A Secure Communication Method and System Based on SM Cryptography Algorithm and Improved Modbus TCP Protocol
By integrating the national secret algorithm, especially the SM2 and SM4 algorithms in the Modbus TCP protocol, the problem of lack of security authentication and compliance in industrial automation is solved, secure identity authentication and anti-replay attacks are realized, and the security and compliance of data transmission are improved.
Patent Information
- Application Number
- CN202411718247.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-11-28
AI Technical Summary
The lack of a security authentication mechanism in the application of the Modbus TCP protocol in the field of industrial automation has led to data transmission being susceptible to eavesdropping, tampering and replay attacks, and the existing solutions use non-domestic cryptographic algorithms that do not meet compliance requirements.
The improved Modbus TCP protocol based on the national secret algorithm is adopted, and through cryptographic applications such as signature, signature verification, encryption, decryption and key exchange, the SM2 asymmetric algorithm and SM4 symmetric algorithm are integrated to enhance the security of data transmission and realize identity authentication and prevent replay attacks.
It improves the security and compliance of the Modbus TCP protocol, realizes secure identity authentication and data transmission confidentiality between the host and slave, prevents replay attacks, and meets the secure communication needs in industrial control environments.
Smart Images

Figure CN119232482B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to a secure communication method and system based on national cryptographic algorithms and an improved Modbus TCP protocol. Background Art
[0002] Modbus is a communication protocol designed specifically for industrial automation systems, adopting a master-slave mode, that is, a master device (usually a computer or a programmable logic controller) communicates with multiple slave devices (such as sensors, actuators, etc.). Modbus TCP is a variant of the Modbus protocol, which uses TCP as the transport layer protocol for data transmission over Ethernet. Modbus TCP maintains the core features of the Modbus protocol, such as the master-slave mode and function codes, while taking advantage of the TCP protocol to provide network interconnection and transmission.
[0003] Modbus TCP has characteristics such as high speed, stability, and easy configuration, so it has been widely used in the field of industrial automation. However, Modbus TCP uses the TCP network to transmit Modbus messages, and the protocol itself has no security authentication mechanism. Any network access can connect and communicate with the host or slave, and the identities of both communication parties cannot be verified. Moreover, the Modbus protocol itself does not include an encryption mechanism. Therefore, when transmitting over the TCP network, all data is transmitted in plain text, which may lead to the transmitted data being easily eavesdropped, tampered with, impersonated, and the host system and slave system being subject to replay attacks, etc.
[0004] The existing way to solve the security problem of Modbus TCP is to adopt the TLS / SSL protocol, but the TLS / SSL protocol uses non-domestic cryptographic algorithms such as RSA and ECC for protection, which does not meet the requirements of cryptographic compliance.
[0005] Therefore, it is necessary to solve the defect of the lack of security design in the Modbus TCP protocol, integrate domestic cryptographic algorithms with the Modbus TCP protocol at the application protocol layer, and improve the security of the Modbus TCP protocol. Summary of the Invention
[0006] In order to overcome the above-mentioned deficiencies in technology, the present invention provides a secure communication method and system based on national cryptographic algorithms and an improved Modbus TCP protocol. During the communication process, cryptographic applications such as signature, signature verification, encryption, decryption, and key exchange are integrated to achieve the integration of domestic cryptographic algorithms and the Modbus TCP / TP protocol at the application protocol layer, aiming to achieve the security and compliance of the Modbus TCP protocol.
[0007] The technical solution adopted by the present invention to overcome its technical problems is as follows: The first aspect of the present invention proposes a secure communication method based on national cryptographic algorithms and an improved Modbus TCP protocol, which is applied to a communication system composed of a host and several slaves based on the improved Modbus TCP protocol. Both the host and the slaves are configured with password modules. The specific steps of the secure communication method are as follows: Share the initial public key between the host and the slaves; Establish a TCP connection between the host and the slaves and generate random numbers respectively based on the password modules; Sign and verify the random numbers using national cryptographic algorithms to achieve secure identity authentication between the host and the slaves; Negotiate an encryption key between the host and the slaves based on the national cryptographic algorithms; Transmit data based on the improved Modbus TCP protocol between the host and the slaves using the encryption key.
