Wireless internet of things data security management method and device
By encrypting data in a wireless IoT system using a preset key and encryption algorithm parameters, and splitting the key into two parts and transmitting them through different transmission channels, the problem of insufficient data transmission security in wireless IoT is solved, and high data transmission security is achieved.
Patent Information
- Application Number
- CN202211459712.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-16
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-11-16
AI Technical Summary
In wireless IoT scenarios, data transmission security is insufficient, and existing technologies are unable to effectively improve it.
The data to be transmitted is encrypted using a preset key and preset encryption algorithm parameters. The key is split into two parts and transmitted through different data transmission channels to ensure that the encryption algorithm parameters and part of the key are sent through separate channels.
Even if a portion of the key is cracked, the data cannot be decrypted, ensuring the security of data transmission and improving the security of wireless IoT data transmission.
Smart Images

Figure CN115714684B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a wireless Internet of Things data security management method and device. BACKGROUND
[0002] With the rapid development of communication technology and electronic technology, modern human life has become more and more different, and various electronic products serving people have also become more and more.
[0003] In life, the Internet of Things has become an important application of electronic devices (such as mobile phones, tablet computers, etc.), and the Internet of Things enables the interconnection of things, greatly facilitating the life of users. Although the Internet of Things can realize fast data transmission, the security of data has always been the focus of users, so how to improve the security of data transmission in the wireless Internet of Things scene is an urgent problem to be solved. SUMMARY
[0004] The embodiments of the present application provide a wireless Internet of Things data security management method and device, which can improve the security of data transmission in the wireless Internet of Things scene.
[0005] In a first aspect, the embodiments of the present application provide a wireless Internet of Things data security management method applied to an electronic device in a wireless Internet of Things system, the wireless Internet of Things system comprising the electronic device and a plurality of Internet of Things devices connected to the electronic device, and the method comprising:
[0006] Obtaining to-be-transmitted data and a receiving device, the receiving device being one of the plurality of Internet of Things devices;
[0007] Encrypting the to-be-transmitted data using a preset key and a preset encryption algorithm parameter to obtain target to-be-transmitted data;
[0008] Splitting the preset key to obtain a first part of the key and a second part of the key;
[0009] Determining three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels comprising a first data transmission channel, a second data transmission channel and a third data transmission channel;
[0010] Transmitting the target to-be-transmitted data to the receiving device through the first data transmission channel;
[0011] Transmitting the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel;
[0012] Transmitting the second part of the key to the receiving device through the third data transmission channel.
[0013] In a second aspect, an embodiment of the present application provides a wireless Internet of Things data security management device applied to an electronic device in a wireless Internet of Things system, the wireless Internet of Things system comprising the electronic device and a plurality of Internet of Things devices connected to the electronic device, and the device comprising an acquisition unit, an encryption unit, a splitting unit, a determination unit and a transmission unit, wherein
[0014] The acquisition unit is configured to acquire to-be-transmitted data and a receiving device, the receiving device being one of the plurality of Internet of Things devices.
[0015] The encryption unit is configured to encrypt the to-be-transmitted data by using a preset key and a preset encryption algorithm parameter to obtain target to-be-transmitted data.
[0016] The splitting unit is configured to split the preset key to obtain a first part of the key and a second part of the key.
[0017] The determination unit is configured to determine three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels comprising a first data transmission channel, a second data transmission channel and a third data transmission channel.
[0018] The transmission unit is configured to transmit the target to-be-transmitted data to the receiving device through the first data transmission channel, transmit the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel, and transmit the second part of the key to the receiving device through the third data transmission channel.
[0019] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor, a memory, a communication interface and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the processor, and the programs comprise instructions for performing the steps in the first aspect of the embodiments of the present application.
[0020] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium storing a computer program for electronic data exchange, wherein the computer program causes a computer to perform some or all of the steps described in the first aspect of the embodiments of the present application.
[0021] In a fifth aspect, an embodiment of the present application provides a computer program product comprising a non-transitory computer readable storage medium storing a computer program, the computer program being operable to cause a computer to perform some or all of the steps described in the first aspect of the embodiments of the present application. The computer program product can be a software installation package.
