Security protection method, device and computer-readable storage medium for IoT terminal

By determining the security level based on the identification of the IoT terminal and performing differentiated protection, the security problem of IoT terminals in unmanned areas is solved, and the overall security of the Internet of Things is improved.

CN115643039BActive Publication Date: 2025-08-26STATE GRID ANHUI ELECTRIC POWER CO LTD +4
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210986068.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-16
Publication Date
2025-08-26
Estimated Expiration
2042-08-16

AI Technical Summary

Technical Problem

The IoT terminal is deployed in an unmanned area and is vulnerable to attacks and is not well configured, making it difficult to apply high-level security protection methods, reducing the difficulty of illegal intrusion.

Method used

Determine the security level based on the identification of the IoT terminal, and perform security verification according to the corresponding security policies, including identity verification and data encryption, and divide it into differentiated protections.

Benefits of technology

Improve the security of IoT terminals, ensure the overall security of the Internet of Things, and prevent illegal intrusion and abnormal connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643039B_ABST
    Figure CN115643039B_ABST
Patent Text Reader

Abstract

One or more embodiments of this specification provide a security protection method, apparatus, and computer-readable storage medium for an IoT terminal. A forwarding node receives a connection request from an IoT terminal, determines the IoT terminal's security level based on the terminal's identifier, and performs a security check on the IoT terminal based on the security level and the corresponding security policy. By classifying IoT terminals into different security levels and employing appropriate and effective security protection policies for IoT terminals of different security levels, the security of IoT terminals can be improved, ensuring the security of the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the field of network security technology, and in particular, to a security protection method, device, and computer-readable storage medium for an Internet of Things terminal. Background Art

[0002] IoT technology has been widely adopted in fields such as electricity and transportation. The IoT consists of a large number of interconnected IoT terminals, and the security of these terminals is directly related to the security of the IoT. Some IoT terminals are deployed in unsupervised areas, making them vulnerable to unauthorized intrusion. Furthermore, due to the low configuration of these terminals, it is difficult to apply high-security protection methods. Some IoT terminals even lack any protection at all, making illegal intrusions less difficult. Summary of the Invention

[0003] In view of this, the purpose of one or more embodiments of this specification is to propose a security protection method, device and computer-readable storage medium for an Internet of Things terminal to solve the security protection problem of the Internet of Things terminal.

[0004] Based on the above objectives, one or more embodiments of this specification provide a security protection method for an IoT terminal, including:

[0005] Receiving a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal;

[0006] Determining a security level of the IoT terminal according to the identifier of the IoT terminal;

[0007] According to the security level, the security of the IoT terminal is checked according to the corresponding security policy.

[0008] Optionally, the IoT terminal is a first control type terminal;

[0009] Determining the security level and corresponding security policy of the IoT terminal according to the identifier of the IoT terminal includes:

[0010] Determining, according to the identifier of the first control-type terminal, that the security level of the first control-type terminal is a first level;

[0011] According to the security level, a security check is performed on the IoT terminal according to the corresponding security policy, including:

[0012] The first control type terminal is authenticated by using a first verification module. If the authentication is successful, a first key is negotiated with the first control type terminal, and ciphertext data encrypted by the first control type terminal using the first key is received.

[0013] Optionally, the IoT terminal is a second control type terminal;

[0014] Determining the security level and corresponding security policy of the IoT terminal according to the identifier of the IoT terminal includes:

[0015] determining, according to the identifier of the second control-type terminal, that the security level of the second control-type terminal is a second level;

[0016] According to the security level, a security check is performed on the IoT terminal according to the corresponding security policy, including:

[0017] The second control type terminal is authenticated by using a second verification module. If the authentication is successful, a second key is negotiated with the second control type terminal, and the ciphertext data encrypted by the second control type terminal using the second key is received.

