A data encryption system and method based on edge cloud computing

By using an edge cloud computing-based data encryption system, which leverages the collaborative work of IoT terminals and edge cloud servers, the problem of high CPU resource consumption is solved, and efficient data encryption and traceability checks are achieved.

CN115941334BActive Publication Date: 2025-11-18SHENZHEN MING LI YANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211584406.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-11-18
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

In existing technologies, the data encryption process is mainly completed by the central processing unit, which leads to excessive consumption of computing resources, reduces encryption efficiency, and increases the workload of the server.

Method used

An edge cloud computing-based data encryption system is adopted. Through the collaborative work of IoT terminals, IoT servers, edge cloud servers, and cloud servers, encryption policies are assigned according to terminal attributes, and data operations are saved to a dedicated edge cloud server to achieve secure data encryption and traceability inspection.

Benefits of technology

It effectively reduces the burden on the central processing unit, improves encryption efficiency, and ensures data security and operational traceability through the allocation strategy of edge cloud servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941334B_ABST
    Figure CN115941334B_ABST
Patent Text Reader

Abstract

The application provides a data encryption system and method based on edge cloud computing. According to the scheme of the embodiment of the application, corresponding encryption strategies can be distributed according to the properties of Internet of Things terminals, and operations on data are saved to a special edge cloud server, so that the safety of data is ensured, and data operation traceability checking can be provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud computing technology, and specifically to a data encryption system and method based on edge cloud computing. Background Technology

[0002] With the rapid development of IT, communication, and software technologies, the Internet of Things is becoming increasingly widespread, and people are using the internet more frequently. Information content has permeated all fields, and the big data environment has changed people's worldviews and lifestyles. In the era of big data, the application of computer network technology and the effective integration of data have accelerated information processing and helped people obtain various information and data more conveniently. However, while generating and transmitting large amounts of data, it also leads to the loss and theft of some information.

[0003] Encrypting data can significantly improve user data security and reduce data security risks. However, the encryption process is often completed solely by the central processing unit (CPU), consuming substantial computing resources, increasing its workload, and reducing encryption efficiency. Therefore, the entire encryption process places high demands on the overall computing power of the server. Consequently, a data encryption solution based on edge cloud computing is needed. Summary of the Invention

[0004] This invention addresses the aforementioned problems by proposing a data encryption system and method based on edge cloud computing. Through the scheme of this invention, corresponding encryption strategies can be assigned according to the attributes of IoT terminals, and data operations are saved to a dedicated edge cloud server. This not only ensures data security but also provides traceability and verification of data operations.

[0005] In view of this, one aspect of the present invention proposes a data encryption system based on edge cloud computing, comprising: multiple IoT terminals, multiple IoT servers, a first cloud server for storing and managing data, multiple edge cloud servers, and a second cloud server for subject registration, allocation of storage resources, and provision of encryption strategies; wherein,

[0006] The second cloud server is configured as follows:

[0007] The system receives registration requests from the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers, registers them, and configures unique identifiers for each of the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers.

[0008] Establish communication connections with the multiple edge cloud servers and form a security verification system;

[0009] The first IoT terminal among the plurality of IoT terminals is configured to: collect first terminal data and send first attribute data generated based on the first terminal data to the second cloud server;

[0010] The second cloud server is configured as follows:

[0011] Determine the first encryption strategy for the first terminal data based on the first attribute data;

[0012] Send the first encryption policy to the first cloud server;

[0013] The first cloud server is configured to: parse the first encryption policy and send the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers;

[0014] The first IoT server is configured as follows:

[0015] After receiving the first terminal data, the first terminal data is encrypted to obtain the first encrypted terminal data;

[0016] The first encrypted terminal data is transmitted to the first cloud server, and the operation record of the operation performed on the first terminal data is sent to the corresponding first edge cloud server among the plurality of edge cloud servers.

[0017] Optionally, the first cloud server is configured as follows:

[0018] Based on the attribute characteristics of the multiple IoT terminals, multiple data transmission routes, data volume attribute characteristics, and data operation characteristics of each IoT terminal are generated, and a first correspondence is established between each IoT terminal and each IoT server.

[0019] The multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship are sent to the second cloud server.

[0020] Optionally, the second cloud server is configured as follows:

[0021] Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence, determine the first transmission route and the first storage location of the first terminal data;

[0022] Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence, and in conjunction with preset selection rules, the first registration position of the relevant operation record of the first terminal data is selected from the multiple edge cloud servers.

[0023] Send the first transmission route, the first storage location, and the first registration location to the first cloud server;

[0024] The first cloud server is configured to: send the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

[0025] Optionally, the first cloud server is configured as follows:

[0026] The steps of parsing the first encryption strategy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers include:

[0027] The first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key are obtained from the first encryption strategy.

