Method and system for data interworking between different satellite communication systems
By implementing encrypted key management and quantum key sharing in satellite terminals and gateway stations, the problem of secure interoperability and switching between different satellite communication systems has been solved, achieving seamless communication and secure interconnection, and avoiding the risks of data loss and key reuse.
Patent Information
- Application Number
- PCT/CN2024/116998
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-23
- Filing Date
- 2024-09-05
- Publication Date
- 2026-01-29
AI Technical Summary
Secure interoperability and handover between different satellite communication systems are difficult, especially when the network connection between the satellite terminal and the third-party certificate authority is unstable. Session keys are easily cracked, and satellite movement can cause connection interruptions and data loss.
By implementing encrypted key management in satellite terminals and gateway stations, and utilizing quantum key sharing and access credentials, seamless switching and secure communication between different satellite systems can be achieved, including quantum key sharing and encrypted transmission between satellite terminals and peer satellite terminals.
It enables seamless communication switching while the satellite is in motion, avoids data loss, ensures communication quality, and achieves secure interconnection between different satellite systems through quantum key sharing, avoiding the security risk of key reuse.
Smart Images

Figure CN2024116998_29012026_PF_FP_ABST
Abstract
Description
Method and system for data intercommunication between different satellite communication systems
[0001] Cross-reference to Related Applications
[0002] This application claims priority to the Chinese patent application No. 202410985644.4, filed on July 23, 2024, and entitled "Method and system for data intercommunication between different satellite communication systems", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of satellite communication, in particular to a method and system for data intercommunication between different satellite communication systems. BACKGROUND
[0004] With the development of science and technology, satellite communication has become the main force of information transmission and communication, and is closely related to people's daily life. The importance of satellite communication not only lies in ordinary communication transmission, but also has a profound impact on military defense, production safety and economic development. Therefore, the security of satellite communication cannot be ignored.
[0005] Current satellite secure communication is mostly based on digital certificates and public-private key cryptography systems, that is, the key of the authentication agency is used to protect data. However, there are difficulties in actual use:
[0006] (1) The number of satellite communication terminal users is huge and widely distributed, and it is easy to appear that the terminal equipment cannot maintain network connection with the third-party certificate authority, and then the problem of unverifiable digital certificate occurs.
[0007] (2) The process of session key negotiation or distribution is based on asymmetric key pairs and digital certificates. The public key used to encrypt the session key material is public, and with the improvement of the computing power of quantum computers, there is a possibility of being cracked, which leads to the session key to be stolen.
[0008] At the same time, the great demand for personal communication globalization is constantly promoting the research of communication satellites, and currently there are many satellite internet key projects such as Star Network Project, Tian Tong, Tian Qi, Jilin No. 1, etc. in parallel promotion in China. Although different satellite communications are mostly based on CCSDS (Consultative Committee for Space Data Systems) protocol system, and there are several decode-encode-forward mechanisms to realize data interconnection between different satellite communication systems, but in the case of data encryption protection, different satellite communication systems use different keys, so how to realize safe interconnection between different satellite communication systems is still a technical problem. At the same time, the satellite is in continuous motion, and the distance between the satellite and the satellite terminal is too far, which may cause the connection to be interrupted, at this time the satellite switching will be performed, how to ensure the safety of the switching process and prevent the loss of user data is an important problem related to business availability and security.
[0009] In the related art, as an example, the scheme of multi-satellite multi-orbit global broadband satellite communication system only focuses on connecting the interconnection and interconnection between constellations through ground stations, and does not consider the switching problem when the running position of different satellites changes; as another example, the scheme of satellite-ground integrated quantum key distribution network, the connection between a single satellite network and a ground network does not involve how to interconnect between multiple different satellites; as another example, the scheme of satellite communication encryption system based on quantum key is a centerless system to realize position query, and the mobile terminal under a single satellite cannot address to find the terminal under other satellites.
[0010] SUMMARY
[0011] The technical problem to be solved by the present application is how to realize switching communication between different satellites.
[0012] The present application solves the above technical problems by the following technical means:
[0013] In some embodiments of the present application, the present application provides a method for data interconnection between different satellite communication systems, the method comprising:
[0014] Receiving the same downlink data sent by the original satellite and the first satellite to which the satellite terminal belongs, wherein the first satellite is the satellite closest to the satellite terminal in the same system as the original satellite, and the first satellite carries access credentials encrypted by the encryption key filled in the satellite terminal in the first data packet of the downlink data;
[0015] Synchronously sending the uplink data to the original satellite and the first satellite, and only sending the uplink data to the first satellite when the original satellite leaves the connection range of the satellite terminal;
[0016] Based on the first satellite and the satellite terminal of the opposite end for communication.
[0017] In some embodiments of the present application, the access credential carries information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0018] In some embodiments of the present application, for the calling satellite terminal, the communication with the satellite terminal at the opposite end based on the first satellite includes:
[0019] The calling satellite terminal sends a communication application to the first satellite to which it belongs, so that the first satellite relays the communication application to a first gateway station corresponding to the first satellite, and the communication application includes information of the calling and called satellite terminals.
[0020] The calling satellite terminal receives a key ciphertext returned by the first satellite, which is obtained by the first gateway station applying for a shared quantum key between a key management (KM) device corresponding to the calling satellite terminal and a KM device corresponding to the called satellite terminal based on the communication application, and encrypting the shared quantum key using an encryption key pre-charged in the calling satellite terminal.
[0021] The calling satellite terminal decrypts the key ciphertext using the encryption key pre-charged in itself to obtain the shared quantum key, and encrypts the communication data using the shared quantum key to obtain data ciphertext.
[0022] The calling satellite terminal transmits the data ciphertext to the called satellite terminal according to an information transmission path between the calling and called satellite terminals.
[0023] In some embodiments of the present application, the calling satellite terminal sends the communication application to the first satellite to which it belongs, and further includes:
[0024] The calling satellite terminal encrypts the communication application using an encryption key pre-charged in itself to obtain communication application ciphertext.
[0025] The calling satellite terminal sends the communication application ciphertext to the first satellite to which it belongs.
[0026] In some embodiments of the present application, the information transmission path is a first satellite-first gateway station-second gateway station corresponding to the called satellite terminal-second satellite to which the called satellite terminal belongs-called satellite terminal.
[0027] In some embodiments of the present application, the method further includes:
[0028] After receiving the data ciphertext, the called satellite terminal relays the key application to the second gateway station via the second satellite, and the key application includes information of the calling and called satellite terminals.
[0029] The called satellite terminal receives the key ciphertext returned by the second satellite, the key ciphertext being obtained by the second gateway station applying for the shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the calling satellite terminal based on the key application, and encrypting the shared quantum key using the encryption key filled in the called satellite terminal;
[0030] The called satellite terminal decrypts the key ciphertext using the encryption key filled in the called satellite terminal to obtain the shared quantum key;
[0031] The shared quantum key is used to decrypt the data ciphertext to obtain the communication data sent by the calling satellite terminal.
