A secure communication method and system for the MQTT protocol based on a national cryptographic module

By introducing the national secret cryptographic module into the MQTT protocol, using SM2 and SM4 algorithms for signature verification and encryption and decryption, the shortcomings of the MQTT protocol in terms of security and compliance are solved, and the security and compliance communication between devices are achieved.

CN119232499BActive Publication Date: 2025-05-27CHINA TRANSPORT INFORMATION TECH GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411748346.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2025-05-27
Estimated Expiration
2044-12-02

AI Technical Summary

Technical Problem

The MQTT protocol has shortcomings in terms of security, especially the username/password explicit storage and transmission, and the international password algorithms and certificates used do not meet the national password compliance requirements, which pose security risks and compliance issues.

Method used

The secure communication method based on the national secret cryptographic module is adopted, and the SM2 algorithm is used for signature verification and identity authentication, and the SM4 algorithm is used for symmetric encryption and decryption to ensure the security and compliance of the MQTT protocol.

Benefits of technology

It realizes secure identity authentication, data encryption and compliant communication of the MQTT protocol, ensuring the confidentiality, integrity and undeniability of secure communication and data transmission between devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119232499B_ABST
    Figure CN119232499B_ABST
Patent Text Reader

Abstract

The present invention discloses a secure communication method and system for the MQTT protocol based on a national cryptographic module. Both the server and the client communicating based on the MQTT protocol are configured with a national cryptographic module. The secure communication method includes: the server and the client generate an initial key pair based on the national cryptographic module, and perform signature verification based on the national cryptographic algorithm and the initial key pair to achieve secure identity authentication between the server and the client; negotiate an encryption key between the server and the client based on the national cryptographic algorithm; the client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national cryptographic algorithm to the server to verify the client's username and password; perform communication of the MQTT protocol based on the encryption key and the national cryptographic algorithm based on the verification result, integrate the SM2 algorithm signature and verification in the MQTT protocol based on the national cryptographic hardware module, symmetrically encrypt and decrypt the data transmitted by the MQTT protocol using the SM4 algorithm, and design an MQTT protocol compliant with national cryptography to ensure the confidentiality of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a secure communication method and system for the MQTT protocol based on a national cryptography module. Background Art

[0002] MQTT (Message Queuing Telemetry Transport) is a lightweight messaging protocol specifically designed for efficiently and reliably transmitting data in resource-constrained network environments. The MQTT protocol features simplicity, low overhead, and low bandwidth occupancy, and is particularly suitable for communication among Internet of Things (IoT) devices, small devices, and mobile applications.

[0003] There are two implementations of the security mechanism of the MQTT protocol: One is that the MQTT protocol supports username / password authentication to ensure that only authorized devices can connect to the MQTT server. That is, each device is assigned a unique username and password, which are verified on the server side to ensure the server's confirmation of the client's identity. The other is that to ensure the security of this communication, especially when sensitive data or remote control instructions are involved, MQTT usually relies on Transport Layer Security (TLS) or its predecessor Secure Sockets Layer (SSL) to provide encryption, authentication, and data integrity protection, and to implement the authentication and encrypted transmission between the server and the client.

[0004] However, for the security mechanism of the MQTT protocol using username / password authentication, the username and password are stored and transmitted in plain text on both the client side and the server side, and an attacker can easily steal the username and password of the device. When the MQTT protocol is used in combination with the TLS protocol, although it can ensure the secure transmission of data and the authentication of both communication parties, the cryptographic algorithms and digital certificates used in the TLS protocol are all international algorithms and international certificates, which do not meet the requirements of cryptographic compliance.

[0005] The MQTT protocol operates on top of the TCP / IP protocol family. Although MQTT itself only requires the underlying transport layer to provide an ordered and reliable two-way byte stream for transmission, it usually chooses to use TCP as its main transport layer protocol to ensure the reliability of the connection and the sequential transmission of data.

