthermore, traditional encryption schemes and physical layer scrambling techniques are difficult to meet the real-time and security requirements in dynamic low-Earth orbit satellite networking scenarios.

Method used

A dynamic fragmentation embedding method is adopted to fragment the control information and perform LDPC error correction encoding. A dynamic mapping rule R is generated through a hash function. The encoded information fragments are embedded in the QPSK symbol phase of the data field and the satellite state parameters are transmitted through quantum key encryption. The receiving end decrypts and reproduces the dynamic mapping rule R to extract the control information.

Benefits of technology

It achieves the frame structure of frames with physically disappeared frame headers and frames with unlocatable control information, and frames with unlocatable frame headers, increasing the difficulty of cracking by 10^6 times. It meets the millisecond-level switching requirements of low-orbit satellites, has high compatibility, low modification cost, and strong anti-interference ability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121864166A_ABST
    Figure CN121864166A_ABST
Patent Text Reader

Abstract

The invention discloses a satellite communication frame structure security enhancement method and system based on dynamic fragmentation embedding, and the method comprises the steps: carrying out the fragmentation processing of the control information of a satellite communication frame, and carrying out the LDPC error correction coding operation; a sending end collects a satellite state parameter P in real time, and a dynamic mapping rule R is generated through a hash function; the encoded information fragments are embedded into a QPSK symbol phase of a data field according to a dynamic mapping rule R to form an integrated frame and transmit the integrated frame, and meanwhile, a satellite state parameter P is sent to a receiving end in a quantum key encryption mode; a receiving end performs decryption to obtain a satellite state parameter P, reproduces a dynamic mapping rule R, extracts information fragments from the integrated frame, recombines the information fragments into a control information set C, and analyzes service data; and updating the dynamic mapping rule R according to the satellite orbit type and the channel change. The invention provides a technical scheme which does not have an independent frame header and is used for dynamically distributing and embedding control information, and dual security enhancement of frame header physical disappearance and control information non-localization is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of satellite communication security technology, and specifically relates to a method and system for enhancing the security of satellite communication frame structure based on dynamic fragmentation embedding. Background Technology

[0002] In satellite communication, the traditional frame structure adopts a binary architecture of "frame header + data field". The frame header contains fixed-format control information such as synchronization word (e.g., 0xAA55), frame length (16 bits), and checksum (CRC16), accounting for approximately 5%-10% (e.g., a 1024-byte frame contains a 64-byte frame header). Attackers can identify frame header patterns by collecting 100-1000 frames of data and then analyze the frame structure to launch an attack through pattern matching (e.g., K-means clustering). Existing technology has the following drawbacks:

[0003] (1) Encryption schemes (such as AES encrypted frame headers) rely on key distribution. In the scenario of dynamic networking of low-orbit satellites, the key update delay can reach hundreds of milliseconds, which poses a risk of key leakage.

[0004] (2) Dynamic frame header schemes (such as generating variable frame headers based on timestamps) still retain the feature that "the frame header is located at the beginning of the frame". Attackers can locate the frame header area by statistically analyzing the frame length.

[0005] (3) Physical layer scrambling techniques (such as Scrambler) only perform pseudo-randomization on the frame header. The scrambling sequence period is usually 2^15-1, which is easily cracked by brute force. Summary of the Invention

[0006] The purpose of this invention is to provide a method and system for enhancing the security of satellite communication frame structure based on dynamic fragmentation embedding. It provides a technical solution with no independent frame header and dynamic distribution embedding of control information, achieving dual security enhancement of "physical disappearance of frame header + unlocatable control information".

[0007] The technical solution adopted in this invention is a satellite communication frame structure security enhancement method based on dynamic fragmentation embedding, which includes the following steps:

[0008] S1, fragments the control information of the satellite communication frame and performs LDPC error correction coding operation;

[0009] S2, The transmitting end collects satellite status parameters P in real time and generates dynamic mapping rules R through a hash function;

[0010] S3, the encoded information fragments are embedded into the QPSK symbol phase of the data field according to the dynamic mapping rule R, forming an integrated frame and transmitting it. At the same time, the satellite state parameters P are sent to the receiving end through quantum key encryption.

[0011] S4, the receiving end decrypts and obtains the satellite status parameter P, reproduces the dynamic mapping rule R, extracts information fragments from the integrated frame and reassembles them into a control information set C, and parses the service data;

[0012] S5 updates the dynamic mapping rule R based on satellite orbit type and channel changes.

[0013] Furthermore, in step S1, the control information of the satellite communication frame is fragmented and LDPC error correction coding is performed. The specific steps include:

[0014] S11, Extract the control information set C of the satellite communication frame;

[0015] The control information set C includes a synchronization identifier, frame length, source / destination address, and checksum, with a total length of 112 bits.

[0016] S12, split the control information set C into N information fragments;

[0017] The rule for N is: N = ceil(total length / 8), that is, 112 bits are split into 14 fragments, the first 13 are 8 bits, the last one is 4 bits, and 4 redundant bits are added to make up 8 bits.

