Meteorological data transmission method based on edge protection gateway algorithm
By adopting an edge protection gateway algorithm based on the meteorological data transmission system, the problem of insufficient data security protection in the prior art is solved, and higher data transmission security and reliability are achieved.
Patent Information
- Application Number
- CN202510032154.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-08
- Publication Date
- 2025-05-16
AI Technical Summary
The existing meteorological data transmission systems have shortcomings in data security protection, including insufficient security strength of encryption algorithms, lack of a complete identity authentication mechanism, excessive permission control, and inability to effectively defend against advanced cyber attacks.
The meteorological data transmission method based on the edge protection gateway algorithm is adopted, and the communication connection with the meteorological observation equipment is established through the serial port service controller, and the data is obtained by polling and standardized processing is carried out. The hardware random number generator is used to generate random seeds, and the round key is generated through the key expansion function, the data is encrypted and the message authentication code is calculated. Use digital certificates for identity authentication, establish permission relationship tables, and secure data through firewall status tables and feature matching algorithms.
It improves the security of meteorological observation data transmission, prevents data leakage, tampering and attacks, and ensures the security and reliability of meteorological data.
Smart Images

Figure CN120017318A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data transmission, and in particular to a meteorological data transmission method based on an edge protection gateway algorithm. Background Art
[0002] With the continuous development of meteorological observation technology and the widespread application of Internet of Things technology, the amount of data generated by meteorological observation equipment has increased exponentially. These data play a key role in meteorological forecasting, climate research, disaster prevention and mitigation, and other fields. Traditional meteorological data transmission systems mainly adopt simple network transmission methods, which have significant deficiencies in data security protection. The existing technologies generally adopt basic encryption algorithms and simple access control mechanisms, which show obvious limitations in the face of increasingly complex network security threats. Specifically, the existing technologies have the following major problems in the data transmission process: first, the encryption algorithm used is not strong enough, easy to be cracked, and cannot effectively prevent data leakage; second, there is a lack of a complete identity authentication mechanism, which may lead to unauthorized users obtaining sensitive data; third, the permission control mechanism is too simple and cannot achieve fine-grained access control; finally, in the face of advanced network attacks such as distributed denial of service attacks (DDoS) and man-in-the-middle attacks, the existing protection measures are often unable to provide timely and effective protection, resulting in major hidden dangers in system security.
[0003] In response to the above problems, the industry has carried out a lot of improvement work. In terms of encryption algorithms, some systems have begun to use high-intensity symmetric encryption algorithms, such as AES-256, to improve the strength of data encryption; in terms of identity authentication, a certificate-based authentication mechanism has been introduced to enhance the reliability of identity authentication; in terms of permission control, a role-based access control (RBAC) model has been adopted to achieve more fine-grained permission management; in terms of attack protection, some systems have integrated intrusion detection systems (IDS) and intrusion prevention systems (IPS) to improve the security protection capabilities of the system. However, these improvement measures still have some technical problems and limitations: first, the computational overhead of high-intensity encryption algorithms is large, which may cause system performance degradation when processing high-concurrency meteorological data transmission; second, the certificate-based authentication mechanism is complex in certificate management and update, which increases the system maintenance cost; third, the RBAC model has low efficiency in permission allocation and management when dealing with large-scale users and complex permission relationships; finally, the existing IDS / IPS system has low detection accuracy and a high false alarm rate when facing new network attacks. In addition, most of these improvement measures are implemented independently and lack a unified security framework, which leads to insufficient coordination between the various security modules of the system and difficulty in achieving comprehensive security protection. In practical applications, these technical problems may affect the availability and maintainability of the system, restricting the further development of the meteorological data transmission security system.
[0004] Therefore, there is an urgent need for a technical solution to improve the security of meteorological observation data transmission, prevent data leakage, tampering and attacks, and ensure the security and reliability of meteorological data. Summary of the invention
[0005] In order to solve the deficiencies of the prior art, the embodiment of the present application discloses a meteorological data transmission method based on an edge protection gateway algorithm. The present application solves the technical problems that the prior art meteorological observation data transmission mainly relies on traditional network transmission methods, lacks effective security protection measures, and some devices use simple encryption algorithms, which are insufficient in security and difficult to resist advanced attacks.
[0006] The embodiment of the present application discloses a meteorological data transmission method based on an edge protection gateway algorithm, including: establishing a communication connection with a meteorological observation device through a serial port service controller, obtaining data by polling, storing and backing up the data through sharding after standardization; generating a random seed by using a hardware random number generator, generating round keys by using a key expansion function, performing encryption operations on the grouped data and calculating a message authentication code; sending a cipher suite list to establish a handshake connection, exchanging keys through elliptic curve operations, dividing the compressed data into records and adding authentication tags for transmission; using a digital certificate for identity authentication, establishing a permission relationship table, and performing security protection on the data through a firewall status table and a feature matching algorithm.
[0007] In a possible implementation, a communication connection with a meteorological observation device is established through a serial port service controller, data is obtained by polling, and the data is standardized before being stored and backed up through shards, including: establishing a serial port communication connection with the meteorological observation device through a multi-threaded method, and configuring the communication parameters of the serial port service controller; sending a data request command to the meteorological observation device by polling, and the command frame includes a start identifier, a device address, a command type, a data length, a data content and a check bit; creating an independent acquisition thread to obtain data, and encapsulating the data into a message object containing a timestamp, a device identifier, a data type and load data; using a ring buffer to implement message queue storage, controlling the production rate through a back pressure mechanism, and the consumer thread obtaining messages in batches through a lock-free queue algorithm; standardizing the collected data, including unit conversion, outlier processing and quality control; using a consistent hashing algorithm for data shard storage, achieving load balancing through virtual node mapping, and using a two-phase commit protocol for data backup.
[0008] In a possible implementation, a random seed is generated by a hardware random number generator, a round key is generated by a key expansion function, and encryption operations are performed on the grouped data and a message authentication code is calculated, including: generating an initial entropy pool by a hardware random number generator to generate a random seed; generating round keys by a key expansion function, wherein the expansion function uses system parameters for nonlinear transformation; grouping meteorological observation data according to group length, and padding data that is less than the group length; performing multiple rounds of encryption operations through nonlinear transformation and linear transformation to achieve data obfuscation and diffusion; generating a key stream by a counter working mode, and performing an XOR operation on the key stream and plaintext data; calculating the authentication code using a message authentication algorithm, and performing message authentication by block processing.
