Data transmission method and apparatus

By verifying and encrypting device information through a proxy server, the problem of older devices being unable to connect to the Internet of Things (IoT) is solved, enabling low-cost IoT management and control.

CN116346876BActive Publication Date: 2026-03-17SHANGHAI BANGBANG ROBOT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-22
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In existing technologies, the lack of encryption functionality prevents IoT devices from directly connecting to the Internet of Things (IoT), increasing the cost of IoT management and control.

Method used

The device's legitimacy is verified by a proxy server, and the device information is encrypted and sent to the IoT server after verification, thus establishing a communication connection between the device and the IoT server.

Benefits of technology

The Internet of Things (IoT) can be managed without replacing outdated equipment, thus reducing the management and control costs of IoT.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346876B_ABST
    Figure CN116346876B_ABST
Patent Text Reader

Abstract

The application provides a data transmission method and device, the method comprising: obtaining device information of a device according to a first connection request sent by the device when the first connection request is received; verifying whether the device is a legal device when it is determined according to the device information that the device does not meet access conditions of an Internet of Things server; establishing a communication connection between the device and the proxy server when it is verified that the device is a legal device; receiving first information sent by the device and encrypting the first information to obtain second information; and sending the second information to the Internet of Things server. In the application, the proxy server encrypts information sent by a device and sends the encrypted information to the Internet of Things server when it is verified that the device is a legal access device and does not have the ability to connect to the Internet of Things server, so that the Internet of Things can be managed and controlled without replacing old devices, and the management and control cost of the Internet of Things is low.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) technology, and more particularly to a data transmission method and apparatus. Background Technology

[0002] The Internet of Things (IoT) is an information carrier based on the Internet, traditional telecommunications networks, and other infrastructure. It enables all independently addressable ordinary physical devices to form an interconnected network, achieving ubiquitous connectivity between things and between things and people, and realizing intelligent sensing, identification, and management of objects and processes.

[0003] With the development of IoT technology, IoT requires connected devices to have data encryption capabilities. However, some older devices lack data encryption capabilities, thus preventing them from connecting to the IoT.

[0004] If customers need to perform IoT sensing, identification, and management, they will need to replace these outdated devices, which shows that IoT management and control costs are relatively high. Summary of the Invention

[0005] This invention provides a data transmission method and apparatus to solve the problem of achieving high control and management efficiency in the Internet of Things.

[0006] On one hand, the present invention provides a data transmission method applied to a proxy server, comprising:

[0007] Upon receiving a first connection request from the device, the device information of the device is obtained based on the first connection request;

[0008] When it is determined from the device information that the device does not meet the access conditions of the IoT server, verify whether the device is a legitimate device;

[0009] When verifying that the device is a legitimate device, a communication connection is established between the device and the proxy server;

[0010] Receive the first information sent by the device, and encrypt the first information to obtain the second information;

[0011] The second information is sent to the IoT server.

[0012] In one embodiment, the step of verifying whether the device is a legitimate device includes:

[0013] The proxy server's current network time is sent to the device so that the device's network time is synchronized with the proxy server's.

[0014] Receive the first digital signature sent by the device;

[0015] Parsing the first digital signature yields a first random number generated by the device using a first random number generator and the generation time point corresponding to the first random number, wherein the first random number generator generates random numbers with a preset pattern within a periodic time.

[0016] Obtain the second random number generated by the second random number generator in the proxy server at the generation time point, wherein the second random number generator generates random numbers with the preset pattern within a periodic time.

[0017] If the first random number is the same as the second random number, the device is determined to be a legitimate device.

[0018] In one embodiment, the step of verifying whether the device is a legitimate device includes:

[0019] Obtain the second digital signature of the device according to the first connection request;

[0020] Parsing the second digital signature yields a third random number generated by the device using a first random number generator, and the interval between the generation time point and the target time point corresponding to the third random number. The first random number generator generates random numbers with a preset pattern within a periodic time, and the target time point is the start or end time point within the periodic time.

