Low-power-consumption hardware encryption system based on geological disaster monitoring scene

By building a low-power hardware encryption system with hierarchical architecture and dynamic key management, the security protection problems of geological disaster monitoring equipment are solved, data confidentiality and integrity are achieved, and the equipment endurance and real-time analysis are improved.

CN120434040AActive Publication Date: 2025-08-05中国地质环境监测院(自然资源部地质灾害技术指导中心)

Patent Information

Application Number
CN202510863696.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-08-05
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

The existing geological disaster monitoring equipment has problems such as inaccurate power consumption control, insufficient data confidentiality and integrity, vulnerability to attacks, insufficient equipment battery life in terms of security protection, and lacks layered encryption strategies and local analysis capabilities.

Method used

Build the terminal perception layer and the cloud platform layer, use a layered architecture to generate a three-dimensional risk heat map, implement multi-dimensional identity verification and dynamic key management, deploy quantum key terminals to establish a secure channel, combine the active state of the system to perform intelligent power consumption management, and adopt dynamic compression algorithms and security monitoring mechanisms.

Benefits of technology

It enhances the security protection capabilities of geological disaster monitoring equipment, improves the confidentiality and integrity of data transmission, reduces transmission load, extends the equipment battery life, and realizes end-to-end differentiated protection and real-time analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434040A_ABST
    Figure CN120434040A_ABST
Patent Text Reader

Abstract

The invention relates to the field of hardware encryption, and discloses a geological disaster monitoring scene-based low-power-consumption hardware encryption system, which comprises a layered architecture module for constructing a terminal sensing layer and a cloud platform layer, generating a three-dimensional risk thermodynamic diagram, and carrying out short-term early warning model and emergency deduction; the encryption and decryption module is used for carrying out multi-dimensional identity verification based on protocol layering and national secret algorithm fusion, carrying out dynamic management and eavesdropping monitoring on a secret key, optimizing a data processing flow, and establishing a secure channel to dynamically negotiate whether encryption or decryption is needed; the key management module is used for implementing a triple binding mechanism, carrying out processing and risk assessment on the monitoring data, and carrying out key backup and recovery by adopting a dynamic key period according to a generated risk level; and the safety protection module is used for performing intelligent management on the power consumption of the system based on the active state of the system, selecting a compression strategy according to the data type by adopting a dynamic compression algorithm, performing safety monitoring on hardware and firmware, performing intrusion monitoring on the system and performing automatic repair.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of hardware encryption technology, and in particular to a low-power hardware encryption system based on a geological disaster monitoring scenario. Background Art

[0002] In the existing technology, the geological disaster monitoring and early warning network has formed a monitoring and early warning capability covering provinces with high incidence of geological disasters across the country, involving multiple geological disaster hazards, building geological disaster monitoring equipment and monitoring and early warning items. The geological disaster monitoring equipment includes: GNSS receivers, crack meters, inclinometers, accelerometers, moisture meters and rain gauges. The daily average monitoring time series data mainly monitors surface deformation and rainfall, and monitors geological disasters. Geological disasters include landslides, collapses and mud-rock flows, and improve the level of human defense and technical defense capabilities of geological disasters. The current geological disaster monitoring equipment safety protection measures lack accurate control of power consumption according to risk levels, and the data Confidentiality and integrity have not yet been effectively protected; traditional geological disaster monitoring equipment often uses a fixed key cycle, with a single key-to-device binding method, which is easily cracked by long-term eavesdropping; most use standard TLS protocols or single national secret algorithms, lacking a layered encryption strategy, making them vulnerable to man-in-the-middle attacks or protocol vulnerabilities; most systems rely on the cloud to process raw data, resulting in high latency and inability to perform local analysis in disconnected scenarios; traditional equipment lacks firmware integrity verification at startup, resulting in a low detection rate for hardware Trojans; it relies on single-parameter threshold alarms, ignoring the risks of multi-device linkage, resulting in a high false alarm rate; equipment often uses a fixed power consumption mode, with high standby energy consumption, resulting in insufficient battery life for field equipment; In view of this, it is necessary to provide a low-power hardware encryption system based on geological disaster monitoring scenarios to enhance the security protection capabilities of existing geological disaster monitoring equipment, ensure the security of collected data, prevent data theft and tampering, provide confidentiality and integrity of collected data transmission, and ensure network transmission performance. Summary of the Invention