[0009] In a possible implementation, a cipher suite list is sent to establish a handshake connection, keys are exchanged through elliptic curve operations, compressed data is divided into records and authentication tags are added for transmission, including: sending a list of supported cipher suites and client random numbers to establish a handshake connection; generating a temporary private key, calculating a public key through elliptic curve point multiplication operations, and both parties exchanging public keys; deriving a master key through a key expansion algorithm, and generating a session key in combination with a random number; compressing the data, and using a double hash linked list to accelerate string matching; dividing the data into records, each record containing header information and an authentication tag; ensuring the correctness of message exchange through a state machine, and using a priority queue to implement message transmission.
[0010] In a possible implementation, digital certificates are used for identity authentication, a permission relationship table is established, and data is securely protected through a firewall state table and a feature matching algorithm, including: using digital certificates for identity authentication, generating signatures through a deterministic random number scheme; establishing a user role relationship table and a role permission relationship table, and using prefix tree indexes to accelerate queries; managing permission changes through a multi-version concurrent control mechanism, and synchronizing data through incremental replication; maintaining the firewall state table, using an improved hash algorithm to reduce conflicts, and aging table items through a hierarchical time wheel algorithm; using a token bucket algorithm to limit the number of connections, and dynamically adjusting the state table capacity; using an improved automaton algorithm for feature matching, and taking corresponding protection measures according to the risk level of the rules.
[0011] In a possible implementation, multiple rounds of encryption operations are performed through nonlinear transformation and linear transformation to achieve data obfuscation and diffusion, including: performing nonlinear transformation on input data according to preset table lookup rules, mapping the input data into transformed output data; performing a first cyclic shift transformation on the output data in sequence to obtain first transformed data; performing a second cyclic shift transformation on the output data in sequence to obtain second transformed data; performing a third cyclic shift transformation on the output data in sequence to obtain third transformed data; performing a fourth cyclic shift transformation on the output data in sequence to obtain fourth transformed data; performing an XOR operation on the original output data and the four transformed data to obtain the final transformation result.
[0012] In a possible implementation, a counter working mode is used to generate a key stream, and the key stream is XORed with plaintext data, including: collecting device timestamp information and device identification information, and obtaining a counter initial value through hash function processing; incrementing the counter initial value based on a preset prime number to generate a counter sequence value; concatenating the counter sequence value with a system random number to form combined data; performing encryption operation on the combined data to generate corresponding key stream data; and performing an XOR operation on the key stream data and the plaintext data to be encrypted to obtain ciphertext data.
[0013] In a possible implementation, a token bucket algorithm is used to limit the number of connections and dynamically adjust the state table capacity, including: setting the capacity parameters and token filling rate parameters of the token bucket; periodically adding tokens to the token bucket according to the preset filling rate; detecting the current memory usage status of the system and calculating the available memory capacity; dynamically adjusting the maximum capacity of the state table according to the available memory capacity; performing token acquisition judgment on newly established connection requests, and allowing the connection to be established when the token is acquired; and rejecting new connection requests when there are no available tokens in the token bucket.
[0014] In a meteorological data transmission method based on an edge protection gateway algorithm as disclosed above, the embodiment of the present application encrypts meteorological observation data through a symmetric encryption scheme based on the national secret SM4 algorithm, and can transmit the encrypted data blocks to ensure the security of data transmission. Further, in some embodiments, by adopting the TLS protocol for data transmission, the data can be encrypted using a session key, and the encrypted data can be sent to the target device. Further, in some embodiments, by adopting an identity authentication mechanism based on a digital certificate, the authenticity of the user's identity can be proved. Further, in some embodiments, by adopting a role-based permission control mechanism, different permissions can be assigned according to user roles, limiting the user's access scope and operation permissions to data. Further, in some embodiments, by adopting a rule-based firewall and intrusion detection system for attack protection, it is possible to monitor network traffic, identify abnormal traffic, and intercept abnormal traffic according to rules to prevent attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0016] Figure 1 A schematic diagram of a flow chart of a meteorological data transmission method based on an edge protection gateway algorithm disclosed in an embodiment of the present application;
[0017] Figure 2 A schematic diagram of a multi-level edge protection architecture disclosed in an embodiment of the present application;
[0018] Figure 3 A schematic diagram of a communication model between a gateway and a security management platform disclosed in an embodiment of the present application;
[0019] Figure 4 A schematic diagram of a process for obtaining a certificate offline by a gateway disclosed in an embodiment of the present application;
[0020] Figure 5 A timing flow chart of online authentication of a gateway device disclosed in an embodiment of the present application;
[0021] Figure 6 A key initialization flow chart disclosed in an embodiment of the present application;
[0022] Figure 7 An overall communication flow chart disclosed in an embodiment of the present application. DETAILED DESCRIPTION
[0023] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that the relative arrangement of components and steps, numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present disclosure unless otherwise specifically stated.
[0024] Those skilled in the art can understand that the terms "first", "second" and the like in the embodiments of the present disclosure are only used to distinguish different steps, devices or modules, etc., and neither represent any specific technical meaning nor represent the necessary logical order between them. It should also be understood that in the embodiments of the present disclosure, "multiple" can refer to two or more, and "at least one" can refer to one, two or more. It should also be understood that for any component, data or structure mentioned in the embodiments of the present disclosure, in the absence of explicit limitation or contrary revelation given in the context, it can generally be understood as one or more. In addition, the term "and / or" in the present disclosure is only a description of the association relationship of the associated objects, indicating that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in the present disclosure generally indicates that the associated objects before and after are an "or" relationship. It should also be understood that the description of each embodiment in the present disclosure emphasizes the differences between the embodiments, and the same or similar parts can refer to each other. For the sake of brevity, they will not be repeated one by one.
[0025] At the same time, it should be understood that, for ease of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship. The following description of at least one exemplary embodiment is actually only illustrative and is by no means intended to limit the present disclosure and its application or use. The techniques, methods and devices known to ordinary technicians in the relevant fields may not be discussed in detail, but where appropriate, the techniques, methods and devices should be considered part of the specification. It should be noted that similar numbers and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0026] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0027] Figure 1 A flow chart of a meteorological data transmission method based on an edge protection gateway algorithm disclosed in an embodiment of the present application.
