Internet of Things equipment traffic confusion method based on server strategy formulation
By adopting a traffic obfuscation method based on server policy in IoT devices, through data clustering and decomposition of packet length distribution, the complexity problem of users requiring manual configuration of parameters in the prior art is solved, and automated traffic obfuscation is achieved, and security and availability are improved.
Patent Information
- Application Number
- CN202410971731.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-07-19
AI Technical Summary
Existing IoT device traffic obfuscation technology requires users to manually configure parameters, which is complex and difficult to automate, and is especially a huge challenge for ordinary users.
The Internet of Things device traffic obfuscation method based on server policies is adopted. The data amount generated by the instruction is mapped into a fixed value through data clustering and decomposed into a specific packet length distribution, thereby realizing the automatic determination of traffic obfuscation parameters.
It realizes automatic determination of traffic obfuscation parameters, without user participation, is easy to deploy and use, and can produce different obfuscation effects for different IoT devices, improving security and availability.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security of Internet of Things devices, and relates to a traffic obfuscation method for Internet of Things devices. Specifically, it covers strategy formulation and traffic obfuscation technology when establishing a communication connection between an Internet of Things device and a server and performing data transmission. Background Art
[0002] With the rapid development of IoT technology and the emergence of IoT devices and smart home platforms from manufacturers such as Google, Amazon, and Xiaomi, the scale of communication between devices has increased dramatically. As IoT devices grow rapidly, users' personal privacy and data security issues have become particularly important. However, the resulting network traffic has also brought new threats and challenges to network security. IoT devices such as smart speakers interact with servers through messages to meet user needs and provide customized services. In order to protect the privacy of user communication data, the network interactions between IoT devices and servers are mostly encrypted traffic. However, the latest research shows that attackers can infer users' privacy information from encrypted network messages. The reason is that users' privacy activities will be reflected in the traffic data of the interaction between IoT devices and servers. User activities are highly correlated with statistical features such as message length and time series of network traffic. Attackers can infer users' behavior by analyzing the message features in user activities, thereby obtaining user privacy information such as the opening and closing of smart door locks and the content played by smart speakers. To meet this challenge, existing research proposes to use traffic obfuscation technology to improve the security of IoT devices. Current research on obfuscation technology for smart IoT devices at home and abroad mainly includes a variety of methods, such as data packet padding, traffic shaping, false traffic injection, virtual users, etc. Among them, data packet padding is mainly aimed at attack methods that rely on data packet size characteristics, while traffic shaping targets the overall statistical characteristics of data flows, including traffic timing, cycle, rate, etc. The purpose of false traffic injection is to deceive attackers and imitate the traffic of real devices, including imitating characteristics such as traffic size, traffic type, and traffic pattern. Virtual users are an optimization method based on false traffic injection proposed in recent years. It constructs a logically complete and realistic user behavior model and projects it into home traffic to prevent attackers from spying on the privacy information of real users. However, the above methods all require IoT users to configure specific traffic obfuscation parameters, such as the amount of data sent, the time interval distribution of message sending, etc. When configuring the above parameters, factors such as network bandwidth and IoT device performance need to be considered comprehensively, which is a huge challenge for ordinary users. Therefore, it is necessary to design a traffic obfuscation method for IoT devices that can automatically determine parameters, without user participation during the execution of the method, which is convenient for actual deployment and use. This patent proposes a method for traffic obfuscation of IoT devices based on server policy formulation, which can realize the automatic determination of traffic obfuscation parameters. Unlike existing methods, the traffic obfuscation strategy in this patent method is formulated by the server. The server clusters the amount of data generated by the instructions of the IoT device and maps the amount of data in the same class to a fixed value. According to the network communication environment of the IoT device, the fixed value is decomposed into a specific message length distribution to achieve traffic obfuscation. The patent of this invention can realize the automatic determination of the obfuscation strategy and can produce different obfuscation effects for different IoT devices, thereby achieving high availability and high security protection. Summary of the invention
[0003] The present invention aims to solve the privacy and security issues in IoT device communications and to provide an innovative IoT device traffic obfuscation method to defend against passive attacks in the IoT field. In order to solve the above technical problems, the present invention proposes a method for obfuscating IoT device traffic based on server strategy formulation, which includes the following steps: (1) Establishing a communication connection: The IoT device establishes an encrypted network communication connection with the server; (2) Request to send obfuscation strategy: The IoT device sends a request to the server to obtain the traffic obfuscation strategy; (3) Server obfuscation strategy formulation: The server maps the amount of data generated by the instruction to a fixed value through data clustering. The server confirms the request of the IoT device. The server analyzes the statistical characteristics of the traffic interaction of the IoT device and returns the traffic distribution to the IoT device as an obfuscation strategy; (4) IoT devices accept the obfuscation strategy and perform traffic obfuscation. IoT devices reshape data into a specific message length distribution for communication according to the message size and format determined by the obfuscation strategy; (5) Server