Universal Internet of Things security encryption gateway equipment based on meteorological industry
By combining hardware authentication algorithms and TLS encryption technology, the security vulnerabilities in meteorological data transmission are solved, ensuring the security and efficiency of data transmission and enabling point-to-point encrypted transmission between devices and the cloud platform.
Patent Information
- Application Number
- CN202520043849.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2035-01-08
AI Technical Summary
Existing meteorological data transmission methods have security vulnerabilities in encryption algorithms, and the transmission channels have security risks. The risk of data leakage is high, and the encryption and decryption process consumes a lot of computing resources, resulting in low data transmission efficiency.
The system employs hardware authentication algorithms combined with TLS encryption technology, using the HSC3213 encryption chip to encrypt the transmission channel. It also integrates digital signature technology with the central CA unified authentication platform to form a coordinated signature authentication system, ensuring the security and efficiency of data transmission.
It ensures the security and reliability of meteorological data during transmission, prevents data theft or tampering, improves data transmission efficiency, and reduces the consumption of computing resources.
Smart Images

Figure CN223639275U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to the technical field of internet of things gateway equipment especially relates to a general type internet of things security encryption gateway equipment based on meteorological industry. BACKGROUND
[0002] At present, meteorological data transmission mainly relies on traditional wired or wireless communication mode: observation field transmits data to the center server through dedicated communication line such as broadband, optical fiber etc.; wireless communication: the area station without wired link condition transmits data to the center server through wireless network.
[0003] The existing encryption algorithm has security vulnerabilities and is cracked by hackers. There may be security risks in the transmission channel, for example, wireless signals may be intercepted or interfered, access control mechanisms may have vulnerabilities, leading to data leakage, encryption and decryption processes require a large amount of computing resources, resulting in reduced data transmission efficiency; in view of this, a general type internet of things security encryption gateway equipment based on meteorological industry is provided. UTILITY MODEL CONTENT
[0004] The main purpose of the utility model is to provide a general type internet of things security encryption gateway equipment based on meteorological industry, to solve the problem that the existing encryption algorithm in the related art may have security vulnerabilities and be cracked by hackers. There may be security risks in the transmission channel, for example, wireless signals may be intercepted or interfered, access control mechanisms may have vulnerabilities, leading to data leakage, encryption and decryption processes require a large amount of computing resources, resulting in reduced data transmission efficiency.
[0005] In order to achieve the above purpose, according to one aspect of the utility model, a general type internet of things security encryption gateway equipment based on meteorological industry is provided, comprising RK3568J processor, communication unit, memory unit, clock unit and power supply unit;
[0006] Among them, the communication unit includes data encryption module, data transmission module, data acquisition module and identity authentication module;
[0007] The data encryption module is connected to the RK3568J processor through the SPI serial peripheral interface;
[0008] The data transmission module is used for the realization of physical communication link, and the RK3568J processor communicates with external equipment or network through corresponding interface protocol;
[0009] The data acquisition module is used for obtaining meteorological data from external sensor, and then transmitting data to RK3568J processor through UART or CAN protocol for subsequent processing and uploading.
[0010] Further, the data transmission module includes an LTE module, an Ethernet PHY module, an RS232 interface module, an RS485 interface module, and a CAN bus module.
[0011] The LTE module is connected to the RK3568J through a Minipcie interface and communicates through a USB or UART.
[0012] The Ethernet PHY module is connected to the RK3568J processor through an RGMII interface.
[0013] Further, the data acquisition module is composed of an RS232 interface module, an RS485 interface module, and a CAN bus module.
[0014] The RS232 interface module and the RS485 interface module are connected to the RK3568J processor through a UART interface.
[0015] The CAN bus module is connected to the RK3568J processor through a CAN interface.
[0016] Further, the identity authentication module integrates an HSC3213 encryption chip to provide trusted computing services for the RK3568J processor based on a hardware authentication algorithm.
[0017] The HSC3213 encryption chip is connected to the RK3568J processor through an SPI interface.
