Internet of Things data secure transmission method and Internet of Things data secure transmission system

By adopting encryption and signature mechanisms between IoT devices and platforms, the security issues of IoT devices when transmitting data are solved, data confidentiality and integrity are achieved, and the security of IoT data transmission is ensured.

CN119995942AActive Publication Date: 2025-05-13SHEN ZHEN HUA XIN AN QUAN JI SHU YOU XIAN GONG SI
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510015476.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-13
Estimated Expiration
2045-01-06

Smart Images

  • Figure CN119995942A_ABST
    Figure CN119995942A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to an Internet of Things data secure transmission method and an Internet of Things data secure transmission system.The system comprises Internet of Things equipment and an Internet of Things platform, service plaintext data and a first symmetric key are generated through the Internet of Things equipment, and the service plaintext data and an equipment serial number are encrypted to obtain a ciphertext; the method comprises the following steps: firstly, using a platform encryption public key to encrypt a first symmetric key, using a platform encryption public key to encrypt the first symmetric key, meanwhile, using an equipment signature private key to sign business plaintext data by the Internet of Things equipment, sending a ciphertext, the encrypted first symmetric key and signature data to an Internet of Things platform by the Internet of Things equipment, using the platform encryption private key to decrypt the first symmetric key by the platform, and sending the first symmetric key to the Internet of Things equipment; and decrypting the ciphertext to obtain the service plaintext data and the equipment serial number, and querying the equipment signature public key through the equipment serial number to verify the signature data. And after the verification succeeds, the Internet of Things platform processes the service plaintext data. According to the invention, the security of Internet of Things data transmission is ensured, and the method is suitable for various Internet of Things application scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method and system for securely transmitting data in the Internet of Things. Background Art

[0002] The national standards for IoT devices, "GB / T 36951-2018 Information Security Technology - Technical Requirements for Application Security of IoT Perception Terminals", "GB / T 37024-2018 Information Security Technology - Technical Requirements for Security of IoT Perception Layer Gateways", "GB / T 37025-2018 Information Security Technology - Technical Requirements for Data Transmission Security of IoT", and "GB / T 37093-2018 Information Security Technology - Security Requirements for Access to Communication Networks of IoT Perception Layers", clearly require that the data collected by IoT devices must ensure the confidentiality, integrity, and freshness of the data.

[0003] With the popularity of IoT devices, their security has received widespread attention. However, in the current communication between IoT devices and the cloud, there are risks of IoT devices being counterfeited as terminal devices, data theft, and man-in-the-middle attacks. However, when IoT device manufacturers and application manufacturers use IoT devices to transmit data, the use of plain text, weak encryption, and other methods cannot guarantee data security. Device authentication through device serial number authentication cannot ensure device access security. Summary of the invention

[0004] In order to overcome the shortcomings of the prior art, the present invention provides an Internet of Things data security transmission method and an Internet of Things data security transmission system to ensure the security of Internet of Things data during transmission.

[0005] A first aspect of the present application provides an IoT data security transmission method, which is applied to an IoT data security transmission system. The IoT data security transmission system includes an IoT device and an IoT platform. The method includes: The IoT device generates business plaintext data and randomly generates a first symmetric key; The IoT device encrypts the service plaintext data and the device serial number according to the first symmetric key to obtain a ciphertext; the device serial number corresponds to the IoT device; The IoT device encrypts the first symmetric key according to the platform encryption public key to obtain first key ciphertext data; the platform encryption public key corresponds to the IoT platform and is preset in the IoT device; The IoT device signs the business plaintext data according to a device signature private key in a pre-generated device signature key pair to obtain first signature data; The Internet of Things device sends the ciphertext, the first key ciphertext data and the first signature data to the Internet of Things platform; When the IoT platform receives the ciphertext, the first key ciphertext data and the first signature data sent by the IoT device, the IoT platform decrypts the first key ciphertext data according to the platform encryption private key to obtain the first symmetric key; The Internet of Things platform decrypts the ciphertext according to the first symmetric key to obtain the business plaintext data and the device serial number; The IoT platform queries the device signature public key according to the device serial number, and verifies the first signature data according to the device signature public key; When the Internet of Things platform determines that the first signature data is successfully verified, the business processes the business plaintext data.

[0006] In an optional embodiment, the method further comprises: The Internet of Things platform generates instruction plaintext data and randomly generates a second symmetric key; The Internet of Things platform encrypts the instruction plaintext data according to the second symmetric key to obtain data ciphertext; The IoT platform queries the corresponding device encryption public key in the pre-generated device encryption key pair according to the device serial number, and encrypts the second symmetric key according to the device encryption public key to obtain second key ciphertext data; The Internet of Things platform signs the instruction plaintext data according to the platform signature private key to obtain second signature data; Sending the data ciphertext, the second key ciphertext data and the second signature data to the Internet of Things device; When the IoT device receives the data ciphertext, the second key ciphertext data and the second signature data sent by the IoT platform, the IoT device decrypts the second key ciphertext data according to the device encryption private key to obtain the second symmetric key; The IoT device decrypts the data ciphertext according to the second symmetric key to obtain the instruction plaintext data; The IoT device verifies the second signature data according to the platform signature public key; the platform signature public key corresponds to the IoT platform and is preset in the IoT device; When the IoT device determines that the second signature data has been verified, the service processes the instruction plaintext data.

