A test method, a test terminal device and a medium of a low-power wide-area network

By selecting different network modes and encryption algorithms, and combining them with machine learning intrusion detection systems, the network performance testing and security issues of low-power wide-area networks in different scenarios are solved, enabling low-cost network architecture construction and intrusion detection.

CN116669033BActive Publication Date: 2026-05-15CHINA ELECTRONICS STANDARDIZATION INST
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA ELECTRONICS STANDARDIZATION INST
Filing Date
2023-04-07
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing low-power wide-area networks are susceptible to radio frequency interference in unlicensed spectrum, making it difficult to guarantee service quality. On the other hand, large-scale application in licensed spectrum is costly, and there is a lack of effective intrusion detection testing methods in IoT device connection environments.

Method used

A testing method for low-power wide-area networks is proposed. By selecting different network modes (unlicensed spectrum, licensed spectrum, or hybrid network mode) and employing an intrusion detection system based on encryption algorithms and machine learning, the quality of network services and potential attacks are tested.

Benefits of technology

It enables low-cost network architecture construction and testing in different scenarios, ensuring network performance, while providing security and intrusion detection capabilities for the MQTT protocol, reducing equipment costs and resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116669033B_ABST
    Figure CN116669033B_ABST
Patent Text Reader

Abstract

The application provides a test method of a low-power wide-area network, which is applied to a test terminal and comprises the following steps: selecting a test request and a test target, wherein the test target comprises a network mode selection instruction of a low-power wide-area network to be tested or the test target comprises a selection instruction of an MQTT test scene; the network mode selection instruction comprises any one of a network mode of an unlicensed frequency spectrum, a network mode of a licensed frequency spectrum and a hybrid network mode; according to the network mode selection instruction, data of Internet of Things nodes in different network modes are collected and transmitted according to test paths of the respective network modes; the service quality of the transmitted data is tested according to the test paths; when a user selects a test target comprising a selection instruction of an MQTT test scene, test data sets are generated according to the MQTT test scene selected by the user, and the test data sets are input into an intrusion detection system built in an MQTT agent to test the intrusion detection system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network testing technology, and relates to a testing method, testing terminal device and medium for low power wide area networks. Background Technology

[0002] Low-power wide-area networks, also known as LPWAN, are a widely used Internet of Things (IoT) technology. Examples include SIGFOX, LoRaWAN, INGENU, WeightlessW / N / P, NB-IoT, and mMTC. LPWANs can be divided into two categories based on their application scenarios: one category includes technologies such as LoRa and SigFox that operate on unlicensed spectrum, with LoRa frequently used in various time-sensitive network services; the other category includes 2G / 3G / 4G cellular communication technologies supported by 3GPP, such as EC-GSM, LTE Cat-m, and NB-IoT, operating on licensed spectrum. NB-IoT is gradually becoming a standard technology for 5G. Based on global network coverage, operators can quickly deploy global LPWANs. Currently, NB-IoT / eMTC has become the primary choice for the core infrastructure of cellular IoT services for major global operators. Compared to telecom operators, technologies like LoRa can be deployed on demand and on a small scale. However, not all companies have the capability or need to build their own core network, network management, and billing systems. They can quickly achieve network operation by leveraging existing third-party cloud platforms.

[0003] With the active promotion of mainstream operators, equipment manufacturers, and the international standards organization 3GPP, NB-IoT / eMTC can easily achieve wide-ranging, global coverage, focusing on the "large market." Meanwhile, unlicensed networks such as LoRa, driven by SMEs and the strong demand for customized network construction, are thriving in various deployment scenarios, focusing on the "small market" and the "long tail market." In terms of scale, due to diverse and fragmented scenario demands, the long tail market will likely account for half of the market in the future. The two networks complement each other, jointly improving the IoT network layer and promoting the rapid development of the IoT industry.

