Data security communication method and system between digital power supply and microcontroller

By performing feature extraction, channel detection, abnormality detection and dynamic strategy adjustment in the data communication system between digital power supply and microcontroller, the data communication security problem between digital power supply and microcontroller is solved, and the system adaptability and efficiency are achieved.

CN119094184BActive Publication Date: 2025-05-16孙洪丽
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411169135.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-23
Publication Date
2025-05-16
Estimated Expiration
2044-08-23

AI Technical Summary

Technical Problem

The data communication security between digital power supplies and microcontrollers is difficult to cope with complex and changing communication environments and increasingly severe security threats. The existing methods lack systematic security guarantees and cannot adaptively adjust them. In addition, performance bottlenecks and scalability problems in large-scale and high-concurrency scenarios.

Method used

By acquiring communication data for feature extraction, generating adaptive chirped signals for channel detection, building a multi-dimensional security feature space for abnormal detection, dynamically adjusting encryption policies and routing mechanisms, and using graph neural network analysis to optimize routing policies and security configuration parameters.

Benefits of technology

It realizes dynamic perception of the communication channel status, evaluates security risks in real time, and flexibly adjusts encryption and routing policies, improves the accuracy and timeliness of security threat identification of communication systems, optimizes system performance, and has good scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094184B_ABST
    Figure CN119094184B_ABST
Patent Text Reader

Abstract

The present invention relates to a data security communication method and system between a digital power supply and a microcontroller. The method: obtains the communication data between the digital power supply and the microcontroller and performs feature extraction to obtain a communication feature vector and channel state information; performs communication channel detection to obtain real-time channel characteristic parameters; performs anomaly detection to obtain security risk assessment results; performs encryption to obtain an encrypted communication data stream and generates an authentication token; constructs a dynamic graph structure model to perform graph neural network analysis to obtain an optimized routing strategy and security configuration parameters; performs transmission monitoring to obtain monitoring results and generate a target security communication strategy. The implementation of the present invention can dynamically perceive the communication channel state, evaluate security risks in real time, flexibly adjust encryption strategies and routing mechanisms, and has good scalability and performance optimization capabilities, thereby providing a strong guarantee for the safe and stable operation of the digital power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security communication, and in particular to a method and system for data security communication between a digital power supply and a microcontroller. Background Art

[0002] The data communication security issue between digital power supply and microcontroller is becoming increasingly prominent. Traditional communication methods often use static encryption algorithms and fixed communication strategies, which are difficult to cope with complex and changing communication environments and increasingly severe security threats. Especially in key areas such as industrial control and smart grids, the communication security between digital power supply and microcontroller is directly related to the stability and reliability of the system. Once a security vulnerability occurs, it may lead to serious economic losses or even safety accidents.

[0003] Most existing communication security methods focus on single-dimensional security protection, such as data encryption or identity authentication only, and lack systematic security protection for the entire communication process. At the same time, these methods often ignore the dynamic characteristics of the communication channel and the impact of environmental factors, and cannot be adaptively adjusted according to the real-time channel status and security risks, resulting in difficulty in maintaining security performance in the optimal state. In addition, traditional methods often face performance bottlenecks and scalability issues when dealing with large-scale, high-concurrency communication scenarios, and are unable to meet the needs of new digital power systems for efficient and secure communications. Summary of the invention

[0004] The main purpose of the present invention is to provide a data security communication method and system between a digital power supply and a microcontroller, so as to realize dynamic perception of the communication channel status, real-time assessment of security risks, flexible adjustment of encryption strategies and routing mechanisms, and good scalability and performance optimization capabilities, thereby providing strong guarantees for the safe and stable operation of the digital power supply system.

[0005] To achieve the above object, the present invention provides a method for secure data communication between a digital power supply and a microcontroller, comprising the following steps:

[0006] Acquire the communication data between the digital power supply and the microcontroller and perform feature extraction to obtain the communication feature vector and channel state information;

[0007] Based on the communication feature vector and the channel state information, an adaptive chirp signal is generated and communication channel detection is performed to obtain real-time channel characteristic parameters;

[0008] According to the real-time channel characteristic parameters and the preset initial security communication strategy, a multi-dimensional security feature space is constructed and anomaly detection is performed to obtain a security risk assessment result;

[0009] Based on the security risk assessment result, encrypt the communication data to obtain an encrypted communication data stream and generate an authentication token;

[0010] Based on the encrypted communication data stream and the authentication token, a dynamic graph structure model is constructed and a graph neural network analysis is performed to obtain an optimized routing strategy and security configuration parameters;

[0011] According to the optimized routing strategy and the security configuration parameters, the encrypted communication data stream is monitored for transmission, a monitoring result is obtained and a target secure communication strategy is generated.

[0012] The present invention also provides a data security communication system between a digital power supply and a microcontroller, comprising:

[0013] An acquisition module is used to acquire communication data between the digital power supply and the microcontroller and perform feature extraction to obtain communication feature vectors and channel state information;

[0014] A detection module, used to generate an adaptive chirp signal and perform communication channel detection based on the communication feature vector and the channel state information to obtain real-time channel characteristic parameters;

[0015] A detection module, used to construct a multi-dimensional security feature space and perform anomaly detection according to the real-time channel characteristic parameters and the preset initial security communication strategy to obtain a security risk assessment result;

[0016] An encryption module, used to encrypt the communication data based on the security risk assessment result, obtain an encrypted communication data stream and generate an authentication token;

[0017] An analysis module, used to construct a dynamic graph structure model and perform graph neural network analysis based on the encrypted communication data stream and the authentication token to obtain optimized routing strategies and security configuration parameters;

[0018] A generation module is used to monitor the transmission of the encrypted communication data stream according to the optimized routing strategy and the security configuration parameters, obtain monitoring results and generate a target secure communication strategy.

[0019] The present invention also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of any one of the above methods when executing the computer program.

[0020] The present invention also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned methods are implemented.

[0021] In summary, the technical solution provided by the present invention can obtain channel characteristic parameters in real time by generating adaptive chirp signals for communication channel detection, provide accurate channel state information for subsequent security policy formulation, and improve the adaptability of the communication system to environmental changes. Constructing a multi-dimensional security feature space and performing anomaly detection can comprehensively evaluate the security risks of the communication system and improve the accuracy and timeliness of security threat identification. Dynamically selecting the optimal encryption algorithm and adjusting the key length based on the security risk assessment results achieves a precise match between encryption strength and security requirements, and optimizes system performance while ensuring security. Using graph neural networks to construct a dynamic graph structure model can effectively capture the spatiotemporal characteristics of complex communication networks and provide data-driven decision support for routing strategy optimization and security configuration. Importance grading and differential encryption of multiple parallel transmission data streams are performed, and traffic scheduling is performed in combination with load balancing, realizing efficient utilization of communication resources and refined management of security. By real-time monitoring of communication quality and security status, the communication strategy is dynamically adjusted to ensure that the system always maintains the optimal security communication performance under different working conditions. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 It is a schematic diagram of the steps of a method for secure data communication between a digital power supply and a microcontroller in one embodiment of the present invention;

[0023] Figure 2 is a structural block diagram of a data security communication system between a digital power supply and a microcontroller in one embodiment of the present invention;

[0024] Figure 3 It is a schematic block diagram of the structure of a computer device according to an embodiment of the present invention.

[0025] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0026] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0027] Reference Figure 1 , this embodiment provides a data security communication method between a digital power supply and a microcontroller, comprising the following steps:

[0028] S1, acquiring the communication data between the digital power supply and the microcontroller and performing feature extraction to obtain the communication feature vector and channel state information;

[0029] Specifically, a serial port analyzer is connected to the communication line between the digital power supply and the microcontroller. By configuring the communication parameters, the serial port analyzer can accurately capture the bidirectional communication data stream and obtain the complete communication data. These data usually contain a lot of noise interference. In order to ensure the accuracy of subsequent analysis, the communication data is de-noised to obtain filtered communication data. The filtered communication data is normalized to convert the data into a unified standard so that data of different dimensions or units can be compared and analyzed on the same scale to obtain normalized communication data. Outlier detection is performed on the normalized communication data, and outliers in the data are identified through a series of algorithms to generate outlier marking results. Based on the outlier marking results, the normalized communication data is analyzed by least squares method. The algorithm obtains preliminary channel characteristic parameters by analyzing the linear relationship in the data. According to the preliminary channel characteristic parameters, a weighted least squares optimization objective function is constructed to optimize the channel characteristics. The design of the objective function includes multiple key indicators, including communication delay, throughput, energy consumption, and security level, and each indicator is assigned a corresponding weight. These weights reflect the importance of each indicator in a specific application scenario. By solving the objective function, the optimized security communication protocol parameters are obtained. Based on the optimized security communication protocol parameters, the normalized communication data is feature extracted to obtain the final communication feature vector and channel state information.

