Data distribution method and apparatus, communication device, and storage medium
By introducing QoS3 (Quality of Service Level 3) and encryption processing from the security module into the industrial PON system, the problem that the MQTT protocol cannot meet the security requirements of sensitive data in industrial PON applications is solved, thereby improving the security and reliability of data distribution.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
- Filing Date
- 2024-12-31
- Publication Date
- 2026-04-17
AI Technical Summary
In traditional industrial PON applications, the QoS level of the MQTT protocol can only guarantee the reliability of message data, which cannot meet the security requirements of sensitive data in industrial scenarios, resulting in poor security of message data distribution.
The target service quality level QoS3 is introduced. The target instructions are encrypted through a security module to generate encrypted message data. Interaction messages of the target protocol type are introduced into the MQTT protocol to ensure the security of messages during transmission.
In industrial PON systems, the secure forwarding of sensitive data is achieved, preventing message data from being attacked and tampered with, and improving the security and reliability of data distribution.
Smart Images

Figure CN119696921B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial passive optical network technology, and in particular to a data distribution method, apparatus, communication equipment, and storage medium. Background Technology
[0002] With the combined development of the Internet and the industrial sector, industrial PON (Passive Optical Network) technology has emerged, which enables the interconnection of various industrial equipment in factories.
[0003] In traditional technologies, MQTT (Message Queuing Telemetry Transport) is commonly used for message distribution in industrial PON applications. The controller and industrial gateway in the industrial PON application act as clients, subscribing to and publishing messages to the broker. The broker forwards messages to different clients, and the QoS (Quality of Service) level in the MQTT protocol controls the number of times the message data is processed.
[0004] However, in industrial scenarios, there are sensitive data in the message data transmitted, which have high security requirements. In traditional technology, the QoS level of the MQTT protocol only constrains the reliability of message data processing, resulting in poor security of message data distribution in industrial scenarios. Summary of the Invention
[0005] This application provides a data distribution method, apparatus, communication device, and storage medium that can prevent message data in target messages from being attacked and tampered with, and can also improve the security of message data distribution in industrial scenarios.
[0006] In a first aspect, this application provides a data distribution method, the method being applied to a first client, the method comprising:
[0007] Obtain the target instruction and identify the service quality level corresponding to the target instruction;
[0008] If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data;
[0009] Based on the target quality of service level and the encrypted message data, a target message under the target protocol is generated, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0010] In one embodiment, the quality of service level in the target protocol includes the target quality of service level; before obtaining the target instruction and identifying the quality of service level corresponding to the target instruction, the method further includes:
[0011] In the target protocol, the service quality level is determined when both target bits are 1, based on the two target bits representing the service quality level.
[0012] In one embodiment, after generating a target message under a target protocol based on the target quality of service level and the encrypted message data, and sending the target message to a message server based on the target protocol, and instructing the message server to forward the target message to the second client, the method further includes:
[0013] The message server receives encrypted feedback based on the target protocol type of the interaction message; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0014] In one embodiment, the encrypted feedback between the interaction message based on the target protocol type and the message server includes:
[0015] In response to the first encrypted message fed back by the message server, a second encrypted message is sent to the message server;
[0016] In response to the third encrypted message fed back by the message server, the storage state information of the target message is released.
[0017] Secondly, this application provides a data distribution method, which is applied to a second client, the method comprising:
[0018] Receive a target message sent by a message server, the target message carrying a quality of service level;
[0019] If the service quality level is the target service quality level, the encrypted message data in the target message is decrypted according to the security module to obtain the message data;
[0020] The message data is processed to obtain the message processing result, and an encrypted feedback is sent to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0021] In one embodiment, after processing the message based on the message data to obtain the message processing result, the method further includes:
[0022] In response to the target message published by the message server, a first encrypted message is sent back to the message server;
[0023] In response to the second encrypted message fed back by the message server, a third encrypted message is fed back to the message server, and the storage state information corresponding to the target message is released.
[0024] Thirdly, this application also provides a data distribution apparatus, which is applied to a first client, and the apparatus includes:
[0025] The acquisition module is used to acquire the target instruction and identify the service quality level corresponding to the target instruction;
[0026] An encryption module is used to encrypt the target instruction according to the security module if the service quality level of the target instruction is the target service quality level, so as to obtain encrypted message data.
[0027] The publishing module is used to generate a target message under the target protocol based on the target service quality level and the encrypted message data, and to send the target message to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0028] In one embodiment, the quality of service level in the target protocol includes the target quality of service level; the apparatus further includes:
[0029] A predefined module is used to determine the service quality level as the target service quality level when both target bits in the target protocol are 1.
[0030] In one embodiment, the device further includes:
[0031] The first feedback module is used to provide encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0032] In one embodiment, the first feedback module is specifically used to send a second encrypted message to the message server in response to the first encrypted message fed back by the message server.
[0033] In response to the third encrypted message fed back by the message server, the storage state information of the target message is released.
[0034] Fourthly, this application also provides a data distribution apparatus, which is applied to a second client, the apparatus comprising:
[0035] The receiving module is used to receive a target message sent by the message server, wherein the target message carries a service quality level;
[0036] The decryption module is used to decrypt the encrypted message data in the target message according to the security module if the service quality level is the target service quality level, so as to obtain the message data.