[0032] In some embodiments of the present application, the method further comprises:
[0033] The called satellite terminal encrypts the key application using the encryption key filled in the called satellite terminal to obtain the key application ciphertext;
[0034] The called satellite terminal relays the key application ciphertext to the second gateway station through the second satellite.
[0035] In some embodiments of the present application, the shared quantum key is discarded after the current session of the calling and called satellite terminals ends.
[0036] In some embodiments of the present application, the present application proposes a method for data intercommunication between different satellite communication systems, the method comprising:
[0037] Inquiring the ephemeris information of the original satellite and the position information of the satellite terminal in a timely manner;
[0038] When it is judged based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, traversing all satellites that can be connected to and are in the same system as the original satellite to find the satellite closest to the satellite terminal as the first satellite;
[0039] Sending a switching instruction to the first satellite and sending the information of the satellite terminal to the first satellite, so that the first satellite sends downlink data to the satellite terminal, wherein the information of the satellite terminal carries access credentials encrypted using the encryption key filled in the satellite terminal;
[0040] Communicating with the satellite terminal at the opposite end based on the first satellite.
[0041] In some embodiments of the present application, the access credentials carry information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0042] In some embodiments of the present application, communicating with the satellite terminal at the opposite end based on the first satellite comprises:
[0043] receive a communication application sent by a first satellite to which the satellite terminal belongs, and initiate a user query application to a quantum identity authentication cloud platform based on the communication application, the communication application including information of both the calling satellite terminal and the called satellite terminal and being initiated by the calling satellite terminal;
[0044] receive called satellite terminal information sent by the quantum identity authentication cloud platform, the called satellite terminal information including a serial number of a key management (KM) device corresponding to the called satellite terminal;
[0045] apply for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal, and encrypt the shared quantum key using an encryption key in the calling satellite terminal to obtain key ciphertext;
[0046] relay the key ciphertext to the calling satellite terminal through the first satellite, so that the calling satellite terminal decrypts the key ciphertext to obtain the shared quantum key and encrypts communication data using the shared quantum key.
[0047] In some embodiments of the present application, the communication application is an encrypted communication application encrypted using the encryption key in the calling satellite terminal.
[0048] In some embodiments of the present application, receiving the communication application sent by the first satellite to which the satellite terminal belongs and initiating the user query application to the quantum identity authentication cloud platform based on the communication application comprises:
[0049] receiving the encrypted communication application sent by the first satellite to which the satellite terminal belongs and decrypting the encrypted communication application;
[0050] initiating the user query application to the quantum identity authentication cloud platform based on the decrypted communication application.
[0051] In some embodiments of the present application, the method further comprises:
[0052] receiving a key application sent by the called satellite terminal, and applying for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the key application;
[0053] encrypting the shared quantum key using an encryption key in the called satellite terminal and then relaying the encrypted shared quantum key to the called satellite terminal through the second satellite, so that the called satellite terminal decrypts the encrypted shared quantum key to obtain the shared quantum key and decrypts encrypted data.
[0054] In some embodiments of the present application, the key application is an encrypted key application encrypted using the encryption key in the called satellite terminal.
[0055] In some embodiments of the present application, the key application sent by the called satellite terminal is received, and a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the calling satellite terminal is applied based on the key application.
[0056] The encrypted key application sent by the called satellite terminal is received and decrypted;
[0057] Based on the decrypted key application, a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the calling satellite terminal is applied.
[0058] In some embodiments of the present application, the present application provides a satellite terminal, which comprises a satellite switching connection module and a first satellite communication module, wherein:
[0059] The satellite switching connection module is used for receiving the same downlink data sent by the original satellite and the first satellite, wherein the first satellite is the satellite in the same system as the original satellite and closest to the satellite terminal, and the first data packet of the downlink data sent by the first satellite carries access credentials encrypted by the encryption key filled in the satellite terminal; the uplink data is synchronously sent to the original satellite and the second satellite, and when the original satellite leaves the connection range of the satellite terminal, only the uplink data is sent to the first satellite;
[0060] The first satellite communication module is used for communicating with the satellite terminal at the opposite end based on the first satellite.
[0061] In some embodiments of the present application, the access credentials carry information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0062] In some embodiments of the present application, the first satellite communication module comprises a key management unit, a data processing unit, a secure medium, and a communication unit, wherein:
[0063] The communication unit is used for sending a communication application or a key application to the satellite to which it belongs, and receiving a key ciphertext or a data ciphertext returned by the satellite, the key ciphertext being a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the calling satellite terminal applied by the gateway station to which the satellite belongs based on the communication application, and the shared quantum key being encrypted by using the encryption key filled in the calling satellite terminal to obtain;
[0064] The key management unit is used for calling the pre-filled encryption key in the secure medium;
[0065] The data processing unit is configured to, when receiving the key ciphertext returned by the satellite, call the encryption key by using the key management unit to decrypt the key ciphertext to obtain the shared quantum key, and encrypt the communication data by using the shared quantum key to obtain the data ciphertext or decrypt the data ciphertext to obtain the communication data.
[0066] In some embodiments of the present application, the data processing module is further configured to encrypt the communication application or the key application by using the key management unit to call the encryption key.
[0067] In some embodiments of the present application, the present application provides a gateway station, which comprises a satellite switching management module and a second satellite communication module, wherein:
[0068] The satellite switching management module is configured to periodically inquire the ephemeris information of the original satellite in the connection and the position information of the satellite terminal, and when judging that the original satellite is about to leave the connection range of the satellite terminal based on the ephemeris information and the position information, traverse all satellites that can be connected to and are in the same system as the original satellite to select the satellite closest to the satellite terminal as the first satellite, then send a switching instruction to the first satellite and send the information of the satellite terminal to the first satellite, so that the first satellite sends downlink data to the satellite terminal, wherein the information of the satellite terminal carries an access credential encrypted by using the encryption key filled in the satellite terminal.
[0069] The second satellite communication module is configured to perform communication based on the first satellite and the satellite terminal of the opposite end.
[0070] In some embodiments of the present application, the access credential carries information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0071] In some embodiments of the present application, the second satellite communication module comprises a quantum key distribution device and a quantum cryptography service platform, wherein:
[0072] The quantum cryptography service platform is configured to, based on the communication application or the key application relayed by the satellite, initiate a user query application to the quantum identity authentication cloud platform to query the information of the satellite terminal of the opposite end, wherein the information of the satellite terminal of the opposite end includes the satellite information, the gateway station information, and the serial number of the corresponding key management (KM) device of the opposite end, and the communication application includes the information of the satellite terminals of the calling party and the called party.
[0073] The quantum key distribution device is configured to, based on the information of the satellite terminal of the opposite end returned by the quantum identity authentication cloud platform, apply for a shared quantum key between the KM device corresponding to the satellite terminal of the opposite end and the KM device corresponding to the satellite terminal of the opposite end.
[0074] The quantum cryptography service platform is further configured to encrypt the shared quantum key using the encryption key filled in the local satellite terminal, to obtain key ciphertext and return to the local satellite terminal through the satellite.
[0075] In some embodiments of the present application, the quantum cryptography service platform is further configured to encrypt the communication application using the encryption key filled in the local satellite terminal.