[0028] like Figure 1 As shown, at step S101, a communication connection with a meteorological observation device is established through a serial port service controller, data is obtained by polling, and the data is standardized and stored and backed up through sharding. It includes: establishing a serial port communication connection with a meteorological observation device through a multi-threaded method, configuring the communication parameters of the serial port service controller; sending a data request command to the meteorological observation device in a polling manner, and the command frame includes a start identifier, a device address, a command type, a data length, a data content, and a check bit; creating an independent acquisition thread to obtain data, and encapsulating the data into a message object containing a timestamp, a device identifier, a data type, and load data; using a ring buffer to implement message queue storage, controlling the production rate through a back pressure mechanism, and the consumer thread batches to obtain messages through a lock-free queue algorithm; standardizing the collected data, including unit conversion, outlier processing, and quality control; using a consistent hashing algorithm for data sharding storage, achieving load balancing through virtual node mapping, and using a two-phase commit protocol for data backup.
[0029] Specifically, the meteorological data transmission method based on the edge protection gateway of the embodiment of the present application starts with the secure data collection link. At this stage, the system establishes a reliable connection with the meteorological observation equipment through a variety of standardized interfaces, including RS232, RS485, TCP / IP and other diversified communication protocols. In order to ensure the efficiency and reliability of data collection, the system adopts a multi-threaded parallel processing mechanism, each observation device is equipped with an independent data collection thread, and efficient data transmission is achieved through an asynchronous message queue. At the same time, the system will perform preliminary format analysis on the collected raw data, support multiple data formats including XML, JSON and binary, and realize dynamic adaptation of the data format through the parsing rules defined in the configuration file. In this link, the system will also perform standardized processing of the data, including unit conversion, outlier processing and quality control operations, to ensure the consistency and reliability of the data. A distributed architecture is used for data storage, and the security and availability of the data are guaranteed through data sharding and backup management mechanisms.
[0030] In one embodiment, in the data security collection link, firstly, the communication parameters of RS232 and RS485 serial interfaces are configured through the serial port service controller, and the baud rate of RS232 is set to 115200bps, the data bit is 8 bits, the stop bit is 1 bit, and there is no check bit; the baud rate of RS485 interface is set to 9600bps, the data bit is 8 bits, the stop bit is 1 bit, and odd check is adopted. For TCP / IP connection, the Socket buffer size is set to 8192 bytes, the TCP_NODELAY option is enabled to disable the Nagle algorithm, and the connection timeout is set to 30 seconds. After establishing the communication connection, a data request command is sent to the meteorological observation equipment every 0.937 seconds through polling mode, and the command frame consists of a start identifier (0x7E), a device address (2 bytes), a command type (1 byte), a data length (2 bytes), data content and a CRC check (2 bytes).
[0031] For each observation device, an independent collection thread is created, with the thread priority set to THREAD_PRIORITY_ABOVE_NORMAL and the thread stack size to 1MB. The collection thread encapsulates the acquired data into a message object, which contains fields such as timestamp, device identification, data type, and load data. The message queue is implemented using a ring buffer with a buffer size of 4096 message slots. When the buffer usage rate exceeds 87.5%, the production rate is controlled by setting a back pressure mechanism with a waiting time of 1.5 milliseconds. The consumer thread obtains messages in batches through a lock-free queue algorithm, processing up to 256 messages at a time.
[0032] For data in XML format, a streaming parsing method based on FSM (finite state machine) is adopted. XML nodes are mapped to state transitions by pre-building a character conversion table. The conversion table size is a two-dimensional array of 256×16. JSON data uses an improved recursive descent parser to optimize the search efficiency of arrays and objects through character pre-reading and skip tables. For binary format, it is parsed according to big-endian byte order, and the value is extracted through bit operations. Shift and mask operations are used to handle unaligned data fields. Data parsing rules are stored in the configuration file. The rule description uses an XML-like DSL (domain-specific language). The rule definition is parsed by the lexical analyzer and the syntax analyzer to generate a parsing instruction sequence.
[0033] In the data standardization process, the modified z-score method is used, and the calculation formula is z = (x-median) / (1.4826 × MAD), where MAD is the median absolute deviation, and when |z|> 3.7, it is marked as an outlier. The outliers are corrected by the local linear interpolation method, and the interpolation window size is 5 data points.
[0034] Data sharding uses a consistent hashing algorithm to map data to different storage nodes according to the hash value of the timestamp. The hash ring is implemented using a balanced binary search tree. The nodes of the tree contain virtual node identifiers, physical node information, and load factors. Each physical node corresponds to 173 virtual nodes, and the hash value of the virtual node is calculated using the MurmurHash3 algorithm. Data backup uses a synchronous replication mechanism. After the master node receives a write request, it synchronizes the data to two slave nodes through a two-phase commit protocol. A successful response is returned only when more than half of the nodes confirm that the write is successful. When a node failure is detected, the node status information is synchronized between surviving nodes through the Gossip protocol, and the data distribution is recalculated.
[0035] At step S102, a random seed is generated by a hardware random number generator, a round key is generated by a key expansion function, and the grouped data is encrypted and a message authentication code is calculated. This includes: generating an initial entropy pool by a hardware random number generator to generate a random seed; generating a round key by a key expansion function, wherein the expansion function uses a system parameter for nonlinear transformation; grouping the meteorological observation data according to the group length, and padding the data that is less than the group length; performing multiple rounds of encryption operations by nonlinear transformation and linear transformation to achieve data obfuscation and diffusion; generating a key stream by a counter working mode, and performing an XOR operation on the key stream and the plaintext data; calculating the authentication code by a message authentication algorithm, and performing message authentication by block processing.
[0036] Specifically, the system enters the data encryption stage and uses a high-intensity SM4 encryption algorithm to protect the data. In this stage, a random seed is first generated by a hardware random number generator, and then a 128-bit encryption key is generated by a key expansion algorithm. The system groups the meteorological observation data into 128 bits, and uses PKCS7 padding to fill the last data block of less than 128 bits. Subsequently, encryption operations are performed through 32 rounds of iterative structures. Each round of operations includes nonlinear transformation τ and linear transformation L, and full obfuscation and diffusion of data are achieved through substitution and shift operations. The encryption process supports multiple working modes, including ECB, CBC, CTR, etc., and can be combined with HMAC-SM3 to achieve data authentication protection. This encryption scheme ensures the confidentiality and integrity of data during transmission, and effectively prevents data from being accessed or tampered with without authorization.
