Data transmission security protection system adaptive to communication base station

By adopting a dual-factor verification mechanism of message authentication code and digital signature in the data transmission system of the communication base station and introducing blockchain technology, the problem of data tampering and unrepudiation of source during data transmission of the communication base station is solved, and efficient and reliable security guarantees of data transmission are achieved.

CN120166403APending Publication Date: 2025-06-17HENAN TRACEABILITY COMM TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510496393.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Communication base stations face security challenges such as data tampering and data source non-refutability during data transmission. The security strength of the existing technology is low and it is difficult to withstand complex attack methods.

Method used

A two-factor verification mechanism combining message authentication code technology and digital signature is adopted to provide storage and verification for important data transmission records through blockchain distributed ledger technology, ensuring data integrity and authenticity and non-repudiation.

Benefits of technology

Effectively resist common tampering attacks, improve data integrity protection capabilities, ensure the security and reliability of data transmission, and take into account security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120166403A_ABST
    Figure CN120166403A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, and particularly discloses a data transmission security protection system adapted to a communication base station, which comprises a sending end, a communication base station, a receiving end and a block chain verification unit, the sending end is in communication connection with the receiving end through a network transmission interface of the communication base station, and the sending end and the receiving end are both connected with the block chain verification unit. Through cooperative operation of a sending end, a communication base station, a receiving end and a block chain verification unit, in terms of data integrity verification, a dual mechanism combining a message authentication code technology and a digital signature is adopted, the message authentication code technology can quickly check whether data is tampered or not, the digital signature ensures that a data source is real and non-repudiation, and common tampering attacks are effectively resisted; and meanwhile, a block chain distributed account book technology is introduced, safe storage and reliable verification are provided for important data transmission records by utilizing decentralization and tamper-resistant characteristics of the block chain distributed account book technology, and even if data are tampered, the tampered data can be timely perceived through an original hash value, so that the data integrity protection capability is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and specifically refers to a data transmission security protection system adapted to communication base stations. Background Art

[0002] In today's digital communication era, communication base stations, as the key hubs for data transmission, carry a huge amount of information interaction tasks. However, the data transmission process faces many severe security challenges, which are specifically manifested as follows:

[0003] During the data transmission process, data is extremely easy to be maliciously tampered with. Traditional data integrity verification methods, such as simple check sums, etc., have low security strength and are difficult to resist complex attack means. Even if some systems adopt message authentication code technology or digital signature technology, there are limitations when used alone. The MAC technology can quickly verify whether the data has been tampered with, but it cannot guarantee the non-repudiation of the data source; although the digital signature can confirm the data source, it is insufficient in quickly detecting data tampering and is difficult to meet the high requirements of communication base stations for data integrity protection.

[0004] Therefore, there is an urgent need for a more perfect and reliable security protection system to ensure the security and integrity of data transmission in communication base stations. Summary of the Invention

[0005] In view of the above situation, in order to overcome the defects of the prior art, the present invention provides a data transmission security protection system adapted to communication base stations to solve the above-mentioned technical defects.

[0006] To achieve the above object, the present invention is realized through the following technical solutions: A data transmission security protection system adapted to communication base stations includes a sending end, a communication base station, a receiving end, and a blockchain verification unit; the sending end is communicatively connected to the receiving end through the network transmission interface of the communication base station, and both the sending end and the receiving end are connected to the blockchain verification unit;

[0007] The sending end is used to encapsulate the original data to be transmitted, the message authentication code obtained by calculation, and the generated digital signature to form a data transmission packet;

[0008] The system verifies data integrity through a dual verification mechanism combining message authentication code technology and digital signature, where the message authentication code technology is used to verify whether the data has been tampered with during the transmission process, and the digital signature is used to ensure the authenticity and non-repudiation of the data source;

[0009] The blockchain verification unit introduces blockchain distributed ledger technology during the data transmission process to provide storage and verification for the transmission records of important data.