return data traffic obfuscation: The server shapes the data into a specific message length distribution and sends the return data according to the traffic characteristics determined by the obfuscation strategy. The step (1) specifically includes the following steps: (1-1) The IoT device starts and tries to establish a network connection with the server; (1-2) IoT devices and servers use encrypted transmission protocols such as the Transport Layer Security (TLS) protocol to handshake, negotiate encryption algorithms and session keys, and establish encrypted communication channels. In step (2), after the IoT device starts and establishes a connection with the server, it sends a request to obtain the traffic obfuscation policy. Taking the common IoT communication protocol such as MQTT (Message Queuing Telemetry Transport) as an example, after the IoT device connects to the MQTT proxy server, the device subscribes to a specific topic (Topic) such as "confusion_policy_request". The IoT device publishes a message to the topic, indicating a request to obtain the traffic obfuscation policy. After receiving the message, the server performs subsequent obfuscation operations based on the device's identification and context information. The step (3) specifically includes the following steps: (3-1) The server extracts the traffic data of all device instructions stored; (3-2) The server confirms the IoT device request; (3-3) The server maps the amount of data generated by the instruction to a fixed value through data clustering; (3-4) The server formulates the obfuscation strategy for this communication interaction based on the characteristics of the IoT device message; (3-5) The server sends the obfuscation strategy to the IoT device for use in this communication. In step (3-1), the server collects and stores the server-sent and returned data of all device commands to form a set D1 = {d 11 , d 12 , …, d 1n} and D2 = {d 21 , d 22 , …, d 2n}, where d 1i Indicates the amount of traffic data sent by the IoT device for the i-th instruction, d 2i Indicates the amount of traffic data returned by the server for the i-th instruction. In step (3-2), the server receives the IoT device interaction request, starts the data clustering and obfuscation strategy formulation process on the server side, and returns confirmation information. In step (3-3), the data clustering algorithm adopts the K-means algorithm, and the specific process is as follows: (3-3-1): The server uses the K-means algorithm to perform cluster analysis on sets D1 and D2. First, the elbow method is used to determine the optimal number of clusters k1 and k2. (3-3-2): Calculate the total variation WSS (Within Sum of Squares) under different k values in order to generate the best clustering results. (3-3-3): Select the k value that makes WSS(k) drop sharply and begin to level off as the optimal number of clusters. (3-3-4): According to the optimal clustering number k1, k2, cluster the set D1 into k1 clusters: {S1, S2, …, S k1}, and cluster the set D2 into k2 clusters: {R1, R2, …, R k2}, where S i , R i They represent the clustering results of the sent and returned traffic data volumes, respectively. Based on the clustering results, the server maps the maximum value of each cluster as a fixed value. In step (3-4), the server analyzes the statistical characteristics of the IoT device traffic, extracts the traffic data volume distribution that meets the data volume size to construct the sets Send[] and Return[]. For the IoT device type currently requested, the server will count the average traffic data volume sent and returned, and divide the clusters that meet the data volume range of this type according to the average data size. The average data size of the sent message is defined as l, the average data size of the returned message is defined as h, and the fixed value of the cluster is max(S i ) or max(R i ), the server divides the clusters corresponding to the sending and returning traffic data volume into several specific message lengths {l1, l2, …, l p} and {h1, h2, …, h q}. As shown in formulas (1) and (2), the sum of these lengths is approximately equal to max(S i ) or max(R i ). Among them, the p and q values represent the number of segments divided by the maximum value in the corresponding cluster, which is determined according to the actual situation and the average data size l and h. The server generates the message length distribution based on the decomposition result. After the clustering result is generated in step (3-3), cluster S i , R i The selection is based on the instruction set of the device stored in the server. The data volume range of the instruction set should be included in the cluster. max(S i ) or max(R i ) as the maximum value of the selected cluster and as a fixed value for obfuscation. The server sets the command set commands of the IoT device and the fixed value max(S i ) and the length distribution of the messages sent by the device {l1, l2, …, l p} loads the set Send[], and sets the command set commands and the fixed value max(R i ) and the length distribution of the messages sent by the server {h1, h2, …,h q}Load the collection Return[]. In steps (3-5), the server converts the collections Send[] and Return[] into JSON format data, as shown below: Send[] = { "commands": ["cmd1", "cmd2", …, "cmd n "] "max(S i ) " "distribution": ["l1", "l2", …, "l p "] } Return[] = { "commands": ["cmd1", "cmd2", …, "cmd n "] "max(R) " "distribution": ["h1", "h2", …, "h q "] } The server sends Send[] as the obfuscation strategy to the IoT device. The step (4) specifically includes the following steps: (4-1) The IoT device receives and stores the obfuscation strategy sent by the server; (4-2) IoT devices perform traffic shaping on the data they send according to a specific message length distribution; (4-3) IoT devices send data. In step (4-2), when the IoT device triggers the user command and communicates with the server, it needs to adopt the obfuscation strategy issued by the server. The specific operation is as follows: the device maps the data required for this communication to the message length distribution {l1, l2, …, l p}, intercept l1 to l according to the amount of communication data n (n≤p) data to meet the message length requirement. In addition, the data packet to be transmitted is divided into multiple parts according to the message length distribution. The size of the data packet sent is equal to the message length distribution {l1, l2, …, l n} until the sending is completed, thus forming a specific message length distribution. In step (4-3), the IoT device performs traffic shaping on the traffic corresponding to the user command and sends the data packets according to the preset message length distribution. When the IoT device receives the user command and forms a specific message length distribution, it sequentially distributes the packets according to