[0018] Further, the memory unit includes a 4GB LPDDR4 memory module, a 16GB eMMC module, and an EEPROM module.
[0019] The memory unit is connected to the RK3568J processor through an LPDDR4 interface and an eMMC interface.
[0020] The RK3568J processor calls the memory unit to save collected data, key information, and temporary data of a runtime operating system.
[0021] The EEPROM module is used to save key configuration information and parameters required for the RK3568J processor to run.
[0022] Further, the clock unit integrates an AT8340Z real-time clock chip connected to the RK3568J processor through an I2C connection interface to provide a real-time clock function and timestamp data.
[0023] Further, the power supply unit is used for providing power for the RK3568J processor, the communication unit, the memory unit and the clock unit, and the power supply unit comprises a DC-DC power module and a PMIC power management module;
[0024] The DC-DC power module is used for converting a 12V voltage into a 3.3V voltage;
[0025] The PMIC power management module is responsible for generating a plurality of power supplies for the RK3568J processor and other peripheral sub-modules.
[0026] Compared with the prior art, the utility model has the following beneficial effects:
[0027] In the general Internet of Things security encryption gateway device based on the meteorological industry, transmission channel encryption is realized by combining a hardware authentication algorithm with TLS encryption technology, a point-to-point encryption transmission channel of a device and an observation data cloud management and service platform is constructed, and it is ensured that data is not stolen or tampered with in the transmission process;
[0028] The digital signature technology is organically combined with the central CA unified authentication platform to form an upper and lower linkage signature authentication system, automatic digital identity verification of the device is realized, and the identity legality, effectiveness and credibility of the accessed detection device are ensured through automatic issuance of credit certificates and the like.
[0029] It should be understood that the content described in the utility model content part is not intended to limit the key or important features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become apparent through the following description. BRIEF DESCRIPTION OF DRAWINGS
[0030] The above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent by describing in detail the following embodiments with reference to the attached drawings. The attached drawings are used to better understand the present scheme and do not constitute a limitation on the present disclosure. In the drawings, the same or similar reference numerals refer to the same or similar elements, wherein:
[0031] Figure 1 The schematic diagram of the overall structure module of the preferred embodiment of the utility model is shown in the figure;
[0032] Explanation of reference numerals:
[0033] 1, RK3568J processor; 2, communication unit; 21, data encryption module; 22, data transmission module; 23, data acquisition module; 24, identity authentication module; 3, memory unit; 4, clock unit; 5, power supply unit; 51, DC-DC power module; 52, PMIC power management module. DETAILED DESCRIPTION
[0034] To make the purposes, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some but not all of the embodiments of the present disclosure. Based on the embodiments in the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present disclosure.
[0035] In order to make the above-mentioned purposes, features and advantages of the utility model more obvious and easy to understand, the utility model will be further described in detail below with reference to the drawings and specific embodiments.
[0036] Please refer to Figure 1 The utility model provides a general type thing networking security encryption gateway equipment based on meteorological profession, including RK3568J treater 1, communication unit 2, memory unit 3, clock unit 4, communication unit 5 and power supply unit 5;
[0037] Among them, communication unit 2 includes HSC3213 data encryption module 21, data transmission module 22, data acquisition module 23 and identity authentication module 24.
[0038] Data acquisition module 23 transmits external sensor data to RK3568J treater through RS232 / RS485 / CAN, and data acquisition module 23 transmits external sensor data to RK3568J treater 1 through data transmission module 22, and the data collected are encrypted by HSC3213 data encryption module 21, and the identity of the equipment is verified by identity authentication module.
[0039] The HSC3213 data encryption module 21 is connected to the RK3568J treater 1 through the SPI serial peripheral interface;
[0040] The communication unit 5 is composed of data acquisition module 23 and data transmission module 22.