[0010] Further, the specific processing method of the message authentication code for data transmission by the sending end includes:

[0011] Utilize the intrusion detection system and security information and event management system deployed by the communication base station to monitor network traffic and security events in real time, and evaluate the security threat level;

[0012] Utilize the performance monitoring module integrated inside the communication base station to monitor the usage of device hardware resources in real time, and evaluate the device computing power in combination with the hardware configuration parameters;

[0013] According to the evaluation results of the security threat level and the device computing power, the system management module of the sending end selects an appropriate message authentication code algorithm according to the preset decision rule, and performs corresponding configuration or initialization settings.

[0014] Further, the message authentication code processing method of the sending end further includes:

[0015] During the device deployment phase, import the pre-stored key into the sending end and the receiving end through the physical storage device to complete key sharing; or use the advanced key management system to update the shared key regularly;

[0016] The communication base station obtains the key pre-shared with the receiving end from the security key storage module, takes the service data and this key as the input parameters of the selected message authentication code algorithm module, and calculates the message authentication code value.

[0017] Further, the sending end is also used to adopt the elliptic curve digital signature algorithm, perform signature operation on the calculated message authentication code value as the signature object to obtain the digital signature result; and encapsulate the original data to be transmitted, the calculated message authentication code value and the generated digital signature to form a data transmission packet, and send it to the receiving end through the network transmission interface of the communication base station according to the established communication protocol.

[0018] Further, the data transmission packet adopts a hierarchical data structure, including the original data, the message authentication code value, the digital signature, and header information such as the data length, data type, message authentication code algorithm identifier, signature algorithm identifier, etc.

[0019] Further, the verification process based on the blockchain distributed ledger technology includes:

[0020] The sending end selects a hash algorithm to perform hash operation on the data to be transmitted to obtain a hash value, combines the accurate transmission time, sender and receiver identification information, and organizes them into a data record set;

[0021] The sending end takes the data record set as the transaction content, adds the transaction version number and transaction serial number, digitally signs it with the private key, then forms a blockchain transaction and broadcasts it to the blockchain network;

[0022] Nodes in the blockchain network perform format verification and digital signature verification on transactions. Transactions that pass the verification are temporarily stored in the local transaction pool and are packaged into new blocks after meeting certain conditions. Under the consensus mechanism based on the Practical Byzantine Fault Tolerance (PBFT) algorithm, after more than 2 / 3 of the nodes reach a consensus, the new block is added to the main chain of the blockchain to complete the data on-chain.

[0023] The receiving end calculates the hash value of the received data. Through the blockchain network query interface, it queries the corresponding transaction records on the blockchain based on the transmission time, sender, and receiver identification information, extracts the hash value therein, and compares the two to verify the data integrity.

[0024] Advantages of the present invention:

[0025] Through the coordinated operation of the sender, communication base station, receiving end, and blockchain verification unit, in terms of data integrity verification, a dual mechanism combining the message authentication code technology and digital signature is adopted. The former can quickly check whether the data has been tampered with, and the latter ensures that the data source is real and non-repudiable, effectively resisting common tampering attacks. At the same time, the blockchain distributed ledger technology is introduced, and its decentralized and immutable characteristics are utilized to provide secure storage and reliable verification for important data transmission records. Even if the data is tampered with, it can be detected in time through the original hash value, greatly improving the data integrity protection ability. In the data transmission link, the message authentication code algorithm is intelligently selected according to the security threat level and device computing power, taking into account both security and efficiency; the security of the key is guaranteed by means of a secure key sharing method and an updatable mechanism; the data encapsulation follows a reasonable structure and adds header information, and combined with the network protocol, it ensures accurate data transmission without loss or damage, providing a strong and reliable guarantee for the security of data transmission in the communication base station in all aspects. Description of the Drawings

[0026] The present invention will be further described below with reference to the accompanying drawings.