[0008] Further, the improved Modbus TCP protocol includes a security check field, and the security check field is the random number generated by the host and the slaves based on the password module for each data transmission.
[0009] Further, the improved Modbus TCP protocol also includes a message header and a protocol data unit. The message header includes at least a transaction identifier, a protocol identifier, a length, and a unit identifier. The protocol data unit includes at least a function code, data, and a random number.
[0010] Adding a random number as a security check field to the Modbus TCP protocol improvement to achieve anti-replay.
[0011] Further, the national cryptographic algorithms adopt a combination of SM2 asymmetric algorithm and SM4 symmetric algorithm. Among them, the SM2 asymmetric algorithm is used for signature verification and negotiation of the SM4 symmetric key, and the SM4 symmetric algorithm is used for data encryption transmission.
[0012] The host and the slaves establish a TCP connection and generate random numbers respectively based on the password modules, and sign and verify the random numbers using national cryptographic algorithms to achieve secure identity authentication between the host and the slaves. The specific steps are as follows: After the host and the slaves establish a TCP connection, the host generates a first random number based on the password module and sends it to the slaves; The slaves generate a second random number based on the password module, sign the first random number and the second random number based on the slave's asymmetric private key, and then send them to the host; The host verifies the signature based on the slave's asymmetric public key to authenticate the slave's identity; The host signs the second random number based on the host's asymmetric private key and sends it to the slaves; The slaves verify the signature based on the host's asymmetric public key, and after signature verification, complete the authentication of the host's identity and return a confirmation message.
[0013] Through the combination of the SM2 asymmetric algorithm and the SM4 symmetric algorithm, the authentication method of Modbus TCP communication is improved, and the communication security is enhanced.
[0014] Furthermore, an encryption key is negotiated between the host and the slave based on the national cryptographic algorithm, which specifically includes: the host generates a first symmetric key based on the hardware cryptographic module, encrypts it with the slave public key to obtain a first encrypted ciphertext, and signs the first encrypted ciphertext with the host asymmetric private key to generate a first signature message, and then sends the first encrypted ciphertext and the first signature message to the slave; the slave verifies the first signature message based on the slave asymmetric public key, and after the verification passes, decrypts the first encrypted ciphertext with the slave asymmetric private key to obtain the first symmetric key as the encryption key; both the host and the slave use the first symmetric key as the encryption key.
[0015] Furthermore, the host and the slave perform data transmission based on the improved Modbus TCP protocol based on the encryption key, which specifically includes: the host encrypts the function code and data of the plaintext protocol data unit in the improved Modubus TCP protocol with the encryption key to generate a second encrypted ciphertext and sends it to the slave; the slave decrypts the received second encrypted ciphertext with the encryption key to obtain the plaintext, and obtains the function code, data and random number based on the plaintext; the slave operates based on the obtained function code and data, and sends the operation result to the host based on the encryption key.
[0016] The SM4 symmetric key is negotiated through SM2 asymmetric algorithm signature verification and SM2 asymmetric algorithm encryption, and then data encryption is performed through the SM4 symmetric key to ensure the confidentiality of the data, thereby realizing secure communication in the one-host / multi-slave mode in the industrial control environment.
[0017] Furthermore, both the host and the slave are configured with a random number storage table for storing random number fields. Each communication between the host and the slave compares the random number field in the Modbus TCP packet with the data in the random number table storage to achieve anti-replay; a shared key configuration table is configured between the host and the slave for sharing the initial public key.
