Security transmission method and system for low-orbit satellite video conference based on rolling key chain and ABE, electronic equipment and storage medium

By combining rolling key chains and ABE technology with multi-beam communication mode, the problems of low key management efficiency and insufficient security in low-Earth orbit satellite networks are solved, enabling efficient and secure video conferencing transmission that adapts to dynamic network environments.

CN121865035APending Publication Date: 2026-04-14CHENGDU SANLING RUITONG MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Traditional low-Earth orbit satellite encrypted video conferencing transmission methods suffer from low key management efficiency, making them difficult to adapt to highly dynamic networks, and static encryption is insufficient to meet low latency and security requirements.

Method used

By employing rolling key chain and attribute-based encryption (ABE) technology, dynamic session keys are generated through ground terminals, and the satellite network constructs the key chain and performs multicast encryption. Combined with multi-beam technology, efficient and secure video conferencing transmission is achieved.

Benefits of technology

It achieves efficient transmission in an adaptive low-Earth orbit satellite dynamic network environment, and features forward security and fine-grained access control to ensure the security and real-time performance of video conferencing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121865035A_ABST
    Figure CN121865035A_ABST
Patent Text Reader

Abstract

The invention discloses a low-orbit satellite video conference secure transmission method and system based on a rolling key chain and an ABE, electronic equipment and a storage medium, and belongs to the crossing field of satellite communication and information security, and the method comprises the following steps: S1, a ground terminal system carries out encryption and uplink transmission on a video stream; s2, processing uplink data by the satellite network relay and video service system; and S3, distributing the multicast encrypted data of the satellite network. The method improves the transmission efficiency and safety, and is especially suitable for a low-orbit satellite network scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the interdisciplinary field of satellite communication and information security, and more specifically, to a method, system, electronic device, and storage medium for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chains and ABE. Background Technology

[0002] Traditional low-Earth orbit satellite encrypted video conferencing transmission methods have the following problems: 1) Low key management efficiency: Centralized key distribution is prone to becoming a performance bottleneck and is difficult to adapt to the high dynamism of low-Earth orbit satellite networks; 2) Conflict between security and real-time performance: Static encryption is difficult to meet low latency requirements, and satellite links are vulnerable to eavesdropping attacks. Summary of the Invention

[0003] The purpose of this invention is to overcome the shortcomings of the prior art and provide a method, system, electronic device and storage medium for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE, which improves transmission efficiency and security, and is especially suitable for low-Earth orbit satellite network scenarios.

[0004] The objective of this invention is achieved through the following approach: A secure transmission method for low-Earth orbit satellite video conferencing based on rolling key chains and ABE, characterized by the following steps: S1: The ground terminal system encrypts and transmits the video stream upstream; S2: Satellite network relay and video service system processes uplink data; S3: Satellite network multicast encrypted data distribution.

[0005] Furthermore, in step S1, the ground terminal system encrypts and transmits the video stream upstream, specifically including the following sub-steps: Step S11: Terminal registration and initialization. The terminal registers with the video server via satellite link to obtain the initial attribute certificate and the Ellipse ECC key pair, including the initial key K0. The registration process ensures terminal identity authentication and attribute binding. Step S12: The terminal security module derives a temporary key Ki frame by frame based on K0 generated by ECC using a ratchet algorithm; the formula is: Ki = H(Ki-1⊕Noncei); where H is a hash function used to ensure that the key is irreversible; Ki is the temporary key for the i-th frame, and Noncei is a combination of frame number and timestamp; Step S13: The encryption module uses the Ki generated in step S12 to encrypt the real-time video stream using the AES-GCM algorithm; Step S14: Dynamic beam allocation and uplink transmission. The encrypted video stream is sent to the low-Earth orbit satellite via the uplink unicast link. The satellite network dynamically allocates bandwidth based on multi-beam technology. The uplink unicast occupies a narrow beam to establish a dedicated connection for the terminal. The encrypted data is transmitted through optimized uplink and connected to the satellite relay.

[0006] Further, in step S2, the satellite network relay and video service system processes uplink data, specifically including the following sub-steps: Step S21: Real-time forwarding. After receiving the uplink data, the low-orbit satellite performs real-time forwarding within the network to transmit the encrypted video stream to the ground video server. Step S22: Extract the latest key. The video server extracts the latest dynamic key Ki from each terminal from the received data. The server collects Ki in real time and constructs a dynamic key chain Chain = {K1, K2, ..., Kn}, where n is the number of terminals. After extracting the key, the server prepares to construct the ABE strategy. Step S23: Generate access policies. The key chain building module maps the Chain to an ABE access policy tree. Step S24: Synthesize the encrypted video stream. The CP-ABE encryption module encrypts the synthesized video data M according to the strategy generated in step S23, generating ciphertext that can only be decrypted by terminals whose attributes meet the strategy.