[0003] The purpose of the present invention is to provide a low-power hardware encryption system based on geological disaster monitoring scenarios. In order to solve the above-mentioned existing technical problems, the present invention is implemented through the following technical solutions: The embodiment of the present invention provides a low-power hardware encryption system based on geological disaster monitoring scenarios, including the following modules: Layered architecture module: Build terminal perception layer and cloud platform layer, generate three-dimensional risk heat map, conduct short-term early warning model and emergency simulation; Encryption and decryption module: Based on the integration of protocol layering and national secret algorithms, it performs multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing procedures, and establishes a secure channel to dynamically negotiate whether encryption or decryption is required; Key management module: implements a triple binding mechanism, processes and assesses the risk of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery; Security protection module: Intelligently manages system power consumption based on the system's active status, uses a dynamic compression algorithm, selects compression strategies based on data types, performs security monitoring of hardware and firmware, monitors system intrusions, and automatically repairs them.

[0004] Furthermore, the method for obtaining the terminal perception layer is: Deploy third-generation embedded security terminals, integrating dual-core heterogeneous processors, built-in independent hardware random number generators based on hybrid modeling of MEMS vibration entropy sources and temperature sensor noise, multi-threaded concurrent processing of sensor data, and adding edge computing micro-modules for basic data preprocessing; Furthermore, the cloud platform layer acquisition method is: Adopting a three-level architecture of regional center cloud + provincial core cloud + national disaster recovery cloud, the regional center cloud deploys edge nodes to perform abnormal data cleaning and equipment status monitoring in real time; Furthermore, the method for dynamically managing keys is: Deploy quantum key distribution terminals in high-risk monitoring areas, establish quantum secure channels between gateways and platforms, and implement key update cycles in normal and high-risk modes; Furthermore, the method for optimizing the data processing flow is: Based on the need to use the secure transmission function provided by the encryption and decryption module, call the module initialization interface, the sending processing interface and the receiving processing interface to process the hardware data; A joint regression model of temperature sensor noise and MEMS vibration entropy source is established, and the formula Predict the sensor zero drift, where It represents the rate of temperature change, It represents the vibration acceleration amplitude. and All represent preset time-varying coefficients; Self-calibration is triggered once per calibration cycle, random excitation signals are generated using a hardware random number generator, and compensation parameters are updated using the least squares method. The module initialization interface completes the security parameter negotiation between the IoT terminal and the IoT security gateway, encrypts and decrypts the data based on the security parameters, and after the decryption is completed, the initiator sends a notification payload Furthermore, the excitation signal is obtained by: The 0.5-2kHz frequency band background noise output by the MEMS vibration sensor is set as the main entropy source, and the LSB bit noise of the temperature sensor is set as the auxiliary entropy source through the formula Synthetic excitation signal ,in, It represents the dynamic amplitude, which is dynamically adjusted according to the real-time temperature. It represents the time interval, , It represents a hardware random bit stream; Based on the excitation signal, the original data is denoised by using an improved wavelet threshold; Furthermore, the improved wavelet threshold denoising method is: Based on the excitation signal, the formula Calculate the denoised data after denoising ,in, represents the standard deviation of the noise, It represents the number of data points. It represents the vibration energy adjustment factor, It represents the real-time vibration energy integral value. It represents the preset critical energy threshold; Based on the notification payload, the network data packet sending interface is called when the IoT terminal sends data. After completing the encapsulation of the network data packet and before sending it to the Ethernet / 4G network port, the network data packet sending interface determines whether the network data packet needs to be encrypted; Furthermore, the risk assessment method is: A 1-hour sliding window with a step size of 10 minutes is used to count the number of device anomalies. The abnormal frequency of the i-th device is calculated using the calculation formula. A circular grid with a radius of R is constructed with the target device as the center. The valid neighboring devices are determined to form an adjacency matrix. The number of devices in a high abnormal state in the neighborhood is divided by the total number of devices in the neighborhood to obtain the abnormal device ratio. ,like , it is considered that there is regional abnormal linkage; Based on the obtained core parameters, the number of devices in the neighborhood with the same abnormal parameters as the target device is divided by the total number of devices in the neighborhood to calculate the abnormal parameter overlap of the devices in the neighborhood. ,like , it indicates that the anomaly is caused by similar factors and the risk correlation is higher; Furthermore, the method of adopting a dynamic key period is: The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting. The edge gateway encrypts and stores key logs within 60 days, based on blockchain evidence, and supports key usage record tracing; The cloud platform establishes a key history database, supports cross-device key correlation analysis, and identifies abnormal key reuse behavior; If the device detects a decryption failure, it will automatically switch to the next-newest key version. If decryption fails three times in a row, a key audit on the gateway side will be triggered to verify the validity of the certificate and the matching degree of the key version. If the audit passes, an emergency key will be reissued through an out-of-band channel. Furthermore, the safety monitoring method is: Deploy lightweight IDS based on DPI deep packet monitoring and AI-based behavioral analysis; identify ESP encapsulation field anomalies; By learning the normal communication patterns of devices through LSTM, a secondary warning is triggered for behaviors with a deviation greater than 3σ, where σ represents the standard deviation. Network interruption handling has been enhanced, the local cache has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, an ACK confirmation mechanism has been introduced, and out-of-order reassembly is supported.