[0018] Furthermore, each communication between the host and the slave compares the random number field in the Modbus TCP packet with the data in the random number table storage to achieve anti-replay, which specifically includes: if the random number in the packet in the random number storage table already exists, it indicates that the message transmitted this time is a replayed message, and the host / slave discards the message transmitted this time and does not process it; if the random number is not in the random number table, the random number in the packet is put into the random number table, and the host / slave performs corresponding operations according to the received function code and data.
[0019] Another aspect of the present invention also proposes a secure communication system based on the national cryptographic algorithm and the improved Modbus TCP protocol, including a host and several slaves that communicate based on the improved Modbus TCP protocol. Both the host and the slaves at least include a Modbus application module, a security protocol parsing and encapsulation module, and a cryptographic module. The security protocol parsing and encapsulation module responds to the instructions issued by the Modbus application module, and sends the parsed instructions to the Modbus application module; the security protocol parsing and encapsulation module encapsulates the issued instructions into a message to be sent based on the improved Modbus TCP protocol, or parses the decrypted message into an instruction to be executed; the cryptographic module is used for cryptographic operations of the host and the slaves, generating public and private keys based on the national cryptographic algorithm and adding random numbers to the message to be sent, as well as encrypting, signing, verifying signatures, and decrypting the received message.
[0020] Through the cryptographic support ability of the cryptographic module, the national cryptographic algorithm is integrated into the Modbus TCP protocol and the industrial application system to meet the information security compliance communication of the industrial application system.
[0021] The beneficial effects of the present invention are:
[0022] 1. Add a random number field to the Modbus TCP message as a security verification field to achieve anti-replay attack;
[0023] 2. Improve the Modbus TCP communication connection establishment method. When establishing a connection between the master / slave, it was only based on the handshake and wave processes of the TCP protocol to establish a connection. It is improved to add an identity authentication and key negotiation process based on SM2 when establishing a connection, improving security;
[0024] 3. Expand the national cryptographic protocol design based on the combination of SM2 asymmetric algorithm and SM4 symmetric algorithm to ensure data security. Sign and verify signatures through the SM2 asymmetric algorithm and negotiate the SM4 symmetric key through the SM2 asymmetric algorithm encryption, and then encrypt the data through the SM4 symmetric key to ensure data confidentiality, thereby realizing secure communication in the one-host / multi-slave mode in the industrial control environment;
[0025] 4. Through the cryptographic support ability of the cryptographic module, the national cryptographic algorithm is integrated into the Modbus TCP protocol and the industrial application system to meet the information security compliance communication of the industrial application system. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 It is a schematic flow chart of a secure communication method based on the national cryptographic algorithm and the improved Modbus TCP protocol according to an embodiment of the present invention;
[0027] Figure 2Schematic diagram of the identity authentication process in the embodiment of the present invention;
[0028] Figure 3 Schematic diagram of the process of negotiating encryption keys between the host and the slave based on the national cryptographic algorithm in the embodiment of the present invention;
[0029] Figure 4 Schematic diagram of the data transmission process between the host and the slave based on the encryption key in the embodiment of the present invention;
[0030] Figure 5 Schematic diagram of the improved Modbus TCP message format in the embodiment of the present invention;
[0031] Figure 6 Schematic diagram of the architecture of a secure communication system based on the national cryptographic algorithm and the improved Modbus TCP protocol in the embodiment of the present invention. Detailed implementation manners
[0032] To facilitate better understanding of the present invention by those skilled in the art, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. The following is only exemplary and does not limit the protection scope of the present invention.
[0033] As Figure 1 shown, it is a schematic diagram of the process of a secure communication method based on the national cryptographic algorithm and the improved Modbus TCP protocol, including sharing an initial public key between the host and the slave; establishing a TCP connection between the host and the slave and respectively generating random numbers based on the cryptographic module; performing signature verification on the random numbers using the national cryptographic algorithm to achieve secure identity authentication between the host and the slave; negotiating an encryption key between the host and the slave based on the national cryptographic algorithm; and the host and the slave performing data transmission based on the encryption key and the improved Modbus TCP protocol. The following will describe each step in detail according to specific embodiments.