[0022] The embodiments of the present application have the following beneficial effects:
[0023] It can be seen that the wireless Internet of Things data security management method and device described in the embodiments of the present application are applied to an electronic device in a wireless Internet of Things system, the Internet of Things system includes the electronic device, and a plurality of Internet of Things devices connected with the electronic device, the receiving device is one of the plurality of Internet of Things devices, the preset key and the preset encryption algorithm parameter are used to encrypt the to-be-transmitted data to obtain target to-be-transmitted data, the preset key is split to obtain a first part of the key and a second part of the key, three data transmission channels between the to-be-transmitted data and the receiving device are determined, the three data transmission channels include a first data transmission channel, a second data transmission channel and a third data transmission channel, the target to-be-transmitted data is transmitted to the receiving device through the first data transmission channel, the first part of the key and the preset encryption algorithm parameter are transmitted to the receiving device through the second data transmission channel, and the second part of the key is transmitted to the receiving device through the third data transmission channel. First, the to-be-encrypted data is encrypted by the key and the encryption algorithm parameter to ensure the data transmission security, and the data is transmitted through different data transmission channels from the key. Second, the key is split into two parts, and the two parts of the key are transmitted through different data transmission channels. Even if a part of the key is cracked, the data cannot be decrypted. Third, the encryption algorithm parameter is also sent to the receiving device together with a part of the key through a separate data transmission channel. Therefore, even if the data of any one or two data transmission channels is cracked, the target to-be-transmitted data cannot be decrypted, and thus the data transmission security is ensured. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0025] Figure 1 is a structural schematic diagram of a wireless Internet of Things system provided by the embodiments of the present application;
[0026] Figure 2 is a flowchart of a wireless Internet of Things data security management method provided by the embodiments of the present application;
[0027] Figure 3 is a structural schematic diagram of an electronic device provided by the embodiments of the present application;
[0028] Figure 4is a functional unit composition block diagram of a wireless Internet of Things data security management device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0029] In order for those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0030] The terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product, or device.
[0031] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The appearance of the phrase in various places in the specification does not necessarily all refer to the same embodiment, nor is it necessarily mutually exclusive of other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0032] The Internet of Things device or electronic device described in the embodiments of the present application can include at least one of the following: a smart light lighting device, a smart phone, a smart power distribution box, a smart switch controller, a smart control panel, a smart power socket, a smart gateway, a smart coordinator, a smart node, a smart router, a smart set-top box, a smart meter, a smart television, a tablet computer, a smart refrigerator, a smart washing machine, a smart massage chair, a smart office table, a smart air conditioner, a smart humidifier, an edge server, a smart range hood, a smart microwave oven, a smart water purifier, a smart rice cooker, a smart heater, a smart door, a smart fan, a smart water dispenser, a smart curtain, a smart toilet, a smart phone, a smart security system, smart furniture, a smart sweeping robot, and the like, without limitation.
[0033] The embodiments of the present application will be described in detail below.
[0034] Please refer to Figure 1 , Figure 1A wireless Internet of Things system structure schematic diagram provided by an embodiment of the present application, the wireless Internet of Things system comprising an electronic device and a plurality of Internet of Things devices connected to the electronic device, as shown, the wireless Internet of Things provided by the embodiment of the present application can perform the following functions, which are applied to the electronic device, as follows:
[0035] Obtaining to-be-transmitted data and a receiving device, the receiving device being one of the plurality of Internet of Things devices;
[0036] Encrypting the to-be-transmitted data using a preset key and a preset encryption algorithm parameter to obtain target to-be-transmitted data;
[0037] Splitting the preset key to obtain a first part of the key and a second part of the key;
[0038] Determining three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels comprising a first data transmission channel, a second data transmission channel, and a third data transmission channel;
[0039] Transmitting the target to-be-transmitted data to the receiving device through the first data transmission channel;
[0040] Transmitting the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel;
[0041] Transmitting the second part of the key to the receiving device through the third data transmission channel.
[0042] Optionally, the splitting of the preset key to obtain a first part of the key and a second part of the key comprises:
[0043] Splitting the preset key according to a preset splitting processing parameter to obtain the first part of the key and the second part of the key;
[0044] The transmitting of the second part of the key to the receiving device through the third data transmission channel comprises:
[0045] Transmitting the second part of the key and the preset splitting processing parameter to the receiving device through the third data transmission channel.
[0046] Optionally, the preset splitting processing parameter comprises a segment number and a merging rule, the segment number being not less than 3, and the splitting of the preset key according to the preset splitting processing parameter to obtain the first part of the key and the second part of the key comprises:
[0047] Splitting the preset key into multiple segments according to the segment number to obtain multiple keys.
[0048] merge the multiple segments of keys according to the merging rule, to obtain the first part of keys and the second part of keys.
[0049] Optionally, the encrypting the to-be-transmitted data by using the preset key and the preset encryption algorithm parameter comprises:
[0050] determining a target importance degree of the to-be-transmitted data;
[0051] determining the preset encryption algorithm parameter corresponding to the target importance degree according to a preset mapping relationship between importance degrees and encryption algorithm parameters;
[0052] determining a target memory size of the to-be-transmitted data;
[0053] determining the preset key corresponding to the target memory size according to a preset mapping relationship between memory sizes and keys.
[0054] Optionally, the electronic device is specifically configured to:
[0055] when the target importance degree is lower than a preset importance degree, determining multiple data transmission channels between the to-be-transmitted data and the receiving device;
[0056] evaluating channel quality of the multiple data transmission channels, to obtain multiple channel quality evaluation values;
[0057] determining a maximum value in the multiple channel quality evaluation values, and obtaining a target data transmission channel corresponding to the maximum value;
[0058] transmitting the to-be-transmitted data through the target data transmission channel.