[0041] The data transmission module 22 is used for realizing physical communication link, and the RK3568J treater 1 communicates with external equipment or network through corresponding interface protocol, and the data transmission module 22 includes LTE module, Ethernet PHY module, RS232 interface module, RS485 interface module and CAN bus module;
[0042] Among them, the LTE module is connected with RK3568J through Minipcie interface and communicates through USB or UART;
[0043] The Ethernet PHY module is connected with RK3568J treater through RGMII interface.
[0044] The data acquisition module 23 is used to obtain meteorological data from external sensors, and then transmit the data to the RK3568J processor 1 through UART or CAN protocol for subsequent processing and uploading. The data acquisition module 23 is composed of an RS232 interface module, an RS485 interface module and a CAN bus module;
[0045] The RS232 interface module and the RS485 interface module are connected to the RK3568J processor through the UART interface;
[0046] The CAN bus module is connected to the RK3568J processor through the CAN interface.
[0047] The identity authentication module 24 integrates an HSC3213 encryption chip to provide trusted computing services for the RK3568J processor 1 based on a hardware authentication algorithm (such as device authentication or key verification). The hardware authentication algorithm combines with the TLS encryption technology to realize transmission channel encryption and construct a point-to-point encrypted transmission channel for the device and the observation data cloud management and service platform.
[0048] The HSC3213 encryption chip is connected to the RK3568J processor 1 through the SPI interface.
[0049] The hardware authentication algorithm is specifically: integrating ChaCha20-Poly1305 encryption algorithm, GCM encryption algorithm and SM encryption algorithm based on TLS encryption technology to protect the confidentiality, integrity and identity verification of communication data.
[0050] When implementing TLS-based encryption, the following are the main steps:
[0051] TLS handshake is used to negotiate security parameters, including encryption algorithms and keys. The mathematical process is as follows:
[0052] The client generates a random number , the server generates a random number , and exchanges it to generate a session key;
[0053] Use asymmetric encryption (such as RSA or ECC) to protect key exchange:
[0054] ;
[0055] The client and the server jointly derive a session key , which is used for subsequent communication; represents a key derivation function used to generate a session key from initial data (such as random numbers and pre-master keys); represents a pre-master key, which is generated by the client and encrypted with the server's public key before being transmitted to the server. The server decrypts it to obtain the same pre-master key.
[0056] At the same time, the digital signature technology is organically combined with the central CA unified authentication platform to form a signature authentication system in an up-down linkage, so as to realize automatic digital identity verification of the equipment, and ensure the identity legality, validity and credibility of the accessed detection equipment through automatic issuance of credit certificates and the like.
[0057] The digital signature technology uses an identity authentication means generated by asymmetric encryption technology to ensure the integrity and identity authenticity of the message through private key signature and public key verification.
[0058] The central CA unified authentication platform is responsible for issuing and managing digital certificates, and provides trusted endorsement for the public keys of the equipment and users as an authority of trust.
[0059] When transmitting data, the symmetric encryption algorithm (ChaCha20-Poly1305, AES-GCM or SM4) negotiated is used to encrypt and authenticate the data.
[0060] The memory unit 3 includes a 4GB LPDDR4 memory module, a 16GB eMMC module and an EEPROM module.
[0061] The memory unit is connected with the RK3568J processor through an LPDDR4 interface and an eMMC interface.
[0062] The RK3568J processor calls the memory unit to save collected data, key information and temporary data of a runtime operating system.
[0063] The EEPROM module is used to save key configuration information and parameters (such as device ID and network configuration) required for the RK3568J processor to run.
[0064] The 4GB LPDDR4 memory module is used to support efficient multitasking and temporary storage of runtime data.
[0065] The 16GB eMMC module is connected with the RK3568J processor through an I2C connection interface, and is used to store system logs, meteorological data and configuration files.
[0066] The EEPROM module is used to store device running parameters and fault records.
[0067] The clock unit 4 is integrated with an AT8340Z real-time clock chip, which is connected with the RK3568J processor 1 through an I2C connection interface, and is used to provide a real-time clock function and time stamp data, and to provide power supply for the RTC module through a CR1220 battery when the power is disconnected.