[0021] Obtain each fourth random number generated by the second random number generator within the proxy server within the specified period, wherein the second random number generator generates random numbers with a preset pattern within the specified period.

[0022] Determine the target random number corresponding to the interval duration from each of the fourth random numbers;

[0023] When the third random number is the same as the target random number, the device is determined to be a legitimate device.

[0024] In one embodiment, the step of sending the second information to the IoT server includes:

[0025] Running a four-layer proxy function;

[0026] The second information is forwarded to the IoT server based on the four-layer proxy function.

[0027] In one embodiment, after the step of sending the second information to the IoT server, the method further includes:

[0028] Receive third information fed back by the IoT server based on the second information;

[0029] The fourth information is obtained by decrypting the third information;

[0030] The fourth piece of information is sent to the device.

[0031] In one embodiment, the step of sending the second information to the IoT server includes:

[0032] The IoT server that the device requests to access is determined based on the first information;

[0033] Send a second connection request to the IoT server, the second connection request being used to request access to the IoT server;

[0034] Upon receiving access permission information from the IoT server, a communication connection is established between the proxy server and the IoT server, and the second information is sent to the IoT server.

[0035] On the other hand, the present invention also provides a proxy server, the proxy server comprising:

[0036] The acquisition module is used to acquire device information of the device according to the first connection request when it receives a first connection request sent by the device;

[0037] The verification module is used to verify whether the device is a legitimate device when it is determined from the device information that the device does not meet the access conditions of the IoT server.

[0038] A module is established to establish a communication connection between the device and the proxy server when verifying that the device is a legitimate device;

[0039] A receiving module is used to receive first information sent by the device and encrypt the first information to obtain second information;

[0040] The sending module is used to send the second information to the Internet of Things server.

[0041] On the other hand, the present invention also provides a proxy server, including: a memory and a processor;

[0042] The memory stores computer-executed instructions;

[0043] The processor executes computer execution instructions stored in the memory, causing the processor to perform the data transfer method as described above.

[0044] On the other hand, the present invention also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the data transmission method described above.

[0045] On the other hand, the present invention also provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the data transmission method as described above.

[0046] The data transmission method and apparatus provided by this invention, upon receiving a first connection request from a device, obtains the device information based on the connection request. If, based on the device information, it is determined that the device does not meet the access conditions for the Internet of Things (IoT), the method verifies whether the device is a legitimate device. If the device is legitimate, a communication connection is established between the device and a proxy server. Upon receiving first information sent by the device, the method encrypts the first information to obtain second information, which is then sent to the IoT server. In this invention, when the proxy server verifies that the device is legitimately connected and does not have the capability to connect to the IoT server, it encrypts the information sent by the device and sends it to the IoT server. This allows for IoT management without replacing outdated equipment, resulting in lower IoT management costs. Attached Figure Description

[0047] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0048] Figure 1 This is a system architecture diagram of the data transmission method of the present invention;

[0049] Figure 2 This is a flowchart illustrating the first embodiment of the data transmission method of the present invention;

[0050] Figure 3 This is a detailed flowchart of step S20 in the second embodiment of the data transmission method of the present invention;

[0051] Figure 4 This is a detailed flowchart of step S20 in the third embodiment of the data transmission method of the present invention;

[0052] Figure 5 This is a detailed flowchart of step S50 in the fourth embodiment of the data transmission method of the present invention;

[0053] Figure 6 This is a schematic diagram of the proxy server module of the present invention;

[0054] Figure 7 This is a schematic diagram of the proxy server structure of the present invention.

