Secure communication method for heterogeneous Internet of Things

By establishing hidden channels in a heterogeneous Internet of Things environment and performing multi-protocol conversion, the problems of communication incompatibility between heterogeneous devices and encryption key exchange are solved, and secure and efficient information transmission is achieved.

CN119996007AActive Publication Date: 2025-05-13CHONGQING UNIV OF POSTS & TELECOMM
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510162339.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-13
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

In the heterogeneous Internet of Things, there are problems with communication incompatibility, poor concealment and encryption key exchange between devices, resulting in insecure and inefficient information transmission.

Method used

By establishing a hidden channel between the control end and the controlled end, data transmission is carried out using a symmetric encryption key, and multi-protocol conversion is carried out in the channel, secure interconnection and interoperability between heterogeneous devices is achieved.

Benefits of technology

Quickly establish lightweight secure channels in a heterogeneous IoT environment, support multi-protocol conversion, reduce hardware overhead, improve information transmission efficiency, and solve key exchange problems, ensuring the security and concealment of information transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996007A_ABST
    Figure CN119996007A_ABST
Patent Text Reader

Abstract

The invention relates to a secure communication method for heterogeneous Internet of Things, which comprises the following steps that: a control end establishes a covert channel according to a communication protocol between the control end and a controlled end, sends an encryption mode and a random key to the controlled end by using the covert channel, establishes a secure channel with the control end, encrypts a control instruction input by a user to obtain an instruction ciphertext, and sends the instruction ciphertext to the controlled end; the specified ciphertext is transmitted to the controlled end through the established secure channel, the controlled end decrypts the instruction ciphertext through the obtained encryption mode and the random key to obtain a decryption instruction, and the decryption instruction is forwarded to a specified destination address through a corresponding port after being subjected to protocol conversion. The device of the destination address executes a corresponding operation according to the decryption instruction and returns a corresponding request resource, the controlled end encrypts the request resource through the obtained encryption mode and the random key to obtain an encrypted request resource, and the encrypted request resource is forwarded to the control end through a corresponding port after being subjected to protocol conversion; and the control end receives the encrypted request resource returned by the controlled end, decrypts the encrypted request resource by using the selected encryption mode and the random key to obtain a decrypted request resource, prints the decrypted request resource on a command line interface, and displays the decrypted request resource to a user. According to the invention, the concealment of network communication is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication technology, and in particular relates to a secure communication method for heterogeneous Internet of Things. Background Art

[0002] The concept of the Internet of Things (IoT) is increasingly being integrated into various industries, such as smart homes, smart healthcare, forest fire prevention, agricultural irrigation, geological surveys, military, transportation, and other fields. With the continuous advancement of modern communication technology, the scale of the IoT will continue to expand, making it possible to accommodate more terminals and transmit more data. At the same time, it has brought about the coexistence of multiple communication networks, including wireless local area networks (WiFi), wireless personal area networks (Bluetooth), mobile communication networks (4G 5G), short-range wireless sensor networks (ZigBee, Zwave), satellite networks, Ethernet, etc., forming a heterogeneous network.

[0003] In order to adapt to the increasingly dynamic and complex environment, heterogeneous IoT technologies have shown different advantages and disadvantages in deployment and operation environment, system scale, communication range, required bandwidth, latency, reliability, security, etc., and have realized different functions and applications. However, there are a large number of devices and sensors in heterogeneous IoT. These devices may come from different manufacturers and use different communication protocols and data formats, resulting in incompatibility between different networks in terms of interconnection and information exchange. In current research, the mainstream method mostly uses specific protocols for specific devices to build IoT gateways, which is difficult to migrate to other IoT environments. In addition, IoT gateways are usually additional physical devices with very low convenience and timeliness, which is not conducive to information acquisition in the increasingly complex heterogeneous IoT scenarios.