[0068] The power supply unit 5 is used for providing power for the RK3568J processor 1, the communication unit 2, the memory unit 3 and the clock unit 4, and the power supply unit 5 comprises a DC-DC power module 51 and a PMIC power management module 52.
[0069] The DC-DC power module 51 selects an SGM6132 power module, which is used for converting 12V voltage into 3.3V voltage.
[0070] The PMIC power management module 52 selects a PK809-5 power management module, which is responsible for generating multiple power supplies (such as 0.8V, 0.9V, 1.2V, etc.) for the RK3568J processor 1 and other peripheral sub-modules.
[0071] The above specific embodiments of the utility model do not constitute the limitation of the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement within the spirit and principle of the present disclosure should be included in the protection scope of the present disclosure.
Claims
1. A general-purpose Internet of Things security encryption gateway device based on the meteorological industry, characterized in that: It comprises an RK3568J processor (1), a communication unit (2), a memory unit (3), a clock unit (4) and a power supply unit (5); The communication unit (2) comprises a data encryption module (21), a data transmission module (22), a data acquisition module (23) and an identity authentication module (24); The data encryption module (21) is connected to the RK3568J processor (1) through an SPI serial peripheral interface; The data transmission module (22) is used for the realization of a physical communication link, and the RK3568J processor (1) communicates with external devices or a network through a corresponding interface protocol; The data acquisition module (23) is used for acquiring meteorological data from external sensors and transmitting the data to the RK3568J processor (1) through a UART or CAN protocol for subsequent processing and uploading.
2. The weather industry based generic IoT security encryption gateway device according to claim 1, wherein, The data transmission module (22) comprises an LTE module, an Ethernet PHY module, an RS232 interface module, an RS485 interface module and a CAN bus module; The LTE module is connected to the RK3568J through a Minipcie interface and communicates through a USB or UART; The Ethernet PHY module is connected to the RK3568J processor through an RGMII interface. 3.The weather industry based general purpose IoT security encryption gateway device of claim 1, wherein, The data acquisition module (23) is composed of an RS232 interface module, an RS485 interface module and a CAN bus module; The RS232 interface module and the RS485 interface module are connected to the RK3568J processor through a UART interface; The CAN bus module is connected to the RK3568J processor through a CAN interface.
4. The weather industry based generic IoT security encryption gateway device of claim 1, wherein, The identity authentication module (24) integrates an HSC3213 encryption chip to provide trusted computing services for the RK3568J processor (1) based on a hardware authentication algorithm, which realizes transmission channel encryption in combination with a TLS encryption technology and constructs a point-to-point encrypted transmission channel for a device and an observation data cloud management and service platform; The HSC3213 encryption chip is connected to the RK3568J processor (1) through an SPI interface. 5.The weather industry based general purpose IoT security encryption gateway device of claim 1, wherein, The memory unit (3) comprises a 4GB LPDDR4 memory module, a 16GB eMMC module and an EEPROM module; The memory unit (3) is connected to the RK3568J processor (1) through an LPDDR4 interface and an eMMC interface; The RK3568J processor (1) calls the memory unit (3) to save collected data, key information and temporary data of a runtime operating system; The EEPROM module is used for saving key configuration information and parameters required for the RK3568J processor (1) to run.
6. The weather industry based generic IoT security encryption gateway device of claim 1, wherein, The clock unit (4) integrates an AT8340Z real-time clock chip, which is connected to the RK3568J processor (1) through an I2C connection interface to provide a real-time clock function and timestamp data.
7. The weather industry based generic IoT security encryption gateway device of claim 1, wherein, The power supply unit (5) is used for providing power for the RK3568J processor (1), the communication unit (2), the memory unit (3) and the clock unit (4), and the power supply unit (5) comprises a DC-DC power module (51) and a PMIC power management module (52); The DC-DC power module (51) is used for converting 12V voltage into 3.3V; The PMIC power management module (52) is responsible for generating multiple power supplies for the RK3568J processor (1) and other peripheral sub-modules.