Terminal intelligent control system based on commercial secret algorithm

By integrating the trade secret algorithm and dynamic key mechanism in the terminal intelligent control system, the problems of key leakage and complex abnormal detection in high-security demand scenarios are solved, and high-security data transmission and stable equipment management are achieved.

CN120017365APending Publication Date: 2025-05-16CHENGUANG ANYI (BEIJING) TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510166168.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing terminal intelligent control systems have the risk of key leakage in high security needs scenarios, the difficulty in identifying complex abnormal behaviors with single rule matching, and the lack of protection against replay attacks.

Method used

The terminal intelligent control system based on the trade secret algorithm is adopted, and SM2, SM3 and SM4 algorithms are integrated to realize user identity authentication, data encryption transmission and integrity verification, and through dynamic key generation, timestamp and random number mechanisms, the system's security and attack resistance are enhanced.

Benefits of technology

Effectively ensure the confidentiality, integrity and attack resistance of data, adapt to application scenarios with high security needs, improve the stability and management efficiency of equipment operation, and reduce potential risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017365A_ABST
    Figure CN120017365A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and discloses an intelligent terminal control system based on a commercial secret algorithm, and the system comprises an intelligent terminal control module which is used for collecting identity information, operation data and equipment state data inputted by a user; the commercial secret algorithm security engine module is used for executing an SM2 public key cryptographic algorithm, an SM3 hash algorithm and an SM4 symmetric cryptographic algorithm, and carrying out security protection on identity authentication, data integrity verification and data encryption processing; the distributed secure communication module is used for transmitting encrypted data between the terminal and the control center through a secure communication channel to prevent data leakage and tampering; and a remote monitoring and management module. According to the invention, through a commercial secret algorithm, dynamic secret key updating, a timestamp and random number mechanism and intelligent anomaly detection, comprehensive improvement of data security, communication reliability and anomaly response capability of a terminal intelligent control system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a terminal intelligent control system based on a commercial secret algorithm. Background Art

[0002] With the rapid development of Internet of Things technology, terminal intelligent control systems have been widely used in express cabinets, document cabinets, smart homes and other fields. These systems realize the interaction of user operations and real-time management of equipment operation status through terminal devices, and play an important role in life services, file delivery and equipment security. The popularization of terminal intelligent control systems has greatly improved people's operation convenience and equipment management efficiency, and also laid the foundation for intelligent and networked equipment control.

[0003] At present, with the continuous advancement of domestic encryption technology, more and more terminal intelligent control systems have begun to adopt independently developed commercial encryption algorithms (such as SM2, SM3, SM4, etc.) for user identity authentication and data encryption processing. These domestic algorithms have the characteristics of high security, low latency and compliance with national regulations, ensuring information security and compliance. At the same time, through the centralized monitoring system to monitor and record the status of the equipment in real time, these systems can effectively realize user identity verification, equipment status management, and basic data security protection. The existing system performs well in terms of operational convenience and equipment response speed, and is widely used in medium and low-intensity security scenarios, such as ordinary file access or daily item storage services. Its advantages include high data processing efficiency, low system cost, and low implementation difficulty. It has become a basic solution for intelligent management.

[0004] However, the existing terminal intelligent control systems still have some shortcomings in high-security scenarios. First, traditional encryption technology lacks a dynamic key update mechanism, and is prone to the risk of key leakage or reuse during data transmission. Second, the anomaly detection of equipment operation status relies on rule matching, which cannot adapt to complex abnormal behaviors or potential security risks, and is difficult to meet the needs of intelligent analysis. Finally, the existing data transmission mechanism lacks protection against replay attacks and cannot effectively prevent attackers from performing malicious operations through historical data packets. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present invention provides a terminal intelligent control system based on a commercial secret algorithm, which solves the risk of key leakage caused by the lack of a dynamic key update mechanism in the existing terminal intelligent control system and the problem that anomaly detection relying on single rule matching is difficult to identify complex behaviors.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a terminal intelligent control system based on a commercial secret algorithm, the system comprising: Terminal intelligent control module, used to collect identity information, operation data and device status data input by users; The commercial key algorithm security engine module is used to execute the SM2 public key cryptographic algorithm, SM3 hash algorithm and SM4 symmetric cryptographic algorithm to provide security protection for identity authentication, data integrity verification and data encryption processing; Distributed secure communication module, used to transmit encrypted data between the terminal and the control center through a secure communication channel to prevent data leakage and tampering; Remote monitoring and management module, used to monitor device status, manage operation logs, and detect abnormal behavior.