[0004] In heterogeneous IoT, there are a large number of devices and a huge amount of data exchange between devices, which may contain a large amount of personal data and privacy information. The security performance and data protection capabilities of different devices may vary. The communication process lacks security and confidentiality, and may face various interferences and attacks, such as network attacks, data tampering or device impersonation, which may easily cause privacy leakage, identity theft and other problems. Heterogeneous IoT communication is mainly carried out in wireless network channels. Due to the openness of wireless networks, attackers are widely present in open networks. Communication eavesdropping and privacy data leakage may cause immeasurable hidden dangers and dangers. The upper-layer encryption technology based on cryptography is the most important means to protect data security, but it is difficult to distribute and manage keys in highly dynamic heterogeneous networks. Summary of the invention

[0005] In order to solve the problem existing in background memory, the present invention provides a secure communication method for heterogeneous Internet of Things, including:

[0006] S1: The control end establishes a covert channel according to the communication protocol between the control end and the controlled end, and uses the covert channel to send the encryption method and random key to the controlled end;

[0007] S2: The controlled end receives the encryption method and random key from the covert channel and establishes a secure channel with the control end;

[0008] S3: The control end encrypts the control command input by the user to obtain the command ciphertext, and transmits the specified ciphertext to the controlled end through the established secure channel;

[0009] S4: The controlled end decrypts the command ciphertext using the obtained encryption method and random key to obtain a decrypted command, converts the decrypted command into a protocol, and forwards it to the specified destination address through the corresponding port;

[0010] S5: The device at the destination address performs corresponding operations according to the decryption instruction and returns the corresponding requested resources;

[0011] S6: The controlled end encrypts the request resource by using the obtained encryption method and the random key to obtain an encrypted request resource, performs protocol conversion on the encrypted request resource, and forwards it to the control end through the corresponding port;

[0012] S7: The control end receives the encrypted request resource sent back by the controlled end, decrypts the encrypted request resource using the selected encryption method and the random key to obtain the decrypted request resource, prints the decrypted request resource on the command line interface, and displays it to the user.

[0013] The present invention has at least the following beneficial effects

[0014] The present invention starts from the perspective of secure transmission of IoT data, and proposes a solution to the problems of lack of interoperability, concealment, and difficulty in exchanging traditional encryption keys in multi-protocol and multi-channel data communications in heterogeneous IoT scenarios. In a large heterogeneous IoT environment, the present invention can quickly provide a lightweight secure channel for the control platform to directly connect to the terminal nodes. The channel supports multi-protocol conversion of heterogeneous IoT, breaks the communication barriers between heterogeneous devices, enables interconnection between heterogeneous devices, reduces additional hardware overhead, and makes network construction more flexible. Furthermore, a covert channel is constructed in the channel between the control end and the controlled end for symmetric encryption key distribution, which ensures information transmission efficiency while solving the key exchange problem. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a schematic diagram of an application scenario of the present invention in a heterogeneous Internet of Things;

[0016] Figure 2 is an overall communication flow chart of an embodiment of the present invention;

[0017] Figure 3 It is a flow chart of the protocol conversion function of the present invention;

[0018] Figure 4 This is an example diagram of port forwarding across Bluetooth and WiFi according to the present invention. DETAILED DESCRIPTION

[0019] The following describes the embodiments of the present invention by specific examples, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner, and the following embodiments and features in the embodiments can be combined with each other without conflict.

[0020] See also Figure 1 The present invention provides a secure communication method for heterogeneous Internet of Things, comprising:

[0021] S1: The control end establishes a covert channel according to the communication protocol between the control end and the controlled end, and uses the covert channel to send the encryption method and random key to the controlled end;

[0022] Preferably, the step S1 specifically includes:

[0023] S11: After the control terminal is started, the encryption method used for this communication is selected from the preset encryption algorithm list;

[0024] S12: According to the selected encryption method, call the key generation function in the corresponding encryption algorithm library to generate a random key;

[0025] S13: When the communication protocol pre-agreed between the control terminal and the controlled terminal is the Bluetooth protocol, selecting a manufacturer-specific data field in the advertisement data as a covert channel;

[0026] S14: When the communication protocol pre-agreed between the control end and the controlled end is the WIFI protocol, the empty field in the extra field of the control frame is used as a covert channel;

[0027] S15: The control end sends a communication request message to the predetermined controlled end through a normal network communication protocol, and formats the selected encryption method and the generated random key, embeds them into a covert channel and sends them to the controlled end.

