Satellite on-orbit security anomaly identification method for far offshore wind farm
By introducing XOR filters and a simple privacy collection transfer protocol into the satellite network, the problem of difficult security of satellite in orbit data processing is solved, especially in the long-sea wind farm scenarios, efficient and secure satellite collaborative data processing is achieved.
Patent Information
- Application Number
- PCT/CN2023/135747
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-20
- Filing Date
- 2023-12-01
- Publication Date
- 2025-05-30
AI Technical Summary
Existing satellite network security technologies cannot effectively protect the security of satellite in orbit data processing, especially in the long-sea wind farm scenarios, satellite resources are limited, existing privacy collection transaction protocols are complex and computing and communication overheads are large, making it difficult to apply to this scenario.
A satellite in-orbit safety abnormality identification method for far-sea wind farms is adopted, and the XOR filter and a concise privacy collection interception protocol are used to realize the security identification and processing of satellite in-orbit data through system initialization, abnormal data organization and abnormal data interception stage.
On the premise of protecting the confidentiality of data of far-sea wind farms, satellite in-orbit security abnormal data identification is realized, reducing calculation overhead and communication overhead, and ensuring the security and confidentiality of data.
Smart Images

Figure CN2023135747_30052025_PF_FP_ABST
Abstract
Description
A satellite on-orbit safety anomaly identification method for offshore wind farms Technical Field
[0001] The present invention relates to satellite communication data security technology, and in particular to a method for identifying satellite on-orbit safety anomalies. Background Art
[0002] As the application scope of satellite communication networks continues to expand, demand for satellite communications is also increasing. Satellite internet is receiving unprecedented attention. With the launch of thousands of low-cost satellites into space, satellite communication security is facing greater challenges. The excessive number of inexpensive satellites makes it easier for hackers to conduct intrusion experiments. Once a hacker group completes an intrusion operation on a single satellite, it becomes easy to intrude on a large number of satellites. Hackers can arbitrarily control satellites and even deny them service. They can also cause damage to social infrastructure such as power grids and water supply systems through signal interference and spoofing. Currently, research on satellite network security is still in its infancy. Research on the application of cryptographic protocols in satellite networks focuses on three aspects: secure transmission protocols for satellite communication networks, secure routing algorithms in satellite networks, and secure mobility management mechanisms in satellite networks.
[0003] Satellite communication network transmission protocol. Satellite communication network transmission protocol mainly relies on the design of key distribution and key management framework to achieve confidentiality, integrity and availability on the transmission link, ensuring that the transmitted data is not eavesdropped, tampered with or destroyed during the transmission process.
[0004] Secure routing algorithms in satellite networks. To ensure routing security, cryptographic techniques are used to authenticate and verify information integrity. Authenticity, confidentiality, and non-repudiation are essential for building and maintaining secure routing.
[0005] Secure mobility management mechanism in satellite networks. The secure mobility management process includes secure handover and secure location management, and its security requirements involve mutual authentication, key establishment, and forward and backward key separation.
[0006] Low Earth Orbit (LEO) satellites have become a hot topic for researchers both domestically and internationally. They offer a new communication solution for areas beyond the reach of terrestrial networks. LEO satellites' on-orbit computing and storage resources can provide real-time monitoring and observation services to remote regions. By connecting to ground stations, monitoring data can be transmitted in real time and processed and analyzed on-orbit. This data also requires protection. Existing satellite network security technologies based on cryptographic protocols focus on protecting satellite communications, while research has failed to identify technologies specifically designed to protect on-orbit data processing. Furthermore, existing satellite network protection technologies primarily focus on protecting the authenticity and confidentiality of satellite-to-ground and inter-satellite links, while lacking research on security technologies for satellite collaborative computing. Consequently, existing technical solutions fail to guarantee the security of satellite on-orbit data and the security of satellite collaborative computing. Furthermore, existing privacy set intersection protocols are complex and require multiple rounds of interaction, resulting in high computational and communication overhead, making them unsuitable for situations where satellite resources are limited.