[0028] Send the unique identifier of the first IoT server to the first IoT terminal;

[0029] The first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy are sent to the first IoT server.

[0030] Optionally, in the operation of encrypting the first terminal data after receiving the first terminal data to obtain the first encrypted terminal data, the first IoT server is specifically configured as follows:

[0031] A second encryption key and a second decryption key are generated according to the second encryption algorithm generation strategy;

[0032] The first terminal data is encrypted using the second encryption key to obtain the first encrypted data;

[0033] Obtain multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypt the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data;

[0034] The first encrypted data, the supplementary data, and the second decryption key are encrypted separately using the fourth encryption key and then mixed to obtain the second encrypted data.

[0035] The first encryption key is used to encrypt the second encryption data to obtain the first encrypted terminal data;

[0036] In determining the plurality of geographic location data, the first cloud server is configured as follows:

[0037] Using the location coordinates of any one of the multiple IoT servers as the center and a preset radius, construct a sphere, and select N points on the surface of the sphere;

[0038] The N coordinate values ​​corresponding to the N points are used as geographical location coordinates;

[0039] For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained;

[0040] The set of geographic coordinates is used as the multiple geographic location data.

[0041] Another aspect of the present invention provides a data encryption method based on edge cloud computing, applied to the data encryption system described above. The data encryption system includes multiple IoT terminals, multiple IoT servers, a first cloud server for storing and managing data, multiple edge cloud servers, and a second cloud server for subject registration, allocation of storage resources, and provision of encryption strategies. The method includes:

[0042] The plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively send registration requests to the second cloud server;

[0043] The second cloud server receives the registration request, registers the data, and configures unique identifiers for the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively.

[0044] The second cloud server establishes a communication connection with the multiple edge cloud servers and forms a security verification system;

[0045] The first IoT terminal among the plurality of IoT terminals collects first terminal data and sends first attribute data generated based on the first terminal data to the second cloud server.

[0046] The second cloud server determines the first encryption strategy for the first terminal data based on the first attribute data;

[0047] The second cloud server sends the first encryption policy to the first cloud server;

[0048] The first cloud server parses the first encryption policy and sends the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers;

[0049] After receiving the data from the first terminal, the first IoT server encrypts the data to obtain the first encrypted terminal data.

[0050] The first IoT server transmits the first encrypted terminal data to the first cloud server, and simultaneously sends the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers.

[0051] Optionally, the method further includes:

[0052] The first cloud server generates multiple data transmission routes, data volume attribute characteristics, and data operation characteristics for each of the multiple IoT terminals based on the attribute characteristics of the multiple IoT terminals, and establishes a first correspondence between each of the multiple IoT terminals and each of the multiple IoT servers.

[0053] The first cloud server sends the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship to the second cloud server.

[0054] Optionally, the method further includes:

[0055] The second cloud server determines the first transmission route and the first storage location of the first terminal data based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence.

[0056] The second cloud server selects the first registration position of the relevant operation record of the first terminal data from the multiple edge cloud servers based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship, and in combination with preset selection rules.

[0057] The second cloud server sends the first transmission route, the first storage location, and the first registration location to the first cloud server;

[0058] The first cloud server distributes the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

[0059] Optionally, the step of the first cloud server parsing the first encryption policy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers includes:

[0060] The first cloud server parses the first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key from the first encryption strategy;

[0061] The first cloud server sends the unique identifier of the first IoT server to the first IoT terminal;

[0062] The first cloud server sends the first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy to the first IoT server.

[0063] Optionally, the step of encrypting the first terminal data to obtain the first encrypted terminal data after receiving the first terminal data by the first IoT server includes:

[0064] The first IoT server generates a second encryption key and a second decryption key according to the second encryption algorithm generation strategy;

[0065] The first IoT server uses the second encryption key to encrypt the data of the first terminal to obtain the first encrypted data;

[0066] The first IoT server obtains multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypts the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data;

[0067] The first IoT server uses the fourth encryption key to encrypt the first encrypted data, the supplementary data, and the second decryption key respectively, and then mixes them to obtain the second encrypted data;

[0068] The first IoT server uses the first encryption key to encrypt the second encryption data to obtain the first encrypted terminal data;

[0069] The plurality of geographic location data are determined in the following manner:

[0070] The first cloud server uses the location coordinates of any one of the multiple IoT servers as the center of a sphere with a preset radius, and selects N points on the surface of the sphere.