[0037] Among them, multiple rounds of encryption operations are performed through nonlinear transformation and linear transformation to achieve data obfuscation and diffusion, including: performing nonlinear transformation on input data according to preset table lookup rules to map the input data into transformed output data; performing a first cyclic shift transformation on the output data in sequence to obtain first transformed data; performing a second cyclic shift transformation on the output data in sequence to obtain second transformed data; performing a third cyclic shift transformation on the output data in sequence to obtain third transformed data; performing a fourth cyclic shift transformation on the output data in sequence to obtain fourth transformed data; performing an XOR operation on the original output data and the four transformed data to obtain the final transformation result.
[0038] Among them, a counter working mode is adopted to generate a key stream, and an XOR operation is performed on the key stream and the plaintext data, including: collecting device timestamp information and device identification information, and obtaining a counter initial value through hash function processing; incrementing the counter initial value based on a preset prime number to generate a counter sequence value; concatenating the counter sequence value with a system random number to form combined data; performing encryption operation on the combined data to generate corresponding key stream data; performing an XOR operation on the key stream data and the plaintext data to be encrypted to obtain ciphertext data.
[0039] In one embodiment, the data encryption stage first uses a hardware random number generator based on Intel QRG to generate an initial entropy pool by thermal noise sampling, and the entropy pool size is 4096 bytes. The entropy pool data is input into the AES-256-CTR-DRBG algorithm to generate a random seed, and the seed length is 256 bits. The key expansion algorithm generates 32 round keys through the key expansion function FK, and the system parameters of the FK function are (FK0=0xA3B1BAC6, FK1=0x56AA3350, FK2=0x677D9197, FK3=0xB27022DC). The expansion process uses a nonlinear transformation T, and the τ transformation uses an 8×8 S box for byte replacement. The design of the S box is based on the multiplication inverse operation and affine transformation on the finite field GF(28).
[0040] When grouping meteorological observation data, the tail data block that is less than 128 bits is padded according to the PKCS7 specification. The value of the padding byte is equal to the number of padding bytes. For example, when 3 bytes need to be padded, the padding value is 0x03. When the data length is an integer multiple of the packet length, an additional complete packet is padded. In the 32 rounds of encryption iterations, the nonlinear transformation τ of each round is implemented by table lookup, and the linear transformation L is defined as Where B is a 32-bit input and <<< indicates a circular left shift.
[0041] In CTR working mode, the key stream is generated by combining a counter and a random number. The initial value of the counter is generated by processing the timestamp and device identification through the SHA-256 hash function, and the counter increment is 0xF12D94B7 (prime number). The counter value is concatenated with the random number and then encrypted with SM4 to obtain the key stream, which is encrypted with the plaintext through an XOR operation. The HMAC-SM3 algorithm is used to calculate the message authentication code for the encrypted data. The HMAC key length is 256 bits and is derived from the master key through the HKDF-SHA256 algorithm. The message authentication code calculation adopts a block processing method with a block size of 512 bits and an MD construction method for padding.
[0042] At step S103, a cipher suite list is sent to establish a handshake connection, keys are exchanged through elliptic curve operations, and the compressed data is divided into records and an authentication tag is added for transmission. This includes: sending a list of supported cipher suites and client random numbers to establish a handshake connection; generating a temporary private key, calculating a public key through elliptic curve point multiplication, and both parties exchanging public keys; deriving a master key through a key expansion algorithm, and generating a session key in combination with a random number; compressing the data, and using a double hash linked list to accelerate string matching: dividing the data into records, each record containing header information and an authentication tag; ensuring the correctness of message exchange through a state machine, and using a priority queue to achieve message transmission.
[0043] In the data transmission link, the system establishes a secure communication channel based on the TLS1.3 protocol. First, a handshake negotiation is performed, supporting multiple elliptic curve cryptographic algorithms including SM2-P-256 and secp256r1, and ensuring the legitimacy of the identities of both communicating parties through two-way authentication. Subsequently, a temporary Diffie-Hellman key negotiation mechanism is used to generate a 48-byte master key material, and the session key for encryption and authentication is derived through the HKDF algorithm. The data transmission adopts the AEAD encryption method, which divides the data into records with a maximum size of 16384 bytes. Each record contains a 5-byte header and a 16-byte MAC value. The system adopts a pipeline processing method, and is responsible for data fragmentation, compression and integrity protection through the record layer protocol. It supports the DEFLATE compression algorithm and multiple symmetric encryption algorithms. During the entire transmission process, the handshake layer protocol ensures the correctness and integrity of the message exchange through a state machine.
[0044] In one embodiment, during the TLS handshake negotiation phase, the client sends a list of supported cipher suites through a ClientHello message, including TLS_SM4_GCM_SM3_SM2, TLS_AES_256_GCM_SHA384, etc. A 32-byte client random number and session identifier are also sent. The cipher suite selection algorithm gives priority to the ECDHE key exchange scheme with forward security, using the SM2-P-256 elliptic curve.
[0045] During the temporary Diffie-Hellman key negotiation process, the client generates a 32-byte random private key and calculates the public key through elliptic curve multiplication. The server also generates a temporary private key and public key. After the two parties exchange public keys, a 48-byte pre-master key is generated through ECDH operation. The pre-master key is combined with the random numbers in ClientHello and ServerHello to derive the master key through the HKDF-SM3 algorithm. The HKDF algorithm uses a two-step method. First, it extracts the pseudo-random key through HMAC-SM3, and then expands it to obtain the required key material.
[0046] The data record layer numbers each TLS record and uses a 64-bit serial number to prevent replay attacks. The 5 bytes of the record header are: content type (1 byte), protocol version (2 bytes) and length (2 bytes). Before AEAD encryption, the data is first compressed with DEFLATE. The compression algorithm uses a 15-bit window size and a double hash list to accelerate string matching. AEAD encryption uses the SM4-GCM mode, with the record serial number as the associated data, to generate a 16-byte authentication tag. The encrypted data and authentication tag are encapsulated in the TLSInnerPlaintext structure.