[0007] In an optional embodiment, the method further comprises: The IoT device randomly generates the device signature key pair, and signs the device signature public key and the device serial number according to the device signature private key in the device signature key pair to obtain third signature data, and encrypts the device signature public key and the device serial number according to the platform encryption public key to obtain ciphertext data; The Internet of Things device sends the third signature data and the ciphertext data to the Internet of Things platform; The IoT platform decrypts the ciphertext data according to the platform encryption private key to obtain the device signature public key and the device serial number, and verifies the third signature data according to the device signature public key; The Internet of Things platform randomly generates the device encryption key pair, and encrypts the device encryption private key in the device encryption key pair according to the device signature public key to obtain an encrypted private key ciphertext, and signs the device encryption public key and the encrypted private key ciphertext according to the platform signature private key to obtain fourth signature data; The Internet of Things platform sends the encrypted private key ciphertext, the device encrypted public key and the fourth signature data to the Internet of Things device; The IoT device verifies the fourth signature data according to the platform signature public key, and decrypts the encrypted private key ciphertext according to the device signature private key to obtain the device encryption private key; The IoT device stores the device encryption public key and the device encryption private key to obtain the device encryption key pair.

[0008] In an optional implementation, the IoT device integrates a security chip MCU and a communication module, and the IoT device sends the ciphertext, the first key ciphertext data, and the first signature data to the IoT platform, including: The security chip MCU sends the ciphertext, the first key ciphertext data and the first signature data to the communication module; The communication module establishes a communication connection with the Internet of Things platform to send the ciphertext, the first key ciphertext data and the first signature data to the Internet of Things platform.

[0009] A second aspect of the present application provides an IoT data security transmission system, the system comprising: IoT devices and IoT platforms; The IoT device is used to generate business plaintext data and randomly generate a first symmetric key; encrypt the business plaintext data and the device serial number according to the first symmetric key to obtain a ciphertext; the device serial number corresponds to the IoT device; encrypt the first symmetric key according to the platform encryption public key to obtain first key ciphertext data; the platform encryption public key corresponds to the IoT platform and is preset in the IoT device; sign the business plaintext data according to the device signature private key in the pre-generated device signature key pair to obtain first signature data; send the ciphertext, the first key ciphertext data and the first signature data to the IoT platform; The Internet of Things platform is used for, when receiving the ciphertext, the first key ciphertext data and the first signature data sent by the Internet of Things device, decrypting the first key ciphertext data according to the platform encryption private key to obtain the first symmetric key; decrypting the ciphertext according to the first symmetric key to obtain the business plaintext data and the device serial number; querying the device signature public key according to the device serial number, and verifying the first signature data according to the device signature public key; and when it is determined that the first signature data verification is successful, the business processes the business plaintext data.

[0010] In summary, the IoT data security transmission method and IoT data security transmission system provided by the present application first generate business plaintext data and a random decryption key through the IoT device, and use the key to encrypt the data and its own device serial number to generate ciphertext. Then, the device encrypts the key with the platform's public key to generate a key ciphertext, and uses the pre-set device signature key to digitally sign the plaintext data to generate signature data. Finally, the device sends these three pieces of information to the IoT platform. After receiving the data, the platform uses its own private key to decrypt the key ciphertext to obtain the decryption key, and then uses the decryption key to decrypt the ciphertext sent by the device to obtain the original data and the device serial number, and verifies the signature data of the device by verifying the device signature public key to confirm the data integrity. Only after the verification is successful, the platform performs subsequent business processing. In this way, the entire transmission process realizes data confidentiality and identity authentication, effectively preventing the data from being intercepted or tampered with by a third party during the transmission process, and ensuring the security and reliability of IoT data during the transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 It is a structural diagram of a secure data transmission system for the Internet of Things shown in an embodiment of the present application; Figure 2 It is a flowchart of a method for securely transmitting IoT data shown in an embodiment of the present application; Figure 3This is another schematic diagram of a method for securely transmitting IoT data shown in an embodiment of the present application; Figure 4 This is a schematic diagram of interaction between an IoT device and an IoT platform for secure encrypted data transmission shown in an embodiment of the present application; Figure 5 This is a schematic diagram of a process for securely issuing device keys via an IoT platform as shown in an embodiment of the present application; Figure 6 It is an interactive schematic diagram of an Internet of Things platform securely issuing device keys according to an embodiment of the present application. DETAILED DESCRIPTION

[0012] The present invention is further described below in conjunction with the accompanying drawings and embodiments.

[0013] The following will clearly and completely describe the concept, specific structure and technical effects of the present invention in combination with the embodiments and drawings, so as to fully understand the purpose, characteristics and effects of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, other embodiments obtained by technicians in this field without creative work are all within the scope of protection of the present invention. In addition, all the connection / connection relationships involved in the patent do not refer to the direct connection of components, but refer to the formation of a better connection structure by adding or reducing connection accessories according to the specific implementation situation. The various technical features in the invention can be combined interchangeably without conflicting with each other.