[0034] S1. Share the initial public key between the host and the slave.
[0035] In an embodiment of the present invention, the host / slave configures a shared key preset table. The SM2 public keys corresponding to each host / slave are stored in the shared key preset table. Through this shared key preset table, the host and each slave share the initial SM2 public key.
[0036] S2. Establish a TCP connection between the host and the slave and respectively generate random numbers based on the cryptographic module.
[0037] The random numbers are generated by the hardware cryptographic modules of the host and the slave, and are generated once for each data transmission.
[0038] It should be noted that in this step, the random number is used for signature, and the signature data is the data transmitted for verifying the identities when the host and the slave establish a connection. Only after the host and the slave verify their identities and complete the negotiation of the key can the formal communication start. The function code, operation data, and random number are transmitted through the improved Modbus TCP protocol, where the random number in the formal communication serves as the security verification field.
[0039] S3. The national cryptography algorithm is used to sign and verify the signature of the random number, thereby realizing the secure identity authentication between the host and the slave.
[0040] In an embodiment of the present invention, a combination of national cryptography algorithms based on the SM2 asymmetric algorithm and the SM4 symmetric algorithm is adopted to ensure the security of data. First, the SM2 signature and verification technology is used to implement a secure identity authentication mechanism between the host and the slave; then, the SM2 asymmetric encryption technology is used to securely negotiate an SM4 symmetric key between the client and the server; finally, the negotiated SM4 symmetric key is used to encrypt the transmitted data to ensure the confidentiality of the data. Among them, the host and the slave have the SM2 public and private key pairs generated by the password module, and the host and each slave share the initial SM2 public key with each other.
[0041] The flow chart of the identity authentication process is as Figure 2 shown, and the specific steps are as follows.
[0042] S31. After the host and the slave establish a TCP connection, the host generates the first random number N1 based on the password module and sends it to the slave.
[0043] S32. The slave generates the second random number N2 based on the password module, and signs the first random number N1 and the second random number N2 based on the SM2 private key and then sends them to the host.
[0044] S33. The host verifies the signature based on the slave's asymmetric public key to realize the authentication of the slave's identity.
[0045] S34. The host signs the slave's random number N2 based on the host's asymmetric private key and sends it to the slave.
[0046] S35. The slave verifies the signature based on the host's asymmetric public key, and after the signature verification, completes the authentication of the host's identity and returns a confirmation message.
[0047] S4. The flow chart of negotiating the encryption key between the host and the slave based on the national cryptography algorithm is as Figure 3 shown. It includes the following steps.
[0048] S41. The host generates a first symmetric key, i.e., generates a 16-byte random number K, based on the hardware password module, encrypts it using the public key of the slave's SM2 to obtain a first encrypted ciphertext C, and signs the first encrypted ciphertext C using the private key of the host's SM2 to generate a first signature message Sc, and thus sends the first encrypted ciphertext C and the first signature message Sc to the slave.
[0049] S42. After receiving the first encrypted ciphertext C and the first signature message Sc, the slave verifies the first signature message Sc based on the public key of the slave's SM2, and after successful verification, decrypts the first encrypted ciphertext C using the private key of the slave's SM2 to obtain the first symmetric key K, and returns a confirmation message.
[0050] S43. Both the host and the slave use the first symmetric key K as the encryption key for both parties.
[0051] S5. The host and the slave perform data transmission based on the encryption key of the improved Modbus TCP protocol, and the schematic flow diagram is as Figure 4 shown.
[0052] S51. The host encrypts the function code and data of the plaintext PDU (Protocol Data Unit) in the improved Modbus TCP protocol using the encryption key K to generate a second ciphertext E and sends it to the slave.
[0053] To resist the replay attack of protocol packets, in an embodiment of the present invention, the Modbus TCP packet is transformed, and a random number field of the Modbus TCP packet is added as a security check field. A 16-byte random number field is added at the end of the Modbus TCP packet as a security check field.
