Data encryption method based on avionics system TSN bus transmission

By using PRNG-based data chunking and AES/RSA encryption algorithm methods in avionics systems, the problem of insufficient security of TSN network is solved, and high-security transmission and adaptive encryption of data are achieved.

CN120017421AActive Publication Date: 2025-05-16SHENYANG HANGSHENG TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510473967.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-05-16
Estimated Expiration
2045-04-16

AI Technical Summary

Technical Problem

The existing TSN network lacks effective security measures and poses high security risks, especially in avionics systems, where data leakage is relatively high.

Method used

A data encryption method based on the TSN bus transmission of avionics system is adopted, and the data is blocked by the pseudo-random number generator PRNG, and AES and RSA encryption algorithms are used for layered encryption, and data block rearrangement and decryption are used for data blocks.

Benefits of technology

It improves the security of TSN network communication data in avionics system, increases the randomness of data block length and cracking difficulty, ensures the secure transmission of data, and adapts to the encryption needs of different environments.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A data encryption method based on avionics system TSN bus transmission relates to the technical field of industrial communication, and comprises the following steps: step S01, extracting message key frame data, shunting with common frame data, and generating a random seed; s02, a pseudo random number generator PRNG generates two pseudo random numbers x and y, each packet of key frame data is divided into determined blocks according to the block length, each packet of common frame data is divided into determined blocks according to the block length, and different data heads are added to the data blocks; and S03, generating a permutation table by using a pseudo random number generator PRNG, defining the position of each data block in output by the table, rearranging the layered data blocks according to the permutation table, and generating a key, an initialization vector IV and the like which correspond to each other by using the pseudo random number generator PRNG. According to the invention, the security of the TSN network communication data in the avionics system is improved, and secret leakage is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial communication technology, and in particular to a data encryption method based on TSN bus transmission of an avionics system. Background Art

[0002] With the continuous improvement of the networking and intelligence level of avionics systems, the new generation of aircraft has put forward higher requirements for the real-time and reliability of airborne networks. The TSN bus system based on the time-sensitive network has gradually become an important interconnection solution for avionics systems with its high-precision clock synchronization mechanism, deterministic low-latency transmission characteristics and superior bandwidth expansion capabilities. The TSN bus can effectively meet the collaborative work requirements between key equipment such as flight control systems, mission computers, sensors, etc., while improving system interoperability and ensuring the timeliness of data transmission.

[0003] However, the TSN protocol mainly focuses on deterministic transmission guarantee, and its security protection mechanism has not yet been perfected. The existing TSN network lacks effective security measures, which poses a high risk to its security.

[0004] The existing TSN bus transmission data encryption method relies on the secure tunnel connection protection of the TSN encryption switch, such as Chinese patent CN115225333A, a software-defined TSN encryption method and system, which establishes a secure tunnel between the TSN controller and the TSN encryption switch. The two communicate through the southbound protocol and use fields as flow identifiers to encrypt information. For example, the node receives the terminal plaintext encrypted to the intermediate node, the intermediate node receives the ciphertext and forwards it to the egress node, and the egress node receives the encrypted data and decrypts it to obtain the plaintext. This process requires the response of the intermediate unit to provide encryption calculations, which increases the data transmission load and complexity. Due to the large amount of on-board communication data, the additional addition of intermediate data forwarding links may affect transmission performance. Summary of the invention

[0005] In view of the above-mentioned shortcomings and deficiencies of the prior art, the present invention provides a data encryption method based on TSN bus transmission of an avionics system, which improves the security of TSN network communication data in the avionics system and avoids leakage.

[0006] In order to achieve the above object, the main technical solutions adopted by the present invention include: A data encryption method based on TSN bus transmission of an avionics system includes the following steps: Step S01, extracting the message key frame data according to the data communication protocol of the avionics system, separating it from the common frame data, and using the onboard system time to generate a random seed for use by the pseudo-random number generator PRNG; Step S02, the pseudo-random number generator PRNG generates two pseudo-random numbers x and y, where x is defined as the number of blocks for each key frame data packet, and y is defined as the number of blocks for each ordinary frame data packet, and the packet header format fixed by the TSN protocol is removed from the data packet transmitted by the bus, and the key frame data packet length is obtained as lenx and the ordinary frame data packet length is obtained as leny, and each key frame data packet is divided into a certain data block according to the block length lenx / x, and each ordinary frame data packet is divided into a certain data block according to the block length leny / y, and a different data header is added to each data block; Step S03, using a pseudo-random number generator PRNG to generate a substitution table, the table defines the position of each data block in the output, and rearranges the hierarchical data blocks according to the substitution table, and uses the pseudo-random number generator PRNG to generate mutually corresponding keys and initialization vectors IV; the length and number of the data blocks from which the key frame data and the ordinary frame data are split are put into the substitution table as decryption attributes, and the substitution table is sent to the decryption end along with the encrypted data as a code book; Step S04, hierarchically encrypt the data blocks, encrypt the common frame data and the key frame data using the AES encryption algorithm, and perform secondary data encryption using the RSA encryption algorithm based on the extracted key frame data header; Step S05, storing the generated substitution table and encryption keys of different data blocks and initialization vector IV, and sending the encrypted data block and the recorded substitution table and key information to the receiving end; Step S06: The receiving end performs layered decryption on the received data, decrypts the key frame and common frame data blocks respectively, extracts the length and number of data blocks from which the key frame and common frame are split according to the received substitution table, and restores the data blocks to the original data.