[0018] Optionally, the IoT terminal is a collection terminal, and the number of connection requests is greater than a preset connection amount threshold;

[0019] Determining the security level and corresponding security policy of the IoT terminal according to the identifier of the IoT terminal includes:

[0020] According to the identification of the acquisition terminal, determining that the security level of the acquisition terminal is the third level;

[0021] According to the security level, a security check is performed on the IoT terminal according to the corresponding security policy, including:

[0022] Receive indicator data from various collection terminals;

[0023] Performing traffic statistics based on the indicator data to obtain traffic statistics results; wherein the traffic statistics results include the maximum value of the indicator data, the total amount of the indicator data, and the type of the indicator data;

[0024] If the total amount of indicator data exceeds the amount of connection requests, the maximum value of the indicator data exceeds the preset normal maximum value, and / or the indicator data type is inconsistent with the acquisition terminal type, a connection rejection response is sent to each acquisition terminal.

[0025] Optionally, before receiving the connection request from the IoT terminal, the method further includes:

[0026] According to the configuration information, function type and data type of the IoT terminal, the terminals are divided into first control type terminals, second control type terminals and collection type terminals.

[0027] Optionally, the method further includes:

[0028] Receive connection requests from other forwarding nodes;

[0029] authenticating the other forwarding nodes;

[0030] If the identity authentication of the other forwarding node is passed, a third key is negotiated with the other forwarding node, and the ciphertext data obtained by encrypting the data by the other forwarding node using the third key is received.

[0031] The embodiments of this specification also provide a security protection device for an IoT terminal, including:

[0032] A receiving module, configured to receive a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal;

[0033] A terminal level determination module, configured to determine the security level of the IoT terminal according to the identifier of the IoT terminal;

[0034] The verification module is used to perform security verification on the IoT terminal according to the security level and the corresponding security policy.

[0035] Optionally, the IoT terminal is a first control type terminal;

[0036] The terminal level determination module is configured to determine, based on the identifier of the first control-type terminal, that the security level of the first control-type terminal is the first level;

[0037] The verification module is used to use the first verification module to authenticate the first control type terminal. If the authentication is successful, negotiate a first key with the first control type terminal and receive the ciphertext data encrypted by the first control type terminal using the first key.

[0038] Optionally, the IoT terminal is a second control type terminal;

[0039] The terminal level determination module is configured to determine, based on the identifier of the second control type terminal, that the security level of the second control type terminal is the second level;

[0040] The verification module is used to use the second verification module to authenticate the second control type terminal. If the authentication is successful, negotiate a second key with the second control type terminal and receive the ciphertext data encrypted by the second control type terminal using the second key.

[0041] Optionally, the IoT terminal is a collection terminal, and the number of connection requests is greater than a preset connection amount threshold;

[0042] The terminal level determination module is configured to determine, based on the identification of the acquisition terminal, that the security level of the acquisition terminal is the third level;

[0043] The verification module is configured to receive indicator data from each acquisition terminal; perform traffic statistics based on the indicator data to obtain traffic statistics results; wherein the traffic statistics results include a maximum value of the indicator data, a total amount of indicator data, and an indicator data type; if the total amount of indicator data exceeds the number of connection requests, the maximum value of the indicator data exceeds a preset normal maximum value, and / or the indicator data type is inconsistent with the acquisition terminal type, a connection rejection response is sent to each acquisition terminal.

[0044] An embodiment of this specification also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the security protection method.

[0045] As can be seen from the foregoing, in the security protection method, apparatus, and computer-readable storage medium for IoT terminals provided in one or more embodiments of this specification, a forwarding node receives a connection request from an IoT terminal, determines the IoT terminal's security level based on the IoT terminal's identifier, and performs a security check on the IoT terminal based on the security level and the corresponding security policy. By classifying IoT terminals into different security levels and adopting corresponding reasonable and effective security protection policies for IoT terminals of different security levels, the security of IoT terminals can be improved, ensuring the security of the Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only one or more embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0047] Figure 1 A schematic diagram of a method flow chart of one or more embodiments of this specification;

[0048] Figure 2 A network diagram of one or more embodiments of this specification;