[0047] The handshake state machine defines 13 states and 47 state transition rules, including the initial state, waiting for ServerHello, waiting for encryption parameters, waiting for server certificates, etc. Each state transition has a corresponding timeout and retransmission limit. The message queue is implemented as a priority queue to ensure that handshake messages take precedence over application data transmission. Through the fragmentation mechanism of the record layer protocol, data records exceeding the MTU are split into multiple fragments for transmission, and the size of each fragment does not exceed 1432 bytes (considering IP and TCP header overhead).
[0048] At step S104, digital certificates are used for identity authentication, a permission relationship table is established, and data is protected through a firewall state table and a feature matching algorithm. This includes: using digital certificates for identity authentication, generating signatures through a deterministic random number scheme; establishing a user role relationship table and a role permission relationship table, and using prefix tree indexes to accelerate queries; managing permission changes through a multi-version concurrent control mechanism, and synchronizing data through incremental replication; maintaining the firewall state table, using an improved hash algorithm to reduce conflicts, and aging table entries through a hierarchical time wheel algorithm; using a token bucket algorithm to limit the number of connections and dynamically adjust the state table capacity; using an improved automaton algorithm for feature matching, and taking corresponding protective measures according to the rule risk level.
[0049] In one implementation scenario, identity authentication is performed through a digital certificate based on the X.509v3 standard. The certificate contains key information such as version number, serial number, signature algorithm identifier, etc., and the SM2 algorithm is used to sign the certificate. The system implements role-based access control, implements flexible permission management through user-role relationship table and role-permission relationship table, and supports dynamic adjustment and refined control of permissions. In terms of attack protection, the system adopts a multi-layer protection mechanism, including a firewall based on state detection and intrusion defense based on anomaly detection. By maintaining the connection state table to match the characteristics of the data packet, combined with the predefined rule base to identify common attack patterns, it can achieve real-time protection against threats such as DDoS attacks, SQL injections, and XSS attacks. The system supports 1Gbps to 10Gbps traffic collection capabilities, uses multi-threaded parallel processing to perform protocol parsing and anomaly detection, achieves accurate matching through the improved AC automaton algorithm, and implements a hierarchical processing mechanism based on risk levels.
[0050] Among them, a token bucket algorithm is used to limit the number of connections and dynamically adjust the state table capacity, including: setting the capacity parameters and token filling rate parameters of the token bucket; adding tokens to the token bucket at a preset filling rate; detecting the current memory usage status of the system and calculating the available memory capacity; dynamically adjusting the maximum capacity of the state table according to the available memory capacity; making token acquisition judgments for newly established connection requests, and allowing the connection to be established when the token is acquired; and rejecting new connection requests when there are no available tokens in the token bucket.
[0051] In one embodiment, the digital certificate is stored in ASN.1DER encoding, and the certificate extension field contains information such as key usage and CRL distribution point. The certificate serial number generates a 20-byte random number through CSPRNG, and the signature algorithm adopts SM2-with-SM3. During the certificate signing process, the SM3 hash value of the certificate subject is first calculated, and then the hash value is signed using the SM2 private key. The SM2 signature adopts a deterministic random number generation scheme to derive a random number k from the private key and the message hash value using the method defined in RFC6979. The signing process includes calculating the elliptic curve point kG=(x1, y1), r=(e+x1)modn, s=((1+d A )- 1 ×(kr×d A ))mod n, where e is the message hash value, dA is the signature private key, and n is the order of the elliptic curve.
[0052] The user-role relationship and role-permission relationship are stored in a distributed key-value database, using prefix tree index to accelerate queries. The key of the user-role relationship consists of the "ur:" prefix and the user ID, and the value is a set of role IDs; the key of the role-permission relationship consists of the "rp:" prefix and the role ID, and the value is a set of permission descriptors. The permission descriptor is defined using ABNF syntax: permission = resource-type ": "operation [": "resource-id]. The database uses a multi-version concurrency control mechanism, generating a new version for each permission change, and retaining the history of the last 32 versions. The permission data is synchronized to each edge node through an incremental replication mechanism, and the replication delay does not exceed 0.75 seconds.
[0053] The firewall state table is implemented using a customized hash table. Each table entry contains fields such as source IP, destination IP, protocol type, port number, state flag, and counter. The hash function uses the improved FNV-1a algorithm, and reduces hash conflicts by introducing a random perturbation factor. The table entry aging uses a layered time wheel algorithm, setting the TCP connection timeout to 3600 seconds and the UDP flow timeout to 60 seconds. The state table capacity is dynamically adjusted according to the system memory, and supports 2 million concurrent connections by default. For new connections that exceed the session limit, the token bucket algorithm is used for current limiting. The bucket capacity is 10,000 tokens and the filling rate is 2,000 tokens / second.
[0054] The intrusion prevention module uses an improved AC automaton for feature matching, compresses the state transition table through a double-array dictionary tree, and introduces failure pointer optimization. The attack features in the rule base are described by regular expressions, and the regular expressions are converted into deterministic finite automata through the Thompson algorithm. To improve the matching efficiency, a bidirectional search is performed on the feature string, and the matching starts from the beginning and end of the data packet. The matching process adopts a streaming processing method, and the data to be detected is managed through a ring buffer with a buffer size of 2MB. When a matching attack feature is found, corresponding measures are taken according to the risk level of the rule. For sessions that successfully match high-risk rules, the source IP is added to the blocking list with a blocking time of 1800 seconds; for medium-risk rules, the number of concurrent connections of the source IP is limited to no more than 50; for low-risk rules, alarm logs are recorded and statistical analysis is performed.
[0055] Furthermore, the present application discloses a meteorological data transmission system based on an edge protection gateway algorithm, which includes: the edge protection gateway is provided with a data encryption unit, a data transmission unit, an identity authentication unit, an authority control unit and an attack protection unit. The data encryption unit uses the SM4 algorithm to encrypt the meteorological observation data, the data transmission unit realizes the secure transmission of data based on the TLS protocol, the identity authentication unit verifies the user identity through a digital certificate, the authority control unit realizes role-based access control, and the attack protection unit realizes the interception of abnormal traffic through a rule engine.