[0018] S13, perform LDPC error correction coding operation on each information fragment, and output the encoded 16-bit information fragment.

[0019] Furthermore, in step S2, the transmitting end collects satellite status parameters P in real time and generates dynamic mapping rules R through a hash function. Specific steps include:

[0020] S21, The transmitting end collects satellite status parameters P in real time;

[0021] Satellite status parameters P include orbital angle θ, ephemeris timestamp T, channel SNR value S, and onboard equipment hardware fingerprint F;

[0022] S22, calculate the hash value H of the satellite state parameter P using the national cryptographic SM3 hash function:

[0023] H = SM3(θ||T||S||F)

[0024] We obtain a 256-bit hash value H;

[0025] S23, parse the dynamic mapping rule R from the hash value H of the satellite state parameter P;

[0026] The dynamic mapping rule R includes the embedding positions Pos_i of N information fragments in the data domain, the embedding phase offset Δφ_i, and the embedding order, where:

[0027] Embedding position Pos_i: obtained by parsing the first 14×16=224 bits of the hash value H, and satisfying 0≤Pos_i≤L-1, where L is the length of the data field, and all embedding positions Pos_i do not overlap;

[0028] Embedding method: Take the last 32 bits of the hash value H, and each 8 bits corresponds to an embedding strength coefficient K_i. After normalization, the coefficients of 0-1 are obtained. Multiply them by the normalized value of the channel SNR to obtain the embedding phase offset Δφ_i.

[0029] Embedding order: The order in which fragments are embedded is determined by the middle 14 bits of the hash value H.

[0030] Furthermore, in step S3, the encoded information fragments are embedded into the QPSK symbol phase of the data domain according to the dynamic mapping rule R to form an integrated frame and transmit it. Simultaneously, the satellite state parameters P are sent to the receiving end using quantum key encryption. Specific steps include:

[0031] S31, Data field preprocessing;

[0032] The business data is QPSK modulated to generate an I / Q symbol stream;

[0033] S32, information fragment embedding;

[0034] At the symbol position corresponding to the embedding position Pos_i, the encoded 16-bit information fragment is embedded through phase fine-tuning;

[0035] Each bit corresponds to the ±Δφ_i offset of the symbol phase;

[0036] S33, generate an integrated frame;

[0037] Once the symbol stream is embedded, it is directly used as a transmission frame with a fixed frame length of L+14×16 bits.

[0038] S33, transmits satellite status parameters P;

[0039] The satellite state parameter P is sent to the receiving end via a quantum key encryption link;

[0040] The encryption key is a pre-shared SM4 key between satellite and ground.

[0041] Further, in step S4, the receiving end decrypts and obtains the satellite state parameter P, reproduces the dynamic mapping rule R, extracts information fragments from the integrated frame and reassembles them into a control information set C, and parses the service data. Specific steps include:

[0042] S41, decrypt satellite status parameter P;

[0043] The receiver obtains the encrypted satellite status parameter P through the QKD link, and after decryption, reproduces the hash value H and the dynamic mapping rule R.

[0044] S42, Information Fragment Extraction;

[0045] Phase detection is performed on the embedding position Pos_i of the received symbol stream, the phase offset Δφ_i is calculated, and the encoded 16-bit information fragments are restored.

[0046] S43, Error Correction and Reorganization;

[0047] LDPC decoding is performed on the 16-bit information fragment to obtain an 8-bit original information fragment, which is then spliced ​​together in the embedding order to form a 112-bit control information set C.

[0048] S44, Data Analysis;

[0049] The integrity of the frame is verified based on the synchronization identifier in the control information set C. The service data is extracted through the frame length and address information, and finally the correctness of the data is ensured by CRC32 check.

[0050] Furthermore, in S5, the dynamic mapping rule R is updated according to the satellite orbit type and channel changes, specifically as follows:

[0051] The rule update cycle for low-Earth orbit (LEO) satellites is M=5, meaning that the dynamic mapping rule R is updated every 5 frames transmitted by the LEO satellite; the rule update cycle for high-Earth orbit (HEO) satellites is M=20, meaning that the dynamic mapping rule R is updated every 20 frames transmitted by the HEO satellite.

[0052] When the channel SNR change ΔS > 3dB or the on-board device hardware fingerprint F verification fails, the dynamic mapping rule R is immediately updated to avoid security vulnerabilities caused by sudden changes in channel SNR or on-board device forgery.

[0053] A satellite communication frame structure security enhancement system based on dynamic fragmentation embedding is used to implement the aforementioned satellite communication frame structure security enhancement method based on dynamic fragmentation embedding. It includes a control information processing module, a satellite state awareness module, a dynamic rule engine, a physical layer embedding module, a quantum encrypted transmission module, a receiver parsing module, and a rule update controller, wherein:

[0054] The control information processing module is used to implement control information fragmentation and LDPC encoding.