[0007] Offshore wind farms are typically located more than 10 kilometers from the coast. Operators' signal coverage is limited, making communication between land and sea difficult. Traditional management methods, such as patrol inspections, require significant crew manpower and expensive vessel rentals, and the resulting data lacks continuity and real-time availability. Therefore, to meet the diverse needs of offshore resource development, remote managers are relying on satellite communications to monitor remote sites in areas beyond the reach of terrestrial communication networks, such as offshore wind farms. LEO satellites have become a hot topic for researchers both domestically and internationally, offering new solutions for communication in areas beyond the reach of terrestrial communication networks, such as offshore wind farms. In a LEO satellite constellation, each satellite can provide communications to terminals within its coverage area. If the target is outside of coverage, inter-satellite links can be used for cross-domain communication. Satellite edge computing systems are on-orbit platforms that enable shared remote observation and monitoring. They can recognize and process images and data on satellites, returning only critical information or alarms, rather than all observation results. Since LEO satellites are shared in-orbit platforms for the remote monitoring industry, offshore wind farms typically consist of numerous wind turbines and corresponding sensors. Protecting the security of this sensor data is crucial. This data is commercial and related to energy security. Hackers or attackers could analyze the data, identify weaknesses in key components, and physically damage the wind farm's infrastructure. Therefore, data transmitted to and processed on satellites must be protected. To ensure the reliability and security of data transmission and processing in offshore wind farms, guarantee stable operations, and promote the development and utilization of clean energy, security threats posed by satellite edge computing must be addressed. As mentioned earlier, existing satellite network protection technologies primarily protect satellite network communication links, focusing on the authenticity and confidentiality of satellite-to-ground and inter-satellite links. Various authentication and key establishment protocols are used to establish mutual trust between entities in the satellite network. However, research on data security protection for satellite collaborative computing is relatively limited. Furthermore, cryptographically based satellite network security technologies primarily focus on protecting satellite communication processes, focusing on key distribution and management in satellite systems, routing security, and satellite-to-ground and secure satellite handoffs. However, research on protecting on-orbit data processing is insufficient. Since satellites have very limited onboard resources, their energy supply usually relies on solar panels. Their computing power, storage capacity, and power are usually limited, which cannot meet the energy consumption requirements of public key systems with high computational complexity. Deploying security systems under limited satellite resources is a difficult problem that needs to be solved urgently. At the same time, while protecting data security, completing the identification of abnormal data on LEO satellites in orbit is also a difficult problem that needs to be solved urgently.
[0008] It should be noted that the information disclosed in the above background technology section is only used to understand the background of this application, and therefore may include information that does not constitute prior art known to ordinary technicians in this field.
[0009] Summary of the Invention
[0010] The main purpose of the present invention is to overcome the defects of the above-mentioned background technology and provide a method for identifying satellite on-orbit safety anomalies for offshore wind farms.
[0011] To achieve the above object, the present invention adopts the following technical solutions:
[0012] A method for identifying satellite on-orbit safety anomalies for offshore wind farms, comprising a system initialization phase, an abnormal data organization phase, and an abnormal data intersection phase;
[0013] The system initialization phase includes: the trusted authority center sets the basic security parameters of the system, including the hash function and the fingerprint function, and initializes the XOR filter; the first type satellite and the second type satellite are set up to prepare for subsequent data processing;
[0014] The abnormal data organization stage includes: the first type of satellite receives abnormal data from the remote manager of the offshore wind farm and adds it to the XOR filter, and generates corresponding elements using the fingerprint of the XOR filter and sends them to the second type of satellite;
[0015] The abnormal data intersection stage includes: the second-type satellite receives the real-time data set of the offshore wind farm sensor, uses the XOR filter to filter out the elements that do not belong to the intersection, and processes the filtered elements and sends them to the first-type satellite. The first-type satellite verifies the received elements according to the fingerprint. If the verification is successful, the corresponding element is placed in the final abnormal data intersection set.
[0016] Furthermore, the system initialization phase includes:
[0017] The trusted authority selects three hash functions for data verification, initializes the XOR filter, selects the fingerprint function, and selects an array large enough to create the XOR filter and initializes it to 0;
[0018] The trusted authority generates an identity-based sequence during the registration phase of the first type of satellite and sends it to the first type of satellite, and generates an identity-based key during the registration phase of the second type of satellite and sends it to the second type of satellite;
[0019] The component supplier selects the key and sends it to the offshore wind farm.