[0007] Furthermore, in step S23, each key Ki is associated with the following dynamic attributes: KeyID: A unique identifier for the key, where KeyID_i represents the ID of the i-th key; Timestamp: Key generation timestamp, Timestamp_i represents the timestamp of the i-th key; ValidityWindow: Key validity period. ValidityWindow_i represents the validity period of the i-th key, which is synchronized with the satellite beam switching cycle. The attribute set is defined as: Attr(Chain) = _{i=1}^n {KeyID_i, Timestamp_i,ValidityWindow_i}, where It represents the union of sets.

[0008] Furthermore, in step S23, the policy tree uses threshold logic gates to reconstruct it each time the satellite beam switches, retaining only the attributes within the valid window and removing expired keys; by binding the version number, the terminal verifies version matching during decryption to prevent replay attacks.

[0009] Furthermore, in step S3, the distribution of encrypted multicast data over the satellite network specifically includes the following sub-steps: S31: Multicast encrypted data. The video service system sends the synthesized encrypted video stream (CT) back to the low-Earth orbit satellite network for downlink distribution. After the server completes the processing, the data is returned to the satellite for distribution. S32: Multi-beam multicast distribution, low-Earth orbit satellites use multi-beam technology for distribution; downlink multicast uses wide beams and is distributed simultaneously to terminal groups that conform to the ABE access policy; authorized terminals verify whether their own attributes match the policy, and play the video after decryption using the attribute key.

[0010] An electronic device includes a processor and a memory, wherein the memory stores a computer program that, when loaded by the processor, executes the method described in any of the preceding methods.

[0011] A secure transmission system for low-Earth orbit satellite video conferencing based on rolling keychain and ABE, including the electronic equipment described above.

[0012] A computer-readable storage medium storing a computer program that, when loaded by a processor, executes the method described in any of the preceding claims.

[0013] The beneficial effects of this invention include: The core technical effect of this invention is to create a secure video conferencing transmission solution that can adapt to the dynamic network environment of low-Earth orbit satellites, has forward security, fine-grained access control, and can ensure efficient transmission. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 This is a system architecture diagram of an embodiment of the present invention; Figure 2 This is an encryption / decryption timing diagram (timing relationship between unicast uplink and multicast downlink) of an embodiment of the present invention. Detailed Implementation

[0016] All features disclosed in all embodiments of this specification, or steps in all methods or processes implied in the disclosure, may be combined and / or extended or replaced in any way, except for mutually exclusive features and / or steps.

[0017] This invention combines dynamic key management and attribute encryption technology to optimize communication efficiency and security in large-scale video conferencing scenarios. Specifically, it relates to a secure video conferencing transmission scheme based on low-Earth orbit (LEO) satellite networks, combining dynamic key management and attribute encryption technology to optimize communication efficiency and security in large-scale video conferencing scenarios. Specifically, the invention leverages the multi-beam, high-throughput, and low-latency characteristics of LEO satellite networks to propose a hybrid uplink unicast and downlink multicast communication mode. Terminals generate dynamic session keys using a ratchet rolling key derivation algorithm, implementing a "one key per message, one key per frame" encryption mechanism. The server combines the latest keys from each terminal into a key chain, which serves as the access structure for attribute-based encryption (ABE), dynamically encrypting downlink multicast video data.

[0018] More specifically, as a first aspect of the invention, in a preferred embodiment, such as Figure 1 and Figure 2 As shown, a secure transmission method for low-Earth orbit satellite video conferencing based on rolling key chains and ABE is provided, including the following steps: S1: The ground terminal system performs encryption and uplink transmission, specifically including the following sub-steps: Step S11: Terminal Registration and Initialization. The terminal registers with the video server via satellite link, obtaining an initial attribute certificate and an ECC (Elliptic Curve Cryptography) key pair, including generating an initial key K0 (K0 represents the initial key, based on the ECC algorithm), laying the foundation for subsequent dynamic key derivation. The registration process ensures terminal authentication and attribute binding, preparing for ABE (Attribute-Based Cryptography) access control. This step is the starting point of the process, ensuring the terminal legally joins the conference; subsequent steps rely on this initialization.