[0055] The satellite status sensing module is used to collect satellite status parameters P in real time.

[0056] The dynamic rule engine is used to generate dynamic mapping rules R through a hash function;

[0057] The physical layer embedding module is used to embed the encoded information fragments into the QPSK symbol phase of the data field according to the dynamic mapping rule R, forming an integrated frame for transmission;

[0058] The quantum encryption transmission module is used to send the satellite state parameter P to the receiving end using quantum key encryption.

[0059] The receiving end parsing module is used to decrypt and obtain satellite status parameters P, reproduce dynamic mapping rules R, extract information fragments from the integrated frame and reassemble them into a control information set C, and parse service data.

[0060] The rule update controller is used to update the dynamic mapping rule R according to satellite orbit type and channel changes.

[0061] Furthermore, the control information processing module includes a fragmentation unit and an LDPC encoding unit; the fragmentation unit is used to perform fragmentation processing of the control information of the satellite communication frame; the LDPC encoding unit is used to perform LDPC error correction encoding.

[0062] Furthermore, the satellite status awareness module includes an orbital angle sensor, a time synchronization unit, an SNR detector, and a hardware fingerprint extractor; the orbital angle sensor is used to collect the orbital angle θ; the time synchronization unit is used to collect the ephemeris timestamp T; the SNR detector is used to collect the channel SNR value S; and the hardware fingerprint extractor is used to collect the hardware fingerprint F of the on-board equipment.

[0063] Furthermore, the physical layer embedding module includes a QPSK modulator and a phase fine-tuning unit; the QPSK modulator is used to generate a data symbol stream; the phase fine-tuning unit is used to embed the encoded information fragments into the QPSK symbol phase of the data domain according to the dynamic mapping rule R, forming an integrated frame and transmitting it.

[0064] Furthermore, the receiving end parsing module includes a parameter decryption unit, a dynamic rule reproduction unit, an integrated frame receiving unit, a phase detection unit, an LDPC decoding unit, a control information reassembly unit, and a service data parsing unit. The parameter decryption unit is used to decrypt and obtain satellite state parameters P; the dynamic rule reproduction unit is used to reproduce hash values ​​H and dynamic mapping rules R; the integrated frame receiving unit is used to receive and store integrated frames; the phase detection unit is used to perform phase detection on the embedding position Pos_i of the received symbol stream, calculate the phase offset Δφ_i, and restore the encoded 16-bit information fragments; the LDPC decoding unit is used to perform LDPC decoding on the 16-bit information fragments to obtain 8-bit original information fragments; the control information reassembly unit is used to concatenate the information into a 112-bit control information set C according to the embedding order; and the service data parsing unit is used to implement service data parsing.

[0065] The beneficial effects of this invention are as follows:

[0066] A technical solution is provided that eliminates the need for a separate frame header and dynamically distributes and embeds control information, achieving dual security enhancement through "physical disappearance of the frame header + unlocatable control information," wherein:

[0067] Security: By eliminating independent frame headers, attackers cannot locate control information through the frame structure; the mapping rules are deeply bound to satellite physical parameters, making it 10^6 times more difficult to crack than traditional dynamic frame headers (based on brute-force complexity analysis);

[0068] Real-time performance: Rule generation latency ≤ 1ms (SM3 hash calculation time), meeting the millisecond-level switching requirements of low-Earth orbit satellites;

[0069] Compatibility: It can be directly deployed on the physical layer of the existing DVB-S2 protocol, requiring only software upgrades (no hardware modifications are needed), reducing the transformation cost by 60%;

[0070] Anti-interference: LDPC coding ensures that the bit error rate of fragments is ≤10^-5 when SNR≥5dB, thus ensuring reliable extraction of control information. Attached Figure Description

[0071] Figure 1 This is a flowchart of the satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to the present invention.

[0072] Figure 2 This is a data interaction flowchart of the satellite communication frame structure security enhancement system based on dynamic fragmentation embedding, as described in this invention.

[0073] Figure 3 This is a comparison diagram of the traditional satellite communication frame structure and the "integrated frame structure" proposed in this invention.

[0074] Figure 4 This is a schematic diagram of phase embedding in the present invention. Detailed Implementation

[0075] To make the objectives, technical solutions, and advantages of this invention clearer and more understandable, the technical solutions of this invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the following embodiments are merely illustrative of this invention and are not intended to limit the invention.

[0076] A method for enhancing the security of satellite communication frame structure based on dynamic fragmentation embedding, such as Figure 1 As shown, it includes the following steps:

[0077] S1 involves fragmenting the control information of the satellite communication frame and performing LDPC error correction coding. The specific steps include:

[0078] S11, Extract the control information set C of the satellite communication frame;

[0079] The control information set C includes a synchronization identifier (32 bits), frame length (16 bits), source / destination address (16 bits each), and checksum (CRC32, 32 bits), with a total length of 112 bits.