[0004] In summary, existing technologies have the following drawbacks: Both types of low-power wide-area networks (LPWANs) have their advantages and disadvantages. LPWANs operating on unlicensed spectrum are susceptible to radio frequency interference, making it difficult to guarantee their quality of service. While LPWANs operating on licensed spectrum offer more stable service quality, large-scale applications require mobile network operators to subscribe periodically for each sensor node, consuming significant resources and incurring high costs. One of the issues addressed in this patent is how to construct and test low-power networks in different scenarios to achieve reasonable network performance under a low-cost network architecture. Furthermore, a large number of Internet of Things (IoT) devices and networks are used in various application scenarios, including healthcare, smart cities, supply chains, and agriculture. With this expanding use of IoT, new protocols are being deployed. For example, the MQTT protocol collects data from IoT devices, performs calculations and analyses at edge computing gateway nodes, and then transmits the data to a customer-customized MQTT cloud platform via the MQTT IoT protocol. To ensure the security of the MQTT protocol, it is crucial to handle the connection and transmission of various types of data and prevent vulnerabilities from being exploited by malicious actors. This is an urgent problem to be solved. Currently, no effective testing methods have been found. Achieving effective intrusion detection in various IoT device connection environments is also a concern of ours. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention proposes a testing method for low-power wide-area networks (LPWANs), applied in a test terminal. The method includes the following steps: selecting a test request and a test target, wherein the test target includes a network mode selection instruction for the LPWAN to be tested or a selection instruction for an MQTT test scenario; the network mode selection instruction includes any one of unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode; according to the network mode selection instruction, IoT nodes in different network modes collect data and transmit data according to the test path of their respective network modes; the service quality of the transmitted data is tested according to the test path; wherein, when the network mode of the LPWAN in the test target is selected as unlicensed spectrum network mode, IoT nodes using unlicensed spectrum and unlicensed spectrum gateways are selected. The test path for unlicensed spectrum includes the cloud, MQTT broker, and database. When the network mode of the low-power wide area network (LPWAN) in the test target is selected as the licensed spectrum network mode, the test path for the licensed spectrum includes IoT nodes, mobile operator network base stations, core network, cloud, MQTT broker, and database. When the network mode of the LWAN in the test target is selected as the hybrid network mode, the test path for the licensed spectrum includes IoT nodes, unlicensed spectrum gateways, IoT nodes, mobile operator network base stations, core network, cloud, MQTT broker, and database. When the user selects a test target including an MQTT test scenario, a test dataset is generated based on the user-selected MQTT test scenario. The test dataset is then input into the intrusion detection system built at the MQTT broker to test the intrusion detection system.

[0006] Optionally, when the network mode of the low-power wide area network in the test target is selected as the unlicensed spectrum network mode, the terminal captures the time when the IoT node conforming to the unlicensed spectrum protocol encrypts the collected payload into encrypted data packets using an encryption algorithm, the time when the encrypted data packets are sent to the unlicensed spectrum gateway using the unlicensed spectrum protocol, the time when the collected encrypted data packets are sent from the unlicensed spectrum gateway to the cloud, the time when the cloud transmits the encrypted data packets to the agent, and the time when the agent stores the encrypted data packets in the database; when the network mode of the low-power wide area network in the test target is selected as the licensed spectrum network mode, the terminal captures the time when the IoT node conforming to the licensed spectrum protocol encrypts the collected payload into encrypted data packets using an encryption algorithm, the time when the encrypted data packets are sent to the eNodeB, and the time when the encrypted data packets conforming to the licensed spectrum protocol are stored in the database. The time it takes for the packet to be forwarded from the eNodeB through the core network to the cloud; the time it takes for the cloud to transmit the data to the agent, and the time it takes for the agent to store the encrypted data packet in the database; when the network mode of the low-power wide area network in the test target is selected as hybrid network mode, the time it takes for the terminal to capture the effective payload collected by the IoT node conforming to the unlicensed spectrum protocol and form an encrypted data packet through the encryption algorithm; the time it takes to send the encrypted data packet to the unlicensed spectrum gateway; the time it takes for the encrypted data packet conforming to the unlicensed spectrum protocol to reach the licensed spectrum node from the gateway; the time it takes for the encrypted data packet to be sent to the eNodeB through the licensed spectrum node; the time it takes for the encrypted data packet to be forwarded from the eNodeB through the core network to the cloud; the time it takes for the cloud to transmit the encrypted data packet to the agent, and the time it takes for the agent to store the encrypted data packet in the database.

[0007] Optionally, the test request includes the current time at the test terminal, and the IoT node combines the current time with a symmetric key and the IoT node's identifier as a temporary symmetric encryption key; the encryption algorithm includes using the temporary symmetric encryption key to encrypt the collected payload and the signal strength RSSI at the IoT node to form an encrypted data packet.