[0007] Preferably, the terminal intelligent control module includes: User identity authentication unit, used to receive identity information input by the user and call the SM2 public key cryptographic algorithm for digital signature and identity authentication; A data collection unit, used to collect user operation data and device status data; The data encryption unit is used to encrypt the data using the SM4 symmetric encryption algorithm.

[0008] Preferably, the process of generating a digital signature by the user identity authentication unit includes: Through the user's private key S User Digitally sign the identity data M and obtain the signature S: S=SM2 Sign (S User ,M) Where S: digital signature, which is the result calculated by SM2 algorithm and is used to verify the legitimacy of the user's identity; S User : The user's private key is the private key required by the user to generate a signature, ensuring the uniqueness and security of the signature; M: The identity data entered by the user, as the plaintext data to be signed; SM2 Sign :The signature function based on the SM2 public key cryptography algorithm uses the elliptic curve encryption algorithm to sign the plaintext data.

[0009] Preferably, the data encryption unit encrypts the collected data M by using an SM4 symmetric encryption algorithm, and the encryption step includes: Use the dynamically generated symmetric key K to encrypt the data M and obtain the ciphertext C: C=SM4 Encrypt (K,M) Among them, C: encrypted data ciphertext, which is the result of encrypting plaintext data through SM4 algorithm; K: symmetric encryption key, generated by the key management unit and distributed through the key exchange mechanism, which is used to encrypt and decrypt data and is dynamically updated for each session; M: plaintext data to be encrypted, including user operation data or device status data; SM4 Encrypt : Symmetric encryption function based on SM4 algorithm. SM4 is a symmetric encryption algorithm with a key length of 128 bits and is widely used in data transmission and storage encryption.

[0010] Preferably, the commercial secret algorithm security engine module includes: The key management unit is used to call the SM2 public key cryptographic algorithm to implement key exchange and ensure communication security; The data integrity check unit is used to perform integrity check on the data using the SM3 hash algorithm to ensure that the data has not been tampered with.

[0011] Preferably, the key exchange step of the key management unit includes: The terminal generates a random session key K and uses the control center's public key P Control Encrypt and get the key ciphertext C K : C K =SM2 Encrypt (P Control ,K) The control center uses the private key S Control For ciphertext C K Decrypt and recover the session key K: K=SM2 Decrypt (S Control ,C K ) Among them, C K : Key ciphertext, which is the result of encrypting the session key K through the SM2 algorithm, used for secure transmission; K: Session key, which is the data encryption key used for SM4 symmetric encryption, is randomly generated by the terminal and dynamically updated for each session; P Control : The public key of the control center is used to encrypt the session key K: The public key is distributed to the terminal when the system is deployed; S Control : The private key of the control center, used to decrypt the session key K; SM2 Encrypt : An encryption function based on the SM2 public key cryptographic algorithm, used to protect the security of key transmission; SM2 Decrypt : Decryption function based on SM2 public key cryptography algorithm, used to recover the key for encrypted transmission.

[0012] Preferably, the data integrity check unit calculates the data integrity check value H by using an SM3 hash algorithm, and the calculation step includes: Input data C and calculate the hash value H: H=SM3(C) Among them, H: data integrity check value (hash value), which is a fixed-length value calculated by the SM3 algorithm and is used to verify whether the data has been tampered with during transmission or storage; C: encrypted data ciphertext, including data encrypted by the SM4 algorithm; SM3: a cryptographic hash algorithm that can generate a 256-bit fixed-length hash value, which is used to detect whether the data has been changed or tampered with.