[0080] S12, split the control information set C into N information fragments;

[0081] The rule for N is: N = ceil(total length / 8), that is, 112 bits are split into 14 fragments, the first 13 are 8 bits, the last one is 4 bits, and 4 redundant bits are added to make up 8 bits.

[0082] S13, perform (16,8) LDPC error correction coding operation (code rate 0.5) on each information fragment, and output the encoded 16-bit information fragment to improve noise resistance.

[0083] S2, the transmitting end collects satellite status parameters P in real time and generates dynamic mapping rules R through a hash function. The specific steps include:

[0084] S21, The transmitting end collects satellite status parameters P in real time;

[0085] The satellite status parameters P include orbital angle θ (accuracy 0.01°, 32-bit floating point), ephemeris timestamp T (UTC time, accurate to milliseconds, 64-bit), channel SNR value S (0-30dB, 8-bit quantization), and on-board equipment hardware fingerprint F (unique identifier, 64-bit, such as FPGA chip ID).

[0086] S22, calculate the hash value H of the satellite state parameter P using the national cryptographic SM3 hash function:

[0087] H = SM3(θ||T||S||F) Formula 1

[0088] The 256-bit hash value H is obtained.

[0089] S23, parse the dynamic mapping rule R from the hash value H of the satellite state parameter P;

[0090] The dynamic mapping rule R includes the embedding positions Pos_i of N information fragments in the data domain, the embedding phase offset Δφ_i, and the embedding order, where:

[0091] Embedding position Pos_i: obtained by parsing the first 14×16=224 bits of the hash value H, and satisfying 0≤Pos_i≤L-1, where L is the length of the data field, and all embedding positions Pos_i do not overlap;

[0092] Embedding method: Take the last 32 bits of the hash value H, and assign an embedding strength coefficient K_i (0-255) to every 8 bits. After normalization, obtain a coefficient of 0-1. Multiply this coefficient by the normalized value of the channel SNR (S / 30) to obtain the embedding phase offset Δφ_i.

[0093] Δφ_i=K_i×(S / 30)×π / 8 (range 0-π / 8) Formula 2

[0094] Embedding order: The logical order of fragment embedding is determined by the middle 14 bits of the hash value H (each bit represents the order) (to avoid reassembly errors at the receiving end).

[0095] S3, the encoded information fragments are embedded into the QPSK symbol phase of the data domain according to the dynamic mapping rule R, forming an integrated frame for transmission. Simultaneously, the satellite state parameters P are sent to the receiving end using quantum key encryption. Specific steps include:

[0096] S31, Data field preprocessing;

[0097] The business data is QPSK modulated to generate an I / Q symbol stream.

[0098] S32, information fragment embedding;

[0099] At the symbol position corresponding to the embedding position Pos_i, the encoded 16-bit information fragment is embedded through phase fine-tuning;

[0100] Each bit corresponds to the ±Δφ_i offset of the symbol phase (0→+Δφ_i, 1→-Δφ_i).

[0101] S33, generate an integrated frame;

[0102] After embedding, the symbol stream is directly used as a transmission frame (without an independent frame header), and the frame length is fixed at L+14×16 bits (the total length of the data field and the embedded fragments).

[0103] S33, transmits satellite status parameters P;

[0104] The satellite state parameters P are transmitted to the receiving end via a quantum key encryption link (such as the QKD link of the "Micius" satellite);

[0105] The encryption key is a pre-shared SM4 key (128 bits) between satellite and ground.

[0106] S4, the receiving end decrypts and obtains the satellite status parameter P, reproduces the dynamic mapping rule R, extracts information fragments from the integrated frame and reassembles them into a control information set C, and parses the service data. The specific steps include:

[0107] S41, decrypt satellite status parameter P;

[0108] The receiver obtains the encrypted satellite status parameter P through the QKD link, and after decryption, reproduces the hash value H and the dynamic mapping rule R.

[0109] S42, Information Fragment Extraction;

[0110] Phase detection is performed on the embedding position Pos_i of the received symbol stream, the phase offset Δφ_i is calculated, and the encoded 16-bit information fragment is restored.

[0111] S43, Error Correction and Reorganization;

[0112] LDPC decoding is performed on the 16-bit information fragment to obtain an 8-bit original information fragment, which is then spliced ​​together in the embedding order to form a 112-bit control information set C.

[0113] S44, Data Analysis;

[0114] The integrity of the frame is verified based on the synchronization identifier in the control information set C. The service data is extracted through the frame length and address information, and finally the correctness of the data is ensured by CRC32 check.

[0115] S5 updates the dynamic mapping rule R based on satellite orbit type and channel changes, specifically as follows:

[0116] The rule update cycle for low-Earth orbit (LEO) satellites is M=5, meaning that LEO satellites (such as Starlink) update the dynamic mapping rule R every 5 frames transmitted (approximately 0.1° / s due to rapid changes in orbital angle). The rule update cycle for high-Earth orbit (HEO) satellites is M=20, meaning that HEO satellites update the dynamic mapping rule R every 20 frames transmitted (approximately 0.001° / s due to slower changes in orbital angle).

