Intranet and extranet data encryption transmission internet edge gateway
By designing an IoT edge gateway for encrypted data transmission between internal and external networks, the problem of remote management of dispersed intelligent devices was solved, enabling unified collection and management of data from multiple systems, reducing costs and improving control efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Filing Date
- 2026-05-06
- Publication Date
- 2026-07-07
AI Technical Summary
In existing technologies, the decentralized local deployment mode of intelligent device management systems makes it difficult to achieve remote management around the clock and without geographical restrictions. Moreover, existing integrated systems have long development cycles and high costs, which cannot meet the needs of small and medium-sized enterprises or small and medium-sized projects.
Design an IoT edge gateway for encrypted data transmission between internal and external networks, comprising hardware and software modules, supporting multiple acquisition protocols, employing national cryptographic algorithms for data encryption, configuring an offline module to ensure no data loss, and achieving remote real-time management through a dual-mode data acquisition method.
It enables unified collection and management of data from multiple systems, reduces hardware procurement and maintenance costs, improves equipment management efficiency and data transmission security, ensures data integrity and confidentiality, and simplifies system deployment processes.
Smart Images

Figure CN122348965A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of IoT edge gateway technology, specifically relating to an IoT edge gateway for encrypted transmission of data between internal and external networks. Background Technology
[0002] Currently, intelligent Internet of Things (IoT) has been widely applied in fields such as smart buildings, smart construction sites, smart mines, and smart factories. Its core is to connect objects to the network through information sensing devices following agreed-upon protocols, thereby completing information exchange and communication, and ultimately achieving functions such as intelligent device identification, status monitoring, and remote control. However, existing intelligent systems have significant limitations in practical applications. Most systems (such as Building Automation Systems (BAS), Supervisory Control and Data Acquisition (SCADA) systems, intelligent lighting systems, power monitoring systems, burglar alarm systems, and video surveillance systems) still operate in a decentralized, localized manner, and are mostly deployed in intranet environments, making it difficult to achieve 24 / 7, geographically unrestricted management of intelligent devices.
[0003] The initial local deployment model was primarily based on considerations of security, reliability, and maintainability, but was also constrained by objective technical conditions. For example, BAS and intelligent lighting systems heavily rely on UDP broadcast for data transmission, resulting in massive amounts of data packets on the network; video surveillance systems have high bandwidth requirements for video streams. These factors limited the system's evolution towards remote and centralized management. Although VPN technology can solve the problem of internal and external network access to some extent, it can only achieve basic internal and external network connectivity and cannot meet the needs of remote real-time device management: it cannot obtain dynamic device data in real time, nor can it quickly issue control commands.
[0004] For unified management of dispersed intelligent systems, existing solutions typically require the additional purchase of an intelligent integration system. However, most integration systems on the market require customized development for specific scenarios, which not only involves long development cycles but also high procurement costs, making them unsuitable for the needs of small and medium-sized enterprises or small-to-medium-sized projects. With the continued growth in demand for working from home and remote monitoring, traditional local deployment models can no longer meet users' core requirements for centralized remote management of devices. Therefore, there is an urgent need for a gateway device that can efficiently connect internal and external networks while balancing security, reliability, and economy to fill the existing technological gap. Summary of the Invention
[0005] To overcome the above-mentioned technical problems, the present invention provides an IoT edge gateway for encrypted transmission of data between internal and external networks.
[0006] The present invention adopts the following technical solution: An IoT edge gateway for encrypted data transmission between internal and external networks comprises hardware and software components. The hardware component includes a processor, memory, solid-state drive, WiFi module, gigabit RJ45 network port, RS485 / 232 serial port, USB interface, and HDMI + VGA interface. The software component includes a data acquisition protocol module, a cache queue module, a data processing module, an encryption module, an offline module, and a communication transmission module. These modules work in sequence to acquire, process, and encrypt data from internal network devices before transmitting it to an external network server. The gateway also supports local storage and recovery of data during network interruptions, enabling remote centralized management of intelligent devices.
[0007] Preferably, the acquisition protocol module supports Bacnet, Knx, Mbus, Modbus, IEC104, SNMP, Ppi, Fins, GB26875, and GB28181 protocols, and is compatible with various intelligent devices / subsystems in the fields of smart buildings, smart construction sites, smart mines, and smart factories.
[0008] Preferably, the Bacnet and Knx protocols acquire data using a combination of active reading and passive reporting. The corresponding program includes a polling thread, a broadcast listening thread, and a control thread. The polling thread actively reads the temperature, humidity, and status data of the device in sequence. The broadcast listening thread listens for broadcast notification data of device status updates in the network. The control thread issues control commands, and after the control commands are issued, it prioritizes actively reading the data of the controlled device.