[0007] Furthermore, in step S02, if the length of the data after block division is a non-integer multiple of the size of the generated block, the vacancies are padded, and the insufficient data blocks are filled, and the padded parts are all 0.

[0008] Furthermore, in step S02, each key frame data block contains lenx / x bytes, and each common frame data block contains leny / y bytes, wherein each byte corresponds one-to-one to the content definition of the airborne system.

[0009] Furthermore, each byte corresponds one-to-one to the content definition of the airborne system, including the start bit, end bit, message type, header configuration information of each message definition, and message body content information interpreted by the ICD.

[0010] Furthermore, in step S03, the substitution table is updated regularly.

[0011] Furthermore, in step S06, for the padded data, the padded empty bytes are removed to restore the original data.

[0012] The beneficial effects of the present invention are: 1) The present invention divides the data into blocks by generating random numbers, which increases the randomness of the length of each data block and also increases the difficulty of cracking. Different data blocks are processed in layers according to their importance, which increases the data processing efficiency; 2) The present invention adopts a pseudo-random number generator PRNG to improve the unpredictability of generated pseudo-random numbers, thereby increasing the randomness of the length of the layered data block and the complexity of the generated substitution table, thereby resisting various attacks and cracking methods; 3) The present invention performs hierarchical encryption on data blocks and secondary encryption on key frame data, thus ensuring data security. At the same time, different encryption rules can be changed according to environmental needs to adapt to different environmental requirements; 4) The present invention improves data security by using a substitution table and generated encryption key data for encryption and restoration; 5) The present invention encrypts data by generating pseudo-random numbers. There is no encryption database or sorting database. It is difficult to crack it by brute force means such as exhaustive method, and the encryption security is high. DETAILED DESCRIPTION

[0013] In order to better explain the present invention and facilitate understanding, the present invention is described in detail below through specific implementation methods.

[0014] The present invention provides a data encryption method based on TSN bus transmission of an avionics system, comprising the following steps: Step S01: extract message key frame data according to the data communication protocol of the avionics system, separate it from the common frame data, and use the onboard system time to generate a random seed for use by the pseudo-random number generator PRNG.

[0015] Step S02, the pseudo-random number generator PRNG generates two pseudo-random numbers x and y, where x is defined as the number of blocks for each key frame data packet, and y is defined as the number of blocks for each ordinary frame data packet. The packet header format fixed by the TSN protocol is removed from the data packet transmitted by the bus, and the key frame data packet length is obtained as lenx and the ordinary frame data packet length is obtained as leny. Each key frame data packet is divided into a certain data block according to the block length lenx / x, and each ordinary frame data packet is divided into a certain data block according to the block length leny / y, and a different data header is added to each data block.

[0016] Each key frame data block contains lenx / x bytes, and each normal frame data block contains leny / y bytes, where each byte corresponds to the content definition of the airborne system. Each byte corresponds to the content definition of the airborne system, including the start bit, end bit, message type, header configuration information of each message, and the message body content information that can be interpreted by ICD.

[0017] Specifically, if the length of the data after block division is a non-integer multiple of the generated block size, the empty spaces are padded and the insufficient data blocks are filled, and the padded parts are all 0.

[0018] Step S03, using a pseudo-random number generator PRNG to generate a permutation table, which defines the position of each data block in the output, and rearranges the layered data blocks according to the permutation table, and uses the pseudo-random number generator PRNG to generate corresponding keys and initialization vectors IV; the length and number of data blocks of the key frame data and the ordinary frame data are split into a permutation table as decryption attributes, and the permutation table is sent to the decryption end along with the encrypted data as a code book.

[0019] Step S04: hierarchically encrypt the data blocks, encrypt the common frame data and key frame data using the AES encryption algorithm, and perform secondary encryption of the data using the RSA encryption algorithm based on the extracted key frame data header. Specifically, the substitution table needs to be updated regularly to ensure the security of the decryption attributes within the codebook.

[0020] Step S05, storing the generated substitution table and encryption keys of different data blocks and initialization vector IV, and sending the encrypted data block and the recorded substitution table and key information to the receiving end.

[0021] Step S06: The receiving end performs layered decryption on the received data, decrypts the key frame and common frame data blocks respectively, extracts the length and number of data blocks from which the key frame and common frame are split as decryption attributes according to the received substitution table, and restores the data blocks to the original data.