[0006] However, the TCP / IP protocol itself has not yet implemented the security functions of the protocol. First, in the TCP / IP protocol, the IP address is used as the only identifier of network nodes, lacking reliable identity authentication measures for hosts or slaves. An attacker can imitate a host or slave to send malicious instructions. Although the MQTT protocol itself provides some basic security mechanisms such as username / password authentication for identity authentication, the username and password are stored and transmitted in plain text on both the client and the server, and an attacker can easily steal the username and password of the device. Second, the TCP / IP protocol does not encrypt the data in the packet and does not provide data integrity verification measures, and an attacker can obtain key confidential information of the communication transmission through eavesdropping.

[0007] To enhance the security of data transmission, the existing solution is to use the MQTT protocol in combination with the TLS (Transport Layer Security) protocol to form the MQTT over TLS solution. TLS provides three basic security goals for MQTT: confidentiality, integrity, and authentication. By encrypting information, it prevents unauthorized third parties from obtaining sensitive information; through techniques such as message digest, it confirms that the message has not been tampered with during transmission; and through the mechanism of certificates and keys, it confirms the identities of both communication parties.

[0008] However, when the existing solution combines the MQTT protocol with the TLS protocol, first, it must be ensured that the used TLS version and algorithm library are currently considered secure. Second, if the TLS protocol is misconfigured, it may expose security risks or increase the vulnerability of the system. Finally, the currently mainstream cryptographic algorithms and certificates of the TLS protocol are all international cryptographic algorithms and international digital certificates. When used in important information systems or communication between key Internet of Things, Internet of Vehicles, and other devices, they cannot meet the requirements of cryptographic application and security assessment, and there is a situation of non-compliance in cryptographic application. Summary of the Invention

[0009] In order to overcome the above technical deficiencies, the present invention provides a secure communication method and system for the MQTT protocol based on a national cryptographic module to achieve secure communication of the MQTT protocol. Based on the national cryptographic hardware module, the SM2 algorithm signature and verification are integrated into the MQTT protocol, and the SM2 public key is used to encrypt and store the username and password of each client. The SM4 algorithm is used for symmetric encryption and decryption of the data transmitted by the MQTT protocol, and an MQTT protocol compliant with national cryptography is designed to achieve secure and compliant communication of the MQTT protocol between devices and ensure the confidentiality of data.

[0010] The technical solution adopted by the present invention to overcome its technical problems is as follows: In the first aspect of the present invention, a secure communication method for the MQTT protocol based on a national cryptographic module is proposed. Both the server and the client communicating based on the MQTT protocol are configured with a national cryptographic module, where the client is a subscribing end or a publishing end. The specific steps of the secure communication method are as follows: The server and the client generate an initial key pair based on the national cryptographic module, and perform signature verification based on the national cryptographic algorithm and the initial key pair to achieve secure identity authentication between the server and the client; The server and the client negotiate an encryption key based on the national cryptographic algorithm; The client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national cryptographic algorithm to the server for verification of the client's username and password; Based on the verification result, communication of the MQTT protocol is carried out based on the encryption key and the national cryptographic algorithm.

[0011] Further, the server and the client generate an initial key pair based on the national cryptographic module, and perform signature verification based on the national cryptographic algorithm and the initial key pair to achieve secure identity authentication between the server and the client, which specifically includes: The server and the client respectively generate corresponding key pairs based on the national cryptographic module and share the public keys in the key pairs of each other; The server Broker establishes a TCP connection with the client; The server generates a first random number based on the national cryptographic module and sends it to the client; The client generates a second random number based on the national cryptographic module, signs the first random number and the second random number based on the client's private key, and sends the signature data to the server; After receiving the signature data, the server verifies the signature based on the client's public key. If the verification passes, the server signs the second random number based on the server's private key and sends the signature data to the client. If the verification fails, the connection with the corresponding client is closed; The client verifies the signature based on the server's public key. If the verification passes, the client returns a confirmation message to the server to complete the authentication of the server. If the verification fails, the connection with the corresponding server is closed.

[0012] Identity authentication is performed by signing and verifying signatures through the SM2 asymmetric key.