[0055] The accompanying drawings have illustrated specific embodiments of this disclosure, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concepts of this disclosure to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0056] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0057] This invention provides a data transmission method. For example... Figure 1 As shown, proxy server 100 communicates with IoT server 200 via a TCP (Transmission Control Protocol) connection. Proxy server 100 can also be an Nginx reverse proxy server. Proxy server 100 connects to multiple devices 300. Devices 300 may not meet IoT access requirements; for example, they may be devices with a 2G communication module or lack data encryption capabilities. Devices 300 send data to proxy server 100, which encrypts the data and then sends the encrypted data to IoT server 200, thus indirectly enabling data transmission between devices 300 and IoT server 200.

[0058] The technical solutions of the present invention and how they solve the above-mentioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present invention will now be described with reference to the accompanying drawings.

[0059] Reference Figure 2 , Figure 2 This is a first embodiment of the data transmission method of the present invention, which includes the following steps:

[0060] Step S10: Upon receiving the first connection request sent by the device, obtain the device information of the device according to the first connection request.

[0061] In this embodiment, the execution entity is a proxy server. The proxy server can be an Nginx reverse proxy server. The device sends a connection request to the proxy server; this connection request is defined as the first connection request. The first connection request carries the device's information, including its identifier, model, and other information. The proxy server needs to determine, based on the device information, whether the device is capable of connecting to the IoT server.

[0062] The proxy server first determines the device model based on the device information, then obtains the device's functional information associated with that model. This functional information can be obtained from the internet. If the device's functional information indicates that it lacks data encryption capabilities, then the device does not meet the access requirements of the IoT server. Data encryption is required when transmitting data between IoT devices; therefore, having data encryption capabilities is a prerequisite for access. Furthermore, the proxy server can directly obtain the device model based on the device information, and then determine whether the device is an older model based on its signal strength, specifically whether its communication module is a 2G or 3G module. Devices with 2G communication modules do not have data encryption capabilities. If the device's communication module is a 2G module, then the device does not meet the access requirements of the IoT server.

[0063] In addition, IoT servers require data encryption using SSL (Secure Sockets Layer) encryption. If a device only supports TCP encryption, it does not meet the access requirements for an IoT server.

[0064] Step S20: If it is determined from the device information that the device does not meet the access conditions of the IoT server, verify whether the device is a legitimate device.

[0065] Proxy servers communicate with any device, therefore device verification is necessary to prevent unauthorized devices from connecting and ensure the security of information within the proxy server. To this end, when the proxy server determines that a device does not meet the access requirements of the IoT server based on its device information, it needs to further verify whether the device is legitimate. Devices can register on the proxy server. After successful registration, the proxy server sends a random number generator to the device. The random number generator generates random numbers according to a preset pattern within a periodic interval. Therefore, when a device requests access to the proxy server, it can include a random number in its initial connection request. If the random number generated by the proxy server's random number generator matches the random number included in the initial connection request, the device is confirmed to be a registered and legitimate device.

[0066] Step S30: When verifying that the device is a legitimate device, establish a communication connection between the device and the proxy server.

[0067] After the proxy server verifies that the device is a legitimate device, it establishes a communication connection between the device and the proxy server, and the proxy server can then forward the information sent by the device to the IoT server.

[0068] Step S40: Receive the first information sent by the receiving device and encrypt the first information to obtain the second information.

[0069] When the proxy server receives the first message from the device, it needs to determine whether the first message is destined for the IoT server. If the first message contains preset fields, it can be determined that the first message needs to be sent to the IoT server. The proxy server encrypts the first message to obtain the second message. If the IoT server requires SSL encryption, then SSL encryption is used to encrypt the first message to obtain the second message. If the IoT server requires TCP encryption, then TCP encryption is used to encrypt the first message to obtain the second message.

[0070] Step S50: Send the second information to the IoT server.

[0071] After receiving the second information, it is sent to the IoT server. When the proxy server is an Nginx reverse proxy server, the Nginx reverse proxy server establishes a TCP connection with the device and runs a Layer 4 proxy function to open a dedicated TLS channel to connect to the IoT server. The second information is then sent to the IoT server through the Layer 4 proxy function, thus achieving Layer 4 proxy forwarding from TCP to TLS.

