A method and system for distributed attack-resistant domain management and control for giant constellations
By constructing a distributed control domain architecture and a multivariate maximum entropy trust model, the problems of dynamic topology changes and anti-attack capabilities of giant heterogeneous satellite constellations were solved, achieving stable communication and dynamic management of cross-orbit resources, and improving the system's adaptability and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HARBIN INST OF TECH
- Filing Date
- 2026-03-31
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies are insufficient in terms of dynamic topology changes and anti-attack capabilities for giant heterogeneous satellite constellations, making it difficult to achieve stable communication and dynamic management of cross-orbit resources, and lacking the ability to adapt to heterogeneous constellations.
A distributed control domain architecture is constructed, and a multivariate maximum entropy trust model is introduced. Through fuzzy C clustering algorithm and distributed consensus algorithm, trust assessment of satellite nodes and identification and isolation of malicious nodes are realized, forming a distributed collaborative network across orbits and domains.
It achieves efficient collaborative management and anti-attack capabilities for multi-layered heterogeneous mega-constellations, enhances the system's robustness and flexibility, and enables the system to maintain stable operation in complex threat environments.
Smart Images

Figure CN122120772A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of satellite constellation management technology, and more specifically, to a distributed anti-attack domain management method and system for the Giants constellation. Background Technology
[0002] With the rapid development of commercial spaceflight, multi-layered heterogeneous mega-constellations composed of low Earth orbit (LEO), medium Earth orbit (MEO), and geostationary orbit (GEO) satellite clusters have become the core architecture of next-generation space information networks. These constellations integrate multi-level satellite resources for communication, navigation, and remote sensing to form a globally covering, functionally complementary, three-dimensional network, significantly improving the continuity of communication services, the accuracy of navigation and positioning, and the efficiency of remote sensing data acquisition. However, the massive satellite resources of these mega-constellations also bring unprecedented management challenges: satellites in different orbits differ significantly in terms of operational cycles, coverage areas, and communication latency. Achieving stable communication and dynamic management across orbital resources has become a key bottleneck restricting constellation performance.
[0003] In terms of security threats, the openness and heterogeneity of mega-constellations further amplify the risk of attack. Attackers can selectively interfere with cross-orbit communication links or take the opportunity to implant malware and Trojan viruses, turning satellites into malicious nodes that spread tampered and forged information, disrupting the normal operation of the mega-constellation control system. Currently, the traditional ground-based centralized control architecture has shown limitations in responding to the dynamic topology changes and massive amounts of real-time information of mega-constellations, including slow response times and insufficient anti-attack capabilities. To address these issues, several hierarchical distributed architectures for control nodes in mega-satellite constellations have been proposed.
[0004] For example, patent announcements CN112532296B and CN112532297B, entitled "A Method for Constructing a Large-Scale Satellite Network Based on Elliptical Satellite Coverage" and "A Method for Constructing a Large-Scale Satellite Network Based on Rectangular Satellite Coverage," respectively propose methods for deploying control domains based on elliptical and rectangular shapes, aiming to achieve full-coverage control of large-scale satellite constellations. However, these methods rely on the stability of the constellation system configuration and topology, lacking the ability to adapt to heterogeneous constellations and unforeseen circumstances, and are difficult to adapt to dynamic changes in the topology between constellations and the anti-attack requirements of the Giant Star constellation system.
[0005] For example, the authorization announcement number CN 113115313B, entitled "A Network Security Routing Method for LEO Satellite Networks Based on Node Trust," detects and isolates malicious nodes in LEO satellite networks by constructing direct trust models, indirect trust models, and aggregate trust models, thereby reducing the impact of malicious satellites on inter-satellite data transmission. However, this method only provides security protection for communication routing in LEO satellite networks with uniform orbit configurations, and does not consider the dynamic communication topology of multi-layered heterogeneous satellite constellations or the collaborative management of massive satellite resources, lacking support for the collaborative capabilities between heterogeneous satellite resources.
[0006] In summary, existing technologies still have significant shortcomings in areas such as the collaborative dynamic management of massive resources in the Giants constellation and the resistance to attacks from heterogeneous constellations. Therefore, there is an urgent need to develop a distributed dynamic management and control method for the Giants constellation that possesses the capability for collaborative management of heterogeneous satellite resources and the ability to resist attacks, in order to address the system security and reliability requirements under complex threat environments. Summary of the Invention
[0007] The technical problem to be solved by this invention:
[0008] In view of the above problems, this invention proposes a giant constellation anti-attack domain management system and method based on space-based distributed management nodes and a multivariate maximum entropy trust model, aiming to solve the problem of collaborative management and anti-attack elastic maintenance of multi-layered heterogeneous giant constellations in dynamic topology environments.
[0009] This invention achieves its objective through the following technical concept:
[0010] A distributed control domain architecture is constructed: with control node satellites as the core, combined with cluster head satellites and ordinary satellites within the domain, a distributed control domain structure is formed. This structure undertakes cross-orbit communication switching and distributed collaborative control functions, effectively addressing the collaborative control challenges brought about by differences in the operational cycles, communication topologies, and communication latency of multiple orbital satellites.
[0011] A multivariate maximum entropy trust model is introduced: based on the fuzzy C-clustering algorithm and the maximum entropy principle, a dynamic trust evaluation system is constructed to comprehensively quantify the trust level of distributed nodes. By identifying high-risk nodes in real time and implementing isolation measures, interference from malicious satellites to inter-satellite data transmission is significantly reduced, thereby improving system security.