[0071] The N coordinate values ​​corresponding to the N points are used as geographical location coordinates;

[0072] For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained;

[0073] The set of geographic coordinates is used as the multiple geographic location data.

[0074] The data encryption method based on edge cloud computing, using the technical solution of this invention, includes: the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively sending registration requests to the second cloud server; the second cloud server receiving the registration requests, registering, and configuring unique identifiers for the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively; the second cloud server establishing a communication connection with the plurality of edge cloud servers and forming a security verification system; the first IoT terminal among the plurality of IoT terminals collecting first terminal data and sending first attribute data generated based on the first terminal data to the second cloud server; the second cloud server determining a first encryption strategy for the first terminal data based on the first attribute data; the second cloud server sending the first encryption strategy to the first cloud server; the first cloud server parsing the first encryption strategy and sending relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers; after receiving the first terminal data, the first IoT server encrypts the first terminal data to obtain first encrypted terminal data; the first IoT server transmitting the first encrypted terminal data to the first cloud server, and simultaneously sending the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers. The solution of this invention can assign corresponding encryption strategies according to the attributes of IoT terminals and save the data operations to a dedicated edge cloud server, which not only ensures data security but also provides data operation traceability and inspection. Attached Figure Description

[0075] Figure 1 This is a schematic block diagram of a data encryption system based on edge cloud computing provided in one embodiment of the present invention;

[0076] Figure 2 This is a flowchart of a data encryption method based on edge cloud computing provided in another embodiment of the present invention. Detailed Implementation

[0077] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other.

[0078] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and therefore the scope of protection of the invention is not limited to the specific embodiments disclosed below.

[0079] The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0080] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0081] The following reference Figures 1 to 2 This invention describes a data encryption system and method based on edge cloud computing, provided by some embodiments of the present invention.

[0082] like Figure 1 As shown, one embodiment of the present invention provides a data encryption system based on edge cloud computing, comprising: multiple IoT terminals, multiple IoT servers, a first cloud server for storing and managing data, multiple edge cloud servers, and a second cloud server for subject registration, allocation of storage resources, and provision of encryption strategies; wherein,

[0083] The second cloud server is configured as follows:

[0084] The system receives registration requests from the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers, registers them, and configures unique identifiers for each of the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers.

[0085] Establish communication connections with the multiple edge cloud servers and form a security verification system;

[0086] The first IoT terminal among the plurality of IoT terminals is configured to: collect first terminal data and send first attribute data generated based on the first terminal data to the second cloud server;

[0087] The second cloud server is configured as follows:

[0088] Determine the first encryption strategy for the first terminal data based on the first attribute data;

[0089] Send the first encryption policy to the first cloud server;

[0090] The first cloud server is configured to: parse the first encryption policy and send the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers;

[0091] The first IoT server is configured as follows:

[0092] After receiving the first terminal data, the first terminal data is encrypted to obtain the first encrypted terminal data;

[0093] The first encrypted terminal data is transmitted to the first cloud server, and the operation record of the operation performed on the first terminal data is sent to the corresponding first edge cloud server among the plurality of edge cloud servers.

[0094] It is understood that, in this embodiment of the invention, the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers are all registered on the second cloud server and configured with unique identifiers. The IoT terminals, IoT servers, and the first cloud server constitute a system for data acquisition, processing, transmission, and storage. Connections / correspondences are established between the plurality of IoT terminals and the plurality of IoT servers based on factors such as the attributes of the IoT terminals, the type of data collected, the data volume, and the performance / processing capabilities of the IoT servers (for example, a data transmission and processing correspondence is established between IoT terminal A and IoT server b). The IoT terminals can be smart home terminals, smart streetlights, smart health terminals, smart teaching terminals, smart camera terminals, smart machine tools, smart cars, robots, etc.

[0095] The second cloud server establishes a communication connection with the multiple edge cloud servers to form a security verification system, and the second cloud server allocates storage resources and provides encryption strategies.

[0096] The first IoT terminal among the plurality of IoT terminals collects first terminal data and sends first attribute data generated based on the first terminal data (such as attribute information of the first terminal and attribute information of the first terminal data) to the second cloud server; the second cloud server determines a first encryption strategy for the first terminal data based on the first attribute data (such as selecting a fast and secure encryption strategy based on the type, size, and format of the first terminal data); the second cloud server sends the first encryption strategy to the first cloud server; the first cloud server parses the first encryption strategy and sends relevant encryption information (such as encryption key, unique identifier of the IoT server performing the encryption operation, etc.) to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers; the first IoT terminal sends the first terminal data to the first IoT server based on the relevant encryption information; after receiving the first terminal data, the first IoT server encrypts the first terminal data to obtain first encrypted terminal data; the first IoT server transmits the first encrypted terminal data to the first cloud server, and simultaneously sends the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers to ensure that all data operations can be traced in the future.

