A communication encryption method and device, equipment, and storage medium
By introducing self-mapping keys and key pool management into UAV communication, the problems of poor fault tolerance for addition and deletion and high synchronization overhead in synchronous sequence encryption methods are solved, achieving high security and stable data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE CHENGDU INFORMATION & TELECOMM TECH CO LTD
- Filing Date
- 2022-01-07
- Publication Date
- 2026-04-28
AI Technical Summary
In UAV communication, the synchronous sequence encryption method has problems such as poor fault tolerance for addition and deletion and large synchronization overhead. Furthermore, a single erroneous data can lead to continuous errors in subsequent data, affecting the stability and security of the system.
Self-mapping keys are used to encrypt and decrypt encryption keys. By introducing key IDs into the keys, synchronization operations are reduced. Encryption keys are stored and managed using a key pool, and a supplement threshold is set to ensure that keys are sufficient and available, thus ensuring the security and stability of data transmission.
It improves the system's fault tolerance for additions and deletions, reduces the system overhead of synchronization operations, enhances the security of data transmission, prevents the continuous propagation of erroneous data, and ensures the stability and security of UAV communication.
Smart Images

Figure CN116456332B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this application belong to the field of communication security, and particularly relate to the secure interaction of data information during data acquisition and control. Background Technology
[0002] With the rapid development of 5G technology, data collection and information interaction are increasing, leading to greater security risks in communication. To prevent interception, tampering, and replay of communication data, encryption is essential. Synchronous sequence encryption is a common communication encryption method, but it suffers from poor fault tolerance for additions and deletions and high synchronization overhead. Summary of the Invention
[0003] In view of this, embodiments of this application provide a communication encryption method, apparatus, device, and storage medium.
[0004] The technical solution of this application embodiment is implemented as follows:
[0005] In a first aspect, embodiments of this application provide a communication encryption method applied to a first client. The method includes: obtaining plaintext messages; obtaining an encryption key from a first encryption key pool; wherein the encryption key is obtained by encrypting with a self-mapping key with a key ID on the server and decrypting with a self-mapping key with the same key ID in the first self-mapping key pool; encrypting the plaintext messages using the encryption key to obtain ciphertext messages; wherein the ciphertext messages carry the key ID; and sending the ciphertext messages to a second client.
[0006] Secondly, embodiments of this application provide a communication encryption method applied to a server. The method includes: generating a synthesized key plaintext; the synthesized key plaintext includes a mapping parameter and an encryption key, wherein the mapping parameter is located before the encryption key and is used to transform the encryption key; obtaining a second self-mapping key from a second self-mapping key pool; wherein the second self-mapping key has a key ID and is unrelated to the encryption key; encrypting the synthesized key plaintext using the second self-mapping key to obtain a synthesized key; wherein the synthesized key carries the key ID of the second self-mapping key; and synchronously sending the synthesized key to a first client and a second client.
[0007] Thirdly, embodiments of this application provide a communication encryption method applied to a second client. The method includes: obtaining ciphertext of a message; obtaining an encryption key from a third encryption key pool; wherein the encryption key is obtained by encrypting with a self-mapping key with a key ID on the server and decrypting with a self-mapping key with the same key ID in the third self-mapping key pool; and decrypting the ciphertext of the message using the encryption key to obtain plaintext of the message.
[0008] The beneficial effects of the technical solutions provided in this application include at least the following:
[0009] In this embodiment, the encryption key is first encrypted using a self-mapping key with a key ID, and then decrypted using a self-mapping key with the same key ID. Next, the plaintext message is encrypted using the encryption key with the key ID to obtain ciphertext, where the ciphertext carries the key ID. Finally, the ciphertext is sent to the second client. This method of using a self-mapping key with a key ID for encryption and decryption improves the system's add / delete fault tolerance and prevents the key from being deduced and cracked during data transmission, providing a high level of security for streaming data transmission. Furthermore, encrypting the plaintext message with a key with a key ID eliminates the need for client-side sequence synchronization, reducing the high system overhead associated with synchronization operations. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein:
[0011] Figure 1A A schematic diagram of an optional network architecture for a communication encryption system provided in this application embodiment;
[0012] Figure 1B A schematic diagram illustrating the implementation process of a communication encryption method provided in this application embodiment;
[0013] Figure 1C This is a schematic diagram illustrating the implementation process of a method for decryption using self-mapped keys with the same key ID in a first self-mapped key pool, as provided in an embodiment of this application.
[0014] Figure 1D A schematic diagram illustrating the implementation flow of a method for generating a self-mapping key provided in an embodiment of this application;
[0015] Figure 2A A schematic diagram illustrating the implementation process of a communication encryption method provided in this application embodiment;
[0016] Figure 2B A schematic diagram illustrating the implementation process of a method for synchronously sending a synthesized key from a server to a client, provided in an embodiment of this application;
[0017] Figure 3A schematic diagram illustrating the implementation process of a communication encryption method provided in this application embodiment;
[0018] Figure 4 A schematic diagram illustrating the implementation process of a synchronous sequence encryption method provided in this application embodiment;
[0019] Figure 5A A schematic diagram of the framework structure of a key derivation service module provided in an embodiment of this application;
[0020] Figure 5B A schematic diagram of the framework structure of a client synchronization encryption module provided in an embodiment of this application;
[0021] Figure 6 A schematic diagram illustrating the implementation flow of a self-mapping key generation method provided in an embodiment of this application;
[0022] Figure 7A This is a schematic diagram illustrating the implementation process of a method for generating a synthetic key provided in this application embodiment;
[0023] Figure 7B This is a schematic diagram illustrating the implementation process of a method for synchronously distributing a synthesized key to a client, as provided in an embodiment of this application.