[0013] Further, the server and the client negotiate an encryption key based on the national cryptographic algorithm, which specifically includes: The server generates a symmetric key based on the national cryptographic hardware module, encrypts it with the client's public key to obtain an encrypted ciphertext, and signs the encrypted ciphertext with the server's private key to generate a signature message, and sends the encrypted ciphertext and the signature message to the client; The client verifies the signature message based on the server's public key, and after the verification passes, decrypts the encrypted ciphertext with the client's private key to obtain the symmetric key and returns a confirmation message; Both the server and the client use the symmetric key as the encryption key.

[0014] Negotiate the SM4 symmetric key through the SM2 asymmetric key and SM2 asymmetric encryption.

[0015] Furthermore, each device of the client is assigned a unique client username and password during initial deployment. The client encrypts the client username and password using the public key of the server based on the national cryptographic module.

[0016] Encrypt the username and password according to the SM2 asymmetric key.

[0017] Furthermore, the client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national cryptographic algorithm to the server for verifying the client username and password. Specifically, the client sends a connection message encrypted based on the national cryptographic algorithm and the encryption key to the server. The connection message at least includes the client username and password encrypted based on the public key of the server. The server decrypts the connection message based on the encryption key and decrypts the client username and password based on the private key of the server. The server verifies the client username and password. If the verification passes, the server sends a reply message corresponding to the connection message to the client. If the verification fails, the connection with the corresponding client is closed.

[0018] Furthermore, for the communication of the MQTT protocol based on the encryption key and the national cryptographic algorithm, it at least includes the subscriber of the client subscribing to a topic from the server. Specifically, the subscriber sends the topic information and payload information in the subscription message encrypted based on the national cryptographic algorithm and the encryption key to the server. The server decrypts the received topic information and payload information based on the encryption key and replies a subscription reply message to the subscriber.

[0019] Furthermore, for the communication of the MQTT protocol based on the encryption key and the national cryptographic algorithm, it at least includes the publisher of the client publishing data. Specifically, the publisher sends a publish message and the topic information and payload information in the publish message encrypted based on the national cryptographic algorithm and the encryption key to the server. The server decrypts the received topic information and payload information based on the encryption key and replies a reply message to the publish message. The server sends a publish message to the subscriber and encrypts the topic information and payload information in the publish message based on the national cryptographic algorithm and the encryption key. The subscriber decrypts the topic information and payload information based on the encryption key and then replies a reply message corresponding to the publish message to the server.

[0020] Use the SM4 symmetric key for encrypted data transmission.

[0021] Furthermore, the national cryptographic algorithm adopts a combination of the SM2 asymmetric algorithm and the SM4 symmetric algorithm. Among them, the SM2 asymmetric algorithm is used for signature verification and negotiation of the SM4 symmetric key, and the SM4 symmetric algorithm is used for encrypted data transmission.

[0022] Further, the initial key pair is an SM2 key pair.

[0023] Another aspect of the present invention proposes a secure communication system for operating the above-mentioned secure communication method of the MQTT protocol based on a national cryptography module. The secure communication system at least includes a server and several clients that communicate based on the MQTT protocol. Both the server and the clients are at least configured with a national cryptography module. The national cryptography module at least includes an initial key unit, a signature and verification unit, an asymmetric encryption and decryption unit, a random number unit, a key unit, and a symmetric encryption and decryption unit. The initial key unit is used to generate an initial asymmetric key for the device; the random number unit is used to generate random numbers; the key unit is used to generate symmetric keys; the signature verification unit is used to perform signature verification based on random numbers and the initial asymmetric key to achieve secure identity authentication between the server and the clients; the asymmetric encryption and decryption unit is used to encrypt and decrypt the username and password of the client based on the initial asymmetric key, and is also used to negotiate an encryption key based on the symmetric key and the initial asymmetric key; the symmetric encryption and decryption unit is used to encrypt and decrypt the messages transmitted by the MQTT protocol based on the encryption key.