[0076] In some embodiments of the present application, the present application provides a data intercommunication system between different satellite communication systems, the data intercommunication system comprising a satellite terminal, a gateway station and a quantum cryptography service network, wherein:
[0077] The gateway station inquires the ephemeris information of the original satellite in the connection and the position information of the satellite terminal, and when it is judged based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, the satellite closest to the satellite terminal among all the satellites that can be connected and are in the same system as the original satellite is searched as the first satellite;
[0078] The gateway station sends a switching instruction to the first satellite, and sends the information of the satellite terminal to the first satellite to enable the first satellite to access the satellite terminal, wherein the information of the satellite terminal carries access credentials encrypted using the encryption key filled in the satellite terminal;
[0079] The satellite terminal receives the same downlink data sent by the original satellite and the first satellite, and synchronously sends uplink data to the original satellite and the first satellite, and only sends the uplink data to the first satellite when the original satellite leaves the connection range of the satellite terminal;
[0080] The satellite terminal communicates with the opposite satellite terminal based on the gateway station, the first satellite and the quantum cryptography service network.
[0081] In some embodiments of the present application, the satellite terminal communicates with the opposite satellite terminal based on the gateway station, the first satellite and the quantum cryptography service network, comprising:
[0082] The calling satellite terminal sends a communication application to the first satellite, so that the first satellite relays the communication application to the first gateway station corresponding to the first satellite, and the communication application comprises the information of the calling and called satellite terminals;
[0083] The first gateway station initiates a user query application to the quantum identity authentication cloud platform in the quantum cryptography service network based on the communication application, to obtain the information of the called satellite terminal, and the information of the called satellite terminal comprises the serial number of the key management (KM) device corresponding to the called satellite terminal;
[0084] The first gateway station applies for a shared quantum key between the KM device corresponding to the called satellite terminal from the KM device corresponding to the calling satellite terminal, and encrypts the shared quantum key using the encryption key filled in the calling satellite terminal to obtain key ciphertext;
[0085] The calling satellite terminal receives the key ciphertext returned by the first satellite, decrypts the key ciphertext using the encryption key filled in the calling satellite terminal to obtain the shared quantum key, and encrypts the communication data using the shared quantum key to obtain data ciphertext;
[0086] The calling satellite terminal transmits the data ciphertext to the called satellite terminal according to the first satellite-the first gateway station-the second gateway station corresponding to the called satellite terminal-the second satellite to which the called satellite terminal belongs.
[0087] The application has the following advantages:
[0088] (1) When a satellite terminal is about to leave the communication coverage range of the original connected satellite due to satellite movement, the application can switch the satellite connected by the satellite terminal in the same system during satellite movement, realize seamless switching of other satellites in the same system, and not lose the communication data between the satellite terminal and the opposite satellite terminal and the satellite to which the opposite satellite terminal belongs; the switching connection with the terminal in the satellite movement state is realized, the terminal data is avoided to be lost, and the communication quality of the terminal is ensured.
[0089] (2) The application realizes source encryption in the satellite communication system, instead of traditional physical layer protection, avoids the situation that the satellite is difficult to keep network connection with the third party certificate authority at all times during communication / verification, and as long as the satellite terminal can exchange signals with the communication satellite, the sharing and encrypted transmission of the key can be realized, the secure interconnection between different satellite communication systems is realized, the situation that the keys are different between different systems and communication cannot be realized is avoided, and the problems of secure communication of the satellite terminal and secure communication across satellite communication systems are solved.
[0090] (3) After the sharing of the quantum key between the calling satellite terminal and the called satellite terminal is realized, the shared quantum key can be continuously used for session protection within one session, and after the current session ends, the shared quantum key is discarded, so that different shared quantum keys are used for protection in each session, and the security risk caused by repeated use of the key is avoided.
[0091] Additional aspects and advantages of the application will be in part apparent and in part pointed out hereinafter in the description. BRIEF DESCRIPTION OF DRAWINGS
[0092] Fig. 1 is a flow diagram of a method for data intercommunication between different satellite communication systems according to the first embodiment of the application;
[0093] Figure 2 is a flowchart of a method for data intercommunication between different satellite communication systems according to a second embodiment of the present application;
[0094] Figure 3 is a structural diagram of a satellite terminal according to a third embodiment of the present application;
[0095] Figure 4 is a structural diagram of a gateway station according to a fourth embodiment of the present application;
[0096] Figure 5 is a structural diagram of a system for data intercommunication between different satellite communication systems according to a fifth embodiment of the present application. DETAILED DESCRIPTION
[0097] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in a clear and complete manner with reference to the embodiments of the present application. Obviously, the described embodiments are only some, but not all of the embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0098] In order to better understand the embodiments of the present application, some nouns or terms appearing in the process of describing the embodiments of the present application are explained as follows:
[0099] Satellite terminal: including intelligent satellite phone, satellite phone and satellite positioning terminal and other terminal devices, which can transmit information based on a satellite communication system and communicate with other satellite terminals. The satellite terminal can have different forms of expression, such as handheld terminal or vehicle-mounted terminal, etc.
[0100] Gateway station: a ground station of a satellite, used for connecting a satellite network and a ground network.
[0101] Quantum cryptography service network: including quantum key distribution device, quantum cryptography service platform and quantum identity authentication cloud platform, realizing quantum key generation, quantum key relay, cryptography operation agent and other services.
[0102] Satellite: including a plurality of communication satellites, the number of which is not limited, and which can belong to the same satellite communication system or different satellite communication systems.
[0103] In the embodiments of the present application, a method for data intercommunication between different satellite communication systems is provided. The method for data intercommunication between different satellite communication systems is applied to a satellite terminal, as shown in Figure 1, and specifically includes the following steps:
[0104] S101, receive the same downlink data sent by the original satellite and the first satellite, wherein the first satellite is the satellite closest to the satellite terminal in the same system as the original satellite, and the first data packet of the downlink data sent by the first satellite carries access credentials encrypted by the encryption key charged in the satellite terminal;
[0105] It should be noted that the satellite terminal decrypts the access credentials in the downlink data packet sent by the satellite using the encryption key charged by itself to realize access authentication.
[0106] S102, synchronously send uplink data to the original satellite and the first satellite, and only send uplink data to the first satellite when the original satellite leaves the connection range of the satellite terminal;
[0107] S103, communicate with the satellite terminal of the opposite end based on the first satellite.
[0108] The embodiment can switch the satellite to which the satellite terminal is connected in the same system when the satellite moves, realize seamless switching of other satellites in the same system, and not lose the communication data between the satellite terminal and the satellite terminal of the opposite end and the satellite to which the satellite terminal of the opposite end belongs; realize switching connection with the terminal in the satellite motion state, avoid losing terminal data, and ensure the communication quality of the terminal.
[0109] In some embodiments of the present application, the access credentials carry information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0110] It should be noted that the encrypted first satellite information of the embodiment refers to the part of the data in the information transmitted between the satellite and the ground satellite terminal that requires security protection.