[0049] Figure 3 A block diagram of the device structure of one or more embodiments of this specification;

[0050] Figure 4 This is a structural block diagram of an electronic device according to one or more embodiments of this specification. DETAILED DESCRIPTION

[0051] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0052] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in one or more embodiments of this specification should have the usual meanings understood by people with ordinary skills in the field to which this disclosure belongs. The "first", "second" and similar words used in one or more embodiments of this specification do not indicate any order, quantity or importance, but are only used to distinguish different components. "Include" or "comprise" and similar words mean that the elements or objects appearing before the word include the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative position relationships. When the absolute position of the object being described changes, the relative position relationship may also change accordingly.

[0053] like Figure 1 、 2 As shown, the embodiment of this specification provides a security protection method for an IoT terminal, including:

[0054] S101: Receive a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal;

[0055] S102: Determine the security level of the IoT terminal according to the identifier of the IoT terminal;

[0056] S103: Perform security verification on the IoT terminal according to the security level and corresponding security policy.

[0057] In this embodiment, the IoT is distributed with several IoT terminals, forwarding nodes, and a central node. Based on the geographic location of the IoT terminals and forwarding nodes, IoT terminals in the same geographic area connect to corresponding forwarding nodes, while forwarding nodes in different geographic areas connect to the central node. For example, several IoT terminals (e.g., electricity meters) in a building connect to one forwarding node, while forwarding nodes in various buildings in the same residential complex connect to one central node.

[0058] When an IoT terminal accesses a forwarding node, it sends a connection request carrying the IoT terminal's identifier to the forwarding node. The forwarding node determines the security level of the IoT terminal based on the IoT terminal's identifier, determines the corresponding security protection strategy based on the security level of the IoT terminal, and performs security verification on the IoT terminal according to the determined security protection strategy.

[0059] In this embodiment, taking into account the diversity of IoT terminals, IoT terminals are divided into first control type terminals, second control type terminals and acquisition type terminals according to the configuration information, function type and data type of the IoT terminals. Each type of IoT terminal is divided into corresponding security levels. For IoT terminals of different security levels, security verification and protection are performed according to different security protection strategies, thereby ensuring the security of various IoT terminals.

[0060] In some embodiments, IoT terminals can be divided into acquisition terminals for data collection and control terminals for data processing and control based on their functions. Acquisition terminals have lower resource allocations, lack data processing capabilities, and are used solely for data collection. Control terminals can be further divided into first and second control terminals based on resource allocation conditions, implemented functions, and the type of data processed. First control terminals, for example, are control terminals with high resource allocations, strong data processing capabilities, and are used to process core data. Second control terminals, for example, are control terminals with high resource allocations, certain data processing capabilities, and are used to process routine data. It is understood that for the different IoT terminals described above, first control terminals are of the highest importance and their security level can be set to the highest level, with the corresponding security protection policy having the highest security. Second control terminals are of the second highest importance and their security level can be set to the second highest level, with the corresponding security protection policy having the second highest security. Acquisition terminals, because they are used solely for data collection, have the lowest security level and their corresponding security protection policy having the lowest security.

[0061] Optionally, the configuration information of the IoT terminal includes but is not limited to computing resources, storage resources, throughput, power supply information, power consumption, and other parameters related to the terminal's working performance.

[0062] Optionally, in an IoT topology, data connections can be established between underlying IoT terminals and forwarding nodes via wired (e.g., serial bus, CAN bus, Ethernet, etc.) or wireless (e.g., Bluetooth, WiFi, ZigBee, LoRa, NB-IoT) communications, depending on distance, configuration, and functionality. Data connections can be established between the central node and each forwarding node via the network. The specific networking method and node connection method are not limited. It is understood that the security level of the forwarding node is higher than the security level of the underlying IoT terminal.

[0063] In some methods, a forwarding node is a node with functions such as data transmission, processing, and forwarding, and has certain requirements for resource configuration. For example, a forwarding node can be a routing node, a relay node, a base station gateway, and other nodes.