[0013] Preferably, the distributed secure communication module includes: The data transmission unit is used to add a timestamp T and a random number R to the data packet to prevent data replay attacks; the data verification unit is used to verify the validity of the timestamp T and the random number R.

[0014] Preferably, when the data transmission unit generates a transmission data packet, the steps include: Combine the encrypted data C, integrity check value H, timestamp T and random number R into a transmission data packet [C, H, T, R]; Where C is the data encrypted by SM4, and H is the SM3 check value.

[0015] Preferably, the remote monitoring and management module includes: The device status monitoring unit is used to collect and transmit the device's operating status data; the anomaly detection unit is used to analyze the device status data, detect abnormal behavior and generate anomaly reports.

[0016] The present invention provides a terminal intelligent control system based on a commercial secret algorithm, which has the following beneficial effects: 1. The present invention realizes the whole process security protection from user identity authentication, data encryption transmission to integrity verification by integrating commercial secret algorithms (SM2, SM3 and SM4). It combines dynamic key generation, timestamp and random number mechanism to effectively ensure the confidentiality, integrity and anti-attack capability of data, and adapts to application scenarios with high security requirements.

[0017] 2. The present invention realizes dynamic control of equipment operation status and accurate identification of abnormal behavior through real-time data collection of the equipment status monitoring unit and multi-dimensional intelligent analysis of the abnormality detection unit. Combined with the alarm mechanism, it improves the stability of equipment operation and management efficiency and reduces potential risks.

[0018] 3. The present invention constructs a safe and efficient distributed communication mechanism through data packet encryption, integrity check and time window verification. The data transmission module has strong anti-replay attack capability and data credibility verification capability while achieving high-speed transmission, thus providing guarantee for multi-terminal secure communication. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 is a system structure diagram of the present invention; Figure 2 This is a system structure diagram of the terminal intelligent control module of the present invention; Figure 3 It is a schematic diagram of the system structure of the Sunmi algorithm security engine module of the present invention. DETAILED DESCRIPTION

[0020] The following will be combined with the drawings in the specification of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] Please see attached Figure 1 -Attached Figure 3 The embodiment of the present invention provides a terminal intelligent control system based on a commercial secret algorithm, the system comprising: The terminal intelligent control module is used to collect the identity information, operation data and device status data input by the user. Through the terminal intelligent control module, the efficient collection and real-time processing of user operation and device status data can be realized, ensuring the integrity and accuracy of system data, and providing a reliable data basis for subsequent data encryption and authentication; The commercial secret algorithm security engine module is used to execute the SM2 public key cryptographic algorithm, SM3 hash algorithm and SM4 symmetric cryptographic algorithm to provide security protection for identity authentication, data integrity verification and data encryption processing. The commercial secret algorithm security engine module effectively ensures the legitimacy verification of user identity, data integrity verification and data confidentiality; Distributed secure communication module, used to transmit encrypted data between the terminal and the control center through a secure communication channel to prevent data leakage and tampering. Through the distributed secure communication module, the present invention realizes high-intensity data encryption transmission and has anti-replay attack capability, effectively preventing data leakage, tampering and man-in-the-middle attack problems; The remote monitoring and management module is used to monitor device status, manage operation logs, and detect abnormal behavior. The remote monitoring and management module realizes efficient management and abnormality detection functions of the equipment, can discover and warn potential security threats in real time, and provides comprehensive protection for system security.

