A secure communication system for Internet of Things group gateways
Through the combined communication method of visible light VLC and power supply power carrier PLC, combined with random combination encryption of multiple light sources and operating systems, the problem of IoT group gateways being easily hacked is solved, and high-security and low-interference data transmission is achieved.
Patent Information
- Application Number
- CN202211378108.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-04
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-11-04
AI Technical Summary
Traditional IoT group gateways are easily hacked, leaving the basic control of the entire building exposed to hackers. The security issues of group intelligent networks are prominent, especially when wired or wireless gateway nodes are hacked, the security of the entire group is difficult to guarantee.
A combined communication method of visible light VLC and power supply carrier PLC is adopted. The device side adopts VLC photoelectric receiving module and PLC modulation module, and the server side adopts PLC demodulation module and PLC-VLC conversion module. Communication is carried out through different uplink and downlink data channels. Encryption is performed by combining random combinations of multiple light sources and operating systems, and random numbers are generated for encryption method selection.
It reduces the chance of data being intercepted and controlled, reduces electromagnetic wireless signal interference, achieves physical link isolation, improves the security and accuracy of data transmission, and avoids the risk of two-way interception on a single link.
Smart Images

Figure CN115766146B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of device communication technology, and in particular to a secure communication system for an Internet of Things group gateway. Background Art
[0002] Traditional smart buildings achieve intelligence through unified deployment of unified controls. Typically, each floor uses a gateway to connect device controls to the outside world. Once this gateway is compromised, the entire building's basic controls are exposed to hackers. The subsequent development of swarm intelligence networks has further enhanced the intelligence of traditional controlled devices. Through communication and computing modules, each controlled device can communicate bidirectionally according to set objectives, rather than simply responding passively. Consequently, when all devices have communication capabilities, swarm intelligence security issues also arise. Similarly, if a wired or wireless gateway node is compromised, the entire swarm is compromised. Therefore, there is a need to provide an IoT swarm gateway secure communication system to address or alleviate the aforementioned issues. Summary of the Invention
[0003] In view of the deficiencies in the prior art, the object of the present invention is to provide an Internet of Things group gateway secure communication system to solve or alleviate the problems existing in the above-mentioned background technology.
[0004] The present invention is implemented as follows: a secure communication system for an Internet of Things group gateway, the system includes a server end and a device end, the device end is provided with a device gateway, the server end includes a server-end PLC modulation module, a server-end PLC demodulation module and a PLC-VLC conversion module, the device end includes a VLC photoelectric receiving module, a device-end PLC modulation module and a device control module, the VLC photoelectric receiving module, the device-end PLC modulation module and the device control module together constitute the device gateway, the device-end PLC modulation module is used to modulate an electrical signal into a high-frequency signal that meets the PLC standard and transmit it, and is also used to transmit a feedback signal to a PLC transmission line, the server-end PLC demodulation module converts the feedback signal in the PLC transmission line into a data signal for the server end to receive; the server-end PLC modulation module transmits the data signal to the PLC transmission line, and converts the high-frequency AC signal into a VLC spectrum signal through the PLC-VLC conversion module, the VLC photoelectric receiving module is used to receive the VLC spectrum signal and convert the VLC spectrum signal into a readable electrical signal.
[0005] As a further solution of the present invention, when the server communicates with the device, the server PLC modulation module sends out a data packet signal with address information, the PLC-VLC conversion module receives the data packet signal and matches the address, and after successful matching, converts the data packet signal into a VLC spectrum signal and sends it out, the VLC photoelectric receiving module with matching address performs photoelectric conversion on the VLC spectrum signal, and sends the converted data packet to the device control module, the device control module receives the data and processes it, and sends the processing result with the corresponding address information to the device PLC modulation module, the device PLC modulation module sends out a feedback signal with address information, the server PLC demodulation module receives the feedback signal, and the server receives it after processing and conversion.
[0006] As a further solution of the present invention, it is applied to a light source emission system, which includes an emitting lamp head. The emitting lamp head has a variety of light sources. The emitting lamp head responds to the PLC-VLC conversion module to select emission and uses different light sources to emit spectral data.
