A data encryption method based on TSN bus transmission in an avionics system

Through pseudo-random number generator PRNG and permutation table hierarchical encryption technology, the problem of insufficient data transmission in the existing TSN bus is solved, and efficient and secure data transmission in the avionics system is achieved.

CN120017421BActive Publication Date: 2025-07-04SHENYANG HANGSHENG TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510473967.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-07-04
Estimated Expiration
2045-04-16

AI Technical Summary

Technical Problem

The existing TSN bus transmission data encryption method relies on the secure tunnel connection protection of TSN encrypted switches, which increases the data transmission load and complexity, and lacks effective security measures, resulting in high risks in the security of avionics systems.

Method used

The pseudo-random number generator PRNG is used to generate random seeds, diversion keyframes and ordinary frame data, segment and add data headers according to the block length, and layered encryption is used using permutation tables and AES/RSA algorithms to generate initialization vector IV to ensure the randomness and security of data blocks.

Benefits of technology

It improves the security of TSN network communication data in avionics system, enhances data processing efficiency and adaptability, resists various attacks and cracking methods, and ensures data security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

A data encryption method based on TSN bus transmission in an avionics system, which relates to the field of industrial communication technology, includes the following steps: Step S01, extract the message key frame data, split it from the ordinary frame data, and generate a random seed; Step S02, the pseudo-random number generator PRNG generates two pseudo-random numbers x and y, divide each packet of key frame data into determined blocks according to the block length, divide each packet of ordinary frame data into determined blocks according to the block length, and add different data headers to each data block; Step S03, use the pseudo-random number generator PRNG to generate a permutation table, which defines the position of each data block in the output, rearrange the hierarchical data blocks according to this permutation table, and use the pseudo-random number generator PRNG to generate corresponding keys and initialization vectors IV, etc. The present invention improves the security of TSN network communication data in the avionics system and avoids information leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial communication technologies, and in particular, to a data encryption method for TSN bus transmission based on an avionics system. Background Art

[0002] With the continuous improvement of the networking and intelligence levels of avionics systems, new-generation aircraft have put forward higher requirements for the real-time performance and reliability of on-board networks. Based on the time-sensitive network (TSN) bus system, with its high-precision clock synchronization mechanism, deterministic low-latency transmission characteristics, and superior bandwidth expansion ability, it has gradually become an important interconnection solution for avionics systems. The TSN bus can effectively meet the collaborative work requirements among key devices such as flight control systems, mission computers, and sensors, while improving system interoperability and ensuring the timeliness of data transmission.

[0003] However, the TSN protocol mainly focuses on ensuring deterministic transmission, and its security protection mechanism is not yet perfect. The existing TSN networks lack effective security measures, making their security at high risk.

[0004] Existing data encryption methods for TSN bus transmission rely on the security tunnel connection protection of TSN encryption switches. For example, in Chinese Patent CN115225333A, a software-defined TSN encryption method and system establish a security tunnel between the TSN controller and the TSN encryption switch, and the two communicate through the southbound protocol. The fields are used as flow identifiers to encrypt information. For example, the node receives the plaintext of the terminal and encrypts it to the intermediate node. The intermediate node receives the ciphertext and forwards it to the outgoing node. The outgoing node receives the encrypted data and decrypts it to obtain the plaintext. This process requires the response of the intermediate unit to provide encryption calculations, increasing the data transmission load and complexity. Due to the large volume of on-board communication data, adding an extra intermediate data forwarding link may affect the transmission performance. Summary of the Invention

[0005] In view of the above-mentioned disadvantages and deficiencies of the prior art, the present invention provides a data encryption method for TSN bus transmission based on an avionics system, which improves the security of TSN network communication data in the avionics system and avoids leakage of secrets.

[0006] To achieve the above object, the main technical solutions adopted by the present invention include:

[0007] A data encryption method for TSN bus transmission based on an avionics system, comprising the following steps:

[0008] Step S01: According to the data communication protocol of the avionics system, extract the key frame data of the message, separate it from the ordinary frame data, and generate a random seed for the pseudo-random number generator (PRNG) using the on-board system time;

[0009] Step S02: The pseudo-random number generator PRNG generates two pseudo-random numbers x and y. Define x as the number of split blocks for each packet of key frame data and y as the number of split blocks for each packet of ordinary frame data. Remove the fixed header format of the TSN protocol from the data packets transmitted on the bus, obtain the length of the key frame data packet as lenx and the length of the ordinary frame data packet as leny. Divide each packet of key frame data into determined data blocks according to the block length lenx / x, and divide each packet of ordinary frame data into determined data blocks according to the block length leny / y. Add different data headers to each data block;