[0024] The hardware national cryptography module has a commercial cryptography product model certificate issued by the National Cryptography Administration, can meet the information security compliance requirements of the application system, can be used for secure management / storage of keys, and is a hardware device that can provide cryptographic calculation operations. This module is generally connected to the device in the form of an expansion or an external device.

[0025] The beneficial effects of the present invention are as follows:

[0026] 1. By configuring the hardware national cryptography module, cryptographic algorithm operations, signature verification, key generation, and random number generation are realized, thereby supporting the implementation of the national cryptography algorithm MQTT protocol communication of the device and meeting the information security compliance requirements of the application system;

[0027] 2. Through technologies such as digital signature, key negotiation, and data encryption of the national cryptography algorithm, the confidentiality, integrity, and non-repudiation of communication and data transmission using the MQTT protocol can be achieved;

[0028] 3. By adopting SM2 signature verification for identity authentication and verifying the username and password according to the SM4 algorithm and the SM4 symmetric key, the identities of both communication parties are confirmed multiple times to ensure the transmission security of the MQTT protocol. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 It is a schematic flowchart of a secure communication method of the MQTT protocol based on a national cryptography module according to an embodiment of the present invention;

[0030] Figure 2 Schematic diagram of the process for secure identity authentication between the server and the client in the embodiment of the present invention;

[0031] Figure 3 Schematic diagram of the process for negotiating an encryption key between the server and the client in the embodiment of the present invention based on the national cryptographic algorithm;

[0032] Figure 4 Schematic diagram of the process for the MQTT protocol communication between the server and the client in the embodiment of the present invention based on the encryption key and the national cryptographic algorithm. Detailed implementation manners

[0033] To facilitate better understanding of the present invention by those skilled in the art, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. The following is only exemplary and does not limit the protection scope of the present invention.

[0034] As Figure 1 shown, the schematic diagram of the process of a secure communication method based on the MQTT protocol with a national cryptographic module in this embodiment. Both the server and the client communicating based on the MQTT protocol are configured with a national cryptographic module, where the client is a subscribing end or a publishing end.

[0035] Among them, the hardware national cryptographic module has a commercial cryptographic product model certificate issued by the National Cryptography Administration, can meet the information security compliance requirements of the application system, can be used for secure management / storage of keys, and is a hardware device that can provide cryptographic calculation operations. This module is generally connected to the device in the form of an expansion or an external device. The secure communication method based on the MQTT protocol with a national cryptographic module in this embodiment specifically includes the following steps.

[0036] S1. The server and the client generate an initial key pair based on the national cryptographic module, and perform signature verification based on the national cryptographic algorithm and the initial key pair to achieve secure identity authentication between the server and the client.

[0037] The schematic diagram of the process for secure identity authentication between the server and the client is as Figure 2 shown, and specifically includes the following steps.

[0038] S11. The server and the client respectively generate corresponding initial asymmetric key pairs based on the national cryptographic module, and share the public keys in each other's key pairs.

[0039] The server and the client have generated the initial SM2 key pairs of the device through the national cryptographic module, and the server Broker and the client share the initial SM2 public keys with each other through installation and configuration before communication.

[0040] S12. The server Broker and the client establish a TCP connection.

[0041] S13. The server Broker generates a first random number R1 through the hardware national cryptography password module and sends it to the client.

[0042] S14. The client generates a second random number R2 through the hardware national cryptography password module, signs the first random number R1 and the second random number R2 using the client's initial SM2 private key, and sends the signature data to the server.

[0043] S15. After receiving the signature data, the server Broker verifies the signature using the client public key to complete the authentication of the client; if the signature verification fails, the connection with the corresponding client is closed; if the signature verification passes, the server Broker signs the client's second random number R2 using the server SM2 private key and sends the signature data to the client.

[0044] S16. After receiving the signature data, the client verifies the signature data using the server public key to complete the authentication of the server. If the signature verification fails, the connection with the corresponding server is closed. If the signature verification passes, a confirmation message is returned.