[0008] Optionally, testing the quality of service of the transmitted payload according to the test path includes: obtaining the signal strength RSSI at the IoT node by decrypting with a temporary symmetric key, as part of the test result parameters; and calculating the total time delay based on the time delay on the captured path as the test result.

[0009] Optionally, when the user selects a test target including a normal MQTT data communication scenario, a test dataset needs to be constructed first. The payloads randomly generated from IoT nodes conforming to unlicensed spectrum protocols and IoT nodes conforming to licensed spectrum protocols of different types are encapsulated through the MQTT protocol to form a test data set. The test dataset is then input into an intrusion detection system built at the MQTT broker in a publish-subscribe mode; the intrusion detection system is then trained and tested.

[0010] Optionally, when the user selects an MQTT attack data communication scenario as the test target, a corresponding dataset is constructed. This dataset includes MQTT protocol data packets encapsulated with payloads randomly generated by IoT nodes using unlicensed spectrum protocols and IoT nodes using licensed spectrum protocols, along with MQTT format data packets with attack characteristics, forming a test dataset. The test dataset is then input into an intrusion detection system built at an MQTT broker using a publish-subscribe model. The intrusion detection system is then trained and tested.

[0011] Optionally, the unlicensed spectrum protocol includes the LoRa protocol or the SigFox protocol; the licensed spectrum protocol includes the NB-IoT protocol.

[0012] This invention also proposes a test terminal device for low-power wide-area networks, the test terminal device comprising:

[0013] The test selection unit is used to select the test request and test target to be sent. The test target includes a network mode selection instruction for the low-power wide area network to be tested or a selection instruction for an MQTT test scenario. The network mode selection instruction includes any one of the following three: unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode.

[0014] The path delay testing unit is used to collect data from IoT nodes in different network modes according to the network mode selection instruction and transmit the data according to the test path of each network mode; and to test the service quality of the transmitted data according to the test path; wherein, when the network mode of the low-power wide area network in the test target is selected as the unlicensed spectrum network mode, the IoT nodes using unlicensed spectrum, unlicensed spectrum gateways, cloud, MQTT brokers, and databases are selected as the unlicensed spectrum test path; when the network mode of the low-power wide area network in the test target is selected as the licensed spectrum network mode, the IoT nodes using licensed spectrum and mobile operator network base stations are selected as the test path. The test path for the core network, cloud, MQTT broker, and database is selected as the licensed spectrum. When the network mode of the low-power wide area network in the test target is selected as the hybrid network mode, the test path for the hybrid network mode is selected as the IoT node of the unlicensed spectrum, the gateway of the unlicensed spectrum, the IoT node of the licensed spectrum, the mobile operator network base station, the core network, the cloud, the MQTT broker, and the database. When the user selects the test target including the MQTT test scenario selection instruction, a test dataset is generated according to the MQTT test scenario selected by the user, and the test dataset is input into the intrusion detection system built at the MQTT broker. The intrusion detection system is then tested.

[0015] The present invention also proposes a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the test method for the low-power wide-area network.

[0016] The present invention also proposes an electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute a testing method for a low-power wide-area network as described above by executing the executable instructions. Using the method of the present invention, low-power wide-area networks in different scenarios can be constructed and tested, and training and testing of machine learning-based intrusion detection systems within the entire network architecture can be achieved. Attached Figure Description

[0017] Figure 1 This is a flowchart of a testing method for a low-power wide-area network proposed in this invention. Detailed Implementation

[0018] The following description, with reference to the accompanying drawings, illustrates several preferred embodiments of the present invention to make its technical content clearer and easier to understand. The present invention can be embodied in many different forms, and the scope of protection of the present invention is not limited to the embodiments mentioned herein.

[0019] According to one aspect of the embodiments of this application, a testing method for low-power wide-area networks is provided, applied in a test terminal, the process of which is as follows: Figure 1 As shown: This method includes the following steps:

[0020] Step 1: Select the test request and test target. The test target may include a network mode selection instruction for the low-power wide area network to be tested or a selection instruction for the MQTT test scenario. The network mode selection instruction may include any one of the following: unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode.