[0097] The solution of this invention can assign corresponding encryption strategies according to the attributes of IoT terminals and save the data operations to a dedicated edge cloud server, which not only ensures data security but also provides data operation traceability and inspection.

[0098] It should be known that, Figure 1 The block diagram of the edge cloud computing-based data encryption system shown is for illustrative purposes only, and the number of modules shown does not limit the scope of protection of this invention.

[0099] In some possible embodiments of the present invention, the first cloud server is configured as follows:

[0100] Based on the attribute characteristics of the multiple IoT terminals, multiple data transmission routes, data volume attribute characteristics, and data operation characteristics of each IoT terminal are generated, and a first correspondence is established between each IoT terminal and each IoT server.

[0101] The multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship are sent to the second cloud server.

[0102] Understandably, in order to provide the optimal security solution for data transmission, in this embodiment, the first cloud server generates multiple data transmission routes (such as routes connecting different IoT servers), data volume attribute characteristics (such as data size, data volume variation characteristics over time, etc.), and data operation characteristics (such as operation type, operation time, operation number, etc.) for each IoT terminal among the multiple IoT terminals based on the attribute characteristics of each IoT terminal among the multiple IoT terminals. It then establishes a first correspondence between each IoT terminal among the multiple IoT terminals and each IoT server among the multiple IoT servers (such as establishing a correspondence between IoT servers with matching processing capabilities based on the attribute information / characteristics of the IoT terminals and / or the attribute information / characteristics of the collected data). The first cloud server then sends the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence to the second cloud server.

[0103] In some possible embodiments of the present invention, the second cloud server is configured as follows:

[0104] Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence, determine the first transmission route and the first storage location of the first terminal data;

[0105] Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence, and in conjunction with preset selection rules, the first registration position of the relevant operation record of the first terminal data is selected from the multiple edge cloud servers.

[0106] Send the first transmission route, the first storage location, and the first registration location to the first cloud server;

[0107] The first cloud server is configured to: send the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

[0108] Understandably, to further determine an efficient and secure data transmission scheme, in this embodiment, the second cloud server determines the first transmission route (e.g., determining the transmission route based on the correspondence between the attribute information / features of the collected data and IoT servers with matching processing capabilities) and the first storage location (e.g., selecting a specific storage partition from the first cloud server, or selecting one from multiple first cloud servers) of the first terminal data based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence, combined with preset selection rules (e.g., randomly specified by the second cloud server or specified according to a preset algorithm), and selects the first registration location of the relevant operation records of the first terminal data from the multiple edge cloud servers. The first cloud server distributes the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the multiple IoT servers to facilitate data transmission.

[0109] In some possible embodiments of the present invention, the first cloud server is configured as follows:

[0110] The steps of parsing the first encryption strategy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers include:

[0111] The first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key are obtained from the first encryption strategy.

[0112] Send the unique identifier of the first IoT server to the first IoT terminal;

[0113] The first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy are sent to the first IoT server.

[0114] It is understood that in this embodiment, the first cloud server parses the first encryption key and first decryption key, third encryption key and third decryption key, fourth encryption key and fourth decryption key, and second encryption algorithm generation strategy from the first encryption strategy. The first cloud server sends the unique identifier of the first IoT server to the first IoT terminal so that the first IoT terminal can determine the recipient of its data, and sends the first encryption key, third encryption key, fourth encryption key, and second encryption algorithm generation strategy to the first IoT server. This scheme can accurately and efficiently allocate encryption keys.

[0115] In some possible embodiments of the present invention, in the operation of encrypting the first terminal data after the first IoT server receives the first terminal data to obtain the first encrypted terminal data, the first IoT server is specifically configured as follows:

[0116] A second encryption key and a second decryption key are generated according to the second encryption algorithm generation strategy;

[0117] The first terminal data is encrypted using the second encryption key to obtain the first encrypted data;

[0118] Obtain multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypt the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data;

[0119] The first encrypted data, the supplementary data, and the second decryption key are encrypted separately using the fourth encryption key and then mixed to obtain the second encrypted data.

[0120] The first encryption key is used to encrypt the second encryption data to obtain the first encrypted terminal data;

[0121] In determining the plurality of geographic location data, the first cloud server is configured as follows:

[0122] Using the location coordinates of any one of the multiple IoT servers as the center and a preset radius, construct a sphere, and select N points on the surface of the sphere;

[0123] The N coordinate values ​​corresponding to the N points are used as geographical location coordinates;

[0124] For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained;

[0125] The set of geographic coordinates is used as the multiple geographic location data.