[0014] Reference Figure 1 , which is a schematic diagram of the structure of a system for secure data transmission of the Internet of Things shown in an embodiment of the present application.

[0015] The IoT data security transmission system 1 includes an IoT terminal and an IoT platform 10. The IoT terminal includes a plurality of IoT devices 20 connected to the Internet. The IoT devices 20 are provided with a security chip MCU 201 and a communication module 202. The security chip MCU 201 is responsible for data encryption, decryption, signature and signature verification and other security operations, while the communication module 202 is responsible for data transmission and reception. The IoT platform 10 and the IoT devices 20 perform data transmission and key exchange through the communication module 202. In some embodiments, the security chip MCU refers to a data security chip that integrates the national secret IP security core (a hardware module that integrates the national secret SM2 / SM3 / SM4 / SM9 algorithm), or uses the HXMU305 data security chip equipped with a data security software development kit (SDK) that supports the national secret SM2 / SM3 / SM4 / SM9 algorithm. The IoT platform can be connected to Tianyi IoT's IoT AIoT platform + application services, and through the AIoT national secret service, it provides zero-trust authentication based on UDP / TCP / HTTP / MQTT / LWM2M protocols, uses national secret key management, and supports DTLS / TLS channel encryption. In addition, the IoT platform can also be connected to other cloud application systems to achieve cross-cloud data transmission and processing.

[0016] This application provides security based on data security chips and cloud cryptographic services, solves the process of secure data transmission between IoT devices and IoT platforms, and realizes data security transmission, device authentication, confidentiality protection, and integrity protection.

[0017] Reference Figure 2 The figure is a flow chart of a method for securely transmitting data of the Internet of Things shown in an embodiment of the present application, and the method for securely transmitting data of the Internet of Things includes the following steps.

[0018] Among them, the platform signature public key and platform encryption public key are corresponding to the IoT platform and are pre-set in the IoT device, that is, the IoT device has the signature public key and encryption public key corresponding to the IoT platform pre-set. It should be noted that the signature key pair includes a signature public key and a signature private key, and the encryption key pair includes an encryption public key and an encryption private key. In order to distinguish the signature key pair and encryption key pair of the IoT platform and the IoT device, the signature public key of the IoT platform is called the platform signature public key, the signature private key of the IoT platform is called the platform signature private key, the encryption public key of the IoT platform is called the platform encryption public key, the encryption private key of the IoT platform is called the platform encryption private key, the signature public key of the IoT device is called the device signature public key, the signature private key of the IoT device is called the device signature private key, the encryption public key of the IoT device is called the device encryption public key, and the encryption private key of the IoT device is called the device encryption private key.

[0019] S21, the IoT device generates business plaintext data and randomly generates a first symmetric key.

[0020] Refer to Figure 4When an IoT device needs to report data to the IoT platform, the security chip MCU of the IoT device first needs to determine the business plaintext data D that needs to be reported. Among them, the symmetric key K on the IoT device side is randomly generated and pre-generated. In order to distinguish the symmetric key on the IoT platform side, the symmetric key on the IoT device side is called the first symmetric key.

[0021] S22, the IoT device encrypts the business plaintext data and the device serial number according to the first symmetric key to obtain a ciphertext.

[0022] The device serial number corresponds to the IoT device, and the device serial number ID is unique. Figure 4 The security chip MCU obtains the device serial number of the IoT device stored in advance, and uses the first symmetric key K to encrypt the business plaintext data D and the device serial number ID to obtain the ciphertext .

[0023] S23, the IoT device encrypts the first symmetric key according to the platform encryption public key to obtain first key ciphertext data.

[0024] Among them, the IoT device has a pre-built-in platform encryption public key corresponding to the IoT platform. Figure 4 The security chip MCU can use the pre-stored platform encryption public key to encrypt the first symmetric key K to obtain the key ciphertext data (called the first key ciphertext data).

[0025] S24, the IoT device signs the business plaintext data according to the device signature private key in the pre-generated device signature key pair to obtain first signature data.

[0026] In some embodiments, in order to avoid data tampering and forgery to enhance data confidentiality, the IoT device randomly generates its corresponding signature key pair, including a device signature public key and a device signature private key. Figure 4 , the security chip MCU can use the device signature private key to sign the business plaintext data D to obtain signature data s (called the first signature data).

[0027] S25, the IoT device sends the ciphertext, the first key ciphertext data and the first signature data to the IoT platform.

[0028] Refer to Figure 4 , when generating ciphertext , first key ciphertext data After the first signature data s, the security chip MCU can , first key ciphertext data The first signature data s is sent to the communication module that establishes a communication connection with the Internet of Things platform, and the ciphertext , first key ciphertext data And the first signature data s is sent to the IoT platform.

[0029] S26, when the Internet of Things platform receives the ciphertext, the first key ciphertext data and the first signature data sent by the Internet of Things device, the first key ciphertext data is decrypted according to the platform encryption private key to obtain the first symmetric key.

[0030] Refer to Figure 4 When the IoT platform receives the ciphertext uploaded by the IoT device , first key ciphertext data When the first key ciphertext data is encrypted by the IoT device using the platform encryption public key to encrypt the first symmetric key K, the IoT platform can use the platform encryption private key that corresponds to the platform encryption public key to encrypt the first key ciphertext data. Decryption is performed. When the decryption is successful, the first symmetric key K can be correctly obtained.