[0111] In some embodiments of the present application, step S103: based on the first satellite and the satellite terminal of the opposite end to communicate, specifically includes:
[0112] S131, the calling satellite terminal sends a communication application to the first satellite to which it belongs, so that the first satellite relays the communication application to the first gateway station corresponding to the first satellite, and the communication application includes the information of the calling and called satellite terminals;
[0113] S132, the calling satellite terminal receives the key ciphertext returned by the first satellite, and the key ciphertext is obtained by encrypting the shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the communication application by the first gateway station, and using the encryption key charged in the calling satellite terminal.
[0114] S133, the calling satellite terminal decrypts the key ciphertext by using the encryption key filled by itself to obtain the shared quantum key, and encrypts the communication data by using the shared quantum key to obtain data ciphertext;
[0115] It should be noted that the calling satellite terminal and the called satellite terminal are both provided with a security medium, and the security medium stores the encryption key filled by the quantum password service platform in advance.
[0116] It should be understood that the security medium is a security medium that meets the certificate issued by the State Commercial Cipher Bureau and has a security protection capability, and can be connected to the key management platform to realize the key filling function. The security medium can adopt a secure SIM (Subscriber Identity Module) card or a secure U token (Security Token).
[0117] S134, the calling satellite terminal transmits the data ciphertext to the called satellite terminal according to the information transmission path between the calling satellite terminal and the called satellite terminal.
[0118] The embodiment realizes the sharing of the quantum key between the calling satellite terminal and the called satellite terminal, and realizes the encryption of the signal source in the satellite communication system by using the shared quantum key, instead of the traditional physical layer protection. The satellite communication system avoids the situation that the satellite is difficult to keep network connection with the third party certificate authority at all times during communication / verification. As long as the satellite terminal can exchange signals with the communication satellite, the sharing and encrypted transmission of the key can be realized, the secure interconnection between different satellite communication systems is realized, and the situation that the communication cannot be realized due to different keys between different systems is avoided. The secure communication of the satellite terminal and the secure communication across the satellite communication systems are solved.
[0119] Specifically, step S131: the calling satellite terminal sends a communication application to the first satellite to which the calling satellite terminal belongs, and the step further includes:
[0120] The calling satellite terminal encrypts the communication application by using the encryption key filled by itself to obtain communication application ciphertext;
[0121] The calling satellite terminal sends the communication application ciphertext to the first satellite to which the calling satellite terminal belongs.
[0122] It should be noted that when the calling satellite terminal communicates with the called satellite terminal, the calling satellite terminal first sends a communication application to the first satellite to which the calling satellite terminal belongs. The communication application includes the information of the calling satellite terminal and the information of the called satellite terminal. The communication application can be specifically the communication application ciphertext encrypted by the filled key in the security medium in the calling satellite terminal. Then, the first satellite to which the calling satellite terminal belongs relays the encrypted communication application to the first gateway station corresponding to the first satellite in a transparent mode.
[0123] Correspondingly, after receiving the encrypted communication application, the first gateway station calls the corresponding encryption key to decrypt the encrypted communication application, and then initiates a user query application to the quantum identity authentication cloud platform based on the called satellite terminal information vector contained in the communication application, requiring to query the information of the second satellite to which the called satellite terminal belongs, the information of the corresponding second gateway station, and the serial number of the corresponding KM (Key Management) device; then, the first gateway station applies for a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the called satellite terminal, and encrypts the shared quantum key using the encryption key charged in the called satellite terminal to obtain the key ciphertext.
[0124] Specifically, in step S134, the calling satellite terminal transmits the data ciphertext to the called satellite terminal according to the information transmission path between the calling satellite terminal and the called satellite terminal, wherein the information transmission path is: the first satellite-the first gateway station-the second gateway station corresponding to the called satellite terminal-the second satellite to which the called satellite terminal belongs-the called satellite terminal.
[0125] Specifically, the method further comprises the following steps:
[0126] S135, after receiving the data ciphertext, the called satellite terminal relays the key application to the second gateway station via the second satellite, wherein the key application comprises the information of the calling satellite terminal and the called satellite terminal;
[0127] S136, the called satellite terminal receives the key ciphertext returned by the second satellite, wherein the key ciphertext is obtained by the second gateway station applying for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the key application, and encrypting the shared quantum key using the encryption key charged in the called satellite terminal.
[0128] S137, the called satellite terminal decrypts the key ciphertext using the encryption key charged in the called satellite terminal to obtain the shared quantum key.
[0129] S138, the shared quantum key is used to decrypt the data ciphertext to obtain the communication data sent by the calling satellite terminal.
[0130] Specifically, after the called satellite terminal obtains the data ciphertext, the key application is transmitted to the second satellite relay, and the quantum key for decryption is applied to the second gateway station. The key application includes the information of the calling satellite terminal and the called satellite terminal. The second gateway station receives the key application, and based on the information of the calling satellite terminal and the called satellite terminal included in the key application, applies for the shared quantum key between the KM device in the second gateway station and the KM device in the first gateway station, and then returns the shared quantum key applied by the second gateway station to the second gateway station as needed. The second gateway station encrypts the shared quantum key using the encryption key filled in the called satellite terminal, and sends the shared quantum key to the called satellite terminal through the second satellite relay. The called satellite terminal decrypts the shared quantum key, and uses the shared quantum key to decrypt the data ciphertext, and obtains the communication data sent by the calling satellite terminal.
[0131] Specifically, the method further comprises:
[0132] The called satellite terminal encrypts the key application using the encryption key filled in the called satellite terminal, to obtain the key application ciphertext.
[0133] The called satellite terminal transmits the key application ciphertext to the second gateway station through the second satellite relay.
[0134] It should be noted that the key application ciphertext can be encrypted using the encryption key filled in the secure medium of the called satellite terminal.
[0135] Specifically, after the calling satellite terminal and the called satellite terminal end this session, the shared quantum key is discarded.
[0136] After the sharing of the quantum key between the calling satellite terminal and the called satellite terminal in the embodiment, the shared quantum key can be continuously used for session protection within one session, and the shared quantum key is discarded after the end of the session, so that different shared quantum keys are used for protection in each session, and the security risk caused by repeated use of the key is avoided.
[0137] In the embodiment of the application, a method for data intercommunication between different satellite communication systems is provided. The method for data intercommunication between different satellite communication systems is applied to a gateway station, as shown in FIG. 2. The method specifically comprises the following steps:
[0138] S201, inquire the ephemeris information of the original satellite in the connection and the position information of the satellite terminal at a fixed time;
[0139] S202, when it is judged based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, traverse all satellites that can be connected to and are in the same system as the original satellite to find the satellite closest to the satellite terminal as the first satellite;
[0140] S203, sending a switching instruction to the first satellite and sending information of the satellite terminal to the first satellite, so that the first satellite sends downlink data to the satellite terminal, wherein the information of the satellite terminal carries an access credential encrypted by the encryption key charged in the satellite terminal;
[0141] S204, the first satellite and the satellite terminal of the opposite end communicate.