[0024] Figure 8 This is a schematic diagram illustrating the implementation process of a method provided in this application embodiment for a client to decrypt synthesized key ciphertext and extract encryption key and self-mapping key;
[0025] Figure 9A This is a schematic diagram illustrating the implementation process of a method provided in this application for a first client to encrypt plaintext information and send it to a paired second client to synthesize a key;
[0026] Figure 9B A schematic diagram illustrating the implementation process of a method for a second client to decrypt encrypted messages, provided in an embodiment of this application;
[0027] Figure 10 This is a schematic diagram illustrating the implementation framework of an improved UAV communication encryption method provided in this application embodiment. Detailed Implementation
[0028] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0029] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0030] It should be noted that the terms "first, second, and third" used in the embodiments of this application are merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, and third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.
[0031] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments of this application pertain. It should also be understood that terms such as those defined in general dictionaries should be understood to have a meaning consistent with their meaning in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.
[0032] Currently, with the rapid development of 5G technology, the number of drones used in various major events is constantly increasing, and the security risks to communications are also increasing. Drone communication mainly involves data interaction between drones (intra-group communication) and between drones and ground control stations. To prevent drone communication data from being intercepted, tampered with, and replayed, drone communication data must be encrypted.
[0033] Cryptography is mainly divided into two categories based on its encryption method: stream ciphers and block ciphers. Block ciphers use fixed transformations to process blocks of plaintext data, making encryption more complex and susceptible to error propagation and latency. They are generally used in applications requiring high-quality communication channels or those with data retransmission capabilities. Stream ciphers, on the other hand, transform the plaintext sequence bit by bit or block by block over time. They offer fast hardware encryption speeds, are easy to implement, and provide low latency and no error propagation for signal encryption.
[0034] Unmanned aerial vehicle (UAV) communication demands high real-time data transmission. Ground control stations transmit and receive data at millisecond-level frequencies, thus low-latency stream ciphers are typically used for encryption. Stream cipher encryption includes synchronous stream ciphers and self-synchronizing stream ciphers. In synchronous stream ciphers, the key sequence synchronization must be checked periodically. During encrypted transmission, any addition or deletion of data in the ciphertext stream will corrupt the data decryption at the receiving end. Without timely synchronization, the entire data stream will fail to decrypt. However, increasing the synchronization frequency at each end increases synchronization overhead, reduces encryption efficiency, and is detrimental to system stability.
[0035] In view of this, this application provides a communication encryption method, and the technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments.
[0036] This embodiment first provides an optional network architecture for a communication encryption system. Figure 1A This is a schematic diagram of an optional network architecture for a communication encryption system provided in an embodiment of this application, such as... Figure 1A As shown, in some embodiments, server 100 synchronously sends a synthesized key with the same key ID to first electronic device 200 and second electronic device 300. The synthesized key is an encrypted key. First electronic device 200 and second electronic device 300 decrypt the synthesized key to obtain an encrypted key with the same key ID, and store the encrypted key in a first encryption key pool and a second encryption key pool, respectively. When first electronic device 200 collects a plaintext message, it first encrypts the plaintext message using an encrypted key with the same key ID to obtain a ciphertext message, and then sends the ciphertext message to second electronic device 300. Second electronic device 300 decrypts the ciphertext message using an encrypted key with the same key ID to obtain the plaintext message.
[0037] In some embodiments, server 100 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, and big data and artificial intelligence platforms. The first electronic device 200 can be various types of devices with data acquisition capabilities, such as drones, and the second electronic device 300 can be various types of computer devices with information processing capabilities, such as desktop computers, mobile phones, and tablet computers.
[0038] Figure 1B This is a schematic diagram illustrating the implementation process of a communication encryption method provided in an embodiment of this application, applied to a first client, such as... Figure 1B As shown, the method includes:
[0039] Step S101: Obtain the plaintext message;
[0040] Here, plaintext messages refer to the collected information data. In practice, plaintext messages can be collected by unmanned intelligent devices such as drones and unmanned vessels during operations; there is no limitation on this. Taking drones as an example, plaintext messages refer to image, sound, text, and video data collected by drones in certain areas of the operational area, such as the air, sea, river, and land.
[0041] Step S102: Obtain an encryption key from the first encryption key pool; wherein, the encryption key is obtained by encrypting with a self-mapped key with a key ID on the server and decrypting with a self-mapped key with the same key ID in the first self-mapped key pool;
[0042] Here, the encryption key is a stream key used for symmetric encryption and decryption of plaintext messages.
[0043] An encryption key pool is a memory space used to store available encryption keys. Each encryption key in the encryption key pool corresponds to a globally unique key ID, which can be generated using parameters such as an auto-incrementing sequence and a key hash value.
[0044] Here, the self-mapping key is a stream key generated by byte transformation of the encryption key through mapping parameters, which is used to encrypt other encryption keys. The mapping parameters include offset and offset step size. The offset refers to the distance between the actual address of the storage unit and the segment address of the segment where the storage unit is located; the offset step size refers to the distance between two adjacent addresses when the storage unit is offset.
[0045] The first self-mapping key pool refers to the memory space used to store available self-mapping keys. Each self-mapping key in the self-mapping key pool corresponds to a key ID that is a globally unique identifier that is the same as the encryption key.
[0046] Step S103: Encrypt the plaintext message using the encryption key to obtain ciphertext message; wherein the ciphertext message contains the key ID;
[0047] Here, the encryption method employs synchronous sequence encryption. In implementation, the encryption algorithm uses the Exclusive OR (XOR) algorithm. The ciphertext is obtained by performing an XOR operation between the encryption key and the plaintext message. After the calculation, the key ID of the encryption key is bound to the header of the ciphertext, meaning the ciphertext carries the key ID.