[0126] Understandably, to improve the security level of data encryption, in this embodiment, the first IoT server first generates a paired second encryption key and a second decryption key according to the second encryption algorithm generation strategy. Then, the second encryption key is used to encrypt the first terminal data to obtain the first encrypted data. Next, considering the security and convenience of data selection, multiple geographical location data and unique identifiers of the multiple IoT servers are obtained from the first cloud server. The third encryption key is used to encrypt the multiple geographical location data and the unique identifiers of the multiple IoT servers to obtain supplementary data to increase the difficulty of data cracking. Then, the first encrypted data, the supplementary data, and the second decryption key are encrypted using the fourth encryption key and mixed to obtain the second encrypted data. Finally, the first encryption key is used to encrypt the second encrypted data to obtain the first encrypted terminal data. It should be noted that, in order to further improve security, the multiple geographic location data are determined in the following way: The first cloud server takes the location coordinates of any one of the multiple IoT servers as the center and constructs a sphere with a preset radius, and selects N points on the surface of the sphere; the N three-dimensional coordinate values ​​corresponding to the N points are used as geographic location coordinates (N is a positive integer); for the remaining IoT servers among the multiple IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the multiple IoT servers is obtained; the geographic location coordinate set is used as the multiple geographic location data (for example, the X, Y and Z values ​​of multiple three-dimensional coordinate values ​​in the geographic location coordinate set are extracted separately to form a sequence, and then the sequence is randomly divided into multiple sub-sequences, and the multiple sub-sequences are subjected to matrix operations and used as the multiple geographic location data).

[0127] Please refer to Figure 2 Another embodiment of the present invention provides a data encryption method based on edge cloud computing, applied to a data encryption system. The data encryption system includes multiple IoT terminals, multiple IoT servers, a first cloud server for storing and managing data, multiple edge cloud servers, and a second cloud server for subject registration, allocation of storage resources, and provision of encryption strategies. The method includes:

[0128] The plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively send registration requests to the second cloud server;

[0129] The second cloud server receives the registration request, registers the data, and configures unique identifiers for the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively.

[0130] The second cloud server establishes a communication connection with the multiple edge cloud servers and forms a security verification system;

[0131] The first IoT terminal among the plurality of IoT terminals collects first terminal data and sends first attribute data generated based on the first terminal data to the second cloud server.

[0132] The second cloud server determines the first encryption strategy for the first terminal data based on the first attribute data;

[0133] The second cloud server sends the first encryption policy to the first cloud server;

[0134] The first cloud server parses the first encryption policy and sends the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers;

[0135] After receiving the data from the first terminal, the first IoT server encrypts the data to obtain the first encrypted terminal data.

[0136] The first IoT server transmits the first encrypted terminal data to the first cloud server, and simultaneously sends the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers.

[0137] It is understood that, in this embodiment of the invention, the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers are all registered on the second cloud server and configured with unique identifiers. The IoT terminals, IoT servers, and the first cloud server constitute a system for data acquisition, processing, transmission, and storage. Connections / correspondences are established between the plurality of IoT terminals and the plurality of IoT servers based on factors such as the attributes of the IoT terminals, the type of data collected, the data volume, and the performance / processing capabilities of the IoT servers (for example, a data transmission and processing correspondence is established between IoT terminal A and IoT server b). The IoT terminals can be smart home terminals, smart streetlights, smart health terminals, smart teaching terminals, smart camera terminals, smart machine tools, smart cars, robots, etc.

[0138] The second cloud server establishes a communication connection with the multiple edge cloud servers to form a security verification system, and the second cloud server allocates storage resources and provides encryption strategies.

[0139] The first IoT terminal among the plurality of IoT terminals collects first terminal data and sends first attribute data generated based on the first terminal data (such as attribute information of the first terminal and attribute information of the first terminal data) to the second cloud server; the second cloud server determines a first encryption strategy for the first terminal data based on the first attribute data (such as selecting a fast and secure encryption strategy based on the type, size, and format of the first terminal data); the second cloud server sends the first encryption strategy to the first cloud server; the first cloud server parses the first encryption strategy and sends relevant encryption information (such as encryption key, unique identifier of the IoT server performing the encryption operation, etc.) to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers; the first IoT terminal sends the first terminal data to the first IoT server based on the relevant encryption information; after receiving the first terminal data, the first IoT server encrypts the first terminal data to obtain first encrypted terminal data; the first IoT server transmits the first encrypted terminal data to the first cloud server, and simultaneously sends the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers to ensure that all data operations can be traced in the future.