[0021] Step 2: Control the IoT nodes in different network modes to collect data and transmit data according to their respective network modes, and perform quality of service (QoS) tests on the transmitted data. Specifically, the data collected by the IoT nodes in different network modes is the payload; when the test target is an unlicensed spectrum network, the IoT nodes used are those conforming to the LoRa or SigFox protocols. These IoT nodes have a pre-negotiated symmetric encryption key with the test terminal. When a test request is received from the test terminal, the IoT node parses the request, which includes the current time at the test terminal. The IoT node combines the current time with the symmetric key and the IoT node's identifier to form a temporary symmetric encryption key. Specifically, this combination can be achieved by logically concatenating the two.

[0022] The encryption algorithm used in this embodiment includes: encrypting the collected payload and the current signal strength (RSSI) at the IoT node conforming to the LoRa or SigFox protocol using the temporary symmetric encryption key to form an encrypted data packet; sending the encrypted data packet to a gateway in the unlicensed spectrum; the gateway in the unlicensed spectrum, upon receiving the encrypted data packet from the IoT node, encapsulates it in the MQTT lightweight protocol and sends it to the cloud; the cloud then forwards the encrypted data packet to the server via a proxy and stores it in a database. Therefore, when calculating the transmission delay of this network mode, the time delay on each of the above paths is calculated according to the transmission path, i.e., the time it takes for the terminal to capture the collected payload from the IoT node conforming to the LoRa or SigFox protocol and obtain the encrypted data packet using the encryption algorithm. The time intervals are as follows: the time when encrypted data packets are sent to the unlicensed spectrum gateway via the unlicensed spectrum protocol; the time when the collected encrypted data packets are sent from the unlicensed spectrum gateway to the cloud; the time when the cloud transmits the encrypted data packets to the agent; and the time when the agent stores the encrypted data packets on the server and stores them in the database. The test terminal reads the encrypted data packets from the database, and similarly, based on the time when the test command is sent, combines them with the symmetric key and the identifier of the IoT node to generate a temporary symmetric key. The temporary symmetric key is used to decrypt the payload conforming to the LoRa or SigFox protocol and the signal strength RSSI at the IoT node, which is used as part of the test result parameters. At the same time, the total time delay is calculated based on the time delay on the captured path, which is used as another part of the test result parameters.

[0023] When the user selects the licensed spectrum network mode, i.e., the test target is a licensed spectrum network, the IoT node used in this embodiment is an IoT node conforming to the NB-IoT protocol. The IoT node conforming to the NB-IoT protocol has a symmetric encryption key negotiated in advance with the test terminal. When a test request is received from the test terminal, the IoT node parses the test request. The test request includes the current time at the test terminal. The IoT node combines the current time with the symmetric key and the IoT node's identifier as a temporary symmetric encryption key. The specific combination method can be to logically connect the two.

[0024] The encryption algorithm used in this embodiment includes: encrypting the collected payload and the current signal strength (RSSI) at the IoT node conforming to the NB-IoT protocol using the temporary symmetric encryption key, and then encapsulating it as an encrypted data packet conforming to the NB-IoT protocol in the MQTT lightweight protocol and sending it to the eNodeB. The eNodeB then sends the MQTT protocol data packet to the NB-IoT core network. Here, the NB-IoT core network is responsible for interacting with the terminal's non-access layer. The eNodeB operates on a closed network server and multiple licensed frequencies. It can also forward IoT service-related data to the cloud through the core network and store the encrypted data packet of the NB-IoT protocol in the database through a proxy. Therefore, when calculating the transmission delay of this network mode, the time delay on the above path will be calculated separately according to the transmission path, namely, the time when the terminal captures the collected payload from the IoT node conforming to the NB-IoT protocol and forms an encrypted data packet using the encryption algorithm; the time when the encrypted data packet is sent to the eNodeB; the time when the encrypted data packet conforming to the licensed spectrum protocol is forwarded from the eNodeB to the cloud through the core network; the time when the cloud transmits the data to the proxy; and the time when the proxy stores the encrypted data packet in the database. The test terminal reads encrypted data packets conforming to the NB-IoT protocol from the database. Similarly, based on the time when the test command is sent, a temporary symmetric key is generated by combining the symmetric keys corresponding to the IoT node identifier. The signal strength RSSI at the IoT node conforming to the NB-IoT protocol is obtained by decrypting with the temporary symmetric key and is used as part of the test result parameters. At the same time, the total time delay is calculated based on the time delay on the captured path and is used as another part of the test result parameters.