[0028] Preferably, the formatting of the selected encryption method and the generated random key includes:

[0029] For a set of elements {A i | 0 < i < n}, all elements are stored in an array in a certain order. Array[0] = A 1 , Array[1] = A 2 ,..., Array[n - 1] = A n . During one encoding process, the total number of elements in the array is n, and N bits of covert information can be transmitted each time, where N = log 2 n; Define a mapping relationship f to achieve a one-to-one correspondence between the bit sequence and the elements; The mapping relationship f is defined as follows: For any variable x, 0 ≤ x < 2 N , let the binary representation of x be {b N-1 , b N-2 ,..., b 0}, that is, x = b 2 + b 0 × 2 + … + b 1 × 2 N-2 + b N-2 × 2 N-1 × 2 N-1 , where b i ∈ {0, 1}; Through Array[x], it uniquely corresponds to A x+1 , thus realizing the unique correspondence between the message bits and the elements. Convert the selected encryption method and the generated random secret key into binary representation, and then perform formatting processing through the defined mapping relationship f.

[0030] S2: The controlled end receives the encryption method and the random secret key from the covert channel and establishes a secure channel with the control end;

[0031] Preferably, the establishment of the secure channel includes: The controlled end parses the communication request message according to the communication protocol with the control end, identifies the normal communication request message, and identifies the encryption method and the random secret key in the covert channel according to the rules pre-agreed with the control end, and confirms whether it has the ability to perform secure communication according to this information. If so, through the normal network communication channel, send an agreement communication response packet to the control end.至此, the control end and the controlled end establish a secure channel.

[0032] Preferably, the identification of the encryption method and the random secret key in the covert channel according to the rules pre-agreed with the control end includes: The controlled end obtains the formatted encryption method and the random secret key from the covert channel, finds the position in the array through the mapping relationship f to restore the original binary sequence of N bits in length, and converts the binary sequence into characters to obtain the encryption method and the random secret key.

[0033] S3: The control end encrypts the control instruction input by the user to obtain the instruction ciphertext, and transmits the specified ciphertext to the controlled end through the established secure channel;

[0034] S4: The controlled end decrypts the command ciphertext using the obtained encryption method and random key to obtain a decrypted command, converts the decrypted command into a protocol, and forwards it to the specified destination address through the corresponding port;

[0035] S5: The device at the destination address performs corresponding operations according to the decryption instruction and returns the corresponding requested resources;

[0036] S6: The controlled end encrypts the request resource by using the obtained encryption method and the random key to obtain an encrypted request resource, performs protocol conversion on the encrypted request resource, and forwards it to the control end through the corresponding port;

[0037] Preferably, the controlled end monitors the communication connection of the controlled end in real time through a wireless loop thread. When the controlled end receives a data packet, it first parses the received data packet according to the communication protocol between the sending end and the controlled end, extracts the valid fields in the data packet, and then re-encapsulates the valid field data based on the communication protocol between the controlled end and the receiving end, and sends it to the receiving end through the corresponding port to complete the data protocol conversion.

[0038] S7: The control end receives the encrypted request resource sent back by the controlled end, decrypts the encrypted request resource using the selected encryption method and the random key to obtain the decrypted request resource, prints the decrypted request resource on the command line interface, and displays it to the user.

[0039] Preferably, the controlled end runs silently in the loT device. When the controlled end receives the self-destruction instruction from the control end, the controlled end performs the following operations: disconnecting from the control end and destroying the communication data by multiple replications; terminating and deleting the application according to the operating system of the controlled end; and closing the network connection of the controlled end.

[0040] In order to explain the above scheme in more detail, the following specific implementation methods are provided herein:

[0041] In this embodiment, the control end and the controlled end are deployed at both ends in a dual-end manner. The controlled end is a lightweight heterogeneous IoT middleware, which does not require a fixed gateway device and can be implanted into existing IoT devices and run silently; the control end can run in a PC or Linux terminal, as a command sending and data receiving center, and can access heterogeneous IoT devices without feeling. The two ends are specifically composed of four modules: the control end includes a communication module, an encryption and decryption module, a parameter parsing module, and a data storage module, and the controlled end includes a communication module, an encryption and decryption module, a parameter parsing module, and a self-destruction module. The function of the communication module is to perform various protocol conversions, data exchange, perception networks, and key exchange functions in the heterogeneous IoT. The encryption and decryption module contains symmetric encryption algorithms such as TwoFish, RC4, AES, and SM4 and hash value calculation functions. The parameter parsing module is mainly used to process and interpret various input parameter information. The data storage module is used to save the content returned by the communication locally, and the self-destruction module is used to self-destruct after the communication is completed to complete the senseless access.