[0045] S2. The server and the client negotiate an encryption key based on the national cryptography algorithm.

[0046] The schematic diagram of the process for the server and the client to negotiate an encryption key based on the national cryptography algorithm is as Figure 3 shown, and specifically includes the following steps.

[0047] S21. The server Broker generates a 16-byte symmetric key K through the national cryptography password module, encrypts it into a ciphertext C using the client SM2 public key, signs the ciphertext C using the server Broker SM2 private key to generate a signature message Sc, and sends the encrypted ciphertext C and the signature message Sc to the client;

[0048] S22. The client receives the encrypted ciphertext C and the signature message Sc, verifies the signature message Sc using the client SM2 public key, and after the verification passes, decrypts C using the client's own SM2 private key to obtain K and returns a confirmation message.

[0049] S23. The server Broker and the client use the symmetric key K as the encryption key for encrypting data transmission between the two parties.

[0050] S3. The client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national cryptography algorithm to the server for verifying the client username and password.

[0051] As Figure 4As shown in the figure, it is a flowchart of the data transmission process between the server and the client. Each device of the client is assigned a unique client username and password during initial deployment. The username and password of the client are encrypted using the SM2 public key of the server Broker by the hardware national cryptography password module and stored for the server side to verify the client during MQTT communication. The client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national cryptography algorithm to the server for verification of the client username and password, which mainly includes the following processes.

[0052] S31, the client sends a connection message of the MQTT protocol encrypted based on the national cryptography algorithm and the encryption key, that is, the CONNECT message, to the server. The connection message at least includes the username and password of the client encrypted based on the server public key.

[0053] The payload message Payload in the CONNECT message at least includes the above-mentioned client username and password encrypted using the SM2 public key.

[0054] The national cryptography algorithm used for encrypting the message during the data transmission process is the SM4 algorithm.

[0055] S32, the server decrypts the CONNECT message based on the encryption key and decrypts the username and password of the client in the payload message Payload based on the server SM2 private key.

[0056] S33, the server verifies the username and password of the client. If the verification of the client username and password passes, the server sends a reply message corresponding to the CONNECT message, that is, the CONNACK message, to the client and proceeds with the data transmission in the subsequent step S4.

[0057] It should be noted that the replied CONNACK message only has a message header and does not include a payload, so there is no need for encryption. For example, the replied CONNACK message indicates the success of this connection, the message length supported for communication, and the supported functions.

[0058] If the verification of the client username and password fails, the connection with the corresponding client is closed.

[0059] S4, based on the verification result, perform communication of the MQTT protocol based on the encryption key and the national cryptography algorithm.

[0060] In an embodiment of the present invention, taking the transmission methods of the commonly used PUBLISH, PUBACK, SUBSCRIBE, and SUBACK messages in the encrypted communication process of the MQTT protocol as examples, the communication of the MQTT protocol between the server and the client based on the encryption key and the national cryptography algorithm is described.

[0061] The process by which the subscription end of the client subscribes to a topic from the server includes the following steps:

[0062] S411, the subscription end sends the topic information and payload information in the SUBSCRIBE message encrypted based on the SM4 national cryptography algorithm and the encryption key to the server.

[0063] The subscription end encrypts the two parts of the topic information (Topic) and payload information (payload) transmitted in the protocol through the encryption key K to generate the ciphertext E, E = SM4_enc(Topic||payload).

[0064] S412, the server decrypts the received topic information and payload information based on the encryption key K and replies with a subscription reply message to the subscription end.

[0065] The server decrypts the received ciphertext E according to the encryption key K (Topic||payload) = SM4_dec(E) to obtain the message topic (Topic) and payload (payload) sent by the client.

[0066] The process by which the publishing end publishes data includes the following steps:

[0067] S421, the publishing end sends the topic information and payload information in the PUBLISH message encrypted based on the SM4 national cryptography algorithm and the encryption key to the server.

[0068] S422, the server decrypts the received topic information and payload information based on the encryption key K and replies with the corresponding PUBACK message to the publishing end.