[0027] Figure 1 It is a principle block diagram of the data transmission security protection system adapted to the communication base station in the embodiment of the present invention;

[0028] Figure 2 It is a processing flow chart of the sender using the message authentication code for data transmission;

[0029] Figure 3 It is a verification flow chart of the sender and the receiving end based on the blockchain distributed ledger technology. Detailed Embodiments

[0030] Next, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments of the present invention. It should be understood that the present invention is not limited by the exemplary embodiments described herein.

[0031] Embodiment 1

[0032] Please refer to Figure 1 As shown, a data transmission security protection system adapted to a communication base station includes: a sending end, a communication base station, a receiving end, and a blockchain verification unit; the sending end is communicatively connected to the receiving end through the network transmission interface of the communication base station, and both the sending end and the receiving end are connected to the blockchain verification unit. The original data to be transmitted is encapsulated together with the message authentication code calculated and the digital signature generated to form a complete data transmission packet. By adopting a dual verification mechanism combining the message authentication code technology and digital signature, the advantages of both are fully utilized. The message authentication code technology can quickly verify whether the data has been tampered with during transmission, while the digital signature ensures the authenticity and non-repudiation of the data source, enhancing the reliability of data integrity verification and effectively resisting common data tampering attacks; and during the data transmission process, the blockchain distributed ledger technology is introduced through the blockchain verification unit, and its decentralized and immutable characteristics provide a secure and reliable storage and verification method for the transmission records of important data. Even if the data is tampered with during transmission, it can be detected in time through the original hash value recorded on the blockchain, further improving the ability of data integrity protection and providing a stronger guarantee for the security of data transmission in the communication base station.

[0033] It should be further noted that, as Figure 2 shown is the specific process of the sending end using the message authentication code for data transmission.

[0034] The specific process is as follows:

[0035] Evaluate the security threat level: Use the intrusion detection system and security information and event management system deployed in the communication base station to monitor network traffic and security events in real time to determine the degree of security risk faced by the current communication system; among them, the intrusion detection system identifies security threats such as port scanning, denial-of-service attacks, and malware propagation by analyzing the characteristics and behavior patterns of network data packets, and evaluates the security threat level according to factors such as the type, frequency, and intensity of the attacks; the security information and event management system collects log information from multiple security devices (such as firewalls, routers, etc.), conducts comprehensive analysis and correlation. For example, when a large number of abnormal traffic attempts from different IP addresses are detected to connect to a specific port of the base station within a short period of time, it can be judged that the security threat level is relatively high.

[0036] Evaluating the computing power of the device: By using the performance monitoring module integrated inside the communication base station, the hardware resource usage conditions such as the CPU usage rate, memory occupancy rate, and storage read / write speed of the device are monitored in real time. Through the analysis of the above indicators, the current computing power of the device is evaluated. It should be noted that when evaluating the current computing power of the device, the hardware configuration parameters of the device, such as the CPU model, core number, main frequency, and memory capacity, will also be considered to comprehensively judge the computing load that the device can bear. For example, if the device has an older CPU model, fewer cores, and the current CPU usage rate is close to 80%, it indicates that the computing power of the device is relatively limited.

[0037] Algorithm selection decision: According to the evaluation results of the security threat level and the device computing power, the system management module at the sending end selects an appropriate message authentication code algorithm according to the preset decision rules. If the security threat level is high and the device computing resources are sufficient, the system management module will automatically configure an algorithm with high security strength such as HMAC-SHA256. During the configuration process, the corresponding algorithm library will be loaded, and the parameters of the algorithm (the number of iterations of the hash function can be selected here) will be set. If the security threat level is relatively low, the device has high requirements for real-time performance, and the computing resources are limited, the system management module will select an algorithm with higher operation efficiency but slightly lower security strength such as HMAC-MD5 and perform the corresponding initialization settings.

