A hybrid encryption method based on industrial bus

By adopting a hybrid encryption method in the industrial bus communication system, combining multiple elliptic curve collaborative optimization algorithm and deep learning algorithm, the problem of difficult balance of efficiency and security in a high dynamic environment is solved, and efficient and flexible key management and encryption strategies are realized.

CN119363455BActive Publication Date: 2025-05-06SUZHOU XINWANGFENG INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411523841.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-30
Publication Date
2025-05-06
Estimated Expiration
2044-10-30

AI Technical Summary

Technical Problem

When handling large-scale and high-real-time data transmission, existing industrial bus communication systems face the problem of balancing efficiency and security, and are difficult to adapt to dynamic network changes in high-dynamic environments, and there are problems such as key leakage and encryption delay.

Method used

Adopting hybrid encryption method based on industrial buses, combining multiple elliptic curve collaborative optimization algorithms, intelligent classifiers, dynamic key management systems and deep learning algorithms, we realize adaptive key generation, intelligent data priority classification, pseudo-random number generator and real-time update of keys.

Benefits of technology

It improves the security and efficiency of data transmission, realizes the flexibility and efficient encryption of key management, and is suitable for industrial control systems with high concurrency, large data volume and real-time performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119363455B_ABST
    Figure CN119363455B_ABST
Patent Text Reader

Abstract

The present invention discloses a hybrid encryption method based on industrial bus, comprising the following steps: S1, using multiple elliptic curve algorithms to generate initial session keys, and generating initial key pairs through pseudo-random number generators; S2, using primary keys to encrypt control data; S3, generating secondary keys to encrypt ordinary transmission data; S4, using pseudo-random number generators to dynamically generate three-level temporary session keys to encrypt large amounts of real-time transmission data; S5, realizing collaborative key generation and synchronous update of multiple communication nodes through a distributed key management system; S6, regularly using probability density regression forest algorithms to dynamically update keys, and triggering key renegotiation when communication anomalies are detected; S7, integrating a classifier based on a combination of deep forests and gradient boosting decision trees to automatically classify data and dynamically adjust encryption strategies. The present invention combines multiple elliptic curve algorithms and dynamic key management, etc., to achieve efficient encryption in industrial bus communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial automation and network security, and in particular to a hybrid encryption method based on an industrial bus. Background Art

[0002] In modern industrial control systems, industrial bus, as an important means of communication, is widely used in data transmission and control signal interaction between various automation devices. However, with the increasing complexity of industrial control systems, especially under the promotion of Industry 4.0 and intelligent manufacturing, data interaction between industrial equipment is frequent, the amount and type of communication data are increasing, and security issues have become particularly prominent. Existing industrial bus communication systems usually rely on traditional encryption methods, such as symmetric encryption algorithms (such as AES) and asymmetric encryption algorithms (such as RSA) to protect the confidentiality, integrity and authenticity of data. However, traditional encryption methods face the problem of balancing efficiency and security when dealing with large-scale, high-real-time data transmission.

[0003] Although existing symmetric encryption algorithms have high encryption efficiency when the amount of data is large, their security depends on the confidentiality of the key and the soundness of key management. In a highly dynamic environment such as an industrial bus, the long-term non-update of the key is prone to the risk of key leakage, which in turn threatens the entire communication system. On the other hand, although asymmetric encryption algorithms, such as RSA, can provide higher security, their computational complexity is high when processing large amounts of data transmission, which easily leads to delays and is difficult to meet the strict real-time requirements in industrial control systems. Existing technologies usually find it difficult to find an optimal balance between security and efficiency.

[0004] With the high degree of interconnection of industrial control systems, the threat of network attacks is also increasing, such as man-in-the-middle attacks, replay attacks, and distributed denial of service attacks. These attack methods can bring serious security risks to production processes and equipment control by monitoring or tampering with data transmission on industrial buses. When preventing such attacks, existing technologies mainly rely on static encryption schemes and preset key update mechanisms, which are difficult to adapt to dynamic changes in the network. When the network load, transmission rate or external environment changes, the traditional static encryption mechanism cannot respond in time, which easily leads to encryption failure or data leakage.

[0005] In addition, existing key management systems usually rely on centralized key management, which easily creates a single point of failure risk in industrial buses. Once the key management system of a key node fails, the encryption mechanism of the entire system will fail, affecting the security of data transmission. Although some industrial systems have introduced distributed key management systems, these systems still face synchronization problems and security threats during key generation and distribution, especially in a high-concurrency industrial bus communication environment, where delays and failures in key synchronization will seriously affect the stability of the system.

[0006] When dealing with key management issues in dynamic environments, the update mechanism of existing technologies is often executed periodically. Even if no abnormality is detected during the communication process, the key will still be updated at the preset time. This approach not only increases the computing and communication overhead, but also in actual operation, since the network status and security risks change at any time, the regular update mechanism cannot be flexibly adjusted according to system requirements, resulting in encryption strategies that are difficult to adapt to data streams with different security levels and communication requirements. At the same time, existing technologies also lack the ability to classify real-time transmission data and cannot dynamically adjust the encryption strength according to the priority and risk level of the data. For high-priority control data and low-priority sensor data, the existing encryption mechanism does not differentiate and process them according to the sensitivity and real-time nature of the data, which may lead to unnecessary waste of encryption resources in some cases, or provide insufficient security protection when facing high-risk data.

[0007] In order to solve these problems in the existing technology, many researchers have proposed a variety of improvement schemes, such as dynamic key update mechanism, intelligent key generation algorithm and encryption strategy optimization model based on machine learning. However, most of these schemes are simply superpositions of existing technologies, lacking overall collaborative optimization, especially when dealing with high concurrency, large data volume and real-time communication environment such as industrial bus, there are still limitations. Although some existing encryption optimization methods based on machine learning can predict risks based on some historical data, these methods have slow response speeds when facing new attacks or data fluctuations, and it is difficult to provide timely encryption adjustments in a highly dynamic environment. In addition, existing encryption optimization models usually rely only on a single data feature to select encryption strategies, and fail to combine multi-dimensional data features (such as transmission rate, node load, data volume and latency) for comprehensive evaluation, resulting in insufficient accuracy and flexibility of encryption decisions.