[0069] S423, the server sends the topic information and payload information in the PUBLISH message encrypted based on the SM4 national cryptography algorithm and the encryption key to the subscription end.

[0070] S424, after decrypting the topic information and payload information based on the encryption key, the subscription end replies with the corresponding PUBACK message to the server.

[0071] Another embodiment of the present invention also proposes a secure communication system for running the secure communication method based on the above MQTT protocol based on the national cryptography module. Among them, the secure communication system at least includes a server communicating based on the MQTT protocol and several clients, and both the server and the clients are at least configured with a national cryptography module.

[0072] The national secret cipher module at least includes an initial key unit, a signature and verification unit, an asymmetric encryption and decryption unit, a random number unit, a key unit, and a symmetric encryption and decryption unit. The initial key unit is used to generate the initial asymmetric key of the device; the random number unit is used to generate random numbers; the key unit is used to generate symmetric keys; the signature and verification unit is used to perform signature and verification based on random numbers and the initial asymmetric key to achieve secure identity authentication between the server and the client; the asymmetric encryption and decryption unit is used to encrypt and decrypt the username and password of the client based on the initial asymmetric key, and is used to negotiate an encryption key based on the symmetric key and the initial asymmetric key; the symmetric encryption and decryption unit is used to encrypt and decrypt the messages transmitted by the MQTT protocol based on the encryption key.

[0073] A secure communication method and system based on the MQTT protocol using the national secret cipher module proposed by the present invention, based on the generation of an initial public-private key pair by the national secret cipher module, supports multiple functions such as asymmetric encryption and decryption, generation of random numbers, generation of symmetric keys, and symmetric encryption and decryption. First, use the SM2 signature and verification technology to implement a secure identity authentication mechanism between the server Broker and the client; then use the SM2 asymmetric encryption technology to securely negotiate an SM4 symmetric key for encrypting transmitted data between the server Broker and the client; finally, use the negotiated SM4 symmetric key to encrypt and transmit the transmitted data, thereby realizing MQTT protocol communication based on the national secret algorithm and ensuring the confidentiality of data.

[0074] It should be noted that: in other embodiments, the steps of the corresponding methods are not necessarily executed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may also be combined into a single step for description in other embodiments.

[0075] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the system or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments. The systems and system embodiments described above are only illustrative, and some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0076] Those skilled in the art will appreciate that the elements and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of functionality in the foregoing description. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints of the technical solution. Those skilled in the art may implement the described functionality in different ways for each particular application, but such implementation should not be regarded as exceeding the scope of the present invention.

Claims

1. A secure communication method based on the MQTT protocol of the national secret password module, characterized in that: The server and client based on MQTT protocol communication are both equipped with national secret password modules, where the client is the subscriber or publisher. The secure communication method specifically includes: The server and the client generate an initial key pair based on the national secret password module, and perform signature verification based on the national secret algorithm and the initial key pair to achieve secure identity authentication between the server and the client. The national secret algorithm adopts a combination of the SM2 asymmetric algorithm and the SM4 symmetric algorithm, wherein the SM2 asymmetric algorithm is used for signature verification and negotiation of the SM4 symmetric key, the SM4 symmetric algorithm is used for data encryption transmission, and the initial key pair is the SM2 key pair; The server and client negotiate encryption keys based on the national secret algorithm; The client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national encryption algorithm to the server to verify the client username and password; Based on the verification results, the MQTT protocol based on encryption keys and national secret algorithms is used for communication; The client sends a connection message of the MQTT protocol encrypted based on the encryption key and the national encryption algorithm to the server to verify the client username and password, specifically including: The client sends a connection message of the MQTT protocol encrypted based on the national secret algorithm and encryption key to the server, where the connection message includes at least the client's username and password encrypted based on the server's public key; The server decrypts the connection message based on the encryption key, and decrypts the client's username and password based on the server's private key; The server verifies the client's username and password. If the verification is successful, the server replies to the client with a reply message corresponding to the connection message. If the verification fails, the server closes the connection with the corresponding client.