[0025] When the user selects a hybrid network mode, the IoT nodes using unlicensed spectrum communicate with IoT nodes using licensed spectrum via a network structure connected in series through a gateway. While this communication method may result in higher latency, it combines the advantages of both licensed and unlicensed spectrum. It enables data collection from IoT nodes through a low-cost unlicensed spectrum network; it leverages the stable transmission characteristics of licensed spectrum to ensure stable transmission quality; and by using unlicensed spectrum as the aggregation node, it significantly reduces data transmission costs, avoiding the high costs associated with traditional methods where each cellular IoT node requires a separate SIM card for communication with a licensed spectrum network. In this hybrid communication mode, IoT devices can still use IoT nodes compliant with LoRa or SigFox protocols. When receiving a test request from a test terminal, the IoT node parses the request, which includes the current time at the test terminal. The IoT node combines this current time with a symmetric key and its identifier to create a temporary symmetric encryption key; this combination can be achieved by logically concatenating the two.

[0026] The encryption algorithm used in this embodiment includes: encrypting the collected payload and the current signal strength (RSSI) at the IoT node conforming to the LoRa or SigFox protocol using the temporary symmetric encryption key, and then sending the encrypted data packet conforming to the LoRa or SigFox protocol to the gateway in the unlicensed spectrum; the gateway in the unlicensed spectrum relays the data to the network node in the licensed spectrum, and through the network in the licensed spectrum, forwards the encrypted data packet from the eNodeB through the core network to the cloud, and then the cloud transmits the data to the proxy service; finally, the proxy service stores the encrypted data packet in the database. Therefore, when calculating the transmission delay of this network mode, the time delay on the above path is calculated separately according to the transmission path, namely: the time when the terminal captures the encrypted payload collected by the IoT node conforming to the LoRa or SigFox protocol and encrypts it to form an encrypted data packet; the time when the encrypted data packet is sent to the unlicensed spectrum gateway; the time when the encrypted data packet is sent from the unlicensed spectrum gateway to the node conforming to the licensed spectrum; the time when the encrypted data packet is sent from the node conforming to the licensed spectrum; the time when the encrypted data packet is sent from the node conforming to the licensed spectrum; the time when the encrypted data packet is sent from the node conforming to the licensed spectrum; the time when the encrypted data packet is sent from the eNodeB through the core network; the time when the cloud transmits the encrypted data packet to the proxy; and the time when the proxy stores it in the database. The test terminal reads payloads conforming to the LoRa or SigFox protocol from the database. Similarly, based on the time of sending the test command, a temporary symmetric key is generated from the symmetric key combination corresponding to the IoT node identifier. This temporary symmetric key is used to decrypt the data collected at the IoT node conforming to the LoRa or SigFox protocol, along with the corresponding RSSI signal strength, as part of the test result parameters. Simultaneously, the total time delay is calculated based on the time delay along the captured path, serving as another part of the test result parameters. In practice, while this communication method may result in greater latency, it combines the advantages of both licensed and unlicensed spectrum. It enables data collection from IoT nodes through low-cost unlicensed spectrum networks; it leverages the stable transmission characteristics of licensed spectrum to ensure stable transmission quality; and by using unlicensed spectrum as the aggregation node, it significantly reduces data transmission costs, avoiding the high costs associated with traditional methods where each cellular IoT node requires a separate SIM card for communication with licensed spectrum networks.

[0027] In the above embodiments, network service quality testing is achieved by including three different network modes in the test target. The advantages of each network mode can be combined individually or in combination to achieve hybrid mode communication testing.

[0028] The test focuses on MQTT scenarios used in network communication, where data is transmitted from the cloud to the broker service. When the test target is an MQTT scenario selection command, a corresponding test set is generated based on the selected MQTT scenario. Specifically, the MQTT scenario can include at least normal MQTT data communication scenarios and scenarios involving MQTT attacks. When the user selects the normal MQTT data communication scenario, a test dataset needs to be constructed first. Data packets are randomly generated from IoT nodes conforming to LoRa or SigFox protocols, and from different types of IoT nodes conforming to NB-IoT protocols. These data packets are then encapsulated using the MQTT protocol to form a test data set. The test data set is then detected by an intrusion detection system built at the MQTT broker in a publish-subscribe mode.