[0031] S27, the Internet of Things platform decrypts the ciphertext according to the first symmetric key to obtain the business plaintext data and the device serial number.

[0032] After decryption, the IoT platform can use the first symmetric key K to decrypt the ciphertext. Decryption is performed. When the decryption is successful, the business plaintext data D and the device serial number ID can be correctly obtained.

[0033] S28, the Internet of Things platform queries the device signature public key according to the device serial number, and verifies the first signature data according to the device signature public key.

[0034] Since the device serial number ID of each IoT device is unique, the device signature key and device encryption key corresponding to each IoT device are different. Among them, the IoT device needs to be registered before accessing the IoT platform. During the registration process, the IoT device will generate a pair of signature key pairs, namely, a device signature public key and a device signature private key. When registering, the IoT device will upload the device signature public key to the IoT platform, and the device signature public key will be used by the IoT platform to encrypt the device encryption private key and verify the integrity of the data sent by the device IoT. The device signature private key is stored in the security chip MCU of the IoT device, which is used to decrypt the encrypted private key ciphertext sent by the IoT platform and verify the signature of the data sent by the IoT platform. After the IoT platform decrypts and obtains the device serial number ID, it can query the corresponding device signature public key in the database. The device signature public key is generated by the IoT device when it is registered and stored on the IoT platform, which is used to verify the signature data of the IoT device. When the device signature public key is queried, the IoT platform can verify the first signature data s based on the device signature public key. Specifically, since the first signature data s is obtained by the security chip MCU signing the business plaintext data D based on the device signature private key, and the device signature private key and the device signature public key are one-to-one corresponding, the Internet of Things platform verifies the first signature data s by using the correct device signature public key.

[0035] S29, when the Internet of Things platform determines that the first signature data is successfully verified, the business processes the business plaintext data.

[0036] Furthermore, when the verification is successful, that is, the first signature data s is indeed sent by the corresponding IoT device and has not been tampered with, the IoT platform can perform corresponding processing on the successfully verified business plaintext data D according to the business logic, including updating device status, recording logs, executing instructions and other operations.

[0037] Through the above optional implementation, the business plaintext data is encrypted by the randomly generated first symmetric key, which effectively prevents the leakage of data during transmission. At the same time, the symmetric key is encrypted by the platform encryption public key, and the business plaintext data is signed by the device signature private key, which further enhances the confidentiality and integrity of the data. By verifying the signature and decrypting the data, the IoT platform can confirm the source and integrity of the data, so as to make correct business processing, ensure the security of data transmission between the IoT device and the platform, improve the security and credibility of the IoT system, and provide a strong security guarantee for IoT applications.

[0038] Reference Figure 3 , is another flow chart of a method for securely transmitting data of the Internet of Things shown in an embodiment of the present application, and the method for securely transmitting data of the Internet of Things includes the following steps.

[0039] S31, the Internet of Things platform generates instruction plaintext data and randomly generates a second symmetric key.

[0040] Refer to Figure 4 When the IoT platform needs to send data to the IoT device, the IoT platform first determines the plaintext data d of the instruction to be sent. Similarly, the symmetric key k on the IoT platform is also randomly generated and pre-generated. In order to distinguish the symmetric key on the IoT device, the symmetric key on the IoT platform is called the second symmetric key.

[0041] S32, the Internet of Things platform encrypts the instruction plaintext data according to the second symmetric key to obtain data ciphertext.

[0042] Refer to Figure 4 The IoT platform can use the second symmetric key k to encrypt the instruction plaintext data d to obtain the data ciphertext .

[0043] S33, the Internet of Things platform queries the corresponding device encryption public key in the pre-generated device encryption key pair according to the device serial number, and encrypts the second symmetric key according to the device encryption public key to obtain second key ciphertext data.

[0044] The device encryption public key is generated when the IoT device is registered and stored on the IoT platform. The IoT platform queries the device encryption public key corresponding to the device serial number ID of the IoT device from the database. Figure 4 After the device encryption public key is queried, the IoT platform can use the device encryption public key to encrypt the second symmetric key k to obtain the key ciphertext data (referred to as the second key ciphertext data).

[0045] S34, the Internet of Things platform signs the instruction plaintext data according to the platform signature private key to obtain second signature data.

[0046] Refer to Figure 4 The IoT platform can use the platform signature private key to sign the instruction plaintext data d and obtain the signature data (called the second signature data).

[0047] S35, sending the data ciphertext, the second key ciphertext data and the second signature data to the Internet of Things device.

[0048] Refer to Figure 4 , when generating data ciphertext , Second key ciphertext data And the fourth signature data After that, the IoT platform can generate data ciphertext , Second key ciphertext data And the fourth signature data The communication model sent to the IoT device will generate data ciphertext through the communication module , Second key ciphertext data And the fourth signature data Sent to the security chip MCU of the IoT device.

[0049] S36, when the IoT device receives the data ciphertext, the second key ciphertext data and the second signature data sent by the IoT platform, it decrypts the second key ciphertext data according to the device encryption private key to obtain the second symmetric key.