[0009] Preferably, the implementation process of the IEC104 protocol is as follows: 1) The gateway, acting as the master station, establishes a TCP connection with the slave station. The master station sends a start frame to the slave station, and the slave station replies with a start confirmation frame. 2) The master station sends a general call command to the slave station, and the slave station replies with a general call confirmation; 3) Upload remote signaling, telemetry, and electricity metering I-frame information frames from the slave station, and send a general call-off end frame after completion; 4) After receiving the end frame, the master station replies with an S frame to confirm and enters the next communication cycle.
[0010] 5. The IoT edge gateway according to claim 1, wherein the encryption module adopts a full-link national cryptographic algorithm, including the SM2 asymmetric encryption algorithm, the SM3 hash algorithm, and the SM4 symmetric encryption algorithm; wherein the SM2 algorithm is used for digital signature and key exchange to verify the identities of the communicating parties; the SM3 algorithm is used to generate a digital digest of the original data to verify the integrity of data transmission; and the SM4 algorithm uses the session key negotiated by SM2 to encrypt and decrypt the communication content to ensure data confidentiality.
[0011] Preferably, the cache queue module uses a Redis key-value storage database, including a point exchange cache queue and a point status cache queue; the point exchange cache queue includes a Bacnet queue, a Knx queue, an Mbus queue, an IEC104 queue, an SNMP queue, an OPC queue, a Dev queue, and a Poi queue, wherein the Dev queue and the Poi queue are standardized queues that support uploading after data processing, and the rest are dedicated queues for communication protocols; the point status cache queue includes a point status set, a point alarm set, and a data statistics set.
[0012] Preferably, the offline module is configured with an OceanBase local database and uses cloud service heartbeat detection to determine network status. When a network interruption is detected, data is routed to the offline module for local storage and is not sent to the cloud. When the network is restored, the data stored offline is automatically re-uploaded to the external network server to ensure that the data is not lost.
[0013] Preferably, the data processing module includes data cleaning and filtering, alarm processing, linkage processing, and bypass processing; the data cleaning and filtering filters out expired data, duplicate data, and invalid data; the alarm processing marks alarm data according to preset alarm trigger conditions and reports it to the server; the linkage processing automatically sends linkage control commands to devices / subsystems according to preset linkage trigger conditions; the bypass processing determines bypass data based on the bypass identifier, and bypass data is not reported, alarm processed, or linkage processed.
[0014] Preferably, the communication transmission module uses UDP communication to realize Socket communication between the edge gateway and the external network server; the external network server adopts a multi-threaded or asynchronous I / O model to receive data in a non-blocking manner, process data asynchronously, and manage tasks to be processed through a thread pool and task queue to improve concurrent processing capabilities.
[0015] Preferably, it also includes a Tengine local management terminal based on Nginx, providing an efficient, stable, and secure web management platform; the HDMI interface supports 4096×2160@60Hz display output, the VGA interface supports 1920×1200@60Hz display output, and the Mbus protocol, Modbus protocol, Snmp protocol, Ppi protocol, and Fins protocol actively read device data through a polling thread, and issue control commands through a control thread and prioritize reading the data of the controlled device.
[0016] Compared with the prior art, the beneficial effects of the present invention are: The gateway's data acquisition protocol module supports multiple mainstream protocols such as Bacnet, Knx, Mbus, Modbus, IEC104, Snmp, Ppi, Fins, GB26875, and GB28181. It can be directly adapted to various intelligent devices and subsystems in fields such as smart buildings, smart construction sites, smart mines, and smart factories. There is no need to configure a dedicated gateway for different systems. A single device can achieve unified data acquisition and management of multiple systems, which greatly reduces hardware procurement costs and the technical complexity of interfacing with multiple systems. Remote real-time management enhances device control efficiency. Compared to the limitations of VPNs, which only provide basic connectivity, this gateway supports a dual-mode data acquisition method of "active reading + passive reporting": For Bacnet and Knx protocol devices, data such as temperature, humidity, and device status can be collected sequentially through a polling thread, while a broadcast listening thread receives real-time device status update notifications; for Mbus and Modbus protocol devices, data can be efficiently acquired through a polling thread; the control threads for all protocols support real-time control command issuance, and after the command is issued, the status of the controlled device will be actively read first to ensure the effectiveness of the command execution. Regardless of the location of the administrator, they can monitor the device dynamics in real time and complete remote control, improving device control efficiency.