[0037] The processing module is used to process messages based on the message data, obtain message processing results, and send encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0038] In one embodiment, the device further includes:
[0039] The second feedback module is used to respond to the target message published by the message server and send a first encrypted message back to the message server.
[0040] The third feedback module is used to respond to the second encrypted message fed back by the message server, send a third encrypted message back to the message server, and release the storage state information corresponding to the target message.
[0041] Fifthly, this application also provides a data distribution system, the system comprising:
[0042] The first client is used to obtain the target instruction and identify the service quality level corresponding to the target instruction;
[0043] If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data; a target message under the target protocol is generated according to the target quality of service level and the encrypted message data, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client;
[0044] The second client is used to receive a target message sent by a message server, the target message carrying a quality of service (QoS) level; if the QoS level is the target QoS level, the client decrypts the encrypted message data in the target message according to the security module to obtain message data; performs message processing based on the message data to obtain a message processing result, and sends encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message;
[0045] The message server is used to forward the target message to the second client.
[0046] Sixthly, this application also provides a communication device, including: a transmitter, a processor, and a receiver;
[0047] The processor is configured to acquire a target instruction and identify the quality of service level corresponding to the target instruction; if the quality of service level of the target instruction is a target quality of service level, the processor encrypts the target instruction according to the security module to obtain encrypted message data; and generates a target message under the target protocol based on the target quality of service level and the encrypted message data.
[0048] The transmitter is used to send the target message to the message server based on the target protocol, and instruct the message server to forward the target message to the second client.
[0049] In a seventh aspect, this application also provides a communication device, including: a transmitter, a processor, and a receiver;
[0050] The receiver is used to receive a target message sent by the message server, the target message carrying a quality of service level;
[0051] The processor is configured to, if the quality of service level is a target quality of service level, decrypt the encrypted message data in the target message according to the security module to obtain message data; and perform message processing based on the message data to obtain a message processing result.
[0052] The sender is used to send encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0053] Eighthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0054] Obtain the target instruction and identify the service quality level corresponding to the target instruction;
[0055] If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data;
[0056] Based on the target quality of service level and the encrypted message data, a target message under the target protocol is generated, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0057] Ninthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the data distribution method provided in the embodiments of this application. This method may include:
[0058] Obtain the target instruction and identify the service quality level corresponding to the target instruction;
[0059] If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data;
[0060] Based on the target quality of service level and the encrypted message data, a target message under the target protocol is generated, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0061] The aforementioned data distribution method, apparatus, communication equipment, and storage medium acquire the target instruction and its corresponding target quality of service (QoS) level. The target instruction is then encrypted using a security module to obtain encrypted message data. A target message under the target protocol is generated based on the target QoS level and the encrypted message data. This target message is then sent to a message server according to the target protocol, instructing the message server to forward the target message to the second client. The QoS level in the target protocol includes the target QoS level. An encrypted feedback is provided to the message server based on the target protocol type. This encrypted feedback instructs the message server to release the storage state information corresponding to the target message. By encrypting the target instruction under the target QoS level using a security module, this method provides secure data forwarding capabilities for industrial PON systems, even in scenarios with high data security requirements. Specifically, during the process of the target message being sent to the second client via the message server, the message data in the target message is sent and forwarded in an encrypted state, preventing attacks and tampering with the message data and improving the security of message data distribution in industrial scenarios. Attached Figure Description
[0062] Figure 1 This is a diagram illustrating the application environment of a data distribution method in one embodiment.
[0063] Figure 2 This is a diagram illustrating the interaction between a traditional MQTT protocol client and a message server.
[0064] Figure 3 This is a flowchart illustrating a data distribution method applied to a first client in one embodiment;
[0065] Figure 4 This is a schematic diagram illustrating the encryption process performed by the security module in one embodiment.
[0066] Figure 5 This is a schematic diagram of a fixed message header in an MQTT message structure in one embodiment;
[0067] Figure 6 This is a schematic diagram of the process by which the first client interacts with the message server after completing data distribution in one embodiment.
[0068] Figure 7 This is a schematic diagram illustrating the interaction and feedback between the first client and the message server after the first client completes data distribution in one embodiment.
[0069] Figure 8 This is a flowchart illustrating a data distribution method applied to a second client in one embodiment;
[0070] Figure 9 This is a schematic diagram illustrating the interaction and feedback process between the message server and the second client in one embodiment.