[0048] Step S104: Send the encrypted message to the second client.
[0049] Here, the encrypted message is sent based on the communication address and port of the paired client.
[0050] In this embodiment, the encryption key is first encrypted using a self-mapping key with a key ID, and then decrypted using a self-mapping key with the same key ID. Next, the plaintext message is encrypted using the encryption key with the key ID to obtain ciphertext, where the ciphertext carries the key ID. Finally, the ciphertext is sent to the second client. This method of using a self-mapping key with a key ID for encryption and decryption improves the system's add / delete fault tolerance and prevents the key from being deduced and cracked during data transmission, providing a high level of security for streaming data transmission. Furthermore, encrypting the plaintext message with a key with a key ID eliminates the need for client-side sequence synchronization, reducing the high system overhead associated with synchronization operations.
[0051] In some embodiments, after obtaining the plaintext message in step S101 and before obtaining the encryption key from the first encryption key pool in step S102, the method further includes:
[0052] Step 1011: Store the received plaintext message into a buffer and determine the length of the plaintext message in bytes in the buffer in real time;
[0053] Here, the buffer is used to store the received plaintext messages.
[0054] Step 1012: When the plaintext of the message occupies a length of M bytes, obtain the encryption key from the first encryption key pool;
[0055] Here, the byte length M of the plaintext message is related to the data processing capabilities of the client and server. In implementation, different byte lengths M of the plaintext message can be set based on the amount of data that the client and server can process.
[0056] Step 1013: When the length of the plaintext message is less than M, determine the length of the plaintext message in the buffer in real time until the length of the buffer reaches M, and obtain the encryption key from the first encryption key pool.
[0057] In this embodiment of the application, the encryption key is only obtained from the first encryption key pool when the length of the plaintext message reaches M bytes. This can reduce the amount of computation for client data processing and improve work efficiency.
[0058] In some embodiments, the step of "decrypting using a self-mapped key with the same key ID in the first self-mapped key pool" in step S102 is as follows: Figure 1C As shown, the method includes:
[0059] Step S1021: Obtain the synthesis key;
[0060] Here, the synthesized key is obtained by encrypting the encryption key with a self-mapping key that has a key ID. The encryption algorithm used is the XOR algorithm.
[0061] Step S1022: Obtain a first self-mapping key with the same key ID as the synthesized key from the first self-mapping key pool;
[0062] Step S1023: Decrypt the synthesized key using the first self-mapping key to obtain the synthesized key plaintext; wherein, the synthesized key plaintext includes the key ID and the encryption key;
[0063] Here, the decryption algorithm used is the XOR algorithm. In practice, the decryption is performed by XORing the first self-mapping key with the synthesized key, and the synthesized key plaintext is obtained after decryption.
[0064] Here, the synthesized key plaintext includes an offset, an offset step size, and an encryption key, with the offset and offset step size located at the beginning of the encryption key.
[0065] Step S1024: Obtain the encryption key from the synthesized key plaintext and store it in the first encryption key pool.
[0066] Step S1025: Repeat the above steps until the number of encryption keys in the first encryption key pool reaches the available number threshold.
[0067] Here, the number of encryption keys in the first encryption key pool can only be used if it reaches a certain threshold.
[0068] In this embodiment, decryption is performed using self-mapped keys with the same key ID in the first self-mapped key pool. This improves the system's fault tolerance for additions and deletions and makes it impossible to deduce and crack the key during data transmission, providing a high level of security for streaming data transmission. In addition, an encryption key pool is used to store encryption keys. The encryption keys can only be used when the number of available encryption keys in the encryption key pool reaches a threshold. In this way, reliable streaming encryption can be achieved during the transmission of large amounts of data.
[0069] In some embodiments, after step S1023, the method further includes:
[0070] Step S102a: Destroy the first self-mapping key;
[0071] Here, destroying the first self-mapping key that has been used is to ensure that one self-mapping key encrypts only one encryption key.
[0072] Step S102b: Obtain the encryption key and mapping parameters from the synthesized key plaintext;
[0073] Here, the mapping parameters include the offset and the offset step size.
[0074] Step S102c: Based on the encryption key and mapping parameters, generate a new first self-mapping key and store it in the first self-mapping pool.
[0075] In some embodiments, the mapping parameters include an offset and an offset step size, the encryption key occupies a byte length of M, the offset is S, the offset step size is N, and the total byte length occupied by the offset and the offset step size is K. Therefore, step S102c is implemented as follows: Figure 1D As shown, the method includes:
[0076] Step S11: Create an empty self-mapping key; wherein the empty self-mapping key occupies a byte length of M+K;
[0077] Here, an empty self-mapping key refers to a self-mapping key that does not contain any data information.
[0078] Step S12: Initially offset S bytes from the header of the encryption key and read the byte data of the encryption key at the offset position to fill the corresponding position in the empty self-mapped key;
[0079] Step S13: When the padding length of the empty self-mapping key is less than M+K bytes, continue to offset N bytes and read the byte data of the encryption key at the offset position to fill the corresponding position in the empty self-mapping key;
[0080] Step S14: When the offset position is greater than M bytes after offsetting N bytes, continue to offset P bytes, and then offset NP bytes from the beginning of the encryption key; where P is less than N.
[0081] Here, when the offset position is greater than M bytes after offsetting N bytes, it is necessary to first offset P bytes so that the offset position reaches the end of the encryption key, and then continue to offset from the beginning of the encryption key.
[0082] Step S15: Repeat the above steps until the empty self-mapping key data is filled in, obtain a new first self-mapping key and store it in the first self-mapping key pool.