[0064] In some embodiments, for the first control type terminal, determining the security level of the IoT terminal and the corresponding security policy based on the identifier of the IoT terminal includes:

[0065] Determining, according to the identifier of the first control-type terminal, that the security level of the first control-type terminal is the first level;

[0066] According to the security level, the IoT terminal is security-verified according to the corresponding security policy, including:

[0067] The first control terminal is authenticated by using the first verification module. If the authentication is successful, a first key is negotiated with the first control terminal, and ciphertext data encrypted by the first control terminal using the first key is received.

[0068] In this embodiment, the security level of the first control-class terminal is set to the first level. When the first control-class terminal accesses the forwarding node, the forwarding node uses the first verification module to authenticate the first control-class terminal, first verifying the legitimacy of the first control-class terminal's identity. Once the identity authentication is successful, the first control-class terminal negotiates with the forwarding node for a first key used to encrypt data. Subsequently, the first control-class terminal and the forwarding node use the negotiated first key to encrypt and decrypt the exchanged data, thereby enabling control and data interaction between the forwarding node and the legitimate first control-class terminal. The security verification algorithm of the first verification module has the highest security. For example, a third-party authentication server can be used to authenticate the first control-class terminal's digital certificate. The specific identity authentication method is not limited.

[0069] If the forwarding node fails to pass the identity authentication of the first control type terminal, a connection rejection request is sent to the first control type terminal, and the security of the Internet of Things is ensured by disconnecting the connection with the first control type terminal. At the same time, a corresponding prompt alarm message can be issued according to the identification of the first control type terminal to prompt the terminal that a security problem may occur, and the terminal can be further tested for security subsequently.

[0070] In some embodiments, for the second control type terminal, determining the security level of the IoT terminal and the corresponding security policy based on the identifier of the IoT terminal includes:

[0071] Determining, according to the identifier of the second control class terminal, that the security level of the second control class terminal is the second level;

[0072] According to the security level, the IoT terminal is security-verified according to the corresponding security policy, including:

[0073] The second control terminal is authenticated by using the second verification module. If the authentication is successful, a second key is negotiated with the second control terminal, and the ciphertext data encrypted by the second control terminal using the second key is received.

[0074] In this embodiment, the security level of the second control-class terminal is set to the second level. When the second control-class terminal accesses the forwarding node, the forwarding node uses the second verification module to authenticate the second control-class terminal, first verifying the legitimacy of the identity of the second control-class terminal. When the identity authentication is successful, the second control-class terminal negotiates with the forwarding node for a second key used to encrypt data. Subsequently, the second control-class terminal and the forwarding node use the negotiated second key to encrypt and decrypt the exchanged data, thereby realizing control and data interaction between the forwarding node and the legitimate second control-class terminal. Among them, the security verification algorithm of the second verification module has the second highest security, the algorithm is relatively simple, and the processing efficiency is high. For example, digital signatures or other cryptographic algorithms can be used to realize the identity authentication between the forwarding node and the second control-class terminal. The specific identity authentication method is not limited.

[0075] If the forwarding node fails to pass the identity authentication of the second control type terminal, a connection rejection request is sent to the second control type terminal. By disconnecting the connection with the second control type terminal, the security of the Internet of Things is ensured. At the same time, a corresponding prompt alarm message can be issued according to the identification of the second control type terminal to prompt the terminal that there may be security problems. The terminal can then be further tested for security.

[0076] In some embodiments, for acquisition terminals, the number of connection requests received by the forwarding node from several acquisition terminals is greater than a preset connection threshold; then,

[0077] Determine the security level of the IoT terminal and the corresponding security policy based on the IoT terminal's identification, including:

[0078] According to the identification of the collection terminal, the security level of the collection terminal is determined to be the third level;

[0079] According to the security level, the IoT terminal is security-verified according to the corresponding security policy, including:

[0080] Receive indicator data from various collection terminals;

[0081] Perform traffic statistics based on the indicator data to obtain traffic statistics results; wherein the traffic statistics results include the maximum value of the indicator data, the total amount of the indicator data, and the type of the indicator data;

[0082] If the total amount of indicator data exceeds the amount of connection requests, the maximum value of the indicator data exceeds the preset normal maximum value, and / or the indicator data type is inconsistent with the acquisition terminal type, a connection rejection response is sent to each acquisition terminal.