[0030] S2, based on the communication feature vector and channel state information, generates an adaptive chirp signal and performs communication channel detection to obtain real-time channel characteristic parameters;

[0031] Specifically, a basic chirp signal is constructed based on the communication feature vector and channel state information to provide a basic waveform structure for subsequent communication channel detection. In order to ensure the stability and reliability of the signal during the communication process, the basic chirp signal is monitored in real time to obtain the signal-to-noise ratio monitoring result. The real-time monitoring of the signal-to-noise ratio directly affects the transmission quality of the signal, and thus determines the accuracy of the communication. Based on the signal-to-noise ratio monitoring result, the signal amplitude of the basic chirp signal is dynamically adjusted to obtain the chirp signal after amplitude adjustment, thereby optimizing the transmission effect of the signal in a noisy environment, so that the signal can still maintain sufficient strength and clarity in a strong noise environment. The chirp signal after amplitude adjustment is subjected to spectrum analysis to reveal the frequency components of the signal. Based on the spectrum analysis results, the starting frequency and frequency change rate of the chirp signal after amplitude adjustment are optimized to obtain the chirp signal after frequency optimization. The purpose of the optimization is to adjust the frequency characteristics of the signal so that it can better adapt to the current channel state and enhance the anti-interference ability of the signal. The signal parameters of the frequency-optimized chirp signal are fine-tuned in real time to obtain an adaptive chirp signal, which enables the signal to adapt more flexibly to the real-time changing channel environment. The communication channel is periodically detected based on the adaptive chirp signal to obtain the original detection data, which contains the real-time state information of the channel. The original detection data is analyzed in time and frequency to obtain the real-time channel characteristic parameters of the communication channel, including channel delay spread, Doppler spread and coherence bandwidth, which together describe the dynamic change characteristics of the channel.

[0032] S3, based on the real-time channel characteristic parameters and the preset initial security communication strategy, construct a multi-dimensional security feature space and perform anomaly detection to obtain a security risk assessment result;

[0033] Specifically, based on the real-time channel characteristic parameters and the preset initial security communication strategy, multi-dimensional security features are extracted to reflect multiple dimensions of the current communication state, and a security feature vector describing the current communication state is obtained. The feature vector integrates the key elements of the channel characteristics and the security strategy in the multi-dimensional space to form a complete description of the current communication state. The security feature vector is subjected to feature dimensionality reduction processing to obtain a feature representation after dimensionality reduction. The feature representation after dimensionality reduction is input into a pre-trained Gaussian mixture model for processing. Through the model, the probability density of the current communication state is calculated to obtain a preliminary abnormality evaluation value. The calculation of the probability density helps to identify whether the current communication state deviates from the normal range and provides a preliminary quantitative basis for abnormality detection. The Mahalanobis distance is calculated based on the preliminary evaluation value of the abnormality degree to obtain a more accurate abnormality detection index. The Mahalanobis distance is a distance measurement method that considers the covariance of multi-dimensional data and can more effectively evaluate the difference between the current communication state and the normal state. By comparing the abnormality detection index with the preset threshold, a preliminary abnormality detection result is obtained. This result can indicate whether there is an abnormality in the current communication state and the severity of the abnormality. The initial anomaly detection results are classified to obtain a clearer initial anomaly detection result. The anomaly classification process can distinguish different types of anomalies, such as anomalies caused by channel interference or anomalies caused by equipment failure. The initial anomaly detection results are quantitatively evaluated for the degree of anomaly to obtain an anomaly degree score that reflects the risk level of the current communication status. Based on the anomaly degree score and the preset risk level classification standard, the current communication status is classified into risk levels to obtain the final security risk assessment result.

[0034] S4, based on the security risk assessment result, encrypt the communication data, obtain the encrypted communication data stream and generate an authentication token;

[0035] Specifically, a candidate encryption algorithm list is matched according to the security risk assessment result. The list contains a variety of encryption algorithms that are suitable for current security requirements, and these algorithms can cope with different levels of security threats. In order to ensure that the selected encryption algorithm can provide sufficient security and maintain high efficiency in the current communication environment, each encryption algorithm in the candidate encryption algorithm list is evaluated for performance, and a performance score of each algorithm is obtained. These scores are based on multiple indicators, such as encryption speed, resource consumption, and anti-attack capability. Based on the algorithm performance score and the current communication environment parameters, the optimal encryption algorithm is selected to obtain the target encryption algorithm. The selection of the optimal encryption algorithm should not only consider its security, but also ensure its operating efficiency in the current communication environment to ensure the performance of the overall system. In order to optimize security and performance, the key length of the target encryption algorithm is dynamically adjusted to obtain optimized encryption parameters. The adjustment of the key length is a balancing process. A key that is too long may increase the computational complexity, while a key that is too short may reduce security. It is precisely adjusted according to actual needs. The communication data is encrypted based on the optimized encryption parameters to obtain a preliminary encrypted data stream. In order to enhance the security and integrity of the data, the preliminary encrypted data stream is processed in blocks, and a unique identifier is generated for each data block to obtain a block encrypted data stream. Based on the block encrypted data stream, a data integrity verification tree is constructed. The verification tree can provide integrity verification for the block data, allowing the receiver to detect any tampering or data corruption. In order to ensure the security of the verification tree itself, the root node of the verification tree is signed using the elliptic curve digital signature algorithm to ensure the non-repudiation and integrity of the data, and obtain the final encrypted communication data stream and the corresponding authentication token.

[0036] S5, based on the encrypted communication data stream and authentication token, builds a dynamic graph structure model and performs graph neural network analysis to obtain optimized routing strategies and security configuration parameters;

[0037] Specifically, a time-varying graph structure is constructed based on encrypted communication data streams and authentication tokens to reflect the dynamic changes of the communication network at different time points. Nodes represent communication entities, while edges represent communication links between these entities. The attributes of nodes and edges are continuously updated over time to form a dynamic communication topology graph. The dynamic communication topology graph not only shows the current network structure, but also captures the time-varying characteristics in the communication process. The temporal graph convolutional network is used to extract spatiotemporal features of the dynamic communication topology graph, identify and extract the temporal features of each node and its connection in the network, and obtain the graph temporal feature sequence to describe the behavior patterns of nodes and edges in the network over time. After the graph temporal feature sequence is input into the graph attention layer, the dynamic correlation strength between nodes is calculated to obtain an adaptive adjacency matrix. The adaptive adjacency matrix can capture the correlation changes between nodes and dynamically adjust the network structure to make it more in line with the actual communication state. The adaptive adjacency matrix is ​​input into the graph diffusion convolutional network for multi-scale feature extraction. Through analysis at different scales, a multi-level graph representation is obtained. The multi-level graph representation is subjected to graph pooling operations to achieve node clustering and dimensionality reduction, and a compressed graph structure is obtained. Based on the compressed graph structure, a graph generative adversarial network is constructed to learn the implicit distribution of communication patterns. The graph generative adversarial network can simulate complex communication patterns in the network and generate new pattern samples. Through adversarial learning, the network gradually grasps the deep characteristics of the communication pattern and obtains the communication pattern generator. The generator is used to generate candidate routing strategies and analyze them. The candidate routing strategies are analyzed through the communication pattern generator to obtain a routing strategy set. In this set, each strategy has passed the simulation and test of the communication pattern to ensure its feasibility and effectiveness. The routing strategy set is evaluated and optimized to obtain the optimized routing strategy and security configuration parameters.

[0038] The self-attention calculation in the time dimension is performed on the graph temporal feature sequence. The self-attention mechanism can capture the correlation of different time points in the sequence without relying on a fixed order, and generate a temporal attention weight matrix. This matrix assigns importance weights to each time point in the sequence, so that in the subsequent processing process, the time nodes that contribute more to the network characteristics can be focused on. Based on the temporal attention weight matrix, the graph temporal feature sequence is weighted aggregated to obtain the temporal aggregated features. The graph attention calculation in the spatial dimension is performed on the temporal aggregated features to obtain the initial correlation strength matrix between nodes. This matrix reflects the mutual influence between nodes in the network at the current moment and reveals the spatial relationship of the network structure. A multi-head attention mechanism is constructed based on the initial correlation strength matrix. Through the multi-head attention mechanism, the correlation strength between nodes is modeled from multiple perspectives to obtain a multi-perspective correlation strength representation. The multi-perspective correlation strength representation is nonlinearly transformed and normalized to generate an adaptive adjacency matrix. This matrix not only dynamically adjusts the connection relationship between nodes, but also can adaptively reflect the optimal structure under the current network state. The adaptive adjacency matrix is ​​input into the graph convolution layer approximated by Chebyshev polynomials to obtain local feature representation. Chebyshev polynomial approximation is an efficient graph convolution method that can approximate the convolution operation in a polynomial manner, thereby extracting local features of the graph while maintaining computational efficiency. Skip connections and residual learning are performed on the local feature representation. Skip connections allow features to be directly transmitted across multiple convolutional layers, and residual learning helps to retain the original input information and avoid the gradual loss of information in deep networks. In this way, multi-scale feature fusion results are obtained. The multi-scale feature fusion results are input into the graph diffusion convolution layer for global information propagation to obtain global feature representation. The graph diffusion convolution layer diffuses information throughout the graph structure so that the final feature representation can reflect global network information. Long-term dependencies are captured for the global feature representation in order to identify long-term dependencies in the network and obtain temporal dependency features. Hierarchical feature aggregation is performed on the temporal dependency features to obtain a multi-level graph representation.