[0072] In the technical solution provided in this embodiment, upon receiving a first connection request from a device, the device information of the device is obtained based on the connection request. If it is determined from the device information that the device does not meet the access conditions for the Internet of Things (IoT), the device is verified as a legitimate device. If the device is legitimate, a communication connection is established between the device and the proxy server. Upon receiving first information sent by the device, the first information is encrypted to obtain second information, which is then sent to the IoT server. In this invention, when the proxy server verifies that the device is legitimately accessing the IoT server and does not have the capability to connect to it, it encrypts the information sent by the device and sends it to the IoT server. This allows for IoT management without replacing outdated equipment, resulting in lower IoT management costs.

[0073] Reference Figure 3 , Figure 3 This is a second embodiment of the data transmission method of the present invention. Based on the first embodiment, step S20 includes:

[0074] Step S21: Send the current network time of the proxy server to the device so that the network time of the device is synchronized with that of the proxy server.

[0075] In this embodiment, if the device is registered with the proxy server, both the device and the proxy server have the same random number generator. The random number generators in both the device and the proxy server need to generate random numbers synchronously so that the proxy server can successfully verify that the device is legitimate. To this end, the proxy server sends its network time to the device, ensuring that the device's network time is synchronized with the proxy server's.

[0076] Step S22: Receive the first digital signature sent by the receiving device, and parse the first digital signature to obtain the first random number generated by the device using the first random number generator and the generation time point corresponding to the first random number. The first random number generator generates random numbers with a preset pattern within a periodic time.

[0077] After synchronizing network time, the device generates a first random number using a first random number generator. This generator produces random numbers with a preset pattern within a set period. This preset pattern is set by the proxy server. The device then uses the first random number, its generation time, and verification information to create a digital signature. This digital signature is defined as the first digital signature. The device then sends the first digital signature to the proxy server.

[0078] The proxy server parses the first digital signature to obtain the first random number and the corresponding generation time of the first random number.

[0079] Step S23: Obtain the second random number generated by the second random number generator in the proxy server at the generation time point, wherein the second random number generator generates random numbers with a preset pattern within a periodic time.

[0080] The proxy server includes a second random number generator. This second random number generator generates random numbers according to a preset pattern within a set period; that is, the second random number generator is identical to the first random number generator. The proxy server controls the second random number generator to continuously generate the second random number.

[0081] When the proxy server obtains the generation time of the first random number, it retrieves the second random number generated by the second random number generator at the generation time.

[0082] Step S24: When the first random number and the second random number are the same, determine that the device is a legitimate device.

[0083] Because the device synchronizes its network time with the proxy server, and the first and second random number generators all generate random numbers according to a preset pattern within a periodic time, when the device is legitimate, the random numbers generated by the first and second random number generators at the same point in time will be the same. In other words, if the first and second random numbers are the same, the device can be determined to be legitimate.

[0084] In the technical solution provided in this embodiment, after the proxy server synchronizes time with the device, it obtains the first random number sent by the device and the generation time of the first random number, and obtains the second random number generated by the proxy server at the generation time. If the first random number and the second random number are the same, it can be accurately determined that the device is a legitimate device.

[0085] Reference Figure 4 , Figure 4 This is a third embodiment of the data transmission method of the present invention. Based on the first embodiment, step S20 includes:

[0086] Step S25: Obtain the device's second digital signature according to the first connection request.

[0087] In this embodiment, both the device and the proxy server store the same random number generator, and both random number generators generate random numbers with a preset pattern within a period of time.

[0088] After generating a third random number using its own first random number generator, the device needs to obtain the generation time and target time of the third random number. The target time refers to the start or end time of the period in which the generation time falls.

[0089] The device generates a second digital signature using a third random number, the generation time point, the target time point, and verification information. Based on this second digital signature, it generates a first connection request and sends it to the proxy server. Upon receiving the first connection request, the proxy server parses it to obtain the second digital signature.