[0012] Ultimately, this invention achieves efficient collaborative management and enhanced anti-attack capabilities for the multi-layered heterogeneous giant constellation, providing key technical support for the stable operation of the giant constellation in complex threat environments.
[0013] The technical solution adopted by the present invention to solve the above-mentioned technical problems is as follows:
[0014] A distributed, attack-resistant domain management system for the Giant constellation, suitable for mega-constellation systems composed of a large number of heterogeneous satellites.
[0015] The giant constellation comprises two main components: a control constellation and a mission constellation. The control constellation consists of multiple control satellites deployed in various orbits, providing full communication coverage of the mission constellation and establishing stable connections with mission satellites within appropriate ranges based on communication reachability. The control satellites play a core node role in the system, responsible for key functions such as cross-domain information scheduling, security control, and resource coordination. The mission constellation is a heterogeneous constellation composed of various types of satellites, including communication satellites, navigation satellites, and remote sensing satellites. These satellites work collaboratively to overcome the limitations of individual nodes and jointly complete diverse space information service tasks.
[0016] The aforementioned mission constellation exhibits clustering characteristics, meaning that due to factors such as payload functionality, spatial distribution, or ground mission requirements, mission satellite nodes spontaneously form multiple independent clusters, known as independent mission satellite clusters. Within each independent mission satellite cluster, mission satellites can interconnect via direct communication or relay methods.
[0017] Within the aforementioned independent mission satellite cluster, the mission satellite nodes are relatively close in terms of mission attributes and geographical location, exhibiting strong network connectivity. Furthermore, the mission satellite nodes can observe, monitor, and record each other's behavior. Through this distributed mutual trust assessment mechanism, and based on a multivariate maximum entropy trust model, the comprehensive trust index of each satellite node (such as data credibility, communication latency, and computing power) is quantitatively analyzed, thereby constructing an effective trust management mechanism.
[0018] Within an independent mission satellite cluster, an optimal cluster leader satellite is dynamically elected based on the overall trust value of each satellite node. This cluster leader satellite serves as the communication hub between the cluster and the control satellite nodes, responsible for task coordination, data aggregation, and security incident reporting within the cluster.
[0019] Furthermore, each control node can connect to multiple cluster leader satellites to achieve unified control over multiple independent mission satellite clusters. All independent mission satellite clusters connected by a single control node constitute a control domain. Communication between control domains is achieved through inter-satellite links between control nodes, forming a distributed collaborative network architecture that spans orbits and domains.
[0020] Based on the aforementioned distributed anti-attack domain management system for the Giants constellation, the following technical solutions can also be obtained based on the same inventive concept:
[0021] A distributed anti-attack domain management method for the Giants constellation specifically includes the following technical solutions:
[0022] I. Methods for dividing mission star clusters independently for mission star constellations:
[0023] Step 1: Calculate the adjacency matrix of the mission constellation based on the topology of communication links between mission satellites. Matrix elements This indicates whether a direct communication link exists between mission star node i and mission star node j. If it exists... ,otherwise ;
[0024] Step 2, with Indicates the first The and the first The distances between mission satellites are calculated, and the adjacency communication distance matrix of the mission satellites is determined. Matrix elements .
[0025] Step 3, based on the adjacency communication distance matrix Calculate the shortest communication distance matrix ,matrix It can measure whether there is direct or relay communication between nodes, and the shortest communication path that exists.
[0026] Step 4, based on the shortest communication distance matrix Calculate and obtain at least one independent mission star cluster. If there are two nodes within the cluster whose shortest communication distance exceeds a given threshold, then the independent mission star cluster needs to be split into two or more independent mission star clusters until there are no two nodes whose shortest communication distance exceeds the given threshold. Each independent mission star cluster contains at least one mission star node.
[0027] II. A Distributed Trust Evaluation Method for Mission Stars Based on a Multivariate Maximum Entropy Trust Model:
[0028] This invention designs a trust assessment mechanism for satellite nodes within an independent mission satellite constellation based on communication behavior, assuming a total of n satellites in the constellation. Trust levels continuously change with system operation and the generation of behavior records. Positive behaviors (e.g., successful data transmission) increase node trust, while negative behaviors (e.g., signal interruption, garbled information) decrease it. Furthermore, nodes with longer stable operating times within the current independent mission satellite constellation should also achieve higher trust levels. Specifically, the satellite trust assessment covers multiple key indicators, including data reliability, data transmission rate, communication stability, communication latency, attack risk, computing power, storage capacity, link resource configuration capabilities, and resource capabilities such as the ability to maintain control satellite links.
[0029] Step 1: Set Let be the confidence level of satellite i in the capabilities of satellite j, where Let be the confidence level of satellite i in the m-th capability of satellite j. .
[0030] Step 2: Using the satellite as the object to be evaluated, and the remaining n-1 satellites as the recommending entities. Taking satellite k as an example, construct a trust matrix for satellite k. ,in represent The transpose of . Definition The elements in .
[0031] Step 3: Introduce the fuzzy C-means clustering algorithm (FCM) to classify the multidimensional evaluation indicators, thereby highlighting the differences in importance of different attributes. Construct the membership matrix of satellite k. Matrix elements express The element represents the level of trust in the ability. The degree of membership also represents the level of trust in ability. The exact probability has constraints: That is, the sum of the membership degrees of each capability trust type is 1.
[0032] Step 4: Based on the trust matrix Define overall trust level As a comprehensive trust value for a satellite entity, the comprehensive trust level reflects the overall evaluation of the trust of all n-1 other satellites in capability i. Next, this invention defines trust bias. This represents the deviation between satellite j's trust rating of capability i and the average trust level. This indicates the difference between the membership matrix and the expected trust level caused by objective differences or misunderstandings among all satellites. .