[0008] Therefore, how to provide a hybrid encryption method based on an industrial bus is a problem that those skilled in the art urgently need to solve. Summary of the invention

[0009] One purpose of the present invention is to propose a hybrid encryption method based on industrial bus, which combines multiple elliptic curve collaborative optimization algorithms, intelligent classifiers and dynamic key management systems, and provides an efficient hybrid encryption method for high concurrency, large data volume and real-time requirements in industrial bus communication environments. Through the collaborative work of adaptive key generation, intelligent data priority classification, pseudo-random number generator and deep learning algorithm, dynamic encryption of data and real-time update of keys are realized, which has significant advantages such as high security, strong encryption flexibility, high system resource utilization, and intelligent key management, and is particularly suitable for industrial control systems that require highly secure and efficient data transmission.

[0010] A hybrid encryption method based on an industrial bus according to an embodiment of the present invention comprises the following steps:

[0011] S1. Between the communication nodes of the industrial bus system, an initial session key is generated using a multi-elliptic curve collaborative optimization algorithm, and an initial key pair for encrypted communication is generated using a pseudo-random number generator;

[0012] S2. Encrypting the control data of the industrial bus system using a primary key, wherein the primary key adopts an RSA algorithm;

[0013] S3, generating a secondary key for encrypting common transmission data, wherein the secondary key adopts the AES algorithm, encrypts the secondary key with the primary key, and transmits it to the recipient;

[0014] S4. During the data transmission process, a pseudo-random number generator is used to dynamically generate a three-level temporary session key, wherein the three-level temporary session key has a short life cycle and is used to encrypt real-time transmission data of a large amount of data;

[0015] S5. A distributed key management system is used to achieve collaborative key generation and synchronous update of multiple communication nodes, and to prevent single point failures and security risks;

[0016] S6. During the communication process, the probability density regression forest algorithm is used to dynamically update the key regularly, and when a communication anomaly is detected, key renegotiation is triggered, and the encryption key is regenerated and distributed to each communication node;

[0017] S7. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to automatically classify data into high priority or low priority according to the characteristics, priority and risk level of real-time transmission data, and dynamically adjust the encryption strategy. The high priority data is transmitted using an asymmetric encryption channel, and the low priority data is transmitted using a symmetric encryption channel.

[0018] Optionally, the S1 specifically includes:

[0019] S11. Preset multi-level key exchange parameters in each communication node of the industrial bus, wherein the key exchange parameters include two elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2), wherein each parameter set defines an elliptic curve, a1, a2, b1 and b2 represent coefficients of the elliptic curve, p1 and p2 represent prime numbers of the elliptic curve, and G1 and G2 represent base points on the elliptic curve;

[0020] S12. When exchanging keys between communication node A and communication node B, node A generates an initial session key by using an adaptive key length selection algorithm, based on the current network load, transmission rate, and preset security level, and selecting and using elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2);

[0021] S13, node A generates a private key d through a dynamic pseudo-random number generator A , the private key d A is a random integer in the range [1, p-1]. Node A uses the private key d A Calculate the public key P A =d A ×G, and the public key P A Sent to node B, while node A generates the initial session key K for encrypted communication A =d A ×G1;

[0022] S14. Node B receives the public key P of node A. A After that, generate the private key d of node B B , the private key d B Generated by a dynamic pseudo-random number generator in the range [1, p-2], node B uses the private key d B Calculate the public key P B =d B ×G, and the public key P B Sent to node A, while node B generates the initial session key K B =d B ×G2;

[0023] S15. After receiving the other party’s public key, the two communicating parties calculate the shared key K through a multi-elliptic curve collaborative optimization algorithm. AB =d A ×P B and K BA =d B ×P A , generate the session key K for initial encryption AB =K BA, and use the session key as part of the initial key pair, node A and node B use the shared key K AB Generate an initial key pair, which serves as an encryption key and a decryption key respectively;

[0024] S16, the generated initial key pair is subjected to secondary randomization processing by an enhanced pseudo-random number generator;

[0025] S17. The selection of elliptic curve parameter set is based on the system's multiple performance evaluation models, including security, computational complexity, and communication delay factors. Elliptic curves such as secp256k1 and secp384r1 are preferred. The elliptic curve equation is y 2 =x 3 +ax+b mod p.

[0026] Optionally, the S3 specifically includes:

[0027] S31, the industrial bus system dynamically generates a secondary key in the sending node A according to the characteristics of the transmitted data, wherein the secondary key is generated according to the real-time characteristics of the transmitted data, including the data volume, transmission rate and security level, and the adaptive key length K2 is determined by a multiple feature analysis algorithm, and the key length is dynamically adjusted to 128 bits, 192 bits or 256 bits;

[0028] S32. Analyze data features in real time, select encryption mode using adaptive encryption strategy, select GCM or CTR encryption mode based on the classification results of transmitted data, and use GCM mode for encryption first for data with high security requirements to ensure data integrity and authentication functions; and use CTR mode for data with high efficiency transmission to improve encryption efficiency;

[0029] S33, at node A, use the adaptive key length K2 to perform normal transmission of data D A Encryption is performed, and the encryption mode is adjusted in real time according to data characteristics:

[0030] C A =AES-GCM(K2,D A );

[0031] C A =AES-CTR(K2,D A );

[0032] Among them, C A Indicates the encrypted ciphertext;

[0033] S34. After completing data encryption, node A generates a secondary key that is optimized through a dynamic key update mechanism. The dynamic key update mechanism combines a pseudo-random number generator with a dynamic key evaluation algorithm to adjust the update frequency of the secondary key according to real-time security requirements. Node A encrypts the secondary key through the primary key:

[0034]

[0035] Among them, e A represents the public key of node A, n represents the modulus of the RSA algorithm, Indicates the encrypted secondary key;

[0036] S35. After obtaining the secondary key, node B uses the secondary key to encrypt the data C. A Decryption is performed. The decryption process is consistent with the encryption mode and uses the same encryption mode as node A:

[0037] D B =AES-GCM -1 (K2,C A );

[0038] D B =AES-CTR -1 (K2,C A );

[0039] Among them, D B Represents the decrypted data.