[0071] Figure 10 This is a structural block diagram of a data distribution device applied to a first client in one embodiment;
[0072] Figure 11 This is a structural block diagram of a data distribution device applied to a second client in one embodiment;
[0073] Figure 12 This is an internal structure diagram of a communication device in one embodiment. Detailed Implementation
[0074] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0075] This invention can be applied to communication network scenarios within industrial internet projects based on PON technology. The workshop industrial internet covers the collection of production material information, equipment data, production process information, personnel information, product quality information, and workshop operating condition information. Equipment data collection can be achieved between the controller and multiple industrial gateways via a publish / subscribe message pattern using the MQTT protocol. In industrial PON applications, this includes multiple clients (with the message publisher as the first client 102 and at least one message receiver as the second client 104) and a message server 106. The first client 102 obtains the target instruction and identifies the corresponding Quality of Service (QoS) level. If the QoS level of the target instruction matches the target QoS level, the first client 102 encrypts the target instruction using a security module to obtain encrypted message data. The first client 102 generates a target message under the target protocol based on the target QoS level and the encrypted message data, and sends the target message to the message server 106 based on the target protocol, instructing the message server 106 to forward the target message to the second client 104. For example, both the controller and the industrial gateway act as clients, subscribing to and publishing information to the message server. Data acquisition and control command return data are primarily published from the industrial gateway to the broker, which then distributes them to the controller. Similarly, data acquisition and subscription data and control commands are primarily published from the controller to the broker, which then distributes them to the industrial gateway.
[0076] In traditional technologies, industrial PON applications commonly use the MQTT protocol for message distribution. The controller and industrial gateway in the industrial PON application act as clients, subscribing to and publishing messages to the broker. The broker forwards messages to different clients, and the QoS levels in the MQTT protocol control the number of times message data is processed. For example, ... Figure 2 As shown, after the client sends a PUBLISH data packet with a QoS (Quality of Service) level of 2 to the message server, the client and the message server exchange PUBREC, PUBREL, and PUBCOMP messages to ensure that the message server processes the PUBLISH data packet only once.
[0077] Therefore, traditional technologies, where the broker uniformly distributes all data streams, cannot meet the specific needs of industrial scenarios where sensitive data must pass through secure encrypted channels. While the PUBLISH message in the MQTT protocol has a QoS level, messages like PUBACK, PUBREC, PUBREL, and PUBCOMP, as part of the QoS level mechanism, do not have a QoS concept themselves and thus cannot be securely forwarded. Therefore, the existing QoS capabilities of the MQTT protocol only constrain reliability, lacking security requirements, and cannot meet the specific needs of industrial scenarios for secure encrypted channels for sensitive data.
[0078] It should be noted that the beneficial effects or technical problems solved by the embodiments of this application are not limited to this one, but may also be other implicit or related problems. For details, please refer to the description of the embodiments below.
[0079] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0080] In one embodiment, such as Figure 3 As shown, a data distribution method is provided, which can be applied to... Figure 1 Taking the first client in the example, the explanation includes the following steps:
[0081] Step 302: Obtain the target instruction and identify the service quality level corresponding to the target instruction.
[0082] In this embodiment of the application, in the data acquisition of the industrial Internet in the workshop of the industrial PON field, the current mainstream access network OLT (Optical Line Terminal) equipment adopts Telemetry technology for high-precision acquisition. Industrial PON gateway resources are limited. Given that the MQTT protocol stack is already available, supporting the acquisition function of the industrial PON gateway through MQTT technology has great application prospects.
[0083] In an industrial PON MQTT scenario, the first client is the command (message) publisher. After the first client publishes a message on a certain topic to the message server (the Broker in the MQTT protocol), the second client, which has subscribed to the topic corresponding to the message, receives the message and performs response processing based on the message.
[0084] In the message publishing supported by the first client, each message has a predefined topic, Quality of Service (QoS) level, etc. The topic name can be a string, a hierarchical structure separated by forward slashes, such as "myhome / livingroom / temperature". The QoS level is a protocol between the message sender and the message receiver, defining the delivery guarantee for a specific message. For example, in scenarios with low reliability requirements, the QoS level of a message can be set to 0 or 1 to reduce the consumption of communication resources. For messages with high reliability requirements, a higher QoS level (QoS2) is set to ensure that the message is delivered exactly once.
[0085] The target instruction in the first client can come from different sources, such as user input, other systems, or automated processes. When the first client receives or generates a target instruction, it first identifies the corresponding server quality level within a predefined quality of service (QoS) level for each message.
[0086] Step 304: If the service quality level of the target instruction is the target service quality level, the target instruction is encrypted according to the security module to obtain encrypted message data.
[0087] The target Quality of Service (QoS) level is an additional, higher QoS level: QoS3, where the service quality is level 3. Both bits corresponding to the target QoS level are 1, and its specific definition is explained in detail in the following embodiment 3021.
[0088] In this embodiment, if the first client determines that the predefined quality of service level corresponding to the target instruction is the target quality of service level, it indicates that the target instruction not only has high reliability requirements but also high security requirements; that is, the target instruction is sensitive data, and if it is attacked and tampered with, it will have a significant impact on industrial production. Therefore, before generating a message using the target instruction as message data, the first client also needs to encrypt the target instruction, such as... Figure 4 As shown, the first client encrypts the target instruction through the security module to obtain encrypted message data, and then publishes the encrypted message data based on the encrypted state. Specifically, the first client calls the integrated security module, which is responsible for encrypting and decrypting sensitive data. The security module selects an appropriate encryption algorithm (e.g., AES, RSA, etc.) according to a predefined encryption or security policy to encrypt the payload data of the target instruction, generating encrypted message data. This process ensures that even if the message is intercepted during transmission, it cannot be easily decrypted. The encrypted payload data is then recombined with other parts of the instruction (such as the subject and QoS level) to generate complete encrypted message data.