[0142] Specifically, the gateway station inquires the ephemeris information of the satellite to which the satellite terminal belongs in the connection and the position of the satellite terminal. When it is determined that the satellite to which the satellite terminal belongs is about to leave the connection range of the satellite terminal, all satellites in the same system as the original satellite to which the satellite terminal belongs and connected to the gateway station are traversed to find the satellite closest to the satellite terminal as the first satellite. The switching instruction is sent to the first satellite, and the information of the satellite terminal is sent to the first satellite. Before the original satellite to which the satellite terminal belongs leaves, the original satellite and the first satellite simultaneously send the same downlink data to the satellite terminal, and the satellite terminal synchronously sends the uplink message to the first satellite. When the original satellite leaves, the first satellite keeps the connection with the satellite terminal, and the satellite terminal sends the uplink message to the first satellite only after it is found that the original satellite no longer sends data.
[0143] In the embodiment, when the gateway station sends the information of the satellite terminal to the first satellite, the information includes an access credential encrypted by the charging key of the satellite terminal. The access credential carries information including an encryption key identifier, encrypted first satellite information and a timestamp. When the first satellite starts to forward data to the satellite terminal, the access credential is added in the first data packet, so that when the first satellite connects the satellite terminal, the access authentication is realized based on the charging key in the satellite terminal.
[0144] It should be noted that the embodiment can switch the satellite to which the satellite terminal is connected in the same system when the satellite moves, realize seamless switching of other satellites in the same system, and not lose the communication data between the satellite terminal and the opposite satellite terminal and the satellite to which the opposite satellite terminal belongs. The switching connection with the terminal is realized in the satellite movement state, the terminal data is avoided to be lost, and the communication quality of the terminal is ensured.
[0145] In some embodiments of the present application, step S204: the first satellite and the satellite terminal of the opposite end communicate, specifically comprising the following steps:
[0146] S241, receiving the communication application sent by the first satellite to which the satellite terminal belongs and initiating a user query application to the quantum identity authentication cloud platform based on the communication application, the communication application including the information of the calling satellite terminal and the called satellite terminal and being initiated by the calling satellite terminal;
[0147] Specifically, the calling satellite terminal and the called satellite terminal are both provided with a security medium, and the security medium stores an encryption key pre-charged by a quantum password service platform; the quantum identity authentication cloud platform stores user information of the security medium, a business opening state and the like, and since the security medium and the satellite terminal are opened simultaneously, the quantum identity authentication cloud platform also stores a corresponding relationship between the satellite terminal corresponding to the security medium and quantum devices deployed in the satellite-gateway station-gateway station.
[0148] S242, receiving the called satellite terminal information sent by the quantum identity authentication cloud platform, the called satellite terminal information at least including a serial number of a key management KM device corresponding to the called satellite terminal;
[0149] Specifically, the called satellite terminal information further includes identification information of a second satellite to which the called satellite terminal belongs, identification information of a corresponding second gateway station and identification information of a corresponding second KM device, and the like, and the identification information can be a serial number or an ID, which is not limited here.
[0150] S243, applying for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal, and encrypting the shared quantum key using the encryption key in the calling satellite terminal to obtain a key ciphertext;
[0151] S244, relaying the key ciphertext to the calling satellite terminal through the first satellite, so that the calling satellite terminal decrypts the key ciphertext to obtain the shared quantum key and encrypts the communication data using the shared quantum key.
[0152] It should be noted that the embodiment realizes the effect of issuing a session key between two satellite terminals through quantum key sharing, and the two gateway stations share the quantum key, and then use the charging key of the satellite terminal to encrypt the quantum key and send it to the satellite terminal as a session key for communication.
[0153] Specifically, the communication application is an encrypted communication application encrypted using the encryption key in the calling satellite terminal; in some embodiments of the present application, the communication application sent by the first satellite belonging to the communication application is received, and a user query application is initiated to the quantum identity authentication cloud platform based on the communication application, including:
[0154] receiving the encrypted communication application sent by the first satellite and decrypting the encrypted communication application;
[0155] initiating a user query application to the quantum identity authentication cloud platform based on the decrypted communication application.
[0156] It should be noted that after receiving the encrypted communication application relayed by the first satellite, the first gateway station calls the quantum password service platform CSP-1 deployed in the first gateway station to decrypt the communication application ciphertext.
[0157] Specifically, when the gateway station is a second gateway station to which the called satellite terminal belongs, the method further comprises the following steps:
[0158] receiving a key application sent by the called satellite terminal, and applying for a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the called satellite terminal based on the key application;
[0159] encrypting the shared quantum key using an encryption key in the called satellite terminal and relaying the encrypted shared quantum key to the called satellite terminal through the second satellite, so that the called satellite terminal decrypts the encrypted data by obtaining the shared quantum key.
[0160] Specifically, the key application is an encrypted key application encrypted using an encryption key in the called satellite terminal; in some embodiments of the present application, receiving a key application sent by the called satellite terminal, and applying for a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the called satellite terminal based on the key application, comprises:
[0161] receiving an encrypted key application sent by the called satellite terminal and decrypting the encrypted key application;
[0162] applying for a shared quantum key between the KM device corresponding to the called satellite terminal and the KM device corresponding to the called satellite terminal based on the decrypted key application.
[0163] It should be noted that after the called satellite terminal obtains the data ciphertext, the second satellite transmits the decryption key to the second gateway station, the key application includes the information of the called satellite terminal and the called satellite terminal, and the key application is encrypted by the encryption key filled in the security medium of the called satellite terminal; the second gateway station calls the quantum cryptographic service platform CSP-2 (Cryptographic Service Platform, quantum cryptographic service platform) in the second gateway station for decryption, and then applies for a quantum key between the KM device in the first gateway station corresponding to the called satellite terminal and the KM device in the first gateway station corresponding to the called satellite terminal; the KM device in the second gateway station distributes the shared key between the KM device in the first gateway station through the quantum key network, and returns the quantum key applied by the second gateway station to the second gateway station as needed after receiving the key application; the second gateway station calls CSP-2, encrypts the returned quantum key using the key filled in the called satellite terminal, and sends the encrypted quantum key to the called satellite terminal through the second satellite.
[0164] It should be noted that the gateway station discards the quantum key after sending the encrypted quantum key to the corresponding satellite terminal.
[0165] In the embodiments of the present application, a satellite terminal is provided, as shown in FIG. 3, which comprises a satellite switching connection module 11 and a first satellite communication module 12, wherein:
[0166] The satellite switching connection module 11 is configured to receive the same downlink data sent by the original satellite and the first satellite, wherein the first satellite is the satellite closest to the satellite terminal in the same system as the original satellite, and the first satellite carries access credentials encrypted by the encryption key filled in the satellite terminal in the first data packet of the downlink data; the uplink data is synchronously sent to the original satellite and the second satellite, and only the uplink data is sent to the first satellite when the original satellite leaves the connection range of the satellite terminal;
[0167] The first satellite communication module 12 is configured to communicate with the satellite terminal at the opposite end based on the first satellite.
[0168] Specifically, the access credentials carry information including an encryption key identifier, encrypted first satellite information and a timestamp.