[0010] Step S03: Use the pseudo-random number generator PRNG to generate a permutation table, which defines the position of each data block in the output, rearrange the hierarchical data blocks according to this permutation table, and use the pseudo-random number generator PRNG to generate corresponding keys and initialization vectors IV; The lengths and numbers of the split data blocks of the key frame data and the ordinary frame data are used as decryption attributes and put into the permutation table. The permutation table is sent to the decryption end as a cipher book along with the encrypted data;

[0011] Step S04: Perform hierarchical encryption on the data blocks. Encrypt the ordinary frame data and the key frame data through the AES encryption algorithm, and perform secondary encryption on the data through the RSA encryption algorithm according to the extracted key frame data header;

[0012] Step S05: Store the generated permutation table, the encryption keys of different data blocks, and the initialization vector IV, and send the encrypted data blocks, the recorded permutation table, and the key information to the receiving end;

[0013] Step S06: The receiving end performs hierarchical decryption on the received data, decrypts the key frame and ordinary frame data blocks respectively, extracts the lengths and numbers of the split data blocks of the key frame and the ordinary frame from the received permutation table, and restores the data blocks to the original data.

[0014] Further, in the step S02, if the length of the data after splitting is not an integer multiple of the generated block size, then fill in empty positions for it, and perform padding processing on the insufficient data blocks. The filled parts are all 0.

[0015] Further, in the step S02, each key frame data block contains lenx / x bytes, and each ordinary frame data block contains leny / y bytes, where each byte corresponds one-to-one with the content definition of the airborne system.

[0016] Further, each byte corresponds one-to-one with the content definition of the airborne system, including the start bit, end bit, message type, header configuration information defined by the message, and the message body content information interpreted through ICD.

[0017] Further, in the step S03, the substitution table is updated regularly.

[0018] Further, in the step S06, for the filled data, the filled empty bytes are removed to restore the original data.

[0019] The beneficial effects of the present invention are as follows:

[0020] 1) The present invention divides data into blocks by generating random numbers, increasing the randomness of the length of each data block and also increasing the cracking difficulty. For different data blocks, hierarchical processing is performed according to the importance level, improving the data processing efficiency;

[0021] 2) The present invention adopts a pseudo-random number generator PRNG to improve the unpredictability of generating pseudo-random numbers, thereby increasing the randomness of the length of hierarchical data blocks and the complexity of generating the substitution table, thus resisting various attack and cracking means;

[0022] 3) The present invention performs hierarchical encryption on data blocks, and performs secondary encryption processing on key frame data, ensuring data security. At the same time, different encryption rules can also be changed according to environmental needs to adapt to different environmental requirements;

[0023] 4) The present invention encrypts and restores data by using the substitution table and the generated encryption key data, improving data security;

[0024] 5) The present invention encrypts data by generating pseudo-random numbers, without an encryption database and a sorting database, and it is difficult to perform brute-force cracking by brute-force means such as exhaustive search, and the encryption security is high. Specific embodiments

[0025] In order to better explain the present invention for easy understanding, the present invention will be described in detail below through specific embodiments.

[0026] The present invention provides a data encryption method based on the transmission of the TSN bus of an avionics system, including the following steps:

[0027] Step S01: According to the data communication protocol of the avionics system, extract the message key frame data, separate it from the ordinary frame data, and use the airborne system time to generate a random seed for use by the pseudo-random number generator PRNG.

[0028] Step S02: The pseudo-random number generator PRNG generates two pseudo-random numbers x and y. Define x as the number of chunks for each packet of key frame data and y as the number of chunks for each packet of ordinary frame data. Remove the fixed header format of the TSN protocol from the data packets transmitted on the bus, obtain the length of the key frame data packet as lenx and the length of the ordinary frame data packet as leny. Divide each packet of key frame data into determined data chunks according to the chunk length lenx / x, and divide each packet of ordinary frame data into determined data chunks according to the chunk length leny / y. Add different data headers to each data chunk.

[0029] Each key frame data chunk contains lenx / x bytes, and each ordinary frame data chunk contains leny / y bytes. Each byte corresponds one-to-one with the content definition of the airborne system. Each byte corresponds one-to-one with the content definition of the airborne system, including the start bit, end bit, message type, header configuration information defined by the message, and message body content information that can be interpreted through the ICD.