[0005] Beneficial effects of the present invention: 1. Enhance the security protection capabilities of existing geological disaster monitoring equipment. Through multi-dimensional binding of physical, environmental, and temporal dimensions, the uniqueness of device identity is enhanced to adapt to the security requirements of different scenarios and achieve end-to-end differentiated protection. The quantum key terminal identifies eavesdropping through bit error rate mutations, reduces transmission load, and improves real-time performance. Pre-processing is achieved through sliding window filtering to eliminate high-frequency noise and the 3σ outlier elimination algorithm. Encrypted data is cached locally and supports offline feature analysis. A hybrid entropy source model is constructed using temperature sensor noise and vibration background noise to improve the quality of random number generation. An adjacency matrix is constructed to calculate the proportion of abnormal devices and parameter overlap, identify regional linkage risks, identify abnormal hardware behavior through current ripple characteristics, and dynamically adjust the power consumption mode to ensure safety protection while improving battery life. 2. Deploy third-generation embedded security terminals, use dual-core heterogeneous processors with multiple sensors to collect data to ensure data security, add edge computing micro-modules to enhance autonomy and real-time performance; clean data and monitor equipment in real time; integrate multi-source data to generate a three-dimensional risk heat map; based on protocol layering and national secret algorithm integration, different communication layers use different encryption protocols to improve communication security and encryption efficiency; deploy quantum key distribution terminals in high-risk areas, establish secure channels, and pre-store quantum key seeds in terminal devices and be able to monitor quantum attacks; set dynamic key cycles according to risk levels, establish a key backup system for intelligent key recovery processes, build a risk assessment model, and generate risk levels based on the frequency of single-device anomalies and the correlation of local grids to provide a basis for key management; achieve precise control of power consumption based on the system's active state; use dynamic compression algorithms to select compression strategies according to data types, warn of abnormal behavior, and establish a self-repair mechanism for key systems and data links. BRIEF DESCRIPTION OF THE DRAWINGS

[0006] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0007] Figure 1 This is a schematic structural diagram of a low-power hardware encryption system based on a geological disaster monitoring scenario provided by Example 1 of the present invention; Figure 2 This is a flowchart of the steps of a low-power hardware encryption system based on a geological disaster monitoring scenario provided by Example 2 of the present invention; Figure 3 This is a schematic diagram of the logical connections of the encryption and decryption modules of a low-power hardware encryption system based on a geological disaster monitoring scenario provided by Example 1 of the present invention. DETAILED DESCRIPTION

[0008] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work should fall within the scope of protection of the present invention.