[0020] Furthermore, the abnormal data organization stage includes:
[0021] A remote manager of an offshore wind farm collects abnormal data from component suppliers, generates a protected sequence of data items, and sends the sequence to the first type of satellite. The sequence of data items includes abnormal values belonging to different suppliers, and each abnormal value is marked with a current time period.
[0022] The first type of satellite generates the array and the three hash functions using the XOR filter and generates a set containing all fingerprints;
[0023] The first type of satellite organizes the abnormal data according to a set rule, wherein the rule is related to fingerprints and data items, and the data items are grouped according to fingerprints that meet the set conditions;
[0024] The first type of satellite selects random numbers and calculates elements using fingerprints of abnormal data, the elements forming a secure sequence;
[0025] When the first type of satellite determines that the second type of satellite will pass through the offshore wind farm, the first type of satellite generates a message and sends it to the second type of satellite, where the message contains the array and the element sequence information.
[0026] Furthermore, the abnormal data intersection stage includes:
[0027] At a designated time, the offshore access point collects sensor data of various components of the offshore wind farm and sends the data to the second type of satellite, and the second type of satellite receives the information sent by the first type of satellite;
[0028] The second type of satellites generates two empty sets Yb and Fb;
[0029] For each data item collected from the maritime access point, the second type of satellite is tested by the detection mechanism of the XOR filter, and if the test result is true, the data item is stored in Yb;
[0030] The second type of satellite calculates a fingerprint for each data item in Yb and stores the first occurrence of the fingerprint in Fb;
[0031] The second type of satellite selects a random number for each fingerprint in Fb, generates a new sequence through a bilinear map and / or a hash function, processes the corresponding elements of each fingerprint and generates a corresponding set Zd, and then sends the new sequence and the set Zd corresponding to all fingerprints to the first type of satellite;
[0032] After receiving the message from the second-type satellite, the first-type satellite checks whether each fingerprint in Fb exists in the set. If so, it further checks whether each data item corresponding to the fingerprint exists in the set. If so, the first-type satellite adds the corresponding data item to the intersection set, and finally obtains the abnormal data intersection.
[0033] Furthermore, the first type of satellite and the second type of satellite are low earth orbit (LEO) satellites.
[0034] A satellite on-orbit safety anomaly identification system for offshore wind farms includes a trusted authority center, a first-class satellite, and a second-class satellite. The system uses the satellite on-orbit safety anomaly identification method to achieve safe identification of abnormal data in offshore wind farms.
[0035] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the method for identifying satellite in-orbit safety anomalies.
[0036] The present invention has the following beneficial effects:
[0037] To address the challenges mentioned above and address offshore wind farm scenarios, this paper proposes a method for identifying satellite in-orbit security anomalies. This method can identify anomalies in satellite in-orbit while protecting the confidentiality of offshore wind farm data. This method leverages existing cryptographic and multi-party secure computing technologies, making it suitable for use in situations where satellite resources are limited, and enabling efficient and secure processing of satellite in-orbit data.
[0038] The present invention can effectively realize the safe anomaly identification of satellite on-orbit data in offshore wind farm scenarios. Its main advantages include: first, it ensures that the real abnormal data values of the wind farm are only available to the remote managers of the wind farm and the offshore access points; second, it ensures the security and confidentiality of the data transmitted during the collaborative calculation of abnormal data intersection between satellites; third, it realizes efficient and safe satellite collaborative data processing, greatly reducing computing and communication overhead.
[0039] The method of the present invention uses XOR filters and a concise private set intersection protocol to achieve secure on-orbit anomaly identification. The method first uses all abnormal data to generate an XOR filter, and uses the fingerprint of the XOR filter to complete the interactive process of the concise private set intersection protocol. By combining the XOR filter, the on-orbit computing overhead and communication overhead are greatly reduced.
[0040] The anomaly identification method of the present invention meets the security requirements of confidentiality. The satellite can only learn the intersection result of two sets, but cannot know the true value of the two set data, nor the true value of the intersection data.