[0038] Key sharing: The key is transmitted through a physical storage device. Before the device leaves the factory, the key is pre-stored in a secure physical storage device. During the device deployment stage, the physical storage device is inserted into the sending end and receiving end devices manually to complete the key import. It should be noted that this method avoids the risk of the key being stolen during network transmission and ensures the confidentiality of the key. In addition, a more advanced key management system can be adopted to update the shared key regularly to further enhance security.

[0039] Calculating the message authentication code value: The communication base station obtains the key pre-shared with the receiving end from the secure key storage module. The secure key storage module uses encryption storage technology to protect the key, and only authorized operations can access the key. Then, the service data and the obtained key are used as input parameters for the HMAC-SHA256 algorithm module. The HMAC-SHA256 algorithm first processes the key to make its length meet the algorithm requirements, and then performs multiple hash operations on the processed key and the service data to finally obtain a message authentication code value with a fixed length. It should be noted that this message authentication code value is closely related to the data content and the shared key, and has uniqueness and unpredictability.

[0040] Generate Data Signature: The sender uses the Elliptic Curve Digital Signature Algorithm (ECDSA) to perform digital signature operations. Taking the calculated Message Authentication Code (MAC) value as the signature object, it uses the extracted private key to perform signature operations on it, obtaining two components of the digital signature. It should be noted that these two components constitute the complete digital signature result for subsequent verification by the receiver. The ECDSA signature operation process is based on the mathematical properties of elliptic curves, and its specific calculation process is as follows: First, select a suitable set of elliptic curve parameters, which are publicly available and fixed in the communication system. Then, based on the private key and the MAC value, a digital signature result is generated through a series of complex point multiplication and addition operations. Specifically, first randomly select an integer as a temporary parameter, use this parameter and the base point of the elliptic curve for point multiplication to obtain a temporary point. Then, perform a series of calculations on the MAC value and the coordinates of the temporary point, and further combine with the private key for operations, finally obtaining the two components of the digital signature.

[0041] Data Encapsulation and Transmission: The sender encapsulates the original data to be transmitted, the calculated MAC value, and the generated digital signature to form a complete data transmission packet. Through the network transmission interface of the communication base station, it sends this data transmission packet to the receiver according to the established communication protocol. It should be noted that during the transmission process, the data may be forwarded through multiple network nodes. Each network node processes it according to the Internet Protocol (IP) or the Transmission Control Protocol (TCP). The data transmission packet is encapsulated in an IP data packet for transmission. Routers in the network forward the data packet to the correct path based on the IP address information to ensure that the data can accurately reach the receiver. The Transmission Control Protocol (TCP) is used to manage the data transmission process, such as flow control and error retransmission, to ensure that the data is not lost or damaged during transmission. In addition, this data transmission packet adopts a hierarchical data structure, placing the original data, MAC value, and digital signature in different fields respectively, and adding corresponding header information, including data length, data type, MAC algorithm identifier, signature algorithm identifier, etc. These header information helps the receiver correctly parse the content of the data transmission packet.

[0042] It should be further noted that, as Figure 3 shown, the following is the verification process between the sender and the receiver based on blockchain distributed ledger technology.

[0043] The verification process is as follows:

[0044] Data Recording: The sender selects the SHA3-512 algorithm, takes the data to be transmitted as the input of this hashing algorithm, obtains a hash value of a fixed length through hashing operations. At the same time, the sender obtains the precise transmission time through the system clock, records the time accurate to the second level, and adopts a unified time format. The sender and receiver information is determined according to the unique identifier of the communication device. These information are organized into a data record set. It should be noted that this identifier can be the device's MAC address, IP address, or other authenticated unique identifier. The data record set includes contents such as the data hash value, transmission time, sender identifier, and receiver identifier.