[0083] In some embodiments, the encryption key is a random number, the byte length M of the encryption key is a prime number, the offset S is less than M-1, and the offset step size N is a prime number and less than or equal to one-tenth of M.
[0084] In this embodiment, after creating an empty self-mapping key, data information at different positions in the encryption key is obtained using the offset and the byte length occupied by the offset step, and this data information is filled into the corresponding positions of the empty self-mapping key to obtain a new self-mapping key. In this way, each generated self-mapping key is different. Therefore, the synthesized key obtained by encrypting with the self-mapping key is different each time, making it impossible to deduce and crack the key during data transmission, thus providing a high level of security for the transmission of streaming data.
[0085] This application provides a communication encryption method, applied to a server, such as... Figure 2A As shown, the method includes:
[0086] Step S201: Generate a synthesized key plaintext; the synthesized key plaintext includes a mapping parameter and an encryption key, the mapping parameter being located before the encryption key and used to transform the encryption key; here, the mapping parameter includes an offset and an offset step size, the offset being S and the offset step size being N.
[0087] Here, in the synthesized key plaintext, the plaintext is arranged from front to back as offset, offset step, and encryption key. Since the offset and offset step are different from the encryption key, adding the offset and offset step before the encryption key can transform the encryption key, making it more difficult to crack after encryption.
[0088] Step S202: Obtain the second self-mapping key from the second self-mapping key pool; wherein the second self-mapping key has a key ID and is not related to the encryption key;
[0089] Here, the second self-mapping key pool is the server-side self-mapping key pool.
[0090] Step S203: Encrypt the plaintext of the synthesized key using the second self-mapping key to obtain the synthesized key; wherein the synthesized key carries the key ID of the second self-mapping key;
[0091] Here, when the number of encryption keys in the encryption key pools of the first client and the second client is lower than the available number threshold, the first client and the second client will notify the server to supplement the synthesized key.
[0092] Here, the synthesized key carries the key ID of the second self-mapping key, so that when the synthesized key is sent to the client, the client can extract the self-mapping key with the same key ID as the second self-mapping key for decryption, and obtain the same synthesized key plaintext as the server.
[0093] Step S204: Simultaneously send the synthesized key to the first client and the second client.
[0094] Here, after the synthesized key is generated, the same synthesized key is sent synchronously to the first client and the second client. After receiving the same synthesized key, the first client and the second client decrypt the synthesized key and store it in their respective encryption key pools.
[0095] In this embodiment of the application, a self-mapping key with a key ID that is unrelated to the encryption key is used to encrypt the plaintext of the synthesized key to obtain the ciphertext of the synthesized key. In this way, the synthesized key obtained by encryption with the self-mapping key is different each time, so that the key cannot be deduced and cracked during data transmission, thus providing a high level of security for the transmission of streaming data.
[0096] In some embodiments, the implementation steps of step S204 are as follows: Figure 2B As shown, the method includes:
[0097] Step S2041: Obtain the encryption module of the paired first client and the encryption module of the second client;
[0098] Here, the encryption modules of the currently paired first and second clients are queried from the client communication relationship mapping table.
[0099] Step S2042: Synchronously send the synthesized key to the encryption module of the first client and the encryption module of the second client.
[0100] Here, based on the communication addresses and ports of the encryption modules of the paired first and second clients, the synthesized key ciphertext with the key ID of the self-mapped key is synchronously distributed to the encryption modules of the first and second clients.
[0101] In this embodiment, the synthesized key is synchronously distributed to the first client and the second client. This ensures that the first client and the second client obtain the same encryption key after decrypting the synthesized key, which facilitates the encryption and decryption of plaintext messages by the first client and the second client.
[0102] In some embodiments, the implementation steps of step S201 include:
[0103] Step S2011: Obtain the encryption key and the mapping parameters; wherein the mapping parameters include offset and offset step size;
[0104] Step S2012: Add the offset and offset step size to the header of the encryption key in sequence to generate the synthesized key plaintext.
[0105] Here, the offset position is before the offset step position.
[0106] In some embodiments, the server includes a true random number generator, a master encryption key pool, and a self-mapping module. The method for the server to generate a self-mapping key is as follows:
[0107] Step S21: A true random number generator generates unpredictable physical random numbers and random parameter values; wherein the random number occupies a fixed byte length of M bytes, and the random parameter values include an offset and an offset step size;
[0108] Here, a true random number generator refers to a hardware device that uses data sources such as thermal noise, clock drift, and radio frequency (RF) noise to generate unpredictable random numbers.
[0109] In some embodiments, the byte length M of the encryption key is a prime number, the offset S is less than M-1, and the offset step size N is a prime number and is less than or equal to one-tenth of M.
[0110] Step S22: Store the random number as the encryption key in the main encryption key pool;
[0111] Here, the main encryption key pool refers to the place on the server side where encryption keys are stored.
[0112] Step S23: Store the random parameter values into the self-mapping module;
[0113] Here, the self-mapping module is used to generate self-mapping keys.
[0114] Step S24: Generate a new self-mapping key based on the random number and the random parameter value.
[0115] Here, the method for the new self-mapping key in step S24 can be understood by referring to the methods shown in steps S11 to S15.
[0116] This application provides a communication encryption method applied to a second client, such as... Figure 3 As shown, the method includes:
[0117] Step S301: Obtain the ciphertext of the message;
[0118] Here, the ciphertext of the message is obtained by encrypting the plaintext of the message with the encryption key.
[0119] Step S302: Obtain an encryption key from the third encryption key pool; wherein the encryption key is obtained by encrypting with a self-mapped key with a key ID on the server and decrypting with a self-mapped key with the same key ID in the third self-mapped key pool.
[0120] Here, the third self-mapping key pool is the self-mapping key pool in the second client.