[0039] S6, based on the optimized routing strategy and security configuration parameters, the encrypted communication data flow is monitored for transmission, the monitoring result is obtained and a target security communication strategy is generated.

[0040] Specifically, based on the optimized routing strategy, the encrypted communication data stream is segmented and routed to obtain multiple parallel transmission data streams, ensuring that the communication data can be transmitted simultaneously through multiple paths. The encryption strength of the multiple parallel transmission data streams is dynamically adjusted based on the security configuration parameters to obtain differentiated encrypted data streams. Different encryption strategies are applied on different transmission paths to adapt to the current security requirements and network environment to ensure the flexibility and effectiveness of encryption. Traffic scheduling is performed on the differentiated encrypted data streams to obtain the optimized transmission path. Through the intelligent scheduling mechanism, network resources are reasonably allocated to reduce network congestion and improve transmission efficiency. In order to ensure the high quality of data during transmission, the data packets on the optimized transmission path are monitored in real time for throughput and delay to obtain key network performance indicators, including network throughput, delay, etc., which directly reflect the current network transmission status and efficiency. Based on the network performance indicators, the communication quality score is calculated to generate the communication status evaluation result. According to the communication status evaluation result, the communication strategy is adjusted to obtain a preliminary adjustment plan. The preliminary adjustment plan is automatically generated according to the current network status and can improve the network performance to a certain extent. The preliminary adjustment plan is matched with the preset strategy library to obtain a candidate communication strategy set. The policy library stores a variety of pre-set communication policies, which have been tested and verified to adapt to different network environments and security requirements. The candidate communication policy set is simulated and security evaluated to verify the effectiveness and security of each candidate policy in actual applications. Potential problems are discovered through simulation tests and appropriate adjustments are made according to the actual network conditions. The policy with the best overall performance is selected from the candidate policy set to obtain the target secure communication policy.

[0041] The data importance of multiple parallel transmission data streams is graded to determine the priority and security requirements of each data stream, and the graded data stream is obtained. Based on the security configuration parameters and the importance level of the graded data stream, appropriate encryption algorithms and key lengths are assigned to form an encryption configuration scheme. According to the encryption configuration scheme, the graded data streams are differentially encrypted to generate preliminary differentiated encrypted data streams. Different importance levels correspond to different encryption strengths, thereby reducing unnecessary computing overhead while ensuring data security. The preliminary differentiated encrypted data streams are segmented and reassembled to generate encrypted data packets of variable length. The length of the data packet is dynamically adjusted, which not only helps to optimize the bandwidth utilization during the transmission process, but also improves the security and concealment of the data. Based on the encrypted data packets of variable length, virtual private network tunnels are constructed to form multi-layer encrypted channels. These tunnels provide an additional layer of protection for data during transmission to prevent data from being stolen or tampered with. Load balancing calculations are performed on the multi-layer encrypted channels to generate a preliminary traffic distribution plan. The data streams are reasonably distributed among the various transmission channels to prevent a certain channel from being overloaded, thereby improving the transmission efficiency and stability of the overall network. Based on the preliminary traffic distribution plan and the current network topology information, the shortest path first algorithm is used to calculate the optimal transmission path and generate a routing table. The shortest path first algorithm can quickly find the most effective transmission path under the current network conditions to ensure that the data can reach the destination at the fastest speed. After the routing table is generated, the data packets in the multi-layer encrypted channel are forwarded and scheduled according to its instructions. The scheduling process combines the results of load balancing and the calculation results of the optimal path to ensure that the data packet always chooses the best path during the transmission process and optimizes the transmission path.

[0042] In one example, communication data between a digital power supply and a microcontroller is acquired and feature extraction is performed to obtain a communication feature vector and channel state information, including:

[0043] Connect a serial port analyzer to the communication line between the digital power supply and the microcontroller, configure communication parameters, capture the bidirectional communication data stream, and obtain communication data;

[0044] performing noise removal on the communication data to obtain filtered communication data, and performing normalization processing on the filtered communication data to obtain normalized communication data;

[0045] Perform outlier detection on the normalized communication data to obtain an outlier marking result, and perform least squares analysis on the normalized communication data based on the outlier marking result to obtain preliminary channel characteristic parameters;

[0046] According to the preliminary channel characteristic parameters, a weighted least squares optimization objective function is constructed, and the objective function is solved to obtain the optimized security communication protocol parameters; wherein the objective function includes a communication delay index, a throughput index, an energy consumption index, and a security level index, and each index is assigned a corresponding weight;

[0047] Based on the optimized secure communication protocol parameters, feature extraction is performed on the normalized communication data to obtain communication feature vectors and channel state information.

[0048] In this example, a serial port analyzer is connected to the communication line between the digital power supply and the microcontroller. A serial port analyzer is a tool used to monitor and analyze serial communications. It can capture bidirectional communication data streams without interfering with the communication process. By configuring communication parameters such as baud rate, data bits, stop bits, and parity bits, ensure that the serial port analyzer can correctly decode and record the transmitted data. After the configuration is completed, the serial port analyzer begins to capture the communication data stream between the digital power supply and the microcontroller. These data streams include instructions sent from the digital power supply to the microcontroller and responses returned from the microcontroller. The communication data is processed to remove noise. The noise removal process usually uses filtering technology. The filter can effectively suppress or eliminate high-frequency noise components in the signal to obtain cleaner and more accurate filtered communication data. The filtered communication data is normalized to unify the scale of the data so that data from different sources or types can be analyzed on the same scale to obtain normalized communication data. Outlier detection is performed on the normalized communication data to identify those data points that are significantly different from the majority of data points. These abnormal data may be caused by noise, equipment failure, or other abnormal operations. Commonly used outlier detection methods include the statistical Z-Score detection method and the density-based local outlier factor (LOF) algorithm. The presence of outliers will have an adverse effect on the accuracy of data analysis. These outliers are marked, and the normalized communication data is analyzed based on the outlier marking results. The marked normalized communication data is analyzed using the least squares method to obtain preliminary channel characteristic parameters. The least squares method is an optimization technique used to fit the best linear model between multiple variables. Its goal is to minimize the sum of the squares of the distances between the data points and the fitted straight line. The set objective function can be expressed as:

[0049]

[0050] Among them, y i is the ith observation, x iis the corresponding eigenvector, w is the weight vector to be optimized, and n is the number of data points. By minimizing the objective function, the preliminary characteristic parameters of the channel are obtained, including the gain and attenuation coefficient of the channel. The objective function of weighted least squares optimization is constructed based on the preliminary channel characteristic parameters. The objective function not only takes into account the physical characteristics of the channel, but also integrates indicators such as communication delay, throughput, energy consumption, and security level. Each indicator is assigned a different weight in the objective function, and the optimization goal can be expressed as:

[0051]

[0052] Among them, d i represents the target value of each indicator, f(x i ,w) represents the weighted communication performance, α i is the weight of each indicator. By solving the objective function, the optimized security communication protocol parameters are obtained. The optimization process takes into account the various requirements of communication, so that the final protocol can not only meet the security requirements, but also maintain a good balance in terms of latency, throughput and energy consumption. Based on the optimized security communication protocol parameters, the normalized communication data is feature extracted to obtain the communication feature vector and channel state information. The key features that best reflect the communication behavior and channel state are extracted from the original data, such as the average power, variance, peak value, etc. of the signal. The feature vector is used for subsequent applications such as channel prediction, data encryption or communication strategy adjustment.

[0053] In one example, based on the communication feature vector and the channel state information, an adaptive chirp signal is generated and communication channel detection is performed to obtain real-time channel characteristic parameters, including:

[0054] A basic chirp signal is constructed based on the communication feature vector and the channel state information, and a real-time signal-to-noise ratio monitoring is performed on the basic chirp signal to obtain a signal-to-noise ratio monitoring result;

[0055] Dynamically adjusting the signal amplitude of the basic chirp signal according to the signal-to-noise ratio monitoring result to obtain a chirp signal with adjusted amplitude;

[0056] Performing spectrum analysis on the amplitude-adjusted chirp signal to obtain a spectrum analysis result, and optimizing the starting frequency and the frequency change rate of the amplitude-adjusted chirp signal based on the spectrum analysis result to obtain a frequency-optimized chirp signal;

[0057] The signal parameters of the frequency-optimized chirp signal are fine-tuned in real time to obtain an adaptive chirp signal, and the communication channel is periodically detected based on the adaptive chirp signal to obtain original detection data;

[0058] The original detection data is subjected to time-frequency analysis to obtain real-time channel characteristic parameters; wherein the real-time channel characteristic parameters include channel delay spread, Doppler spread and coherence bandwidth.