[0017] The gateway encryption module employs SM2, SM3, and SM4 national cryptographic algorithms to construct a comprehensive security protection system: the SM2 asymmetric encryption algorithm is used for digital signatures and key exchange, effectively verifying the identities of both communicating parties and preventing identity impersonation risks; the SM3 hash algorithm generates a unique "digital fingerprint" for the original data, and if the data is tampered with during transmission, the "fingerprint" will change significantly, allowing for real-time verification of data integrity; the SM4 symmetric encryption algorithm, based on the session key negotiated by SM2, encrypts the communication content at high speed, ensuring that even if the data is intercepted, unauthorized parties cannot obtain valid data content, comprehensively protecting the confidentiality and security of data transmission between internal and external networks.
[0018] Offline data protection ensures no data loss. The gateway is configured with an offline module and an OceanBase local database. The network status is determined in real time through cloud service heartbeat detection: when a network interruption is detected, the data is automatically routed to the offline module and stored in the local database to avoid data loss; after the network is restored, the data stored offline is automatically re-uploaded to the external network server. Data retransmission can be completed without manual intervention, which not only ensures data continuity but also significantly reduces the operation and maintenance costs in network interruption scenarios.
[0019] Data preprocessing reduces workload and optimizes system operating efficiency. The gateway's data processing module can perform data cleaning and filtering, alarm handling, linkage processing, and bypass processing: by filtering out expired, duplicate, and invalid data, the amount of data transmitted to the server is reduced; alarm data is marked and reported according to preset alarm trigger conditions, reducing the server's data judgment pressure; control commands are automatically issued based on linkage rules, responding to equipment anomalies without manual intervention; data marked as "bypass" is not reported or further processed, further simplifying the process. Through full-process data preprocessing, the operating efficiency of the gateway and server can be significantly optimized, reducing the overall system load.
[0020] Low-cost alternative to customized integrated systems, improving cost-effectiveness. This gateway can directly realize remote centralized management of multiple systems without the need to purchase additional customized intelligent integrated systems. This not only shortens the project deployment cycle, but also reduces procurement costs and subsequent maintenance costs. Whether it is a small or medium-sized project or a large and complex scenario, it can achieve remote control of intelligent devices with higher cost performance. Attached Figure Description
[0021] Figure 1 This is an overall schematic diagram of the invention; Figure 2 This is the flowchart of the module execution in this solution; Figure 3 This is the network topology diagram for this solution. Detailed Implementation
[0022] The embodiments of the present invention are described in detail below. Examples of the embodiments are shown in the accompanying drawings. Unless otherwise specified, the raw materials and equipment used can be purchased from the market or are commonly used in the art. The methods in the embodiments, unless otherwise specified, are conventional methods in the art. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0023] IoT edge gateway for encrypted data transmission between internal and external networks 1. Hardware components The hardware parameters for this solution are as follows: Processor: Intel® Core™ i5-7200U (2.5GHz up to 3.1GHz, 2 cores, 4 threads) Memory: 8GB (single SO-DIMMSlot) Hard drive: 128GB wide-temperature-range solid-state drive WiFi: Built-in Network ports: 2*RJ45 Intel I210 (10 / 100 / 1000Mbps) Serial ports: 2*RS485 / 232 USB: 2*USB2.0 + 4*USB3.0 Display: 1xHDMI, 4096*216060Hz, 1xVGA, 1920*120060Hz Dimensions: 160mm*127mm*53mm Net weight: 1.2kg Operating temperature: -20~60°C Relative humidity: 5~95% Input voltage: DC-12V.
[0024] 2. Software component This solution includes the following modules: Acquisition protocol modules include Bacnet, Knx, Mbus, Modbus, IEC104, Snmp, Ppi (Siemens), Fins (Omron), GB26875, and GB28181 protocols.
[0025] 1) The Bacnet and Knx protocols acquire data using active reading and passive reporting methods. The program includes a polling thread, a broadcast listening thread, and a control thread. The polling thread is responsible for actively reading data such as temperature, humidity, and status from the devices in sequence; the broadcast listening thread is responsible for listening for status update data reported by devices in the network (the Bacnet and Knx protocols will actively send broadcast notifications after a device's status changes); the control thread is responsible for issuing control commands, and after a control command is issued, it will prioritize actively reading the controlled devices.