[0019] Step S12: Following the initialization in step S11, a dynamic key is immediately generated to provide the foundation for the encrypted video stream. Specifically, the terminal security module, based on K0 generated by ECC, derives a temporary key Ki frame-by-frame using a ratchet algorithm. The formula is: Ki = H(Ki-1⊕Noncei); where H is a hash function (such as SHA-256) to ensure the key is irreversible. Ki is the temporary key for the i-th frame, achieving "one key per frame". Noncei is a combination of the frame sequence number and the timestamp (Noncei represents a random number composed of the frame sequence number and the timestamp) to prevent replay attacks. Key derivation is performed every frame to ensure forward security.

[0020] Step S13: Encrypt the video stream. The encryption module uses the Ki generated in step S12 to encrypt the real-time video stream using the AES-GCM (Advanced Encryption Standard - Galois / Counter Mode) algorithm. AES-GCM provides efficient encryption and authentication, ensuring confidentiality and integrity. The dynamic key Ki is directly used for encryption, ensuring that each frame of data is independently secure.

[0021] Step S14: Dynamic beam allocation and uplink transmission. The encrypted video stream is sent to the low-Earth orbit satellite via an uplink unicast link. The satellite network dynamically allocates bandwidth based on multi-beam technology. Uplink unicast occupies a narrow beam, establishing a dedicated connection for the terminal and ensuring low latency. Encrypted data is transmitted via optimized uplink, connecting to satellite relay.

[0022] S2: Satellite network relay and video service system processing, specifically including the following sub-steps: Step S21: Real-time forwarding. After receiving the uplink data, the low-Earth orbit satellite performs real-time forwarding within the network, transmitting the encrypted video stream to the ground video server. The satellite acts as a relay, ensuring efficient data delivery to the server.

[0023] Step S22: Extract the latest key. The video server extracts the latest dynamic key Ki from each terminal from the received data. The server collects Ki in real time and constructs a dynamic key chain Chain = {K1, K2, ..., Kn} (Chain is the set of the latest keys for each terminal), where n is the number of terminals. After extracting the keys, the server prepares for constructing the ABE strategy.

[0024] Step S23: Generate access policies. The key chain building module maps the Chain to an ABE access policy tree, and each key Ki is associated with the following dynamic attributes: KeyID: A unique identifier for the key (KeyID_i represents the ID of the i-th key).

[0025] Timestamp: Key generation timestamp (Timestamp_i represents the timestamp of the i-th key).

[0026] ValidityWindow: Key validity period (ValidityWindow_i represents the validity period of the i-th key, which can be synchronized with the satellite beam switching cycle).

[0027] The attribute set is defined as: Attr(Chain) = _{i=1}^n {KeyID_i, Timestamp_i,ValidityWindow_i} (where (This represents the union of sets).

[0028] It should be noted that the policy tree uses a threshold gate. For example, "at least 3 latest valid keys are required for decryption" is represented as Policy = (k=3, {KeyID_1, KeyID_2, ..., KeyID_m}), where k=3 is the minimum number of keys required for decryption and m is the total number of currently valid keys.

[0029] It should be noted that the policy tree is reconstructed each time the satellite beam switches, retaining only the attributes within the valid window and removing expired keys.

[0030] It should be noted that the binding version number PolicyVersion = Hash(Timestamp || BeamID) (|| represents concatenation) is used to verify version matching during terminal decryption, which can prevent replay attacks.

[0031] The strategy based on the extracted key can ensure fine-grained access control to facilitate subsequent encryption synthesis.

[0032] Step S24: Synthesize the encrypted video stream. The CP-ABE (Ciphertext Policy Attribute Encryption) module encrypts the synthesized video data M according to the Policy(Chain) generated in step S23, generating ciphertext CT = Enc_ABE(M, Policy(Chain)). Only terminals whose attributes satisfy the policy can decrypt it. The policy is directly used for encryption, realizing secure multicast preparation.

[0033] S3: Satellite network multicast distribution process, specifically including the following sub-steps: Step S31: Multicast encrypted data. The video service system sends the synthesized encrypted video stream (CT) back to the low-Earth orbit satellite network, preparing for downlink distribution. After the server completes processing, the data is returned to the satellite for distribution.

[0034] Step S32: Multi-beam multicast distribution. Low-Earth orbit satellites utilize multi-beam technology. Downlink multicast uses a wide beam and is simultaneously distributed to terminal groups conforming to the ABE access policy. Authorized terminals verify that their attributes match the policy, decrypt using the attribute key, and then play the video. Downlink coverage is optimized to ensure efficient decryption by authorized terminals, completing the entire transmission loop.

[0035] Table 1 for Symbol Explanation

[0037] In other aspects, the present invention provides an electronic device including a processor and a memory, wherein the memory stores a computer program that, when loaded by the processor, executes the method described in any of the preceding claims.

[0038] In other aspects, the present invention provides a low-Earth orbit satellite video conferencing secure transmission system based on rolling key chains and ABE, including the electronic devices described above.