[0022] Please see attached Figure 1 and attached Figure 2In a preferred embodiment of the present invention, the terminal intelligent control module includes: a user identity authentication unit, which is used to receive identity information input by the user and call the SM2 public key cryptographic algorithm for digital signature and identity authentication. The user enters identity information through the terminal, including a password or biometrics, and the biometric information is collected by the terminal hardware module and converted into a digital format; the terminal calls the SM2 public key cryptographic algorithm and uses the user's private key S User Digitally sign the identity information M to generate a signature S. The calculation formula is: S=SM2 Sign (S User ,M) Where: S User : User private key, used to generate a unique signature; M: identity information or feature data entered by the user; S: generated digital signature, used for identity authentication, signature S and plaintext data M are transmitted to the control center together, and the control center uses the SM2 algorithm and the user's public key P User Verify the legitimacy of the signature to ensure that the user's identity is authentic and has not been forged. Through the user identity authentication unit, efficient verification of the user's identity can be achieved to ensure that the system only allows authenticated users to access and prevent unauthorized operations. In addition, the SM2 algorithm is used to generate a digital signature during the identity authentication process, which has a higher anti-forgery capability and can effectively defend against man-in-the-middle attacks and identity fraud problems; The data acquisition unit is used to collect user operation data and equipment status data. Through the data acquisition unit, user operation behavior and equipment operation status can be obtained comprehensively and in real time, providing accurate and reliable data support for system operation. The introduction of this unit improves the automation and real-time performance of the system, laying a solid foundation for security protection and anomaly detection; A data encryption unit, used to encrypt data using an SM4 symmetric encryption algorithm; Specifically: the data encryption unit generates a dynamic session key K through the commercial secret algorithm security engine module. Key generation and distribution rely on the SM2 key exchange mechanism to ensure key security. The generated key K is used to encrypt the collected data M through the SM4 symmetric encryption algorithm to generate the ciphertext C. The calculation formula is: C=SM4 Encrypt (K,M) Where: M: user operation data or device status data; K: session key, dynamically generated by the key exchange mechanism; C: ciphertext data, used to protect data confidentiality. The encrypted ciphertext C is transmitted to the distributed secure communication module for transmission or stored locally on the terminal to ensure that the data will not be illegally accessed or stolen; The data encryption unit uses the SM4 algorithm to strongly encrypt data, improving the security of data during transmission and storage. The encryption process is efficient and the key security is strong, meeting the data protection requirements in scenarios with high security requirements.

[0023] Please see attached Figure 1 and attached Figure 2 In a preferred embodiment of the present invention, the process of generating a digital signature by the user identity authentication unit includes: Through the user's private key S User Digitally sign the identity data M and obtain the signature S: S=SM2 Sign (S User ,M) Where S: digital signature, which is the result calculated by SM2 algorithm and is used to verify the legitimacy of the user's identity; S User : The user's private key is the private key required by the user to generate a signature, ensuring the uniqueness and security of the signature; M: The identity data entered by the user, as the plaintext data to be signed; SM2 Sign :Based on the signature function of the SM2 public key cryptographic algorithm, the plaintext data is signed using the elliptic curve encryption algorithm; The digital signature generation process can effectively prevent identity forgery and ensure the security of user identity authentication. Through the signing process of the user's private key, the user's identity data can be effectively bound, so that the signature is associated with the user's unique private key and cannot be forged by others. At the same time, combined with the efficiency and security of the elliptic curve encryption algorithm, the digital signature generation process can adapt to high-real-time and data-sensitive application scenarios. The digital signature generation and transmission process has strong anti-attack capabilities, which can ensure the security of user identity authentication and is highly efficient to meet real-time authentication needs.

[0024] Please see attached Figure 1 and attached Figure 2 In a preferred embodiment of the present invention, the data encryption unit encrypts the collected data M by using the SM4 symmetric encryption algorithm, and the encryption step includes: Use the dynamically generated symmetric key K to encrypt the data M and obtain the ciphertext C: C=SM4 Encrypt (K,M) Among them, C: encrypted data ciphertext, which is the result of encrypting plaintext data through SM4 algorithm; K: symmetric encryption key, generated by the key management unit and distributed through the key exchange mechanism, which is used to encrypt and decrypt data and is dynamically updated for each session; M: plaintext data to be encrypted, including user operation data or device status data; SM4 Encrypt: Symmetric encryption function based on SM4 algorithm. SM4 is a symmetric encryption algorithm with a key length of 128 bits, which is widely used in data transmission and storage encryption; The data encryption unit provides powerful data protection capabilities. Combined with the dynamic key management mechanism, it can effectively prevent data from being stolen or tampered with during transmission or storage, thereby improving the overall security of the system and greatly enhancing the system's anti-attack capabilities. The data encryption unit provides the system with core data protection capabilities through a dynamic key mechanism and an efficient encryption algorithm. The irreversibility of encrypted data and the dynamic key update characteristics further enhance the system's anti-attack capabilities and data integrity protection level.