[0056] The data encryption unit is provided with a key generation module, a data block module and an encryption processing module. The key generation module includes a 128-bit key generator, which generates a random seed through a hardware random number generator and generates the round key required for encryption through a key expansion algorithm. The data block module groups the received meteorological observation data into 128 bits, and fills the last data block of less than 128 bits with PKCS7 padding. The encryption processing module adopts a 32-round iterative structure, each round includes a nonlinear transformation τ and a linear transformation L, and achieves data obfuscation and diffusion through substitution and shift operations.
[0057] In a preferred embodiment, the data transmission unit can adopt the TLS1.3 protocol, including a handshake negotiation module, a key exchange module and a data transmission module. The handshake negotiation module supports the elliptic curve cryptographic algorithm, and curves such as SM2-P-256 and secp256r1 can be selected to ensure the legitimacy of the identities of both communicating parties through two-way authentication. The key exchange module adopts a temporary Diffie-Hellman key negotiation mechanism to generate a 48-byte master key material, and then derives a session key for encryption and authentication through the HKDF algorithm. The data transmission module uses AEAD encryption to divide the data into records with a maximum size of 16384 bytes, each record containing a 5-byte header and a 16-byte MAC value for authentication.
[0058] The identity authentication unit implements user identity authentication through a digital certificate based on the X.509v3 standard. The certificate contains fields such as version number, serial number, signature algorithm identifier, issuer name, validity period, subject name, subject public key information, etc. The certificate signature adopts the SM2 algorithm and uses a 256-bit private key to sign the hash value of the certificate content. During the certificate verification process, the integrity of the certificate chain is first verified, then the certificate is checked to see if it is within the validity period, and finally the certificate revocation status is verified.
[0059] The permission control unit implements the role-based access control (RBAC) model. The unit maintains the user-role relationship table and the role-permission relationship table, and implements flexible permission management through the role inheritance mechanism. When performing permission checks, first obtain the role set to which the user belongs, then obtain the permission set possessed by these roles, and finally determine whether the user has the permission to perform a specific operation. The permission granularity can be refined to the data field level, supporting different types of operation permission control such as read, write, and delete.
[0060] The attack protection unit adopts a multi-layer protection mechanism, including a firewall module based on state detection and an intrusion defense module based on anomaly detection. The firewall module maintains the connection state table and matches the source address, destination address, port number and other features of each data packet to filter illegal connections. The intrusion defense module adopts a feature-based detection method to identify common attack patterns through a predefined rule base, combined with traffic statistics analysis, to achieve real-time protection against DDoS attacks, SQL injections, XSS attacks and other threats.
[0061] Figure 2A multi-level protection architecture diagram disclosed in an embodiment of the present application. It should be understood that the system shown in the figure is exemplary and not restrictive. This means that the system architecture involved is not limited to a specific form or design, but is presented as an example. In other words, the architecture shown in the figure can be regarded as a way of expression to clearly describe related concepts and relationships, and does not exclude other forms of architecture. Therefore, when interpreting the architecture in the picture, it should be understood that the model is flexible and diverse, and its purpose is to disclose an exemplary description rather than a restrictive provision on a specific form.
[0062] The system adopts a multi-level protection architecture design and realizes security isolation through the DMZ network area. The system input layer includes an integrated controller, a security module, and an idle review module. These modules are connected to the DMZ area via an n:1 security gateway. A two-layer service architecture is set up in the DMZ area. The first layer is a security access authentication module, including connecting to the main server and connecting to the physical server; the second layer is four groups of communication service ports, which are responsible for data distribution. The system also deploys multiple groups of parallel security protection policy server clusters to implement policy execution through master-slave application servers. The security protection AGENT module synchronizes policies with the security protection policy server through an independent channel to ensure the real-time and consistency of the policy.
[0063] The output end of the system is connected to three external systems: the IoT Security Center discloses low-level security service platform support, the connection authentication LDM server is responsible for identity authentication, and the meteorological data acquisition equipment processes the actual business data. The solid line of the data flow represents the conventional data transmission channel, and the dotted line represents the privileged communication link with the meteorological data acquisition equipment. The entire system adopts a deep defense architecture with partition isolation and multi-level authentication. The DMZ area is used as the core security barrier. Through multiple mechanisms such as secure access authentication, communication service port distribution, and security protection strategies, the full process of observation equipment access, data transmission, and business processing is realized. The functional modules of the system communicate through standardized interfaces to ensure the security and reliability of data flow.
[0064] Figure 3 A schematic diagram of a communication model between a gateway and a security management platform disclosed in an embodiment of the present application. The communication model between the gateway and the security management platform adopts a three-layer security protection architecture. The application layer implements the encryption and decryption functions of the information element, adopts a dynamic key mechanism, and the server periodically updates the KeyId and IV parameters to ensure the confidentiality of data transmission. The transport layer uses a P10 digital certificate to implement two-way identity authentication to ensure the authenticity and legitimacy of the identities of both communicating parties. The underlying communication adopts the TLS3 encryption protocol, and ensures the security of the communication link through mechanisms such as session key negotiation and data encryption transmission. During the entire communication process, an end-to-end encrypted channel is established between the network security module (gateway) and the connected main server, realizing full encryption protection of data transmission.
[0065] The server is configured with a dual certificate system, including a public key certificate and a private key certificate. Public key certificates are used for data encryption and identity authentication, while private key certificates are used for digital signatures and decryption operations. During the communication process, a complete secure communication link is built through the collaborative work of multiple mechanisms such as cell encryption and decryption, certificate authentication, and TLS encryption. The system adopts a layered design concept, and the security mechanisms at each layer are independent of each other but closely coordinated. Cell encryption and decryption ensures the security of application layer data, P10 certificates implement transport layer identity authentication, and TLS3 protocol ensures the security of underlying communications, forming a systematic security protection system. The design of the entire communication model fully considers the requirements of security, reliability, and efficiency, and realizes reliable communication between the gateway and the security management platform through a multi-level security mechanism.
[0066] Figure 4 A schematic diagram of the process of offline certificate acquisition by a network security module disclosed in an embodiment of the present application. The process of offline certificate acquisition by the network security module is represented by a standard UML timing diagram, which fully describes the interaction sequence between the participating entities in the certificate acquisition process. Process participants include user terminals, network management servers and security management systems in the DMZ network area, operation and maintenance centers in the meteorological intranet area, authorization centers and other core nodes. The entire process unfolds in chronological order, and the message transmission process between entities is depicted through horizontal message lines and vertical lifelines. A security boundary is set between the DMZ network and the meteorological intranet, and different network security domains are clearly divided by dotted boxes, and message transmission strictly follows the access control requirements of the security domain. The system has designed an asynchronous processing mechanism, which effectively handles the timing problem of cross-domain certificate acquisition through the offline asynchronous operation link marked by the dotted box in the lower right corner.