[0083] In this embodiment, the security level of collection terminals is set to level three. When a collection terminal accesses a forwarding node, the forwarding node first determines the number of collection terminals. For collection terminals with fewer than a connection threshold, security protection policies such as verification are not implemented. When the number of accessed collection terminals reaches the connection threshold, security verification is required for these collection terminals. Specifically, the forwarding node receives indicator data transmitted by these collection terminals and performs traffic statistics on the received indicator data, including calculating the total indicator data volume, determining the maximum and minimum values ​​in the indicator data, and calculating the type of the indicator data. After obtaining the traffic statistics, the forwarding node compares the total indicator data volume with the number of connection requests from the collection terminals to determine whether there are any illegal, abnormal connections in addition to normal connection requests. The forwarding node compares the maximum and minimum indicator data values ​​with the maximum and minimum indicator data that can be collected by the collection terminal to determine whether there is any abnormal data in the indicator data. The forwarding node compares the indicator data type with the type of the collection terminal to determine whether there is any abnormal data. Through the above data comparison and analysis, if the maximum value of the indicator data exceeds the set normal maximum value, or the indicator data type is inconsistent with the type of the collection terminal, or the total number of indicator data exceeds the actual number of connection requests, it is judged that these collection terminals are abnormal. To ensure the security of the Internet of Things, the forwarding node sends a connection rejection response to each collection terminal, refusing the collection terminal to access the Internet of Things; at the same time, corresponding prompt alarm information can also be issued to prompt the collection terminal that there may be security problems, and further security detection and analysis of these terminals can be carried out subsequently.

[0084] Combine Figure 2 As shown, in some embodiments, the Internet of Things is divided into different security domains according to geographical locations. Within a security domain, there is at least one forwarding node and several IoT terminals connected to the forwarding node. When each IoT terminal connects to the forwarding node, the forwarding node determines the security level of the IoT terminal and performs corresponding security verification on the IoT terminal according to the corresponding security level, thereby realizing the security protection of the IoT terminal within the security domain by the forwarding node. In some methods, the forwarding node also needs to exchange data with forwarding nodes in other security domains. When the forwarding node receives a connection request from another forwarding node, it needs to authenticate the identity of the other forwarding node. If the identity authentication of the other forwarding node is passed, the third key is negotiated with the other forwarding node, and then the two use the negotiated third key to encrypt and decrypt the exchanged data. If the identity authentication of the other forwarding node is not passed, the connection between the forwarding node and the other forwarding node is disconnected, and no more data is transmitted between the two security domains.

[0085] In some methods, the forwarding node is also used to monitor the network status of the security domain in which it is located. The forwarding node periodically obtains the network connection status (number of network connections, network connection speed, etc.) and data throughput (determined based on the amount of data received by the security domain from the IoT terminal, central node and / or other forwarding nodes and the amount of data sent to the IoT terminal, central node and / or other forwarding nodes), etc. within the security domain. Based on the network connection status and / or data throughput, it is determined whether the security domain has an abnormality. For example, when the network connection status is abnormal or the data throughput increases or decreases abnormally, the access volume of the IoT terminal exceeds the preset normal access range, etc., when it is determined that the security domain has an abnormality, the forwarding node disconnects the network connection with the central node and other security domains to prevent security risks from spreading in the Internet of Things, and at the same time sends a reminder alarm message to the central node.

