A data security transmission method and an electronic device based on encoding and encryption
By introducing encryption algorithms and dynamic key management into the physical layer of wireless communication, the problem of key exposure and risk cracking in the prior art is solved, and efficient encrypted communication and data secure transmission of the physical layer is realized.
Patent Information
- Application Number
- CN202410718372.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-04
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-06-04
AI Technical Summary
In the existing wireless communication technology, software secure encrypted communication is mainly implemented in the application layer and the MAC layer, with risks of key exposure and cracking, and data encryption and key security in the physical layer are difficult to ensure.
The encryption algorithm is introduced in the physical layer, and the key number is dynamically changed by solidifying multiple keys in the baseband chip and indexing the sequence number, combining the upper-layer register configuration and the MAC layer to negotiate the key number, thereby encrypting data transmission.
Effectively prevent eavesdroppers from demodulating physical layer data, improve the concealment and security of wireless communication, avoid the risks of key exposure and cracking, and ensure the security of data encryption algorithms and keys.
Smart Images

Figure CN118945644B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless communications and industrial wireless networks, and in particular to a data security transmission method and electronic equipment based on coding and encryption. Background Art
[0002] Current wireless communication technologies, including 4G / 5G, WIFI, Bluetooth, industrial wireless network protocols, and wireless sensor network protocols, mainly use network access authentication and encryption technologies in terms of security protection. For example, WIFI's WPA2 authentication mechanism and AES algorithm packet encryption mechanism are used to solve the problems of "fake base stations" illegally accessing the network and "eavesdroppers" cracking the plaintext of communication data.
[0003] However, current wireless network attacks generally involve the cracking of traditional authentication keys and encryption keys. Once the key information is exposed, it will not only cause the leakage of wireless transmission information, but may also be attacked by malicious forged data, causing all devices in the wireless network to be unable to send data, or even paralyzing the wireless network.
[0004] At present, software security encryption communication methods are mainly implemented in the application layer and MAC layer. The encryption communication of subsequent data is completed through the upper-layer key configuration, which may have the risk of key exposure and cracking. At present, encoders are generally used in the physical layer to implement data conversion functions and interleaved memories to implement data interleaving algorithms to complete basic data transmission and anti-interference functions. How to ensure the security of data encryption algorithms and keys is an important issue that needs to be solved urgently. Summary of the invention
[0005] The purpose of the present invention is to address the fact that the current software security encryption communication means are mainly implemented in the application layer and the MAC layer. At the physical layer, encoders are generally used to implement data conversion functions and interleaving memories to implement data interleaving algorithms to complete basic data transmission and anti-interference. How to ensure the security of physical data and keys is an urgent problem to be solved. In view of this, a data security transmission method based on encoding and encryption is proposed. The method adds an encryption algorithm to the physical layer encoding and interleaving algorithm. There are N keys, all of which are solidified in the baseband chip and indexed by serial numbers. The key serial numbers are configured through upper-layer registers. The MAC layer negotiates the key number through MAC data frames to achieve dynamic changes in the key number, making it impossible for eavesdroppers to demodulate the physical layer data, thereby ensuring the concealment and security of the physical layer.
[0006] In order to achieve the aforementioned purpose, the present invention adopts the following technical scheme.
[0007] In a first aspect, the present invention provides a data security transmission method based on coding and encryption, comprising the following steps:
[0008] S10. Solidify the key inside the chip physical layer and configure the corresponding key serial number for each key;
[0009] S11. The coding check matrix is transformed into an approximate lower triangular matrix by row-column transformation;
[0010] S12. Applying Gaussian elimination method to eliminate the matrix aligned with the approximate lower triangular matrix in the column direction in the coding check matrix to obtain a conjugate matrix of the coding check matrix;
[0011] S13. Set the codeword row sequence to 0 by multiplying the conjugate matrix by the transposed matrix and solve it to obtain the check code row sequence;
[0012] S14. The length of the recorded information sequence is a len sequence of the specified number of bits;
[0013] S15. Align the information sequence by k-bit data groups to obtain a k-bit aligned information sequence;
[0014] S16. According to the key sequence number configured at the link or network layer, the corresponding key is found in the register; the k-bit aligned information sequence is encrypted using the key found by the addressing to obtain an encrypted sequence;
[0015] S17. Concatenate the len sequence of the specified number of bits, the encryption sequence obtained in S16, and the coding check line sequence obtained in S13 to obtain a transmission coding line sequence;
[0016] S18. The code line sequence is transmitted via the channel;
[0017] S19. The receiving end receives the transmitted coded line sequence transmitted via the channel and then decodes and decrypts it to obtain the information sequence.