[0067] During the execution of the process, each system component participates in different stages of certificate acquisition in turn. The user initiates an initialization request through the client, which is received and preprocessed by the network management server. After the request is verified for legitimacy by the security management system, it is forwarded to the operation and maintenance center of the meteorological intranet. After the operation and maintenance center completes the review of the certificate application, the authorization center issues the certificate. The message transmission in the whole process adopts strict timing control to ensure the orderliness and reliability of the certificate acquisition process. The system implements a safe and reliable certificate acquisition process through partition deployment, asynchronous processing, strict access control and other mechanisms.
[0068] Figure 5A timing flow chart of online authentication of a network security module device disclosed in an embodiment of the present application. The timing flow of online authentication of a network security module device deploys a complete DMZ network architecture from left to right, including six core components: user terminal, network security module, manager SDK, security management system, management service platform and LAN manager. The user terminal first initiates an authentication application to the network security module, which preliminarily encapsulates and routes the request and passes the authentication request to the manager SDK. After receiving the authentication request, the manager SDK launches a series of certificate authentication communication processes with the security management system, which covers multiple sub-processes such as submission of certificate files, format verification, validity period verification and signature confirmation. After the certificate authentication link is completed, a dedicated data channel is established between the security management system and the management service platform for transmitting and verifying various types of information required for device authentication. These authentication information interacts multiple rounds between the management service platform and the LAN manager to ensure the accurate transmission and timely update of the device authentication status. Finally, the LAN manager sends an authentication confirmation message, marking the end of the entire authentication process.
[0069] The message flow in the sequence diagram uses solid arrows to represent the synchronous message delivery mechanism, and dashed arrows to represent the asynchronous response mechanism. These arrows connect the communication paths between different components, forming a complete authentication closed loop. Each message flow is marked with the specific operation type and data content, such as certificate submission, verification request, status update, etc. Throughout the authentication process, the various components are synchronized through strict timing relationships, ensuring the continuity and integrity of the authentication information during the transmission process. At the same time, the design of the asynchronous response mechanism also discloses the necessary flexibility for the system, enabling it to better handle concurrent requests and abnormal situations. The design of the entire authentication process fully considers the various needs in actual application scenarios, which not only ensures the reliability of the authentication process, but also discloses sufficient system fault tolerance.
[0070] Figure 6 An initialization key flow chart disclosed in an embodiment of the present application. The figure shows the key exchange process between the terminal device and the various components in the DMZ network. The terminal first initiates a key initialization request through the network security module. After the network security module pre-processes the request, it forwards the initialization instruction to the manager SDK. After receiving the initialization request, the manager SDK immediately generates a pair of temporary encryption keys and performs a preliminary key exchange with the security management system. At this stage, the system adopts a multi-round key negotiation mechanism, including key steps such as the generation, distribution and verification of the initial key. These key operations are protected by strict encryption algorithms and security protocols to ensure the security of the key exchange process. Subsequently, the security management system generates formal encryption keys based on the temporary keys, and distributes these keys to various relevant components in the system through a pre-established secure channel.
[0071] The second half of the sequence diagram depicts the detailed key processing flow, including RSA asymmetric encryption and symmetric key processing. Each message interaction in the diagram is labeled with a specific key operation type, such as key generation, encrypted transmission, decryption verification, etc. The system ensures the security of key exchange through multiple encryption and verification mechanisms, while implementing a regular key update and confirmation mechanism. The entire key initialization process adopts a hierarchical design, dividing different types of key operations into independent processing stages, which not only ensures the independence of each stage, but also maintains the continuity of the entire process. Each processing stage includes the necessary security verification steps to ensure the reliability and security of the key exchange process.
[0072] Figure 7 An overall communication flow chart disclosed in an embodiment of the present application. It includes the interaction process between the user terminal and the core components in the DMZ network. The communication starts with the terminal initiating a request through the network security module, and the manager SDK coordinates the data exchange between the components, including request forwarding and response return. A special channel is established between the security management system and the LAN manager to handle security operations. The management service platform is responsible for overall service coordination and status management, and collaborates with the training software to complete business functions. The system adopts a layered design architecture, and the communication between components follows strict security protocols and data protection mechanisms. The arrows in the timing diagram represent the data flow path, which includes two basic mechanisms: synchronous message transmission and asynchronous response.
[0073] The technical implementation details of system communication include the definition of data transmission format and the design of processing flow. Each request contains a standardized message header and message body structure. The message header carries basic information such as request type, source address, and destination address, while the message body contains specific business data. During the data transmission process, the system assigns a unique identifier to each request, which enables request tracking and status management. For requests that require a long time to process, the system uses an asynchronous processing mechanism to notify the result of request processing through callback functions.
[0074] The overall architecture of the communication system adopts a modular design concept, which decomposes complex business processes into multiple independent functional units. Each functional unit has a clearly defined interface specification, and the units communicate with each other through standardized message formats. The system implements a reliable transmission mechanism at the data transmission level, including functions such as fragmentation, reassembly, and timeout retransmission of data packets. In terms of security, a complete security protection system is built through multiple protection measures such as identity authentication, access control, and data encryption. The system's session management mechanism supports concurrent access by multiple users, and ensures the continuity of user operations through the maintenance of session status.
[0075] Furthermore, an embodiment of the present application also discloses a meteorological data transmission device based on an edge protection gateway algorithm, comprising: a processor, a memory, and a system bus; the processor and the memory are connected via the system bus; the memory is used to store one or more programs, and the one or more programs include instructions, which, when executed by the processor, enable the processor to execute any of the above methods.
[0076] Furthermore, an embodiment of the present application also discloses a computer program product, which, when executed on a terminal device, enables the terminal device to execute any one of the above-mentioned processing methods.
[0077] It can be known from the description of the above implementation mode that those skilled in the art can clearly understand that all or part of the steps in the above-mentioned embodiment method can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product can be stored in a storage medium such as ROM / RAM, a disk, an optical disk, etc., including several instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a media gateway, etc.) to execute the methods described in the various embodiments of the present application or certain parts of the embodiments.