[0059] Optionally, the determining the target importance degree of the to-be-transmitted data comprises:
[0060] obtaining a target attribute parameter of the to-be-transmitted data;
[0061] extracting a target keyword from the target attribute parameter;
[0062] determining the target importance degree according to the target keyword.
[0063] Please refer to Figure 2 , Figure 2 is a flowchart of a wireless Internet of Things data security management method provided by an embodiment of the present application, which is applied to, for example, Figure 1The electronic device in the wireless Internet of Things system shown, the wireless Internet of Things system comprising the electronic device, and a plurality of Internet of Things devices connected to the electronic device, as shown, the wireless Internet of Things data security management method comprises:
[0064] 201, obtain the data to be transmitted and the receiving device, the receiving device is one of the plurality of Internet of Things devices.
[0065] In the embodiment of the application, the data to be transmitted can include at least one of the following: image data, video data, text data, sensor data, application data, software upgrade data, etc.
[0066] In a specific implementation, the electronic device and the plurality of Internet of Things devices connected to the electronic device can constitute a wireless Internet of Things system, the electronic device can obtain the data to be transmitted required by the user, and the receiving device can be one of the plurality of Internet of Things devices through the user's selection.
[0067] 202, encrypt the data to be transmitted using a preset key and a preset encryption algorithm parameter to obtain target data to be transmitted.
[0068] The preset key and the preset encryption algorithm parameter can be pre-set or system default. The preset encryption algorithm parameter can include at least one of the following: encryption algorithm identifier, encryption algorithm complexity, encryption algorithm control parameter, etc. The encryption algorithm identifier is used to identify the algorithm type of the encryption algorithm, the encryption algorithm complexity is used to represent the complexity of the encryption algorithm, and the encryption algorithm control parameter is used to adjust the complexity or security of the encryption algorithm. Different encryption algorithms can correspond to different encryption algorithm control parameters.
[0069] In the embodiment of the application, the data to be transmitted can be encrypted using a preset key and a preset encryption algorithm parameter to obtain target data to be transmitted, which is already encrypted data, thereby ensuring the security of data transmission.
[0070] 203, split the preset key to obtain a first part key and a second part key.
[0071] The preset key can be split into two parts, i.e. a first part key and a second part key, for example, the preset key is 123456, the first part key can be 123, and the second part key can be 456.
[0072] In a specific implementation, the characters in the first part key or the second part key can be in order or not in order.
[0073] 204. Determine three data transmission channels between the data to be transmitted and the receiving device, where the three data transmission channels include a first data transmission channel, a second data transmission channel, and a third data transmission channel.
[0074] In an embodiment of the present application, multiple data transmission channels can be determined between the three data transmission channels between the data to be transmitted and the receiving device. For example, the three data transmission channels with the fastest transmission rates can be selected, or, for another example, the three data transmission channels with the best channel quality can be selected. The three data transmission channels include a first data transmission channel, a second data transmission channel, and a third data transmission channel.
[0075] 205. Transmit the target data to be transmitted to the receiving device through the first data transmission channel.
[0076] In a specific implementation, the target data to be transmitted can be transmitted to a receiving device through a first data transmission channel, and the receiving device can receive the target data to be transmitted through the first data transmission channel. The target data to be transmitted is encrypted data, that is, only by decrypting it can the unencrypted data, that is, the data to be transmitted, be obtained.
[0077] In a specific implementation, when the memory size of the target data to be transmitted is larger than a set value, the target data to be transmitted can also be packaged into multiple data packets, each corresponding to a number, and the numbering sequence is randomly determined. Based on the numbering sequence, the multiple data packets are transmitted to the receiving device via a first data transmission channel. Furthermore, the second part of the key and the numbering sequence can be transmitted to the receiving device via a third data transmission channel. The receiving device can then restore the multiple data packets to the target data to be transmitted based on the numbering sequence. The set value can be pre-set or system default. In this way, the security of data transmission can be improved.
[0078] 206. Transmit the first partial key and the preset encryption algorithm parameters to the receiving device through the second data transmission channel.
[0079] In an embodiment of the present application, the electronic device can transmit the first part of the key and the preset encryption algorithm parameters to the receiving device through the second data transmission channel, that is, the receiving device can receive the first part of the key and the preset encryption algorithm parameters through the second data transmission channel.
[0080] 207. Transmit the second part of the key to the receiving device through the third data transmission channel.
[0081] In the embodiment of the present application, the electronic device can transmit the second part of the key to the receiving device through the third data transmission channel, and the receiving device can receive the second part of the key through the third data transmission channel.
[0082] In a specific implementation, the receiving device can splice the first part of the key and the second part of the key to obtain the preset key, and then use the preset key and the preset encryption algorithm parameter to decrypt the target data to be transmitted to obtain the data to be transmitted.