[0140] The solution of this invention can assign corresponding encryption strategies according to the attributes of IoT terminals and save the data operations to a dedicated edge cloud server, which not only ensures data security but also provides data operation traceability and inspection.

[0141] In some possible embodiments of the present invention, the method further includes:

[0142] The first cloud server generates multiple data transmission routes, data volume attribute characteristics, and data operation characteristics for each of the multiple IoT terminals based on the attribute characteristics of the multiple IoT terminals, and establishes a first correspondence between each of the multiple IoT terminals and each of the multiple IoT servers.

[0143] The first cloud server sends the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship to the second cloud server.

[0144] Understandably, in order to provide the optimal security solution for data transmission, in this embodiment, the first cloud server generates multiple data transmission routes (such as routes connecting different IoT servers), data volume attribute characteristics (such as data size, data volume variation characteristics over time, etc.), and data operation characteristics (such as operation type, operation time, operation number, etc.) for each IoT terminal among the multiple IoT terminals based on the attribute characteristics of each IoT terminal among the multiple IoT terminals. It then establishes a first correspondence between each IoT terminal among the multiple IoT terminals and each IoT server among the multiple IoT servers (such as establishing a correspondence between IoT servers with matching processing capabilities based on the attribute information / characteristics of the IoT terminals and / or the attribute information / characteristics of the collected data). The first cloud server then sends the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence to the second cloud server.

[0145] In some possible embodiments of the present invention, the method further includes:

[0146] The second cloud server determines the first transmission route and the first storage location of the first terminal data based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence.

[0147] The second cloud server selects the first registration position of the relevant operation record of the first terminal data from the multiple edge cloud servers based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship, and in combination with preset selection rules.

[0148] The second cloud server sends the first transmission route, the first storage location, and the first registration location to the first cloud server;

[0149] The first cloud server distributes the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

[0150] Understandably, to further determine an efficient and secure data transmission scheme, in this embodiment, the second cloud server determines the first transmission route (e.g., determining the transmission route based on the correspondence between the attribute information / features of the collected data and IoT servers with matching processing capabilities) and the first storage location (e.g., selecting a specific storage partition from the first cloud server, or selecting one from multiple first cloud servers) of the first terminal data based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence, combined with preset selection rules (e.g., randomly specified by the second cloud server or specified according to a preset algorithm), and selects the first registration location of the relevant operation records of the first terminal data from the multiple edge cloud servers. The first cloud server distributes the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the multiple IoT servers to facilitate data transmission.

[0151] In some possible embodiments of the present invention, the step of the first cloud server parsing the first encryption policy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers includes:

[0152] The first cloud server parses the first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key from the first encryption strategy;

[0153] The first cloud server sends the unique identifier of the first IoT server to the first IoT terminal;

[0154] The first cloud server sends the first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy to the first IoT server.

[0155] It is understood that in this embodiment, the first cloud server parses the first encryption key and first decryption key, third encryption key and third decryption key, fourth encryption key and fourth decryption key, and second encryption algorithm generation strategy from the first encryption strategy. The first cloud server sends the unique identifier of the first IoT server to the first IoT terminal so that the first IoT terminal can determine the recipient of its data, and sends the first encryption key, third encryption key, fourth encryption key, and second encryption algorithm generation strategy to the first IoT server. This scheme can accurately and efficiently allocate encryption keys.

[0156] In some possible embodiments of the present invention, the step of encrypting the first terminal data to obtain first encrypted terminal data after the first IoT server receives the first terminal data includes:

[0157] The first IoT server generates a second encryption key and a second decryption key according to the second encryption algorithm generation strategy;

[0158] The first IoT server uses the second encryption key to encrypt the data of the first terminal to obtain the first encrypted data;

[0159] The first IoT server obtains multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypts the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data;

[0160] The first IoT server uses the fourth encryption key to encrypt the first encrypted data, the supplementary data, and the second decryption key respectively, and then mixes them to obtain the second encrypted data;

[0161] The first IoT server uses the first encryption key to encrypt the second encryption data to obtain the first encrypted terminal data;

[0162] The plurality of geographic location data are determined in the following manner:

[0163] The first cloud server uses the location coordinates of any one of the multiple IoT servers as the center of a sphere with a preset radius, and selects N points on the surface of the sphere.

[0164] The N coordinate values ​​corresponding to the N points are used as geographical location coordinates;

[0165] For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained;

[0166] The set of geographic coordinates is used as the multiple geographic location data.