[0121] Step S303: Decrypt the ciphertext of the message using the encryption key to obtain the plaintext of the message.
[0122] Here, decryption is performed by XORing the encryption key and the ciphertext of the message.
[0123] In some embodiments, decryption using the self-mapped key with the same key ID in a third self-mapped key pool includes:
[0124] Step S31: Obtain the synthesis key;
[0125] Step S32: Obtain a third self-mapping key with the same key ID as the synthesized key from the third self-mapping key pool;
[0126] Step S33: Decrypt the synthesized key using the third self-mapping key to obtain the synthesized key plaintext; wherein, the synthesized key plaintext includes the key ID and the encryption key;
[0127] Step S34: Obtain the encryption key from the synthesized key plaintext and store it in the third encryption key pool.
[0128] Step S35: Repeat the above steps until the number of encryption keys in the third encryption key pool reaches the available quantity threshold.
[0129] Here, steps S31 to S35 can be understood by referring to steps S1021 to S1025.
[0130] In some embodiments, after decrypting the synthesized key using the third self-mapping key to obtain the plaintext of the synthesized key, the method further includes:
[0131] Step S31a: Destroy the third self-mapping key;
[0132] Step S31b: Obtain the encryption key and mapping parameters from the synthesized key plaintext;
[0133] Step S31c: Based on the encryption key and the mapping parameters, generate a new third self-mapping key and store it in the third self-mapping pool.
[0134] Here, steps S31a to S31c can be understood by referring to steps S102a to S102c.
[0135] In some embodiments, the mapping parameters include an offset and an offset step size, the encryption key has a byte length of M, an offset of S, and an offset step size of N. The method for generating a new third self-mapping key based on the encryption key and the mapping parameters and storing it in the third self-mapping pool can be understood by referring to the method shown in steps S11 to S15.
[0136] Unmanned aerial vehicles (UAVs) are unmanned aircraft controlled via onboard terminal equipment using wireless communication technology. UAV communication primarily involves data exchange between UAVs (intra-group communication) and between UAVs and ground control stations. With the rapid development of 5G technology, the application of UAVs in military, transportation, medical, educational, and agricultural sectors, as well as in various major events, is constantly increasing, leading to greater security risks in inter-node communication. To prevent UAV communication data from being intercepted, tampered with, and replayed, encryption of UAV communication data is essential.
[0137] Cryptography is mainly divided into two categories based on its encryption method: stream ciphers and block ciphers. Block ciphers use fixed transformations to process blocks of plaintext data, making encryption more complex and susceptible to error propagation and latency. They are generally used in applications requiring high-quality communication channels or those with data retransmission capabilities. Stream ciphers, on the other hand, transform the plaintext sequence bit by bit or block by block over time. They offer fast hardware encryption speeds, are easy to implement, and provide low latency and no error propagation for signal encryption.
[0138] Unmanned aerial vehicle (UAV) communication demands high real-time data transmission speeds. Ground control station transceivers handle data at millisecond-level frequencies, therefore low-latency stream ciphers are typically used for encryption. UAV communication data sequence encryption methods include:
[0139] Stream encryption is performed using a synchronized sequence. The root key K is injected simultaneously into both the UAV and the ground control station. s The drone generates the encryption root key K through a hardware random number generator. h Through K s and K h Generate encryption key K within the encryption unit. j0 , by K j0 Stream encryption is applied to plaintext data. In implementation, for example... Figure 4 As shown, the drone generates a new encryption root key K every time it is powered on. h After the communication link is established, K will be the first to be sent. h Synchronize with the ground control station, and the ground control station will send K h Stored within the decryption unit, along with the root key Ks The function generates the exact same key K. j0 This allows for symmetric decryption of the data in subsequent steps. Furthermore, the encryption key will be updated to K via a key transformation unit after a certain period of time. j1 K j2 …K jn This method of encryption and decryption is relatively fast and has little impact on communication data, but the encryption key needs to be updated promptly and synchronized with the peer after it is used up.
[0140] The encryption method for UAV communication data sequences has the following drawbacks: the synchronization sequence requires periodic key sequence synchronization checks; during encrypted transmission, any abnormal addition or deletion of data in the ciphertext stream will corrupt the data decryption at the receiving end; if synchronization is not performed in time, the entire subsequent data stream will fail to decrypt. However, increasing the synchronization frequency of data at each end not only reduces the efficiency of data stream encryption but also leaves hidden dangers for the stable operation of the system.
[0141] Therefore, the embodiments of this application solve the following technical problems: (1) In the process of transmitting large amounts of data, stream encryption has the problems of poor fault tolerance for addition and deletion and large synchronization overhead; (2) In the process of synchronous transmission, a single erroneous data will cause subsequent data to be continuously erroneous, that is, data errors have a certain degree of propagation.
[0142] This application provides an improved communication stream encryption method between an unmanned aerial vehicle (UAV) and a ground control station. The encryption key is uniformly generated, processed, and distributed by a dedicated key derivation service module. The encryption key generates a mapping key using a self-mapping method to encrypt itself during transmission. Both communication ends synchronously store the allocated encryption keys through a key pool. The key pool has a replenishment threshold; when the actual number of keys in the key pool falls below the threshold, the key derivation service module replenishes the keys to ensure sufficient availability. The UAV encrypts the plaintext to obtain ciphertext, adds a key ID sequence to the ciphertext header, and transmits it. The ground control station retrieves the corresponding key from the key pool based on the key ID sequence for decryption.