[0083] In the embodiments of the present application, first, the data to be encrypted is encrypted by the key and the encryption algorithm parameter to ensure the security of data transmission, and the key is transmitted through a data transmission channel different from the key; second, the key is split into two parts, and the two parts of the key are transmitted through different data transmission channels, so even if one part of the key is cracked, the data cannot be decrypted; third, the encryption algorithm parameter is also sent to the receiving device together with part of the key through a separate data transmission channel, so even if the data of any or two data transmission channels is cracked, the target data to be transmitted cannot be decrypted, and thus the security of data transmission is ensured.
[0084] Optionally, the step 203 of splitting the preset key into a first part of the key and a second part of the key can include the following steps:
[0085] The preset key is split according to preset splitting processing parameters to obtain the first part of the key and the second part of the key.
[0086] The step 207 of transmitting the second part of the key to the receiving device through the third data transmission channel can be implemented in the following manner:
[0087] The second part of the key and the preset splitting processing parameters are transmitted to the receiving device through the third data transmission channel.
[0088] In the embodiments of the present application, the preset splitting processing parameters can include at least one of the following: segmented data, merging rules, etc., without limitation. Specifically, the preset key can be split according to the preset splitting processing parameters to obtain the first part of the key and the second part of the key, and then the second part of the key and the preset splitting processing parameters are transmitted to the receiving device through the third data transmission channel.
[0089] In a specific implementation, the preset key can be divided into multiple segments, each segment can be numbered, a random number can be generated by a random number generator, and the corresponding segmented key can be selected from the number by the random number. The selected segmented key is used as the first part of the key, and the unselected segmented key is used as the second part of the key. In this way, the security can be improved.
[0090] In a specific implementation, the preset key can be divided into multiple segments, each segment can be numbered, and a corresponding segment key can be selected according to a preset number selection rule, to form the first part key, and the remaining segment keys are used as the second part key. The preset number selection rule can be previously agreed upon by the electronic device and the receiving device, which can be offline agreement between users, and the security of data transmission can be further improved.
[0091] Optionally, the preset splitting processing parameter includes a segment number and a merging rule, the segment number is not less than 3, and the step of splitting the preset key according to the preset splitting processing parameter to obtain the first part key and the second part key can include the following steps.
[0092] 31. splitting the preset key into multiple segments according to the segment number to obtain multiple segment keys;
[0093] 32. merging the multiple segment keys according to the merging rule to obtain the first part key and the second part key.
[0094] In the embodiments of the present application, the preset splitting processing parameter can include a segment number and a merging rule. The segment number and the merging rule can be previously set or system default. For example, the key is divided into 4 segments, and the numbers corresponding to each segment key are 1, 2, 3, and 4 respectively. The merging rule can be that 1 and 3 form a group, and 2 and 4 form a group. In a specific implementation, the preset key can be split into multiple segments according to the segment number to obtain multiple segment keys, that is, the number of characters contained in each segment key can be the same or different. Then, the multiple segment keys can be merged according to the merging rule to obtain the first part key and the second part key, so that the security can be further improved.
[0095] Optionally, the step 202 can include the following steps:
[0096] 21. determining a target importance of the to-be-transmitted data;
[0097] 22. determining the preset encryption algorithm parameter corresponding to the target importance according to a preset mapping relationship between the importance and the encryption algorithm parameter;
[0098] 23. determining a target memory size of the to-be-transmitted data;
[0099] 24. determining the preset key corresponding to the target memory size according to a preset mapping relationship between the memory size and the key.
[0100] In the embodiments of the present application, the electronic device can pre-store a mapping relationship between a preset importance and an encryption algorithm parameter, and a mapping relationship between a preset memory size and a key. The importance is used to represent the importance of data, and different importance degrees can correspond to different encryption algorithm parameters.
[0101] Specifically, the target importance of the to-be-transmitted data can be determined, and then the preset encryption algorithm parameter corresponding to the target importance can be determined according to the mapping relationship between the preset importance and the encryption algorithm parameter. In addition, the target memory size of the to-be-transmitted data can be determined, and then the preset key corresponding to the target memory size can be determined according to the mapping relationship between the preset memory size and the key. That is, the corresponding encryption algorithm parameter can be selected based on the importance of the data, and the corresponding key can be selected based on the memory size of the data, so that the data can be encrypted based on the characteristics of the data, which helps to improve the data encryption efficiency while ensuring data security.
[0102] Optionally, the step 21 of determining the target importance of the to-be-transmitted data can include the following steps:
[0103] 211. Obtain the target attribute parameter of the to-be-transmitted data.
[0104] 212. Perform keyword extraction on the target attribute parameter to obtain a target keyword.
[0105] 213. Determine the target importance according to the target keyword.