[0018] As a possible implementation method, the S11 converts the coding check matrix into an approximate lower triangular matrix through row-column transformation;
[0019] The coding check matrix is denoted as Its dimension is m×n; the dimension of A is (mg)×(nm), the dimension of B is (mg)×g, T is a lower triangular matrix with dimension mg, the dimension of C is g×(nm), the dimension of D is g×g, and the dimension of E is g×(mg).
[0020] As a possible implementation manner, the S12 specifically includes:
[0021] S120.Configuration Matrix
[0022] Wherein, I is the identity matrix; m_g is the dimension of the lower triangular matrix T in the approximate lower triangular matrix; m is the number of rows of the approximate lower triangular matrix; g is the difference between the approximate lower triangular matrix and the number of rows of its lower triangular matrix;
[0023] S121. Multiply the matrix configured in S120 on the left by the approximate lower triangular matrix to obtain the conjugate matrix of the coding check matrix.
[0024] As a possible implementation manner, the S121 is specifically: After multiplying the corresponding elements of each column of the matrix and each row of the coding check matrix and then adding them up.
[0025] As a possible implementation manner, the codeword row sequence in S13 is a vector composed of an information sequence and a coding row sequence, denoted as X = [ur 1 r 2 , where u is the information sequence; the conjugate matrix is expressed as: The transpose matrix of the conjugate matrix, denoted as
[0026] Wherein,
[0027] As a possible implementation manner, when specifically implementing S13, according to the characteristics of the transpose matrix of the conjugate matrix, multiply the transpose matrix of the conjugate matrix on the right, that is Substitute the information sequence u into to solve and obtain the coding check row sequences r 1 and r 2 .
[0028] As a possible implementation manner, the S15 is specifically: If the specified number of bits of the len sequence is not an integer multiple of k, add 0 to make it up to obtain the information sequence aligned to k bits; otherwise, if it is an integer multiple of k, there is no need to align the information sequence in k-bit data groups, and directly use the len sequence as the length of the information sequence aligned to k bits, and jump to S16.
[0029] As a possible implementation manner, the specified number of bits in S14 is determined according to the maximum length of the single-packet sequence. The single-packet sequence is the content of a single packet of data sent at one time.
[0030] As a possible implementation manner, in S18, any one of the encryption algorithms SM4, AES, and DES is used for data encryption.
[0031] In a second aspect, the present invention further provides an electronic device, including a memory and a processor. A program is stored on the memory and runs on the processor. When the processor runs the program, it executes the data security transmission method based on encoding and encryption described in the first aspect.
[0032] Beneficial effects
[0033] The present invention proposes a data security transmission method and an electronic device based on encoding and encryption. Compared with the prior art, the beneficial effects produced by the present invention include:
[0034] 1. The method solves the problem that the current existing software security encryption communication means are mainly implemented at the application layer and the MAC layer, and the subsequent data encryption communication is completed through upper-layer key configuration, which may pose risks of key exposure and cracking.
[0035] 2. The method can achieve encoding encryption and key solidification storage at the physical layer, improving the efficiency in the wireless communication process.
[0036] 3. The method can achieve dynamic change of the key number, making it impossible for eavesdroppers to demodulate the physical layer data, ensuring the concealment and security of the physical layer.