[0033] Step 5: The goal is to find the optimal membership matrix that minimizes the overall trust bias. Minimize it, and the optimization objective function is obtained as follows:
[0034]
[0035] Step 6: This invention objectively quantifies the weights of trust levels for each capability through information entropy, thereby improving the robustness of trust assessment. It also minimizes subjective factors in trust evaluation through the maximum entropy clustering principle. Based on the definition of the membership matrix above, the matrix elements... It can also represent the level of trust in ability. The exact probability can therefore be defined. Information entropy is Therefore, the membership matrix The overall information entropy can be expressed as: To achieve the overall trust bias Minimum At the same time, optimize the overall information entropy It satisfies the maximum entropy clustering principle. The optimization objective is rewritten as: Among them, constants The aim is to eliminate complex constant terms and maintain a balance between trust bias and overall information entropy.
[0036] Step 7: Solve for the minimum value of the objective function. and ,definition This is the membership threshold; if the final result... If the data of satellite i has been tampered with, its evaluation results are unreliable, and some or all of the satellite's data should be isolated.
[0037] Step 8: The membership degree and trust bias can be calculated comprehensively based on the data isolation process. ,in The remaining number of trustworthy data sources after data isolation is used to obtain the quantitative result of the global recommendation trust assessment for satellite k: .
[0038] Step 9: Extend the calculation process from steps 2 to 9 to all n missions within the independent mission star cluster.
[0039] III. Preferred selection method for satellite clusters based on distributed consensus algorithm:
[0040] To achieve communication across isolated satellite clusters, communication relay is required via a control satellite. A suitable cluster head satellite should be selected within each independent isolated satellite cluster as the communication node between the control satellite and that isolated cluster. This invention provides a cluster head selection method based on the distributed consensus Raft algorithm, characterized by the following rules:
[0041] Rule 1, Trust Assessment and Node Isolation: In an independent mission star cluster, calculate the global recommendation trust assessment quantification results for all n mission stars. Furthermore, satellite nodes with membership levels below a preset threshold are identified as malicious or disabled nodes and isolated during subsequent election processes.
[0042] Rule 2, Node State Definition: Each mission satellite node is in one of three states at any given time: cluster leader satellite, ordinary satellite, or candidate satellite. The cluster leader satellite is the sole node responsible for communication between the cluster and the outside world. It is responsible for sending "incumbent broadcasts" to the cluster at regular intervals during its term to maintain its leadership position, suppress election behavior of other nodes, and synchronize the cluster's internal log state to ensure data consistency. Ordinary satellites passively respond to requests from the cluster leader or candidate nodes. Candidate satellites are nodes that temporarily initiate elections. During cluster initialization, all nodes default to the ordinary satellite state. When the cluster has no cluster leader satellite, an ordinary satellite can trigger the election process, switch to the candidate satellite state, and send voting requests to other nodes in the cluster.
[0043] Rule 3: Election Timeout Mechanism: Each node sets an election timeout attribute. If it does not receive an "incumbent broadcast" from the cluster head satellite within the timeout period, it will trigger an election for a new term.
[0044] Rule 4: Election Voting and Election Rules: Each node casts only one vote in favor during a single term; voters prioritize voting for candidates with higher term numbers; for candidates with the same term, voting rights are allocated on a "first-come, first-served" basis. A candidate satellite must receive more than half of the nodes' votes to be promoted to cluster leader satellite; the cluster leader satellite broadcasts an "incumbent broadcast" to the cluster, and the remaining nodes revert to ordinary satellite status.
[0045] Rule 5: Dynamic Node Addition and Cluster Expansion: When a new node is added to the cluster, only one node is allowed at a time. The addition of the next new node is only allowed after obtaining the consent of the majority of the original cluster members, in order to prevent majority splitting issues caused by network partitions or latency.
[0046] The present invention has the following beneficial technical effects:
[0047] This invention proposes a distributed, attack-resistant domain management method for giant constellations. By managing satellite nodes and cluster leader satellites within each independent mission satellite cluster through space-based distributed management, it effectively solves the challenges of collaborative management and attack-resistant elastic maintenance of multi-layered heterogeneous mega-constellations in dynamic topology environments. It also addresses the communication link establishment and collaborative management challenges of large-scale heterogeneous constellation satellite resources. Furthermore, this invention possesses adaptive identification and isolation capabilities for malicious nodes under complex threat environments such as communication link interference and attacks by malware and Trojan viruses on satellite nodes. It can dynamically maintain the mega-constellation system under conditions of satellite failure, communication topology changes, and new satellite launches, enhancing the robustness and flexibility of the entire constellation system. The distributed, attack-resistant domain management system for giant constellations described in this invention is applicable to mega-constellation systems composed of a large number of heterogeneous satellites. Attached Figure Description
[0048] The present invention can be better understood by referring to the description given below in conjunction with the accompanying drawings, which together with the following detailed description are incorporated in and form a part of this specification, and serve to further illustrate preferred embodiments of the invention and explain the principles and advantages of the invention.
[0049] Figure 1 This is an architecture diagram of a distributed anti-attack domain management system for the Giants constellation in this invention embodiment;
[0050] Figure 2 This is a flowchart of the distributed anti-attack domain management method for the Giants constellation in this embodiment of the invention;
[0051] Figure 3 This is a schematic diagram of the satellite cluster selection method based on the distributed consensus algorithm in this embodiment of the invention.