[0025] Please see attached Figure 1 and attached Figure 3 In a preferred embodiment of the present invention, the commercial secret algorithm security engine module includes: a key management unit, which is used to call the SM2 public key cryptographic algorithm to implement key exchange and ensure communication security. The key management unit uses a dynamic key generation and encryption distribution mechanism to ensure that the key for each communication is different, thereby effectively avoiding security risks caused by key duplication. Combined with the high security of the SM2 algorithm, the key transmission process can effectively prevent key leakage and improve the system's anti-attack capability; The data integrity check unit is used to check the integrity of the data through the SM3 hash algorithm to ensure that the data has not been tampered with. The data check value calculated by the SM3 algorithm can detect the tampering behavior of the data during transmission or storage with high efficiency. The fixed length of the hash value ensures the calculation efficiency and can protect the integrity of data of any size.

[0026] Please see attached Figure 1 and attached Figure 3 In a preferred embodiment of the present invention, the key exchange step of the key management unit includes: The terminal generates a random session key K and uses the control center's public key P Control Encrypt and get the key ciphertext C K : C K =SM2 Encrypt (P Control ,K) The control center uses the private key S Control For ciphertext C K Decrypt and recover the session key K: K=SM2 Decrypt (S Control ,C K ) Among them, C K: Key ciphertext, which is the result of encrypting the session key K through the SM2 algorithm, used for secure transmission; K: Session key, which is the data encryption key used for SM4 symmetric encryption, is randomly generated by the terminal and dynamically updated for each session; P Control : The public key of the control center is used to encrypt the session key K: The public key is distributed to the terminal when the system is deployed; S Control : The private key of the control center, used to decrypt the session key K; SM2 Encrypt : An encryption function based on the SM2 public key cryptographic algorithm, used to protect the security of key transmission; SM2 Decrypt : Decryption function based on SM2 public key cryptography algorithm, used to recover the key for encrypted transmission; Specifically: through the key exchange step, the dynamic update and secure distribution of session keys can be achieved to avoid key leakage. This mechanism combines the strong security of the public key cryptographic algorithm to effectively enhance the system's ability to resist man-in-the-middle attacks and eavesdropping. The key exchange mechanism uses the SM2 algorithm to encrypt and decrypt the key, ensuring the high security of the session key during transmission. Even if the key ciphertext C K If the session key K is stolen, the attacker cannot obtain it through brute force or calculation.

[0027] Please see attached Figure 1 and attached Figure 3 In a preferred embodiment of the present invention, the data integrity check unit calculates the data integrity check value H by using the SM3 hash algorithm, and the calculation steps include: Input data C and calculate the hash value H: H=SM3(C) Wherein, H: data integrity check value (hash value), which is a fixed-length value calculated by the SM3 algorithm and is used to verify whether the data has been tampered with during transmission or storage; C: encrypted data ciphertext, including data encrypted by the SM4 algorithm; SM3: a cryptographic hash algorithm that can generate a 256-bit fixed-length hash value, which is used to detect whether the data has been changed or tampered with; Specifically: By using a fixed-length hash value, the data integrity check process is both efficient and secure. The irreversibility of the hash value ensures that attackers cannot restore the original data through reverse calculation, and can quickly detect integrity issues during data transmission or storage; through the check value generation and verification process, the data integrity check unit can effectively ensure the consistency of data during transmission and storage, and improve the reliability and security of the system.