[0086] The embodiments of this specification provide a security protection method for an Internet of Things terminal, which divides the Internet of Things terminal into different security levels according to the configuration, function, data type processed by the Internet of Things terminal, and other conditions, and uses forwarding nodes in the same security domain to perform security verification of the corresponding security level on the Internet of Things terminal, so as to provide hierarchical and classified security protection for the Internet of Things terminal; at the same time, the forwarding nodes and the Internet of Things terminal are divided into different security domains according to the geographical location area, and the forwarding nodes implement the security protection strategy between the security domains, thereby constructing a hierarchical, classified, and domain-based Internet of Things security protection system.

[0087] like Figure 3 As shown, the embodiment of this specification also provides a security protection device for an Internet of Things terminal, including:

[0088] A receiving module, configured to receive a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal;

[0089] A terminal level determination module is used to determine the security level of the IoT terminal based on the identification of the IoT terminal;

[0090] The verification module is used to perform security verification on the IoT terminal according to the security level and the corresponding security policy.

[0091] For the convenience of description, the above devices are described as being functionally divided into various modules. Of course, when implementing one or more embodiments of this specification, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0092] The apparatus of the above embodiment is used to implement the corresponding method in the above embodiment and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0093] Figure 410 is a schematic diagram showing a more specific hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other within the device via the bus 1050.

[0094] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0095] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage devices, dynamic storage devices, etc. The memory 1020 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0096] The input / output interface 1030 is used to connect input / output modules to implement information input and output. The input / output modules can be configured as components within the device (not shown in the figure) or can be externally connected to the device to provide corresponding functions. Input devices may include a keyboard, mouse, touch screen, microphone, various sensors, etc., and output devices may include a display, speaker, vibrator, indicator light, etc.

[0097] The communication interface 1040 is used to connect to a communication module (not shown) to enable communication between the device and other devices. The communication module can communicate via a wired method (such as USB, network cable, etc.) or a wireless method (such as mobile network, WiFi, Bluetooth, etc.).

[0098] The bus 1050 comprises a path for transmitting information between the various components of the device (eg, the processor 1010 , the memory 1020 , the input / output interface 1030 , and the communication interface 1040 ).

[0099] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in a specific implementation, the device may also include other components necessary for normal operation. In addition, it will be understood by those skilled in the art that the above device may only include the components necessary to implement the embodiments of this specification, and does not necessarily include all the components shown in the figure.

[0100] The electronic devices of the above embodiments are used to implement the corresponding methods in the above embodiments and have the beneficial effects of the corresponding method embodiments, which will not be described in detail here.

[0101] The computer-readable media of this embodiment include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0102] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples. Based on the concept of the present disclosure, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of different aspects of one or more embodiments of the present specification as described above, which are not provided in detail for the sake of simplicity.

[0103] In addition, to simplify the description and discussion, and so as not to obscure one or more embodiments of the present specification, well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided figures. In addition, devices may be shown in block diagram form to avoid obscuring one or more embodiments of the present specification, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which one or more embodiments of the present specification will be implemented (i.e., these details should be fully within the purview of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that one or more embodiments of the present specification may be implemented without these specific details or with variations in these specific details. Accordingly, these descriptions should be considered illustrative rather than restrictive.

[0104] Although the present disclosure has been described in conjunction with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0105] The one or more embodiments of this specification are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of this specification shall be included within the scope of protection of this disclosure.

Claims

1. A security protection method for an Internet of Things terminal, applied to a forwarding node, characterized in that: include: Receiving a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal; the IoT terminal includes an acquisition terminal, and the number of the connection requests is greater than a preset connection amount threshold; Determining the security level of the IoT terminal according to the identifier of the IoT terminal includes: determining that the security level of the acquisition terminal is the third level according to the identifier of the acquisition terminal; According to the security level, performing security verification on the IoT terminal in accordance with the corresponding security policy, including: receiving indicator data of each acquisition terminal; Performing traffic statistics based on the indicator data to obtain traffic statistics results; wherein the traffic statistics results include the maximum value of the indicator data, the total amount of the indicator data, and the type of the indicator data; If the total amount of indicator data exceeds the amount of connection requests, the maximum value of the indicator data exceeds the preset normal maximum value, and / or the indicator data type is inconsistent with the acquisition terminal type, a connection rejection response is sent to each acquisition terminal.