[0143] This application's embodiments can reduce the system overhead caused by high-frequency synchronization, thereby reducing the occurrence of large-scale streaming data decryption failures due to untimely synchronization. There is no dependency between the key and the ciphertext; erroneous data bits only affect their own decryption and do not affect other correct data bits, avoiding the continuous propagation of erroneous data. The key itself is encrypted using a self-mapped key generated after transforming the preorder or other streaming keys. This method prevents the key from being brute-force stolen and effectively improves the security of key transmission over the air.
[0144] This application provides an improved method for encrypting data communication between unmanned aerial vehicles (UAVs), the method comprising the following parts:
[0145] (1) The key derivation service module is used to provide key generation and synchronization services for communication between clients. As Figure 5A shown, this module includes a key generation module, a key processing module, and a pairing management module. Among them, the key generation module includes a resource pool management module, a true random number generator, a main encryption key pool, and a self-mapping module. The main encryption key pool includes encryption keys and corresponding global identification IDs, and the self-mapping key pool includes self-mapping keys and corresponding global identification IDs; the key processing module includes a self-encryption module and a self-mapping key pool; the pairing management module includes a client communication relationship mapping table.
[0146] (2) The client synchronization encryption module is used to receive the encryption keys sent by the key derivation module and implement stream encryption communication between clients. As Figure 5B shown, this module includes a paired client encryption module 1, a client encryption module 2, and a data transmission channel. Among them, the client encryption module includes a self-decryption module, a self-mapping module, an encryption key pool, and a self-mapping key pool. The encryption key pool includes encryption keys and corresponding global identification IDs, and the self-mapping key pool includes self-mapping keys and corresponding global identification IDs.
[0147] Furthermore, in the initialization stage, a sufficient number of self-mapping keys need to be preset in the self-mapping key pool of the key processing module of the key derivation server and the client encryption module pair. After the preset is completed, the key derivation server waits for the access of the client network. When a new client pairing is successful, the resource pool management module controls the true random number generator to derive a random number with a fixed byte length M (M must be a prime number) as the encryption key and store it in the main encryption key pool. At the same time, two additional random parameter values are randomly generated and stored in the self-mapping module for subsequent key transformation. The main encryption key pool sends the obtained encryption key into the self-mapping module, and the self-mapping module generates a self-mapping key according to the two obtained random parameter values.
[0148] The embodiment of the present application provides a method for generating a self-mapping key. As Figure 6 shown, the method includes:
[0149] Step S601: Use a true random number generator to generate two random parameter values, namely an initial offset S (0 < S < M - 1) and an offset step N (N must be a prime number and not greater than one-tenth of M), with a total length of K bytes;
[0150] Step S602: Create an empty self-mapping key with a space length of (M + K) bytes;
[0151] Step S603: Offset S bytes from the head of the encryption key;
[0152] Step S604: Read 1 byte of data at the current offset position and store it in the self-mapping key space;
[0153] Step S605: Check whether the filled length of the self-mapping key has reached (M + K) bytes;
[0154] Step S606: If not, offset N bytes and continue to read the byte data of the encryption key for filling. If the offset position is greater than M after offsetting P bytes (P < N), then offset (N - P) bytes from the head;
[0155] Step S607: Repeat the above steps until the self-mapping key data is filled, and store the generated self-mapping key in the self-mapping key pool.
[0156] The embodiment of the present application provides a method for generating a composite key, as Figure 7A shown, the method includes:
[0157] Step S701: Bind the initial offset S and the offset step value N as mapping parameters to the head of the encryption key to generate the composite key plaintext;
[0158] Step S702: Extract a self-mapping key generated by other (or previous) encryption keys from the self-mapping key pool, and this key has no correlation with the composite key to be encrypted;
[0159] Step S703: Use this key to perform an XOR operation on the composite key plaintext to obtain the composite key ciphertext;
[0160] Step S704: Splice the global identification ID of the self-mapping key to the head of the composite key ciphertext.
[0161] In some embodiments, after step S704, as Figure 7B shown, the method further includes:
[0162] Step S705: Query the currently paired client encryption module from the client communication relationship correspondence table (pairing management module);
[0163] Step S706: According to the communication addresses and ports of the paired client modules, synchronously distribute the composite key ciphertext bound with the global identification ID of the self-mapping key to the client encryption module one and the client encryption module two.
[0164] The embodiment of the present application provides a method for a client to decrypt the composite key ciphertext, extract the encryption key and the self-mapping key, and supplement the encryption key pool and the self-mapping key pool, as Figure 8 shown, the method includes:
[0165] Step S801: After receiving the data, the client extracts the global identifier ID of the self-mapped key and the ciphertext of the synthesized key;
[0166] Step S802: Extract the self-mapped key corresponding to the identifier ID from the self-mapped key pool of the client encryption module;
[0167] Step S803: Perform an XOR operation on the self-mapped key and the synthesized key ciphertext to obtain the synthesized key plaintext, and destroy the used self-mapped key;
[0168] Step S804: Import the synthesized key plaintext (mapping parameters and encryption key plaintext) into the self-mapping module to generate a new self-mapping key and store it in the client's self-mapping key pool.
[0169] Step S805: Extract the encryption key from the synthesized key and store it in the client encryption key pool;
[0170] Step S806: Repeat the above steps until the number of keys in the local encryption key pool reaches the available threshold.
[0171] The first client extracts an encryption key with an identifier ID from the key pool, encrypts the plaintext information, and then sends it to the paired second client through the data transmission channel. This process is as follows: Figure 9A As shown, the method includes:
[0172] Step S901: The first client waits for the cached plaintext message to reach M bytes. If the wait times out, it sends all the data currently in the cache.
[0173] Step S902: The first client extracts a single encryption key with an identifier ID from the encryption key pool;
[0174] Step S903: Perform an XOR operation between the encryption key and the plaintext message to obtain the ciphertext message. After use, destroy the storage space of the encryption key and bind the identifier ID to the header of the ciphertext message.