2. According to claim 1, a secure communication method based on the MQTT protocol of the national secret password module is characterized in that: The server and the client generate an initial key pair based on the national secret password module, and perform signature verification based on the national secret algorithm and the initial key pair to achieve secure identity authentication between the server and the client, specifically including: The server and the client generate corresponding key pairs based on the national secret password module respectively, and share the public key in each other's key pair; The server establishes a TCP connection with the client; The server generates a first random number based on the national secret code module and sends it to the client; The client generates a second random number based on the national secret password module, signs the first random number and the second random number based on the client private key, and sends the signature data to the server; After receiving the signed data, the server verifies the signature based on the client public key. If the verification is successful, the server signs the second random number based on the server private key and sends the signature data to the client. If the verification fails, the connection with the corresponding client is closed; The client verifies the signature based on the server public key. If the verification succeeds, the client returns a confirmation message to the server to complete the server's identity authentication. If the verification fails, the client closes the connection with the corresponding server.

3. According to claim 1, a secure communication method based on the MQTT protocol of the national secret password module is characterized in that: The server and the client negotiate an encryption key based on the national secret algorithm, specifically including: The server generates a symmetric key based on the national secret hardware cryptographic module, encrypts it based on the client public key to obtain an encrypted ciphertext, and signs the encrypted ciphertext based on the server private key to generate a signed message, and sends the encrypted ciphertext and signed message to the client; The client verifies the signed message based on the server public key, and after verification, decrypts the encrypted ciphertext based on the client private key to obtain the symmetric key, and returns a confirmation message; Both the server and the client use the symmetric key as the encryption key.

4. According to claim 1, a secure communication method based on the MQTT protocol of the national secret password module is characterized in that: Each device of the client is assigned a unique client username and password during initial deployment, and the client encrypts the client username and password using the server public key based on the national secret password module.

5. The secure communication method according to claim 1, characterized in that: The communication based on the MQTT protocol with encryption keys and national encryption algorithms at least includes the client's subscriber subscribing to a topic from the server, specifically including: The subscriber sends the subject information and load information in the subscription message encrypted based on the national encryption algorithm and encryption key to the server; The server decrypts the received topic information and payload information based on the encryption key, and replies with a subscription reply message to the subscriber.

6. The secure communication method according to claim 1, characterized in that: The communication based on the MQTT protocol with encryption keys and national encryption algorithms at least includes the publishing end of the client publishing data, specifically including: The publisher sends a publishing message to the server, and encrypts the subject information and payload information in the publishing message based on the national encryption algorithm and encryption key; The server decrypts the received topic information and payload information based on the encryption key, and replies with a reply message to the published message; The server sends a publishing message to the subscriber and encrypts the subject information and load information in the publishing message based on the national encryption algorithm and encryption key. The subscriber decrypts the topic information and payload information based on the encryption key and replies to the server with a reply message corresponding to the published message.

7. A secure communication system for running the secure communication method of the MQTT protocol based on the national secret password module according to any one of claims 1 to 6, characterized in that: The secure communication system at least includes a server and several clients communicating based on the MQTT protocol. The server and the client are both equipped with at least a national secret password module. The national secret code module at least includes an initial key unit, a signature and verification unit, an asymmetric encryption and decryption unit, a random number unit, a key unit and a symmetric encryption and decryption unit. The initial key unit is used to generate an initial asymmetric key for the device; The random number unit is used to generate random numbers; The key unit is used to generate a symmetric key; The signing and verification unit is used to perform signature verification based on a random number and an initial asymmetric key to achieve secure identity authentication of the server and the client; The asymmetric encryption and decryption unit is used to encrypt and decrypt the user name and password of the client based on the initial asymmetric key, and to negotiate an encryption key based on the symmetric key and the initial asymmetric key; The symmetric encryption and decryption unit is used to encrypt and decrypt messages transmitted by the MQTT protocol based on an encryption key.