2. The method according to claim 1, characterized in that The IoT terminal is a first control type terminal; Determining the security level and corresponding security policy of the IoT terminal according to the identifier of the IoT terminal includes: Determining, according to the identifier of the first control-type terminal, that the security level of the first control-type terminal is a first level; According to the security level, a security check is performed on the IoT terminal according to the corresponding security policy, including: The first control type terminal is authenticated by using a first verification module. If the authentication is successful, a first key is negotiated with the first control type terminal, and ciphertext data encrypted by the first control type terminal using the first key is received.

3. The method according to claim 1, characterized in that The IoT terminal is a second control type terminal; Determining the security level and corresponding security policy of the IoT terminal according to the identifier of the IoT terminal includes: determining, according to the identifier of the second control-type terminal, that the security level of the second control-type terminal is a second level; According to the security level, a security check is performed on the IoT terminal according to the corresponding security policy, including: The second control type terminal is authenticated by using a second verification module. If the authentication is successful, a second key is negotiated with the second control type terminal, and the ciphertext data encrypted by the second control type terminal using the second key is received.

4. The method according to claim 1, wherein Before receiving the connection request from the IoT terminal, it also includes: According to the configuration information, function type and data type of the IoT terminal, the terminals are divided into first control type terminals, second control type terminals and collection type terminals.

5. The method according to claim 1, wherein Also includes: Receive connection requests from other forwarding nodes; authenticating the other forwarding nodes; If the identity authentication of the other forwarding node is passed, a third key is negotiated with the other forwarding node, and the ciphertext data obtained by encrypting the data by the other forwarding node using the third key is received.

6. A security protection device for an IoT terminal, applied to a forwarding node, characterized in that: include: A receiving module, configured to receive a connection request from an IoT terminal; wherein the connection request includes an identifier of the IoT terminal; the IoT terminal is a collection terminal, and the number of connection requests is greater than a preset connection threshold; a terminal level determination module, configured to determine the security level of the IoT terminal according to the identifier of the IoT terminal, including: determining that the security level of the acquisition terminal is the third level according to the identifier of the acquisition terminal; A verification module is used to perform security verification on the IoT terminal according to the security level and the corresponding security policy, including: receiving indicator data of each collection terminal; Performing traffic statistics based on the indicator data to obtain traffic statistics results; wherein the traffic statistics results include the maximum value of the indicator data, the total amount of the indicator data, and the type of the indicator data; If the total amount of indicator data exceeds the amount of connection requests, the maximum value of the indicator data exceeds the preset normal maximum value, and / or the indicator data type is inconsistent with the acquisition terminal type, a connection rejection response is sent to each acquisition terminal.

7. The device according to claim 6, characterized in that The IoT terminal is a first control type terminal; The terminal level determination module is configured to determine, based on the identifier of the first control-type terminal, that the security level of the first control-type terminal is the first level; The verification module is used to use the first verification module to authenticate the first control type terminal. If the authentication is successful, negotiate a first key with the first control type terminal and receive the ciphertext data encrypted by the first control type terminal using the first key.

8. The device according to claim 6, characterized in that The IoT terminal is a second control type terminal; The terminal level determination module is configured to determine, based on the identifier of the second control-type terminal, that the security level of the second control-type terminal is the second level; The verification module is used to use the second verification module to authenticate the second control type terminal. If the authentication is successful, negotiate a second key with the second control type terminal and receive the ciphertext data encrypted by the second control type terminal using the second key.

9. A non-transitory computer-readable storage medium, characterized in that The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Lightweight Internet of Things security key negotiation method based on edge computing

    CN112073379A

  • Safe access method, device and equipment for Internet of Things equipment and medium

    CN114268508A

  • Digital cable and method for intelligently reporting parameters

    CN114900419A