[0009] Example 1: Figure 1 As shown, an embodiment of the present invention provides a low-power hardware encryption system based on a geological disaster monitoring scenario, which specifically includes the following modules: Layered architecture module: Build terminal perception layer and cloud platform layer, integrate multi-source data fusion algorithm to generate three-dimensional risk heat map, conduct short-term early warning model and emergency simulation; Building a terminal perception layer: Deploy third-generation embedded security terminals with integrated dual-core heterogeneous processors, built-in independent hardware random number generators based on hybrid modeling of MEMS vibration entropy sources and temperature sensor noise, and multi-threaded concurrent processing of sensor data, including but not limited to: GNSS displacement, crack gauge deformation, inclination, acceleration, moisture content, and rainfall; Add an edge computing micromodule to perform basic data preprocessing, including but not limited to sliding window filtering and outlier detection, locally cache encrypted raw data for 30 minutes, and perform offline encrypted raw data feature analysis in network-disconnected scenarios; Specifically, a joint regression model of temperature sensor noise and MEMS vibration entropy source is established, and the formula Predict the sensor zero drift, where It represents the rate of temperature change, It represents the vibration acceleration amplitude. and All represent preset time-varying coefficients; Self-calibration is triggered once per calibration cycle, random excitation signals are generated using a hardware random number generator, and compensation parameters are updated using the least squares method. Specifically, the 0.5-2kHz frequency band background noise output by the MEMS vibration sensor is set as the main entropy source, and the LSB bit noise of the temperature sensor is set as the auxiliary entropy source through the formula Synthetic excitation signal ,in, It represents the dynamic amplitude, which is dynamically adjusted according to the real-time temperature. It represents the time interval, , It represents a hardware random bit stream; Based on the excitation signal, the original data is denoised by the improved wavelet threshold, and the formula Calculate the denoised data after denoising ,in, represents the standard deviation of the noise, It represents the number of data points. It represents the vibration energy adjustment factor, It represents the real-time vibration energy integral value. It represents the preset critical energy threshold; Build a cloud platform layer: adopt a three-level architecture of regional center cloud + provincial core cloud + national disaster recovery cloud. The regional center cloud deploys edge nodes to perform abnormal data cleaning and equipment status monitoring in real time. It should be noted that the provincial core cloud builds a digital twin model based on the Unity digital twin engine, integrates multi-source data fusion algorithms, and generates a three-dimensional risk heat map; the national disaster recovery cloud adopts cross-regional distributed storage and deploys a federated learning system for cross-regional model collaborative training; Built-in disaster prediction AI platform to conduct short-term early warning models and emergency simulations; It should be noted that the short-term warning model is based on the spatiotemporal attention mechanism, supports emergency warning within 1 hour, and integrates the cellular automation model for emergency simulation to simulate the evolution of disasters and output the optimal evacuation route for personnel; Encryption and decryption module: Based on the integration of protocol layering and national secret algorithms, it conducts multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing procedures, and establishes a secure channel for dynamic negotiation to determine whether encryption or decryption is required; The terminal-gateway adopts the lightweight ESPv4+SM4 protocol and uses dynamic payload compression technology to support quantum key pre-distribution; The gateway-platform adopts the national secret TLS1.3+SM2 / SM3 protocol, introduces a dynamic certificate chain verification mechanism, supports differential privacy protection, and has the ability to resist man-in-the-middle attacks; The platform-terminal reverse communication uses SM2 digital signature + SM9 identification password, and the control instructions use two-factor authentication, supporting location-based permission management; Deploy quantum key distribution terminals in high-risk monitoring areas, and establish a quantum secure channel between the gateway and the platform based on the BB84 protocol and decoy state technology. For example, the key update period is 1 minute in normal mode and 10 seconds in high-risk mode; The terminal device pre-stores a quantum key seed and automatically generates a 256-bit symmetric key each time it is powered on. This supports quantum attack monitoring that can identify eavesdropping attempts through sudden changes in the bit error rate. The encryption and decryption module is externally mounted on the network processing module of the IoT terminal; When sending data, after the network processing module completes the encapsulation of the network data packet and before the data packet is sent to the Ethernet / 4G network port, the network data packet processing interface provided by the encryption and decryption module is called to perform data encryption and ESP packet encapsulation. The network processing module then sends the encrypted data packet out from the Ethernet / 4G network port; When receiving data, the network processing module first receives the network data packet from the Ethernet / 4G network port, then calls the network data packet processing interface provided by the encryption and decryption module to decrypt and decapsulate the ESP packet. The network processing module then performs subsequent processing on the decrypted data. The encryption and decryption module provides four types of interfaces: certificate management interface, module initialization interface, network data packet sending and processing interface, and network data packet receiving and processing interface, which facilitate the integration of IoT terminals and encryption and decryption software modules. For example, based on the need to negotiate security parameters with a remote IoT security gateway, and the negotiation process requires the use of digital certificates, the encryption and decryption module provides a certificate management interface for certificate processing, which includes but is not limited to: certificate request generation, certificate import, and certificate deletion; Based on the need to use the secure transmission function provided by the encryption and decryption module, call the module initialization interface, the sending processing interface and the receiving processing interface to process the data; The module initialization interface completes the security parameter negotiation between the IoT terminal and the IoT security gateway. The security parameters are used for subsequent data encryption and decryption. Specifically, the dialogue is based on a message sequence. Message 1: The initiator sends the identity code of its own device to the responder. The identity code includes but is not limited to: device ID, device SN and device PN to ensure that the information is unique across the entire network. Message 2: The responder sends exchange data to the initiator. The exchanged data contains the session key. The session key is encrypted with the identity code and protected by the SM4 symmetric encryption algorithm. The session key is generated by the responder using a random number generator. The data exchanged by the responder is as follows: XCHr=symmetric_Encrypt(key,SN / PN) After receiving the request from the initiator, the responder checks whether the identity code matches the rules and whether the corresponding device is registered; Message 3: After the initiator passes verification, it sends a notification payload and an HMAC payload. Specifically, after receiving message 2, the initiator will parse the corresponding message and decrypt the session key using the identity code; after decryption is completed, the initiator sends a notification payload; Based on the notification payload, the network data packet sending interface is called when the IoT terminal sends data. After completing the encapsulation of the network data packet and before sending it to the Ethernet / 4G network port, the network data packet sending interface determines whether the network data packet needs to be encrypted; If encryption is required, the security parameters obtained during initialization are used for encryption and integrity calculation, and the network data packet is encapsulated in ESP format. Finally, the processed data packet is returned to the caller; After returning to the caller, the network processing module sends the ESP data packet out through the Ethernet / 4G network port; The encrypted file format is shown in Table 1: Table 1 Encrypted file format diagram Based on the encrypted network data packet, the network data packet receiving interface is called when the IoT terminal receives data. After the Ethernet / 4G network port receives the network data and before sending it to the network protocol stack, the network data packet receiving interface determines whether the network data packet needs to be decrypted; If decryption is required, perform integrity check on the network data packet, use the security parameters obtained during initialization to