[0106] In the embodiments of the present application, the target attribute parameter can include at least one of the following: data type, data format, file name, data source, data note information, data security level, and the like, which are not limited herein.
[0107] Specifically, the target attribute parameter of the to-be-transmitted data can be obtained, and then the target keyword can be obtained by performing keyword extraction on the target attribute parameter. In addition, the mapping relationship between the preset keyword and the importance can be pre-stored to determine the target importance corresponding to the target keyword. In this way, the importance of the data can be quickly identified.
[0108] Optionally, the method can further include the following steps:
[0109] A1. When the target importance is lower than a preset importance, determine a plurality of data transmission channels between the to-be-transmitted data and the receiving device.
[0110] A2. Perform channel quality evaluation on the plurality of data transmission channels to obtain a plurality of channel quality evaluation values.
[0111] A3, determining a maximum value in the plurality of channel quality evaluation values, obtaining a target data transmission channel corresponding to the maximum value;
[0112] A4, transmitting the to-be-transmitted data through the target data transmission channel.
[0113] In the embodiments of the present application, the preset importance can be pre-set or system default.
[0114] In a specific implementation, when the target importance is lower than the preset importance, a plurality of data transmission channels between the to-be-transmitted data receiving devices can be determined, channel quality evaluation is performed on the plurality of data transmission channels to obtain a plurality of channel quality evaluation values, a maximum value in the plurality of channel quality evaluation values is determined, a target data transmission channel corresponding to the maximum value is obtained, and the to-be-transmitted data is transmitted through the target data transmission channel, that is, when the data is not important, the data can be transmitted directly through the data transmission channel with the best channel quality without encryption, which helps to improve the data transmission efficiency.
[0115] Of course, when the target importance is greater than or equal to the preset importance, the step of determining the preset encryption algorithm parameter corresponding to the target importance according to the mapping relationship between the preset importance and the encryption algorithm parameter can be performed.
[0116] It can be seen that the wireless Internet of Things data security management method described in the embodiment of the application is applied to an electronic device in a wireless Internet of Things system. The Internet of Things system includes an electronic device and a plurality of Internet of Things devices connected to the electronic device. The target to-be-transmitted data is obtained by encrypting the to-be-transmitted data using a preset key and a preset encryption algorithm parameter. The preset key is split to obtain a first part of the key and a second part of the key. Three data transmission channels between the to-be-transmitted data and the receiving device are determined. The three data transmission channels include a first data transmission channel, a second data transmission channel, and a third data transmission channel. The target to-be-transmitted data is transmitted to the receiving device through the first data transmission channel. The first part of the key and the preset encryption algorithm parameter are transmitted to the receiving device through the second data transmission channel. The second part of the key is transmitted to the receiving device through the third data transmission channel. First, the to-be-encrypted data is encrypted using the key and the encryption algorithm parameter to ensure data transmission security, and the data is transmitted using different data transmission channels from the key. Second, the key is split into two parts, and the two parts of the key are transmitted through different data transmission channels. Even if a part of the key is cracked, the data cannot be decrypted. Third, the encryption algorithm parameter is also sent to the receiving device using a separate data transmission channel with a part of the key. Therefore, even if the data of any one or two data transmission channels is cracked, the target to-be-transmitted data cannot be decrypted, thereby ensuring data transmission security.
[0117] Consistent with the above embodiment, please refer to Figure 3 , Figure 3 is a structural diagram of an electronic device provided by the embodiment of the application. As shown in the figure, the electronic device includes a processor, a memory, a communication interface, and one or more programs. The electronic device is applied to a wireless Internet of Things system. The wireless Internet of Things system includes the electronic device and a plurality of Internet of Things devices connected to the electronic device. The above one or more programs are stored in the above memory and are configured to be executed by the above processor. In the embodiment of the application, the program includes instructions for performing the following steps:
[0118] Obtain to-be-transmitted data and a receiving device. The receiving device is one of the plurality of Internet of Things devices.
[0119] Encrypt the to-be-transmitted data using a preset key and a preset encryption algorithm parameter to obtain target to-be-transmitted data.
[0120] Split the preset key to obtain a first part of the key and a second part of the key.
[0121] determining three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels comprising a first data transmission channel, a second data transmission channel and a third data transmission channel;
[0122] transmitting the target to-be-transmitted data to the receiving device through the first data transmission channel;
[0123] transmitting the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel;
[0124] transmitting the second part of the key to the receiving device through the third data transmission channel.
[0125] Optionally, in the splitting of the preset key to obtain the first part of the key and the second part of the key, the above program comprises instructions for performing the following steps:
[0126] splitting the preset key according to a preset splitting processing parameter to obtain the first part of the key and the second part of the key;
[0127] The transmitting of the second part of the key to the receiving device through the third data transmission channel comprises:
[0128] transmitting the second part of the key and the preset splitting processing parameter to the receiving device through the third data transmission channel.