[0040] Optionally, the S4 specifically includes:

[0041] S41. During the data transmission process, a three-level temporary session key is dynamically generated. The generation of the three-level temporary session key is based on an intelligent load-aware pseudo-random number generator. The intelligent load-aware pseudo-random number generator is adaptively adjusted in combination with the transmission rate, load and inter-node delay of the real-time data stream in the industrial bus. The generation formula is:

[0042] K3 = PRNG-ML (seed, f (L), t);

[0043] Where K3 represents the third-level temporary session key, PRNG-ML represents the pseudo-random number generator based on intelligent load perception, seed represents the preset key seed, f(L) represents the system real-time load function, and t represents the current timestamp;

[0044] S42, adopting a key lifecycle adaptive adjustment mechanism based on data characteristics, evaluating the priority and security level of the transmitted data in real time, and calculating the lifecycle T of the third-level temporary session key K3 K3 :

[0045]

[0046] Among them, S represents the data flow size, R represents the transmission rate, D represents the data type complexity, exp represents the exponential function, P represents the node load state, λ represents the security level of the system, α1, α2, β1, β2, γ and θ represent weight adjustment factors;

[0047] S43, after node A generates the third-level temporary session key, it uses the third-level temporary session key to transmit data D A Encryption is performed using the AES-CTR mode, and the encryption mode is dynamically adjusted in combination with the risk assessment algorithm. If a higher security risk is detected, it is switched to the AES-GCM mode;

[0048] S44. During the data transmission process, the update frequency of the third-level temporary session key is dynamically adjusted through a real-time risk assessment model. The risk assessment model assesses potential attack risks based on the communication behavior of the industrial bus and the external security environment. Each time the industrial bus system is updated, a new key is generated to replace the old key.

[0049] S45. After each data batch encryption is completed, node A transmits the encrypted data and the encrypted third-level temporary session key to receiving node B, where the third-level temporary session key is nested encrypted using the first-level key and the second-level key;

[0050] S46. The receiving node B uses the private key to decrypt the encrypted third-level temporary key, and the decrypted key is used to decrypt the encrypted data.

[0051] Optionally, the S5 specifically includes:

[0052] S51, realize the collaborative key generation and synchronous update of multiple communication nodes through a distributed key management system, each node shares key information with other nodes through a distributed key generation algorithm, the distributed key generation algorithm is based on the Shamir secret sharing algorithm, by splitting the initial key K init Share multiple subkeys and distribute them to each node for encryption:

[0053] K init =a0+a1x+a2x 2 +…+a t x t modp;

[0054] Among them, a0 represents the original key, a1, a2, ..., a t represents the random coefficient, p represents a large prime number, and t represents the threshold for recovering the key;

[0055] The key share obtained by each node is synchronously updated through the global key management system;

[0056] S52. During the key synchronization update process, the status of each communication node is monitored. If a single node is detected to be faulty or the communication is abnormal, the key of the failed node is rebuilt through other healthy nodes. The reconstruction process uses the Lagrange interpolation formula to restore the initial key:

[0057]

[0058] Among them, K i represents the key share held by each node, x i represents the unique identifier of node i, x j represents the unique identifier of node j;

[0059] The rebuilt key will be automatically synchronized to the newly generated or restored node;

[0060] S53, the distributed key management system regularly performs multi-node collaborative updates, and each node periodically generates a new subkey The update request is broadcasted to the entire network, and each node reaches consensus through a distributed consensus algorithm;

[0061] S54: During the key update process, if a potential security threat is detected, the key re-negotiation mechanism is automatically triggered to regenerate the global key K rekey ;

[0062] S55. The key generation and update of each node will be checked for state consistency regularly. The hash function is used to verify whether the key held by each node is consistent with the global key. If the hash function is inconsistent, the exception handling process is triggered and the key synchronization is re-executed.

[0063] S56. Introduce a hierarchical key generation mechanism, use different levels of keys for communication data with different security levels, and use global keys to encrypt critical data first, while ordinary data is encrypted using keys generated by local nodes.

[0064] Optionally, the S6 specifically includes:

[0065] S61. Dynamically update the key during the communication process through the probability density regression forest algorithm. Each time the key is updated, the optimal update time point of the key is calculated based on the multi-dimensional characteristics of the transmitted data:

[0066]

[0067] Among them, T opt represents the optimal key update time, P(t|X i) represents the probability of key update predicted by the PDForest model at a specific time t, X i Represents the multidimensional characteristics of the data stream, w i represents the weight of the regression tree, S i Indicates the data size, R i Indicates the transmission rate, L i represents the transmission delay, P i represents the node load, ζ represents the weight of the data size, ξ represents the control factor, τ represents the weight of the transmission delay on the key update opportunity, ρ and δ represent nonlinear adjustment factors, Z(X) represents the normalization constant, μ represents the weight of the transmission rate, ν represents the weight of the load, θ represents the weight of the data flow size, represents the nonlinear effect of control transmission delay on update frequency, exp represents exponential function, and N represents the total number of data;

[0068] S62, when a communication anomaly is detected, triggering a key renegotiation mechanism, stopping existing communication and generating a new encryption key;

[0069] S63. After the key re-negotiation is completed, the system distributes the new session key to all communication nodes through a secure channel, and the distribution process adopts RSA encryption;

[0070] S64, adopting a multi-level key update mechanism, for data streams of different priorities, the system preferentially performs key update for high-priority data;

[0071] S65. Analyze the communication data characteristics in real time through a recurrent neural network, predict potential security threats, and adjust the key update frequency based on the prediction results. When a potential attack is detected, increase the key update frequency immediately.

[0072] Optionally, the S7 specifically includes:

[0073] S71. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to analyze the characteristics of real-time transmission data, automatically classify the transmission data into high priority or low priority according to priority and risk level, and construct a data feature vector Y, wherein the data feature vector Y includes data size, transmission rate, transmission delay, node load, and historical risk data;

[0074] S72. Calculate the priority of the transmitted data based on the data feature vector Y:

[0075]

[0076] Among them, P class(Y) represents the priority classification result of the transmitted data, 1 represents high priority, 0 represents low priority, S represents data size, R represents transmission rate, L represents transmission delay, P represents node load, F represents the risk level of the current transmission, exp represents exponential function, θ1 represents the threshold of high priority classification, θ2 represents the threshold of low priority classification, α p , β p , γ p , δ p and represents the adjustment factor, F hist Represents historical risk data;

[0077] S73, after the classifier automatically classifies the transmission data into high priority or low priority, an encryption channel is dynamically selected, and the high priority transmission data is transmitted through an asymmetric encryption channel, and the transmission data is encrypted using an RSA algorithm;

[0078] S74. For low-priority transmission data, a symmetric encryption channel is used for encryption, and the transmission data is encrypted using the AES algorithm.

[0079] The beneficial effects of the present invention are:

[0080] First, the invention uses a multi-elliptic curve collaborative optimization algorithm to generate the initial session key, effectively solving the problem of low key generation efficiency in traditional encryption methods. Through the adaptive key length selection algorithm, the system can dynamically select the appropriate elliptic curve parameter set based on the current network load, transmission rate and security level, thereby maximizing the computational efficiency of the encryption process while ensuring high security.