[0054] It should be noted that in the technical solution of the present invention, there are mainly two improvement points for the improved Modbus TCP protocol. The first point is the improvement of the Modbus TCP communication connection establishment: originally, when the master / slave machines established a connection, they only relied on the handshake and wave processes of the TCP protocol to establish a connection. After improvement, an SM2-based identity authentication and key negotiation process is added during connection establishment.
[0055] The second point is the improvement of the packet data structure for the formal communication transmission in the Modbus TCP protocol: the original frame structure for the formal communication transmission data in the Modbus TCP protocol, which is "MBAP packet header + PDU protocol data unit", is improved to "MBAP packet header + PDU protocol data unit + random number security field", that is, a random number field is added after the transmitted data.
[0056] The improved Modbus TCP frame structure is as Figure 5As shown in the figure. Among them, the MBAP message header includes a transaction identifier, a protocol identifier, a length, and a unit identifier. Among them, the transaction identifier occupies 2 bytes and is used for transaction pairing. It is the Modbus transaction code and needs to be incremented by 1 after each communication. The protocol identifier occupies 2 bytes and is used for multiplexing within the system. When its value is 0 (00 00), it indicates the use of the Modbus TCP security protocol. The length occupies 2 bytes and is used to indicate how many more bytes there are below. In this way, even if TCP divides the entire message into multiple packets for transmission, the receiver can identify the message boundary. The unit identifier occupies 1 byte. When the Modbus client sets this field in the request, the server must return this field with the same value in the response. It can be understood as the device address. The PDU protocol data unit includes a function code and data. The function code occupies 1 byte and is the code for performing a function operation. The data length is uncertain and is the data required for performing the operation. The random number field in the security domain occupies 16 bytes and is used to resist replay attacks.
[0057] Among them, E = SM4_enc(plaintext M), where the plaintext M = (function code || data).
[0058] It should be noted that the MBAT message header and the security check field are not encrypted. In some embodiments, the message header is data of a general data structure, and the message header data is automatically generated according to the sending content and order of the data packet; the random number needs to be compared and verified immediately after reception. If the verification fails, the data packet is discarded; only the function code and data are the plaintext messages input and sent by the user and need to be encrypted.
[0059] The random number is generated by the hardware password modules of the host and the slave, and is generated once with each data transmission. In contrast, the host and the slave are respectively configured with a random number storage table, and the random number storage table records the random numbers of each data transmission. The principle of the random number field to resist replay attacks is that for each communication, the random number in the Modbus TCP message is compared with the data in the random number table. If the random number in the message already exists in the system's random number table, it indicates that the message transmitted this time is a replayed message, and the host / slave discards the data packet without processing. If the random number is not in the random number table, the random number in the message is put into the random number table, and the host / slave performs corresponding operations according to the received function code and data. The random number storage table configured by the host / slave is cleared every 30s, which can avoid excessive memory overhead of the host / slave.
[0060] S52, the slave decrypts the received second ciphertext E based on the encryption key K to obtain the plaintext M, M = SM4_dec(E), and obtains the function code, data, and random number based on the plaintext.
[0061] S53. The slave device operates based on the obtained function code and data, and sends the operation result to the master device based on the encryption key K.
[0062] It should be noted that in the formal communication process, the master / slave devices transmit data to each other. The random number serves as a security verification field and is also part of the verification field for the transmitted data. Each time communication occurs, the hardware password module generates a random number, which is sent together with other data. Both the master device and the slave device are configured with a random number storage table for storing the random number field. During each communication between the master device and the slave device, the random number field in the Modbus TCP message is compared with the data stored in the random number table to achieve anti-replay. By comparing the random numbers in the transmitted data during each communication, if the random numbers carried in the communication are the same within a short period of time, the data packet is discarded and no response message is sent, which can prevent the master / slave devices from sending a large number of duplicate messages in a short period of time and prevent replay attacks.