[0169] In some embodiments of the present application, the first satellite communication module comprises a key management unit, a data processing unit, a security medium and a communication unit, wherein:
[0170] The communication unit is configured to send a communication application or a key application to the satellite to which the satellite terminal belongs, and receive the key ciphertext or the data ciphertext returned by the satellite to which the satellite terminal belongs, the key ciphertext is the shared quantum key between the calling satellite terminal corresponding key management KM device and the called satellite terminal corresponding KM device applied by the satellite gateway to which the satellite belongs based on the communication application to the calling satellite terminal, and the shared quantum key is encrypted by using the encryption key filled in the calling satellite terminal to obtain;
[0171] The key management unit is configured to call the encryption key pre-filled in the security medium;
[0172] The data processing unit is configured to, when receiving the key ciphertext returned by the satellite to which the satellite terminal belongs, decrypt the key ciphertext by using the encryption key called by the key management unit to obtain the shared quantum key, and encrypt the communication data by using the shared quantum key to obtain the data ciphertext or decrypt the data ciphertext to obtain the communication data.
[0173] Specifically, the data processing unit is further configured to encrypt the communication application or the key application by using the encryption key called by the key management module.
[0174] Optionally, the security medium provided in the embodiments can be a secure SIM card or a secure U disk, and the communication module provided is specifically a satellite signal transceiver antenna.
[0175] In some embodiments of the present application, the communication data between the calling satellite terminal and the called satellite terminal is transmitted according to an information transmission path between the calling satellite terminal and the called satellite terminal, and the information transmission path is a first satellite-a first gateway-a second gateway corresponding to the called satellite terminal-a second satellite to which the called satellite terminal belongs-the called satellite terminal.
[0176] It should be noted that other embodiments of the satellite terminal of the present application or the implementation method can refer to the above method embodiments, which will not be repeated here.
[0177] In the embodiments of the present application, a gateway is provided, as shown in FIG. 4, the gateway includes a satellite switching management module 21 and a second satellite communication module 22, wherein:
[0178] The satellite switching management module 21 is configured to periodically inquire the ephemeris information of the original satellite in the connection and the position information of the satellite terminal; when it is determined based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, the satellite closest to the satellite terminal among all satellites that can be connected and are in the same system as the original satellite is taken as a first satellite; then a switching instruction is sent to the first satellite, and the information of the satellite terminal is sent to the first satellite, so that the first satellite sends downlink data to the satellite terminal, wherein the information of the satellite terminal carries an access credential encrypted by an encryption key filled in the satellite terminal;
[0179] The second satellite communication module 22 is configured to perform communication based on the first satellite and the satellite terminal at the opposite end.
[0180] Specifically, the access credential carries information including an encryption key identifier, encrypted first satellite information, and a timestamp.
[0181] In some embodiments of the present application, the second satellite communication module includes a quantum key distribution device and a quantum cryptography service platform, wherein:
[0182] The quantum cryptography service platform is configured to initiate a user query application to a quantum identity authentication cloud platform based on a communication application or a key application of a satellite relay belonging to the quantum cryptography service platform, to query the information of the satellite terminal at the opposite end, the information of the satellite terminal at the opposite end including satellite information, gateway information, and a serial number of a corresponding key management (KM) device, and the communication application including the information of the calling satellite terminal and the called satellite terminal.
[0183] The quantum key distribution device is configured to apply for a shared quantum key between the KM device corresponding to the satellite terminal at the opposite end based on the information of the satellite terminal at the opposite end returned by the quantum identity authentication cloud platform.
[0184] The quantum password service platform is further configured to encrypt the shared quantum key using the encryption key filled in the satellite terminal to obtain key ciphertext and return the key ciphertext to the satellite terminal via the satellite.
[0185] Specifically, the quantum password service platform is further configured to encrypt the communication application using the encryption key filled in the satellite terminal.
[0186] In some embodiments of the application, the satellite terminal information sent by the gateway station to the third satellite is encrypted by the quantum password service platform arranged in the gateway station.
[0187] It should be noted that other embodiments of the gateway station or the implementation method of the application can refer to the above method embodiments, which will not be repeated here.
[0188] In the embodiments of the application, a system for data intercommunication between different satellite communication systems is provided, as shown in FIG. 5, the system for data intercommunication includes a calling satellite terminal, a called satellite terminal, a first gateway station, a second gateway station, a quantum password service network and a first satellite and a second satellite, wherein:
[0189] The calling satellite terminal sends a communication application to the first satellite, so that the first satellite relays the communication application to the first gateway station corresponding to the first satellite, and the communication application includes information of the calling and called satellite terminals;
[0190] The first gateway station initiates a user query application to the quantum identity authentication cloud platform in the quantum password service network based on the communication application, and obtains called satellite terminal information, the called satellite terminal information including a serial number of a key management (KM) device corresponding to the called satellite terminal;
[0191] The first gateway station applies for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal, and encrypts the shared quantum key using the encryption key filled in the calling satellite terminal to obtain key ciphertext;
[0192] The calling satellite terminal receives the key ciphertext returned by the first satellite, decrypts the key ciphertext using the encryption key filled in the calling satellite terminal to obtain the shared quantum key, and encrypts communication data using the shared quantum key to obtain data ciphertext;
[0193] The calling satellite terminal transmits the data ciphertext to the called satellite terminal according to the first satellite-first gateway station-second gateway station corresponding to the called satellite terminal-second satellite belonging to the called satellite terminal.
[0194] Correspondingly, the called satellite terminal relays the key application to the second gateway station via the second satellite, and the key application includes information of the calling and called satellite terminals.
[0195] The called satellite terminal receives the key ciphertext returned by the second satellite, the key ciphertext is applied for the shared quantum key between the KM equipment corresponding to the called satellite terminal and the KM equipment corresponding to the calling satellite terminal by the second satellite based on the key application, and the shared quantum key is encrypted by using the encryption key filled in the called satellite terminal to obtain;
[0196] The called satellite terminal decrypts the key ciphertext by using the encryption key filled in the called satellite terminal to obtain the shared quantum key;
[0197] The data ciphertext is decrypted by using the shared quantum key to obtain the communication data sent by the calling satellite terminal.
[0198] It should be noted that the quantum password service network provided in the embodiment includes a quantum key distribution device, a quantum password service platform and a quantum identity authentication cloud platform, which are used to realize quantum key generation, quantum key relay, password operation proxy and the like. Among them, the quantum key distribution device includes a QKD (Quantum Key Distribution) device for generating a quantum key and a KM device for managing quantum keys and network distribution. The quantum key distribution security medium is filled with keys by the quantum password service platform, and the quantum password service platform stores and manages the filled keys. The quantum identity authentication cloud platform stores user information, business opening state and other information of the security medium. Since the security medium and the satellite terminal are opened at the same time, the quantum identity authentication cloud platform also stores the corresponding relationship between the satellite terminal, the satellite, the gateway station and the quantum device deployed in the gateway station corresponding to the security medium.