[0089] Step 306: Generate a target message under the target protocol based on the target quality of service level and encrypted message data, and send the target message to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0090] The target protocol is the MQTT protocol that adds the target Quality of Service (QoS3).
[0091] In this embodiment of the application, the first client constructs a target message containing encrypted message data and a target quality of service level according to the message structure required by the MQTT protocol, and publishes the generated target message to the message server (Broker) through the MQTT protocol, instructing the Broker to forward the target message to the second client (e.g., an industrial gateway) that has subscribed to the corresponding topic.
[0092] In one exemplary embodiment, the security module encrypts high-security messages based on the security requirements of the target message and packages them in a QoS 3 MQTT packet for message publication.
[0093] In the above data distribution method, the target instructions under the target quality of service level are encrypted by the security module. In scenarios with high data security requirements, it can also provide the industrial PON system with the ability to forward data securely. That is, in the process of the target message being published to the second client through the message server, the message data in the target message is sent and forwarded in an encrypted state, which can prevent the message data in the target message from being attacked and tampered with, and can also improve the security of message data distribution in industrial scenarios.
[0094] In an exemplary embodiment, the quality of service level in the target protocol includes a target quality of service level; prior to step 302, the method may further include:
[0095] Step 3021: In the target protocol, among the two target bits that represent the quality of service level, the quality of service level when both target bits are 1 is determined as the target quality of service level.
[0096] In this embodiment, the target protocol is the MQTT protocol. The first client introduces QoS3 into the original MQTT protocol's QoS levels as the target quality of service level, used to identify that the delivery guarantee of the target message is processed only once, with priority forwarding and security requirements. Figure 5 As shown, Figure 5This diagram illustrates the fixed header structure of a message in MQTT. Bits 1 and 2 are target bits used to represent the Quality of Service (QoS) level. These two bits are recorded in binary format: Bit 1 = 0 and Bit 2 = 0 indicates QoS 0, Bit 1 = 0 and Bit 2 = 1 indicates QoS 1, Bit 1 = 1 and Bit 2 = 0 indicates QoS 2, and Bit 1 = 1 and Bit 2 = 1 indicates QoS 3. Similarly, in the MQTT protocol of other clients, a target QoS level is defined, which is the QoS level when all target bits representing the QoS level are 1.
[0097] In this embodiment, by introducing a target quality of service level, secure data forwarding can be achieved, and a new priority can be provided. This provides an implementation method for strictly preventing attacks and tampering with important instructions such as control commands during data delivery, thereby improving the security of data delivery.
[0098] In one exemplary embodiment, after step 306, the method further includes:
[0099] Step 3061: encrypt the interaction message with the message server based on the target protocol type.
[0100] Among them, the target protocol type interaction message refers to the feedback message encrypted by the security module. The encryption method of the target protocol type interaction message is the same as that of the target message. The target protocol type interaction message is used to provide interactive feedback after the target message of the target service quality is sent. The target message of the target service quality is an interaction message that provides feedback on the target message containing encrypted message data encrypted by the security module.
[0101] The encrypted feedback is used to instruct the message server to release the stored state information corresponding to the target message.
[0102] In this embodiment, the first terminal also introduces interactive messages of the target protocol type that provide feedback on the target message. In an optional embodiment, taking the MQTT protocol as an example, the interactive messages of the target protocol type introduced in this embodiment include SECPUBREC messages (SECPUBREC data packets), SECPUBREL messages (SECPUBREL data packets), and SECPUBCOMP messages (SECPUBCOMP data packets) in the original MQTT protocol message types. SECPUBREC messages and SECPUBREC data packets are used as examples (SECPUBREL messages and SECPUBREL data packets, and SECPUBCOMP messages and SECPUBCOMP data packets are similar). SECPUBREC messages and SECPUBREC data packets actually refer to the same concept. SECPUBREC messages refer to the message type of interactive messages of the target protocol type, and SECPUBREC data packets are the actual manifestation of SECPUBREC messages in network transmission. A SECPUBREC data packet is a binary data packet containing specific fields defined in the MQTT protocol, encrypted by a security module, used to identify and acknowledge the received PUBLISH message.
[0103] After the target message is sent, an encrypted response is sent to the receiver using the target protocol type, ensuring that the receiver processes the target message only once. The target protocol type's interactive message provides a feedback confirmation capability for both the sender and receiver after the sender sends a target message with a service quality level of the target service quality level.
[0104] In one specific embodiment, when the receiver receives the target message (which contains a PUBLISH packet and has a QoS level of 3) from the sender, the receiver processes the published message accordingly and replies to the sender via a SECPUBREC packet, which is used to acknowledge the PUBLISH packet. If the sender does not receive a SECPUBREC packet from the receiver, it will resend the PUBLISH packet with a Duplicate (DUP) flag until it receives the SECPUBREC packet.
[0105] Once the sender receives a SECPUBREC packet from the receiver, it can safely discard the initial PUBLISH packet. The sender stores the SECPUBREC packet from the receiver and responds with a SECPUBREL packet.