[0007] As a further solution of the present invention, the device gateway in the device end has multiple operating systems built in. One of the operating systems is randomly started for the first time, and the last selected operating system is not restarted during each subsequent reset. Through the combination of different emitting light sources and different operating systems, the system data will have multiple encryption methods, and the encryption method is randomly selected according to the random number generated at the current time for each communication.
[0008] As a further solution of the present invention, when the server needs to send a command, it generates a data packet with an address, and at the same time obtains the current time as a random number, calculates a numerical value based on the random number using an agreed algorithm, maps it to the corresponding emitting light source, obtains the operating system information of the terminal corresponding to the address according to the address mapping table, selects the corresponding encryption method according to the emitting light source and operating system parameters, encrypts the data packet, packages the data packet, and sends out a data packet signal with an address.
[0009] As a further solution of the present invention, the PLC-VLC conversion module receives a data packet signal, the module corresponding to the address converts the data packet signal into a spectral signal, uses a set light source to emit the spectral signal, the device gateway receives the spectral signal corresponding to the light source, and converts the spectral signal into an electrical signal. After receiving the data, the device control module determines the light source parameters, uses the corresponding decryption method, decrypts the signal and processes the data. After the processing is completed, the device control module generates a feedback data packet, obtains the current time as a random number, calculates the feedback value based on the random number using an agreed algorithm, encrypts the feedback data packet based on the feedback value and the operating system parameters, and the device gateway sends a feedback data packet with the address processing result.
[0010] Compared with the prior art, the present invention has the following beneficial effects:
[0011] The device gateway on the device side receives data using visible light (VLC) communication, while group devices use power carrier (PLC) communication for feedback. This approach, with separate data channels for uplink and downlink, unlike traditional wireless and wired networks, reduces the likelihood of data interception and manipulation under traditional methods and mitigates interference between electromagnetic wireless signals. This invention utilizes group devices with physically isolated uplink and downlink data communication links, eliminating the risk of bidirectional interception from a single link. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 This is a communication diagram between the device side and the server side in a secure communication system of an IoT group gateway.
[0013] Figure 2 This is a system architecture diagram of the lighting and socket power supply circuit in an IoT group gateway secure communication system.
[0014] Figure 3 This is a message flow diagram for communication between the server and the device in a secure communication system of an IoT group gateway.
[0015] Figure 4 This is a flowchart of the encryption processing of data sent by the server in a secure communication system of an Internet of Things group gateway.
[0016] Figure 5 This is a flowchart of the encryption processing of device-side feedback signals in an IoT group gateway secure communication system. DETAILED DESCRIPTION
[0017] In order to make the purpose, technical solutions and advantages of the present invention clearer, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0018] The specific implementation of the present invention is described in detail below with reference to specific embodiments.
[0019] like Figure 1As shown, an embodiment of the present invention provides an Internet of Things group gateway security communication system, the system includes a server end and a device end, the device end is provided with a device gateway, the server end includes a server-side PLC modulation module, a server-side PLC demodulation module and a PLC-VLC conversion module, the device end includes a VLC photoelectric receiving module, a device-side PLC modulation module and a device control module, the VLC photoelectric receiving module, the device-side PLC modulation module and the device control module together constitute the device gateway, the device-side PLC modulation module is used to modulate the electrical signal into a high-frequency signal that meets the PLC standard and transmit it, and is also used to transmit the feedback signal to the PLC transmission line, the server-side PLC demodulation module converts the feedback signal in the PLC transmission line into a data signal for the server to receive; the server-side PLC modulation module transmits the data signal to the PLC transmission line, and converts the high-frequency AC signal into a VLC spectrum signal through the PLC-VLC conversion module, the VLC photoelectric receiving module is used to receive the VLC spectrum signal and convert the VLC spectrum signal into a readable electrical signal.
[0020] It should be noted that the embodiment of the present invention first requires that the control modules of the group intelligent devices all have the capability of a gateway, that is, there are as many group gateways as there are group devices; secondly, the group device gateway receives data communication using visible light VLC, and the group device feedback data communication uses power supply carrier PLC. The uplink and downlink are different from traditional wireless and wired networks, and the different data channels reduce the probability of data being intercepted and controlled under the traditional method, and also reduce the problem of mutual interference between electromagnetic wireless signals. In addition, regardless of the VLC method or the PLC method, the installation and communication of the equipment are very convenient. At the same time, both communication methods can quickly locate the equipment, which is convenient for future operation and maintenance of the equipment. In the embodiment of the present invention, the device control module has the function of controlling the switch and communication of the connected equipment. The embodiment of the present invention focuses on the isolation of group devices based on different uplink and downlink data communication physical links to avoid the risk of bidirectional interception of a single link.