[0042] The main steps of this method are: the controlled end B runs silently in the IoT device, and does not display any content or prompts on the user interface, including hiding program icons, background running, etc.; the control end A performs broadcast detection and perception to find all surviving devices within the range; the control end A selects an encryption algorithm and generates a corresponding random key, sends a communication request in the normal channel, and transmits the key of the encryption algorithm used for subsequent communication in the constructed storage-type covert channel; after receiving the connection request and the key, the controlled end B returns to agree to the communication request and confirms the key in the covert channel. At this point, the control end A establishes a secure channel with the controlled end B; the control end A sends the desired The data to be obtained in the heterogeneous IoT scenario is encrypted and sent to the controlled terminal B in the form of commands. The controlled terminal B decrypts the command and analyzes each parameter in the parameter parsing module. The parsing result is transmitted to the corresponding module and then converted into a specific system action. Port forwarding is performed to access the corresponding device. Different devices may use different protocols. The communication module performs different protocol conversions, encrypts the obtained data and returns it along the original path. After the communication is completed, the control terminal A sends a self-destruct command, the control terminal A disconnects from the control terminal B, and the control terminal B performs program self-destruction, completing the entire process of seamless communication.

[0043] See also Figure 1, a method for building a secure channel for heterogeneous Internet of Things. In complex heterogeneous Internet of Things scenarios, the controlled end can be implanted in Android or PC and run in the background without obvious prompts such as pop-ups and icons; the control end runs in the PC in the form of a command line. The controlled end provides communication conversion capabilities for heterogeneous Internet of Things protocols, supporting Bluetooth / hotspot to WiFi / Bluetooth / ZigBee / 5G cellular network / satellite. The implementation principle is that the controlled end can achieve good access to the communication protocols of different perception network layers and perform corresponding mapping processing; it can uniformly process the data collected and uploaded by the perception network, and at the same time, it can differentiate and convert the commands issued to each perception network node to meet the standard control commands of the perception network. For the protocol conversion function flow, please refer to Figure 3 , specifically:

[0044] 1) Protocol adaptation layer, as a two-way channel, ensures that in the face of heterogeneous perception layer networks, various communication network protocols can parse specific effective information through this layer. On the one hand, it is necessary to aggregate various heterogeneous sensor network data for analysis to obtain effective data information, and on the other hand, it is also necessary to parse and reassemble the command data from the upper layer into a data format that conforms to the sensor network transmission.

[0045] 2) Information conversion layer, which organizes the data of the adaptation layer into a unified data format, is also a two-way interactive conversion layer. On the one hand, it extracts, compresses and implements related mapping processing of the adaptation layer data and converts it into a unified data format. On the other hand, it parses the command data from the upper layer and reorganizes the data to conform to the data format that can be correctly understood by the protocol adaptation layer. The extraction of effective data information mainly completes the extraction of information such as destination address, source address, node address, network number, data information, data length, data protocol, etc. The related information mapping processing completes the mapping of different network numbers to upper-layer ports and the unified mapping of heterogeneous perception network addressing.

[0046] 3) Standard information construction layer, according to the standard protocol stack, on the one hand, converts the unified information format into information as data encapsulated in the standard protocol and transmits it through the established communication port, and on the other hand, it can also receive and process standard information from the external network. The protocol encapsulation process is automatically completed by the gateway protocol stack. It only needs to place the data in the data position of the corresponding protocol stack to encapsulate it, and finally send the encapsulated standard data format to the external network.

[0047] See also Figure 2 , the control end will first execute the -scan command to scan the surviving controlled ends within the network range, and return the host name, Bluetooth address and IP address of the controlled end;

[0048] Bluetooth Scanning: Mainly used to discover and identify nearby Bluetooth devices. When a Bluetooth device is powered on and set to discoverable, it broadcasts its Bluetooth address and other relevant information, such as device name, services, etc. The scanning device listens for these broadcasts and records the discovered Bluetooth devices and their information. Bluetooth scanning technology is executed by calling the Bluetooth adapter device.