[0041] Other beneficial effects of the embodiments of the present invention will be further described below. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] FIG1 is a schematic diagram of an on-orbit anomaly identification of a LEO satellite for an offshore wind farm according to an embodiment of the present invention. DETAILED DESCRIPTION
[0043] The following is a detailed description of the embodiments of the present invention. It should be emphasized that the following description is only exemplary and is not intended to limit the scope of the present invention and its application.
[0044] It should be noted that when an element is referred to as being "fixed to" or "disposed on" another element, it can be directly on the other element or indirectly on the other element. When an element is referred to as being "connected to" another element, it can be directly connected to the other element or indirectly connected to the other element. In addition, connection can be used for both fixing and coupling or communication.
[0045] It should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing the embodiments of the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operate in a specific orientation, and therefore cannot be understood as limiting the present invention.
[0046] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0047] Definitions of Abbreviations and Key Terms:
[0048] XOR Filters:
[0049] XOR filters provide efficient data insertion and querying. In the present invention, XOR filters are used for fast filtering of data items. Given an array B with an array capacity of c, where c is slightly larger than the length of the set S∈U, for example: U represents all possible sets. A random fingerprint function f(·) is chosen to map each item in U to a k-bit value. The XOR filter mainly consists of two functions:
[0050] XOR.Build(S,f(·)→{B,(h0,h1,h2)}): Given a set S and a fingerprint function f(·), repeatedly select three hash functions, namely (h0(·):S→{0,…,c / 3-1},h1(·):S→{c / 3,…,2c / 3-1},h2(·):S→{2c / 3,…,c-1}), until the array B and hash function assigned to the set S are successfully identified, and output B and the hash function.
[0051] XOR.Test(x,B)→True / False: Given an element x∈S, if it satisfies f(x)=B[h0(x)]xorB[h1(x)]xor B[h2(x)], output True, otherwise output False.
[0052] Bilinear Maps:
[0053] Given a security parameter k, For a cyclic group that satisfies |q|=k,
[0054] Bilinear: and We can get e(aP,bQ)=e(P,Q) ab .
[0055] Non-degeneracy: There exist P,Q∈G such that
[0056] Computability: There exists an efficient algorithm to compute e(P,Q).
[0057] The bilinear parameter generator gen(·) represents a probabilistic algorithm that takes parameter κ as input and outputs the seven-tuple Where q represents a large prime number satisfying |q|=k, is an additive cyclic group, is a multiplicative cyclic group, and is a generator, is a bilinear map that satisfies non-degeneracy and computability.
[0058] The coverage of terrestrial communication networks (wireless networks and landlines) is limited, while LEO satellites can provide communication services and remote monitoring services to remote areas that are not covered by terrestrial communication networks. An embodiment of the present invention proposes an inter-satellite on-orbit safety anomaly identification scheme for LEO satellites, as shown in Figure 1. LEO satellites serve as industry-shared on-orbit platforms for remote monitoring and observation. In the inter-satellite on-orbit safety anomaly identification scheme for LEO satellites, the present invention can be oriented towards the specific scenario of offshore wind farms, considering the use of LEO satellites to provide remote monitoring services for them, and realize on-orbit data processing through satellites to complete abnormal data identification for offshore wind farms. In order to achieve security protection for satellite collaborative computing, an embodiment of the present invention proposes a satellite on-orbit safety anomaly identification method for offshore wind farms. This method is a satellite collaborative on-orbit abnormal data security processing method based on multi-party secure computing technology. In this method, the satellite can only learn the results of the intersection of data sets, and cannot know the true value of the data set and the true value of the intersection of the sets. Remote managers at offshore wind farms upload encrypted anomaly data to a satellite. This satellite then employs another satellite to collect real-time data from the offshore wind farm. When the two satellites intersect, they securely calculate the intersection of the two sets and perform anomaly identification. During this on-orbit anomaly identification process, the satellite can only learn the result of the set intersection and cannot determine the true values of the two data sets.