[0026] 2) The Mbus, Modbus, SNMP, PPI, and Fins protocols acquire data through active reading. The program includes a polling thread and a control thread. The polling thread is responsible for actively reading data such as temperature, humidity, and status of the device in sequence; the control thread is responsible for issuing control commands, and after the control command is issued, it will prioritize actively reading the controlled device.
[0027] 3) IEC104 Protocol: The IEC104 protocol is an international standard widely used in industries such as power and urban rail transit. The program establishes a TCP connection and sends a start frame to the slave station through this gateway device (master station). Upon receiving the start frame, the slave station sends a start confirmation frame to the master station. The master station sends a general call to the slave station. Upon receiving the general call command from the master station, the slave station sends a general call confirmation to the master station. The slave station uploads I-frame information frames such as telemetry, telemetry, and electricity consumption data. After sending all data, the slave station sends a general call end frame. Upon receiving the end frame from the slave station, the master station replies with an S-frame confirmation frame and enters the next cycle.
[0028] Cache queue module: Utilizes Redis, an open-source, high-performance key-value store database that provides various data structures for storing data, such as strings, hashes, lists, sets, and sorted sets. Redis stores data in memory to provide fast read and write access and can asynchronously persist data to disk, making it suitable for caching, message queues, short-term data storage, and high-performance applications.
[0029] 1) The point-to-point exchange buffer queues include Bacnet queue, Knx queue, Mbus queue, IEC104 queue, SNMP queue, OPC queue, Dev queue, and Poi queue. Among them, the Dev queue and Poi queue are standardized queues that support uploading after data processing, while the other queues are dedicated queues for communication protocols.
[0030] 2) The location status cache queue includes a location status set, a location alarm set, and a data statistics set.
[0031] Data Processing Module: This module includes data cleaning and filtering, alarm processing, linkage processing, and bypass processing. Data cleaning and filtering primarily targets and eliminates expired, duplicate, and invalid data to ensure data validity and reduce the amount of data processed in subsequent alarm, linkage, and bypass processing. Alarm processing identifies alarm data based on pre-set alarm trigger conditions and reports it to the server, reducing the server's processing load. Linkage processing automatically sends linkage control commands to devices / subsystems after triggering linkage based on pre-set linkage trigger conditions. Bypass processing determines whether data is bypassed; if it is, it will not be reported, including skipping alarm and linkage processing.
[0032] Encryption module: The entire chain adopts national cryptographic algorithms (SM2 signature, SM3 hash, SM4 encryption).
[0033] SM2: Used for digital signatures and key exchange (asymmetric encryption) to verify the identities of both parties in a communication and prevent impersonation.
[0034] SM3: Used to generate digital digests / hashes (hash algorithms), it generates a unique, fixed-length "digital fingerprint" for the original data. Any slight change to the data will completely change the fingerprint, which is used to verify whether the data has been tampered with during transmission.
[0035] SM4: Used for encryption and decryption of data content (symmetric encryption). It uses the session key negotiated by SM2 to encrypt and decrypt actual, large amounts of communication content (such as messages and files) at high speed, ensuring data confidentiality and preventing eavesdropping.
[0036] Communication Transmission Module: The edge gateway communicates with the server using UDP. Server Architecture: Employs a multi-threaded or asynchronous I / O model to fully utilize system resources and improve concurrent processing capabilities. Data Reception and Processing: Uses a non-blocking method to receive data, avoiding blocking threads or processes during data reception; uses an asynchronous method to process data, avoiding blocking threads or processes during data processing. Thread Pool and Task Queue: Manages tasks using a thread pool and a task queue. The thread pool allocates thread resources, and the task queue stores tasks awaiting processing.
[0037] Offline Module: The gateway's offline processing module is one of its core functions, designed to ensure that data is not lost in the event of a network outage and can be re-uploaded once the network is restored. It uses a heartbeat detection (Keep-Alive) mechanism for cloud services; once an offline status is detected, data is not sent to the cloud but is instead routed to the offline processing module for local storage.
[0038] Local database: OceanBase is used. OceanBase is a completely self-developed enterprise-grade native distributed database with features such as cloud-native, strong consistency, and high compatibility with Oracle / MySQL.
[0039] Local management: Tengine is used, which is a web server project based on Nginx, providing an efficient, stable, secure and easy-to-use web platform.
[0040] Although embodiments of the present invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and variations can be made to the above embodiments without departing from the principles and spirit of the present invention, the scope of which is defined by the claims and their equivalents.