the length {l1, l2, …, l n}Send a data packet. When sending the nth data packet, the device will check the size of the data part and fill the packet with blank content at the end of the message to the corresponding length l n . The step (5) specifically includes the following steps: (5-1) The server performs traffic shaping on the sent data according to the specific message length distribution; (5-2) The server sends data. In step (5-1), the server receives the obfuscated IoT device traffic and adopts a predetermined obfuscation strategy when sending the return data. The server maps the amount of data required for this communication to the message length distribution {h1, h2, …, h q}, intercept h1 to h according to the communication data volume m (m≤p) data to meet the message length requirement. In addition, according to the message length distribution, the data packet transmitted this time is divided into multiple parts. The size of the sent data packet is equal to the message length distribution {h1, h2, …, h m} until the sending is completed, thus forming a specific message length distribution. In step (5-2), the server performs traffic shaping on the traffic corresponding to the user command and sends the data packets according to the preset message length distribution. When the server receives the request from the IoT device and forms a specific message length distribution, it sends the data packets in turn according to the length {h1, h2, …, h m}Send a data packet. When sending the mth data packet, the device will check the size of the data portion and fill the packet with blank content at the end of the message to the corresponding length h m . BRIEF DESCRIPTION OF THE DRAWINGS
[0004] Figure 1 The core idea of this patent is given. Figure 2 This is a diagram of data clustering methods. Figure 3 This is the clustering result map. Figure 4 Populate the structure diagram for the data packet. Figure 5 This is the traffic graph after obfuscation. DETAILED DESCRIPTION
[0005] like Figure 1 As shown in the figure, the IoT device starts and tries to establish an initial connection with the server. The two parties shake hands through the Transport Layer Security (TLS) protocol, negotiate encryption algorithms and session keys, and establish an encrypted communication channel. During this process, the IoT device sends the server a list of supported TLS versions and encryption algorithm suites. The server selects the TLS version with the highest security and the appropriate encryption algorithm and sends it to the IoT device as a response. The IoT device verifies the validity and legitimacy of the digital certificate provided by the server to ensure that the other party of the communication is a legitimate server entity. The device and the server negotiate to generate a symmetric encryption key for this communication session and establish a secure encrypted communication channel. Once the encrypted communication channel is established, the IoT device sends a request to the server to obtain the obfuscation strategy formulated by the server based on the communication characteristics of the device. After receiving the request from the IoT device, the server first confirms the request of the IoT device and then clusters the stored traffic data. Figure 2 , Figure 3 The elbow method is used to determine the optimal cluster number graph and clustering result graph during the clustering process of the captured Xiaomi smart speaker dataset. The server extracts the traffic data of all device commands stored. Using the K-means algorithm, the server performs cluster analysis on the data set D1 generated by the command and the returned data set D2, and uses the elbow method to determine the optimal number of clusters. Figure 2 As shown in Figure 1, by calculating the total internal sum of squares WSS of set D1, the k value that makes WSS(k) drop sharply and begin to flatten out is selected as the optimal number of clusters. In this data set, the optimal number of clusters is 4, so the data set D1 is clustered into 4 clusters {S0, S1, S2, S3}. Each cluster S i Represents the clustering result of the amount of data sent. The server maps the maximum value of each cluster as a fixed value based on the clustering result. Figure 3 As shown in the figure, in the data set used this time, the cluster corresponding to the amount of data generated by the device is S2, and the fixed value max(S2) is 880. Let the p value be 5, then the message length distribution {l1, l2, l3, l4, l5}={176, 176, 176, 176, 176} is loaded into the set Send[], and then the json file is sent to the IoT device in the format of: Send[] = { "commands": ["cmd1", "cmd2", …, "cmd n "] "max(S2) " "distribution": ["176", "176", "176", "176", "176"] }. cmd i Represents the set of all user commands of the device, max(S2) represents a fixed value of 880, and distribution represents the message length distribution. After receiving the obfuscation strategy sent by the server, the IoT device starts to perform traffic obfuscation on the sent data. When the user interacts with the IoT device and generates instruction A, the device maps the data volume m corresponding to instruction A to the message length distribution. Let m=700, and the device intercepts the message length distribution {l1, l2, …, l n}, that is, {176, 176, 176, 176}. The IoT device shapes the traffic corresponding to the user command according to the generated message length distribution, and fills 4 bytes of blank data at the end of the fourth message sent to ensure that the data packet is sent according to the preset message length distribution. The traffic diagram after shaping is as follows: Figure 5 As shown, Figure 5 It can be seen that the len value of the obfuscated traffic is 176, which is in line with the obfuscation strategy. After the server receives the data packet sent by the IoT device, it generates the obfuscation strategy Return[] according to the clustering result in the same way. It generates the message length distribution, performs traffic shaping, and sends the return data packet. In the above traffic obfuscation process, it is demonstrated how the server and IoT devices use obfuscation strategies to implement data traffic obfuscation during communication, thereby ensuring the security of communication and the impact on performance. It should be stated that the content and specific implementation methods of the present invention are intended to demonstrate the practical application of the technical solution provided by the present invention and should not be interpreted as limiting the scope of protection of the present invention. Those skilled in the art may make various modifications, equivalent substitutions, or improvements inspired by the spirit and principles of the present invention. However, these changes or modifications are within the scope of protection of the application to be approved.