[0029] When the user selects the MQTT attack scenario, the corresponding dataset also needs to be constructed first. Specifically, the dataset includes MQTT protocol data packets encapsulated in data packets randomly generated by IoT nodes according to the LoRa or SigFox protocols and IoT nodes according to the NB-IoT protocol, as well as MQTT format data packets with attack characteristics. At this time, we connect a host with a Linux operating system installed in the network to generate data with specific attack characteristics, which together with normal data form a test dataset. Since both normal data packets and attack characteristic data packets communicate through a publish-subscribe pattern and have the same communication pattern, it is particularly important to identify the attack characteristic data. In this embodiment, we choose to use machine learning to solve this problem. The attack data set used can include data generated by common network scanning attack methods, such as attack data through UDP scanning, Spartan SSH brute-force attack methods, and datasets using MQTT brute-force scanning attacks.

[0030] Whether it's a test dataset for normal MQTT data communication or a test dataset for an MQTT attack, we divide the test dataset into two parts. When using a normal MQTT data communication scenario, one part of the dataset is used to train a classification model based on the data behavior in a normal data communication scenario; the other part is used to test the trained model. Similarly, when constructing a test dataset for an MQTT attack scenario, the test dataset is also divided into two parts: one part is used to train the classification model, and the other part is used to test the trained model. The test dataset for an MQTT attack scenario includes MQTT format data packets with attack characteristics.

[0031] In this invention, an XGBOOST classification model is trained on behavioral features from a dataset with attack characteristics. The XGBOOST classification model algorithm is an open-source decision tree algorithm, specifically an improvement on the boosting algorithm based on GBDT (Gradient Boosting Decision Tree). Its core lies in the optimization of the loss function and the solution algorithm. The XGBOOST loss function is modeled based on maximum likelihood estimation; for each sample, it is essentially a typical binomial probability model. The XGBOOST solution algorithm, specifically for each tree, involves continuously finding split points to divide the sample set. Initially, all samples are at a single node (the root node). As the tree expands, samples are assigned to the split child nodes. The selection of split points is accomplished by enumerating the feature values ​​on the training sample set, and the selection criterion is to reduce the loss. The XGBOOST algorithm can improve the predictive capabilities of the model. The XGBOOST algorithm features regularization, parallel processing, high flexibility, missing value handling, pruning, built-in cross-validation, and the ability to continue training based on existing models. Of course, those skilled in the art should understand that the training of parameters and behavioral features is not limited to the XGBOOST algorithm trainer described in this invention; other intelligent trainers can also be used. In practical applications, we choose to use two-thirds of the dataset for training the XGBOOST classification model of the intrusion detection system, and the remaining one-third for testing the XGBOOST classification model. The input dataset can be a pcap file directly captured by the TCPDUMP tool, or it can be data packets or data streams.

[0032] Besides the XGBOOST classification model algorithm, we can also choose other machine learning algorithms for classification, such as random forest, support vector machine (SVM), logistic regression, etc.

[0033] The present invention also proposes a test terminal device for low-power wide area networks. The test terminal device includes: a test selection unit, used to select and send a test request and a test target. The test target includes a network mode selection instruction for the low-power wide area network to be tested or a selection instruction for an MQTT test scenario. The network mode selection instruction includes any one of the following: unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode.

[0034] The path delay testing unit is used to collect data from IoT nodes in different network modes according to the network mode selection instruction and transmit the data according to the test path of each network mode; and to test the service quality of the transmitted data according to the test path; wherein, when the network mode of the low-power wide area network in the test target is selected as the unlicensed spectrum network mode, the IoT nodes using unlicensed spectrum, unlicensed spectrum gateways, cloud, MQTT brokers, and databases are selected as the unlicensed spectrum test path; when the network mode of the low-power wide area network in the test target is selected as the licensed spectrum network mode, the IoT nodes using licensed spectrum and mobile operator network base stations are selected as the unlicensed spectrum test path. The test path for the licensed spectrum includes the base station, core network, cloud, MQTT broker, and database. When the network mode of the low-power wide area network in the test target is selected as the hybrid network mode, the test path for the licensed spectrum includes IoT nodes on unlicensed spectrum, gateways on unlicensed spectrum, IoT nodes on licensed spectrum, mobile operator network base stations, core network, cloud, MQTT broker, and database. When the user selects an MQTT test scenario as the test target, a test dataset is generated based on the user-selected MQTT test scenario. The test dataset is then input into the intrusion detection system built at the MQTT broker to test the intrusion detection system.