[0049] ARP Scanning: Within the same local area network, ARP requests can be used to find the mapping relationship between IP addresses and MAC addresses. The principle is to send an ARP request asking for the MAC address corresponding to the target IP address. If the target host is online, it will reply with an ARP response.

[0050] The control end sends a request communication message to the specified controlled end, and through the encryption module, selects an encryption method (one of TwoFish, RC4, AES, SM4) and generates a corresponding random secret key K, which is sent together through the establishment of a storage-type covert channel. The construction of the covert channel is specifically as follows:

[0051] 1) Construction of a covert channel based on the Bluetooth protocol. The Low Energy Bluetooth broadcast data packet includes advertising data (device name, service data, manufacturer-specific data), scan response data, and non-standard fields. Since the content to be transmitted requires less storage space, covert channels can be constructed in all three fields of the data packet. In this invention, information embedding is selected in the manufacturer-specific data field of the advertising data. This field allows device manufacturers to include custom data, has a high degree of uncertainty, and is more difficult to detect hidden data.

[0052] 2) Construction of a covert channel based on the Wi-Fi hotspot. The Wi-Fi network mainly consists of the following three frame types: management frames, control frames, and data frames. Data frames include a frame control field, additional fields of management frames and control frames, additional fields of data frames, and data payloads. The additional fields of data frames describe the types and lengths of upper-layer protocols and data. Since the contained information has differences, some empty fields are reserved to handle different data scenarios. Therefore, this field is a good carrier for a storage-type covert channel.

[0053] 3) Covert information encoding algorithm. For a set of elements {A i | 0 < i < n} of a certain type, all elements are stored in an array in a certain order. Array[0] = A 1 , Array[1] = A 2 ,..., Array[n - 1] = A n . In one encoding process, the total number of elements in the array is n, and N bits of covert information can be transmitted each time, where N = log 2n. Another key to the algorithm is to define a mapping relationship f to achieve a one-to-one correspondence between bit sequences and elements. To this end, this paper finds a mapping relationship f, which is defined as follows: For any variable x, 0≤x<2 N , let the binary representation of x be {b N-1 , b N-2 , ..., b 0}, that is, x = b 0 +b 1 ×2+…+b N-2 ×2 N-2 +b N-1 ×2 N-1 , b i ∈{0, 1}. Uniquely corresponds to A through Array[x] x+1 , thereby achieving a unique correspondence between message bits and elements.

[0054] The controlled end receives the request message and obtains the encryption method and secret key K in the covert channel, and returns a communication consent response packet. At this point, the two ends establish a connection channel;

[0055] The control end enters the expected parameters {control end, controlled end, command, destination address, forwarding protocol, encryption method} in the command line, such as Console.exe 00:1A:7D:DA:71:11-tcp-get 192.168.200.3 / test-wifi-aes. The control end instruction set is shown in Table 1.

[0056] Table 1 Control terminal instruction set

[0057]

[0058]

[0059] The encryption module converts the command body into binary and prints it on the control terminal command line. The binary is encrypted according to the recognized encryption algorithm, and the encrypted result is returned and printed on the control terminal command line. At the same time, the binary is hashed.

[0060] The encrypted result and hash value are transmitted to the controlled end through the channel constructed by S4; the control end receives the ciphertext, decrypts it using the encryption method and secret key K, calculates the hash value of the decrypted content and compares it with the transmitted hash value to ensure the integrity of the message;

[0061] The controlled end performs protocol conversion, converts the Bluetooth protocol content to the WiFi protocol, and forwards the port to the specified destination address. Figure 4In this example, the command to access host C is forwarded to the router, and the router forwards it to host C; host C returns the corresponding requested resources; the controlled end receives the resources of host C, converts the resources into binary and performs protocol conversion, converts the content in WiFi protocol format into content corresponding to the Bluetooth protocol; encrypts according to the obtained encryption method and secret key K, and at the same time, calculates the hash value of the binary content; transmits the encrypted result and hash value to the control end through the constructed secure channel; the control end decrypts and calculates the hash value for comparison to ensure the integrity of resource acquisition; the control end prints the corresponding content in the command line; type the -download command in the control end command line, and the control end calls the data storage module to generate local files and save the most recently returned resources; type the -delete command in the control end command line, and send the command to the controlled end through the above process; the controlled end starts the self-destruct module, disconnects from the control end, and ends the operation and program self-destruction.