[0037] 4. The method solves the problem that the current physical layer generally uses an encoder to implement the data conversion function and an interleaved memory to implement the data interleaving algorithm, which not only completes the basic data transmission and anti-interference functions, but also realizes the guarantee of data encryption algorithms and key security. Description of the drawings
[0038] The drawings described herein are used to provide a further understanding of the present invention and form a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention. In the drawings:
[0039] Figure 1 is a flowchart of the data security transmission method based on encoding and encryption in the embodiment of the present invention.
[0040] Figure 2 is the approximate lower triangular matrix obtained by row and column transformation of the encoding check matrix H in the embodiment of the present invention. Detailed implementation manners
[0041] For the convenience of clearly describing the technical solutions of the embodiments of the present invention, in the embodiments of the present invention, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. For example, the first threshold and the second threshold are only used to distinguish different thresholds, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily limit being different.
[0042] It should be noted that in the present invention, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific manner.
[0043] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. The following at least one (item) or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b or c can represent: a, b, c, the combination of a and b, the combination of a and c, the combination of b and c, or the combination of a, b and c, where a, b and c can be single or multiple.
[0044] Currently, existing software security encryption communication means are mainly implemented at the application layer and the MAC layer, and the subsequent data encryption communication is completed through upper-layer key configuration, which may have the risks of key exposure and cracking; while the method proposed by the present invention can avoid the risks of key exposure and cracking at the link and application layers and achieve efficient encrypted communication.
[0045] Specifically in implementation, the wireless system relied on by the data security transmission method based on coding and encryption provided by the present invention includes multiple devices, and each device has pre-cured 1 to N 16-bit SM4 algorithm keys in the tie chip. It should be understood that the algorithm keys are not limited to SM4. The key serial number corresponding to the SM4 algorithm key is configured through the upper-layer register, and the specific key sequence stored is addressed and taken out for encoding use. The specific encoding can be LDPC code, that is, Low-density Parity-check Codes (abbreviated as LDPC).
[0046] Based on the data security transmission method of coding and encryption, the physical layer coding of the wireless device can be added with the SM4 encryption process based on the LDPC coding. Figure 1 , specifically including the following steps:
[0047] S10. The key is solidified inside the chip physical layer, and each key corresponds to the configuration key number f;
[0048] S11. Convert the coding check matrix into an approximate lower triangular matrix through row-column transformation.
[0049] As an example, the coding check matrix can be defined as H, which can be further expressed as:
[0050]
[0051] The coding check matrix H is transformed into an approximate lower triangular matrix after row-column transformation. Figure 2 ; Where T is a lower triangular matrix; according to the number of rows and columns of T, the remaining H matrix is divided into five matrices ABCDE with fixed numbers of rows and columns. That is, according to the number of rows and columns of the lower triangular matrix, the part of the coding check matrix that does not include the approximate lower triangular matrix is divided into N matrices with fixed numbers of rows and columns.
[0052] S12. Apply the Gaussian elimination method to eliminate the matrix in the coding check matrix that is aligned with the approximate lower triangular matrix in the column direction, and obtain the conjugate matrix of the coding check matrix.
[0053] In the specific implementation, you need to configure Matrix, where I is the identity matrix. Multiply the approximate lower triangular matrix on the left, Each column of the matrix is multiplied by the corresponding element of each row of the coding check matrix and then added to obtain the conjugate matrix of the coding check matrix. The conjugate matrix can be specifically expressed as:
[0054]
[0055] in,
[0056] S13. Right-multiply the codeword row sequence by the conjugate matrix transpose matrix, set it to 0 and solve it to obtain the check code row sequence.
[0057] The codeword row sequence is a vector composed of the information sequence and the coding row sequence, which can be specifically expressed as:
[0058] X=[ur 1 r 2 ]
[0059] The right multiplication of the conjugate matrix transpose matrix is 0 and can be expressed as:
[0060]
[0061] Substituting the information sequence u into the above formula can solve for r 1 and r 2 , at this time, the coded row sequence is obtained.