[0052] Figure 4 This is a simulation result diagram showing the membership degree calculation results and malicious node identification when satellite data is tampered with. Detailed Implementation
[0053] To enable those skilled in the art to better understand the present invention, the accompanying drawings will be described below. Figure 1-4 Exemplary embodiments or examples of the present invention are described herein. Obviously, the described embodiments or examples are merely a part of the embodiments or examples of the present invention, and not all of them. All other embodiments or examples obtained by those skilled in the art based on the embodiments or examples of the present invention without inventive effort should fall within the scope of protection of the present invention.
[0054] To achieve communication interconnection and collaborative management of giant heterogeneous satellite constellations, this invention proposes a specific implementation scheme for a distributed anti-attack domain management system for the Giant Squadron. This scheme constructs a multi-layered heterogeneous constellation architecture, combining trust assessment and distributed consensus algorithms to achieve dynamic collaboration and anti-attack management of cross-orbit resources.
[0055] like Figure 1 The architecture diagram of the distributed anti-attack domain management system for the Giants constellation is shown. The system consists of a management constellation and a mission constellation. The management constellation is deployed in geostationary orbit, and its communication range can fully cover the mission constellation. It establishes stable connections with reachable mission satellites and undertakes cross-domain information scheduling, security management, and resource coordination functions. The mission constellation consists of heterogeneous satellites for communication, navigation, and remote sensing, spontaneously forming multiple independent mission satellite clusters based on payload functions, spatial distribution, and other factors.
[0056] Within each cluster, mission satellite nodes, given strong network connectivity and geographical proximity, interconnect through direct connections or relays. A multivariate maximum entropy trust model is used to quantitatively analyze metrics such as data reliability, communication latency, and computing power. Within independent mission satellite clusters, such as... Figure 3 The diagram illustrates the principle of the cluster leader selection method for satellite clusters based on a distributed consensus algorithm. The optimal cluster leader satellite is generated through dynamic election using a distributed consensus algorithm. The cluster leader satellite will serve as the communication hub between the cluster and the control star nodes.
[0057] Furthermore, such as Figure 1 As shown, each control satellite node connects to multiple cluster head satellites, enabling unified control of multiple independent mission satellite clusters and forming a control domain covered by a single control satellite node. Control domains communicate across domains via inter-satellite links between control satellite nodes, constructing a distributed collaborative network that spans orbits and domains.
[0058] In typical operating scenarios, such as Figure 2 As shown, when the mission satellite constellation is initialized, nodes are clustered based on communication conditions and cluster leaders are elected. Control satellite nodes connect multiple cluster leaders via inter-satellite links to form a control domain. If events such as satellite failure, communication topology change, new satellite entering orbit, cluster leader expiration, or malicious nodes are detected, the system will trigger a new round of cluster leader election or isolation mechanisms. Through the above technical solution, this invention achieves efficient collaborative control and attack-resistant resilient maintenance of multi-layered heterogeneous constellations, providing technical support for the stable operation of the Giants constellation under complex threat environments.
[0059] Based on the aforementioned distributed anti-attack domain management system for the Giants constellation, the following specific embodiments can also be obtained based on the same inventive concept, such as... Figure 2 As shown, this embodiment presents a distributed anti-attack domain management method for the Giants constellation. The specific process is as follows:
[0060] S1. Obtain the adjacency matrix of the mission stars: Based on the topology of communication links between mission stars, calculate the adjacency matrix of the mission star constellation. Matrix elements This indicates whether a direct communication link exists between mission star node i and mission star node j. If it exists... ,otherwise N represents the total number of satellites in the mission constellation. Then proceed to S2.
[0061] S2. Calculate the link establishment index matrix based on the adjacency matrix: Definition Indicates the first The and the first Distance coefficient of each mission star For the first The and the first The position coordinates of each mission satellite in the geocentric inertial coordinate system are used to calculate the adjacency communication distance matrix of the mission satellites. Matrix elements According to the adjacency communication distance matrix Calculate the shortest communication distance matrix ,matrix It can measure whether direct or relay communication exists between nodes, and the shortest communication path that exists. Shortest communication distance matrix. The calculation process is as follows:
[0062] Step 1: Adjacency Communication Matrix Processing is required. Adjacency communication matrix. In the middle, if This indicates the existence of a [something] caused by go through arrive The communication link has a communication coefficient of . In order to find out the origin Arriving after passing through an intermediate node The minimum communication coefficient requires obtaining all corresponding Minimum value. Furthermore, continuously changing. , The value of can be used to calculate the minimum communication coefficient for all nodes passing through no more than one transfer point, which will affect the The algorithm is denoted as or , elements in Based on the above principles, conduct Second-rate The matrix obtained after the operation is defined as follows: , Describe all nodes traversed no more than The minimum communication coefficient for each switching point.
[0063] The second step is to Continuing If the operation yields: That is, after After this operation, no path with a smaller communication coefficient can be found. At this point, a link establishment index matrix is defined. This matrix measures whether communication exists between nodes and the minimum distance path that exists. Then proceed to S3.
[0064] S3. Obtain each independent mission star cluster from the link establishment index matrix: based on the shortest communication distance matrix. Calculate and obtain at least one independent mission satellite cluster. If there are two nodes within the cluster whose shortest communication distance exceeds a given threshold... If so, the independent mission satellite cluster needs to be broken down into two or more independent mission satellite clusters until there are no two nodes within it whose shortest communication distance exceeds a given threshold, and each independent mission satellite cluster contains at least one mission satellite node. Then proceed to S4.