[0062] Specifically: When the IoT device completes the communication task, the self-destruct module of the controlled end will perform a series of operations, such as destroying communication data, ending applications, deleting applications, closing network connections, etc., until it reaches irreversible destruction at the physical level.

[0063] Preferably: overwriting is a commonly used technical means for computer data destruction and erasure. Using the format defined by the budget, meaningless and irregular information is used to overwrite the data originally stored in the disk, so that the data is replaced by the overwritten data after being erased, and it is impossible to recover. This is because the disk data is stored in binary form. When the data is overwritten, it is impossible to determine whether the original data is "0" or "1". Although a successful overwrite will cause the data stored in the disk to be unable to be recovered by computer technology, the overwritten data in the disk can be recovered by physical methods using a "disk magnifying glass". Therefore, in order to ensure the reliability of data destruction, multiple overwrites are usually required. The more overwrites, the better the effect of data destruction. The present invention performs three overwrites.

[0064] The controlled end usually lives in Windows, Linux, and Android. The Windows program self-destruction will first create a batch file (.bat). In the batch file, the taskkill command is used to end the process of the current program; then, the del command is used to delete the file of the specified program; finally, the del%0 command is used to self-delete after the above operations are performed, where %0 represents the path of the batch file itself. The idea of ​​Linux program self-destruction is consistent with the above-mentioned Windows program self-destruction. First, a Shell script file (.sh) will be created. In the script, the kill command is used to end the process of the current program; then, the rm command is used to delete the file of the specified program; finally, the rm$0 command is used to self-delete after the above operations are performed, where $0 represents the path of the script file itself. Android program self-destruction requires that the device has been rooted and the application is deleted by calling the deletePackage method. It should be noted that in addition to the above examples of the present invention, the present invention also includes functions such as silently turning on / off Bluetooth, WiFi, and 5G data links.

[0065] In this embodiment, the steps of identifying the encryption method and random key in the covert channel according to the rules pre-agreed with the control end and confirming the key include:

[0066] 1) The encryption and decryption module of the controlled end obtains the embedded information from the storage covert channel of WiFi or Bluetooth, and restores the original N-bit binary sequence {b N-1 ,b N-2 ,…,b 0}, convert the binary to characters to get the encryption method and key, and store them in the DECRYPTIC_WAY and DECRYPTIC_KEY parameters respectively.

[0067] 2) The controlled end uses the DECRYPTIC_WAY encryption method and the DECRYPTIC_KEY key to encrypt "agree to communicate" and embed it into the covert channel of the data packet agreeing to communicate.

[0068] 3) The encryption and decryption module of the controlled end of the control end obtains the embedded information from the storage covert channel of WiFi or Bluetooth, decrypts it using the previously selected encryption method and the generated key to obtain the plain text, and compares whether the plain text is "agree to communicate". If the comparison is successful, the key distribution is completed.

[0069] The controlled end forwards the instruction-related data to the specified destination address through a port, including:

[0070] 1) The communication module started by the controlled end will start two infinite loop threads. The tcp_handle_connections() thread function is used to listen to TCP connection requests, and the bluetooth_handle_connections() thread function is used to accept Bluetooth connection requests.

[0071] 2) After receiving the data, the hamc_comp() function is used to compare the two hmac values ​​to verify the data integrity, and the process_data() function is called to decrypt the encrypted information using the DECRYPTIC_WAY and DECRYPTIC_KEY parameters to obtain the executed command, forwarded protocol, and forwarded content, which are stored in the dwFunc, dwProto_C, and dwContent variables respectively.

[0072] 3) If dwFunc is GET, perform protocol conversion. Taking WiFi to zigbee as an example, use tcp_handle_connections() thread function and dwProto_C=zigbee. The controlled end will call zigbee_process() function to repackage dwContent data according to the zigbee message format and send it to the zigbee module through the serial port. The data is broadcast to the target device through the Zigbee module to control the zigbee node.