[0167] Understandably, to improve the security level of data encryption, in this embodiment, the first IoT server first generates a paired second encryption key and a second decryption key according to the second encryption algorithm generation strategy. Then, the second encryption key is used to encrypt the first terminal data to obtain the first encrypted data. Next, considering the security and convenience of data selection, multiple geographical location data and unique identifiers of the multiple IoT servers are obtained from the first cloud server. The third encryption key is used to encrypt the multiple geographical location data and the unique identifiers of the multiple IoT servers to obtain supplementary data to increase the difficulty of data cracking. Then, the first encrypted data, the supplementary data, and the second decryption key are encrypted using the fourth encryption key and mixed to obtain the second encrypted data. Finally, the first encryption key is used to encrypt the second encrypted data to obtain the first encrypted terminal data. It should be noted that, in order to further improve security, the multiple geographic location data are determined in the following way: The first cloud server takes the location coordinates of any one of the multiple IoT servers as the center and constructs a sphere with a preset radius, and selects N points on the surface of the sphere; the N three-dimensional coordinate values ​​corresponding to the N points are used as geographic location coordinates (N is a positive integer); for the remaining IoT servers among the multiple IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the multiple IoT servers is obtained; the geographic location coordinate set is used as the multiple geographic location data (for example, the X, Y and Z values ​​of multiple three-dimensional coordinate values ​​in the geographic location coordinate set are extracted separately to form a sequence, and then the sequence is randomly divided into multiple sub-sequences, and the multiple sub-sequences are subjected to matrix operations and used as the multiple geographic location data).

[0168] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.

[0169] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0170] In the several embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical or other forms.

[0171] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0172] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0173] If the integrated units described above are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0174] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0175] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

[0176] While the present invention has been disclosed above, it is not limited thereto. Any person skilled in the art can easily conceive of variations or substitutions without departing from the spirit and scope of the present invention, and various modifications and alterations can be made, including combinations of the different functions and implementation steps described above, as well as software and hardware implementation methods, all of which are within the protection scope of the present invention.

Claims

1. A data encryption system based on edge cloud computing, characterized in that, include: Multiple IoT terminals, multiple IoT servers, a primary cloud server for storing and managing data, multiple edge cloud servers, and a secondary cloud server for subject registration, storage resource allocation, and encryption policy provision; among them, The second cloud server is configured as follows: The system receives registration requests from the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers, registers them, and configures unique identifiers for each of the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers. Establish communication connections with the multiple edge cloud servers and form a security verification system; The first IoT terminal among the plurality of IoT terminals is configured to: collect first terminal data and send first attribute data generated based on the first terminal data to the second cloud server; The second cloud server is configured as follows: Determine the first encryption strategy for the first terminal data based on the first attribute data; Send the first encryption policy to the first cloud server; The first cloud server is configured to: parse the first encryption policy and send the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers; The first IoT server is configured as follows: After receiving the first terminal data, the first terminal data is encrypted to obtain the first encrypted terminal data; The first encrypted terminal data is transmitted to the first cloud server, and the operation record of the operation performed on the first terminal data is sent to the corresponding first edge cloud server among the plurality of edge cloud servers. The first cloud server is also configured as follows: The steps of parsing the first encryption strategy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers include: The first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key are obtained from the first encryption strategy. Send the unique identifier of the first IoT server to the first IoT terminal; The first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy are sent to the first IoT server; Specifically, in the operation where the first IoT server encrypts the first terminal data after receiving the first terminal data to obtain the first encrypted terminal data, the first IoT server is configured as follows: A second encryption key and a second decryption key are generated according to the second encryption algorithm generation strategy; The first terminal data is encrypted using the second encryption key to obtain the first encrypted data; Obtain multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypt the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data; The first encrypted data, the supplementary data, and the second decryption key are encrypted separately using the fourth encryption key and then mixed to obtain the second encrypted data. The first encryption key is used to encrypt the second encryption data to obtain the first encrypted terminal data; In determining the plurality of geographic location data, the first cloud server is configured as follows: Using the location coordinates of any one of the multiple IoT servers as the center and a preset radius, construct a sphere, and select N points on the surface of the sphere; The N coordinate values ​​corresponding to the N points are used as geographical location coordinates; For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained; The set of geographic coordinates is used as the multiple geographic location data.

2. The data encryption system based on edge cloud computing according to claim 1, characterized in that, The first cloud server is configured as follows: Based on the attribute characteristics of the multiple IoT terminals, multiple data transmission routes, data volume attribute characteristics, and data operation characteristics of each IoT terminal are generated, and a first correspondence is established between each IoT terminal and each IoT server. The multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship are sent to the second cloud server.