[0065] S4. Each cluster operates as an independent unit, with satellites mutually calculating trust indicators: This invention designs a trust evaluation mechanism for satellite nodes within an independent mission satellite cluster based on communication behavior, assuming a total of n satellites within the cluster. Trust levels continuously change with system operation and the generation of behavior records. Positive behaviors (e.g., successful data transmission) increase node trust, while negative behaviors (e.g., signal interruption, garbled information) decrease it. Furthermore, nodes with longer stable operating times within the current independent mission satellite cluster should also acquire higher trust levels. Specifically, satellite trust evaluation covers multiple key indicators, including data reliability, data transmission rate, communication stability, communication latency, attack risk, computing power, storage capacity, link resource configuration capability, and control satellite link maintenance capability. The specific process for satellites mutually calculating trust indicators is as follows:
[0066] Step 1: Definition This indicates the resource capabilities possessed by satellite j. Let m represent the normalized m-th capability possessed by satellite j as assessed by satellite i. Where:
[0067] Data credibility: ,in The accuracy rate of data within the time window. This represents the data error rate within the time window. The percentage of uncertain data within the time window. , and This is a penalty coefficient used to assess the negative impact of data error rate and the proportion of uncertain data on trust level. The greater the negative impact on trust level, the lower the risk of data loss. and The larger the value, the better.
[0068] Data transfer rate: ,in The largest communication bandwidth in the entire network. This represents the highest available throughput that can be achieved through testing within the current time window.
[0069] Communication stability: ,in This represents the number of communication interruptions within the current time window. The communication interruption time within the current time window. The penalty coefficient for the number of interruptions. The interruption penalty coefficient is the constant factor. .
[0070] Communication delay: ,in The average delay within the time window. The maximum acceptable latency threshold for the system (preset value).
[0071] Risk of attack: ,in The time of the attack within the current time window. for The average intensity of attacks received over a given time period. The attack penalty coefficient. .
[0072] Computational ability: ,in This represents the remaining available computing power within the current time window. This represents the ideal maximum computing power.
[0073] Storage capacity: ,in The remaining available storage capacity within the current time window. This represents the ideal maximum storage capacity.
[0074] Link resource allocation capability: In large-scale star clusters, the node degree of individual nodes is generally large, and the entire system exhibits an uneven trend. Selecting a cluster head with either a large or small node degree is unreasonable; a large node degree leads to network congestion, while a small node degree wastes communication resources. Therefore, the concept of adaptive node degree is introduced. ,in The node degree of satellite k to be evaluated within the current time window. This represents the sum of the node degrees of all satellites.
[0075] Controlling starlink maintenance capabilities: ,in The maximum time a communication link can be maintained with a single control satellite. The minimum acceptable duration of the control domain for the system.
[0076] The second step is to This represents the minimum threshold of resource capabilities required by satellite i. This represents the minimum normalized requirement of the m-th capability that satellite i needs to meet. If the requirement is less than this threshold, it means that the device does not have the capability to complete the corresponding service.
[0077] The third step is to This represents the resource capacity overflow threshold corresponding to the services required by satellite i. This represents the overflow threshold of the normalized m-th capability of satellite i. A value greater than this threshold indicates that the capability possessed by the satellite is fully sufficient to complete the services required by satellite i, and that increasing the capability level will not produce more beneficial effects on the execution of services.
[0078] Fourth step, set Let be the confidence level of satellite i in the capabilities of satellite j, where Let be the confidence level of satellite i in the m-th capability of satellite j, where Taking satellite k as the evaluated object as an example, the remaining n-1 satellites are the recommending entities, and a trust matrix is constructed for satellite k. ,in represent The transpose of , defining each element therein. Then proceed to S5.
[0079] S5. After receiving the evaluation indicators, the control satellite (ground station) performs a comprehensive evaluation of trust levels using multivariate maximum entropy fuzzy C-clustering: The scientific quantification of trust relationships is the foundation for accurately assessing trust levels. For trust indicators that are highly subjective and difficult to quantify directly, clustering analysis methods from fuzzy mathematics theory can be used to classify and evaluate data. Specifically:
[0080] Step 1: Introduce the Fuzzy C-means Clustering (FCM) algorithm to classify multidimensional evaluation indicators, thereby highlighting the differences in importance of different attributes. Based on the basic principles of fuzzy set theory, construct the membership matrix of satellite k. Matrix elements express The element represents the level of trust in the ability. The degree of membership also represents the level of trust in ability. The exact probability has constraints: The sum of the membership degrees of each capability trust type is 1.
[0081] Step 2: Based on the trust matrix Define overall trust level As a comprehensive trust value for satellite entities, the comprehensive trust level reflects the overall evaluation of the trust of all n-1 other satellites in capability i. Next, this invention defines trust bias. This represents the deviation between satellite j's trust rating of capability i and the average trust level.
[0082] Step 3: Define the trust bias This indicates the difference between the membership matrix and the expected trust level caused by objective differences or misunderstandings among all satellites. The goal of this invention is to find the optimal membership matrix such that the overall trust bias is minimized. Minimize it, and the optimization objective function is obtained as follows:
[0083] Step 4: This invention objectively quantifies the weights of trust levels for each capability through information entropy, thereby improving the robustness of trust assessment. It also minimizes subjective factors in trust evaluation through the maximum entropy clustering principle. Based on the definition of the membership matrix above, the matrix elements... It can also represent the level of trust in ability. The exact probability can therefore be defined. Information entropy is Therefore, the membership matrix The overall information entropy can be expressed as: To achieve the overall trust bias... Minimum At the same time, optimize the overall information entropy It satisfies the maximum entropy clustering principle. The optimization objective is rewritten as: Among them, constants The purpose is to eliminate complex constant terms and maintain a balance between trust bias and overall information entropy. For capabilities with low uncertainty, such as storage capacity, the evaluation results of satellite k by each satellite should be nearly consistent. Therefore, if a sudden change occurs in the data of a certain satellite, there is a very high probability that the data is unreliable. A smaller value should be chosen to minimize the overall confidence bias. The influence of sudden changes in data is weighted more heavily, excluding the impact of such data. For capabilities with high uncertainty, such as communication delay, the evaluation results of each satellite on satellite k are affected by the communication conditions and hop count of inter-satellite links, resulting in significant differences and dispersed data. Therefore, it is impossible to measure data reliability based on data mutations from a single satellite. In such cases, data fusion using the maximum entropy method, which does not consider subjective factors, should be preferred. A larger value should be selected.