Claims
1. Traffic obfuscation of IoT devices based on server policy formulation, characterized by: The method comprises the following steps: (1) Establishing a communication connection: The IoT device establishes an encrypted network communication connection with the server; (2) Request to send obfuscation strategy: The IoT device sends a request to the server to obtain the traffic obfuscation strategy; (3) Server obfuscation strategy formulation: The server maps the amount of data generated by the instruction to a fixed value through data clustering. The server confirms the request of the IoT device. The server analyzes the statistical characteristics of the traffic interaction of the IoT device and returns the traffic distribution to the IoT device as an obfuscation strategy; (4) IoT devices accept the obfuscation strategy and perform traffic obfuscation. IoT devices reshape data into a specific message length distribution for communication according to the message size and format determined by the obfuscation strategy; (5) Server return data traffic obfuscation: The server shapes the data into a specific message length distribution and sends the return data according to the traffic characteristics determined by the obfuscation strategy.
2. The method according to claim 1, characterized in that The step (1) comprises the following steps: (1-1) The IoT device starts and tries to establish a network connection with the server; (1-2) IoT devices and servers use encrypted transmission protocols such as the Transport Layer Security (TLS) protocol to handshake, negotiate encryption algorithms and session keys, and establish encrypted communication channels.
3. The method according to claim 1, characterized in that: The step (3) comprises the following steps: (3-1) The server extracts the traffic data of all device instructions stored; (3-2) The server confirms the IoT device request; (3-3) The server maps the amount of data generated by the instruction to a fixed value through data clustering; (3-4) The server formulates the obfuscation strategy for this communication interaction based on the characteristics of the IoT device message; (3-5) The server sends the obfuscation strategy to the IoT device for use in this communication.
4. The method according to claim 1, characterized in that: The step (4) comprises the following steps: (4-1) The IoT device receives and stores the obfuscation strategy sent by the server; (4-2) IoT devices perform traffic shaping on the data they send according to a specific message length distribution; (4-3) IoT devices send data.
5. The method according to claim 1, characterized in that The step (5) comprises the following steps: (5-1) The server performs traffic shaping on the sent data according to the specific message length distribution; (5-2) The server sends data.
6. The method according to claim 3, characterized in that The step (3-3) comprises the following steps: (3-3-1): The server uses the K-means algorithm to perform cluster analysis on sets D1 and D2. First, the elbow method is used to determine the optimal number of clusters. k 1. k 2; (3-3-2): Calculation is different k The total variation WSS (Within Sum of Squares) under the value is used to generate the best clustering results; (3-3-3): Select the time that causes WSS(k) to drop sharply and then begin to level off. k value as the optimal number of clusters; (3-3-4): Based on the optimal number of clusters k 1. k 2. Cluster set D1 into k 1 cluster: {S1, S2, …, S k1 }, and cluster the set D2 into k 2 clusters: {R1, R2, …, R k2 }, where S i , R i They represent the clustering results of the sent and returned traffic data volumes, respectively. Based on the clustering results, the server maps the maximum value of each cluster as a fixed value.
Citation Information
Patent Citations
Self-adaptive obfuscation method and system based on Meek transmission plug-in, and computer storage medium
CN111953670A
Encryption method based on RISC-V architecture
CN117978367A
Intelligent payment port encryption method and system
CN118138312A
System and method for real-time transactional data obfuscation
US20120030165A1
Obfuscating data using obfuscation table
US20160321468A1