[0073] 4) After host C receives the message from control terminal A through the Zigbee module, it can send information to control terminal A in reverse through the controlled terminal through Zigbee to WiFi. The controlled terminal B program reads the data from Zigbee in the serial port, parses the valid data from the physical layer to the application layer, and then calls the encrypted_date() function to encrypt the data using the DECRYPTIC_WAY and DECRYPTIC_KEY parameters, and encapsulates the encrypted information into the TCP / IP message format, and finally sends it to the hardware processing of the Ethernet communication protocol that complies with IEEE802.3, so as to realize the encryption of Zigbee data and transmit it to the external WiFi.

[0074] The encrypted data received by the control terminal includes:

[0075] 1) The control end receives data in a similar way to the controlled end. The communication module is started to listen to the established secure channel. After receiving the data, the hamc_comp() function is used to compare the two hmac values ​​to verify the data integrity, and the process_data() function is called to use the previously selected encryption method and the generated key to decrypt the plain text, and the print__data() function is called to print it to the console.

[0076] 2) The control end inputs the download command, and the data storage module will call the save_data() function and use the “>>” redirection command to append the decrypted return information to the local file result.txt.

[0077] In response to the self-destruction instruction sent by the control end, the controlled end calls the uninstallDataAPPBySilent() function to perform the following operations:

[0078] 1) Disconnect the connection with the control end and destroy the communication data by copying it multiple times.

[0079] 2) End or delete the application according to the operating system of the controlled end. For example, the self-destruction of the Windows program will first create a batch file (.bat). In the batch file, use the taskkill command to end the process of the current program; then, use the del command to delete the file of the specified program; finally, use the del%0 command to self-delete after executing the above operations, where %0 represents the path of the batch file itself. The idea of ​​Linux program self-destruction is the same as the above-mentioned Windows program self-destruction. First, create a Shell script file (.sh). In the script, use the kill command to end the process of the current program; then, use the rm command to delete the file of the specified program; finally, use the rm$0 command to self-delete after executing the above operations, where $0 represents the path of the script file itself. Android program self-destruction requires the device to be rooted and deletes the application by calling the deletePackage method.

[0080] 3) Turn off the network connection of the controlled end, such as WiFi, Bluetooth, 5G data, etc.

[0081] In summary, the present invention starts from the perspective of secure transmission of IoT data, and proposes a solution to the problems of lack of interoperability, concealment, and difficulty in exchanging traditional encryption keys in multi-protocol and multi-channel data communications in heterogeneous IoT scenarios. In a large heterogeneous IoT environment, it can quickly provide a lightweight secure channel for the control platform to directly connect to the terminal nodes. The channel supports multi-protocol conversion of heterogeneous IoT, breaks the communication barriers between heterogeneous devices, enables heterogeneous devices to interconnect, and reduces additional hardware overhead, making network construction more flexible. Furthermore, a covert channel is constructed in the channel between the control end and the controlled end for symmetric encryption key distribution, which ensures information transmission efficiency while solving the key exchange problem.

[0082] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the purpose and scope of the technical solution, which should be included in the scope of the claims of the present invention.

Claims

1. A secure communication method for heterogeneous Internet of Things, characterized in that: include: S1: The control end establishes a covert channel according to the communication protocol between the control end and the controlled end, and uses the covert channel to send the encryption method and random key to the controlled end; S2: The controlled end receives the encryption method and random key from the covert channel and establishes a secure channel with the control end; S3: The control end encrypts the control command input by the user to obtain the command ciphertext, and transmits the specified ciphertext to the controlled end through the established secure channel; S4: The controlled end decrypts the command ciphertext using the obtained encryption method and random key to obtain a decrypted command, converts the decrypted command into a protocol, and forwards it to the specified destination address through the corresponding port; S5: The device at the destination address performs corresponding operations according to the decryption instruction and returns the corresponding requested resources; S6: The controlled end encrypts the request resource by using the obtained encryption method and the random key to obtain an encrypted request resource, performs protocol conversion on the encrypted request resource, and forwards it to the control end through the corresponding port; S7: The control end receives the encrypted request resource sent back by the controlled end, decrypts the encrypted request resource using the selected encryption method and the random key to obtain the decrypted request resource, prints the decrypted request resource on the command line interface, and displays it to the user.