[0059] In this example, a basic chirp signal is constructed based on the communication eigenvector and channel state information. Chirp signal is a signal form whose frequency changes linearly or nonlinearly with time. It is used in radar and communication systems to improve the resolution and anti-interference ability of channel detection. The construction of the basic chirp signal needs to comprehensively consider the communication eigenvector and channel state information to ensure the effectiveness of the signal in the current environment. For example, if the channel state information indicates that there is a large multipath effect, a chirp signal with a faster frequency change can be designed to improve the multipath resolution capability. The basic chirp signal is monitored in real time for signal-to-noise ratio (SNR). SNR is an important indicator for measuring signal quality. It is defined as the ratio of signal power to noise power and is usually expressed as:

[0060]

[0061] Among them, P s Represents the signal power, P n Represents the noise power. By monitoring the SNR of the basic chirp signal, the noise level and signal quality in the current channel are obtained. During the monitoring process, if the SNR is found to be too low, it indicates that the distinguishability of the signal in the noise is reduced, and the amplitude of the signal needs to be dynamically adjusted to increase the strength of the signal so that it is easier to detect and decode in the noise. According to the signal-to-noise ratio monitoring result, the signal amplitude of the basic chirp signal is dynamically adjusted to obtain the chirp signal after amplitude adjustment. The amplitude adjustment can be achieved by increasing the transmission power of the signal or adjusting the modulation method of the signal. For example, if it is monitored that the noise in the channel is strong, the amplitude of the signal can be appropriately increased to return its SNR to a suitable level, thereby ensuring the reliability of communication. After the amplitude adjustment is completed, the chirp signal after amplitude adjustment is subjected to spectrum analysis to obtain the distribution of the signal in the frequency domain. The purpose of spectrum analysis is to check whether the frequency components of the signal are as expected and to identify possible frequency interference. Spectrum analysis can be achieved through Fourier transform, which converts the time domain signal into a frequency domain representation. The formula is as follows:

[0062]

[0063] Among them, X(f) represents the spectral component of the signal at frequency f, x(t) is the time domain signal, and t is the time variable. The spectrum distribution of the signal is obtained by Fourier transforming the amplitude-adjusted chirp signal. Based on the spectrum analysis results, if it is found that the frequency distribution of the signal is not ideal, it may be necessary to optimize the starting frequency and frequency change rate of the signal. The chirp signal after frequency optimization is fine-tuned in real time to obtain an adaptive chirp signal. Real-time fine-tuning is to make subtle adjustments to multiple parameters of the signal (such as frequency change rate, phase, bandwidth, etc.) according to the current channel state to ensure that the signal can perform optimally in a complex communication environment. For example, in a high-mobility scenario, the frequency characteristics of the channel may change rapidly due to the Doppler effect. At this time, the frequency change rate of the chirp signal can be dynamically adjusted to offset the influence of the Doppler frequency shift. The communication channel is periodically detected based on the adaptive chirp signal to obtain the original detection data. Periodic detection sends an adaptive chirp signal at different time points and records the response of the signal at the receiving end. The response data provides detailed information about the channel, including characteristics such as signal attenuation and delay. Time-frequency analysis is performed on the original detection data to extract the real-time characteristic parameters of the channel. Through short-time Fourier transform or wavelet transform, signal analysis in both time and frequency dimensions is considered at the same time, which is suitable for processing non-stationary signals, that is, situations where the statistical characteristics of the signal change over time. Through time-frequency analysis, the real-time characteristic parameters of the channel are obtained, including channel delay spread, Doppler spread, and coherence bandwidth. Channel delay spread describes the difference in propagation delay of the signal on different paths and is an important indicator for evaluating the multipath effect of the channel. Doppler spread reflects the frequency expansion caused by relative motion, which will cause the signal to shift at the receiving end, and the coherence bandwidth describes the maximum distortion-free bandwidth that the channel can transmit.

[0064] In one example, based on the real-time channel characteristic parameters and the preset initial secure communication strategy, a multi-dimensional security feature space is constructed and anomaly detection is performed to obtain security risk assessment results, including:

[0065] Based on the real-time channel characteristic parameters and the preset initial security communication strategy, multi-dimensional security features are extracted to obtain the security feature vector of the current communication state;

[0066] Perform feature dimensionality reduction processing on the security feature vector to obtain the feature representation after dimensionality reduction, and input the feature representation after dimensionality reduction into the pre-trained Gaussian mixture model to calculate the probability density of the current communication state and obtain a preliminary evaluation value of the abnormality degree;

[0067] The Mahalanobis distance is calculated based on the preliminary evaluation value of the abnormality degree to obtain an abnormality detection index, and the abnormality detection index is compared with a preset threshold to obtain a preliminary abnormality detection result;

[0068] Perform abnormal classification on the preliminary abnormal detection results to obtain initial abnormal detection results, and perform quantitative evaluation on the abnormal degree of the initial abnormal detection results to obtain an abnormal degree score;

[0069] According to the abnormality degree score and the preset risk level classification standard, the current communication status is classified into risk levels to obtain the security risk assessment results.

[0070] In this example, multi-dimensional security features are extracted from the communication data based on the real-time channel characteristic parameters and the preset security communication strategy. The real-time channel characteristic parameters usually include channel delay spread, Doppler spread, coherent bandwidth, etc., while the preset security communication strategy may involve encryption strength, authentication frequency, data integrity check, etc. These features are combined to form a multi-dimensional security feature space, and each feature dimension reflects an important aspect of the communication state. By combining the features together, a security feature vector of the current communication state is obtained. The security feature vector is subjected to feature dimensionality reduction processing to reduce the dimension of the feature vector while retaining the key information of the original data as much as possible to obtain the feature representation after dimensionality reduction. Commonly used dimensionality reduction techniques include principal component analysis and linear discriminant analysis. The feature representation after dimensionality reduction is input into a pre-trained Gaussian mixture model to calculate the probability density of the current communication state. The Gaussian mixture model is a probabilistic model commonly used for clustering and density estimation. It assumes that the data consists of multiple Gaussian distributions, each of which corresponds to a potential category of the data. Through the Gaussian mixture model, the probability density of the reduced-dimensional features under the Gaussian mixture distribution is calculated, reflecting the degree of deviation of the current communication state from the normal state, that is, the preliminary evaluation value of the abnormality. The lower the initial evaluation value of the abnormality, the closer the communication status is to normal; otherwise, there may be an abnormality. The Mahalanobis distance is calculated based on the initial evaluation value of the abnormality to obtain the abnormality detection index. The Mahalanobis distance is an effective multidimensional distance measurement method, which is suitable for judging whether the data point deviates from the mean of the multidimensional normal distribution. The calculation formula is:

[0071] D 2 =(x-μ) T Σ -1 (x-μ);

[0072] Among them, D 2represents the Mahalanobis distance, x is the eigenvector after dimensionality reduction, μ is the mean vector of the eigenvector, and Σ is the covariance matrix of the eigenvector. The Mahalanobis distance takes into account the correlation between the features, so that the degree of anomaly can be measured more accurately in multidimensional space. The anomaly detection index is compared with the preset threshold to obtain a preliminary anomaly detection result. If the Mahalanobis distance exceeds the threshold, it means that there is a large abnormal risk in the current communication state and further analysis is required. Based on the preliminary anomaly detection results, anomaly classification is performed to determine the type and cause of the anomaly. Anomaly classification can be performed based on supervised learning methods, such as using classification algorithms such as support vector machines (SVM) or random forests (RF) to classify the preliminary detection results into different anomaly types, such as channel attacks, data tampering, or communication interruption. The initial anomaly detection results are quantitatively evaluated for the degree of anomaly to generate an anomaly degree score. The anomaly degree score reflects the risk level of the current communication state and is the result of comprehensive consideration of multiple factors such as anomaly type, Mahalanobis distance, and probability density. According to the anomaly degree score and the preset risk level classification standard, the current communication state is divided into risk levels to obtain a security risk assessment result. The risk level classification standard is usually determined by empirical rules or data-driven models, and can be divided into low, medium, and high levels, and each level corresponds to different security measures. For example, at a low risk level, the system can continue to maintain the existing communication strategy; at a high risk level, the system may need to immediately initiate an emergency plan, such as increasing encryption strength, limiting communication bandwidth, or increasing the frequency of identity authentication.

[0073] In one example, based on the security risk assessment result, encrypting the communication data, obtaining the encrypted communication data stream and generating the authentication token include:

[0074] Match the candidate encryption algorithm list according to the security risk assessment results, and perform performance evaluation on each encryption algorithm in the candidate encryption algorithm list to obtain an algorithm performance score;

[0075] Select the optimal encryption algorithm based on the algorithm performance score and the current communication environment parameters to obtain the target encryption algorithm, and dynamically adjust the key length of the target encryption algorithm to obtain the optimized encryption parameters;

[0076] Encrypting the communication data based on the optimized encryption parameters to obtain a preliminary encrypted data stream, and dividing the preliminary encrypted data stream into blocks, generating a unique identifier for each data block, and obtaining a block encrypted data stream;

[0077] A data integrity verification tree is constructed based on the block encrypted data stream, and the root node of the data integrity verification tree is signed using the elliptic curve digital signature algorithm to obtain the encrypted communication data stream and the corresponding authentication token.