[0106] After receiving the SECPUBREL packet, the receiver can discard all stored state and respond with a SECPUBCOMP packet (when the sender receives the SECPUBCOMP packet, the sender also discards all stored state for the PUBLISH packet). Before the receiver completes processing and sends the SECPUBCOMP packet back to the sender, the receiver stores a reference to the packet identifier of the original PUBLISH packet. This step is used to avoid processing the target message containing the PUBLISH packet multiple times. After the sender receives the SECPUBCOMP packet, the packet identifier of the published message becomes reusable.
[0107] In this embodiment, defining an interaction message of a target protocol type for a target message of a target service quality level can ensure the security of the interaction feedback between the first client and the message server on the target message, thereby ensuring the data security of the first client and the message server throughout the entire process of target message delivery and interaction feedback.
[0108] In one exemplary embodiment, such as Figure 6 As shown, step 3061 specifically includes steps 602 to 604. Wherein:
[0109] Step 602: In response to the first encrypted message from the message server, send a second encrypted message to the message server.
[0110] In this embodiment of the application, the first encrypted message is a SECPUBREC message, and the second encrypted message is a SECPUBREL message. For example... Figure 7 As shown, after the first client sends the target message to the message server (Broker), the first client's state is to wait for the message server to send back the first encrypted message. Upon receiving the first encrypted message, it indicates that the message server has received the target message and has stored the reference to the packet identifier of the PUBLISH packet in the target message, and is ready to forward it to the subscriber (second client). The first client responds to the message server based on the second encrypted message, that is, it sends the second encrypted message to the message server. The second encrypted message indicates that the first client has received the first encrypted message from the message server and confirms that the message server has received the target message. At this point, the first client can determine that the target message has been successfully delivered to the message server, and can then release the publication state information associated with the target message.
[0111] If the first client does not receive the SECPUBREC data packet from the message server, it indicates that the target message may have failed to be sent. The first client will then send the target message (PUBLISH data packet) with the DUP flag to the message server again until it receives the SECPUBREC message.
[0112] Step 604: In response to the third encrypted message from the message server, release the storage state information of the target message.
[0113] In this embodiment of the application, the third encrypted message is the SECPUBCOMP message. For example... Figure 7 As shown, when the first client receives the SECPUBCOMP message from the message server, it indicates that the message server has successfully received the target message, and all related acknowledgment messages (SECPUBREC and SECPUBREL messages) have been completed. Therefore, the first client can safely release the stored state information corresponding to the target message, avoiding resource waste and potential memory leaks. The stored state information refers to temporary state information stored during the interaction between the first client and the message server using SECPUBREC and SECPUBREL messages, such as the message identifier (packetID).
[0114] In this embodiment, the first client ensures the high reliability of the target message transmission by interacting with the message server through the first encrypted message, the second encrypted message, and the third encrypted message. After the message publishing and receiving process is completed, the stored state information is released in a timely manner to prevent resource waste and potential memory leaks.
[0115] In one embodiment, such as Figure 8 As shown, a data distribution method is provided, which can be applied to... Figure 1 Taking the second client in the example, the explanation includes the following steps:
[0116] Step 802: Receive the target message sent by the message server.
[0117] The target message carries the quality of service (QoS) level.
[0118] In this embodiment, the first client publishes the target message to the message server, instructing the message server to forward the target message to the second client that has subscribed to the topic to which the target message belongs. The second client directly forwards the encrypted target message to itself, without performing decryption processing on the message server; instead, it decrypts the target message within the second client.
[0119] After the second client receives the target message, the structure of the target message includes the topic, load and quality of service level, etc. When the quality of service level is the target quality of service level (QoS3), it means that the target message contains encrypted message data.
[0120] Step 804: If the service quality level is the target service quality level, the encrypted message data in the target message is decrypted according to the security module to obtain the message data.
[0121] In this embodiment, the second client identifies the quality of service level carried in the target message. If the quality of service level is the target quality of service level, the second client (the recipient of the target message) uses a security module to decrypt the encrypted message data in the target message according to the requirements for processing messages with the target quality of service level as predefined in the target protocol. After decryption, the original message data is obtained.
[0122] Step 806: Perform message processing based on message data to obtain message processing results, and send encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0123] In this embodiment, the second client performs corresponding message processing based on the decrypted message data. The processing result may include performing specific operations, updating status, etc., such as performing a port closing operation. Finally, to ensure that the message server knows that the second client has successfully processed the target message, thereby safely releasing the relevant resources, the second client generates an interactive message according to the target protocol type and sends an encrypted feedback to the message server.
[0124] In this embodiment, the second client ensures the security and reliability of high QoS level messages by decrypting and encrypting the target messages of the target QoS level. It also improves the security of data distribution by working with the message server through the encrypted feedback mechanism to manage message status and resources.
[0125] In one exemplary embodiment, such as Figure 9 As shown, after step 806, the method further includes steps 902 to 904. Wherein:
[0126] Step 902: In response to the target message published by the message server, send back the first encrypted message to the message server.
[0127] In this embodiment, the first encrypted message is a SECPUBREC message. After receiving the target message forwarded by the message server, the second client sends the first encrypted message back to the message server. The first encrypted message indicates that the second client is ready to process the target message and instructs the message server to proceed to the next step of confirmation.