[0021] like Figure 2 As shown, in an embodiment of the present invention, the power supply circuit is divided into a lighting circuit and a socket circuit from the output of the power supply transformer. Due to the isolation of the transformer, the PLC signals on the two circuits do not interfere with each other. The server data signal is transmitted to the lighting circuit through the server PLC debugging module, and the high-frequency AC signal is converted into a spectral signal through the PLC-VLC conversion module and transmitted. The device gateway receives the VLC spectral signal through the VLC photoelectric receiving module and converts the optical signal into a readable electrical signal. The device control module performs corresponding processing based on the received electrical signal. The processed result is transmitted to the socket circuit through the PLC modulation module, and the high-frequency AC signal is converted into a readable electrical signal through the server demodulation module, and the server receives and processes it.
[0022] like Figure 3 As shown, in an embodiment of the present invention, when the server side communicates with the device side, the server side PLC modulation module sends out a data packet signal with address information, the PLC-VLC conversion module receives the data packet signal and matches the address, and after successful matching, converts the data packet signal into a VLC spectrum signal and sends it out, the VLC photoelectric receiving module with matching address performs photoelectric conversion on the VLC spectrum signal, and sends the converted data packet to the device control module, the device control module receives the data and processes it, and sends the processing result with the corresponding address information to the device side PLC modulation module, the device side PLC modulation module sends out a feedback signal with address information, the server side PLC demodulation module receives the feedback signal, and receives it after processing and conversion.
[0023] This achieves physical and logical isolation of northbound and southbound data transmission based on existing infrastructure lines. Furthermore, lighting circuits generally lack exposed wiring ports, enhancing both physical and logical data transmission security. Southbound data is sent to the device via VLC based on address information, avoiding interference between traditional wireless signals while enabling spectral data transmission within a specific, narrow range. This approach, unlike traditional wireless methods, offers precise, spill-free transmission within a narrow range, significantly enhancing data transmission security.
[0024] like Figure 4 and Figure 5 As shown, an embodiment of the present invention is applied to a light source emission system, wherein the light source emission system includes an emission lamp head, the emission lamp head has a variety of light sources, the emission lamp head responds to the PLC-VLC conversion module to select emission, and uses different light sources to emit spectrum data. The device gateway in the device end has multiple operating systems built in, and one of the operating systems is randomly started for the first time. The last selected operating system is not restarted at each subsequent reset. Through the combination of different emission light sources (m represents the number of light sources) and different operating systems (n represents the number of built-in operating systems), the system data can have a maximum of m*n encryption methods, and each communication randomly selects the encryption method based on the random number generated at the current time. The use of different emission light sources reduces the risk of the same spectrum being intercepted, and the use of different operating systems reduces the risk of the same operating system being affected by vulnerabilities in the same period. The practice of randomly selecting the encryption method each time reduces the security risk of a single encryption being cracked.
[0025] In an embodiment of the present invention, when the server sends data for encryption, the server generates an addressed data packet when it needs to send a command, and obtains the current time as a random number (this random number is unique at every moment), calculates a numerical value based on the random number using an agreed algorithm, maps it to the corresponding emitting light source, obtains the operating system information of the terminal corresponding to the address according to the address mapping table, selects the corresponding encryption method according to the emitting light source and operating system parameters, encrypts the data packet, packages the data packet, and sends an addressed data packet signal.
[0026] In an embodiment of the present invention, when the device end performs feedback encryption, the PLC-VLC conversion module receives a data packet signal, the module of the corresponding address converts the data packet signal into a spectral signal, uses the set light source to emit the spectral signal, the device gateway receives the spectral signal corresponding to the light source, and converts the spectral signal into an electrical signal. After receiving the data, the device control module determines the light source parameters, uses the corresponding decryption method, decrypts the signal and processes the data. After the processing is completed, the device control module generates a feedback data packet, obtains the current time as a random number, calculates the feedback value based on the random number using an agreed algorithm, encrypts the feedback data packet based on the feedback value and the operating system parameters, and the device gateway sends a feedback data packet with the address processing result. The feedback data packet is the feedback signal.