[0117] When the channel SNR change ΔS > 3dB or the on-board device hardware fingerprint F verification fails, the dynamic mapping rule R is immediately updated to avoid security vulnerabilities caused by sudden changes in channel SNR or on-board device forgery.

[0118] The satellite communication frame structure security enhancement system based on dynamic fragmentation embedding includes a control information processing module, a satellite state awareness module, a dynamic rule engine, a physical layer embedding module, a quantum encrypted transmission module, a receiver parsing module, and a rule update controller.

[0119] I. Control Information Processing Module

[0120] The control information processing module is used to implement control information fragmentation and LDPC encoding;

[0121] The control information processing module includes a fragmentation unit and an LDPC encoding unit; the fragmentation unit is used to perform fragmentation processing of control information in satellite communication frames; the LDPC encoding unit is used to perform LDPC error correction coding.

[0122] II. Satellite Status Awareness Module

[0123] The satellite status awareness module is used to collect satellite status parameters P in real time.

[0124] The satellite status awareness module includes an orbital angle sensor (accuracy 0.01°), a time synchronization unit (deviation from UTC ≤ 1ms), an SNR detector (sampling rate 1kHz), and a hardware fingerprint extractor; the orbital angle sensor is used to acquire the orbital angle θ; the time synchronization unit is used to acquire the ephemeris timestamp T; the SNR detector is used to acquire the channel SNR value S; and the hardware fingerprint extractor is used to acquire the hardware fingerprint F of the onboard equipment.

[0125] III. Dynamic Rule Engine

[0126] The dynamic rule engine is used to generate dynamic mapping rules R using hash functions.

[0127] IV. Physical Layer Embedded Module

[0128] The physical layer embedding module is used to embed the encoded information fragments into the QPSK symbol phase of the data field according to the dynamic mapping rule R, forming an integrated frame for transmission.

[0129] The physical layer embedding module includes a QPSK modulator and a phase fine-tuning unit (accuracy ±0.01π); the QPSK modulator is used to generate a data symbol stream; the phase fine-tuning unit is used to embed the encoded information fragments into the QPSK symbol phase of the data domain according to the dynamic mapping rule R, forming an integrated frame for transmission.

[0130] V. Quantum Encryption Transmission Module

[0131] The quantum encryption transmission module is used to send the satellite state parameters P to the receiving end using quantum key encryption.

[0132] Quantum encryption transmission module: speed ≥1Mbps, supports SM4 key encryption.

[0133] VI. Receiver Parsing Module

[0134] The receiver parsing module is used to decrypt and obtain satellite status parameters P, reproduce dynamic mapping rules R, extract information fragments from the integrated frame and reassemble them into a control information set C, and parse service data.

[0135] The receiver parsing module includes a parameter decryption unit, a dynamic rule reproduction unit, an integrated frame receiving unit, a phase detection unit (accuracy ±0.005π), an LDPC decoding unit, a control information reassembly unit, and a service data parsing unit. The parameter decryption unit decrypts and obtains the satellite state parameter P. The dynamic rule reproduction unit reproduces the hash value H and the dynamic mapping rule R. The integrated frame receiving unit receives and stores the integrated frame. The phase detection unit performs phase detection on the embedding position Pos_i of the received symbol stream, calculates the phase offset Δφ_i, and restores the encoded 16-bit information fragment. The LDPC decoding unit performs LDPC decoding on the 16-bit information fragment to obtain an 8-bit original information fragment. The control information reassembly unit concatenates the fragments into a 112-bit control information set C according to the embedding order. The service data parsing unit performs service data parsing.

[0136] VII. Rule Update Controller

[0137] The rule update controller is used to update the dynamic mapping rule R based on satellite orbit type and channel changes.

[0138] The data interaction process of the satellite communication frame structure security enhancement system based on dynamic fragmentation embedding of this invention is as follows: Figure 2 As shown:

[0139] I. Interaction between the sending module:

[0140] (1) The fragmentation unit of the control information processing module splits the 112-bit control information into 14 fragments, which are then expanded into 16-bit anti-interference fragments by the LDPC encoding unit;

[0141] (2) The satellite status perception module collects satellite status parameters P (orbit angle θ, timestamp T, channel SNR value S, hardware fingerprint F) through sub-units such as orbit angle sensor (accuracy 0.01°) and SNR detector (sampling rate 1kHz), and inputs them into the dynamic rule engine;

[0142] (3) The dynamic rule engine generates dynamic mapping rule R (containing 14 embedding positions Pos_i, phase offset Δφ_i and embedding order) based on the SM3 hash function, and outputs it to the physical layer embedding module and the quantum encryption transmission module respectively;

[0143] (4) The physical layer embedding module generates a data symbol stream through a QPSK modulator, and the phase fine-tuning unit (accuracy ±0.01π) embeds the fragments into the phase according to the dynamic mapping rule R to form an integrated frame;

[0144] (5) After the quantum encryption transmission module encrypts the satellite state parameter P, it transmits it with the integrated frame through the satellite-to-ground communication link.