[0078] In this example, a list of candidate encryption algorithms is matched according to the security risk assessment results. The security risk assessment results usually include information such as the current threat level, channel characteristics, and the availability of computing resources. Based on this information, a set of candidate encryption algorithms is screened out, which may include symmetric encryption algorithms such as AES (Advanced Encryption Standard), DES (Data Encryption Standard), and asymmetric encryption algorithms such as RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography). The performance of each encryption algorithm in the candidate encryption algorithm list is evaluated to obtain the performance score of the algorithm. Performance evaluation involves many considerations, including encryption and decryption speed, computational complexity, energy consumption, and security. For example, although AES performs well in most cases, it may not be suitable for use on resource-constrained devices due to its high computing requirements; while ECC is more suitable for use in low-bandwidth and low-energy environments because it has a shorter key length while providing the same security level. During the evaluation process, the performance of each algorithm is scored using the following formula:

[0079] Score=α·Speed+β·Security-γ·Energy;

[0080] Among them, α, β, and γ are weight coefficients representing speed, security, and energy consumption respectively; Speed ​​is the speed of encryption and decryption; Security is the security level provided by the algorithm (such as the ability to resist known attacks); Energy is the energy consumption of the algorithm. These weight coefficients can be adjusted according to the needs of actual applications to ensure that the optimal encryption algorithm is selected in a specific environment. Based on the performance score, combined with the current communication environment parameters, the optimal encryption algorithm is selected to obtain the target encryption algorithm. For example, if the current communication environment has high requirements for energy consumption, then the ECC algorithm with low energy consumption but sufficient security may be selected; if security is the primary consideration, a higher-strength algorithm such as AES-256 may be selected as the target encryption algorithm. Dynamic adjustment is made according to the key length of the target encryption algorithm. The key length directly affects the strength and computational overhead of encryption. Generally, the longer the key, the higher the encryption strength, but at the same time the computational complexity will also increase. For example, AES can use 128-bit, 192-bit, or 256-bit keys. The longer the key, the higher its security, but at the same time it is more complex in computation. According to the current security requirements and computing resources, the key length is optimized and adjusted to obtain the optimized encryption parameters. The communication data is encrypted based on the optimized encryption parameters to generate a preliminary encrypted data stream. The preliminary encrypted data stream is divided into blocks, and the entire data stream is divided into smaller units. Each unit is encrypted and transmitted independently, so that the data can be restored faster when a transmission error or attack occurs. A unique identifier is generated for each data block to ensure that the integrity and order of each data block are not destroyed, forming a block encrypted data stream. Based on the block encrypted data stream, a data integrity verification tree is constructed. The data integrity verification tree is similar to a Merkle tree, which aggregates the hash values ​​of all data blocks layer by layer to generate a root hash value. The construction process of the data integrity verification tree can be expressed by the following formula:

[0081] H root =H(H(H(D1)||H(D2))||H(H(D3)||H(D4)));

[0082] Where H(·) represents the hash function, D i represents each data block, || represents the concatenation operation of the hash value, H rootis the root hash value finally generated. In this way, it is possible to effectively detect whether the data block has been tampered with during transmission. In order to ensure the security of the data integrity verification tree itself, the root node of the data integrity verification tree is signed using the elliptic curve digital signature algorithm to generate an encrypted communication data stream and a corresponding authentication token. The elliptic curve digital signature algorithm is a digital signature algorithm based on elliptic curve cryptography, which has the characteristics of high security and low computational cost. The purpose of the signature is to ensure that the data has not been tampered with during transmission and that the signature is undeniable. The signing process can be described as:

[0083] Signature=s(H root ,k priv );

[0084] Among them, Signature is the generated digital signature, H root is the root hash value of the data integrity verification tree, k priv The private key of the signer. The signature can be verified at the receiving end using the public key, thus confirming the integrity and origin of the data.

[0085] In one example, based on encrypted communication data streams and authentication tokens, a dynamic graph structure model is constructed and graph neural network analysis is performed to obtain optimized routing strategies and security configuration parameters, including:

[0086] A time-varying graph structure is constructed based on encrypted communication data streams and authentication tokens to obtain a dynamic communication topology graph, in which nodes represent communication entities, edges represent communication links, and the attributes of nodes and edges are dynamically updated over time.

[0087] Based on the time-series graph convolutional network, the spatiotemporal features of the dynamic communication topology graph are extracted to obtain the graph time-series feature sequence;

[0088] The graph temporal feature sequence is input into the graph attention layer to calculate the dynamic correlation strength between nodes to obtain an adaptive adjacency matrix, and the adaptive adjacency matrix is ​​input into the graph diffusion convolution network to extract multi-scale features to obtain a multi-level graph representation;

[0089] Perform graph pooling operations on multi-level graph representations to achieve node clustering and dimensionality reduction, obtain a compressed graph structure, and build a graph generation adversarial network based on the compressed graph structure to learn the implicit distribution of communication patterns and obtain a communication pattern generator;

[0090] The candidate routing strategies are analyzed by the communication pattern generator to obtain a routing strategy set, and the routing strategy set is evaluated and optimized to obtain an optimized routing strategy and security configuration parameters.

[0091] In this example, a time-varying graph structure is constructed based on encrypted communication data streams and authentication tokens to obtain a dynamic communication topology graph. In the graph structure, nodes represent communication entities, such as digital power supplies, microcontrollers, gateways, etc., while edges represent communication links between these entities. The attributes of nodes and edges in the dynamic communication topology graph are dynamically updated over time. These attributes include link bandwidth, latency, encryption strength, authentication status, etc. The dynamic communication topology graph can not only reflect the current network structure, but also capture the network status and communication characteristics that change over time. Based on the time-series graph convolutional network, the dynamic communication topology graph is subjected to spatiotemporal feature extraction to obtain a graph time-series feature sequence. The time-series graph convolutional network can effectively combine time and space information, and extract key features that reflect communication behavior by capturing changes in communication links and node attributes in the time dimension. The features of nodes are aggregated in the neighborhood of the graph through convolution operations, and time series models (such as LSTM or GRU) are used to process changes in the time dimension to generate a graph time-series feature sequence, which contains the state information of nodes and their neighbors at multiple time points. The graph time-series feature sequence is input into the graph attention layer to calculate the dynamic association strength between nodes and obtain an adaptive adjacency matrix. The graph attention layer can dynamically adjust the connection weights between nodes so that the edges between nodes with strong associations are strengthened, while the edges with weak associations are weakened. The adaptive adjacency matrix reflects the degree of association and mutual influence between communication entities at the current moment. The adaptive adjacency matrix can be expressed by the following formula:

[0092]

[0093] Among them, A ij is the strength of the association between node i and node j, q i and k jare the feature vectors of node i and node j respectively. After normalization by the softmax function, the adaptive adjacency matrix obtained can adaptively capture the dynamic relationship between nodes. The adaptive adjacency matrix is ​​input into the graph diffusion convolutional network for multi-scale feature extraction to obtain a multi-level graph representation. The graph diffusion convolutional network can capture complex features in the graph structure at multiple scales (such as local and global). Through the diffusion convolution operation, the graph diffusion convolutional network can not only aggregate the local features of the nodes, but also extract feature representations reflecting the global communication mode through multi-level convolution operations. The multi-level graph representation is subjected to graph pooling operation to achieve node clustering and dimensionality reduction to obtain a compressed graph structure. The graph pooling operation is similar to the pooling operation in the convolutional neural network. It reduces the complexity of the graph while retaining key information and simplifies the complexity of subsequent calculations. Through node clustering, similar or highly correlated nodes are clustered together to reduce the number of nodes in the graph and obtain a more compact compressed graph structure. A graph generation adversarial network is constructed based on the compressed graph structure to learn the implicit distribution of communication patterns and obtain a communication pattern generator. The graph generation adversarial network learns the potential distribution of the graph through adversarial training between a generator and a discriminator, and is able to generate a new graph structure that conforms to this distribution. The generator tries to generate a graph similar to the real graph structure, while the discriminator tries to distinguish the difference between the generated graph and the real graph. Through adversarial training, the generator eventually learns the implicit distribution of the communication mode and is able to generate a graph structure that conforms to the actual communication mode. The communication pattern generator is used to analyze candidate routing strategies. The generator can simulate different communication scenarios and modes to generate a series of candidate routing strategy sets. Each candidate routing strategy reflects a possible communication path and configuration. By analyzing these strategies, the strategy that best suits the current network status is identified. The generated routing strategy set is evaluated and optimized to obtain the final optimized routing strategy and security configuration parameters. The criteria for strategy evaluation include multiple indicators such as communication delay, data throughput, encryption strength, etc. By combining these indicators, the candidate strategies are sorted and screened. The goal of optimization is to select a strategy that achieves the best balance between security and performance to ensure that data transmission is both fast and secure.