[0039] The units described in the embodiments of the present invention can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.

[0040] According to one aspect of the present invention, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the computer device to perform the methods provided in the various optional implementations described above.

[0041] In another aspect, embodiments of the present invention also provide a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the methods described in the above embodiments.

Claims

1. A method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chains and ABE, characterized in that, Includes the following steps: S1: The ground terminal system encrypts and transmits the video stream upstream; S2: Satellite network relay and video service system processes uplink data; S3: Satellite network multicast encrypted data distribution.

2. The method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE according to claim 1, characterized in that, In step S1, the ground terminal system encrypts and transmits the video stream upstream, specifically including the following sub-steps: Step S11: Terminal registration and initialization. The terminal registers with the video server via satellite link to obtain the initial attribute certificate and the Ellipse ECC key pair, including the initial key K0. The registration process ensures terminal identity authentication and attribute binding. Step S12: The terminal security module derives a temporary key Ki frame by frame based on K0 generated by ECC using a ratchet algorithm; the formula is: Ki = H(Ki-1⊕Noncei); where H is a hash function used to ensure that the key is irreversible; Ki is the temporary key for the i-th frame, and Noncei is a combination of frame number and timestamp; Step S13: The encryption module uses the Ki generated in step S12 to encrypt the real-time video stream using the AES-GCM algorithm; Step S14: Dynamic beam allocation and uplink transmission. The encrypted video stream is sent to the low-Earth orbit satellite via the uplink unicast link. The satellite network dynamically allocates bandwidth based on multi-beam technology. The uplink unicast occupies a narrow beam to establish a dedicated connection for the terminal. The encrypted data is transmitted through optimized uplink and connected to the satellite relay.

3. The method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE according to claim 1, characterized in that, In step S2, the satellite network relay and video service system processes uplink data, specifically including the following sub-steps: Step S21: Real-time forwarding. After receiving the uplink data, the low-orbit satellite performs real-time forwarding within the network to transmit the encrypted video stream to the ground video server. Step S22: Extract the latest key. The video server extracts the latest dynamic key Ki from each terminal from the received data. The server collects Ki in real time and constructs a dynamic key chain Chain = {K1, K2, ..., Kn}, where n is the number of terminals. After the server extracts the key, it prepares to build the ABE strategy; Step S23: Generate access policies. The key chain building module maps the Chain to an ABE access policy tree. Step S24: Synthesize the encrypted video stream. The CP-ABE encryption module encrypts the synthesized video data M according to the strategy generated in step S23, generating ciphertext that can only be decrypted by terminals whose attributes meet the strategy.

4. The method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE according to claim 3, characterized in that, In step S23, each key Ki is associated with the following dynamic attributes: KeyID: A unique identifier for the key, where KeyID_i represents the ID of the i-th key; Timestamp: Key generation timestamp, Timestamp_i represents the timestamp of the i-th key; ValidityWindow: Key validity period. ValidityWindow_i represents the validity period of the i-th key, which is synchronized with the satellite beam switching cycle. The attribute set is defined as: Attr(Chain) = _{i=1}^n {KeyID_i, Timestamp_i,ValidityWindow_i}, where It represents the union of sets.

5. The method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE according to claim 3, characterized in that, In step S23, the policy tree uses threshold logic gates to reconstruct it each time the satellite beam switches, retaining only the attributes within the valid window and removing expired keys; by binding the version number, the terminal verifies version matching during decryption to prevent replay attacks.

6. The method for secure transmission of low-Earth orbit satellite video conferencing based on rolling key chain and ABE according to claim 1, characterized in that, In step S3, the distribution of encrypted multicast data over the satellite network specifically includes the following sub-steps: S31: Multicast encrypted data. The video service system sends the synthesized encrypted video stream (CT) back to the low-Earth orbit satellite network for downlink distribution. After the server completes the processing, the data is returned to the satellite for distribution. S32: Multi-beam multicast distribution, low-Earth orbit satellites use multi-beam technology for distribution; downlink multicast uses wide beams and is distributed simultaneously to terminal groups that conform to the ABE access policy; authorized terminals verify whether their own attributes match the policy, and play the video after decryption using the attribute key.

7. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program that, when loaded by the processor, executes the method as described in any one of claims 1 to 6.

8. A low-Earth orbit satellite video conferencing secure transmission system based on rolling key chains and ABE, characterized in that, Includes the electronic device described in claim 7.

9. A computer-readable storage medium, characterized in that, A computer program is stored in a readable storage medium, which, when loaded by a processor, executes the method as described in any one of claims 1 to 6.