[0050] Refer to Figure 4 The security chip MCU of the IoT device receives the data ciphertext sent by the IoT platform , Second key ciphertext data And the fourth signature data When the device encrypts the private key, the second key ciphertext data is first Decryption is performed. When the decryption is successful, the second symmetric key k can be correctly obtained.

[0051] S37, the Internet of Things device decrypts the data ciphertext according to the second symmetric key to obtain the instruction plaintext data.

[0052] Refer to Figure 4 Since the data ciphertext is encrypted by the IoT platform based on the second symmetric key pair k instruction plaintext data d, after the security chip MCU decrypts and obtains the second symmetric key k, the security chip MCU can use the second symmetric key k to encrypt the data ciphertext Decryption is performed. When the decryption is successful, the instruction plaintext data d can be correctly obtained.

[0053] S38, the IoT device verifies the second signature data according to the platform signature public key.

[0054] Since the second signature data The IoT platform signs the instruction plaintext data d using the platform signature private key. Therefore, when the IoT device receives the second signature data When the second signature data of the platform signature public key corresponding to the pre-stored IoT platform is obtained, to verify. S39: When the IoT device determines that the second signature data has been verified, the service processes the instruction plaintext data.

[0055] When the verification is successful, the second signature data If it is indeed issued by the corresponding IoT platform and has not been tampered with, the IoT device can process the successfully verified command plaintext data d accordingly according to the service logic, including updating device status, recording logs, executing commands and other operations.

[0056] Through the above-mentioned optional implementation method, the plaintext data of the instruction is encrypted by a randomly generated second symmetric key to ensure the confidentiality of the data, and the symmetric key is encrypted by using the device encryption public key and the platform signature private key to sign the instruction data, thereby enhancing the integrity of the data and the credibility of the source. The IoT device verifies the signature and decrypts the data to ensure that the received instructions are authentic and valid, thereby accurately executing the operation, effectively preventing data leakage and tampering, and providing security for the stable operation of the IoT system.

[0057] Reference Figure 5 As shown, a schematic diagram of a process for securely issuing device keys via an Internet of Things platform is shown in an embodiment of the present application.

[0058] S51, the IoT device randomly generates the device signature key pair, and signs the device signature public key and the device serial number according to the device signature private key in the device signature key pair to obtain third signature data, and encrypts the device signature public key and the device serial number according to the platform encryption public key to obtain ciphertext data.

[0059] In some embodiments, based on the PKI public key infrastructure, each IoT device is assigned unique identity authentication information (such as a device encryption key) for identity recognition and security verification when the IoT device accesses the network or communicates with other devices or servers. The device encryption key is like the "ID card" of the IoT device. Only after the verification of the device encryption key can the IoT device perform legal operations, such as data transmission, receiving instructions, etc. Figure 6When the IoT device needs to upload data to the IoT platform, the device serial number ID of the IoT device is determined, and the platform signature public key PubK and the device serial number ID are signed using the device signature private key to obtain signature data S (referred to as the third signature data). Then, the platform signature public key PubK and the device serial number ID are encrypted using the platform encryption public key to obtain the ciphertext data E. Specifically, the platform signature public key PubK and the platform encryption public key corresponding to the IoT platform are pre-stored in the security chip MCU built into the IoT device, and a pair of signature key pairs, namely the device signature public key and the device signature private key, are randomly generated through the security chip MCU. In the security chip MCU, the platform signature public key PubK and the device serial number ID are signed using the device signature private key to obtain the third signature data S, and the platform encryption public key can also be used to encrypt the platform signature public key PubK and the device serial number ID to obtain the ciphertext data E.

[0060] S52, the Internet of Things device sends the third signature data and the ciphertext data to the Internet of Things platform.

[0061] After the third signature data S and ciphertext data E are generated, the security chip MCU of the IoT device can send the third signature data S and ciphertext data E to the communication module that establishes a communication connection with the IoT platform, and the third signature data S and ciphertext data E are sent to the IoT platform through the communication module. In some embodiments, during the initialization phase, when the IoT device is manufactured or configured for the first time, a unique asymmetric key (including a public key and a private key) can be generated. During the identity authentication phase, the IoT device can use its own private key to sign the authentication information, and the IoT platform uses the corresponding public key for verification, wherein the public key can be public, but only the IoT device with the corresponding private key can correctly sign, thereby ensuring the authenticity of the IoT device. During the data transmission phase, the IoT device can use the public key of the recipient (for example, the IoT platform) to encrypt the data to be transmitted, and only the recipient with the corresponding private key can correctly decrypt the data, thereby ensuring that the data can only be read by the authorized recipient. It should be noted that the key pair (including the signature key pair and the encryption key pair) is unique during the life cycle of the IoT device, and the private key is securely stored inside the IoT device, that is, stored in the security chip MCU inside it, and is not accessible externally. To enhance security, the system should support regular or on-demand updates of key pairs. When a key pair needs to be updated, a new key pair can be generated through the IoT platform and sent to the IoT device through a secure channel. After receiving the new key pair, the IoT device will replace the old key pair and continue to use the new key pair for subsequent data transmission and authentication operations.