[0090] Step S26: Parse the second digital signature to obtain the third random number generated by the device using the first random number generator and the interval between the generation time point and the target time point corresponding to the third random number. The first random number generator generates random numbers with a preset pattern within a periodic time, and the target time point is the start time point or the end time point within the periodic time.

[0091] After obtaining the second digital signature, the proxy server parses the second digital signature to obtain the third random number, the generation time of the third random number, and the target time, and then obtains the interval duration based on the generation time and the target time.

[0092] Step S27: Obtain each fourth random number generated by the second random number generator in the proxy server within a period of time, wherein the second random number generator generates random numbers with a preset pattern within a period of time.

[0093] Step S28: Determine the target random number corresponding to the interval duration from each of the fourth random numbers.

[0094] The proxy server's second random number generator generates several fourth random numbers within a period. Because there may be a time discrepancy between the device and the proxy server, the proxy server selects the target random number corresponding to the interval from these fourth random numbers. For example, if the interval is the time between the start time and the generation time, and the first random number generator generates 8 random numbers within that interval, then the 8th fourth random number generated by the second random number generator within the period is the target random number corresponding to the interval.

[0095] Step S29: When the third random number is the same as the target random number, determine that the device is a legitimate device.

[0096] Since both the first and second random number generators generate random numbers with preset patterns within a period of time, and after correcting for the time error between the device and the proxy server, if the third random number is the same as the target random number, it can be determined that the device is a legitimate device.

[0097] In the technical solution provided in this embodiment, the proxy server obtains the third random number sent by the device, the generation time of the third random number, and the target time. It then obtains the interval between the generation time and the target time and determines the target random number corresponding to the interval from each of the fourth random numbers it generates. If the third random number is the same as the target random number, it can accurately determine that the device is a legitimate device.

[0098] In one embodiment, after step S50, the method further includes:

[0099] Receive third information from the IoT server based on the second information;

[0100] The fourth information is obtained by decrypting the third information;

[0101] The fourth piece of information is sent to the device.

[0102] In this embodiment, when the IoT server receives the second information, it may send a third information to the device. The third information may be the device's control information or the feedback information corresponding to the second information.

[0103] When the proxy server receives the third information from the IoT server based on the second information, it decrypts the third information to obtain the fourth information, and then sends the fourth information to the device, thereby completing the data interaction between the device and the IoT server.

[0104] Reference Figure 5 , Figure 5 In the fourth embodiment of the data transmission method of the present invention, based on any one of the first to third embodiments, step S50 includes:

[0105] Step S51: Determine the IoT server that the device requests to access based on the first information.

[0106] In this embodiment, when sending the first information, the device specifies the IoT server to which the first information should be sent. The first information carries device information of the IoT server.

[0107] The proxy server obtains the device information of the IoT server based on the first information, that is, the proxy server determines the IoT server that the device requests to access based on the first information.

[0108] Step S52: Send a second connection request to the IoT server. The second connection request is used to request access to the IoT server.

[0109] The proxy server sends a second connection request to the IoT server, which is used to request access to the IoT server.

[0110] Step S53: Upon receiving access permission information from the IoT server, establish a communication connection between the proxy server and the IoT server, and send the second information to the IoT server.

[0111] When the proxy server receives the access permission information from the IoT server, it establishes a communication connection between the proxy server and the IoT server, and then sends the second information to the IoT server.

[0112] In the technical solution provided in this embodiment, the proxy server determines the IoT server that the device requests to access through the first information, and then sends a second connection request to the IoT server. After receiving the access permission information sent by the IoT server, the proxy server establishes a communication connection with the IoT server, and then sends the second information to the IoT server to avoid sending the second information to the wrong IoT server.

[0113] The present invention also provides a proxy server, as described above. Figure 6 The proxy server 600 includes:

[0114] The acquisition module 610 is used to acquire device information of the device according to the first connection request when it receives the first connection request sent by the device;

[0115] The verification module 620 is used to verify whether the device is a legitimate device when it is determined from the device information that the device does not meet the access conditions of the IoT server.