[0035] It should be understood that the processor in the embodiments of the present invention may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method embodiments can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor described above can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0036] It is understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). It should be noted that the memory used in the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0037] It should be understood that the above-described memory is exemplary but not restrictive. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.

[0038] This application also provides a computer-readable storage medium for storing computer programs.

[0039] Optionally, the computer-readable storage medium can be applied to the terminal device in the embodiments of this application, and the computer program causes the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0040] This application also provides a computer program product, including computer program instructions.

[0041] Optionally, the computer program product can be applied to the terminal device in the embodiments of this application, and the computer program instructions cause the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of this application. For the sake of brevity, they will not be described in detail here.

[0042] This application also provides a computer program.

[0043] Optionally, the computer program can be applied to the vehicle autonomous driving device in the embodiments of this application. When the computer program is run on a computer, it causes the computer to execute the corresponding processes implemented by the terminal device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.

[0044] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0045] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0046] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0047] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

Claims

1. A testing method for low-power wide-area networks, applied in a test terminal, characterized in that, The method includes the following steps: Select the test request and test target to send. The test target includes a network mode selection instruction for the low-power wide area network to be tested or a selection instruction for an MQTT test scenario. The network mode selection instruction includes any one of the following: unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode. According to the network mode selection instruction, IoT nodes in different network modes collect data and transmit data according to the test path of their respective network modes; the quality of service of the transmitted data is tested according to the test path. Specifically, when the network mode of the low-power wide area network (LPWAN) in the test target is selected as the unlicensed spectrum network mode, the test path for the unlicensed spectrum will be selected, consisting of IoT nodes using unlicensed spectrum, gateways using unlicensed spectrum, cloud, MQTT broker, and database. When the network mode of the LWAN in the test target is selected as the licensed spectrum network mode, the test path for the licensed spectrum will be selected, consisting of IoT nodes using unlicensed spectrum, gateways using unlicensed spectrum, IoT nodes using licensed spectrum, base stations using mobile operator networks, core network, cloud, MQTT broker, and database. When the user selects a test target including an MQTT test scenario, a test dataset is generated based on the user-selected MQTT test scenario, and the test dataset is input into the intrusion detection system built at the MQTT broker; the intrusion detection system is then tested.

2. The testing method for low-power wide-area networks according to claim 1, characterized in that, When the network mode of the low-power wide area network in the test target is selected as the unlicensed spectrum network mode, the terminal captures the time when the IoT node that conforms to the unlicensed spectrum protocol obtains the encrypted data packet by encrypting the collected payload through the encryption algorithm, the time when the encrypted data packet is sent to the unlicensed spectrum gateway through the unlicensed spectrum protocol, the time when the collected encrypted data packet is sent from the unlicensed spectrum gateway to the cloud, the time when the cloud transmits the encrypted data packet to the agent, and the time when the agent stores the encrypted data packet in the database. When the network mode of the low-power wide area network in the test target is selected as the licensed spectrum network mode, the terminal captures the time when the IoT node conforming to the licensed spectrum protocol forms an encrypted data packet from the collected payload through the encryption algorithm, the time when the encrypted data packet is sent to the eNodeB, the time when the encrypted data packet conforming to the licensed spectrum protocol is forwarded from the eNodeB to the cloud through the core network, the time when the cloud transmits the data to the agent, and the time when the agent stores the encrypted data packet in the database. When the network mode of the low-power wide area network in the test target is selected as the hybrid network mode, the terminal captures the following time: the time when the IoT node conforming to the unlicensed spectrum protocol forms an encrypted data packet from the collected payload through the encryption algorithm; the time when the encrypted data packet is sent to the unlicensed spectrum gateway; the time when the encrypted data packet conforming to the unlicensed spectrum protocol arrives at the IoT node conforming to the licensed spectrum from the gateway; the time when the IoT node with the licensed spectrum sends the encrypted data packet to the eNodeB; the time when the encrypted data packet is forwarded from the eNodeB to the cloud through the core network; the time when the cloud transmits the encrypted data packet to the agent; and the time when the agent stores the encrypted data packet in the database.