[0062] Through the above optional implementation, through "one device, one key", each IoT device has an independent key. Even if the key of one device is cracked, the security of other devices will not be affected. Compared with the "one device, multiple keys" or shared key method, the scope of security risk is greatly reduced. And the key of each device is unique, so that in the process of security management, it is easy to monitor, audit and troubleshoot a single device. If a security problem occurs, the specific device can be accurately located and the source of the security incident can be traced.

[0063] S53, the Internet of Things platform decrypts the ciphertext data according to the platform encryption private key, obtains the device signature public key and the device serial number, and verifies the third signature data according to the device signature public key.

[0064] Refer to Figure 6 When the IoT platform receives the third signature data S and ciphertext data E sent by the IoT device, since the ciphertext data E is encrypted by the platform encryption public key, which contains the platform signature public key PubK and the device serial number ID, the IoT platform can decrypt the ciphertext data E based on its own platform encryption private key. Since encryption and decryption are corresponding, the data encrypted with the corresponding public key can be successfully decrypted using the correct private key. When the decryption is successful, the IoT platform can correctly obtain the platform signature public key PubK and the device serial number ID in plain text. Further, after decrypting and obtaining the platform signature public key PubK, the IoT platform can verify the third signature data S based on the platform signature public key PubK. Since the third signature data S is obtained by signing the platform signature public key PubK and the device serial number ID with the device signature private key, it is used to verify the integrity of the information and the identity of the sender. Therefore, when verifying the third signature data S, the IoT platform can recalculate the hash value of the device serial number ID, and then use the platform signature public key PubK to perform some mathematical operation on the third signature data S (such as the verification algorithm in RSA or ECDSA), and compare the output result with the calculated hash value. When the two match, it means that the signature is valid, that is, the third signature data S is indeed generated by the IoT device with the corresponding private key, and the data has not been tampered with during transmission. If they do not match, the signature is invalid, and there may be security issues or data errors.

[0065] Through the above optional implementation methods, encryption ensures the confidentiality of data during transmission, while signature ensures the integrity of data and the identity authentication of the sender. The security and integrity of data are jointly guaranteed by encryption and signature mechanisms.

[0066] S54, the Internet of Things platform randomly generates the device encryption key pair, and encrypts the device encryption private key in the device encryption key pair according to the device signature public key to obtain an encrypted private key ciphertext, and signs the device encryption public key and the encrypted private key ciphertext according to the platform signature private key to obtain fourth signature data.

[0067] S55, the Internet of Things platform sends the encrypted private key ciphertext, the device encrypted public key and the fourth signature data to the Internet of Things device.

[0068] Refer to Figure 6 , the IoT platform randomly generates a pair of encryption key pairs, including an encryption public key EPubK (called a device encryption public key) and an encryption private key EPriK (called a device encryption private key), and encrypts the device encryption private key EPriK based on the device signature public key to obtain the encryption private key ciphertext Enc (EPriK), and uses the platform signature private key to sign the device encryption public key EPubK and the encryption private key ciphertext Enc (EPriK) to obtain a signature data Sign (called the fourth signature data). When the encryption private key ciphertext Enc (EPriK) and the fourth signature data Sign are generated, the IoT platform can send the encryption private key ciphertext Enc (EPriK), the fourth signature data Sign and the device encryption public key EPubK to the IoT device. Specifically, the IoT platform first sends the encryption private key ciphertext Enc (EPriK), the fourth signature data Sign and the device encryption public key EPubK to the communication module of the IoT device, and sends the encryption private key ciphertext Enc (EPriK), the fourth signature data Sign and the device encryption public key EPubK to the security chip MCU of the IoT device through the communication module.

[0069] Through the above optional implementation method, an encryption key pair is randomly generated by the Internet of Things platform, and the device encryption private key is encrypted using the device signature public key, thereby ensuring the security of the device encryption private key during transmission. The Internet of Things platform uses the platform signature private key to sign the device encryption public key and the encrypted private key ciphertext to generate a second signature data to verify the integrity and authenticity of the data, effectively preventing data tampering and leakage during transmission, and ensuring the security of communication between the Internet of Things device and the Internet of Things platform.

[0070] S56, the IoT device verifies the fourth signature data according to the platform signature public key, and decrypts the encrypted private key ciphertext according to the device signature private key to obtain the device encryption private key.

[0071] When the security chip MCU of the IoT device receives the encrypted private key ciphertext Enc (EPriK), the fourth signature data Sign and the device encryption public key EPubK, the fourth signature data Sign can be verified based on the platform signature public key in the same implementation method as step S23. If the verification is successful, it can be determined that the encrypted private key ciphertext Enc (EPriK) and the device encryption public key EPubK have not been tampered with during the transmission process and are indeed sent by the IoT platform. After successfully verifying the second signature data, the IoT device can use the platform signature private key to decrypt the encrypted private key ciphertext Enc (EPriK), and when the decryption is successful, the device encryption private key EPriK can be obtained.

[0072] S57, the IoT device stores the device encryption public key and the device encryption private key to obtain the device encryption key pair.