[0116] Establishment module 630 is used to establish a communication connection between the device and the proxy server when verifying that the device is a legitimate device;

[0117] The receiving module 640 is used to receive the first information sent by the device and encrypt the first information to obtain the second information;

[0118] The sending module 650 is used to send the second information to the IoT server.

[0119] In one embodiment, the proxy server 600 includes:

[0120] The sending module 650 is used to send the current network time of the proxy server to the device so that the network time of the device is synchronized with that of the proxy server.

[0121] Receiver module 640 is used to receive the first digital signature sent by the device;

[0122] The parsing module is used to parse the first digital signature to obtain the first random number generated by the device using the first random number generator and the generation time point corresponding to the first random number. The first random number generator generates random numbers with a preset pattern within a period of time.

[0123] The acquisition module 610 is used to acquire the second random number generated by the second random number generator in the proxy server at the generation time point, wherein the second random number generator generates random numbers with a preset pattern within a periodic time.

[0124] The determination module is used to determine whether a device is a legitimate device when the first random number and the second random number are the same.

[0125] In one embodiment, the proxy server 600 includes:

[0126] The acquisition module 610 is used to acquire the second digital signature of the device according to the first connection request;

[0127] The parsing module is used to parse the second digital signature to obtain the third random number generated by the device using the first random number generator and the interval between the generation time point and the target time point corresponding to the third random number. The first random number generator generates random numbers with a preset pattern within a period of time, and the target time point is the start time point or the end time point in the period of time.

[0128] The acquisition module 610 is used to acquire each fourth random number generated by the second random number generator in the proxy server within a period of time, wherein the second random number generator generates random numbers with a preset pattern within a period of time.

[0129] The determination module is used to determine the target random number corresponding to the interval duration from each of the fourth random numbers;

[0130] The determination module is used to determine whether a device is a legitimate device when the third random number is the same as the target random number.

[0131] In one embodiment, the proxy server 600 includes:

[0132] The runtime module is used to run the layer 4 proxy function;

[0133] The sending module 650 is used to forward the second information to the IoT server based on the four-layer proxy function.

[0134] In one embodiment, the proxy server 600 includes:

[0135] The receiving module 640 is used to receive third information from the IoT server based on the second information feedback;

[0136] The decryption module is used to decrypt the third information to obtain the fourth information;

[0137] The sending module 650 is used to send the fourth information to the device.

[0138] In one embodiment, the proxy server 600 includes:

[0139] The determination module is used to determine the IoT server that the device requests to access based on the first information.

[0140] The sending module 650 is used to send a second connection request to the IoT server, the second connection request being used to request access to the IoT server;

[0141] Module 630 is used to establish a communication connection between the proxy server and the IoT server when it receives access permission information from the IoT server, and to send the second information to the IoT server.

[0142] Figure 7 This is a hardware structure diagram of a proxy server according to an exemplary embodiment.

[0143] The proxy server 700 may include: a processor 71, such as a CPU, a memory 72, and a transceiver 73. Those skilled in the art will understand that... Figure 7 The structure shown does not constitute a limitation on the proxy server and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. Memory 72 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0144] The processor 71 can call the computer program stored in the memory 72 to complete all or part of the steps of the above-described data transmission method.

[0145] Transceiver 73 is used to receive information sent by external devices and to send information to external devices.

[0146] A non-transitory computer-readable storage medium, wherein instructions in the storage medium, when executed by the processor of a proxy server, enable the proxy server to perform the aforementioned data transmission method.

[0147] A computer program product includes a computer program that, when executed by the processor of a proxy server, enables the proxy server to perform the aforementioned data transmission method.