[0081] Secondly, the present invention realizes the dynamic generation and adaptive adjustment of the three-level temporary session key by combining the pseudo-random number generator with the dynamic key update mechanism. The intelligent load-aware pseudo-random number generator combines the real-time transmission data flow, node load and delay of the industrial bus to ensure the randomness and security of the key generation process under different communication conditions. The life cycle of the three-level temporary session key is adaptively adjusted according to the characteristics and security level of data transmission, thereby ensuring that the key can be updated in a high-load or high-risk transmission environment, avoiding the security risks caused by long-term key exposure.

[0082] Through the distributed key management system, the present invention further solves the single point failure problem in the existing centralized key management system. In the process of distributed key generation and synchronous update, the Shamir secret sharing algorithm is used to split and distribute the key, and each node collaboratively participates in the generation and maintenance of the key, effectively reducing the risk of key synchronization failure. At the same time, the system can monitor the node status in real time. When a node fails, other healthy nodes can quickly restore the key and synchronize it to the failed node, thereby ensuring the continuity and security of communication.

[0083] Through the probability density regression forest algorithm, the present invention optimizes the key update frequency and timing. Based on the characteristics of real-time data transmission and historical risk assessment, the system can predict the optimal key update time, trigger the key renegotiation mechanism when communication anomalies are detected, and generate new encryption keys in time, thereby preventing potential attacks from threatening communication security. Combined with the threat prediction mechanism of the recurrent neural network model, the system can respond quickly to potential security threats and improve the security protection level by increasing the key update frequency.

[0084] In addition, the present invention integrates a classifier based on a combination of deep forest and gradient boosting decision tree to analyze the characteristics of transmitted data in real time, including data size, transmission rate, delay, load and historical risk level, and automatically divides the data into high priority and low priority. High-priority data, such as control signals and key configuration data, are transmitted using asymmetric encryption channels (such as RSA) to ensure the high security of key data. Low-priority data, such as sensor data, are processed using symmetric encryption channels (such as AES) to improve encryption efficiency and save system resources. The classifier can also dynamically adjust the encryption strategy according to the real-time communication status and external security environment to ensure that the system can automatically enhance the encryption strength when facing high risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0085] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0086] Figure 1 A flow chart of a hybrid encryption method based on industrial bus proposed by the present invention;

[0087] Figure 2 A schematic diagram of generating an initial session key by using a multiple elliptic curve collaborative optimization algorithm of a hybrid encryption method based on an industrial bus proposed in the present invention. DETAILED DESCRIPTION

[0088] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, which only illustrate the basic structure of the present invention in a schematic manner, and therefore only show the components related to the present invention.

[0089] refer to Figure 1 and Figure 2 , a hybrid encryption method based on industrial bus, comprising the following steps:

[0090] S1. Between the communication nodes of the industrial bus system, an initial session key is generated using a multi-elliptic curve collaborative optimization algorithm, and an initial key pair for encrypted communication is generated using a pseudo-random number generator;

[0091] S2. Encrypting the control data of the industrial bus system using a primary key, wherein the primary key adopts an RSA algorithm;

[0092] S3, generating a secondary key for encrypting common transmission data, wherein the secondary key adopts the AES algorithm, encrypts the secondary key with the primary key, and transmits it to the recipient;

[0093] S4. During the data transmission process, a pseudo-random number generator is used to dynamically generate a three-level temporary session key, wherein the three-level temporary session key has a short life cycle and is used to encrypt real-time transmission data of a large amount of data;

[0094] S5. A distributed key management system is used to achieve collaborative key generation and synchronous update of multiple communication nodes, and to prevent single point failures and security risks;

[0095] S6. During the communication process, the probability density regression forest algorithm is used to dynamically update the key regularly, and when a communication anomaly is detected, key renegotiation is triggered, and the encryption key is regenerated and distributed to each communication node;

[0096] S7. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to automatically classify data into high priority or low priority according to the characteristics, priority and risk level of real-time transmission data, and dynamically adjust the encryption strategy. The high priority data is transmitted using an asymmetric encryption channel, and the low priority data is transmitted using a symmetric encryption channel.

[0097] In this implementation, S1 specifically includes:

[0098] S11. Preset multi-level key exchange parameters in each communication node of the industrial bus, wherein the key exchange parameters include two elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2), wherein each parameter set defines an elliptic curve, a1, a2, b1 and b2 represent coefficients of the elliptic curve, p1 and p2 represent prime numbers of the elliptic curve, and G1 and G2 represent base points on the elliptic curve;

[0099] S12. When exchanging keys between communication node A and communication node B, node A generates an initial session key by using an adaptive key length selection algorithm, based on the current network load, transmission rate, and preset security level, and selecting and using elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2);

[0100] S13, node A generates a private key d through a dynamic pseudo-random number generator A , the private key d A is a random integer in the range [1, p-1]. Node A uses the private key d A Calculate the public key P A =d A ×G, and the public key P A Sent to node B, while node A generates the initial session key K for encrypted communication A =d A ×G1;

[0101] S14. Node B receives the public key P of node A. A After that, generate the private key d of node B B , the private key d B Generated by a dynamic pseudo-random number generator in the range [1, p-2], node B uses the private key d B Calculate the public key P B =d B ×G, and the public key P B Sent to node A, while node B generates the initial session key K B =d B ×G2;

[0102] S15. After receiving the other party’s public key, the two communicating parties calculate the shared key K through a multi-elliptic curve collaborative optimization algorithm. AB =d A ×P B and K BA =d B ×P A , generate the session key K for initial encryption AB =K BA, and use the session key as part of the initial key pair, node A and node B use the shared key K AB Generate an initial key pair, which serves as an encryption key and a decryption key respectively;

[0103] S16, the generated initial key pair is subjected to secondary randomization processing by an enhanced pseudo-random number generator;

[0104] S17. The selection of elliptic curve parameter set is based on the system's multiple performance evaluation models, including security, computational complexity, and communication delay factors. Elliptic curves such as secp256k1 and secp384r1 are preferred. The elliptic curve equation is y 2 =x 3 +ax+b mod p.