[0175] Step S904: Send the ciphertext containing the encryption key identifier ID to the second client through the established data transmission channel.
[0176] Furthermore, the second client retrieves an encryption key with the same identifier ID as the first client from its local key pool to decrypt and restore the plaintext. This process is as follows: Figure 9B As shown, the method includes:
[0177] Step S901a: The second client obtains the encrypted data sent by the first client;
[0178] Step S901b: The second client extracts the encryption key identifier ID and message ciphertext from the ciphertext data;
[0179] Step S901c: The second client extracts the encryption key corresponding to the identifier ID from the local encryption key pool;
[0180] Step S901d: Use the encryption key to perform an XOR operation on the ciphertext to obtain the plaintext message. Destroy the storage space for the encryption key after use.
[0181] Step S901e: Check if the number of encryption keys in the local encryption key pool is lower than the replenishment threshold;
[0182] Step S901f: When the number of encryption keys is lower than the replenishment threshold, notify the server to replenish the keys.
[0183] This application provides an improved method for encrypting unmanned aerial vehicle (UAV) communication, such as... Figure 10 As shown, the method has a practical application scenario: the UAV and the ground control station have built-in key derivation service modules and client encryption modules, which run simultaneously as processes. First, a certain number of self-mapping keys are pre-set on both the ground and airborne ends to ensure that subsequent keys can be remotely derived normally. During the flight control initialization phase, the ground control station fills the key pool into the client encryption modules of both the local and remote UAVs through the key derivation service module. During aircraft operation, all plaintext data streams of acquisition and control between the ground control station and the UAV are encrypted and transmitted through the data transmission channel of the client encryption module process, following the steps described in this application.
[0184] The beneficial effects achieved in the embodiments of this application include at least the following: (1) The scheme of supplementing the existing key with a low threshold achieves the technical effect of reliable stream encryption during the transmission of a large amount of data; (2) The scheme of generating a self-mapped key by mapping the key body with random parameters to encrypt and protect itself achieves the technical effect of efficient dynamic protection of the stream key; (3) The scheme of uniquely identifying the key with a global identifier ID achieves the technical effect of preventing message encryption and decryption failure due to key synchronization disorder.
[0185] The technical terms used in this application are explained as follows:
[0186] 1. True Random Number Generator: A hardware device that generates unpredictable random numbers using data sources such as thermal noise, clock drift, and RF noise. 2. Key Pool: Memory space used to store available encryption keys and encryption mapping keys. This application mainly involves encryption key pools and self-mapping key pools. Each key in the pool corresponds to a globally unique identifier ID, which can be generated using parameters such as an auto-incrementing sequence and a key hash value. 3. Encryption Key: A stream key used for symmetric encryption and decryption of plaintext messages. 4. Mapping Parameter: Random mapping parameters that convert the encryption key into a self-mapping key. The mapping parameters described in this invention consist of two values: an initial offset and an offset step size generated by the true random number generator. 5. Self-Mapping Key: A stream key generated by byte transformation of the encryption key using the mapping parameters, used to encrypt other encryption keys.
[0187] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely descriptive and do not represent the superiority or inferiority of the embodiments.
[0188] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0189] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication encryption method, characterized in that, Applied to a first client, the method includes: Get the plaintext message; Obtain an encryption key from the first encryption key pool; wherein the encryption key is obtained by encrypting with a self-mapped key with a key ID on the server and decrypting with a self-mapped key with the same key ID in the first self-mapped key pool; The plaintext message is encrypted using the encryption key to obtain ciphertext message; wherein the ciphertext message contains the key ID. Send the encrypted message to the second client; The decryption using a self-mapped key with the same key ID from the first self-mapped key pool includes: Obtain the synthesized key; Obtain a first self-mapping key with the same key ID as the synthesized key from the first self-mapping key pool; decrypt the synthesized key using the first self-mapping key to obtain the synthesized key plaintext; wherein, the synthesized key plaintext includes key ID, encryption key and mapping parameters; Destroy the first self-mapping key; Based on the encryption key and mapping parameters obtained from the synthesized key plaintext, a new first self-mapping key is generated and stored in the first self-mapping key pool; the mapping parameters are located before the encryption key and are used to transform the encryption key. The encryption key is obtained from the synthesized key plaintext and stored in the first encryption key pool; Repeat the above steps until the number of encryption keys in the first encryption key pool reaches the available quantity threshold.
2. The method according to claim 1, characterized in that, After obtaining the plaintext message and before obtaining the encryption key from the first encryption key pool, the method further includes: The received plaintext message is stored in a buffer, and the length of the plaintext message in the buffer is determined in real time. When the plaintext of the message occupies a length of M bytes, the encryption key is obtained from the first encryption key pool; When the length of the plaintext message is less than M bytes, the length of the plaintext message in the buffer is determined in real time until the length of the buffer reaches M, and then the encryption key is obtained from the first encryption key pool.
3. The method according to claim 2, characterized in that, The mapping parameters include an offset and an offset step size. The encryption key occupies a byte length of M, an offset of S, and an offset step size of N. The total byte length occupied by the offset and the offset step size is K. The step of generating a new first self-mapping key based on the encryption key and the mapping parameters and storing it in the first self-mapping key pool includes: Create an empty self-mapping key; wherein the empty self-mapping key occupies a length of M+K bytes; The encryption key is initially offset by S bytes from the head and the byte data of the encryption key at the offset position is read and filled into the corresponding position in the empty self-mapped key; When the padding length of the empty self-mapping key is less than M+K bytes, continue to offset by N bytes and read the byte data of the encryption key at the offset position to fill the corresponding position in the empty self-mapping key; When the offset position is greater than M bytes after offsetting P bytes, offset NP bytes from the beginning of the encryption key; where P is less than N. Repeat the above steps until the empty self-mapping key data is filled in, obtain a new first self-mapping key and store it in the first self-mapping key pool.