[0084] Step 7: Use the Lagrange multiplier method to define the constraints. Introducing Lagrange multipliers The optimization objective is transformed into:
[0085] For the objective function Solve this problem, let ,have , Right now For the objective function Solve this problem, let ,have After iterative solution, the initial value for another iteration is... until the membership degree is satisfied. or The algorithm terminates. Then proceed to S6.
[0086] S6. Identify satellites with excessively low membership: Determine whether the final result meets the requirements based on the obtained membership degrees. in This is the membership threshold. If the threshold is met, proceed to S7; otherwise, proceed to S8.
[0087] S7. Control satellite (ground station) isolation of satellites with low affiliation: It can be determined that the data of satellite i has been tampered with, and its evaluation results are unreliable. Some or all of the data of this satellite should be isolated. Then proceed to S8.
[0088] S8. The control satellite (ground station) selects a suitable cluster leader satellite as the communication relay node based on voting:
[0089] Step 1: The calculated values can be derived by combining the obtained membership degree and confidence bias. ,in This represents the remaining trustworthy data after data isolation. Finally, the quantitative result of the global recommendation trust assessment for satellite k is obtained: .
[0090] Step 2: After calculating all indicators, perform satellite cluster selection based on a distributed consensus algorithm. This step is characterized by the following rules:
[0091] Rule 1, Trust Assessment and Node Isolation: In an independent mission star cluster, calculate the global recommendation trust assessment quantification results for all n mission stars. Furthermore, satellite nodes with membership levels below a preset threshold are identified as malicious or disabled nodes and isolated during subsequent election processes.
[0092] Rule 2, Node State Definition: Each mission satellite node is in one of three states at any given time: cluster leader satellite, ordinary satellite, or candidate satellite. The cluster leader satellite is the sole node responsible for communication between the cluster and the outside world. It is responsible for sending "incumbent broadcasts" to the cluster at regular intervals during its term to maintain its leadership position, suppress election behavior of other nodes, and synchronize the cluster's internal log state to ensure data consistency. Ordinary satellites passively respond to requests from the cluster leader or candidate nodes. Candidate satellites are nodes that temporarily initiate elections. During cluster initialization, all nodes default to the ordinary satellite state. When the cluster has no cluster leader satellite, an ordinary satellite can trigger the election process, switch to the candidate satellite state, and send voting requests to other nodes in the cluster.
[0093] Rule 3: Election Timeout Mechanism: Each node sets an election timeout attribute. If it does not receive an "incumbent broadcast" from the cluster head satellite within the timeout period, it will trigger an election for a new term.
[0094] Rule 4: Election Voting and Election Rules: Each node casts only one vote in favor during a single term; voters prioritize voting for candidates with higher term numbers; for candidates with the same term, voting rights are allocated on a "first-come, first-served" basis. A candidate satellite must receive more than half of the nodes' votes to be promoted to cluster leader satellite; the cluster leader satellite broadcasts an "incumbent broadcast" to the cluster, and the remaining nodes revert to ordinary satellite status.
[0095] Rule 5: Dynamic Node Addition and Cluster Expansion: When a new node is added to the cluster, only one node is allowed at a time. The addition of the next new node is only allowed after obtaining the consent of the majority of the original cluster members, in order to prevent majority splitting issues caused by network partitions or latency.
[0096] S9. Determine whether events such as satellite malfunction, communication topology change, or new satellite entering orbit have occurred. If so, proceed to S10; otherwise, proceed to S11.
[0097] S10. Update the adjacency matrix of the mission stars: Update the adjacency matrix of the mission star constellation based on the topology of communication links between mission stars. Matrix elements This indicates whether a direct communication link exists between mission star node i and mission star node j. If it exists... ,otherwise N represents the total number of satellites in the mission constellation. Then proceed to S2.
[0098] S11. After the term of each cluster leader in the domain ends or a new term of candidate satellite emerges, proceed to S12.
[0099] S12. Each cluster's internal satellites calculate the trust index of the currently nominated satellites, using the same calculation method as in S4. After completion, proceed to S13.
[0100] S13. After receiving the evaluation indicators, the control satellite performs a comprehensive evaluation of the trust level using multivariate maximum entropy fuzzy C-clustering, calculated using the same method as in S5. After completion, proceed to S16.
[0101] Verified, as shown in the attached document. Figure 4 As shown, the simulation experiment is set up as follows: 200 satellites are selected to form an independent mission satellite cluster. From these 200 satellites, 20 are randomly selected as malicious node satellites whose data is tampered with. The tampering process is reflected in the malicious node satellites' calculation of the capability trust index of other satellites exhibiting a random deviation of ±100%. A membership threshold is set. The simulation results of the calculated membership degree distribution of each satellite are shown in the figure. The horizontal axis represents the satellite number, and the vertical axis represents the calculated membership degree. The values below the membership degree threshold are... A total of 20 satellites were identified, and verification showed that they completely corresponded to 20 randomly generated malicious satellites, indicating that malicious node satellites could be effectively identified, thus proving the technical effectiveness and practicality of the present invention. The method proposed in this invention solves the technical problem it addresses. Simulation experiments and practical applications have verified the claimed technical effectiveness and practicality of the method.