[0145] II. Receiver module interaction:

[0146] (1) After the quantum decryption unit of the receiver parsing module decrypts and obtains the satellite state parameter P, the dynamic rule reproduction unit reconstructs the dynamic mapping rule R.

[0147] (2) After receiving and storing the integrated frame, the integrated frame receiving unit sends it to the phase detection unit. The phase detection unit (accuracy ±0.005π) extracts the coded fragments from the integrated frame according to the satellite state parameter P. The complete control information is obtained by the LDPC decoding unit and the control information reassembly unit. Finally, the effective data is extracted by the service data parsing unit.

[0148] III. Dynamic Update Mechanism

[0149] The rule update controller triggers dynamic mapping rule R updates based on satellite type (low orbit / high orbit) and channel changes (ΔS>3dB) to ensure the real-time performance and security of dynamic mapping rule R.

[0150] like Figure 3 As shown, the core differences between the traditional satellite communication frame structure and the "integrated frame structure" proposed in this invention are as follows:

[0151] (1) Traditional frame structure (right):

[0152] The system employs a binary segmentation model consisting of a frame header and a data field. The frame header region, located at the beginning of the frame and occupying 5%-10% of the total length, contains control information in a fixed format (synchronization word, frame length, address, checksum, etc.). In this structure, the position and format of the frame header exhibit strong regularity, allowing attackers to quickly identify its boundaries and content through multi-frame acquisition.

[0153] (2) The integrated frame structure of the present invention (left):

[0154] The independent frame header is completely eliminated, and the overall frame structure is a single data field. The control information in the original frame header is split into 14 fragments, which are then encoded by LDPC and embedded into random positions (Pos_0 to Pos_13) in the data field using a dynamic mapping rule R. Fragment embedding does not change the overall length ratio of the data field (business data still accounts for approximately 98.5%), and the embedding position changes dynamically with satellite status parameters, making it impossible for attackers to locate the control information using a fixed pattern.

[0155] The core difference between the two is that the traditional structure relies on "independent frame headers" to realize control functions, while the present invention achieves "physical stealth" of control information through "fragmented embedding + dynamic distribution", fundamentally avoiding the risk of frame headers being identified and cracked.

[0156] Figure 4 This demonstrates the correspondence between QPSK symbol phase offset and information fragment bits:

[0157] This diagram illustrates the phase embedding principle of information fragments in QPSK modulation symbols using a simplified model. The core logic is as follows:

[0158] (1) QPSK standard phase (base reference):

[0159] The four largest parts in the diagram correspond to the four reference phases of traditional QPSK modulation (0°, 90°, 180°, 270°), which represent binary data “00”, “01”, “11”, and “10”, respectively, and are the original modulation state of the service data.

[0160] (2) Phase embedding method of information fragment bits:

[0161] When the bit of the embedded information fragment is "0", the sign corresponding to the 90° standard phase will be offset by +Δφ_i (e.g., 90°+Δφ_i), which is marked as "embedded bit = 0" in the figure;

[0162] When the bit of the embedded information fragment is "1", the sign corresponding to the 270° standard phase will be offset by -Δφ_i (e.g., 270°-Δφ_i), which is marked as "embedded bit = 1" in the figure.

[0163] (3) Characteristics of dynamic offset Δφ_i:

[0164] The value of Δφ_i ranges from 0 to π / 8 (approximately 0 to 22.5°), and is dynamically determined by the dynamic mapping rule R (positively correlated with the channel SNR). Since the offset is much smaller than the interval between adjacent standard phases (90°), it will not affect the normal demodulation of service data, but can achieve the covert transmission of fragment information.

[0165] Through this phase fine-tuning mechanism, control information fragments are "hidden" in the physical layer characteristics of business data, making it difficult for attackers to distinguish between normal phase fluctuations and embedded fragment information, thus significantly improving the frame structure's resistance to cracking.

[0166] Example 1

[0167] Low Earth Orbit (LEO) satellite communication scenario: orbital altitude 550km, data rate 100Mbps;

[0168] The data field length L = 8192 bytes (65536 bits), and the control information set C = 112 bits → N = 14 fragments;

[0169] Satellite status parameters P: θ = 51.23° (32-bit floating point), ephemeris timestamp T = 1620000000000ms (64-bit), channel SNR value S = 15dB (8-bit quantization value 0x3C), on-board device hardware fingerprint F = 0x123456789ABCDEF0 (64-bit);

[0170] Hash value H = SM3(0x4041F666||0x5F584680000||0x3C||0x123456789ABCDEF0) = 0xA1B2C3...(256bit);

[0171] Embedded positions Pos_i: Pos_0 = 0x00A3 (163), Pos_1 = 0x1F2E (7982)... (14 non-overlapping positions);

[0172] Embedding strength: K_0=0x80(128)→normalization coefficient 0.5, Δφ_0=0.5×(15 / 30)×π / 8=π / 32;

[0173] Transmission and parsing: The transmitter embeds the fragment information by shifting the QPSK symbol phase by ±π / 32 at position Pos_0; the receiver extracts the fragment information by phase detection and then reassembles the control information set C by LDPC decoding, with a parsing time of ≤50μs.