decrypt and decapsulate the ESP format to obtain the original network data packet, and finally return the processing result to the caller; The network processing module sends the original network data packets to the protocol stack for processing; Key management module: implements a triple binding mechanism, processes and assesses the risk of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery; Based on the device registration phase, triple binding is adopted, including: physical binding, environmental binding and time binding; Specifically, the specific method of the physical binding is: burning the unique identification code of the hardware encryption module into the chip fuse bit, which cannot be tampered with; The specific method of the environment binding is: deploying the latitude, longitude and altitude of the location, and performing real-time calibration through BeiDou / GNSS; The specific method of time binding is: obtaining and binding the registration timestamp and the certificate validity period, using the blockchain timestamp service to prevent replay attacks; Acquire monitoring data based on geological hazard monitoring equipment deployed at the geological hazard monitoring site, including but not limited to: GNSS receivers, crack meters, inclinometers, accelerometers, moisture meters, and rain gauges; The original data is lightweight preprocessed based on the edge computing micromodule built into the terminal device to obtain the feature vector; Specifically, outliers are eliminated based on the 3σ principle, and high-frequency noise is eliminated using sliding window filtering. The deformation gradients within a unit period in the horizontal and vertical directions based on the horizontal plane are obtained, the rainfall within 72 hours is obtained, and the average hourly precipitation is calculated. The stress change within a unit period is obtained, and the stress change rate is calculated. Output feature vectors and transmit them to the smart gateway via an encrypted link; A lightweight risk assessment model is built for the NPU neural network processor of the smart gateway based on LSTM and sliding windows, and single device data is analyzed in real time. Monitor single parameter anomalies, build a local risk grid based on LoRaMesh networking data, and analyze the parameter correlation of more than N adjacent devices, for example, when multiple devices experience deformation acceleration at the same time; Generate a preliminary risk level based on the frequency of single device anomalies and the local grid correlation; Specifically, based on the core parameters of geological disaster monitoring equipment, three levels of abnormal thresholds are set; For example, the core parameters of the GNSS receiver are shown in Table 2: Table 2 GNSS receiver core parameter classification statistics Use a 1-hour sliding window with a step length of 10 minutes to count the number of device abnormalities and calculate the formula Calculate the abnormal frequency of the i-th device ,in, It represents the number of data points in the sliding window. Indicates the total number of core parameters. Represents the core parameters The weight of With the target device as the center, a circular grid with a radius of R is constructed, and the valid neighbor devices are determined by Delaunay triangulation to form an adjacency matrix. ; Divide the number of devices in a high abnormal state in the neighborhood by the total number of devices in the neighborhood to get the abnormal device ratio ,like , it is considered that there is regional abnormal linkage; Based on the obtained core parameters, the number of devices in the neighborhood with the same abnormal parameters as the target device is divided by the total number of devices in the neighborhood to calculate the abnormal parameter overlap of the devices in the neighborhood. ,like , it indicates that the anomaly is caused by similar factors and the risk correlation is higher; like or , then the association level is marked as weak association, and the single device is independent and abnormal; like and , then the correlation level is marked as strong correlation, and regional anomalies are linked; Cross-mapping the frequency of single-device anomalies with the local grid correlation to form 1-3 risk levels, including: normal mode, warning mode, and disaster mode; Adopt dynamic key cycles based on risk level; In normal mode, the session SM4 key is updated every 7 days, and the key version number is generated using the HMAC-SM3 algorithm; In early warning mode, updates are made 24 hours a day, and a new temporary emergency key is added to support pre-distribution when the device is offline; In disaster mode, a real-time dynamic key is used, which is destroyed after each communication. A 256-bit random key is generated based on TRNG. In addition to regular updates, key update trigger conditions also include: three consecutive data integrity check failures, device location deviation exceeding the threshold, and abnormal power consumption fluctuations. The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting. The edge gateway encrypts and stores key logs within 60 days, based on blockchain evidence, and supports key usage record tracing; The cloud platform establishes a key history database, supports cross-device key correlation analysis, and identifies abnormal key reuse behavior; If the device detects a decryption failure, it will automatically switch to the next latest key version; If decryption fails three times in a row, a key audit on the gateway side will be triggered to verify the validity of the certificate and the matching degree of the key version. If the audit passes, the emergency key will be reissued through the out-of-band channel; Security protection module: Intelligently manages system power consumption based on system activity status, uses a dynamic compression algorithm, selects compression strategies based on data type, monitors hardware and firmware security, and monitors and automatically repairs system intrusions. Specifically, it is triggered during data transmission and reception / key negotiation, with power consumption ≤ 50mW, full-function operation, cryptographic chip 20MHz, and sensor full-rate sampling; Timed heartbeat / status reporting trigger, power consumption ≤ 15mW, cryptographic chip frequency reduced to 10MHz, sensor sampling rate reduced to 1Hz, only necessary communications processed; Triggered when no data transmission exceeds 30 seconds, power consumption ≤ 5mW, the cryptographic chip enters clock hold mode, the sensor is powered off, and only the RF wake-up circuit is maintained, with a wake-up time of 200ms; Triggered when manually set or when there is no data for a long time, power consumption ≤ 100μW, all modules are powered off, except the RTC real-time clock, which requires an external interrupt to wake up, and the wake-up time is 5s; Use dynamic compression algorithm and select compression strategy according to data type; For example, GNSS coordinate data uses differential decompression with a compression ratio of 8:1; image data uses the SM256 compression algorithm certified by the National Security Agency; and supports batch encryption of data blocks up to 1024 bytes; Hardware Trojan detection through power consumption fingerprint analysis; At each startup, the firmware hash is calculated using the SM3 algorithm and compared with the pre-stored value in the secure storage area to perform firmware integrity verification; It should be noted that the SM3 algorithm is a cryptographic hashing algorithm that pads the message to make its length an integer multiple of 512 bits. The padding method is to add a 1 and several 0s after the message until the length requirement is met. The padded message is divided into 512-bit groups, and each group is processed in turn. Each group is processed using a compression function, which consists of multiple round functions. Each round function contains a series of logical operations and shift operations, and generates a new intermediate state by repeatedly calculating the message group and the intermediate state. The output of the previous round is used as the input of the next round, and all message groups are iteratively processed in sequence. The output of the last round is the hash value of the SM3 algorithm. Deploy lightweight IDS based on DPI deep packet monitoring and AI-based behavioral analysis; identify ESP encapsulation field anomalies; It should be noted that DPI deep packet inspection refers to the ability to identify the application layer protocol and content characteristics carried in the data packet through in-depth inspection of the payload of the network data packet; lightweight IDS refers to a technical system used to monitor unauthorized activities and potential security threats in computer networks; By learning the normal communication patterns of devices through LSTM, a secondary warning is triggered for behaviors with a deviation greater than 3σ, where σ represents the standard deviation. If a key leakage risk is detected: immediately freeze the key and generate a temporary emergency key; initiate the device certificate revocation process; trigger a hardware module self-test, reset the secure storage area, and re-inject a new certificate; Network interruption handling has been enhanced, and the local cache has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, supporting 72-hour power outage retention. It should be noted that non-volatile RAM (NVRAM) storing encrypted data refers to a type of computer memory that retains its stored contents even after power is removed; Optimize breakpoint resuming, introduce ACK confirmation mechanism, and support out-of-order reassembly.