2. A secure communication method for heterogeneous Internet of Things according to claim 1, characterized in that: The step S1 specifically includes: S11: After the control terminal is started, the encryption method used for this communication is selected from the preset encryption algorithm list; S12: According to the selected encryption method, call the key generation function in the corresponding encryption algorithm library to generate a random key; S13: When the communication protocol pre-agreed between the control terminal and the controlled terminal is the Bluetooth protocol, selecting a manufacturer-specific data field in the advertisement data as a covert channel; S14: When the communication protocol pre-agreed between the control end and the controlled end is the WIFI protocol, the empty field in the extra field of the control frame is used as a covert channel; S15: The control end sends a communication request message to the predetermined controlled end through a normal network communication protocol, and formats the selected encryption method and the generated random key, embeds them into a covert channel and sends them to the controlled end.

3. A secure communication method for heterogeneous Internet of Things according to claim 2, characterized in that: The establishment of a secure channel includes: the controlled end parses the communication request message according to the communication protocol between the controlled end and the control end, identifies the normal communication request message, and identifies the encryption method and random key in the covert channel according to the rules pre-agreed with the control end, confirms whether it has the ability to communicate securely according to this information, and if so, sends a communication consent response packet to the control end through the normal network communication channel. At this point, the control end and the controlled end establish a secure channel.

4. A secure communication method for heterogeneous Internet of Things according to claim 3, characterized in that: The formatting of the selected encryption method and the generated random key includes: For a set of elements {A i | 0 < i < n}, all elements are stored in an array in a certain order, Array[0] = A1, Array[1] = A2, …, Array[n - 1] = A n . During one encoding process, the total number of elements in the array is n, and N bits of hidden information can be transmitted each time, where N = log2n; Define a mapping relationship f to achieve a one-to-one correspondence between the bit sequence and the elements; The mapping relationship f is defined as follows: For any variable x, 0 ≤ x < 2 N , let the binary representation of x be {b N-1 , b N-2 , …, b0}2, that is, x = b0 + b1×2 + … + b N-2 ×2 N-2 + b N-1 ×2 N-1 , where b i ∈{0, 1}; Through Array[x], it uniquely corresponds to A x+1 , thus achieving a one-to-one correspondence between the message bits and the elements, converting the selected encryption method and the generated random secret key into binary representation, and then performing formatting processing through the defined mapping relationship f.

5. A secure communication method for heterogeneous Internet of Things according to claim 4, characterized in that: The method of identifying the encryption method and random key in the covert channel according to the rules pre-agreed with the control end includes: the controlled end obtains the formatted encryption method and random key from the covert channel, restores the original N-bit binary sequence by searching the position in the array through the mapping relationship f, and converts the binary sequence into characters to obtain the encryption method and random key.

6. A secure communication method for heterogeneous Internet of Things according to claim 4, characterized in that: The controlled end monitors the communication connection of the controlled end in real time through a wireless loop thread. When the controlled end receives a data packet, it first parses the received data packet according to the communication protocol between the sending end and the controlled end, extracts the valid fields in the data packet, and then re-encapsulates the valid field data based on the communication protocol between the controlled end and the receiving end, and sends it to the receiving end through the corresponding port to complete the data protocol conversion.

7. A secure communication method for heterogeneous Internet of Things according to claim 4, characterized in that: The controlled end runs silently in the loT device. When the controlled end receives the self-destruction command from the control end, the controlled end performs the following operations: disconnects from the control end and destroys the communication data by multiple replications; End and delete the application according to the operating system of the controlled end; close the network connection of the controlled end.

Citation Information

Patent Citations

  • Block chain covert communication method based on generative steganography network and image double steganography

    CN116527278A

  • Efficient block chain covert communication method based on address coding

    CN116866052A

  • Block chain privacy protection method and system based on homomorphic encryption algorithm and zero-knowledge proof protocol

    CN116915379A

  • Block chain covert communication method and system based on transaction amount

    CN117114684A

  • Block chain group concealed transmission communication method, system and device and electronic equipment

    CN117714078A