[0102] The algorithm (method) proposed in this invention is the underlying technical core of this invention, and various products can be derived based on the algorithm.
[0103] Based on the algorithm (method) proposed in this invention, a distributed anti-attack domain management system for the Giants constellation is developed using a programming language. This system has program modules corresponding to the steps of the aforementioned technical solution, and executes the steps of the aforementioned distributed anti-attack domain management method for the Giants constellation during runtime. The developed system (software) computer program is stored on a computer-readable storage medium, and the computer program is configured to implement the steps of the aforementioned distributed anti-attack domain management method for the Giants constellation when called by a processor. In other words, this invention is materialized on a carrier, becoming a computer program product.
[0104] A distributed anti-attack domain management device for the Giants constellation, the device comprising at least one processor and a memory communicatively connected to the at least one processor, wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one distributed anti-attack domain management method for the Giants constellation to achieve drive control of a nonlinear system.
[0105] Various implementations of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, application-specific integrated circuits (ASICs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0106] The computational programs (also referred to as programs, software, software applications, or code) of this invention include machine instructions of a programmable processor and can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device PLD) for providing machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0107] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this application can be achieved, they are all within the protection scope of this invention.
Claims
1. A distributed anti-attack domain management system for the Giants constellation, characterized in that, The system includes: Construct a distributed control domain architecture: With the control node satellite as the core, combined with the cluster head satellite and ordinary satellites in the domain, a distributed control domain structure is formed; this structure is used for cross-orbit communication transfer and distributed collaborative control to cope with the differences in operating cycles, communication topologies and communication latency of multi-orbit satellites; A multivariate maximum entropy trust model is introduced: Based on the fuzzy C-clustering algorithm and the maximum entropy principle, a dynamic trust evaluation system is constructed to comprehensively quantify the trust level of distributed nodes; high-risk nodes are identified in real time and isolation measures are implemented to reduce the interference of malicious satellites on inter-satellite data transmission; and efficient collaborative management and enhanced anti-attack capabilities of the multi-layered heterogeneous giant constellation are achieved.
2. The distributed anti-attack domain management system for the Giants constellation according to claim 1, characterized in that, The Giants constellation comprises two main components: a control constellation and a mission constellation. The control constellation consists of multiple control satellites deployed in multiple orbits, whose communication range can fully cover the mission constellation and establish stable connections with mission satellites within an appropriate range based on communication reachability. The control satellites play a core node role in the system, responsible for cross-domain information scheduling, security control, and resource coordination. The mission constellation includes communication satellites, navigation satellites, and remote sensing satellites. These satellites work collaboratively to overcome the limitations of individual nodes and jointly complete diverse space information service tasks. In the aforementioned mission constellation, mission star nodes will spontaneously form multiple independent clusters, called independent mission star clusters; within each independent mission star cluster, mission stars can interconnect through direct communication or relay methods. Within the aforementioned independent mission satellite cluster, the mission satellite nodes are close in terms of mission attributes and geographical location, and have strong network connectivity. Simultaneously, the mission satellite nodes can observe, monitor, and record each other's behavior. Through this distributed mutual trust assessment mechanism, a multivariate maximum entropy trust model is used to quantitatively analyze the comprehensive trust index of each satellite node, thus constructing an effective trust management mechanism. The comprehensive trust index includes data transmission rate, communication stability, attack risk, storage capacity, link resource configuration capability, and control satellite link maintenance capability. Within an independent mission satellite cluster, an optimal cluster leader satellite is dynamically elected based on the comprehensive trust value of each satellite node. This cluster leader satellite serves as the communication hub between the cluster and the control satellite nodes, and is responsible for mission coordination, data aggregation, and security incident reporting within the cluster.
3. A distributed anti-attack domain management system for the Giants constellation according to claim 2, characterized in that, Each control star node can connect to multiple cluster head satellites to achieve unified control of multiple independent mission star clusters; all independent mission star clusters connected by a single control star node constitute a control domain; and the control domains communicate with each other through inter-satellite links of the control star nodes, forming a distributed collaborative network architecture that spans orbits and domains.
4. A distributed anti-attack domain management method for the Giants constellation, characterized in that, The implementation process of the method is as follows: I. Independent Mission Star Cluster Division for Mission Star Constellations: Step 1: Calculate the adjacency matrix of the mission constellation based on the topology of communication links between mission satellites. Matrix elements This indicates whether a direct communication link exists between mission star node i and mission star node j. If it exists... ,otherwise ; Step 2, with Indicates the first The and the first The distances between mission satellites are calculated, and the adjacency communication distance matrix of the mission satellites is determined. Matrix elements ; Step 3: Based on the adjacency communication distance matrix Calculate the shortest communication distance matrix ,matrix Used to measure whether there is direct or relay communication between nodes, and the shortest communication path that exists; Step 4: Based on the shortest communication distance matrix Calculate and obtain at least one independent mission star cluster. If there are two nodes in the cluster whose shortest communication distance exceeds a given threshold, the independent mission star cluster needs to be split into two or more independent mission star clusters until there are no two nodes whose shortest communication distance exceeds the given threshold. Each independent mission star cluster contains at least one mission star node. II. Distributed Trust Evaluation Process for Mission Stars Based on a Multivariate Maximum Entropy Trust Model: A trust assessment mechanism for satellite nodes within an independent mission satellite constellation is designed based on communication behavior. The constellation contains n satellites. Trust levels change continuously with system operation and the generation of behavior records; positive behavior increases node trust, while negative behavior decreases it. Nodes with longer stable operating times within the constellation should also achieve higher trust levels. Satellite trust assessment indicators include data reliability, data transmission rate, communication stability, communication latency, attack risk, computing power, storage capacity, link resource configuration capability, and control satellite link maintenance capability. III. Cluster Selection Process for Satellite Clusters Based on Distributed Consensus Algorithm: To achieve communication across isolated satellite clusters, communication relay is required through the control satellite. Appropriate cluster head satellites should be selected within each independent isolated satellite cluster as communication nodes between the control satellite and the isolated satellite cluster. This can be achieved using a cluster head selection method based on the distributed consensus Raft algorithm.