[0062] S14. Record the len sequence with a specified number of digits for the information sequence u. This number of digits can be determined according to the maximum length of the single-packet sequence. It should be further explained that in different wireless application environments, the data content transmitted each time is different. After the device receives a packet of data frames, it uses the receive interrupt loop counting method to record its data byte count as the len sequence, and the value of this bit can be determined. The above single-packet sequence is the content of a single packet sent at one time.
[0063] S15. Align the information sequence u in groups of k bits to obtain the k-bit aligned information sequence.
[0064] Taking the SM4 algorithm as an example, in specific implementation, align the information sequence u in groups of 16 (k = 16) bits. If the length len of the data u is not an integer multiple of 16, add 0 to make it up. If it is an integer multiple of 16, there is no need to align the information sequence in groups of 16 bits. Directly use the u sequence with length len as the 16-bit aligned information sequence, and jump to S16.
[0065] Of course, the encryption algorithm is not limited to SM4, and encryption algorithms such as AES and DES can also be used for data encryption.
[0066] The described method can achieve coding encryption and key solidification storage at the physical layer, improving the efficiency in the wireless communication process; in specific implementation, key solidification storage is achieved through S10, and coding encryption at the physical layer is achieved through S11 to S15.
[0067] S16. Locate the corresponding key in the register according to the key serial number configured by the link or network layer; encrypt the k-bit aligned information sequence with the key configured by S10 to obtain the encrypted sequence u wia . It should be further explained that the information sequence aligned by S15 is encrypted using the current key with the SM4 algorithm. The SM4 encryption algorithm function can be used to input the sequence array and the detailed key sequence, and output the encrypted information sequence. The encrypted results obtained by encrypting the same information with different keys are all different.
[0068] S17. Concatenate the len sequence with a specified number of digits, the encrypted sequence obtained in S16, and the check coding row sequence obtained in S13 to obtain the transmission coding row sequence; the transmission coding row sequence is specifically represented as X wia , X wia = [len u wia r1 r 2 .
[0069] S18. Transmit the transmitted coded line sequence through the channel.
[0070] S19. The receiving end receives the transmitted coded line sequence transmitted through the channel and then decodes and decrypts it to obtain the information sequence.
[0071] In a second aspect, an embodiment of the present invention further provides an electronic device, including a memory and a processor. A program running on the processor is stored on the memory. When the processor runs the program, it executes the data security transmission method based on coding and encryption in the first aspect.
[0072] The method can realize the dynamic change of the key number, making it impossible for eavesdroppers to demodulate the physical layer data, and ensuring the concealment and security of the physical layer. For example, the device MAC layer in a wireless system negotiates the key number through the MAC data frame to realize the dynamic change of the key number. After the field device uses the default secret key to complete the first communication with the access device, it can negotiate and change the key through the key change instruction. The access device records the corresponding device address and key number, and performs the data transmission function of decoding, decrypting, encoding, and encrypting through the device ID to change the secret key. The following fixed data frame format can be adopted:
[0073] Table 1 Fixed data frame format
[0074]
[0075] The secret key serial number of the encryption algorithm used by the device should be updated periodically. After the device in the wireless communication system receives the data frame, it first finds the key pair corresponding to the device ID according to the received length to decrypt the coded information sequence, and performs decoding verification after decryption: when the verification fails, a security warning is generated and the current information sequence is discarded; when the length of the information sequence does not correspond to the check bit sequence after decrypting with the used key, a security warning is generated; when the source address, destination address, and key serial number in the data frame verify whether the data frame is legal, a security warning is generated when there is an abnormality.
[0076] The method solves the problem that currently, the physical layer generally uses an encoder to implement the data conversion function and an interleaved memory to implement the data interleaving algorithm, which not only completes the basic data transmission and anti-interference functions, but also realizes data encryption and secret key security.