[0073] After the IoT platform generates a device encryption key pair (device encryption public key EPubK and device encryption private key EPriK), the IoT platform simultaneously sends the device encryption public key EPubK when sending the fourth signature data Sign to the IoT device. After decrypting to obtain the device encryption private key EPriK, the IoT device can store the device encryption public key EPubK and the device encryption private key EPriK in the device's secure storage area, that is, in the security chip MCU, thereby obtaining a complete encryption key pair.

[0074] Through the above optional implementation, the security and integrity of data transmission are ensured through two-way authentication and data encryption transmission between the IoT device and the IoT platform. The IoT device uses a signature key pair to sign, and the IoT platform uses the corresponding public key to verify, ensuring the authenticity of the IoT device identity. At the same time, the encryption key pair generated by the IoT platform ensures the security of the encryption key during transmission. After receiving the encryption key, the IoT device verifies and decrypts it to obtain the device encryption private key, and forms an encryption key pair with the device encryption public key for subsequent secure communication, effectively preventing data leakage and tampering, and improving the overall security of the IoT system.

[0075] In an optional embodiment, the method further comprises: The IoT device determines the corresponding device serial number and verifies the device serial number; When the device serial number is successfully verified, the IoT device uploads the device serial number to the IoT platform through device registration; The Internet of Things platform generates a device encryption key corresponding to the Internet of Things device based on the device serial number; The IoT platform sends the device encryption key to the IoT device, so that the IoT device stores the device encryption key in a secure storage area.

[0076] In some embodiments, when the IoT device is started or at a specific time, the device serial number stored in the device, such as the device serial number stored in the security chip MCU, is read through the hardware interface, and the read device serial number is verified through the security chip MCU to ensure that its format is correct, has not been tampered with, and complies with the specifications of the device manufacturer. When the device serial number is successfully verified, the IoT device starts the device registration process, in which the IoT device can establish a connection with the IoT platform based on a secure communication protocol (such as HTTPS, TLS, etc.) through the communication module, and the IoT device uploads the device serial number as part of the registration information to the IoT platform. The IoT platform receives the device serial number uploaded by the IoT device, and also needs to verify the received device serial number to ensure its uniqueness, non-repeated registration, and compliance with the registration specifications of the platform. When the device serial number is successfully verified, the IoT platform generates a device encryption key based on the device serial number, in which the generation process can use a secure encryption algorithm (such as AES, RSA, etc.) and combine the device serial number as input to ensure the uniqueness and security of the key. In addition, the IoT platform can also associate the device serial number with the device encryption key for subsequent management and query. Further, the IoT platform sends the generated device encryption key back to the IoT device through a secure communication protocol. During the transmission process, the IoT platform takes the above-mentioned encryption, signing and other measures to ensure the security and integrity of the device encryption key during transmission. After receiving the device encryption key, the IoT device stores it in the device's secure storage area, such as the security chip MCU.

[0077] In an optional embodiment, the method further comprises: The IoT platform updates the device encryption key according to a preset time period, obtains a new device encryption key, and sends the new device encryption key to the IoT device; After receiving the new device encryption key, the IoT device matches the new device encryption key with the device encryption key currently in use; When the matching result of the Internet of Things device is a successful match, the new device encryption key replaces the device encryption key.

[0078] In some embodiments, the IoT platform can periodically generate a new device encryption key based on the device serial number of the IoT device, and send the new device encryption key to the corresponding IoT device through a secure channel (such as TLS / SSL protocol). After receiving the new device encryption key, the IoT device can match the new device encryption key with the device encryption key in use to determine whether the two are the same. When the two are not the same, the matching result is determined to be a successful match. When the matching result is a successful match, the IoT device can use the new device encryption key to replace the old device encryption key, and ensure that the current data transmission and authentication operations are not interrupted during the replacement process. Further, the IoT device can update its configuration (for example, update the device's firmware, software, or related configuration files) to use the new device encryption key for subsequent data transmission and authentication operations. In some embodiments, after replacing the device encryption key, the IoT device can perform a series of tests to ensure that the new device encryption key can work properly and that data transmission and authentication operations are not affected.

[0079] Through the above optional implementation, the IoT platform generates device encryption keys based on the device serial number, which enhances the uniqueness and security of the keys, and regularly updates the device encryption keys, effectively preventing the risk of key leakage. When the IoT device receives the new key, it can smoothly replace the old key, ensuring the continuity of data transmission and authentication operations, and improving the security of IoT devices and the flexibility of key management.

[0080] It should be noted that, for the convenience of description, the aforementioned method embodiments are all described as a series of action combinations, but those skilled in the art should be aware that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present invention.

[0081] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0082] The above is a specific description of the preferred implementation of the present invention, but the invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of this application.