[0027] The above is only a detailed description of the preferred embodiments of the present invention, which is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
[0028] It should be understood that, although the various steps in the flow chart of each embodiment of the present invention are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence according to the order indicated by the arrows. Unless otherwise specified herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0029] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0030] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the disclosure in the specification and examples. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered merely as exemplary, and the true scope and spirit of the present disclosure are indicated by the claims.
Claims
1. A secure communication system for an Internet of Things group gateway, characterized in that: The system includes a server side and a device side, wherein a device gateway is provided in the device side, wherein the server side includes a server-side PLC modulation module, a server-side PLC demodulation module and a PLC-VLC conversion module, and the device side includes a VLC photoelectric receiving module, a device-side PLC modulation module and a device control module, wherein the VLC photoelectric receiving module, the device-side PLC modulation module and the device control module together constitute the device gateway, wherein the device-side PLC modulation module is used to transmit a feedback signal to a PLC transmission line, and the server-side PLC demodulation module converts the feedback signal in the PLC transmission line into a data signal for reception by the server side; the server-side PLC modulation module transmits the data signal to the PLC transmission line, and converts the high-frequency alternating current signal into a VLC spectrum signal through the PLC-VLC conversion module, and the VLC photoelectric receiving module is used to receive the VLC spectrum signal and convert the VLC spectrum signal into a readable electrical signal; Applied to the light source emission system, the light source emission system includes an emitting lamp head, which has a variety of light sources. The emitting lamp head responds to the PLC-VLC conversion module to select the emission, and uses different light sources to emit spectral data. The device gateway in the device end has multiple operating systems built in. One of the operating systems is randomly started for the first time, and the last selected operating system is not restarted during each subsequent reset. Through the combination of different emitting light sources and different operating systems, the system data will have multiple encryption methods, and the encryption method is randomly selected according to the random number generated at the current time for each communication.
2. The Internet of Things group gateway secure communication system according to claim 1, characterized in that: When the server communicates with the device, the PLC modulation module on the server sends out a data packet signal with address information, the PLC-VLC conversion module receives the data packet signal and matches the address, and after successful matching, converts the data packet signal into a VLC spectrum signal and sends it out, the VLC photoelectric receiving module with matching address performs photoelectric conversion on the VLC spectrum signal, and sends the converted data packet to the device control module, the device control module receives the data and processes it, and sends the processing result with the corresponding address information to the PLC modulation module on the device, the PLC modulation module on the device sends out a feedback signal with address information, the PLC demodulation module on the server receives the feedback signal, and the server receives it after processing and conversion.
3. The Internet of Things group gateway secure communication system according to claim 1, characterized in that: When the server needs to send a command, it generates an addressed data packet and obtains the current time as a random number. It uses an agreed algorithm to calculate a numerical value based on the random number and maps it to the corresponding emitting light source. According to the address mapping table, it obtains the operating system information of the terminal corresponding to the address, selects the corresponding encryption method according to the emitting light source and operating system parameters, encrypts the data packet, packages the data packet, and sends out an addressed data packet signal.
4. The Internet of Things group gateway secure communication system according to claim 3, characterized in that: The PLC-VLC conversion module receives the data packet signal, and the module with the corresponding address converts the data packet signal into a spectral signal. The spectral signal is emitted using the set light source. The device gateway receives the spectral signal corresponding to the light source and converts the spectral signal into an electrical signal. After receiving the data, the device control module determines the light source parameters, uses the corresponding decryption method, decrypts the signal and processes the data. After the processing is completed, the device control module generates a feedback data packet. The device control module obtains the current time as a random number, calculates the feedback value based on the random number using the agreed algorithm, encrypts the feedback data packet based on the feedback value and the operating system parameters, and the device gateway sends a feedback data packet with the address processing result.
Citation Information
Patent Citations
Visible light communication-based underground radio communication system
CN102868449A
Intelligent network system combined with visible light
CN114157697A