[0128] Step 904: In response to the second encrypted message from the message server, send a third encrypted message to the message server and release the storage state information corresponding to the target message.
[0129] In this embodiment, the second encrypted message is SECPUBREL, and the third encrypted message is SECPUBCOMP. After the message server sends the second encrypted message to the second client, the second client sends the third encrypted message to the message server, ensuring that the second client processes the target message only once. After sending the third encrypted message, the second client releases the stored state information related to the target message, including the message identifier (packetId) and acknowledgment status.
[0130] In this embodiment, reliable message transmission of target messages under the target service quality level is achieved through the interaction and feedback between the second client and the message server, effectively ensuring the accuracy and uniqueness of messages between the message server and the second client. At the same time, through the encrypted message feedback mechanism, efficient resource management and timely release of status information are achieved, thereby improving the overall stability and resource utilization of industrial PON technology.
[0131] In one embodiment, an example of a data distribution method is provided, which is applied to a scenario where an industrial PON controller (first client) collects port traffic information from thousands of industrial gateways (second clients) under an OLT. The method includes:
[0132] Step 1: The industrial PON controller, acting as a Client, sends message a containing data acquisition instructions to the industrial gateway.
[0133] Step 2: The industrial gateway, acting as the Client, publishes message b, containing port traffic information, to the Broker every 15 seconds (the quality of service level corresponding to message b is lower than the target quality of service level, i.e., QoS < 3).
[0134] Step 3: The Broker publishes message c containing all the collected data to the Industrial PON Controller Client.
[0135] Step 4: The industrial PON controller determines that the traffic of a certain industrial gateway port a is abnormal and generates a configuration command to shut down the industrial gateway port a.
[0136] Step 5: The industrial PON controller, acting as the Client, sends a PUBLISH message d to the Broker (the service quality level corresponding to message d is the target service quality level, i.e., QoS=3). Message d is used to request port a to be closed.
[0137] Step 6: Message d is processed by the security module of the industrial PON controller with special security measures, such as encryption, and then distributed to the Broker according to QoS=3.
[0138] Step 7: Broker confirms successful receipt of the PUBLISH data packet of message d by sending a SECPUBREC message to the Industrial PON Controller Client.
[0139] Step 8: The industrial PON controller Client receives the SECPUBREC message, safely discards the initial PUBLISH packet, stores the SECPUBREC packet from the Broker, and responds with a SECPUBREL packet.
[0140] Step 9: After receiving the SECPUBREL data packet, the Broker discards all stored states related to message d and responds with a SECPUBCOMP data packet (when the Industrial PON Controller Client receives the SECPUBCOMP, it also discards all stored states related to message d). Before the Industrial PON Controller Client completes processing and sends the SECPUBCOMP data packet back to the Broker, the Industrial PON Controller Client stores a reference to the packet identifier of the original SECPUBLISH data packet.
[0141] Step 10: The Broker does not decrypt the QoS 3 message, but instead securely publishes message d (containing a configuration instruction requiring port a to be closed) directly via QoS 3. The industrial gateway Client that subscribes to the control instruction receives message d and, following the same interactive feedback as steps 5 to 9, ensures that the configuration instruction in message d is received once through SECPUBREC, SECPUBREL, and SECPUBCOMP messages, and executes the instruction after decryption by the security module.
[0142] Step 11: After the industrial gateway completes the process of closing port a, it sends a response message of the configuration command to the controller client via the Broker (e.g., <ok>Following the same steps as steps 5 to 10, the message is forwarded twice via two QoS3 logical channels, ensuring one message is delivered. At this point, the configuration instructions in message d and the response message returned by the configuration complete the device control with enhanced security, preventing the device control instructions from being attacked or tampered with.
[0143] In one embodiment, a data distribution system is also provided, the system comprising:
[0144] The first client is used to obtain the target command and identify the service quality level corresponding to the target command.
[0145] If the service quality level of the target instruction is the target service quality level, the target instruction is encrypted according to the security module to obtain encrypted message data; a target message under the target protocol is generated according to the target service quality level and the encrypted message data, and the target message is sent to the message server according to the target protocol, instructing the message server to forward the target message to the second client.
[0146] The second client is used to receive the target message sent by the message server. The target message carries the quality of service level. If the quality of service level is the target quality of service level, the client decrypts the encrypted message data in the target message according to the security module to obtain the message data. The client processes the message based on the message data to obtain the message processing result and sends an encrypted feedback to the message server based on the interaction message of the target protocol type. The encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0147] A message server is used to forward target messages to a second client.
[0148] It should be understood that, although Figure 3 , Figure 6 , Figure 8 and Figure 9 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 3 , Figure 6 , Figure 8 and Figure 9 At least some of the steps in the process may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but may be executed at different times. The execution order of these steps or stages is not necessarily sequential, but may be executed in turn or alternately with other steps or at least some of the steps or stages in other steps.
[0149] In one embodiment, such as Figure 10 As shown, a data distribution device 1000 is provided, which is applied to a first client and includes: an acquisition module 1001, an encryption module 1002, and a publishing module 1003, wherein:
[0150] The acquisition module 1001 is used to acquire the target instruction and identify the service quality level corresponding to the target instruction.