[0148] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0149] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A data transmission method applied to a proxy server, characterized in that, The proxy server is an Nginx reverse proxy server, and the method comprises: Upon receiving a first connection request sent by a device, obtaining device information of the device according to the first connection request; Upon determining that the device does not meet an access condition of an Internet of Things server according to the device information, verifying whether the device is a legal device; the access condition is that the device has a data encryption function; Upon verifying that the device is a legal device, establishing a communication connection between the device and the proxy server; Receiving first information sent by the device, and encrypting the first information to obtain second information; Running a four-layer proxy function, the four-layer proxy function being used to open a dedicated TLS channel to connect to the Internet of Things server; the Nginx reverse proxy server is also in TCP connection with the device; Based on the four-layer proxy function, forwarding the second information to the Internet of Things server, thereby realizing four-layer proxy forwarding from TCP to TLS.

2. The data transmission method of claim 1, wherein, The step of verifying whether the device is a legal device comprises: Sending a current network time of the proxy server to the device, so as to synchronize the network time of the device with the network time of the proxy server; Receiving a first digital signature sent by the device; Parsin the first digital signature to obtain a first random number generated by a first random number generator of the device and a generation time point corresponding to the first random number, wherein the first random number generator generates random numbers with a preset rule within a period of time; Obtaining a second random number generated by a second random number generator in the proxy server at the generation time point, wherein the second random number generator generates random numbers with the preset rule within a period of time; When the first random number is the same as the second random number, determining that the device is a legal device.

3. The data transmission method of claim 1, wherein, The step of verifying whether the device is a legal device comprises: Obtaining a second digital signature of the device according to the first connection request; Parsin the second digital signature to obtain a third random number generated by a first random number generator of the device and an interval duration between a generation time point corresponding to the third random number and a target time point, wherein the first random number generator generates random numbers with a preset rule within a period of time, and the target time point is a starting time point or an ending time point in the period of time; Obtaining each fourth random number generated by a second random number generator in the proxy server within the period of time, wherein the second random number generator generates random numbers with the preset rule within a period of time; Determining a target random number corresponding to the interval duration in each fourth random number; When the third random number is the same as the target random number, determining that the device is a legal device.

4. The data transmission method of claim 1, wherein, The step of sending the second information to the Internet of Things server further comprises: Receiving third information fed back by the Internet of Things server based on the second information; Decrypting the third information to obtain fourth information; Sending the fourth information to the device.

5. The data transmission method according to any one of claims 1-4, characterized in that, The step of sending the second information to the Internet of Things server comprises: According to the first information, determine the device requests to access the Internet of Things server; Send a second connection request to the Internet of Things server, the second connection request is used to request to access the Internet of Things server; When receiving the access permission information fed back by the Internet of Things server, establish the communication connection between the proxy server and the Internet of Things server, and send the second information to the Internet of Things server.

6. A proxy server, characterized by The proxy server is an Nginx reverse proxy server, and the proxy server comprises: An acquisition module is configured to acquire device information of the device according to the first connection request when receiving the first connection request sent by the device; A verification module is configured to verify whether the device is a legal device when determining that the device does not meet the access conditions of the Internet of Things server according to the device information; An establishment module is configured to establish a communication connection between the device and the proxy server when verifying that the device is a legal device; A receiving module is configured to receive first information sent by the device and encrypt the first information to obtain second information; A sending module is configured to run a four-layer proxy function, the four-layer proxy function is used to open a dedicated TLS channel to connect to the Internet of Things server; the Nginx reverse proxy server is also connected with the device TCP; the second information is forwarded to the Internet of Things server based on the four-layer proxy function, so as to realize four-layer proxy forwarding from TCP to TLS.

7. A proxy server, characterized by Comprise: A memory and a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the processor executes the data transmission method in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the data transmission method in any one of claims 1 to 5.

9. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the data transmission method in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Security algorithm consultation method of Internet of Things, network element and Internet of Things terminal

    CN106899562A

  • Data transmission method, device and system

    CN113783893A

  • Device and method for inspecting whether oscillator is operated

    JP2004178302A

  • Security system and method for internet of things

    US10346614B1