[0010] The technical solution of the embodiment of the present invention is: deploying the third-generation embedded security terminal, using dual-core heterogeneous processors with multiple sensors to collect data, and building in a hardware random number generator based on MEMS vibration entropy source and temperature sensor noise hybrid modeling to ensure data security, adding edge computing micro-modules to perform data preprocessing and caching, and offline analysis when the network is disconnected, to enhance autonomy and real-time performance; real-time data cleaning and monitoring equipment; using the Unity digital twin engine to build models, integrating multi-source data to generate three-dimensional risk heat maps; national disaster recovery cloud to achieve data security storage and cross-regional model collaborative training; emergency simulation uses cellular automaton models to simulate disaster evolution and provide evacuation routes; based on protocol layering and national secret algorithm integration, different communication layers use different encryption protocols to improve communication security and encryption efficiency; deploy quantum key distribution terminals in high-risk areas to establish secure channels, and terminal devices pre-store quantum key seeds and can monitor quantum attacks; when the device is registered A triple binding method of physical, environmental, and time is adopted to set a dynamic key cycle according to the risk level, establish a key backup system for the intelligent key recovery process, pre-process the data of geological disaster monitoring equipment and extract feature vectors, build a risk assessment model, and generate risk levels based on the abnormal frequency of single equipment and the correlation of local grids to provide a basis for key management; realize four-level energy efficiency mode switching according to the system activity state, from active to deep sleep, and accurately control power consumption; adopt a dynamic compression algorithm to select compression strategy according to data type, and monitor hardware Trojans through power consumption fingerprint analysis, verify firmware integrity, deploy a lightweight IDS based on DPI deep packet monitoring and AI behavior analysis, and use LSTM to learn normal communication mode to warn of abnormal behavior, and establish a key system and data link self-repair mechanism.