[0199] In some embodiments of the application, any satellite terminal in FIG. 5 can be a calling satellite terminal or a called satellite terminal, and the working process of the system for data interworking between different satellite communication systems includes:
[0200] (1) When the calling satellite terminal wants to communicate with the called satellite terminal, it first sends a communication application to the first satellite to which the calling satellite terminal belongs. The application includes the information of the calling satellite terminal and the information of the called satellite terminal. The application is encrypted by the key management module in the calling satellite terminal by calling the filled key in the security SIM card in the calling satellite terminal;
[0201] (2) The first satellite relays the encrypted communication application to the first gateway station corresponding to the first satellite in a transparent mode;
[0202] (3) The first gateway station receives the communication application and calls the quantum password service platform CSP-1 deployed in the first gateway station to decrypt the first gateway station;
[0203] (4) The first gateway station initiates a user query application to the quantum identity authentication cloud platform by means of the CSP-1, requiring to query the second satellite information, corresponding gateway station and serial number of corresponding KM to which the called satellite terminal belongs;
[0204] (5) The quantum identity authentication cloud platform queries out the serial number of the second satellite / second gateway station / KM-n according to the called satellite terminal information, and returns to the first gateway station;
[0205] (6) The first gateway station applies for the key between KM-1 and KM-n to the KM-1 deployed in the gateway station as a password application user;
[0206] (7) KM-1 and KM-n perform quantum key network distribution to realize key sharing;
[0207] (8) KM-1 returns the quantum key applied by the first gateway station to the first gateway station on demand;
[0208] (9) The first gateway station calls CSP-1, encrypts the quantum key returned by KM-1 using the key filled in the calling satellite terminal, and sends it to the calling satellite terminal through the first satellite relay;
[0209] (10) The calling satellite terminal decrypts to obtain the quantum key, encrypts the information to be transmitted using the quantum key, and then sends the encrypted information to the called satellite terminal through the path of first satellite-first gateway station-second gateway station-second satellite-called satellite terminal;
[0210] (11) The called satellite terminal obtains the encrypted information, applies for a decryption key to the ground station 2 through the second satellite transmittance relay, and the application includes the information of the calling satellite terminal and the information of the called satellite terminal, which is encrypted by the key management module in the called satellite terminal using the filled key in the security SIM card in the called satellite terminal;
[0211] (12) The second gateway station receives the key application, calls CSP-2 for decryption, and then applies for the key between KM-1 and KM-n to the KM-n deployed in the gateway station;
[0212] (13) KM-n has shared the key with KM-1 through the quantum key network distribution in step (7), and returns the quantum key applied by the second gateway station to the second gateway station on demand after receiving the key application;
[0213] (14) The second gateway station calls CSP-2, encrypts the quantum key returned by KM-n using the key filled in the called satellite terminal, and sends it to the called satellite terminal through the second satellite relay;
[0214] (15) The called satellite terminal decrypts to obtain the quantum key, and uses the quantum key to decrypt the encrypted information received in step (10) to obtain the information sent by the calling satellite terminal.
[0215] It should be understood that the process of secure intercommunication between different satellite communication systems implemented by the embodiments of the application can adopt message integrity protection, the message integrity is implemented based on a block cipher algorithm or a keyed hash algorithm, and the key used for the message integrity protection is derived from a pre-charged key in the satellite terminal.
[0216] The method and system of the embodiments of the application are based on but not limited to a QKD key distribution network, and the key pre-charging function involved in the embodiments of the application can be implemented by using any kind of symmetric key management system and device. The symmetric cipher algorithm involved in the application can use any algorithm conforming to the national cipher management regulation.
[0217] The satellite is in continuous motion, and there is a situation that the distance between the satellite and the satellite terminal is too far to be connected, at this time, the satellite switching is usually performed, therefore, based on the system for data intercommunication between different satellite communication systems provided in the above-mentioned embodiments, the embodiments of the application implement the communication switching between the satellite terminal and different satellites, and specifically:
[0218] The gateway station inquires the ephemeris information of the satellite in the connection and the position of the satellite terminal, when it is determined that the satellite will leave the connection range of the satellite terminal, all satellites in the same system as the original satellite to which the gateway station can be connected are traversed to find the satellite closest to the satellite terminal as a first satellite, the switching instruction is sent to the first satellite, and the satellite terminal information is sent to the first satellite. Before the original satellite leaves, the original satellite and the first satellite simultaneously send the same downlink data to the satellite terminal, and the satellite terminal synchronously sends the uplink message to the first satellite. When the original satellite leaves, the first satellite keeps the connection with the satellite terminal, and the satellite terminal sends the uplink message to the first satellite only after it is found that the original satellite no longer sends data.
[0219] In some embodiments of the application, when the first satellite is connected to the satellite terminal, the access authentication is implemented based on the pre-charged key in the satellite terminal. When the gateway station sends the satellite terminal information to the first satellite, the access credential encrypted by using the pre-charged key of the satellite terminal is contained in the information, and when the first satellite starts to forward the data to the satellite terminal, the credential information is added in the first data packet, and the credential includes the pre-charged key identifier, the encrypted information of the first satellite, the timestamp and other information.
[0220] In the embodiment, when the gateway station sends the satellite terminal information to the first satellite, the information contains an access credential encrypted by the satellite terminal charging key. When the first satellite starts to forward data to the satellite terminal, the credential information is added in the first data packet, so that when the first satellite connects to the satellite terminal, the access authentication is realized based on the charging key in the satellite terminal.
[0221] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily mean the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0222] In addition, the terms "first", "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise specifically limited.
[0223] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application.
Claims
1. A method for data interworking between different satellite communication systems, characterized in that, The method comprises: Receiving the same downlink data sent by the original satellite and the first satellite, wherein the first satellite is the satellite closest to the satellite terminal in the same system as the original satellite, and the first satellite carries access credentials encrypted by the encryption key filled in the satellite terminal in the first data packet of the downlink data; Synchronously sending uplink data to the original satellite and the first satellite, and sending the uplink data to the first satellite only when the original satellite leaves the connection range of the satellite terminal; Based on the first satellite and the satellite terminal at the opposite end to communicate.
2. The method for data intercommunication between different satellite communication systems according to claim 1, characterized in that, The access credentials carry information including encryption key identification, encrypted first satellite information and timestamp.
3. The method for data intercommunication between different satellite communication systems according to claim 1, characterized in that, For the calling satellite terminal, the communication based on the first satellite and the satellite terminal at the opposite end comprises: The calling satellite terminal sends a communication application to the first satellite to which it belongs, so that the first satellite relays the communication application to the first gateway station corresponding to the first satellite, and the communication application includes the information of the calling and called satellite terminals; The calling satellite terminal receives the key ciphertext returned by the first satellite, which is obtained by the first gateway station by applying for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the communication application, and encrypting the shared quantum key using the encryption key filled in the calling satellite terminal; The calling satellite terminal decrypts the key ciphertext using the encryption key filled in itself to obtain the shared quantum key, and encrypts the communication data using the shared quantum key to obtain data ciphertext; The calling satellite terminal transmits the data ciphertext to the called satellite terminal according to the information transmission path between the calling and called satellite terminals.
4. The method for data intercommunication between different satellite communication systems according to claim 3, characterized in that, The calling satellite terminal sends a communication application to the first satellite to which it belongs, and further comprises: The calling satellite terminal encrypts the communication application using the encryption key pre-filled in itself to obtain communication application ciphertext; The calling satellite terminal sends the communication application ciphertext to the first satellite to which it belongs.