Claims
1. An IoT edge gateway for encrypted data transmission between internal and external networks, characterized in that: It includes hardware and software components. The hardware components include: a processor, memory, a solid-state drive, a WiFi module, a gigabit RJ45 network port, an RS485 / 232 serial port, a USB interface, and an HDMI interface + VGA interface. The software components include a data acquisition protocol module, a cache queue module, a data processing module, an encryption module, an offline module, and a communication transmission module. These modules work together to acquire, process, and encrypt data from intranet devices before transmitting it to an external network server. They also support local storage and recovery of data during network interruptions, enabling remote centralized management of intelligent devices.
2. The IoT edge gateway according to claim 1, characterized in that, The acquisition protocol module supports Bacnet, Knx, Mbus, Modbus, IEC104, Snmp, Ppi, Fins, GB26875, and GB28181 protocols, and is compatible with various intelligent devices / subsystems in the fields of smart buildings, smart construction sites, smart mines, and smart factories.
3. The IoT edge gateway according to claim 2, characterized in that, The Bacnet and Knx protocols acquire data using a combination of active reading and passive reporting. The corresponding program includes a polling thread, a broadcast listening thread, and a control thread. The polling thread actively reads the temperature, humidity, and status data of the device in sequence. The broadcast listening thread listens for broadcast notifications of device status updates in the network. The control thread issues control commands, and after the control commands are issued, it prioritizes actively reading the data of the controlled device.
4. The IoT edge gateway according to claim 2, characterized in that, The implementation process of the IEC104 protocol is as follows: 1) The gateway, acting as the master station, establishes a TCP connection with the slave station. The master station sends a start frame to the slave station, and the slave station replies with a start confirmation frame. 2) The master station sends a general call command to the slave station, and the slave station replies with a general call confirmation; 3) Upload remote signaling, telemetry, and electricity metering I-frame information frames from the slave station, and send a general call-off end frame after completion; 4) After receiving the end frame, the master station replies with an S frame to confirm and enters the next communication cycle.
5. The IoT edge gateway according to claim 1, characterized in that, The encryption module adopts a full-link national cryptographic algorithm, including the SM2 asymmetric encryption algorithm, the SM3 hash algorithm, and the SM4 symmetric encryption algorithm. Among them, the SM2 algorithm is used for digital signature and key exchange to verify the identities of the communicating parties; the SM3 algorithm is used to generate digital digests of the original data to verify the integrity of data transmission; and the SM4 algorithm uses the session key negotiated by SM2 to encrypt and decrypt the communication content to ensure data confidentiality.
6. The IoT edge gateway according to claim 1, characterized in that, The cache queue module uses a Redis key-value storage database and includes a point exchange cache queue and a point status cache queue. The point exchange cache queue includes Bacnet queue, Knx queue, Mbus queue, IEC104 queue, SNMP queue, OPC queue, Dev queue, and Poi queue. Among them, the Dev queue and Poi queue are standardized queues that support data uploading after processing, while the others are dedicated queues for communication protocols. The point status cache queue includes a point status set, a point alarm set, and a data statistics set.
7. The IoT edge gateway according to claim 1, characterized in that, The offline module is configured with a local OceanBase database and uses cloud service heartbeat detection to determine network status. When a network interruption is detected, data is routed to the offline module for local storage and is not sent to the cloud. Once the network is restored, the offline stored data is automatically re-uploaded to the external server to ensure that no data is lost.
8. The IoT edge gateway according to claim 1, characterized in that, The data processing module includes data cleaning and filtering, alarm processing, linkage processing, and bypass processing. The data cleaning and filtering filters out expired, duplicate, and invalid data. The alarm processing marks alarm data according to preset alarm trigger conditions and reports it to the server. The linkage processing automatically sends linkage control commands to devices / subsystems according to preset linkage trigger conditions. The bypass processing determines bypass data based on its bypass identifier; bypass data is not reported, alarm processed, or linkage processed.
9. The IoT edge gateway according to claim 1, characterized in that, The communication transmission module uses UDP communication to realize Socket communication between the edge gateway and the external network server; the external network server adopts a multi-threaded or asynchronous I / O model to receive data in a non-blocking manner and process data asynchronously, and manages the tasks to be processed through a thread pool and task queue to improve the concurrent processing capability.
10. The IoT edge gateway according to claim 1, characterized in that, It also includes the Tengine local management terminal based on Nginx, providing an efficient, stable, and secure web management platform; the HDMI interface supports 4096×2160@60Hz display output, the VGA interface supports 1920×1200@60Hz display output, and the Mbus, Modbus, Snmp, Ppi, and Fins protocols actively read device data through a polling thread, and issue control commands through a control thread and prioritize reading the data of the controlled device.