[0059] The embodiment of the present invention provides a method for identifying satellite on-orbit safety anomalies for offshore wind farms, comprising a system initialization phase, an abnormal data organization phase, and an abnormal data intersection phase;
[0060] The system initialization phase includes: the trusted authority center sets basic security parameters of the system, including hash functions and fingerprint functions, and initializes the XOR filter; the first type of satellite and the second type of satellite are set up to prepare for subsequent data processing; preferably, the first type of satellite and the second type of satellite are low earth orbit (LEO) satellites;
[0061] The abnormal data organization stage includes: the first type of satellite receives abnormal data from the remote manager of the offshore wind farm and adds it to the XOR filter, generates corresponding elements and sends them to the second type of satellite;
[0062] The abnormal data intersection stage includes: the second-type satellite receives sensor data collected by the maritime access point, filters out elements that do not belong to the intersection using an XOR filter, processes the filtered elements and sends them to the first-type satellite, and the first-type satellite verifies the received elements according to the fingerprint. If the verification is successful, the corresponding element is placed in the final abnormal data intersection set.
[0063] In a preferred embodiment, the system initialization phase includes:
[0064] The trusted authority selects three hash functions for data verification, initializes the XOR filter, selects the fingerprint function, and selects an array large enough to create the XOR filter and initializes it to 0;
[0065] The trusted authority generates an identity-based sequence during the registration phase of the first type of satellite and sends it to the first type of satellite, and generates an identity-based key during the registration phase of the second type of satellite and sends it to the second type of satellite;
[0066] The component supplier selects the key and sends it to the offshore wind farm.
[0067] In a preferred embodiment, the abnormal data organization stage includes:
[0068] A remote manager of an offshore wind farm collects abnormal data from component suppliers, generates a protected sequence of data items, and sends the sequence to the first type of satellite. The sequence of data items includes abnormal values belonging to different suppliers, and each abnormal value is marked with a current time period.
[0069] The first type of satellite generates the array and the three hash functions using the XOR filter and generates a set containing all fingerprints;
[0070] The first type of satellite organizes the abnormal data according to a set rule, wherein the rule is related to fingerprints and data items, and the data items are grouped according to fingerprints that meet the set conditions;
[0071] The first type of satellite selects random numbers and calculates elements using fingerprints of abnormal data, the elements forming a secure sequence;
[0072] When the first type of satellite determines that the second type of satellite will pass through the offshore wind farm, the first type of satellite generates a message and sends it to the second type of satellite, where the message contains the array and the element sequence information.
[0073] In a preferred embodiment, the abnormal data intersection stage includes:
[0074] At a designated time, the offshore access point collects sensor data of various components of the offshore wind farm and sends the data to the second type of satellite, and the second type of satellite receives the information sent by the first type of satellite;
[0075] The second type of satellites generates two empty sets Yb and Fb;
[0076] For each data item collected from the maritime access point, the second type of satellite is tested by the detection mechanism of the XOR filter, and if the test result is true, the data item is stored in Yb;
[0077] The second type of satellite calculates a fingerprint for each data item in Yb and stores the first occurrence of the fingerprint in Fb;
[0078] The second-type satellite selects a random number for each fingerprint in Fb, generates a new sequence through operations such as a random permutation function, a bilinear map and / or a hash function, and processes the corresponding elements of each fingerprint to generate a corresponding set Zd, and then sends the new sequence and the set Zd corresponding to all fingerprints to the first-type satellite;
[0079] After receiving the message from the second-type satellite, the first-type satellite checks whether each fingerprint in Fb exists in the fingerprint set of the data item. If so, it further checks whether the data items corresponding to the fingerprint exist in the fingerprint set of the data item. If so, the first-type satellite adds the corresponding data items to the intersection set, and finally obtains the abnormal data intersection.
[0080] An embodiment of the present invention also provides a satellite on-orbit safety anomaly identification system for offshore wind farms, including a trusted authority center, a first-type satellite and a second-type satellite. The system uses the satellite on-orbit safety anomaly identification method to achieve safe identification of abnormal data in offshore wind farms.
[0081] The present invention's on-orbit secure anomaly identification method for satellites meets confidentiality security requirements. A satellite can only learn the intersection of two sets, but cannot learn the true value of the data in the two sets, nor the true value of the intersection data. The present invention utilizes XOR filters and a concise private set intersection protocol to achieve secure on-orbit anomaly identification. All anomaly data is used to generate an XOR filter, and the fingerprint of the XOR filter is used to complete the interaction process of the concise private set intersection protocol. The combination of XOR filters significantly reduces on-orbit computational and communication overhead.