[0129] Optionally, the preset splitting processing parameter comprises a segment number and a merging rule, and the segment number is not less than 3. In the splitting of the preset key according to a preset splitting processing parameter to obtain the first part of the key and the second part of the key, the above program comprises instructions for performing the following steps:
[0130] splitting the preset key into multiple segments according to the segment number to obtain multiple segments of keys;
[0131] merging the multiple segments of keys according to the merging rule to obtain the first part of the key and the second part of the key.
[0132] Optionally, in the encryption of the to-be-transmitted data by using the preset key and the preset encryption algorithm parameter, the above program comprises instructions for performing the following steps:
[0133] determining a target importance of the to-be-transmitted data;
[0134] determining the preset encryption algorithm parameter corresponding to the target importance according to a mapping relationship between a preset importance and an encryption algorithm parameter;
[0135] determining a target memory size of the to-be-transmitted data;
[0136] determining the preset key corresponding to the target memory size according to a preset mapping relationship between memory sizes and keys.
[0137] Optionally, the program further includes instructions for performing the following steps:
[0138] when the target importance is lower than a preset importance, determining a plurality of data transmission channels between the to-be-transmitted data and the receiving device;
[0139] evaluating channel quality of the plurality of data transmission channels to obtain a plurality of channel quality evaluation values;
[0140] determining a maximum value in the plurality of channel quality evaluation values, and obtaining a target data transmission channel corresponding to the maximum value;
[0141] transmitting the to-be-transmitted data through the target data transmission channel.
[0142] Optionally, in the aspect of determining the target importance of the to-be-transmitted data, the program includes instructions for performing the following steps:
[0143] obtaining a target attribute parameter of the to-be-transmitted data;
[0144] extracting a target keyword from the target attribute parameter;
[0145] determining the target importance according to the target keyword.
[0146] It can be seen that the electronic device described in the embodiment of the application is applied to a wireless Internet of Things system, the Internet of Things system includes an electronic device, and a plurality of Internet of Things devices connected with the electronic device, obtains to-be-transmitted data and a receiving device, the receiving device is one of the plurality of Internet of Things devices, adopts a preset key and a preset encryption algorithm parameter to encrypt the to-be-transmitted data to obtain target to-be-transmitted data, splits the preset key to obtain a first part of the key and a second part of the key, determines three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels include a first data transmission channel, a second data transmission channel and a third data transmission channel, transmits the target to-be-transmitted data to the receiving device through the first data transmission channel, transmits the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel, and transmits the second part of the key to the receiving device through the third data transmission channel. First, since the to-be-encrypted data is encrypted by the key and the encryption algorithm parameter, the data transmission security is ensured, and the data transmission channel different from the key is used for transmission; second, the key is split into two parts of the key, and the two parts of the key are transmitted through different data transmission channels, so even if a part of the key is cracked, the data cannot be decrypted; third, the encryption algorithm parameter is also sent to the receiving device together with a part of the key by using a separate data transmission channel, so that even if the data of any one or two data transmission channels is cracked, the target to-be-transmitted data cannot be decrypted, and thus the data transmission security is ensured.
[0147] Figure 4 is a functional unit composition block diagram of a wireless Internet of Things data security management device 400 involved in the embodiment of the application. The wireless Internet of Things data security management device 400 is applied to an electronic device in a wireless Internet of Things system, the wireless Internet of Things system includes the electronic device, and a plurality of Internet of Things devices connected with the electronic device, the device 400 includes: an acquisition unit 401, an encryption unit 402, a splitting unit 403, a determination unit 404 and a transmission unit 405, wherein,
[0148] The acquisition unit 401 is configured to acquire to-be-transmitted data and a receiving device, the receiving device being one of the plurality of Internet of Things devices.
[0149] The encryption unit 402 is configured to encrypt the to-be-transmitted data by using a preset key and a preset encryption algorithm parameter to obtain target to-be-transmitted data.
[0150] The splitting unit 403 is configured to split the preset key to obtain a first part of the key and a second part of the key.
[0151] The determining unit 404 is configured to determine three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels including a first data transmission channel, a second data transmission channel, and a third data transmission channel.
[0152] The transmitting unit 405 is configured to transmit the target to-be-transmitted data to the receiving device through the first data transmission channel, transmit the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel, and transmit the second part of the key to the receiving device through the third data transmission channel.
[0153] Optionally, in the splitting of the preset key into the first part of the key and the second part of the key, the splitting unit 403 is specifically configured to:
[0154] split the preset key according to preset splitting processing parameters to obtain the first part of the key and the second part of the key;
[0155] The transmission of the second part of the key to the receiving device through the third data transmission channel includes:
[0156] transmission of the second part of the key and the preset splitting processing parameters to the receiving device through the third data transmission channel.