[0151] The encryption module 1002 is used to encrypt the target instruction according to the security module if the service quality level of the target instruction is the target service quality level, so as to obtain encrypted message data.
[0152] The publishing module 1003 is used to generate a target message under the target protocol based on the target service quality level and encrypted message data, and to send the target message to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0153] In one embodiment, the quality of service level in the target protocol includes a target quality of service level. The apparatus 1000 further includes:
[0154] A predefined module is used to determine the service quality level as the target service quality level when both target bits in the target protocol are 1.
[0155] In one embodiment, the device 1000 further includes:
[0156] The first feedback module is used to provide encrypted feedback to the message server based on the interaction message of the target protocol type. The encrypted feedback is used to instruct the message server to release the stored state information corresponding to the target message.
[0157] In one embodiment, the first feedback module is specifically used to send a second encrypted message to the message server in response to the first encrypted message fed back by the message server.
[0158] In response to the third encrypted message from the message server, the stored state information of the target message is released.
[0159] In one embodiment, such as Figure 11 As shown, a data distribution device 1100 is also provided, which is applied to a second client and includes: a receiving module 1101, a decryption module 1102, and a processing module 1103, wherein:
[0160] The receiving module 1101 is used to receive the target message sent by the message server, and the target message carries the quality of service level.
[0161] The decryption module 1102 is used to decrypt the encrypted message data in the target message according to the security module if the service quality level is the target service quality level, so as to obtain the message data.
[0162] Processing module 1103 is used to process messages based on message data, obtain message processing results, and send encrypted feedback to the message server based on the interaction message of the target protocol type. The encrypted feedback is used to instruct the message server to release the stored state information corresponding to the target message.
[0163] In one embodiment, the device 1100 further includes:
[0164] The second feedback module is used to respond to the target message published by the message server and send the first encrypted message back to the message server.
[0165] The third feedback module is used to respond to the second encrypted message from the message server, send a third encrypted message back to the message server, and release the storage state information corresponding to the target message.
[0166] Specific limitations regarding the data distribution device can be found in the limitations of the data distribution method described above, and will not be repeated here. Each module in the aforementioned data distribution device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0167] Figure 12 This is a schematic diagram of the structure of an access network device provided in an embodiment of this application. The access network device may include a receiver 121, a memory 122, a processor 123, at least one communication bus 124, and a transmitter 125. The communication bus 124 is used to implement communication connections between components. The memory 122 may include high-speed RAM memory, and may also include non-volatile memory (NVM), such as at least one disk storage device. The memory 122 can store various programs for performing various processing functions and implementing the method steps of this embodiment. In this embodiment, the transmitter 125 can be a radio frequency processing module or a baseband processing module in the access network device, and the receiver 121 can also be a radio frequency processing module or a baseband processing module in the access network device. The transmitter 125 and the receiver 121 can be integrated together to form a transceiver. Both the transmitter 125 and the receiver 121 can be coupled to the processor 123, and can perform receiving or transmitting actions under the instruction or control of the processor 123.
[0168] In this embodiment, receiver 121 is used to acquire the target instruction and identify the service quality level corresponding to the target instruction;
[0169] Processor 123 is configured to, if the quality of service level of the target instruction is the target quality of service level, encrypt the target instruction according to the security module to obtain encrypted message data; and generate a target message under the target protocol according to the target quality of service level and the encrypted message data.
[0170] The transmitter 125 is used to send the target message to the message server based on the target protocol, and instruct the message server to forward the target message to the second client.
[0171] In one embodiment, the quality of service level in the target protocol includes a target quality of service level; the processor 123 is specifically used to determine the quality of service level when both target bits are 1 in the two target bits that represent the quality of service level in the target protocol as the target quality of service level.
[0172] In one embodiment, the transmitter 125 is specifically used to send encrypted feedback to the message server based on the interactive message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
[0173] In one embodiment, the transmitter 125 is specifically configured to send a second encrypted message to the message server in response to a first encrypted message fed back by the message server; and to release the storage state information of the target message in response to a third encrypted message fed back by the message server.
[0174] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0175] Obtain the target instruction and identify the service quality level corresponding to the target instruction;
[0176] If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data;
[0177] Based on the target service quality level and encrypted message data, a target message under the target protocol is generated, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client.
[0178] In one embodiment, the quality of service level in the target protocol includes a target quality of service level; the computer program, when executed by a processor, also performs the following steps:
[0179] In the target protocol, the service quality level is determined when both target bits are 1, based on the two target bits representing the service quality level.
[0180] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0181] The message exchange with the message server is encrypted based on the target protocol type; the encrypted feedback is used to instruct the message server to release the stored state information corresponding to the target message.
[0182] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0183] In response to the first encrypted message from the message server, a second encrypted message is sent to the message server.
[0184] In response to the third encrypted message from the message server, the stored state information of the target message is released.
[0185] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0186] Receive the target message sent by the message server; the target message carries the quality of service level.
[0187] If the service quality level is the target service quality level, the encrypted message data in the target message is decrypted according to the security module to obtain the message data;
[0188] The message is processed based on the message data to obtain the message processing result, and an encrypted feedback is sent to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the stored state information corresponding to the target message.