[0082] Specific embodiments of the present invention are further described below.
[0083] In order to achieve efficient satellite on-orbit safety identification of abnormal data of offshore wind farms, an embodiment of the present invention proposes a satellite on-orbit safety anomaly identification method.
[0084] The implementation process of the satellite on-orbit safety anomaly identification method of the present invention is divided into three parts: 1) system initialization; 2) abnormal data organization; 3) abnormal data intersection. The processing flow is as follows:
[0085] 1) System initialization
[0086] During the system initialization phase, the remote manager of the offshore wind farm is assumed to be the trusted authority center (TA). The trusted authority center (TA) will perform the following steps to generate the entire system.
[0087] (1) Given a security parameter k, the trusted authority TA calls the bilinear parameter generator gen(k) to generate the parameter in
[0088] (2) The trusted authority TA selects three hash functions
[0089] (3) The trusted authority center TA initializes the XOR filter, selects a fingerprint function with a k-bit output, and selects an array large enough to create the XOR filter, which is initialized to 0.
[0090] In the first type of satellite Sat a During the registration phase, the trusted authority TA first calculates the identity-based sequence Where l = 2 k is the size of the fingerprint. At the same time, the trusted authority center TA securely sends the sequence For the first type of satellite Sat a When the second type of satellite Sat b During registration, the trusted authority TA generates an identity-based key u b =α·H2(id b ) and securely sent to the second type of satellite Sat b During the construction phase of an offshore wind farm, the component supplier chooses a key o and sent to offshore wind farms.
[0091] 2) Abnormal data organization
[0092] The remote manager of the offshore wind farm organizes all abnormal data from all component suppliers and generates a protected sequence of data items, such as X = (x1, x2, ..., x m ). If x i (i∈{1,2,…,m}) belongs to supplier o, then the protected data item is represented by x i =H(a i ||s o ||T k ), where a i is a possible abnormal value, T k Indicates the identifier of time period k and is sent to the first type of satellite Sat through the ground station a In order to safely and efficiently calculate the anomaly identification process, the first type of satellite Sat a Follow these steps:
[0093] First, the first type of satellite Sat aRunning XOR.Build(X,f(·)) generates a length of Array B a And three hash functions (h a,0 ,h a,1 ,h a,2 ), the first type of satellite Sat a Generate a set of all fingerprints The first satellite Sat a According to (f i ,(x i,i ,x i,2 ,…,x i,w )) Organize abnormal data, where f i Satisfy f i ∈F a , data item x i,j The fingerprint of ∈X is f i , w represents the fingerprint f in the data set X i There are w data items.
[0094] Secondly, the first type of satellite Sat a Select random number Computational Elements where u a,0 =H1(id a ),coefficient Taken from where i∈{0,1,…,l a}. Sat a Using random number r a Generate Sequence
[0095] in, is a polynomial The coefficient of , and Meet the conditions When the first satellite Sat a Identify the second type of satellite Sat b The first type of satellite will pass by the target offshore wind farm and generate a message msg1 = B a ||R a And send it to the second type of satellite Sat b .
[0096] 3) Abnormal data intersection
[0097] At time T kWhen the offshore access point collects sensor data of all components of the offshore wind farm, it is expressed as Y = (y1, y2, ..., y n ). The data item generated by supplier o is represented as y j =H(b j ||s o ||T k ),j∈{1,2,…,n}.
[0098] After receiving msg1, the second type of satellite Sat b When it flies over the access point at sea, it receives the Y data sequence. To calculate the intersection of X and Y, the second type of satellite Sat b First generate two empty sets, defined as For each data item y j ∈Y, the second type of satellite Sat b Detect XOR.Test(y j ,B a )=True / False. If the result is True, the second type of satellite Sat b y j Stored in set Y b For each data item y j ∈Y b , the second type of satellite Sat b Calculate fingerprint f j =f(y j ) and stored in the data set F b For each fingerprint f d ∈F b ,d∈{1,…,l b}, the second type of satellite Sat b Select random number Choose a random permutation function π:[l b ]→[l b ], generate (T d ,U d ),Right now
[0099] In addition, each fingerprint f d , the second type of satellite Sat b Generate set Z d =(z d,1 ,z d,2 ,…,z d,v ),in, v is the set Y b Fingerprint f d The number of data items of the second type of satellite Sat b Generate and send a message Sent to the first satellite Sat a .