[0174] Example 2

[0175] High-orbit satellite communication scenario: orbital altitude 35786km, data rate 10Mbps;

[0176] The rule update cycle M = 20, and the channel SNR threshold ΔS = 3dB; when the channel SNR value S is detected to change abruptly from 20dB to 16dB (ΔS = 4dB), the dynamic mapping rule R is immediately updated.

[0177] The on-board device hardware fingerprint F uses the unique ID of the on-board CPU. The receiver can resist deception attacks by spoofing satellites by verifying the on-board device hardware fingerprint F.

[0178] Any content not described in detail in this specification belongs to the prior art in this technical field.

Claims

1. A satellite communication frame structure security enhancement method based on dynamic fragmentation embedding, characterized in that, Includes the following steps: S1, fragments the control information of the satellite communication frame and performs LDPC error correction coding operation; S2, The transmitting end collects satellite status parameters P in real time and generates dynamic mapping rules R through a hash function; S3, the encoded information fragments are embedded into the QPSK symbol phase of the data field according to the dynamic mapping rule R, forming an integrated frame and transmitting it. At the same time, the satellite state parameters P are sent to the receiving end through quantum key encryption. S4, the receiving end decrypts and obtains the satellite status parameter P, reproduces the dynamic mapping rule R, extracts information fragments from the integrated frame and reassembles them into a control information set C, and parses the service data; S5 updates the dynamic mapping rule R based on satellite orbit type and channel changes.

2. The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to claim 1, characterized in that, In step S1, the control information of the satellite communication frame is fragmented and LDPC error correction coding is performed. The specific steps include: S11, Extract the control information set C of the satellite communication frame; The control information set C includes a synchronization identifier, frame length, source / destination address, and checksum, with a total length of 112 bits. S12, split the control information set C into N information fragments; The rule for N is: N = ceil(total length / 8), that is, 112 bits are split into 14 fragments, the first 13 are 8 bits, the last one is 4 bits, and 4 redundant bits are added to make up 8 bits. S13, perform LDPC error correction coding operation on each information fragment, and output the encoded 16-bit information fragment.

3. The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to claim 1, characterized in that, In step S2, the transmitting end collects satellite status parameters P in real time and generates dynamic mapping rules R through a hash function. The specific steps include: S21, The transmitting end collects satellite status parameters P in real time; Satellite status parameters P include orbital angle θ, ephemeris timestamp T, channel SNR value S, and onboard equipment hardware fingerprint F; S22, calculate the hash value H of the satellite state parameter P using the national cryptographic SM3 hash function: H = SM3(θ||T||S||F) We obtain a 256-bit hash value H; S23, parse the dynamic mapping rule R from the hash value H of the satellite state parameter P; The dynamic mapping rule R includes the embedding positions Pos_i of N information fragments in the data domain, the embedding phase offset Δφ_i, and the embedding order, where: Embedding position Pos_i: obtained by parsing the first 14×16=224 bits of the hash value H, and satisfying 0≤Pos_i≤L-1, where L is the length of the data field, and all embedding positions Pos_i do not overlap; Embedding method: Take the last 32 bits of the hash value H, and each 8 bits corresponds to an embedding strength coefficient K_i. After normalization, the coefficients of 0-1 are obtained. Multiply them by the normalized value of the channel SNR to obtain the embedding phase offset Δφ_i. Embedding order: The order in which fragments are embedded is determined by the middle 14 bits of the hash value H.

4. The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to claim 3, characterized in that, In step S3, the encoded information fragments are embedded into the QPSK symbol phase of the data domain according to the dynamic mapping rule R to form an integrated frame and transmit it. At the same time, the satellite state parameters P are sent to the receiving end through quantum key encryption. The specific steps include: S31, Data field preprocessing; The business data is QPSK modulated to generate an I / Q symbol stream; S32, information fragment embedding; At the symbol position corresponding to the embedding position Pos_i, the encoded 16-bit information fragment is embedded through phase fine-tuning; Each bit corresponds to the ±Δφ_i offset of the symbol phase; S33, generate an integrated frame; Once the symbol stream is embedded, it is directly used as a transmission frame with a fixed frame length of L+14×16 bits. S33, transmits satellite status parameters P; The satellite state parameter P is sent to the receiving end via a quantum key encryption link; The encryption key is a pre-shared SM4 key between satellite and ground.