[0189] In one embodiment, when the computer program is executed by a processor, it also performs the following steps:
[0190] In response to the target message published by the message server, send back the first encrypted message to the message server;
[0191] In response to the second encrypted message from the message server, a third encrypted message is sent back to the message server, and the stored state information corresponding to the target message is released.
[0192] This application also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the steps in the above-described method embodiments.
[0193] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0194] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0195] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.< / ok>
Claims
1. A data distribution method, characterized in that, The method is applied to a first client, and the method includes: Obtain the target instruction and identify the service quality level corresponding to the target instruction; If the quality of service level of the target instruction is the target quality of service level, the target instruction is encrypted according to the security module to obtain encrypted message data; A target message under the target protocol is generated based on the target quality of service level and the encrypted message data, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client; the target quality of service level is represented by two target bits in the fixed header of the target message being 1, and the target quality of service level is used to identify that the target message has security requirements; the target protocol is MQTT message queue telemetry transport protocol.
2. The method according to claim 1, characterized in that, The service quality level in the target protocol includes the target service quality level; before obtaining the target instruction and identifying the service quality level corresponding to the target instruction, the method further includes: In the target protocol, the service quality level is determined when both target bits are 1, based on the two target bits representing the service quality level.
3. The method according to claim 1, characterized in that, After generating a target message under the target protocol based on the target quality of service level and the encrypted message data, and sending the target message to the message server based on the target protocol, and instructing the message server to forward the target message to the second client, the method further includes: The message server receives encrypted feedback based on the target protocol type of the interaction message; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message.
4. The method according to claim 3, characterized in that, The encrypted feedback between the interactive message based on the target protocol type and the message server includes: In response to the first encrypted message fed back by the message server, a second encrypted message is sent to the message server; In response to the third encrypted message fed back by the message server, the storage state information of the target message is released.
5. A data distribution method, characterized in that, The method is applied to a second client, and the method includes: Receive a target message sent by a message server, the target message carrying a quality of service level; If the service quality level is the target service quality level, the encrypted message data in the target message is decrypted according to the security module to obtain the message data; Message processing is performed based on the message data to obtain the message processing result, and an encrypted feedback is sent to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message; the target service quality level is represented by two target bits in the fixed message header of the target message being both 1, and the target service quality level is used to identify that the target message has security requirements; the target protocol is the MQTT protocol.
6. The method according to claim 5, characterized in that, After processing the message based on the message data to obtain the message processing result, the method further includes: In response to the target message published by the message server, a first encrypted message is sent back to the message server; In response to the second encrypted message fed back by the message server, a third encrypted message is fed back to the message server, and the storage state information corresponding to the target message is released.
7. A data distribution system, characterized in that, The system includes: The first client is used to obtain the target instruction and identify the service quality level corresponding to the target instruction; If the service quality level of the target instruction is a target service quality level, the target instruction is encrypted according to the security module to obtain encrypted message data; a target message under the target protocol is generated according to the target service quality level and the encrypted message data, and the target message is sent to the message server based on the target protocol, instructing the message server to forward the target message to the second client; the target service quality level is represented by two target bits in the fixed message header of the target message being both 1, and the target service quality level is used to identify that the target message has security requirements; the target protocol is MQTT message queue telemetry transport protocol; The second client is used to receive a target message sent by a message server, the target message carrying a quality of service (QoS) level; if the QoS level is the target QoS level, the client decrypts the encrypted message data in the target message according to the security module to obtain message data; performs message processing based on the message data to obtain a message processing result, and sends encrypted feedback to the message server based on the interaction message of the target protocol type; the encrypted feedback is used to instruct the message server to release the storage state information corresponding to the target message; The message server is used to forward the target message to the second client.
8. A data distribution device, characterized in that, The device is applied to a first client, and the device includes: The acquisition module is used to acquire the target instruction and identify the service quality level corresponding to the target instruction; An encryption module is used to encrypt the target instruction according to the security module if the service quality level of the target instruction is the target service quality level, so as to obtain encrypted message data. The publishing module is used to generate a target message under the target protocol based on the target quality of service level and the encrypted message data, and to send the target message to the message server based on the target protocol, instructing the message server to forward the target message to the second client; the target quality of service level is represented by two target bits in the fixed header of the target message being 1, and the target quality of service level is used to identify that the target message has security requirements; the target protocol is the MQTT protocol.
9. A communication device, characterized in that, include: Transmitter, processor, and receiver; The processor is used to acquire a target instruction and identify the service quality level corresponding to the target instruction; If the service quality level of the target instruction is the target service quality level, the target instruction is encrypted according to the security module to obtain encrypted message data; a target message under the target protocol is generated according to the target service quality level and the encrypted message data; the target service quality level is represented by two target bits in the fixed message header of the target message being 1, and the target service quality level is used to identify that the target message has security requirements; The target protocol is the MQTT (Message Queuing Telemetry Transport Protocol). The transmitter is used to send the target message to the message server based on the target protocol, and instruct the message server to forward the target message to the second client.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4 and 5 to 6.
Citation Information
Patent Citations
Data priority forwarding method and device, electronic equipment and storage medium
CN116980355A