[0094] In one example, the graph temporal feature sequence is input into the graph attention layer to calculate the dynamic correlation strength between nodes to obtain an adaptive adjacency matrix, and the adaptive adjacency matrix is ​​input into the graph diffusion convolution network to extract multi-scale features to obtain a multi-level graph representation, including:

[0095] Perform self-attention calculation on the time dimension of the graph temporal feature sequence to obtain the temporal attention weight matrix, and perform weighted aggregation on the graph temporal feature sequence based on the temporal attention weight matrix to obtain the temporal aggregation feature;

[0096] Perform graph attention calculation on the spatial dimension for the temporal aggregation features to obtain the initial correlation strength matrix between nodes, and build a multi-head attention mechanism based on the initial correlation strength matrix to obtain a multi-view correlation strength representation;

[0097] The multi-view correlation strength representation is nonlinearly transformed and normalized to obtain an adaptive adjacency matrix, which is then input into a graph convolutional layer approximated by Chebyshev polynomials to obtain a local feature representation.

[0098] Perform skip connection and residual learning on the local feature representation to obtain the multi-scale feature fusion result, and input the multi-scale feature fusion result into the graph diffusion convolution layer for global information propagation to obtain the global feature representation;

[0099] The long-term dependencies of the global feature representation are captured to obtain the temporal dependency features, and the temporal dependency features are hierarchically aggregated to obtain a multi-level graph representation.

[0100] In this example, the self-attention calculation is performed on the time dimension of the graph time series feature sequence to obtain the time attention weight matrix. In the self-attention mechanism, the feature vector of each time point is assigned a weight to reflect the importance of the time point in the entire sequence. The self-attention mechanism calculates the query vector Q at each time point t t , key vector K t Sum value vector V t , by calculating the similarity between these vectors, we get the time attention weight matrix A t :

[0101]

[0102] Among them, d k is the dimension of the key vector, which is used to scale the attention score. The softmax function ensures that the weight values ​​in the weight matrix are between [0, 1] and the sum of all weights is 1. Based on the time attention weight matrix, the graph temporal feature sequence is weighted aggregated to generate time aggregate features. The time aggregate feature can comprehensively consider the information on the entire time dimension, so that the system not only pays attention to the features of the current time point, but also utilizes important information from past time points. The graph attention calculation in the spatial dimension is performed on the time aggregate feature to obtain the initial association strength matrix between nodes. In the graph attention mechanism, the relationships between different nodes are assigned different weights, and these weights reflect the strength of the association between nodes. By calculating the attention score for each pair of nodes in the graph, the initial association strength matrix is ​​formed:

[0103]

[0104] Among them, S ij is the strength of the association between node i and node j, q i and k j are the feature vectors of node i and node j, respectively. In order to capture the association relationships at different levels, a multi-head attention mechanism is constructed based on the initial association strength matrix. The multi-head attention mechanism combines the association strengths of multiple perspectives by independently calculating attention in different subspaces to obtain a multi-perspective association strength representation. The multi-perspective association strength representation is subjected to nonlinear transformation and normalization to generate an adaptive adjacency matrix. Nonlinear transformation is usually achieved through activation functions (such as ReLU or LeakyReLU), and normalization ensures that the feature vectors of each node are on the same scale, eliminating the magnitude difference between the features of different nodes. The adaptive adjacency matrix not only reflects the dynamic association between nodes, but also can adaptively adjust the structure of the graph to better adapt to the current task requirements. The adaptive adjacency matrix is ​​input into the graph convolution layer of Chebyshev polynomial approximation to obtain a local feature representation. Chebyshev polynomial approximation is an efficient graph convolution method. It can implement convolution operations on graph data at a lower computational complexity by approximating the convolution kernel. Its core formula is:

[0105]

[0106] Among them, X (k) is the feature representation of the kth layer, θ j are the coefficients of the Chebyshev polynomials, is the recursive calculation of Chebyshev polynomials, is the normalized Laplacian matrix of the graph. Through this operation, the local features of the graph can be effectively extracted to capture the relationship between nodes and their neighbors. The local feature representation is subjected to skip connections and residual learning to obtain the multi-scale feature fusion result. Skip connections allow information to be directly transmitted across multiple convolutional layers, while residual learning helps to retain the original feature information and prevent the information from being gradually lost in the deep network. The multi-scale feature fusion result is input into the graph diffusion convolution layer to propagate global information and obtain the global feature representation. The graph diffusion convolution layer diffuses information in the graph structure so that the final feature representation not only contains the local node relationship, but also reflects the global information of the entire graph structure. The global feature representation is subjected to long-term dependency capture to obtain the temporal dependency feature. The temporal dependency feature is subjected to hierarchical feature aggregation to obtain a multi-level graph representation. Hierarchical feature aggregation can combine feature information at different levels to form a unified feature representation.

[0107] In one example, according to the optimized routing strategy and security configuration parameters, the encrypted communication data flow is monitored for transmission, the monitoring result is obtained and a target secure communication strategy is generated, including:

[0108] Based on the optimized routing strategy, the encrypted communication data stream is segmented and routed to obtain multiple parallel transmission data streams;

[0109] Dynamically adjust the encryption strength of multiple parallel transmission data streams based on security configuration parameters to obtain differentiated encrypted data streams, and perform traffic scheduling on the differentiated encrypted data streams to obtain optimized transmission paths;

[0110] Monitor the real-time throughput and latency of data packets on the optimized transmission path to obtain network performance indicators, and calculate the communication quality score based on the network performance indicators to obtain the communication status evaluation result;

[0111] Adjust the communication strategy according to the communication status evaluation result to obtain a preliminary adjustment plan, and match the preliminary adjustment plan with the preset strategy library to obtain a candidate communication strategy set;

[0112] The performance simulation and security evaluation are performed on the candidate communication strategy set, and the strategy with the best comprehensive performance is selected to obtain the target secure communication strategy.

[0113] In this example, the encrypted communication data stream is segmented and routed based on the optimized routing strategy to obtain multiple parallel transmission data streams. The large-scale communication data stream is divided into multiple independent data segments, each of which is transmitted in parallel through different routing paths, which improves the efficiency of data transmission and enhances the security of data. The encryption strength of multiple parallel transmission data streams is dynamically adjusted based on security configuration parameters to generate differentiated encrypted data streams. The security configuration parameters may include the current threat level, the computing power of the device, the communication delay requirements, etc. The dynamic adjustment of encryption strength means selecting appropriate encryption algorithms and key lengths according to the security requirements and network conditions of each transmission path. For example, for high-risk transmission paths, stronger encryption algorithms and longer keys are selected to provide higher security; while for low-risk paths, lighter encryption algorithms can be selected to reduce computing overhead. Traffic scheduling is performed on differentiated encrypted data streams to determine the optimized transmission path. According to factors such as the current network load condition, path delay and bandwidth, data traffic is reasonably allocated to avoid network congestion and maximize transmission efficiency. This is achieved by solving the following optimization problem:

[0114]

[0115] Among them, P is the set of all possible transmission paths, P i is the i-th path, Delay(P i ) is the path P i The transmission delay, Bandwidth (P i ) is the path P i The available bandwidth, α i and βi is a weight coefficient used to balance the effects of latency and bandwidth. By solving the optimization problem, the optimal transmission path configuration is found to achieve efficient data transmission. As the data stream is transmitted, the throughput and latency of the data packets on the optimized transmission path are monitored in real time to obtain network performance indicators. Throughput measures the amount of data successfully transmitted per unit time, while latency is the time it takes for data to be sent and received. By monitoring these indicators in real time, the performance status of the current network can be dynamically understood. For example, when the network is congested or the latency of a path suddenly increases, the system can immediately detect it and take corresponding measures. Throughput T and latency D can be calculated using the following formula:

[0116]

[0117] Among them, S i is the size of the ith successfully transmitted packet, Δt is the monitoring time interval, t ri and t si are the receiving time and sending time of the ith data packet, respectively, and n is the total number of data packets. The communication quality score Q is calculated based on the network performance index. The communication quality score is a comprehensive indicator to measure the current communication status, which can take into account multiple factors such as throughput, latency, and packet loss rate. The communication quality score can be calculated by the weighted average method:

[0118] Q = α·T-β·D-γ·P;

[0119] Among them, P is the packet loss rate, and α, β, and γ are the weight coefficients of throughput, delay, and packet loss rate, respectively. These coefficients can be adjusted according to the needs of actual applications to ensure that the communication quality score can accurately reflect the communication status. According to the communication quality score Q, the communication strategy is adjusted to obtain a preliminary adjustment plan. The preliminary adjustment plan aims to optimize the current communication status, which may include changing the routing strategy, adjusting the encryption strength, modifying the transmission path, etc. The preliminary adjustment plan is matched with the preset policy library to obtain a candidate communication strategy set. The policy library stores multiple pre-verified communication strategies, which have been tested and verified in different scenarios and can cope with various complex communication environments. The candidate communication strategy set is subjected to performance simulation and security evaluation to select the strategy with the best comprehensive performance. The performance simulation aims to simulate the performance of each candidate strategy in a real communication environment and evaluate its performance under different network loads, delays, packet loss rates, etc. The security evaluation focuses on the security of each strategy in the face of potential attacks or abnormal conditions, including anti-attack capabilities, data confidentiality, authentication reliability, etc. By comprehensively considering the results of performance simulation and security evaluation, a strategy with the best comprehensive performance is finally selected as the target secure communication strategy.