Claims

1. A method for secure transmission of Internet of Things data, characterized in that: Applied to an Internet of Things data security transmission system, the Internet of Things data security transmission system includes an Internet of Things device and an Internet of Things platform, and the method includes: The IoT device generates business plaintext data and randomly generates a first symmetric key; The IoT device encrypts the service plaintext data and the device serial number according to the first symmetric key to obtain a ciphertext; the device serial number corresponds to the IoT device; The IoT device encrypts the first symmetric key according to the platform encryption public key to obtain first key ciphertext data; the platform encryption public key corresponds to the IoT platform and is preset in the IoT device; The IoT device signs the business plaintext data according to a device signature private key in a pre-generated device signature key pair to obtain first signature data; The Internet of Things device sends the ciphertext, the first key ciphertext data and the first signature data to the Internet of Things platform; When the IoT platform receives the ciphertext, the first key ciphertext data and the first signature data sent by the IoT device, the IoT platform decrypts the first key ciphertext data according to the platform encryption private key to obtain the first symmetric key; The Internet of Things platform decrypts the ciphertext according to the first symmetric key to obtain the business plaintext data and the device serial number; The IoT platform queries the device signature public key according to the device serial number, and verifies the first signature data according to the device signature public key; When the Internet of Things platform determines that the first signature data is successfully verified, the business processes the business plaintext data.

2. The method for secure data transmission of the Internet of Things according to claim 1, characterized in that: The method further comprises: The Internet of Things platform generates instruction plaintext data and randomly generates a second symmetric key; The Internet of Things platform encrypts the instruction plaintext data according to the second symmetric key to obtain data ciphertext; The IoT platform queries the corresponding device encryption public key in the pre-generated device encryption key pair according to the device serial number, and encrypts the second symmetric key according to the device encryption public key to obtain second key ciphertext data; The Internet of Things platform signs the instruction plaintext data according to the platform signature private key to obtain second signature data; Sending the data ciphertext, the second key ciphertext data and the second signature data to the Internet of Things device; When the IoT device receives the data ciphertext, the second key ciphertext data and the second signature data sent by the IoT platform, the IoT device decrypts the second key ciphertext data according to the device encryption private key to obtain the second symmetric key; The IoT device decrypts the data ciphertext according to the second symmetric key to obtain the instruction plaintext data; The IoT device verifies the second signature data according to the platform signature public key; the platform signature public key corresponds to the IoT platform and is preset in the IoT device; When the IoT device determines that the second signature data has been verified, the service processes the instruction plaintext data.

3. The method for secure data transmission of the Internet of Things according to claim 1, characterized in that: The method further comprises: The IoT device randomly generates the device signature key pair, and signs the device signature public key and the device serial number according to the device signature private key in the device signature key pair to obtain third signature data, and encrypts the device signature public key and the device serial number according to the platform encryption public key to obtain ciphertext data; The Internet of Things device sends the third signature data and the ciphertext data to the Internet of Things platform; The IoT platform decrypts the ciphertext data according to the platform encryption private key to obtain the device signature public key and the device serial number, and verifies the third signature data according to the device signature public key; The Internet of Things platform randomly generates the device encryption key pair, and encrypts the device encryption private key in the device encryption key pair according to the device signature public key to obtain an encrypted private key ciphertext, and signs the device encryption public key and the encrypted private key ciphertext according to the platform signature private key to obtain fourth signature data; The Internet of Things platform sends the encrypted private key ciphertext, the device encrypted public key and the fourth signature data to the Internet of Things device; The IoT device verifies the fourth signature data according to the platform signature public key, and decrypts the encrypted private key ciphertext according to the device signature private key to obtain the device encryption private key; The IoT device stores the device encryption public key and the device encryption private key to obtain the device encryption key pair.

4. The method for secure data transmission of the Internet of Things according to claim 1, characterized in that: The IoT device is integrated with a security chip MCU and a communication module, and the IoT device sends the ciphertext, the first key ciphertext data and the first signature data to the IoT platform, including: The security chip MCU sends the ciphertext, the first key ciphertext data and the first signature data to the communication module; The communication module establishes a communication connection with the Internet of Things platform to send the ciphertext, the first key ciphertext data and the first signature data to the Internet of Things platform.

5. A secure data transmission system for the Internet of Things, characterized in that: The system comprises: IoT devices and IoT platforms; The IoT device is used to generate business plaintext data and randomly generate a first symmetric key; encrypt the business plaintext data and the device serial number according to the first symmetric key to obtain a ciphertext; the device serial number corresponds to the IoT device; encrypt the first symmetric key according to the platform encryption public key to obtain first key ciphertext data; the platform encryption public key corresponds to the IoT platform and is preset in the IoT device; sign the business plaintext data according to the device signature private key in the pre-generated device signature key pair to obtain first signature data; send the ciphertext, the first key ciphertext data and the first signature data to the IoT platform; The Internet of Things platform is used for, when receiving the ciphertext, the first key ciphertext data and the first signature data sent by the Internet of Things device, decrypting the first key ciphertext data according to the platform encryption private key to obtain the first symmetric key; decrypting the ciphertext according to the first symmetric key to obtain the business plaintext data and the device serial number; querying the device signature public key according to the device serial number, and verifying the first signature data according to the device signature public key; and when it is determined that the first signature data verification is successful, the business processes the business plaintext data.

Citation Information

Patent Citations

  • Implementing method for user key application downloading security protocol applicable to SM9 identity password

    CN108599950A

  • Internet of Things equipment safety communication method and system

    CN112332975A

  • Internet of Things trusted data management method based on block chain technology

    CN113553574A

  • Method and system for enhancing MQTT protocol transmission security by using symmetric cryptographic technology

    CN113630407A

  • Data transmission method and device, electronic equipment and computer readable medium

    CN115941278A