5. The method for data intercommunication between different satellite communication systems according to claim 3, characterized in that, The method further comprises: After receiving the data ciphertext, the called satellite terminal relays the key application to the second gateway station through the second satellite, and the key application includes the information of the calling and called satellite terminals; The called satellite terminal receives the key ciphertext returned by the second satellite, which is obtained by the second gateway station by applying for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the key application, and encrypting the shared quantum key using the encryption key filled in the called satellite terminal; The called satellite terminal decrypts the key ciphertext using the encryption key filled in itself to obtain the shared quantum key; The shared quantum key is used to decrypt the data ciphertext to obtain the communication data sent by the calling satellite terminal. The method further comprises:
6. The method for data intercommunication between different satellite communication systems according to claim 5, characterized in that, The called satellite terminal encrypts the key application using the encryption key filled in itself to obtain key application ciphertext; The called satellite terminal relays the key application ciphertext to the second gateway station through the second satellite. The method comprises:
7. A method for data interworking between different satellite communication systems, characterized in that, Timing inquiry connection of the original satellite ephemeris information and the satellite terminal position information; When judging that the original satellite is about to leave the connection range of the satellite terminal based on the ephemeris information and the position information, traversing the satellite closest to the satellite terminal among all the satellites that can be connected and are in the same system as the original satellite as a first satellite; Send a switching instruction to the first satellite, and send the information of the satellite terminal to the first satellite, so that the first satellite sends downlink data to the satellite terminal, wherein the information of the satellite terminal carries access credentials encrypted by the encryption key filled in the satellite terminal; Based on the first satellite and the satellite terminal of the opposite end to communicate.
8. The method for data intercommunication between different satellite communication systems according to claim 7, characterized in that, The access credentials carry information including an encryption key identifier, encrypted first satellite information, and a timestamp.
9. The method for data intercommunication between different satellite communication systems according to claim 7, characterized in that, The communication based on the first satellite and the satellite terminal of the opposite end includes: Receive the communication application sent by the first satellite and initiate a user query application to the quantum identity authentication cloud platform based on the communication application, the communication application including information of the calling and called satellite terminals and being initiated by the calling satellite terminal; Receive the called satellite terminal information sent by the quantum identity authentication cloud platform, the called satellite terminal information including the serial number of the key management (KM) device corresponding to the called satellite terminal; Apply for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal, and encrypt the shared quantum key using the encryption key in the calling satellite terminal to obtain key ciphertext; Relay the key ciphertext to the calling satellite terminal through the first satellite, so that the calling satellite terminal decrypts the key ciphertext to obtain the shared quantum key and encrypts communication data using the shared quantum key.
10. The method for data intercommunication between different satellite communication systems according to claim 9, characterized in that, The communication application is an encrypted communication application encrypted using the encryption key in the calling satellite terminal. Correspondingly, the receiving of the communication application sent by the first satellite and the initiation of the user query application to the quantum identity authentication cloud platform based on the communication application include: Receive the encrypted communication application sent by the first satellite and decrypt the encrypted communication application; Initiate the user query application to the quantum identity authentication cloud platform based on the decrypted communication application.
11. The method for data intercommunication between different satellite communication systems according to claim 9, characterized in that, The method further includes: Receive the key application sent by the called satellite terminal, and apply for a shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the key application; Encrypt the shared quantum key using the encryption key in the called satellite terminal and relay it to the called satellite terminal through the second satellite, so that the called satellite terminal decrypts the shared quantum key to decrypt the encrypted data.
12. The method for data intercommunication between different satellite communication systems according to claim 11, characterized in that, The key application is an encrypted key application encrypted using the encryption key in the called satellite terminal. Correspondingly, the receiving of the key application sent by the called satellite terminal and the application of the shared quantum key between the KM device corresponding to the calling satellite terminal and the KM device corresponding to the called satellite terminal based on the key application include: Receive the encrypted key application sent by the called satellite terminal and decrypt the encrypted key application; Based on the decrypted key, a shared quantum key between the calling satellite terminal corresponding KM device and the called satellite terminal corresponding KM device is applied for.
13. A satellite terminal, characterized by The satellite terminal comprises a satellite switching connection module and a first satellite communication module, wherein: The satellite switching connection module is configured to receive the same downlink data sent by the original satellite and the first satellite, wherein the first satellite is the satellite closest to the satellite terminal in the same system as the original satellite, and the first satellite carries the access credential encrypted by the encryption key filled in the satellite terminal in the first data packet of the downlink data; the uplink data is synchronously sent to the original satellite and the second satellite until the uplink data is only sent to the first satellite when the original satellite leaves the connection range of the satellite terminal; The first satellite communication module is configured to perform communication with the satellite terminal at the opposite end based on the first satellite. The gateway station comprises a satellite switching management module and a second satellite communication module, wherein:
14. A gateway station, characterized by The satellite switching management module is configured to inquire the ephemeris information of the original satellite in the connection and the position information of the satellite terminal at regular time intervals; when it is determined based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, the satellite closest to the satellite terminal is selected as the first satellite from all the satellites that can be connected and are in the same system as the original satellite; then, the switching instruction is sent to the first satellite, and the information of the satellite terminal is sent to the first satellite, so that the first satellite sends the downlink data to the satellite terminal, wherein the information of the satellite terminal carries the access credential encrypted by the encryption key filled in the satellite terminal; The second satellite communication module is configured to perform communication with the satellite terminal at the opposite end based on the first satellite. The system for data intercommunication comprises a satellite terminal, a gateway station and a quantum cryptography service network, wherein:
15. A system for data interworking between different satellite communication systems, characterized in that, The gateway station inquires the ephemeris information of the original satellite in the connection and the position information of the satellite terminal at regular time intervals, and when it is determined based on the ephemeris information and the position information that the original satellite is about to leave the connection range of the satellite terminal, the satellite closest to the satellite terminal is selected as the first satellite from all the satellites that can be connected and are in the same system as the original satellite; The gateway station sends the switching instruction to the first satellite, and sends the information of the satellite terminal to the first satellite so that the first satellite accesses the satellite terminal, wherein the information of the satellite terminal carries the access credential encrypted by the encryption key filled in the satellite terminal; The satellite terminal receives the same downlink data sent by the original satellite and the first satellite, and synchronously sends the uplink data to the original satellite and the first satellite until the uplink data is only sent to the first satellite when the original satellite leaves the connection range of the satellite terminal; The satellite terminal performs communication with the satellite terminal at the opposite end based on the gateway station, the first satellite and the quantum cryptography service network.
Citation Information
Patent Citations
Satellite switching method, system and equipment in satellite communication system and medium
CN113596945A
Cooperative communication and switching method and system in low-orbit broadband satellite system
CN113872674A
Medium and low orbit satellite switching method and device, ground terminal, satellite and gateway station
CN114039653A
Satellite switching authentication method for low earth orbit satellite network
CN116056080A
Method and system for data intercommunication between different satellite communication systems
CN118523831A