[0063] In another embodiment of the present invention, as Figure 6 shown in the schematic architecture diagram of a secure communication system based on the national cryptographic algorithm and the improved Modbus TCP protocol, it includes a master device system and several slave device systems that communicate based on the improved Modbus TCP protocol. Both the master device system and the slave device system at least include a Modbus application module, a security protocol parsing and encapsulation module, and a password module. The security protocol parsing and encapsulation module responds to the instructions issued by the Modbus application module and sends the parsed instructions to the Modbus application module. The security protocol parsing and encapsulation module encapsulates the issued instructions into a message to be sent based on the improved Modbus TCP protocol, or parses the decrypted message into an instruction to be executed. The password module is used for password operations of the master and slave devices, generating public and private keys based on the national cryptographic algorithm and adding a random number to the message to be sent, as well as encrypting, signing, verifying signatures, and decrypting the received message.
[0064] In an embodiment of the present invention, the password module is a hardware password module that provides password support capabilities, and the hardware password module has a commercial cryptographic product model certificate issued by the National Cryptography Administration, which can meet the information security compliance requirements of the application system.
[0065] The password module can support functions such as password operations, key generation, and random number generation for the master / slave devices, and can support the implementation of the Modbus TCP protocol extended domestic cryptographic protocol.
[0066] Through the password module, random numbers are generated for use as authentication signatures and as random number fields in Modbus TCP messages, achieving anti-replay attack for communication. It can also implement signature verification, generate symmetric keys, implement symmetric encryption and decryption, implement the parsing and encapsulation of the domestic cipher protocol extended from the Modbus TCP protocol, and implement the domestic cipher protocol extended from the Modbus TCP protocol, thereby achieving secure and compliant communication in industrial systems.
[0067] This invention is based on the improvement of the standard Modbus TCP protocol, adding a security check field to achieve anti-replay attack, and extending the design of the domestic cipher protocol through the combination of SM2 asymmetric algorithm and SM4 symmetric algorithm to ensure data confidentiality. By configuring the password module for domestic cipher authentication, it supports functions such as password operation, key generation, and random number generation for the host / slave. Thus, secure and compliant communication based on the improved Modubs TCP protocol in industrial systems is achieved.
[0068] It should be noted that: in other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.
[0069] Each embodiment in this specification is described in a progressive manner. For the same or similar parts between the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments. The systems and system embodiments described above are only illustrative, and some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0070] Professionals can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this invention.
Claims
1. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol, characterized in that: Applied to a communication system consisting of a host and several slaves based on improved Modbus TCP protocol communication, wherein both the host and the slaves are equipped with a password module, the secure communication method specifically includes: The initial public key is shared between the master and slave; The master and slave establish a TCP connection and generate random numbers based on the cryptographic module respectively; The random number is signed and verified using the national secret algorithm, thereby achieving secure identity authentication between the host and the slave; The host and the slave negotiate an encryption key based on a national secret algorithm, which uses a combination of an SM2 asymmetric algorithm and an SM4 symmetric algorithm. The SM2 asymmetric algorithm is used for signature verification and negotiation of an SM4 symmetric key, and the SM4 symmetric algorithm is used for data encryption transmission. The host and the slave perform data transmission based on an improved Modbus TCP protocol based on an encryption key, wherein the improved Modbus TCP protocol includes a security check field, and the security check field is a random number generated by the host and the slave based on a cryptographic module for each data transmission; The improved Modbus TCP frame structure also includes a message header, a protocol data unit and a security domain; the message header also includes a transaction processing identifier, a protocol identifier, a length and a unit identifier; wherein the transaction processing identifier occupies 2 bytes and is used for transaction processing pairing; the protocol identifier occupies 2 bytes and is used for multiplexing within the system; the length occupies 2 bytes and is used to indicate how many bytes are left; the unit identifier occupies 1 byte, when the Modbus client sets this domain in the request, the server must return this domain with the same value in the response; the protocol data unit includes a function code and data; the function code occupies 1 byte and is a code for executing a function operation; the random number field in the security domain occupies 16 bytes and is used to resist replay attacks.
2. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol according to claim 1, characterized in that: The host and the slave establish a TCP connection and generate random numbers based on the password module respectively, and use the national secret algorithm to sign and verify the random numbers, thereby realizing the secure identity authentication between the host and the slave, which specifically includes: After the host and the slave establish a TCP connection, the host generates a first random number based on the cryptographic module and sends it to the slave; The slave generates a second random number based on the cryptographic module, signs the first random number and the second random number based on the slave asymmetric private key, and sends the signatures to the host; The host verifies the signature based on the slave's asymmetric public key to authenticate the slave. The host signs the second random number based on the host asymmetric private key and sends it to the slave; The slave verifies the signature based on the host's asymmetric public key, completes the host's identity authentication after verification, and returns a confirmation message.
3. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol according to claim 1, characterized in that: The host and the slave negotiate an encryption key based on the national secret algorithm, specifically including: The host generates a first symmetric key based on the hardware cryptographic module, encrypts it based on the slave public key to obtain a first encrypted ciphertext, and signs the first encrypted ciphertext based on the host asymmetric private key to generate a first signed message, thereby sending the first encrypted ciphertext and the first signed message to the slave; The slave verifies the first signed message based on the slave asymmetric public key, and after the verification is passed, decrypts the first encrypted ciphertext based on the slave asymmetric private key to obtain a first symmetric key as an encryption key; Both the master and the slave use the first symmetric key as an encryption key.
4. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol according to claim 1, characterized in that: The host and the slave perform data transmission based on the improved Modbus TCP protocol based on the encryption key, specifically including: The host encrypts the function code and data of the plaintext protocol data unit in the improved Modubus TCP protocol based on the encryption key to generate a second ciphertext and sends it to the slave; The slave decrypts the received second ciphertext based on the encryption key to obtain a plaintext, and obtains a function code, data and a random number based on the plaintext; The slave performs operations based on the obtained function code and data, and sends the operation results to the host based on the encryption key.
5. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol according to claim 1, characterized in that: The host and the slave are both configured with a random number storage table for storing random number segments, and each communication between the host and the slave compares the random number segments in the Modbus TCP message with the data stored in the random number table to achieve anti-replay; A shared key configuration table is configured between the host and the slave for sharing an initial public key.
6. A secure communication method based on a national secret algorithm and an improved Modbus TCP protocol according to claim 5, characterized in that: Each communication between the host and the slave compares the random number field in the Modbus TCP message with the data stored in the random number table to achieve anti-replay, specifically including: If the random number in the message already exists in the random number storage table, it indicates that the message being transmitted is a replayed message, and the host / slave discards the message being transmitted and does not process it; If the random number is not in the random number table, the random number in the message is placed in the random number table, and the host / slave performs corresponding operations based on the received function code and data.
7. A secure communication system for running the secure communication method based on the national secret algorithm and the improved Modbus TCP protocol as described in any one of claims 1 to 6, characterized in that: It includes a host and several slaves based on improved Modbus TCP protocol communication. The host and the slave both include at least a Modbus application module, a security protocol parsing and encapsulation module and a password module. The security protocol parsing and encapsulation module responds to the instruction issued by the Modbus application module and sends the parsed instruction to the Modbus application module; The security protocol parsing and encapsulation module encapsulates the issued instructions into messages to be sent based on the improved Modbus TCP protocol, or parses the decrypted messages into instructions to be executed; The cryptographic module is used for cryptographic operations of the host and slave, generating public and private keys based on the national secret algorithm and adding random numbers to messages to be sent, as well as encrypting and signing messages to be sent, verifying signatures and decrypting received messages.