[0105] In this implementation, S3 specifically includes:

[0106] S31, the industrial bus system dynamically generates a secondary key in the sending node A according to the characteristics of the transmitted data, wherein the secondary key is generated according to the real-time characteristics of the transmitted data, including the data volume, transmission rate and security level, and the adaptive key length K2 is determined by a multiple feature analysis algorithm, and the key length is dynamically adjusted to 128 bits, 192 bits or 256 bits;

[0107] S32. Analyze data features in real time, select encryption mode using adaptive encryption strategy, select GCM or CTR encryption mode based on the classification results of transmitted data, and use GCM mode for encryption first for data with high security requirements to ensure data integrity and authentication functions; and use CTR mode for data with high efficiency transmission to improve encryption efficiency;

[0108] S33, at node A, use the adaptive key length K2 to perform normal transmission of data D A Encryption is performed, and the encryption mode is adjusted in real time according to data characteristics:

[0109] C A =AES-GCM(K2,D A );

[0110] C A =AES-CTR(K2,D A );

[0111] Among them, C A Indicates the encrypted ciphertext;

[0112] S34. After completing data encryption, node A generates a secondary key that is optimized through a dynamic key update mechanism. The dynamic key update mechanism combines a pseudo-random number generator with a dynamic key evaluation algorithm to adjust the update frequency of the secondary key according to real-time security requirements. Node A encrypts the secondary key through the primary key:

[0113]

[0114] Among them, e A represents the public key of node A, n represents the modulus of the RSA algorithm, Indicates the encrypted secondary key;

[0115] S35. After obtaining the secondary key, node B uses the secondary key to encrypt the data C. A Decryption is performed. The decryption process is consistent with the encryption mode and uses the same encryption mode as node A:

[0116] D B =AES-GCM -1 (K2,C A );

[0117] D B =AES-CTR -1 (K2,C A );

[0118] Among them, D B Represents the decrypted data.

[0119] In this implementation, S4 specifically includes:

[0120] S41. During the data transmission process, a three-level temporary session key is dynamically generated. The generation of the three-level temporary session key is based on an intelligent load-aware pseudo-random number generator. The intelligent load-aware pseudo-random number generator is adaptively adjusted in combination with the transmission rate, load and inter-node delay of the real-time data stream in the industrial bus. The generation formula is:

[0121] K3 = PRNG-ML (seed, f (L), t);

[0122] Where K3 represents the third-level temporary session key, PRNG-ML represents the pseudo-random number generator based on intelligent load perception, seed represents the preset key seed, f(L) represents the system real-time load function, and t represents the current timestamp;

[0123] S42, adopting a key lifecycle adaptive adjustment mechanism based on data characteristics, evaluating the priority and security level of the transmitted data in real time, and calculating the lifecycle T of the third-level temporary session key K3 K3 :

[0124]

[0125] Among them, S represents the data flow size, R represents the transmission rate, D represents the data type complexity, exp represents the exponential function, P represents the node load state, λ represents the security level of the system, α1, α2, β1, β2, γ and θ represent weight adjustment factors;

[0126] S43, after node A generates the third-level temporary session key, it uses the third-level temporary session key to transmit data D A Encryption is performed using the AES-CTR mode, and the encryption mode is dynamically adjusted in combination with the risk assessment algorithm. If a higher security risk is detected, it is switched to the AES-GCM mode;

[0127] S44. During the data transmission process, the update frequency of the third-level temporary session key is dynamically adjusted through a real-time risk assessment model. The risk assessment model assesses potential attack risks based on the communication behavior of the industrial bus and the external security environment. Each time the industrial bus system is updated, a new key is generated to replace the old key.

[0128] S45. After each data batch encryption is completed, node A transmits the encrypted data and the encrypted third-level temporary session key to receiving node B, where the third-level temporary session key is nested encrypted using the first-level key and the second-level key;

[0129] S46. The receiving node B uses the private key to decrypt the encrypted third-level temporary key, and the decrypted key is used to decrypt the encrypted data.

[0130] In this implementation manner, S5 specifically includes:

[0131] S51, realize the collaborative key generation and synchronous update of multiple communication nodes through a distributed key management system, each node shares key information with other nodes through a distributed key generation algorithm, the distributed key generation algorithm is based on the Shamir secret sharing algorithm, by splitting the initial key K init Share multiple subkeys and distribute them to each node for encryption:

[0132] K init =a0+a1x+a2x 2 +…+a t x t modp;

[0133] Among them, a0 represents the original key, a1, a2, ..., a t represents the random coefficient, p represents a large prime number, and t represents the threshold for recovering the key;

[0134] The key share obtained by each node is synchronously updated through the global key management system;

[0135] S52. During the key synchronization update process, the status of each communication node is monitored. If a single node is detected to be faulty or the communication is abnormal, the key of the failed node is rebuilt through other healthy nodes. The reconstruction process uses the Lagrange interpolation formula to restore the initial key:

[0136]

[0137] Among them, K i represents the key share held by each node, x i represents the unique identifier of node i, x j represents the unique identifier of node j;

[0138] The rebuilt key will be automatically synchronized to the newly generated or restored node;

[0139] S53, the distributed key management system regularly performs multi-node collaborative updates, and each node periodically generates a new subkey The update request is broadcasted to the entire network, and each node reaches consensus through a distributed consensus algorithm;

[0140] S54: During the key update process, if a potential security threat is detected, the key re-negotiation mechanism is automatically triggered to regenerate the global key K rekey ;

[0141] S55. The key generation and update of each node will be checked for state consistency regularly. The hash function is used to verify whether the key held by each node is consistent with the global key. If the hash function is inconsistent, the exception handling process is triggered and the key synchronization is re-executed.

[0142] S56. Introduce a hierarchical key generation mechanism, use different levels of keys for communication data with different security levels, and use global keys to encrypt critical data first, while ordinary data is encrypted using keys generated by local nodes.

[0143] In this implementation manner, S6 specifically includes:

[0144] S61. Dynamically update the key during the communication process through the probability density regression forest algorithm. Each time the key is updated, the optimal update time point of the key is calculated based on the multi-dimensional characteristics of the transmitted data:

[0145]

[0146] Among them, T opt represents the optimal key update time, P(t|X i) represents the probability of key update predicted by the PDForest model at a specific time t, X i Represents the multidimensional characteristics of the data stream, w i represents the weight of the regression tree, S i Indicates the data size, R i Indicates the transmission rate, L i represents the transmission delay, P i represents the node load, ζ represents the weight of the data size, ξ represents the control factor, τ represents the weight of the transmission delay on the key update opportunity, ρ and δ represent nonlinear adjustment factors, Z(X) represents the normalization constant, μ represents the weight of the transmission rate, ν represents the weight of the load, θ represents the weight of the data flow size, represents the nonlinear effect of control transmission delay on update frequency, exp represents exponential function, and N represents the total number of data;

[0147] S62, when a communication anomaly is detected, triggering a key renegotiation mechanism, stopping existing communication and generating a new encryption key;

[0148] S63. After the key re-negotiation is completed, the system distributes the new session key to all communication nodes through a secure channel, and the distribution process adopts RSA encryption;

[0149] S64, adopting a multi-level key update mechanism, for data streams of different priorities, the system preferentially performs key update for high-priority data;

[0150] S65. Analyze the communication data characteristics in real time through a recurrent neural network, predict potential security threats, and adjust the key update frequency based on the prediction results. When a potential attack is detected, increase the key update frequency immediately.