5. The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to claim 4, characterized in that, In step S4, the receiving end decrypts and obtains the satellite status parameter P, reproduces the dynamic mapping rule R, extracts information fragments from the integrated frame and reassembles them into a control information set C, and parses the service data. Specific steps include: S41, decrypt satellite status parameter P; The receiver obtains the encrypted satellite status parameter P through the QKD link, and after decryption, reproduces the hash value H and the dynamic mapping rule R. S42, Information Fragment Extraction; Phase detection is performed on the embedding position Pos_i of the received symbol stream, the phase offset Δφ_i is calculated, and the encoded 16-bit information fragments are restored. S43, Error Correction and Reorganization; LDPC decoding is performed on the 16-bit information fragment to obtain an 8-bit original information fragment, which is then spliced ​​together in the embedding order to form a 112-bit control information set C. S44, Data Analysis; The integrity of the frame is verified based on the synchronization identifier in the control information set C. The service data is extracted through the frame length and address information, and finally the correctness of the data is ensured by CRC32 check.

6. The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding according to claim 1, characterized in that, In S5, the dynamic mapping rule R is updated according to the satellite orbit type and channel changes, specifically as follows: The rule update cycle for low-Earth orbit (LEO) satellites is M=5, meaning that the dynamic mapping rule R is updated every 5 frames transmitted by the LEO satellite; the rule update cycle for high-Earth orbit (HEO) satellites is M=20, meaning that the dynamic mapping rule R is updated every 20 frames transmitted by the HEO satellite. When the channel SNR change ΔS > 3dB or the on-board device hardware fingerprint F verification fails, the dynamic mapping rule R is immediately updated to avoid security vulnerabilities caused by sudden changes in channel SNR or on-board device forgery.

7. A satellite communication frame structure security enhancement system based on dynamic fragmentation embedding, characterized in that, The satellite communication frame structure security enhancement method based on dynamic fragmentation embedding as described in any one of claims 1-6 includes a control information processing module, a satellite state awareness module, a dynamic rule engine, a physical layer embedding module, a quantum encrypted transmission module, a receiver parsing module, and a rule update controller, wherein: The control information processing module is used to implement control information fragmentation and LDPC encoding; The satellite status sensing module is used to collect satellite status parameters P in real time. The dynamic rule engine is used to generate dynamic mapping rules R through a hash function; The physical layer embedding module is used to embed the encoded information fragments into the QPSK symbol phase of the data field according to the dynamic mapping rule R, forming an integrated frame for transmission; The quantum encryption transmission module is used to send the satellite state parameter P to the receiving end using quantum key encryption. The receiving end parsing module is used to decrypt and obtain satellite status parameters P, reproduce dynamic mapping rules R, extract information fragments from the integrated frame and reassemble them into a control information set C, and parse service data. The rule update controller is used to update the dynamic mapping rule R according to satellite orbit type and channel changes.

8. The satellite communication frame structure security enhancement system based on dynamic fragmentation embedding according to claim 7, characterized in that, The control information processing module includes a fragmentation unit and an LDPC encoding unit; the fragmentation unit is used to perform fragmentation processing of control information in satellite communication frames; the LDPC encoding unit is used to perform LDPC error correction encoding.

9. The satellite communication frame structure security enhancement system based on dynamic fragmentation embedding according to claim 7, characterized in that, The satellite status awareness module includes an orbital angle sensor, a time synchronization unit, an SNR detector, and a hardware fingerprint extractor; the orbital angle sensor is used to collect the orbital angle θ; the time synchronization unit is used to collect the ephemeris timestamp T; the SNR detector is used to collect the channel SNR value S; and the hardware fingerprint extractor is used to collect the hardware fingerprint F of the on-board equipment.

10. The satellite communication frame structure security enhancement system based on dynamic fragmentation embedding according to claim 7, characterized in that, The physical layer embedding module includes a QPSK modulator and a phase fine-tuning unit; the QPSK modulator is used to generate a data symbol stream; the phase fine-tuning unit is used to embed the encoded information fragments into the QPSK symbol phase of the data domain according to the dynamic mapping rule R, forming an integrated frame and transmitting it.

11. The satellite communication frame structure security enhancement system based on dynamic fragmentation embedding according to claim 7, characterized in that, The receiving end parsing module includes a parameter decryption unit, a dynamic rule reproduction unit, an integrated frame receiving unit, a phase detection unit, an LDPC decoding unit, a control information reassembly unit, and a service data parsing unit; the parameter decryption unit is used to decrypt and obtain satellite status parameters P; the dynamic rule reproduction unit is used to reproduce hash values ​​H and dynamic mapping rules R; The integrated frame receiving unit is used to receive and store integrated frames; The phase detection unit is used to perform phase detection on the embedding position Pos_i of the received symbol stream, calculate the phase offset Δφ_i, and restore the encoded 16-bit information fragments. The LDPC decoding unit is used to perform LDPC decoding on 16-bit information fragments to obtain 8-bit original information fragments; the control information reassembly unit is used to splice them into a 112-bit control information set C according to the embedding order; and the business data parsing unit is used to implement business data parsing.