[0045] Data Upload to the Blockchain: The sender takes the organized data record set as the transaction content, adds the transaction version number and transaction serial number. Then the sender extracts its own private key from the local secure key storage device and uses this private key to digitally sign the transaction content. The signed transaction content and the digital signature together form a complete blockchain transaction. Among them, the signature algorithm can select the same ECDSA algorithm as the above digital signature. The sender broadcasts the constructed blockchain transaction to the blockchain network through the blockchain network interface. After each node in the blockchain network receives the transaction, it first verifies the transaction format, checks whether the transaction content conforms to the format specified by the blockchain protocol, and then conducts digital signature verification, using the public key of the sender to verify the authenticity of the signature. The nodes that pass the verification temporarily store the transaction in the local transaction pool. When the number of transactions in the transaction pool reaches a certain threshold or after a certain time interval, the nodes start to attempt to package these transactions into a new block. Under the consensus mechanism based on the Practical Byzantine Fault Tolerance algorithm, each node communicates with each other to conduct consensus verification on the transactions in the new block. When more than 2 / 3 of the nodes reach a consensus, the new block is added to the main blockchain, completing the operation of uploading the data record to the blockchain.

[0046] Data Integrity Verification: After receiving the data, the receiver calculates the hash value of the received data according to the same hashing algorithm as the sender, obtaining the hash value of the receiver. The receiver queries the corresponding transaction record on the blockchain through the query interface of the blockchain network according to information such as the transmission time, sender identifier, and receiver identifier in the data record, and extracts the hash value of the data from the queried transaction record. The receiver compares the hash value calculated by the receiver with the hash value extracted from the blockchain. If the two hash values are exactly the same, the receiver determines that the data has not been tampered with during transmission, the data integrity is guaranteed, and the data can be processed normally. If the hash values are inconsistent, it indicates that the data may have been tampered with. The receiver immediately records this abnormal situation, and can send a data anomaly notification to the sender, and can also notify the security management module of the system for further analysis and processing.

[0047] In summary, the data transmission security protection system solution for communication base stations, through the coordinated operation of the sender, communication base station, receiver, and blockchain verification unit, adopts a dual mechanism combining message authentication code technology and digital signature for data integrity verification. The former can quickly check whether the data has been tampered with, and the latter ensures that the data source is real and non-repudiable, effectively resisting common tampering attacks. At the same time, the blockchain distributed ledger technology is introduced, and its decentralized and immutable characteristics are used to provide secure storage and reliable verification for important data transmission records. Even if the data is tampered with, it can be detected in time through the original hash value, greatly improving the data integrity protection ability. In the data transmission link, the message authentication code algorithm is intelligently selected according to the security threat level and device computing power, taking into account both security and efficiency; the security of the key is ensured by means of a secure key sharing method and an updatable mechanism; the data encapsulation follows a reasonable structure and adds header information, and combined with the network protocol, it ensures accurate data transmission without loss or damage, providing a strong and reliable guarantee for the security of data transmission in communication base stations in all aspects.

[0048] All the above formulas are dimensionless and take their numerical values for calculation. The formula is obtained by collecting a large amount of data and performing software simulation to get a formula closest to the real situation. The magnitude of the coefficient is a specific value obtained by quantifying each parameter. Regarding the magnitude of the coefficient, as long as it does not affect the proportional relationship between the parameters and the quantified values.

[0049] In addition, those skilled in the art can understand that various aspects of the present invention can be described and illustrated by several patentable types or situations, including any new and useful process, machine, product, or combination of substances, or any new and useful improvement thereof. Accordingly, various aspects of the present invention can be executed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software can all be referred to as "data blocks", "modules", "engines", "units", "components", or "systems". In addition, various aspects of the present invention may be embodied as a computer product located in one or more computer-readable media, which includes computer-readable program codes.

[0050] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a common dictionary should be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and should not be interpreted in an idealized or overly formal sense unless explicitly defined as such herein.

[0051] The foregoing is a description of the present invention and should not be construed as limiting thereof. Although several exemplary embodiments of the present invention have been described, those skilled in the art will readily appreciate that many modifications can be made to the exemplary embodiments without departing from the novel teachings and advantages of the present invention. Accordingly, all such modifications are intended to be included within the scope of the present invention as defined by the claims. It should be understood that the foregoing is a description of the present invention and should not be considered limited to the specific embodiments disclosed, and modifications to the disclosed embodiments as well as other embodiments are intended to be included within the scope of the appended claims. The present invention is defined by the claims and their equivalents.