[0157] Optionally, the preset splitting processing parameters include a segmentation number and a merging rule, and the segmentation number is not less than 3. In the splitting of the preset key according to the preset splitting processing parameters to obtain the first part of the key and the second part of the key, the splitting unit 403 is specifically configured to:
[0158] split the preset key into multiple segments according to the segmentation number to obtain multiple segments of keys;
[0159] merge the multiple segments of keys according to the merging rule to obtain the first part of the key and the second part of the key.
[0160] Optionally, in the encryption of the to-be-transmitted data by using the preset key and the preset encryption algorithm parameter, the encryption unit 402 is specifically configured to:
[0161] determine a target importance of the to-be-transmitted data;
[0162] determine the preset encryption algorithm parameter corresponding to the target importance according to a preset mapping relationship between an importance and an encryption algorithm parameter;
[0163] determine a target memory size of the to-be-transmitted data;
[0164] According to a preset mapping relationship between memory sizes and keys, the target memory size is determined to correspond to the preset key.
[0165] Optionally, the apparatus 400 is further specific for:
[0166] When the target importance is lower than a preset importance, a plurality of data transmission channels between the to-be-transmitted data and the receiving device are determined;
[0167] Channel quality evaluation is performed on the plurality of data transmission channels to obtain a plurality of channel quality evaluation values;
[0168] The maximum value in the plurality of channel quality evaluation values is determined to obtain a target data transmission channel corresponding to the maximum value;
[0169] The to-be-transmitted data is transmitted through the target data transmission channel.
[0170] Optionally, in the aspect of determining the target importance of the to-be-transmitted data, the encryption unit 402 is specific for:
[0171] A target attribute parameter of the to-be-transmitted data is obtained;
[0172] Keyword extraction is performed on the target attribute parameter to obtain a target keyword;
[0173] The target importance is determined according to the target keyword.
[0174] It can be seen that the wireless Internet of Things data security management device described in the embodiment of the application is applied to an electronic device in a wireless Internet of Things system, the Internet of Things system includes the electronic device, and a plurality of Internet of Things devices connected with the electronic device, obtains to-be-transmitted data and a receiving device, the receiving device is one of the plurality of Internet of Things devices, adopts a preset key and a preset encryption algorithm parameter to encrypt the to-be-transmitted data to obtain target to-be-transmitted data, splits the preset key to obtain a first part of the key and a second part of the key, determines three data transmission channels between the to-be-transmitted data and the receiving device, the three data transmission channels include a first data transmission channel, a second data transmission channel and a third data transmission channel, transmits the target to-be-transmitted data to the receiving device through the first data transmission channel, transmits the first part of the key and the preset encryption algorithm parameter to the receiving device through the second data transmission channel, and transmits the second part of the key to the receiving device through the third data transmission channel. First, since the to-be-encrypted data is encrypted by the key and the encryption algorithm parameter, the data transmission security is ensured, and the data transmission channel different from the key is used for transmission. Second, the key is split into two parts, and the two parts of the key are transmitted through different data transmission channels. Even if a part of the key is cracked, the data cannot be decrypted. Third, the encryption algorithm parameter is also sent to the receiving device together with a part of the key by using a separate data transmission channel. Therefore, even if the data of any one or two data transmission channels is cracked, the target to-be-transmitted data cannot be decrypted, and thus the data transmission security is ensured.
[0175] It can be understood that the functions of the program modules of the wireless Internet of Things data security management device of the embodiment can be specifically implemented according to the methods in the above method embodiments, and the specific implementation process can be referred to the related description of the above method embodiments, which will not be described here.
[0176] The embodiment of the application further provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program causes a computer to execute part or all steps of any method described in the above method embodiments.
[0177] The embodiment of the application further provides a computer program product, and the computer program product includes a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute part or all steps of any method described in the above method embodiments. The computer program product can be a software installation package.
[0178] It should be noted that, for the foregoing method embodiments, the sequences of the described actions can be modified, and certain actions can be performed simultaneously or in different sequences. In addition, the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0179] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0180] In the several embodiments provided by the present application, it should be understood that the disclosed apparatus can be implemented in other manners. For example, the apparatus embodiments described above are merely schematic; the division of the units is only a logical function division; there can be another division manner for the actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0181] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments.
[0182] In addition, each functional unit in the embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be implemented in the form of hardware or software functional units.
[0183] If the above integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable memory. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a memory and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the above-mentioned method of each embodiment of the present application. The aforementioned memory includes: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0184] A person of ordinary skill in the art can understand that all or part of the steps in the above-mentioned embodiments can be completed by instructing the relevant hardware through a program, which can be stored in a computer readable memory. The memory can include: a flash disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0185] The embodiments of the present application are described in detail above, and the principles and implementation manners of the present application are described by applying specific examples. The above description of the embodiments is only used to help understand the method of the present application and its core idea; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation manner and application range will be changed, and the above description of the embodiments is not used to limit the present application.