3. The data encryption system based on edge cloud computing according to claim 2, characterized in that, The second cloud server is configured as follows: Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence, determine the first transmission route and the first storage location of the first terminal data; Based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence, and in conjunction with preset selection rules, the first registration position of the relevant operation record of the first terminal data is selected from the multiple edge cloud servers. Send the first transmission route, the first storage location, and the first registration location to the first cloud server; The first cloud server is configured to: send the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

4. A data encryption method based on edge cloud computing, characterized in that, Applied to the data encryption system as described in claims 1-3, the data encryption system includes multiple IoT terminals, multiple IoT servers, a first cloud server for storing and managing data, multiple edge cloud servers, and a second cloud server for subject registration, allocation of storage resources, and provision of encryption strategies, the method includes: The plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively send registration requests to the second cloud server; The second cloud server receives the registration request, registers the data, and configures unique identifiers for the plurality of IoT terminals, the plurality of IoT servers, the first cloud server, and the plurality of edge cloud servers respectively. The second cloud server establishes a communication connection with the multiple edge cloud servers and forms a security verification system; The first IoT terminal among the plurality of IoT terminals collects first terminal data and sends first attribute data generated based on the first terminal data to the second cloud server. The second cloud server determines the first encryption strategy for the first terminal data based on the first attribute data; The second cloud server sends the first encryption policy to the first cloud server; The first cloud server parses the first encryption policy and sends the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers; After receiving the data from the first terminal, the first IoT server encrypts the data to obtain the first encrypted terminal data. The first IoT server transmits the first encrypted terminal data to the first cloud server, and at the same time sends the operation record of the operation performed on the first terminal data to the corresponding first edge cloud server among the plurality of edge cloud servers; The step of the first cloud server parsing the first encryption policy and sending the relevant encryption information to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers includes: The first cloud server parses the first encryption key, the first decryption key, the second encryption algorithm generation strategy, the third encryption key, the third decryption key, the fourth encryption key, and the fourth decryption key from the first encryption strategy; The first cloud server sends the unique identifier of the first IoT server to the first IoT terminal; The first cloud server sends the first encryption key, the third encryption key, the fourth encryption key, and the second encryption algorithm generation strategy to the first IoT server; The step of encrypting the first terminal data after receiving the first terminal data by the first IoT server to obtain the first encrypted terminal data includes: The first IoT server generates a second encryption key and a second decryption key according to the second encryption algorithm generation strategy; The first IoT server uses the second encryption key to encrypt the data of the first terminal to obtain the first encrypted data; The first IoT server obtains multiple geographic location data and unique identifiers of the multiple IoT servers from the first cloud server, and encrypts the multiple geographic location data and unique identifiers of the multiple IoT servers using the third encryption key to obtain supplementary data; The first IoT server uses the fourth encryption key to encrypt the first encrypted data, the supplementary data, and the second decryption key respectively, and then mixes them to obtain the second encrypted data; The first IoT server uses the first encryption key to encrypt the second encryption data to obtain the first encrypted terminal data; The plurality of geographic location data are determined in the following manner: The first cloud server uses the location coordinates of any one of the multiple IoT servers as the center of a sphere with a preset radius, and selects N points on the surface of the sphere. The N coordinate values ​​corresponding to the N points are used as geographical location coordinates; For the remaining IoT servers among the plurality of IoT servers, the above operation is performed until the geographic location coordinate set of all IoT servers among the plurality of IoT servers is obtained; The set of geographic coordinates is used as the multiple geographic location data.

5. The data encryption method based on edge cloud computing according to claim 4, characterized in that, The method further includes: The first cloud server generates multiple data transmission routes, data volume attribute characteristics, and data operation characteristics for each of the multiple IoT terminals based on the attribute characteristics of the multiple IoT terminals, and establishes a first correspondence between each of the multiple IoT terminals and each of the multiple IoT servers. The first cloud server sends the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship to the second cloud server.

6. The data encryption method based on edge cloud computing according to claim 5, characterized in that, The method further includes: The second cloud server determines the first transmission route and the first storage location of the first terminal data based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, and the first correspondence. The second cloud server selects the first registration position of the relevant operation record of the first terminal data from the multiple edge cloud servers based on the first attribute data, the multiple data transmission routes, the data volume attribute characteristics, the data operation characteristics, and the first correspondence relationship, and in combination with preset selection rules. The second cloud server sends the first transmission route, the first storage location, and the first registration location to the first cloud server; The first cloud server distributes the first transmission route, the first storage location, and the first registration location to the corresponding first IoT server and the first IoT terminal among the plurality of IoT servers.

Citation Information

Patent Citations

  • Information processing method, terminal, central equipment, server and storage medium

    CN113098678A

  • Intelligent network connection automobile data security management system and method based on block chain

    CN114254383A