[0028] Please see attached Figure 1 In a preferred embodiment of the present invention, the distributed security communication module includes: The data transmission unit is used to attach a timestamp T and a random number R to the data packet to prevent data replay attacks; the data verification unit is used to verify the validity of the timestamp T and the random number R. Through the timestamp and random number mechanism, the distributed security communication module can effectively prevent the data packet from being reused, and effectively improve the anti-attack capability during data transmission. The data transmission unit and the data verification unit effectively prevent data packet replay attacks and illegal operations through the coordinated use of timestamps and random numbers, ensuring the timeliness and authenticity of data packet transmission. Through the dual protection of timestamps and random numbers, the distributed security communication module can not only prevent data packet replay attacks, but also improve the real-time, effectiveness and security of transmitted data.

[0029] Please see attached Figure 1 In a preferred embodiment of the present invention, when the data transmission unit generates a transmission data packet, the steps include: The encrypted data C, integrity check value H, timestamp T and random number R are combined into a transmission data packet [C, H, T, R]; where C is the data encrypted by SM4, and H is the SM3 check value. By integrating the encrypted data and the integrity check value into the same data packet, the confidentiality and integrity of the data can be effectively improved to ensure that the transmitted data cannot be cracked or tampered with. Through the standardized data packet generation process, the data transmission unit can ensure the security and reliability of each data packet, while simplifying the data parsing and processing operations at the receiving end. Through the technical advantages of the data transmission unit, the system can achieve all-round protection of the transmitted data and ensure the security and reliability of the data in a complex network environment.

[0030] Please see attached Figure 1 In a preferred embodiment of the present invention, the remote monitoring and management module includes: The equipment status monitoring unit is used to collect and transmit the equipment's operating status data. The equipment status monitoring unit can realize all-round monitoring of the equipment's operating status. Through real-time collection and transmission, it ensures transparent management and information synchronization of the equipment in a complex operating environment; The anomaly detection unit is used to analyze equipment status data, detect abnormal behavior and generate anomaly reports. Through multi-level analysis technology, the anomaly detection unit can accurately detect potential risks in equipment operation and notify management personnel in a timely manner, reducing system security risks caused by equipment failure or abnormal operation; Specifically: Through real-time collection of device status data and multi-dimensional anomaly analysis technology, the remote monitoring and management module can accurately detect and efficiently handle device anomalies, reduce potential safety hazards, improve the system's operating stability and management efficiency, and at the same time improve the system's monitoring and exception handling efficiency, providing a solid guarantee for the safe operation of smart devices.

[0031] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A terminal intelligent control system based on a commercial secret algorithm, characterized in that: The system comprises: Terminal intelligent control module, used to collect identity information, operation data and device status data input by users; The commercial key algorithm security engine module is used to execute the SM2 public key cryptographic algorithm, SM3 hash algorithm and SM4 symmetric cryptographic algorithm to provide security protection for identity authentication, data integrity verification and data encryption processing; Distributed secure communication module, used to transmit encrypted data between the terminal and the control center through a secure communication channel to prevent data leakage and tampering; Remote monitoring and management module, used to monitor device status, manage operation logs, and detect abnormal behavior.

2. The terminal intelligent control system based on the commercial secret algorithm according to claim 1 is characterized in that: The terminal intelligent control module includes: User identity authentication unit, used to receive identity information input by the user and call the SM2 public key cryptographic algorithm for digital signature and identity authentication; A data collection unit, used to collect user operation data and device status data; The data encryption unit is used to encrypt the data using the SM4 symmetric encryption algorithm.

3. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The process of generating a digital signature by the user identity authentication unit includes: Through the user's private key S User Digitally sign the identity data M and obtain the signature S: S=SM2 Sign (S User ,M) Where S: digital signature, which is the result calculated by SM2 algorithm and is used to verify the legitimacy of the user's identity; S User : The user's private key is the private key required by the user to generate a signature, ensuring the uniqueness and security of the signature; M: The identity data entered by the user, as the plaintext data to be signed; SM2 Sign :The signature function based on the SM2 public key cryptography algorithm uses the elliptic curve encryption algorithm to sign the plaintext data.

4. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The data encryption unit encrypts the collected data M by using the SM4 symmetric encryption algorithm, and the encryption step includes: Use the dynamically generated symmetric key K to encrypt the data M and obtain the ciphertext C: C=SM4 Encrypt (K,M) Among them, C: encrypted data ciphertext, which is the result of encrypting plaintext data through SM4 algorithm; K: symmetric encryption key, generated by the key management unit and distributed through the key exchange mechanism, which is used to encrypt and decrypt data and is dynamically updated for each session; M: plaintext data to be encrypted, including user operation data or device status data; SM4 Encrypt : Symmetric encryption function based on SM4 algorithm. SM4 is a symmetric encryption algorithm with a key length of 128 bits and is widely used in data transmission and storage encryption.

5. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The commercial secret algorithm security engine module includes: The key management unit is used to call the SM2 public key cryptographic algorithm to implement key exchange and ensure communication security; The data integrity check unit is used to perform integrity check on the data using the SM3 hash algorithm to ensure that the data has not been tampered with.

6. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The key exchange steps of the key management unit include: The terminal generates a random session key K and uses the control center's public key P Control Encrypt and get the key ciphertext C K : C K =SM2 Encrypt (P Control ,K) The control center uses the private key S Control For ciphertext C K Decrypt and recover the session key K: K=SM2 Decrypt (S Control ,C K ) Among them, C K : Key ciphertext, which is the result of encrypting the session key K through the SM2 algorithm, used for secure transmission; K: Session key, which is the data encryption key used for SM4 symmetric encryption, is randomly generated by the terminal and dynamically updated for each session; P Control : The public key of the control center is used to encrypt the session key K: The public key is distributed to the terminal when the system is deployed; S Control : The private key of the control center, used to decrypt the session key K; SM2 Encrypt : An encryption function based on the SM2 public key cryptographic algorithm, used to protect the security of key transmission; SM2 Decrypt : Decryption function based on SM2 public key cryptography algorithm, used to recover the key for encrypted transmission.

7. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The data integrity check unit calculates the data integrity check value H by using the SM3 hash algorithm, and the calculation step includes: Input data C and calculate the hash value H: H=SM3(C) Among them, H: data integrity check value (hash value), which is a fixed-length value calculated by the SM3 algorithm and is used to verify whether the data has been tampered with during transmission or storage; C: encrypted data ciphertext, including data encrypted by the SM4 algorithm; SM3: a cryptographic hash algorithm that can generate a 256-bit fixed-length hash value, which is used to detect whether the data has been changed or tampered with.

8. The terminal intelligent control system based on commercial secret algorithm according to claim 1 is characterized in that: The distributed safety communication module comprises: The data transmission unit is used to add a timestamp T and a random number R to the data packet to prevent data replay attacks; the data verification unit is used to verify the validity of the timestamp T and the random number R.

9. The terminal intelligent control system based on commercial secret algorithm according to claim 1, characterized in that: When the data transmission unit generates a transmission data packet, the steps include: Combine the encrypted data C, integrity check value H, timestamp T and random number R into a transmission data packet [C, H, T, R]; Where C is the data encrypted by SM4, and H is the SM3 check value.

10. The terminal intelligent control system based on commercial secret algorithm according to claim 1, characterized in that: The remote monitoring and management module includes: The device status monitoring unit is used to collect and transmit the device's operating status data; the anomaly detection unit is used to analyze the device status data, detect abnormal behavior and generate anomaly reports.

Citation Information

Patent Citations

  • Kerberos identity authentication protocol improvement method based on national cryptographic algorithm

    CN113612797A

  • Data link trusted transmission method and system

    CN114826656A

  • Jumping key digital communication encryption system and method based on national secret algorithm

    CN114915396A

  • Security application method in Internet system based on national cryptographic algorithm

    CN117335989A