Claims

1. A data transmission security protection system adapted for a communication base station, characterized in that: It includes a sending end, a communication base station, a receiving end and a blockchain verification unit; The sending end is connected to the receiving end through the network transmission interface of the communication base station, and both the sending end and the receiving end are connected to the blockchain verification unit; The transmitting end is used to encapsulate the original data to be transmitted in combination with the calculated message authentication code and the generated digital signature to form a data transmission packet; The system verifies data integrity through a dual verification mechanism of message authentication code technology combined with digital signatures, where the message authentication code technology is used to verify whether the data has been tampered with during transmission, and the digital signature is used to ensure the authenticity and non-repudiation of the data source; The blockchain verification unit introduces blockchain distributed ledger technology during the data transmission process to provide storage and verification for the transmission records of important data.

2. The data transmission security protection system adapted for a communication base station according to claim 1, characterized in that: The sending end uses a message authentication code to process data transmission, which specifically includes: Use the intrusion detection system and security information and event management system deployed at communication base stations to monitor network traffic and security events in real time and assess the security threat level; Use the performance monitoring module integrated in the communication base station to monitor the use of equipment hardware resources in real time, and evaluate the computing power of the equipment in combination with the hardware configuration parameters; According to the evaluation results of the security threat level and the computing power of the device, the system management module at the sending end selects the appropriate message authentication code algorithm according to the preset decision rules and performs corresponding configuration or initialization settings.

3. The data transmission security protection system adapted for a communication base station according to claim 2, characterized in that: The message authentication code processing method of the sending end also includes: Import the pre-stored keys into the sender and receiver during the device deployment phase through physical storage devices to complete key sharing; or use an advanced key management system to regularly update the shared keys; The communication base station obtains the key pre-shared with the receiving end from the security key storage module, uses the service data and the key as input parameters of the selected message authentication code algorithm module, and calculates the message authentication code value.

4. The data transmission security protection system adapted for a communication base station according to claim 3, characterized in that: The sending end is also used to adopt the elliptic curve digital signature algorithm, use the calculated message authentication code value as the signature object to perform a signature operation, and obtain a digital signature result; and encapsulate the original data to be transmitted, the calculated message authentication code value, and the generated digital signature to form a data transmission package, which is sent to the receiving end through the network transmission interface of the communication base station according to the established communication protocol.

5. The data transmission security protection system adapted for a communication base station according to claim 4, characterized in that: The data transmission packet adopts a layered data structure, including original data, message authentication code value, digital signature, and header information such as data length, data type, message authentication code algorithm identifier, signature algorithm identifier, etc.

6. The data transmission security protection system adapted for a communication base station according to claim 1, characterized in that: The verification process based on blockchain distributed ledger technology includes: The sender uses a hash algorithm to perform a hash operation on the data to be transmitted to obtain a hash value, and combines it with the precise transmission time, sender and receiver identification information to organize it into a data record set; The sender uses the data record set as the transaction content, adds the transaction version number and transaction sequence number, digitally signs it with the private key to form a blockchain transaction, and broadcasts it to the blockchain network; The nodes in the blockchain network verify the format and digital signature of the transaction. The verified transactions are temporarily stored in the local transaction pool and packaged into a new block after meeting certain conditions. Under the consensus mechanism based on the practical Byzantine fault tolerance algorithm, after more than 2 / 3 of the nodes reach a consensus, the new block is added to the blockchain main chain to complete the data on-chain. The receiving end calculates the hash value of the received data, and queries the corresponding transaction record on the blockchain through the blockchain network query interface based on the transmission time, sender and receiver identification information, extracts the hash value, and compares the two to verify data integrity.

Citation Information

Cited By

  • Wifi router online upgrade security verification method and system

    CN120676360A