[0120] In one example, the encryption strength of multiple parallel transmission data streams is dynamically adjusted based on security configuration parameters to obtain differentiated encrypted data streams, and traffic scheduling is performed on the differentiated encrypted data streams to obtain optimized transmission paths, including:

[0121] The data importance of multiple parallel transmission data streams is graded to obtain graded data streams, and based on the security configuration parameters and the importance level of the graded data streams, an encryption algorithm and a key length are assigned to each data stream to obtain an encryption configuration scheme;

[0122] Performing differential encryption processing on the hierarchical data stream according to the encryption configuration scheme to obtain a preliminary differential encrypted data stream, and performing data packet segmentation and reorganization on the preliminary differential encrypted data stream to obtain encrypted data packets of variable length;

[0123] A virtual private network tunnel is constructed based on encrypted data packets of variable length to obtain a multi-layer encrypted channel, and a load balancing calculation is performed on the multi-layer encrypted channel to obtain a preliminary traffic distribution plan;

[0124] Based on the preliminary traffic distribution plan and network topology information, the shortest path first algorithm is used to calculate the optimal transmission path, obtain the routing table, and forward the data packets in the multi-layer encrypted channel according to the routing table to obtain the optimized transmission path.

[0125] In this example, multiple parallel transmission data streams are graded according to their importance and marked according to their criticality in the entire communication task. Data importance grading can be based on a variety of factors, such as data sensitivity, real-time requirements, and acceptability of loss. For example, in a smart grid, control instruction data streams may be considered high-importance data because they directly affect the stability of the grid; while monitoring data streams may be classified as medium-importance because although they provide visual information about the operating status, they do not immediately affect the operation of the system. Based on the security configuration parameters and the importance level of the graded data streams, a suitable encryption algorithm and key length are assigned to each data stream to generate an encryption configuration scheme. The security configuration parameters may include the current threat level, the computing resources of the device, and the real-time requirements of the communication. For high-importance data streams, a high-strength encryption algorithm (such as AES-256) is selected and a longer key is used to ensure data confidentiality and integrity; for low-importance data streams, the system may select a lightweight encryption algorithm (such as AES-128) and a shorter key to reduce the computing burden and improve transmission efficiency. According to the generated encryption configuration scheme, differentiated encryption processing is performed on the hierarchical data stream to obtain a preliminary differentiated encrypted data stream. The preliminary differentiated encrypted data stream is segmented and reassembled into data packets to generate encrypted data packets of variable length. The purpose of the segmentation and reassembly process is to optimize the transmission of data packets so that the length of the data packet can be dynamically adjusted according to the network conditions, improve bandwidth utilization and reduce transmission delay. A virtual private network (VPN) tunnel is constructed based on encrypted data packets of variable length to form a multi-layer encrypted channel. The VPN tunnel provides an encrypted transmission path for data to prevent data from being eavesdropped or tampered with when transmitted on the public network. Multi-layer encrypted channels mean that data may be protected by multiple encryptions during transmission, which enhances data security. Load balancing calculation is performed on multi-layer encrypted channels to obtain a preliminary traffic distribution plan. The data stream is reasonably distributed to different transmission channels to avoid overload or bottleneck problems in a certain channel. Load balancing calculation can be based on factors such as current network traffic, bandwidth of each channel, and delay. The optimization formula can be expressed as:

[0126]

[0127] Among them, L is the traffic distribution plan, F i is the flow rate on the ith channel, B i is the bandwidth capacity of the ith channel, is the objective function of load balancing. By minimizing this function, the optimal distribution of data flows is achieved. Based on the preliminary traffic distribution plan and the current network topology information, the shortest path first algorithm is used to calculate the optimal transmission path and generate a routing table. The shortest path first algorithm aims to find the shortest path from the data source to the destination to reduce transmission delay and improve transmission efficiency. The formula of the shortest path first algorithm is:

[0128]

[0129] Among them, d(v) is the shortest path distance of node v, Adj(v) is the set of nodes adjacent to node v, and w(u,v) is the path weight from node u to node v. Through iterative calculation, the shortest path of all nodes is obtained, and finally the routing table of the entire network is generated. According to the routing table, the data packets in the multi-layer encrypted channel are forwarded and scheduled to obtain the optimized transmission path. The optimized transmission path ensures that the data can reach the destination with the lowest delay and the highest security, avoiding network congestion and potential security risks.

[0130] Reference Figure 2 , this embodiment provides a data security communication system between a digital power supply and a microcontroller, including:

[0131] Acquisition module 1, used to acquire communication data between the digital power supply and the microcontroller and perform feature extraction to obtain communication feature vectors and channel state information;

[0132] Detection module 2, used to generate an adaptive chirp signal and perform communication channel detection based on the communication feature vector and channel state information to obtain real-time channel characteristic parameters;

[0133] Detection module 3, used to construct a multi-dimensional security feature space and perform anomaly detection according to real-time channel characteristic parameters and preset initial security communication strategy to obtain security risk assessment results;

[0134] The encryption module 4 is used to encrypt the communication data based on the security risk assessment result, obtain the encrypted communication data stream and generate the authentication token;

[0135] Analysis module 5, used to build a dynamic graph structure model and perform graph neural network analysis based on encrypted communication data streams and authentication tokens to obtain optimized routing strategies and security configuration parameters;

[0136] The generation module 6 is used to monitor the transmission of the encrypted communication data flow according to the optimized routing strategy and security configuration parameters, obtain the monitoring results and generate a target security communication strategy.

[0137] In this embodiment, for the specific implementation of each unit in the above system embodiment, please refer to the description in the above method embodiment, which will not be repeated here.

[0138] Reference Figure 3 In an embodiment of the present invention, a computer device is also provided. The computer device may be a server, and its internal structure may be as follows: Figure 3 As shown. The computer device includes a processor, a memory, a display screen, an input system, a network interface and a database connected through a system bus. Among them, the processor designed by the computer is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the corresponding data in this embodiment. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.

[0139] Those skilled in the art will understand that Figure 3 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied.

[0140] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the above method is implemented. It can be understood that the computer-readable storage medium in this embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.

[0141] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided by the present invention and used in the embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double-speed data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM.

[0142] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, system, article or method including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, system, article or method. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, system, article or method including the element.

[0143] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A data security communication method between a digital power supply and a microcontroller, characterized in that: The following steps are involved: Acquire the communication data between the digital power supply and the microcontroller and perform feature extraction to obtain the communication feature vector and channel state information; Based on the communication feature vector and the channel state information, an adaptive chirp signal is generated and communication channel detection is performed to obtain real-time channel characteristic parameters; According to the real-time channel characteristic parameters and the preset initial security communication strategy, a multi-dimensional security feature space is constructed and anomaly detection is performed to obtain a security risk assessment result; Based on the security risk assessment result, encrypt the communication data to obtain an encrypted communication data stream and generate an authentication token; Based on the encrypted communication data stream and the authentication token, a dynamic graph structure model is constructed and a graph neural network analysis is performed to obtain an optimized routing strategy and security configuration parameters; According to the optimized routing strategy and the security configuration parameters, the encrypted communication data stream is monitored for transmission, a monitoring result is obtained and a target secure communication strategy is generated.

2. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: The method of acquiring communication data between the digital power supply and the microcontroller and performing feature extraction to obtain a communication feature vector and channel state information includes: Connecting a serial port analyzer to the communication line between the digital power supply and the microcontroller, configuring communication parameters, capturing a bidirectional communication data stream, and obtaining communication data; performing noise removal on the communication data to obtain filtered communication data, and performing normalization processing on the filtered communication data to obtain normalized communication data; Performing outlier detection on the normalized communication data to obtain an outlier marking result, and performing least squares analysis on the normalized communication data based on the outlier marking result to obtain preliminary channel characteristic parameters; Constructing a weighted least squares optimization objective function according to the preliminary channel characteristic parameters, solving the objective function, and obtaining optimized security communication protocol parameters; wherein the objective function includes a communication delay index, a throughput index, an energy consumption index, and a security level index, and each index is assigned a corresponding weight; Feature extraction is performed on the normalized communication data based on the optimized secure communication protocol parameters to obtain a communication feature vector and channel state information.

3. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: The step of generating an adaptive chirp signal and performing communication channel detection based on the communication feature vector and the channel state information to obtain real-time channel characteristic parameters includes: Constructing a basic chirp signal based on the communication feature vector and the channel state information, and performing real-time signal-to-noise ratio monitoring on the basic chirp signal to obtain a signal-to-noise ratio monitoring result; Dynamically adjusting the signal amplitude of the basic chirp signal according to the signal-to-noise ratio monitoring result to obtain a chirp signal with adjusted amplitude; Performing spectrum analysis on the amplitude-adjusted chirp signal to obtain a spectrum analysis result, and optimizing the starting frequency and frequency change rate of the amplitude-adjusted chirp signal based on the spectrum analysis result to obtain a frequency-optimized chirp signal; Fine-tune the signal parameters of the frequency-optimized chirp signal in real time to obtain an adaptive chirp signal, and periodically detect the communication channel based on the adaptive chirp signal to obtain original detection data; Performing time-frequency analysis on the original detection data to obtain real-time channel characteristic parameters; wherein the real-time channel characteristic parameters include channel delay spread, Doppler spread and coherence bandwidth.

4. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: The method of constructing a multi-dimensional security feature space and performing anomaly detection according to the real-time channel characteristic parameters and the preset initial security communication strategy to obtain a security risk assessment result includes: Based on the real-time channel characteristic parameters and the preset initial secure communication strategy, extract multi-dimensional security features to obtain a security feature vector of the current communication state; Performing feature dimensionality reduction processing on the security feature vector to obtain a feature representation after dimensionality reduction, and inputting the feature representation after dimensionality reduction into a pre-trained Gaussian mixture model to calculate the probability density of the current communication state to obtain a preliminary evaluation value of the abnormality degree; Calculating the Mahalanobis distance based on the preliminary evaluation value of the abnormality degree to obtain an abnormality detection index, and comparing the abnormality detection index with a preset threshold to obtain a preliminary abnormality detection result; Performing abnormality classification on the preliminary abnormality detection result to obtain an initial abnormality detection result, and performing quantitative evaluation of the abnormality degree on the initial abnormality detection result to obtain an abnormality degree score; According to the abnormality degree score and the preset risk level classification standard, the current communication status is classified into risk levels to obtain a security risk assessment result.

5. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: The step of encrypting the communication data based on the security risk assessment result to obtain an encrypted communication data stream and generate an authentication token comprises: Matching a list of candidate encryption algorithms according to the security risk assessment result, and performing a performance evaluation on each encryption algorithm in the list of candidate encryption algorithms to obtain an algorithm performance score; Selecting an optimal encryption algorithm based on the algorithm performance score and current communication environment parameters to obtain a target encryption algorithm, and dynamically adjusting the key length of the target encryption algorithm to obtain optimized encryption parameters; Encrypting the communication data based on the optimized encryption parameters to obtain a preliminary encrypted data stream, and dividing the preliminary encrypted data stream into blocks to generate a unique identifier for each data block to obtain a block encrypted data stream; A data integrity verification tree is constructed based on the block encrypted data stream, and an elliptic curve digital signature algorithm is used to sign the root node of the data integrity verification tree to obtain an encrypted communication data stream and a corresponding authentication token.

6. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: Based on the encrypted communication data stream and the authentication token, a dynamic graph structure model is constructed and a graph neural network analysis is performed to obtain optimized routing strategies and security configuration parameters, including: A time-varying graph structure is constructed based on the encrypted communication data stream and the authentication token to obtain a dynamic communication topology graph, wherein nodes represent communication entities, edges represent communication links, and the attributes of nodes and edges are dynamically updated over time; Extracting spatiotemporal features of the dynamic communication topology graph based on a temporal graph convolutional network to obtain a graph temporal feature sequence; Inputting the graph temporal feature sequence into the graph attention layer to calculate the dynamic correlation strength between nodes to obtain an adaptive adjacency matrix, and inputting the adaptive adjacency matrix into the graph diffusion convolution network to extract multi-scale features to obtain a multi-level graph representation; Performing a graph pooling operation on the multi-level graph representation to achieve node clustering and dimensionality reduction, obtaining a compressed graph structure, and constructing a graph generation adversarial network based on the compressed graph structure to learn the implicit distribution of communication patterns and obtain a communication pattern generator; The communication mode generator is used to analyze candidate routing strategies to obtain a routing strategy set, and the routing strategy set is evaluated and optimized to obtain an optimized routing strategy and security configuration parameters.

7. The method for secure data communication between a digital power supply and a microcontroller according to claim 6, characterized in that: The step of inputting the graph temporal feature sequence into the graph attention layer to calculate the dynamic correlation strength between nodes to obtain an adaptive adjacency matrix, and inputting the adaptive adjacency matrix into the graph diffusion convolution network to extract multi-scale features to obtain a multi-level graph representation, including: Performing self-attention calculation on the graph time series feature sequence in the time dimension to obtain a time attention weight matrix, and performing weighted aggregation on the graph time series feature sequence based on the time attention weight matrix to obtain a time aggregation feature; Performing graph attention calculation on the spatial dimension for the temporal aggregation features to obtain an initial correlation strength matrix between nodes, and constructing a multi-head attention mechanism based on the initial correlation strength matrix to obtain a multi-view correlation strength representation; Performing nonlinear transformation and normalization processing on the multi-view correlation strength representation to obtain an adaptive adjacency matrix, and inputting the adaptive adjacency matrix into a graph convolution layer approximated by Chebyshev polynomials to obtain a local feature representation; Performing skip connection and residual learning on the local feature representation to obtain a multi-scale feature fusion result, and inputting the multi-scale feature fusion result into a graph diffusion convolution layer for global information propagation to obtain a global feature representation; The long-term dependency relationship of the global feature representation is captured to obtain a temporal dependency feature, and the temporal dependency feature is subjected to hierarchical feature aggregation to obtain a multi-level graph representation.

8. The data security communication method between a digital power supply and a microcontroller according to claim 1, characterized in that: The step of monitoring the transmission of the encrypted communication data stream according to the optimized routing strategy and the security configuration parameters, obtaining monitoring results and generating a target secure communication strategy includes: Based on the optimized routing strategy, the encrypted communication data stream is segmented and routed to obtain multiple parallel transmission data streams; Dynamically adjusting the encryption strength of the multiple parallel transmission data streams based on the security configuration parameters to obtain differentiated encrypted data streams, and performing traffic scheduling on the differentiated encrypted data streams to obtain an optimized transmission path; Performing real-time throughput and latency monitoring on the data packets on the optimized transmission path to obtain network performance indicators, and calculating a communication quality score based on the network performance indicators to obtain a communication status evaluation result; Adjusting the communication strategy according to the communication status evaluation result to obtain a preliminary adjustment plan, and matching the preliminary adjustment plan with a preset strategy library to obtain a candidate communication strategy set; The candidate communication strategy set is subjected to performance simulation and security evaluation, and the strategy with the best comprehensive performance is selected to obtain the target secure communication strategy.

9. The method for secure data communication between a digital power supply and a microcontroller according to claim 8, characterized in that: The dynamically adjusting the encryption strength of the multiple parallel transmission data streams based on the security configuration parameters to obtain differentiated encrypted data streams, and performing traffic scheduling on the differentiated encrypted data streams to obtain an optimized transmission path includes: The multiple parallel transmission data streams are graded according to data importance to obtain graded data streams, and based on the security configuration parameters and the importance levels of the graded data streams, encryption algorithms and key lengths are assigned to the graded data streams to obtain an encryption configuration scheme; Performing differential encryption processing on the hierarchical data stream according to the encryption configuration scheme to obtain a preliminary differential encrypted data stream, and performing data packet segmentation and reorganization on the preliminary differential encrypted data stream to obtain encrypted data packets of variable length; Building a virtual private network tunnel based on the variable-length encrypted data packet to obtain a multi-layer encrypted channel, and performing load balancing calculation on the multi-layer encrypted channel to obtain a preliminary traffic distribution plan; Based on the preliminary traffic distribution plan and network topology information, the shortest path first algorithm is used to calculate the optimal transmission path to obtain a routing table, and the data packets in the multi-layer encrypted channel are forwarded and scheduled according to the routing table to obtain an optimized transmission path.

10. A data security communication system between a digital power supply and a microcontroller, characterized in that: A method for secure data communication between a digital power supply and a microcontroller according to any one of claims 1 to 9, the system comprising: An acquisition module is used to acquire communication data between the digital power supply and the microcontroller and perform feature extraction to obtain communication feature vectors and channel state information; A detection module, used to generate an adaptive chirp signal and perform communication channel detection based on the communication feature vector and the channel state information to obtain real-time channel characteristic parameters; A detection module, used to construct a multi-dimensional security feature space and perform anomaly detection according to the real-time channel characteristic parameters and the preset initial security communication strategy to obtain a security risk assessment result; An encryption module, used to encrypt the communication data based on the security risk assessment result, obtain an encrypted communication data stream and generate an authentication token; An analysis module, used to construct a dynamic graph structure model and perform graph neural network analysis based on the encrypted communication data stream and the authentication token to obtain optimized routing strategies and security configuration parameters; A generation module is used to monitor the transmission of the encrypted communication data stream according to the optimized routing strategy and the security configuration parameters, obtain monitoring results and generate a target secure communication strategy.

Citation Information

Patent Citations

  • Hierarchical construction distributed power supply intelligent power grid construction method

    CN116865258A

  • Complex scene-oriented RGB video and WiFi signal fused human body action recognition method

    CN117975550A