[0151] In this implementation manner, the S7 specifically includes:

[0152] S71. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to analyze the characteristics of real-time transmission data, automatically classify the transmission data into high priority or low priority according to priority and risk level, and construct a data feature vector Y, wherein the data feature vector Y includes data size, transmission rate, transmission delay, node load, and historical risk data;

[0153] S72. Calculate the priority of the transmitted data based on the data feature vector Y:

[0154]

[0155] Among them, P class(Y) represents the priority classification result of the transmitted data, 1 represents high priority, 0 represents low priority, S represents data size, R represents transmission rate, L represents transmission delay, P represents node load, F represents the risk level of the current transmission, exp represents exponential function, θ1 represents the threshold of high priority classification, θ2 represents the threshold of low priority classification, α p , β p , γ p , δ p and represents the adjustment factor, F hist Represents historical risk data;

[0156] S73, after the classifier automatically classifies the transmission data into high priority or low priority, an encryption channel is dynamically selected, and the high priority transmission data is transmitted through an asymmetric encryption channel, and the transmission data is encrypted using an RSA algorithm;

[0157] S74. For low-priority transmission data, a symmetric encryption channel is used for encryption, and the transmission data is encrypted using the AES algorithm.

[0158] Embodiment 1:

[0159] In order to verify the feasibility of the present invention in implementation, the present invention is applied in an automated control system of a large industrial park for verification. The system mainly realizes communication between devices through the industrial bus protocol. The equipment in the industrial park includes multiple key production equipment such as CNC machine tools, sensors, industrial robots and programmable logic controllers (PLCs). The amount of data transmitted between these devices is huge, and the real-time requirements are extremely high. At the same time, the security requirements are particularly important, especially when transmitting key control instructions. The leakage or tampering of data may cause serious production accidents. The main challenge faced by the industrial bus system is how to improve encryption efficiency and ensure the flexibility of key management while ensuring data security.

[0160] In this embodiment, the traditional static key management mechanism is often difficult to cope with frequent communication changes and data fluctuations between devices, and faces key update delays, resource waste and security risks under high-load environments. The present invention combines multiple elliptic curve collaborative optimization algorithms, dynamic key management and intelligent encryption strategies to achieve efficient data encryption and flexible key management, and applies the method to the control system of the industrial park.

[0161] In order to verify the effectiveness of the present invention, five production lines in the industrial park were selected, each of which includes multiple PLC devices and hundreds of sensors, and all devices interact with each other through the industrial bus. The comparative experiment includes using traditional RSA and AES static encryption schemes as the control group and using the hybrid encryption method of the present invention as the experimental group to perform the same production tasks, and conduct real-time data collection and effect evaluation.

[0162] In the experiment, the initial session key generation of the multiple elliptic curve collaborative optimization algorithm was first performed between all communication nodes of the production line. During peak hours, the data transmission rate of the sensor nodes reached 1Gbps, and the communication delay fluctuated between 5ms and 20ms. The experiment shows that based on the encryption method of the present invention, the communication node A and the node B dynamically select the appropriate elliptic curve parameter set through the adaptive key length selection algorithm. In the process of generating the initial session key, the calculation time is only 12.3ms, which is compared with the 45ms required for the traditional RSA key generation, effectively reducing the communication delay and improving the real-time performance.

[0163] During the data transmission process, the present invention dynamically generates three-level temporary session keys through a pseudo-random number generator, and combines the intelligent load sensing mechanism to dynamically adjust the key life cycle according to the characteristics of the data stream. The experimental group data shows that during the peak period of sensor data transmission, the system can adaptively shorten the update cycle of the three-level temporary key to 1 minute, and increase the key update frequency according to the security level of the transmitted data, thereby ensuring the security of the data. In contrast, the traditional static key management mechanism requires a fixed key update every 5 minutes under the same conditions, which easily causes a waste of resources and unnecessarily increases the encryption overhead in a low-load environment.

[0164] In order to further verify the intelligent adjustment effect of the encryption strategy, the transmission data is prioritized by a classifier composed of a deep forest and a gradient boosting decision tree in the experiment. According to the real-time characteristics of the data, such as data size, transmission rate, delay, node load and historical risk level, the system automatically classifies sensor data and PLC control signals. High-priority data, such as production control signals and key equipment status information, are transmitted using RSA asymmetric encryption channels, with an average data encryption delay of 20ms, while low-priority data, such as temperature sensor and vibration sensor data, are transmitted using AES symmetric encryption channels, with data encryption delays shortened to 5ms, significantly improving overall transmission efficiency. In traditional methods, all data use the same encryption strength, which not only consumes a lot of computing resources, but also reduces encryption efficiency, especially in high-load environments where there is a significant encryption delay, with the highest delay reaching 80ms.

[0165] Throughout the experiment, the system was able to automatically trigger the key renegotiation mechanism for detected communication anomalies. In one experiment, a sudden increase in the sensor data packet loss rate was detected. The system completed the key renegotiation within 1 second, generated a new session key and distributed it to all communication nodes, effectively preventing possible man-in-the-middle attacks. In the control group, the traditional encryption scheme did not detect anomalies and trigger renegotiation in time, resulting in multiple data transmission failures.

[0166] The experiment was run continuously for two weeks, monitoring the data transmission security and encryption efficiency under different loads and communication conditions. The final experimental data showed that the experimental group achieved a 35% reduction in average encryption delay under high load conditions and a 55% reduction under low load conditions through the intelligent encryption strategy, and the overall communication delay of the system decreased by about 42%. At the same time, the intelligent encryption strategy based on deep learning can dynamically adjust the encryption strength according to the real-time characteristics of the data, ensuring that critical data is more securely protected. In contrast, traditional static encryption mechanisms are prone to increased data delays and reduced security under high load environments.