Claims
1. A wireless Internet of Things data security management method, characterized in that: An electronic device applied to a wireless Internet of Things system, wherein the wireless Internet of Things system includes the electronic device and a plurality of Internet of Things devices connected to the electronic device, wherein the method includes: Acquire data to be transmitted and a receiving device, where the receiving device is one of the multiple IoT devices; Encrypting the data to be transmitted using a preset key and preset encryption algorithm parameters to obtain target data to be transmitted; Splitting the preset key to obtain a first key part and a second key part; Determining three data transmission channels between the data to be transmitted and the receiving device, the three data transmission channels including a first data transmission channel, a second data transmission channel, and a third data transmission channel; transmitting the target data to be transmitted to the receiving device through the first data transmission channel; transmitting the first partial key and the preset encryption algorithm parameters to the receiving device through the second data transmission channel; transmitting the second partial key to the receiving device via the third data transmission channel; The step of encrypting the data to be transmitted by using a preset key and preset encryption algorithm parameters includes: Determining the target importance of the data to be transmitted; Determining the preset encryption algorithm parameters corresponding to the target importance according to the mapping relationship between the preset importance and the encryption algorithm parameters; Determining a target memory size of the data to be transmitted; According to the mapping relationship between the preset memory size and the key, the preset key corresponding to the target memory size is determined.
2. The method according to claim 1, characterized in that Splitting the preset key to obtain a first key part and a second key part includes: Splitting the preset key according to preset splitting processing parameters to obtain the first part key and the second part key; The transmitting the second part of the key to the receiving device through the third data transmission channel includes: The second part of the key and the preset splitting processing parameter are transmitted to the receiving device through the third data transmission channel.
3. The method according to claim 2, characterized in that The preset splitting processing parameters include: the number of segments and a merging rule, wherein the number of segments is not less than 3. Splitting the preset key according to the preset splitting processing parameters to obtain the first part key and the second part key includes: Splitting the preset key into multiple segments according to the number of segments to obtain a multi-segment key; The multiple key segments are merged according to the merging rule to obtain the first key segment and the second key segment.
4. The method according to claim 1, wherein The method further comprises: When the target importance is lower than a preset importance, determining a plurality of data transmission channels between the data to be transmitted and the receiving device; Performing channel quality evaluation on the multiple data transmission channels to obtain multiple channel quality evaluation values; Determine a maximum value among the multiple channel quality evaluation values, and obtain a target data transmission channel corresponding to the maximum value; The data to be transmitted is transmitted through the target data transmission channel.
5. The method according to claim 1, wherein Determining the target importance of the data to be transmitted includes: Obtaining target attribute parameters of the data to be transmitted; Perform keyword extraction on the target attribute parameters to obtain target keywords; The target importance is determined according to the target keyword.
6. A wireless Internet of Things data security management device, characterized in that: An electronic device used in a wireless Internet of Things system, the wireless Internet of Things system including the electronic device and multiple Internet of Things devices connected to the electronic device, the device including: an acquisition unit, an encryption unit, a splitting unit, a determination unit and a transmission unit, wherein: The acquiring unit is configured to acquire data to be transmitted and a receiving device, wherein the receiving device is one of the plurality of IoT devices; The encryption unit is used to encrypt the data to be transmitted using a preset key and preset encryption algorithm parameters to obtain target data to be transmitted; The splitting unit is used to split the preset key to obtain a first part key and a second part key; The determining unit is configured to determine three data transmission channels between the data to be transmitted and the receiving device, the three data transmission channels including a first data transmission channel, a second data transmission channel, and a third data transmission channel; The transmission unit is configured to transmit the target data to be transmitted to the receiving device via the first data transmission channel; transmit the first partial key and the preset encryption algorithm parameters to the receiving device via the second data transmission channel; and transmit the second partial key to the receiving device via the third data transmission channel; The step of encrypting the data to be transmitted by using a preset key and preset encryption algorithm parameters includes: Determining the target importance of the data to be transmitted; Determining the preset encryption algorithm parameters corresponding to the target importance according to the mapping relationship between the preset importance and the encryption algorithm parameters; Determining a target memory size of the data to be transmitted; According to the mapping relationship between the preset memory size and the key, the preset key corresponding to the target memory size is determined.
7. The device according to claim 6, characterized in that In the aspect of splitting the preset key to obtain the first key part and the second key part, the splitting unit is specifically used to: Splitting the preset key according to preset splitting processing parameters to obtain the first part key and the second part key; The transmitting the second part of the key to the receiving device through the third data transmission channel includes: The second part of the key and the preset splitting processing parameter are transmitted to the receiving device through the third data transmission channel.
8. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory is used to store one or more programs and is configured to be executed by the processor, wherein the programs include instructions for executing the steps of the method according to any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that A computer program for electronic data exchange is stored, wherein the computer program enables a computer to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Time-space separated mobile encryption communication mechanism
CN105025476A
Method and device for establishing secure encryption channel
CN106788989A
Data security protection method and system
CN112989389A