3. The testing method for low-power wide-area networks according to claim 2, characterized in that, The test request includes the current time at the test terminal. The IoT node combines the current time with a symmetric key and the IoT node's identifier to form a temporary symmetric encryption key. The encryption algorithm includes using the temporary symmetric encryption key to encrypt the collected payload and the signal strength RSSI at the IoT node to form an encrypted data packet.

4. The testing method for low-power wide-area networks according to claim 3, characterized in that, The quality of service (QoS) test of the transmitted payload according to the test path includes: obtaining the signal strength (RSSI) at the IoT node through temporary symmetric key decryption, as part of the test result parameters; and calculating the total time delay based on the time delay on the captured path as the test result.

5. The testing method for low-power wide-area networks according to claim 1, characterized in that, When a user selects a test target that includes a normal MQTT data communication scenario, the first step is to construct a test dataset. This dataset consists of payloads randomly generated from IoT nodes that conform to unlicensed spectrum protocols and IoT nodes that conform to licensed spectrum protocols, respectively. These payloads are then encapsulated using the MQTT protocol to form a test data set. The test dataset is then input into an intrusion detection system built at the MQTT broker in a publish-subscribe pattern. This allows for the training and testing of the intrusion detection system.

6. The testing method for low-power wide-area networks according to claim 1, characterized in that, When the user selects a test target that includes an MQTT attack data communication scenario, a test dataset is constructed that includes MQTT protocol data packets encapsulated with payloads randomly generated by IoT nodes according to unlicensed spectrum protocols and IoT nodes according to licensed spectrum protocols, as well as MQTT format data packets with attack characteristics. Using a publish-subscribe model, the test dataset is input into the intrusion detection system built on the MQTT broker; the intrusion detection system is then trained and tested.

7. The test method for low-power wide-area networks according to any one of claims 2-6, characterized in that, The unlicensed spectrum protocol includes the LoRa protocol or the SigFox protocol; the licensed spectrum protocol includes the NB-IoT protocol.

8. A test terminal device for a low-power wide area network, characterized in that, The test terminal device includes: The test selection unit is used to select the test request and test target to be sent. The test target includes a network mode selection instruction for the low-power wide area network to be tested or a selection instruction for an MQTT test scenario. The network mode selection instruction includes any one of the following three: unlicensed spectrum network mode, licensed spectrum network mode, and hybrid network mode. The path delay testing unit is used to collect data from IoT nodes in different network modes according to the network mode selection instruction and transmit the data according to the test path of each network mode; and to test the service quality of the transmitted data according to the test path; wherein, when the network mode of the low-power wide area network in the test target is selected as the unlicensed spectrum network mode, the IoT nodes using unlicensed spectrum, unlicensed spectrum gateways, cloud, MQTT brokers, and databases are selected as the unlicensed spectrum test paths; when the network mode of the low-power wide area network in the test target is selected as the licensed spectrum network mode, the IoT nodes using licensed spectrum and mobile operator network base stations are selected. The test path uses the core network, cloud, MQTT broker, and database as the licensed spectrum. When the network mode of the low-power wide area network in the test target is selected as the hybrid network mode, the test path will use unlicensed spectrum IoT nodes, unlicensed spectrum gateways, licensed spectrum IoT nodes, mobile operator network base stations, core network, cloud, MQTT broker, and database as the hybrid network mode test path. When the user selects the test target including the MQTT test scenario selection command, a test dataset is generated according to the user's selected MQTT test scenario, and the test dataset is input into the intrusion detection system built at the MQTT broker; the intrusion detection system is then tested.

9. A computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the test method for a low-power wide-area network as described in any one of claims 1 to 7.

10. An electronic device, characterized in that, include: Processor; and A memory for storing executable instructions of the processor; wherein the processor is configured to perform a test method for a low-power wide-area network according to any one of claims 1 to 7 by executing the executable instructions.