[0022] Specifically, for padded data, the padded empty bytes are removed to restore the original data.

[0023] Example Taking a certain type of airborne avionics system as an example, firstly, the type of message to be extracted is determined according to the data communication protocol of the test system. Starting from the type, the importance of the input airborne message is divided, and the message incoming time is recorded. The random time is passed into the pseudo-random number generator PRNG as a random seed. Two pseudo-random numbers are generated using the seed, and the message is divided into key frames and ordinary frames according to the importance. The key frame is the key information of the avionics system, and the ordinary frame is distinguished from the system guarantee message. The two pseudo-random numbers are assigned to the data length of the key frame and the ordinary frame respectively. The different diverted data are divided according to the defined data length to become a certain data block, and different data headers are added to each data block. The positions of different positions in the data block are rearranged by the permutation table generated by the pseudo-random number generator PRNG, and the data block is layered. At the same time, the PRNG is used to generate the key and initialization vector IV corresponding to the data block. The layered data is encrypted in layers using the AES encryption algorithm, and the extracted key frame data header is encrypted again using the RSA encryption algorithm. Then the permutation table, encryption key, initialization vector IV and encrypted data block are sent to the airborne receiver. The receiving end performs layered decryption and restoration on the received data, and restores the data block to the original data according to the received substitution table, encryption key and initialization vector IV.

[0024] Although the embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. Alterations, modifications, substitutions and variations of the above embodiments by a person skilled in the art are all within the scope of the present invention.

Claims

1. A data encryption method based on TSN bus transmission of avionics system, characterized in that: The steps include: Step S01, extracting message key frame data according to the data communication protocol of the avionics system, separating it from the common frame data, and using the onboard system time to generate a random seed for use by the pseudo-random number generator PRNG; Step S02, the pseudo-random number generator PRNG generates two pseudo-random numbers x and y, where x is defined as the number of blocks for each key frame data packet, and y is defined as the number of blocks for each ordinary frame data packet, and the packet header format fixed by the TSN protocol is removed from the data packet transmitted by the bus, and the key frame data packet length is obtained as lenx and the ordinary frame data packet length is obtained as leny, and each key frame data packet is divided into a certain data block according to the block length lenx / x, and each ordinary frame data packet is divided into a certain data block according to the block length leny / y, and a different data header is added to each data block; Step S03, using a pseudo-random number generator PRNG to generate a substitution table, the table defines the position of each data block in the output, and rearranges the hierarchical data blocks according to the substitution table, and uses the pseudo-random number generator PRNG to generate mutually corresponding keys and initialization vectors IV; the length and number of the data blocks from which the key frame data and the ordinary frame data are split are put into the substitution table as decryption attributes, and the substitution table is sent to the decryption end along with the encrypted data as a code book; Step S04, hierarchically encrypt the data blocks, encrypt the common frame data and the key frame data using the AES encryption algorithm, and perform secondary data encryption using the RSA encryption algorithm based on the extracted key frame data header; Step S05, storing the generated substitution table and encryption keys of different data blocks and initialization vector IV, and sending the encrypted data block and the recorded substitution table and key information to the receiving end; Step S06: The receiving end performs layered decryption on the received data, decrypts the key frame and common frame data blocks respectively, extracts the length and number of data blocks from which the key frame and common frame are split according to the received substitution table, and restores the data blocks to the original data.

2. According to claim 1, a data encryption method based on TSN bus transmission of an avionics system is characterized by: In the step S02, if the length of the data after block division is a non-integer multiple of the size of the generated block, the empty spaces are padded and the insufficient data blocks are filled, and the padded parts are all 0.

3. The data encryption method based on TSN bus transmission of avionics system according to claim 1 is characterized in that: In step S02, each key frame data block contains lenx / x bytes, and each common frame data block contains leny / y bytes, wherein each byte corresponds one-to-one to the content definition of the airborne system.

4. The data encryption method based on TSN bus transmission of avionics system according to claim 3 is characterized in that: Each byte corresponds to the content definition of the airborne system one by one, including the start bit, end bit, message type, header configuration information of each message definition, and message body content information interpreted by ICD.

5. The data encryption method based on TSN bus transmission of avionics system according to claim 1 is characterized in that: In step S03, the substitution table is updated regularly.

6. The data encryption method based on TSN bus transmission of avionics system according to claim 1 is characterized in that: In step S06, for the padded data, the padded empty bytes are removed to restore the original data.

Citation Information

Patent Citations

  • TSN encryption method and system based on software definition

    CN115225333A

  • Data encryption and decryption method and apparatus thereof, and communication system

    CN105763315A

  • Streaming media storage system-oriented data security management method and system

    CN114302177A

  • 1553B communication protocol data encryption method

    CN116633543A

  • Method for a Dynamic Perpetual Encryption Cryptosystem

    US20170034167A1