4. The method according to any one of claims 2 or 3, characterized in that, The encryption key is a random number, the byte length M of the encryption key is a prime number, the offset S is less than M-1, and the offset step N is a prime number, which is less than or equal to one-tenth of M.
5. A communication encryption method, characterized in that, Applied to the server side, the method includes: Generate a synthesized key plaintext; the synthesized key plaintext includes mapping parameters and an encryption key, the mapping parameters being located before the encryption key and used to transform the encryption key; the synthesized key plaintext is obtained by decrypting the synthesized key using a first self-mapping key, the first self-mapping key being obtained from a first self-mapping key pool of a first client, the first self-mapping key having the same key ID as the synthesized key; the first self-mapping key pool stores a new first self-mapping key, the new first self-mapping key being generated based on the encryption key and mapping parameters obtained from the synthesized key plaintext after the first self-mapping key is destroyed; Obtain a second self-mapping key from a second self-mapping key pool; wherein the second self-mapping key has a key ID and is not related to the encryption key; The synthesized key plaintext is encrypted using the second self-mapping key to obtain the synthesized key; wherein the synthesized key carries the key ID of the second self-mapping key; The synthesized key is sent synchronously to the first client and the second client.
6. The method according to claim 5, characterized in that, The step of synchronously sending the synthesized key to the first client and the second client includes: Obtain the encryption modules of the paired first client and the second client; The synthesized key is sent synchronously to the encryption modules of the first client and the second client.
7. The method according to claim 5, characterized in that, The generation of the synthesized key plaintext includes: Obtain the encryption key and the mapping parameters; wherein the mapping parameters include an offset and an offset step size; The offset and offset step size are added sequentially to the header of the encryption key to generate the synthesized key plaintext.
8. The method according to claim 5, characterized in that, The encryption key has a byte length of M, an offset of S, and an offset step of N, and the total byte length of the offset and offset step is K. The method further includes: Create an empty self-mapping key; wherein the empty self-mapping key occupies a length of M+K bytes; The encryption key is initially offset by S bytes from the head and the byte data of the encryption key at the offset position is read and filled into the corresponding position in the empty self-mapped key; When the padding length of the empty self-mapping key is less than M+K bytes, continue to offset by N bytes and read the byte data of the encryption key at the offset position to fill the corresponding position in the empty self-mapping key; When the offset position is greater than M bytes after offsetting P bytes, offset NP bytes from the beginning of the encryption key; where P is less than N. Repeat the above steps until the empty self-mapping key data is filled in, obtain a new self-mapping key, and store it in the second self-mapping key pool.
9. The method according to any one of claims 5 to 8, characterized in that, The encryption key is a random number, the byte length M of the encryption key is a prime number, the offset S is less than M-1, and the offset step N is a prime number, which is less than or equal to one-tenth of M.
10. A communication encryption method, characterized in that, Applied to a second client, the method includes: Retrieve the encrypted message; Obtain the encryption key from the third encryption key pool; wherein the encryption key is obtained by encrypting with a self-mapped key with a key ID on the server and decrypting with a self-mapped key with the same key ID in the third self-mapped key pool; The ciphertext of the message is decrypted using the encryption key to obtain the plaintext message; The decryption using the self-mapped key with the same key ID from the third self-mapped key pool includes: Obtain the synthesized key; Obtain a third self-mapping key with the same key ID as the synthesized key from the third self-mapping key pool; The synthesized key is decrypted using the third self-mapping key to obtain the synthesized key plaintext; wherein, the synthesized key plaintext includes key ID, encryption key and mapping parameters; Destroy the third self-mapping key; Obtain the encryption key and mapping parameters from the synthesized key plaintext; Based on the encryption key and the mapping parameters, a new third self-mapping key is generated and stored in the third self-mapping key pool; the mapping parameters are located before the encryption key and are used to transform the encryption key. The encryption key is obtained from the synthesized key plaintext and stored in the third encryption key pool; Repeat the above steps until the number of encryption keys in the third encryption key pool reaches the available quantity threshold.
11. The method according to claim 10, characterized in that, The mapping parameters include an offset and an offset step size. The encryption key occupies a byte length of M, an offset of S, and an offset step size of N. The total byte length occupied by the offset and the offset step size is K. The step of generating a new third self-mapping key based on the encryption key and the mapping parameters and storing it in the third self-mapping key pool includes: Create an empty self-mapping key; wherein the empty self-mapping key occupies a length of M+K bytes; The encryption key is initially offset by S bytes from the head and the byte data of the encryption key at the offset position is read and filled into the corresponding position in the empty self-mapped key; When the padding length of the empty self-mapping key is less than M+K bytes, continue to offset by N bytes and read the byte data of the encryption key at the offset position to fill the corresponding position in the empty self-mapping key; When the offset position is greater than M bytes after offsetting P bytes, offset NP bytes from the beginning of the encryption key; where P is less than N. Repeat the above steps until the empty self-mapping key data is filled in, obtain a new third self-mapping key and store it in the third self-mapping key pool.
12. The method according to any one of claims 10 or 11, characterized in that, The encryption key is a random number, the byte length M of the encryption key is a prime number, the offset S is less than M-1, and the offset step N is a prime number, which is less than or equal to one-tenth of M.
Citation Information
Patent Citations
Data encryption and decryption method and device, and mobile terminal
CN103532706A
Information encryption, decryption and control method and device and electronic equipment
CN112260832A
Data transmission method and device and electronic device
CN112468470A