[0100] After receiving msg2, the first type of satellite Sat a Perform the following steps. For d∈{1,2,…,l b}, the first type of satellite Sat a Check whether all fingerprints f d Exists in set Z d Among them, that is
[0101] If the above equation is true, then the first type of satellite Sat a Determine whether each data item Exists in set Z d Among them, that is
[0102] If the above formula is established, the first type of satellite Sat a x π(d),j Put the final intersection set P s Finally, we get the set P s =X∩Y={p1,p2,…,p e} is the abnormal data obtained by identification.
[0103] In summary, the present invention proposes a method for identifying LEO satellite on-orbit security anomalies, which can complete the identification of LEO satellite on-orbit security anomaly data under the premise of protecting the data confidentiality of offshore wind farms. The method of the present invention comprehensively utilizes existing cryptographic technology and multi-party secure computing technology, making it suitable for situations where satellite resources are limited, and realizes efficient and secure processing of satellite on-orbit data. In this method, the satellite can only learn the intersection result of two sets, but cannot know the true value of the two set data, nor the true value of the intersection data, which meets the security requirements of confidentiality. Among them, the abnormal data identification using XOR filter and simple privacy set intersection protocol, and the interactive process of the simple privacy set intersection protocol using the fingerprint of the XOR filter are completed, which greatly reduces the computational overhead and communication overhead.
[0104] The present invention can effectively realize the safe anomaly identification of satellite on-orbit data in the offshore wind farm scenario. Its main advantages include: first, it ensures that the real abnormal data values of the wind farm are only available to the remote manager of the wind farm and the offshore access point; second, it ensures the security and confidentiality of the data transmitted during the collaborative calculation of abnormal data intersection between satellites; third, it realizes efficient and safe satellite collaborative data processing, greatly reducing computing and communication overhead.
[0105] An embodiment of the present invention further provides a storage medium for storing a computer program, which at least performs the above method when executed.
[0106] An embodiment of the present invention further provides a control device, comprising a processor and a storage medium for storing a computer program; wherein the processor is configured to execute at least the method described above when executing the computer program.
[0107] An embodiment of the present invention further provides a processor, which executes a computer program and at least performs the method described above.
[0108] The storage medium may be implemented by any type of volatile or non-volatile storage device, or a combination thereof. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory may be a magnetic disk memory or a magnetic tape memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM). The storage media described in the embodiments of the present invention are intended to include, but are not limited to, these and any other suitable types of memory.
[0109] In the several embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical, mechanical, or other forms.
[0110] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0111] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0112] Those skilled in the art will appreciate that all or part of the steps of the above-mentioned method embodiments may be implemented by hardware associated with program instructions, and the aforementioned program may be stored in a computer-readable storage medium. When the program is executed, the program executes the steps of the above-mentioned method embodiments. The aforementioned storage medium includes various media that can store program codes, such as mobile storage devices, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical disks.
[0113] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0114] The methods disclosed in the several method embodiments provided by the present invention can be arbitrarily combined without conflict to obtain new method embodiments.
[0115] The features disclosed in several product embodiments provided by the present invention can be arbitrarily combined without conflict to obtain new product embodiments.
[0116] The features disclosed in several method or device embodiments provided by the present invention can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0117] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. Those skilled in the art will recognize that, without departing from the scope of the present invention, several equivalent substitutions or obvious variations can be made, and the performance or use of the same should be considered to fall within the scope of protection of the present invention.