[0011] Example 2: Figure 2 As shown, an embodiment of the present invention provides a low-power hardware encryption method based on a geological disaster monitoring scenario, which specifically includes the following steps: S1: Build the terminal perception layer and cloud platform layer to generate a three-dimensional risk heat map and conduct short-term early warning models and emergency simulations; S2: Based on the integration of protocol layering and national encryption algorithms, multi-dimensional identity verification is carried out, keys are dynamically managed and eavesdropped on, data processing procedures are optimized, and a secure channel is established to dynamically negotiate whether encryption or decryption is required; S3: Implement a triple binding mechanism to process and assess the risk of monitoring data, adopt dynamic key cycles based on the generated risk level, and perform key backup and recovery; S4: Intelligently manages system power consumption based on system activity, uses a dynamic compression algorithm, selects compression strategies based on data type, monitors hardware and firmware security, and monitors and automatically repairs system intrusions.

[0012] An embodiment of the present invention is described in detail above, but the content described is only a preferred embodiment of the present invention and cannot be considered to limit the scope of implementation of the present invention; the above formulas are all dimensionless and numerical calculations, and the formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field based on actual conditions and historical experience, and can be adjusted according to actual conditions; the above description is only a preferred embodiment of the present invention and is not used to limit the present invention. All equal changes and improvements made according to the scope of application of the present invention should still fall within the scope of the patent coverage of the present invention.

Claims

1. A low-power hardware encryption system based on geological disaster monitoring scenarios, characterized in that: Includes the following modules: Layered architecture module: Build terminal perception layer and cloud platform layer, generate three-dimensional risk heat map, conduct short-term early warning model and emergency simulation; Encryption and decryption module: Based on the integration of protocol layering and national secret algorithms, it performs multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing procedures, and establishes a secure channel to dynamically negotiate whether encryption or decryption is required; Key management module: implements a triple binding mechanism, processes and assesses the risk of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery; Security protection module: Intelligently manages system power consumption based on the system's active status, uses a dynamic compression algorithm, selects compression strategies based on data types, performs security monitoring of hardware and firmware, monitors system intrusions, and automatically repairs them.

2. A low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1, characterized in that: The method for obtaining the terminal perception layer is: Deploy the third-generation embedded security terminal, which integrates a dual-core heterogeneous processor, a built-in independent hardware random number generator based on the hybrid modeling of MEMS vibration entropy source and temperature sensor noise, multi-threaded concurrent processing of sensor data, and adds an edge computing micro-module for basic data preprocessing.

3. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The cloud platform layer acquisition method is: A three-level architecture of regional center cloud + provincial core cloud + national disaster recovery cloud is adopted. The regional center cloud deploys edge nodes to perform abnormal data cleaning and equipment status monitoring in real time.

4. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The method for dynamically managing keys is: Quantum key distribution terminals are deployed in high-risk monitoring areas, and quantum secure channels are established between the gateway and the platform. The key update cycles are normal mode and high-risk mode.

5. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The method for optimizing the data processing flow is: Based on the need to use the secure transmission function provided by the encryption and decryption module, call the module initialization interface, the sending processing interface and the receiving processing interface to process the hardware data; A joint regression model of temperature sensor noise and MEMS vibration entropy source is established, and the formula Predict the sensor zero drift, where It represents the rate of temperature change, It represents the vibration acceleration amplitude. and All represent preset time-varying coefficients; Self-calibration is triggered once per calibration cycle, random excitation signals are generated using a hardware random number generator, and compensation parameters are updated using the least squares method. The module initialization interface completes the security parameter negotiation between the IoT terminal and the IoT security gateway, encrypts and decrypts the data based on the security parameters, and after decryption is completed, the initiator sends a notification payload.

6. A low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 5, characterized in that: The method for obtaining the excitation signal is: The 0.5-2kHz frequency band background noise output by the MEMS vibration sensor is set as the main entropy source, and the LSB bit noise of the temperature sensor is set as the auxiliary entropy source through the formula Synthetic excitation signal ,in, It represents the dynamic amplitude, which is dynamically adjusted according to the real-time temperature. represents the time interval, where , It represents a hardware random bit stream; Based on the excitation signal, the original data is denoised by an improved wavelet threshold.

7. A low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 6, characterized in that: The improved wavelet threshold denoising method is: Based on the excitation signal, the formula Calculate the denoised data after denoising ,in, represents the standard deviation of the noise, It represents the number of data points. It represents the vibration energy adjustment factor, It represents the real-time vibration energy integral value. It represents the preset critical energy threshold; Based on the notification payload, the network data packet sending interface is called when the IoT terminal sends data. After completing the encapsulation of the network data packet and before sending it to the Ethernet / 4G network port, the network data packet sending interface determines whether the network data packet needs to be encrypted.

8. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The risk assessment method is: A 1-hour sliding window with a step size of 10 minutes is used to count the number of device anomalies. The abnormal frequency of the i-th device is calculated using the calculation formula. A circular grid with a radius of R is constructed with the target device as the center. The valid neighboring devices are determined to form an adjacency matrix. The number of devices in a high abnormal state in the neighborhood is divided by the total number of devices in the neighborhood to obtain the abnormal device ratio. ,like , it is considered that there is regional abnormal linkage; Based on the obtained core parameters, the number of devices in the neighborhood with the same abnormal parameters as the target device is divided by the total number of devices in the neighborhood to calculate the abnormal parameter overlap of the devices in the neighborhood. ,like , it indicates that the anomaly is caused by similar factors and the risk correlation is higher.

9. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The method of adopting dynamic key period is: The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting. The edge gateway encrypts and stores key logs within 60 days, based on blockchain evidence, and supports key usage record tracing; The cloud platform establishes a key history database, supports cross-device key correlation analysis, and identifies abnormal key reuse behavior; If the device detects a decryption failure, it will automatically switch to the next latest key version; If decryption fails three times in a row, the gateway-side key audit will be triggered to verify the validity of the certificate and the matching degree of the key version. After the audit passes, the emergency key will be reissued through the out-of-band channel.

10. The low-power hardware encryption system based on geological disaster monitoring scenarios according to claim 1 is characterized in that: The safety monitoring method is: Deploy lightweight IDS based on DPI deep packet monitoring and AI-based behavioral analysis; identify ESP encapsulation field anomalies; By learning the normal communication patterns of devices through LSTM, a secondary warning is triggered for behaviors with a deviation greater than 3σ, where σ represents the standard deviation. Network interruption handling has been enhanced, the local cache has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, an ACK confirmation mechanism has been introduced, and out-of-order reassembly is supported.

Citation Information

Patent Citations

  • Geological disaster system based on national secret algorithm

    CN113904877A

  • Data encryption transmission method based on zero-trust architecture

    CN119966746A

  • Computer distributed storage encryption system

    CN120017383A

  • Information security management method based on data processing

    CN120128361A

  • Data link security management and control system and method based on dynamic encryption

    CN120165965A

Cited By

  • Multi-angle campus panoramic intelligent monitoring system

    CN120711152A

  • Network security inspection system based on big data

    CN121239435A

  • A network security inspection system based on big data

    CN121239435B