[0077] Those of ordinary skill in the art will understand that the foregoing is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art may still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A data security transmission method based on coding and encryption, characterized in that: The steps include: S10. Solidify the key inside the chip physical layer and configure the corresponding key serial number for each key; S11. The coding check matrix is transformed into an approximate lower triangular matrix by row-column transformation; S12. Applying Gaussian elimination method to eliminate the matrix aligned with the approximate lower triangular matrix in the column direction in the coding check matrix to obtain a conjugate matrix of the coding check matrix; S13. Set the transposed matrix of the conjugate matrix of the code word row sequence to 0 and solve it to obtain the check code row sequence; the code word row sequence is a vector composed of the information sequence and the code row sequence; S14. The length of the recorded information sequence is a len sequence of a specified number of bits, where the specified number of bits is determined based on the maximum length of a single packet sequence, where the single packet sequence is a packet of data content sent at a single time; S15. Align the information sequence by k-bit data groups to obtain a k-bit aligned information sequence; S16. According to the key sequence number configured at the link or network layer, the corresponding key is found in the register; the k-bit aligned information sequence is encrypted using the key found by the addressing to obtain an encrypted sequence; S17. Concatenate the len sequence of the specified number of bits, the encryption sequence obtained in S16, and the check code line sequence obtained in S13 to obtain a transmission code line sequence; S18. The code line sequence is transmitted via the channel; S19. The receiving end receives the transmitted coded line sequence transmitted via the channel and then decodes and decrypts it to obtain the information sequence.
2. A data security transmission method based on coding and encryption according to claim 1, characterized in that: The S11 converts the coding check matrix into an approximate lower triangular matrix through row-column transformation; The coding check matrix is denoted as Its dimension is m×n; the dimension of A is (mg)×(nm), the dimension of B is (mg)×g, T is a lower triangular matrix with dimension (mg)×(mg), the dimension of C is g×(nm), the dimension of D is g×g, and the dimension of E is g×(mg).
3. A data security transmission method based on coding and encryption according to claim 2, characterized in that: The S12 specifically includes: S120.Configuration Matrix Where I is the identity matrix; (mg)×(mg) is the dimension of the lower triangular matrix T in the approximate lower triangular matrix; m is the number of rows of the approximate lower triangular matrix; g is the difference between the number of rows of the approximate lower triangular matrix and the lower triangular matrix in it; S121. Multiply the matrix configured in S120 by the approximate lower triangular matrix to obtain a conjugate matrix of the coding check matrix.
4. A data security transmission method based on coding and encryption according to claim 3, characterized in that: The S121 is specifically: Each column of the matrix is multiplied by the corresponding element of each row of the coding check matrix and then added.
5. The method for secure data transmission based on coding and encryption according to claim 1, characterized in that: The codeword row sequence in S13 is a vector composed of an information sequence and a coding row sequence, denoted as X=[ur1r2], where u is the information sequence, and r1 and r2 are the check coding row sequences to be solved; the conjugate matrix is expressed as: The transpose matrix of the conjugate matrix is denoted by in, 6. The data security transmission method based on coding and encryption according to claim 5 is characterized in that: When S13 is specifically implemented, according to the characteristics of the transposed matrix of the conjugate matrix, the transposed matrix of the conjugate matrix is right-multiplied, that is, Substitute the information sequence u into , solve to obtain the check code row sequences r1 and r2.
7. A data security transmission method based on coding and encryption according to claim 1, characterized in that: The S15 is specifically as follows: if the specified number of bits of the len sequence is not an integer multiple of k, 0 is added to pad it to obtain a k-bit aligned information sequence; otherwise, if it is an integer multiple of k, there is no need to perform k-bit data group alignment on the information sequence, and the len sequence is directly used as the k-bit aligned information sequence, and the process jumps to S16.
8. The data security transmission method based on coding and encryption according to claim 1 is characterized in that: In S18, any one of SM4, AES and DES encryption algorithms is used to encrypt data.
9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a program to be run on the processor, and the processor executes the data security transmission method based on encoding and encryption as described in any one of claims 1 to 8 when running the program.
Citation Information
Patent Citations
Physical layer secure transmission method and system based on dynamic change of channel encoding matrix
CN104780022A
TWDM-PON system physical layer security method based on MD5 verification and AES encryption
CN111786773A