[0078] It should be noted that the various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0079] It should also be noted that, in the embodiments of the present application, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or equipment. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or equipment including the elements.
[0080] The above description of the disclosed embodiments enables professionals and technicians in the field to implement or use the present application. Various modifications to these embodiments will be apparent to professionals and technicians in the field, and the general principles defined in the embodiments of the present application can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown in the embodiments of the present application, but will conform to the widest range consistent with the principles and novel features disclosed in the embodiments of the present application.
Claims
1. A meteorological data transmission method based on edge protection gateway algorithm, characterized in that: include: Establish a communication connection with the meteorological observation equipment through the serial port service controller, obtain data by polling, standardize the data, and then store and back up the data through sharding; A random seed is generated by a hardware random number generator, a round key is generated by a key expansion function, encryption is performed on the grouped data, and a message authentication code is calculated; Send the cipher suite list to establish a handshake connection, exchange keys through elliptic curve operations, split the compressed data into records and add authentication tags for transmission; Digital certificates are used for identity authentication, permission relationship tables are established, and data security is protected through firewall status tables and feature matching algorithms.
2. The method according to claim 1, characterized in that: in, The serial port service controller is used to establish a communication connection with the meteorological observation equipment, and the data is obtained by polling. After the data is standardized, it is stored and backed up through sharding, including: Establish serial port communication connection with meteorological observation equipment through multi-threading mode and configure communication parameters of serial port service controller; A data request command is sent to the meteorological observation device in a polling manner, wherein the command frame includes a start identifier, a device address, a command type, a data length, a data content and a check bit; Create an independent collection thread to obtain data and encapsulate the data into a message object containing timestamp, device identification, data type, and payload data: A ring buffer is used to implement message queue storage, and the production rate is controlled through a back pressure mechanism. Consumer threads obtain messages in batches through a lock-free queue algorithm. Standardize the collected data, including unit conversion, outlier processing and quality control; The consistent hashing algorithm is used for data sharding storage, load balancing is achieved through virtual node mapping, and the two-phase commit protocol is used for data backup.
3. The method according to claim 1, characterized in that in, Use a hardware random number generator to generate a random seed, generate a round key through a key expansion function, perform encryption operations on the grouped data and calculate a message authentication code, including: Generate an initial entropy pool and a random seed using a hardware random number generator; Generate round keys using a key expansion function, where the expansion function uses system parameters to perform nonlinear transformations; The meteorological observation data are grouped according to the group length, and the data that is less than the group length is filled; Through nonlinear transformation and linear transformation, multiple rounds of encryption operations are performed to achieve data obfuscation and diffusion; The counter working mode is used to generate the key stream, and the key stream is XORed with the plaintext data; The authentication code is calculated using a message authentication algorithm, and message authentication is performed using a block processing method.
4. The method according to claim 1, characterized in that in, Send the cipher suite list to establish a handshake connection, exchange keys through elliptic curve operations, split the compressed data into records and add authentication tags for transmission, including: Send the supported cipher suite list and client random number to establish a handshake connection; Generate a temporary private key, calculate the public key through elliptic curve point multiplication, and the two parties exchange public keys; The master key is derived through the key expansion algorithm and combined with the random number to generate the session key; Compress the data and use double hash linked lists to speed up string matching; Split the data into records, each record contains header information and authentication tags; The correctness of message exchange is ensured by the state machine, and message transmission is achieved by using priority queues.
5. The method according to claim 1, characterized in that in, Use digital certificates for identity authentication, establish permission relationship tables, and use firewall status tables and feature matching algorithms to provide data security protection, including: Use digital certificates for identity authentication and generate signatures through deterministic random number schemes; Create a user role relationship table and a role permission relationship table, and use prefix tree index to speed up query; Manage permission changes through a multi-version concurrent control mechanism and synchronize data using incremental replication; Maintain the firewall status table, use an improved hash algorithm to reduce conflicts, and use a layered time wheel algorithm to age table entries; Use the token bucket algorithm to limit the number of connections and dynamically adjust the state table capacity; Use the improved automaton algorithm for feature matching and take corresponding protective measures according to the risk level of the rules.
6. The method according to claim 3, characterized in that in, Through nonlinear transformation and linear transformation, multiple rounds of encryption operations are performed to achieve data obfuscation and diffusion, including: Perform nonlinear transformation on input data according to preset table lookup rules, mapping the input data into transformed output data; Performing a first cyclic shift transformation on the output data in sequence to obtain first transformed data; Performing a second cyclic shift transformation on the output data in sequence to obtain second transformed data; Performing a third cyclic shift transformation on the output data in sequence to obtain third transformed data; Performing a fourth cyclic shift transformation on the output data in sequence to obtain fourth transformed data; The original output data is XORed with the four transformed data to obtain the final transformed result.
7. The method according to claim 3, characterized in that in, The counter working mode is used to generate the key stream, and the key stream is XORed with the plaintext data, including: Collect device timestamp information and device identification information, and obtain the initial value of the counter through hash function processing; Incrementing the initial value of the counter based on a preset prime number to generate a counter sequence value; The counter sequence value is concatenated with the system random number to form combined data; Perform encryption operation on the combined data to generate corresponding key stream data; An XOR operation is performed on the key stream data and the plaintext data to be encrypted to obtain ciphertext data.
8. The method according to claim 5, characterized in that in, The token bucket algorithm is used to limit the number of connections and dynamically adjust the state table capacity, including: Set the capacity parameters of the token bucket and the token filling rate parameters; Add tokens to the token bucket regularly according to the preset filling rate; Detect the current memory usage status of the system and calculate the available memory capacity; Dynamically adjust the maximum capacity of the state table according to the available memory capacity; A token is obtained for the newly established connection request, and the connection is allowed to be established when a token is obtained; When there are no available tokens in the token bucket, new connection requests are rejected.
Citation Information
Cited By
Deterministic random bit generation device and deterministic random bit generation method
CN120915431A
Power secondary equipment fingerprint construction method and system, electronic device and storage medium
CN121278704A
Power secondary equipment fingerprint construction method and system, electronic device, and storage medium
CN121278704B
Data transmission method and system for meteorological satellite communication system
CN121690338A