[0167] Table 1 Performance comparison between hybrid encryption method based on industrial bus and traditional encryption method

[0168] Experimental content Experimental group (the present invention) Control group (traditional method) Initial key generation time 12.3ms 45ms Key update cycle (peak period) 1 minute 5 minutes Key update cycle (off-peak period) Dynamic Adjustment 5 minutes Encryption delay (high priority data) 20ms 80ms Encryption delay (low priority data) 5ms 80ms Communication delay reduction ratio 42% - Automatically trigger key renegotiation response time 1 second No automatic trigger

[0169] Table 1 above compares the performance differences between the hybrid encryption method based on industrial bus and the traditional encryption method in multiple key performance indicators. First, in terms of the initial key generation time, the present invention uses a multiple elliptic curve collaborative optimization algorithm to achieve a generation speed of 12.3ms, which is significantly more efficient than the 45ms of the traditional RSA. In terms of the key update cycle, the present invention can adaptively update the key every 1 minute during peak hours, while the traditional method is fixed to update every 5 minutes, and during low peak hours, the present invention has the ability to dynamically adjust, while the traditional method is still a fixed cycle. For the encryption delay of high-priority data, the present invention reduces the delay to 20ms, while the delay of the traditional method reaches 80ms, and the encryption delay of low-priority data is 5ms in the present invention, which is much lower than the 80ms of the traditional method. The overall communication delay reduction ratio of the present invention reaches 42%, while the traditional method does not significantly reduce. At the same time, the present invention has the ability to automatically trigger key renegotiation when a communication anomaly is detected, and the response time is only 1 second, while the traditional method does not have this function. In general, the present invention is superior to traditional encryption methods in both efficiency and security.

[0170] Through the experiment in this industrial park, the hybrid encryption method of the present invention significantly improves the security and efficiency of industrial bus communication, and successfully solves the problems of inflexible key management, difficulty in adapting encryption strategies to dynamic changes, and difficulty in balancing security and efficiency in traditional static encryption schemes. The adaptive encryption strategy of the present invention can flexibly adjust the encryption strength according to the priority and risk level of the data, and at the same time, through the dynamic key management of multiple elliptic curve collaborative optimization algorithms and pseudo-random number generators, it ensures the security and real-time performance of the system in a high-concurrency and high-dynamic environment.

[0171] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical scheme and inventive concept of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.

Claims

1. A hybrid encryption method based on industrial bus, characterized in that: The steps include: S1. Between the communication nodes of the industrial bus system, an initial session key is generated using a multi-elliptic curve collaborative optimization algorithm, and an initial key pair for encrypted communication is generated using a pseudo-random number generator; S2. Encrypting the control data of the industrial bus system using a primary key, wherein the primary key adopts an RSA algorithm; S3, generating a secondary key for encrypting common transmission data, wherein the secondary key adopts the AES algorithm, encrypts the secondary key with the primary key, and transmits it to the recipient; S4. During the data transmission process, a pseudo-random number generator is used to dynamically generate a three-level temporary session key, wherein the three-level temporary session key has a short life cycle and is used to encrypt real-time transmission data of a large amount of data; S5. A distributed key management system is used to achieve collaborative key generation and synchronous update of multiple communication nodes, and to prevent single point failures and security risks; S6. During the communication process, the probability density regression forest algorithm is used to dynamically update the key regularly, and when a communication anomaly is detected, key renegotiation is triggered, and the encryption key is regenerated and distributed to each communication node; S7. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to automatically classify data into high priority or low priority according to the characteristics, priority and risk level of real-time transmission data, and dynamically adjust the encryption strategy. The high priority data is transmitted using an asymmetric encryption channel, and the low priority data is transmitted using a symmetric encryption channel.

2. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S1 specifically includes: S11. Preset multi-level key exchange parameters in each communication node of the industrial bus, wherein the key exchange parameters include two elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2), wherein each parameter set defines an elliptic curve, a1, a2, b1 and b2 represent coefficients of the elliptic curve, p1 and p2 represent prime numbers of the elliptic curve, and G1 and G2 represent base points on the elliptic curve; S12. When exchanging keys between communication node A and communication node B, node A generates an initial session key by using an adaptive key length selection algorithm, based on the current network load, transmission rate, and preset security level, and selecting and using elliptic curve parameter sets (a1, b1, p1, G1) and (a2, b2, p2, G2); S13, node A generates a private key d through a dynamic pseudo-random number generator A , the private key d A is a random integer in the range [1, p-1]. Node A uses the private key d A Calculate the public key P A =d A ×G, and the public key P A Sent to node B, while node A generates the initial session key K for encrypted communication A =d A ×G1; S14. Node B receives the public key P of node A. A After that, generate the private key d of node B B , the private key d B Generated by a dynamic pseudo-random number generator in the range [1, p-2], node B uses the private key d B Calculate the public key P B =d B ×G, and the public key P B Sent to node A, while node B generates the initial session key K B =d B ×G2; S15. After receiving the other party’s public key, the two communicating parties calculate the shared key K through a multi-elliptic curve collaborative optimization algorithm. AB =d A ×P B and K BA =d B ×P A , generate the session key K for initial encryption AB =K BA , and use the session key as part of the initial key pair, node A and node B use the shared key K AB Generate an initial key pair, which serves as an encryption key and a decryption key respectively; S16, the generated initial key pair is subjected to secondary randomization processing by an enhanced pseudo-random number generator; S17. The selection of elliptic curve parameter set is based on the system's multiple performance evaluation models, including security, computational complexity, and communication delay factors.

3. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S3 specifically includes: S31, the industrial bus system dynamically generates a secondary key in the sending node A according to the characteristics of the transmitted data, wherein the secondary key is generated according to the real-time characteristics of the transmitted data, including the data volume, transmission rate and security level, and the adaptive key length K2 is determined by a multiple feature analysis algorithm, and the key length is dynamically adjusted to 128 bits, 192 bits or 256 bits; S32, analyzing data features in real time, adopting an adaptive encryption strategy to select an encryption mode, and selecting a GCM or CTR encryption mode based on the classification result of the transmitted data; S33, at node A, use the adaptive key length K2 to perform normal transmission of data D A Encryption is performed, and the encryption mode is adjusted in real time according to data characteristics: C A =AES-GCM(K2,D A ); C A =AES-CTR(K2,D A ); Among them, C A Indicates the encrypted ciphertext; S34. After completing data encryption, node A generates a secondary key that is optimized through a dynamic key update mechanism. The dynamic key update mechanism combines a pseudo-random number generator with a dynamic key evaluation algorithm to adjust the update frequency of the secondary key according to real-time security requirements. Node A encrypts the secondary key through the primary key: Among them, e A represents the public key of node A, n represents the modulus of the RSA algorithm, Indicates the encrypted secondary key; S35. After obtaining the secondary key, node B uses the secondary key to encrypt the data C. A Decryption is performed. The decryption process is consistent with the encryption mode and uses the same encryption mode as node A: D B =AES-GCM -1 (K2,C A ); D B =AES-CTR -1 (K2,C A ); Among them, D B Represents the decrypted data.

4. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S4 specifically includes: S41. During the data transmission process, a three-level temporary session key is dynamically generated. The generation of the three-level temporary session key is based on an intelligent load-aware pseudo-random number generator. The intelligent load-aware pseudo-random number generator is adaptively adjusted in combination with the transmission rate, load and inter-node delay of the real-time data stream in the industrial bus. The generation formula is: K3 = PRNG-ML (seed, f (L), t); Where K3 represents the third-level temporary session key, PRNG-ML represents the pseudo-random number generator based on intelligent load perception, seed represents the preset key seed, f(L) represents the system real-time load function, and t represents the current timestamp; S42, adopt the key life cycle adaptive adjustment mechanism based on data characteristics, evaluate the priority and security level of the transmitted data in real time, and calculate the life cycle of the third-level temporary session key K3 Among them, S represents the data flow size, R represents the transmission rate, D represents the data type complexity, exp represents the exponential function, P represents the node load state, λ represents the security level of the system, α1, α2, β1, β2, γ and θ represent weight adjustment factors; S43, after node A generates the third-level temporary session key, it uses the third-level temporary session key to transmit data D A Encryption is performed using the AES-CTR mode, and the encryption mode is dynamically adjusted in combination with the risk assessment algorithm. If a higher security risk is detected, it is switched to the AES-GCM mode; S44. During the data transmission process, the update frequency of the third-level temporary session key is dynamically adjusted through a real-time risk assessment model. The risk assessment model assesses potential attack risks based on the communication behavior of the industrial bus and the external security environment. Each time the industrial bus system is updated, a new key is generated to replace the old key. S45. After each data batch encryption is completed, node A transmits the encrypted data and the encrypted third-level temporary session key to receiving node B, where the third-level temporary session key is nested encrypted using the first-level key and the second-level key; S46. The receiving node B uses the private key to decrypt the encrypted third-level temporary key, and the decrypted key is used to decrypt the encrypted data.

5. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S5 specifically includes: S51, realize the collaborative key generation and synchronous update of multiple communication nodes through a distributed key management system, each node shares key information with other nodes through a distributed key generation algorithm, the distributed key generation algorithm is based on the Shamir secret sharing algorithm, by splitting the initial key K init Share multiple subkeys and distribute them to each node for encryption: K init =a0+a1x+a2x 2 +…+a t x t modp; Among them, a0 represents the original key, a1, a2, ..., a t represents the random coefficient, p represents a large prime number, and t represents the threshold for recovering the key; The key share obtained by each node is synchronously updated through the global key management system; S52. During the key synchronization update process, the status of each communication node is monitored. If a single node is detected to be faulty or the communication is abnormal, the key of the failed node is rebuilt through other healthy nodes. The reconstruction process uses the Lagrange interpolation formula to restore the initial key: Among them, K i represents the key share held by each node, x i represents the unique identifier of node i, x j represents the unique identifier of node j; The rebuilt key will be automatically synchronized to the newly generated or restored node; S53, the distributed key management system regularly performs multi-node collaborative updates, and each node periodically generates a new subkey The update request is broadcasted to the entire network, and each node reaches consensus through a distributed consensus algorithm; S54: During the key update process, if a potential security threat is detected, the key re-negotiation mechanism is automatically triggered to regenerate the global key K rekey ; S55. The key generation and update of each node will be checked for state consistency regularly. The hash function is used to verify whether the key held by each node is consistent with the global key. If the hash function is inconsistent, the exception handling process is triggered and the key synchronization is re-executed. S56. Introduce a hierarchical key generation mechanism, use different levels of keys for communication data with different security levels, and use global keys to encrypt critical data first, while ordinary data is encrypted using keys generated by local nodes.

6. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S6 specifically includes: S61. Dynamically update the key during the communication process through the probability density regression forest algorithm. Each time the key is updated, the optimal update time point of the key is calculated based on the multi-dimensional characteristics of the transmitted data: Among them, T opt represents the optimal key update time, P(t|X i ) represents the probability of key update predicted by the PDForest model at a specific time t, X i Represents the multidimensional characteristics of the data stream, w i represents the weight of the regression tree, S i Indicates the data size, R i Indicates the transmission rate, L i represents the transmission delay, P i represents the node load, ζ represents the weight of the data size, ξ represents the control factor, τ represents the weight of the transmission delay on the key update opportunity, ρ and δ represent nonlinear adjustment factors, Z(X) represents the normalization constant, μ represents the weight of the transmission rate, ν represents the weight of the load, θ represents the weight of the data flow size, represents the nonlinear effect of control transmission delay on update frequency, exp represents exponential function, and N represents the total number of data; S62, when a communication anomaly is detected, triggering a key renegotiation mechanism, stopping existing communication and generating a new encryption key; S63. After the key re-negotiation is completed, the system distributes the new session key to all communication nodes through a secure channel, and the distribution process adopts RSA encryption; S64, adopting a multi-level key update mechanism, for data streams of different priorities, the system preferentially performs key update for high-priority data; S65. Analyze the communication data characteristics in real time through a recurrent neural network, predict potential security threats, and adjust the key update frequency based on the prediction results. When a potential attack is detected, increase the key update frequency immediately.

7. The hybrid encryption method based on industrial bus according to claim 1 is characterized in that: The S7 specifically includes: S71. Integrate a classifier based on a combination of deep forest and gradient boosting decision tree to analyze the characteristics of real-time transmission data, automatically classify the transmission data into high priority or low priority according to priority and risk level, and construct a data feature vector Y, wherein the data feature vector Y includes data size, transmission rate, transmission delay, node load, and historical risk data; S72. Calculate the priority of the transmitted data based on the data feature vector Y: Among them, P class (Y) represents the priority classification result of the transmitted data, 1 represents high priority, 0 represents low priority, S represents data size, R represents transmission rate, L represents transmission delay, P represents node load, F represents the risk level of the current transmission, exp represents exponential function, θ1 represents the threshold of high priority classification, θ2 represents the threshold of low priority classification, α p , β p , γ p ,δ p and represents the adjustment factor, F hist Represents historical risk data; S73, after the classifier automatically classifies the transmission data into high priority or low priority, an encryption channel is dynamically selected, and the high priority transmission data is transmitted through an asymmetric encryption channel, and the transmission data is encrypted using an RSA algorithm; S74. For low-priority transmission data, a symmetric encryption channel is used for encryption, and the transmission data is encrypted using the AES algorithm.

Citation Information

Patent Citations

  • Blockchain key sharing and dynamic updating method based on an elliptic curve

    CN109768863A

  • Hybrid encryption and decryption method, equipment and system

    CN110336774A