5. A distributed anti-attack domain management method for the Giants constellation according to claim 4, characterized in that, The mission-star distributed trust evaluation process based on the multivariate maximum entropy trust model is as follows: Step 1, set Let be the confidence level of satellite i in the capabilities of satellite j, where Let be the confidence level of satellite i in the m-th capability of satellite j. ; Step 2: Using the satellite as the object to be evaluated and the remaining n-1 satellites as recommending entities, construct a trust matrix for satellite k. ,in represent Transpose, definition The elements in ; Step 3: Introduce the fuzzy C-means clustering algorithm (FCM) to classify the multidimensional evaluation indicators and construct the membership matrix of satellite k. Matrix elements express The element represents the level of trust in the ability. The degree of membership also represents the level of trust in ability. The exact probability has constraints: That is, the sum of the membership degrees of each capability trust type is 1; Step 4: Based on the trust matrix Define overall trust level As a comprehensive trust value for satellite entities, the comprehensive trust level can reflect the comprehensive evaluation of the trust of all n-1 other satellites in capability i. Define trust bias This represents the deviation between satellite j's trust rating of capability i and the average trust level. This indicates the difference between the membership matrix and the expected trust level caused by objective differences or misunderstandings among all satellites. ; Step 5: The objective is to find the optimal membership matrix, such that the overall trust bias is... Minimize it, and the optimization objective function is obtained as follows: Step 6: Objectively quantify the weight of each capability's trust level through information entropy to improve the robustness of trust assessment, and minimize the subjective factors in trust value evaluation through the maximum entropy clustering principle. Based on the definition of the membership matrix above, the matrix elements... It can represent the level of trust in ability. The exact probability can therefore be defined. Information entropy is Therefore, the membership matrix The overall information entropy can be expressed as: In order to achieve the overall trust bias Minimum At the same time, optimize the overall information entropy It satisfies the maximum entropy clustering principle. The optimization objective is rewritten as: Among them, constants The purpose is to eliminate complex constant terms and maintain a balance between trust bias and overall information entropy; Step 7: Solve for the minimum value of the objective function. and ,definition This is the membership threshold; if the final result... If the data of satellite i has been tampered with, its evaluation results are unreliable, and some or all of the satellite's data should be isolated. Step 8: Calculate the membership degree and trust bias based on the data after data isolation processing. ,in The remaining number of trustworthy data sources after data isolation is used to obtain the quantitative result of the global recommendation trust assessment for satellite k: ; Step 9: Extend the calculation process from steps 2 to 9 to all n missions within the independent mission star cluster.
6. The distributed anti-attack domain management method for the Giants constellation according to claim 5, characterized in that, The cluster first selection process based on the distributed consensus Raft algorithm is as follows: Step 1, Trust Assessment and Node Isolation: In an independent mission satellite cluster, calculate the global recommendation trust assessment quantification results for all n mission satellites. ; Furthermore, satellite nodes with membership levels below a preset threshold are identified as malicious or disabled nodes and isolated during subsequent election processes. Step 2, Node State Definition: Each mission satellite node is in one of three states at any given time: cluster leader satellite, ordinary satellite, or candidate satellite. The cluster leader satellite is the only node responsible for communication between the cluster and the outside world, and is responsible for sending "incumbent broadcasts" to the cluster at certain time intervals during its term to maintain its leadership position, suppress the election behavior of other nodes, and synchronize the internal log state of the cluster to ensure data consistency. Ordinary satellites passively respond to requests from the cluster leader or candidate nodes. Candidate satellites are nodes that temporarily initiate elections. During cluster initialization, all nodes default to the ordinary satellite state. When there is no cluster leader satellite, an ordinary satellite can trigger the election process, switch to the candidate satellite state, and send voting requests to other nodes in the cluster. Step 3: Election Timeout Mechanism: Each node sets an election timeout attribute. If it does not receive an "incumbent broadcast" from the cluster head satellite within the timeout period, it triggers an election for a new term. Step 4: Election Voting and Election Rules: Each node casts only one vote in favor during a single term; voters give priority to voting for candidate nodes with higher term numbers; for candidate nodes with the same term, voting rights are allocated on a "first-come, first-served" basis; a candidate satellite must obtain more than half of the nodes' votes to be promoted to cluster leader satellite; the cluster leader satellite broadcasts an "incumbent broadcast" to the cluster, and the remaining nodes revert to ordinary satellite status; Step 5: Dynamic Node Addition and Cluster Expansion: When a new node is added to the cluster, only one node is allowed at a time. The addition of the next new node is only allowed after obtaining the consent of the majority of members of the original cluster, in order to prevent the majority from splitting due to network partitions or latency.
7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program configured to implement, when invoked by a processor, the steps of the distributed anti-attack domain management method for the Giants constellation as described in any one of claims 4-6.