Claims
1. A method for identifying satellite on-orbit safety anomalies for a far-sea wind farm, characterized in that, it includes a system initialization stage, an abnormal data organization stage, and an abnormal data intersection stage; The system initialization stage includes: The trusted authority center sets the basic security parameters of the system, including a hash function and a fingerprint function, and initializes the XOR filter; The first type of satellite and the second type of satellite are set up to prepare for subsequent data processing; The abnormal data organization stage includes: The first type of satellite receives abnormal data from the remote manager of the far-sea wind farm and adds it to the XOR filter, generates corresponding elements using the fingerprint of the XOR filter, and sends them to the second type of satellite; The abnormal data intersection stage includes: The second type of satellite receives the real-time data set of the far-sea wind farm sensors, filters out the elements that do not belong to the intersection using the XOR filter, and processes the filtered elements and sends them to the first type of satellite. The first type of satellite verifies the received elements according to the fingerprint. If the verification is successful, the corresponding elements are put into the final abnormal data intersection set.
2. The satellite on-orbit safety anomaly identification method according to claim 1, characterized in that, The system initialization stage includes: The trusted authority center selects three hash functions for data verification, initializes the XOR filter, selects the fingerprint function, and selects a large enough array to create the XOR filter and initializes it to 0; The trusted authority center generates an identity-based sequence during the registration stage of the first type of satellite and sends it to the first type of satellite, and generates an identity-based key during the registration stage of the second type of satellite and sends it to the second type of satellite; The component supplier selects a key and sends it to the offshore wind farm.
3. The satellite on-orbit safety anomaly identification method according to claim 2, characterized in that, The abnormal data organization stage includes: The remote manager of the far-sea wind farm collects abnormal data from each component supplier, generates a protected data item sequence and sends it to the first type of satellite. The data item sequence contains abnormal values belonging to different suppliers, and each abnormal value marks the current time period; The first type of satellite uses the XOR filter to generate the array and the three hash functions, and generates a set containing all fingerprints; The first type of satellite organizes the abnormal data according to the set rules. The rules are related to fingerprints and data items, and the data items are grouped according to the fingerprints that meet the set conditions; The first type of satellite selects a random number and calculates elements using the fingerprint of the abnormal data. These elements form a security sequence; When the first type of satellite determines that the second type of satellite will pass by the offshore wind farm, the first type of satellite generates a message and sends it to the second type of satellite. This message contains information about the array and the element sequence.
4. The satellite on-orbit safety anomaly identification method according to claim 3, characterized in that, The abnormal data intersection stage includes: At a specified time, the offshore access point collects sensor data of each component of the offshore wind farm and sends it to the second type of satellite, and the second type of satellite receives the information sent by the first type of satellite; The second type of satellite generates two empty sets Yb and Fb; For each data item collected from the offshore access point, the second type of satellite detects it through the detection mechanism of the XOR filter. If the detection result is true, the data item is stored in Yb; The second type of satellite calculates fingerprints for each data item in Yb and stores the first-occurring fingerprints in Fb; The second type of satellite selects random numbers for each fingerprint in Fb, generates a new sequence through a random permutation function, a bilinear mapping, and / or a hash function, processes the corresponding elements of each fingerprint and generates a corresponding set Zd, and then sends the new sequence and the set Zd corresponding to all fingerprints to the first type of satellite; After receiving the message from the second type of satellite, the first type of satellite checks whether all fingerprints in Fb exist in the set. If so, it further checks whether each data item in Yb exists in the set. If so, the first type of satellite adds the corresponding data item to the intersection set to finally obtain the abnormal data intersection.
5. The satellite on-orbit safety anomaly identification method according to any one of claims 1 to 4, characterized in that, The first type of satellite and the second type of satellite are low Earth orbit (LEO) satellites.
6. A satellite on-orbit safety anomaly identification system for a far-offshore wind farm, characterized in that: It includes a trusted authority center, a first type of satellite, and a second type of satellite. Among them, the satellite on-orbit safety anomaly identification method according to any one of claims 1 to 5 is used to achieve the secure identification of abnormal data in the far-offshore wind farm.
7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is run by a processor, it implements the satellite on-orbit safety anomaly identification method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Spacecraft system anomaly detection method based on high-dimensional space mapping
CN111274543A
Access and switching authentication method and system in satellite network intermittent connection scene
CN112087750A
Satellite edge calculation method and device for remote monitoring
CN116709303A
Satellite in-orbit security anomaly identification method for open-sea wind power plant
CN117278109A
Blocked XOR filter for blacklist filtering
US20230231828A1