[0030] Specifically, if the length of the data after chunking is not an integer multiple of the generated chunk size, fill in the empty positions. For the insufficient data chunks, perform padding processing, and the padded parts are all 0.

[0031] Step S03: Use the pseudo-random number generator PRNG to generate a permutation table, which defines the position of each data chunk in the output, rearrange the hierarchical data chunks according to this permutation table, and use the pseudo-random number generator PRNG to generate corresponding keys and initialization vectors IV; the lengths and numbers of chunks of the key frame data and ordinary frame data that are split are used as decryption attributes and put into the permutation table. The permutation table is sent to the decryption end as a cipher book along with the encrypted data.

[0032] Step S04: Perform hierarchical encryption on the data chunks. Encrypt the ordinary frame data and key frame data through the AES encryption algorithm, and perform secondary encryption on the data through the RSA encryption algorithm according to the extracted key frame data header. Specifically, the permutation table needs to be updated regularly to ensure the security of the decryption attributes inside the cipher book.

[0033] Step S05: Store the generated permutation table, encryption keys of different data chunks, and the initialization vector IV, and send the encrypted data chunks, the recorded permutation table, and key information to the receiving end.

[0034] Step S06: The receiving end performs hierarchical decryption on the received data, decrypts the key frame and ordinary frame data chunks respectively, extracts the lengths and numbers of chunks of the key frame and ordinary frame that are split out from the received permutation table as decryption attributes, and restore the data chunks to the original data.

[0035] Specifically, for the padded data, remove the padded empty bytes to restore the original data.

[0036] Embodiment

[0037] Taking a certain type of airborne avionics system as an example, first, determine the types of messages to be extracted according to the data communication protocol of the test system. Starting from the types, classify the importance of the input airborne messages, record the message incoming time, and use this random time as a random seed to be passed into the pseudo-random number generator PRNG. Use this seed to generate two pseudo-random numbers. According to the importance of the messages, they are divided into key frames and ordinary frames, where the key frames are the key information of the avionics system, and the ordinary frames are messages such as system guarantee for distinction. The two pseudo-random numbers are respectively assigned to the data lengths of the key frames and ordinary frames. Divide the different classified data according to the defined data lengths to become determined data blocks, and at the same time add different data headers to each data block. Rearrange the positions of different positions in the data block through the permutation table generated by the pseudo-random number generator PRNG, and perform hierarchical processing on the data block. At the same time, use PRNG to generate a key and an initialization vector IV corresponding to the data block. Perform hierarchical encryption on the stratified data through the AES encryption algorithm, and use the RSA encryption algorithm to perform secondary encryption on the extracted key frame data header. Subsequently, send the permutation table, encryption key, initialization vector IV, and the encrypted data block to the airborne receiving end. The receiving end decrypts and restores the received data layer by layer, and restores the data block to the original data according to the received permutation table, encryption key, and initialization vector IV.

[0038] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Any modifications, changes, substitutions, and variations made by those of ordinary skill in the art to the above embodiments fall within the scope of the present invention.

Claims

1. A data encryption method based on TSN bus transmission in an avionics system, characterized in that, It includes the following steps: Step S01: According to the data communication protocol of the avionics system, extract the message key frame data, split it from the ordinary frame data, and use the on-board system time to generate a random seed for the pseudo-random number generator PRNG; Step S02: The pseudo-random number generator PRNG generates two pseudo-random numbers x and y. Define x as the number of split blocks for each packet of key frame data and y as the number of split blocks for each packet of ordinary frame data. Remove the fixed header format of the TSN protocol from the data packets transmitted on the bus, obtain the key frame data packet length lenx and the ordinary frame data packet length leny. Divide each packet of key frame data into determined data blocks according to the block length lenx / x, and divide each packet of ordinary frame data into determined data blocks according to the block length leny / y. Add different data headers to each data block; Step S03: Use the pseudo-random number generator PRNG to generate a permutation table, which defines the position of each data block in the output, rearrange the hierarchical data blocks according to the permutation table, and use the pseudo-random number generator PRNG to generate the corresponding key and initialization vector IV; The lengths and numbers of the split data blocks of the key frame data and the ordinary frame data are used as decryption attributes and put into the permutation table. The permutation table is sent to the decryption end as a cipher book along with the encrypted data; Step S04: Perform hierarchical encryption on the data blocks, encrypt the ordinary frame data and the key frame data through the AES encryption algorithm, and perform secondary data encryption through the RSA encryption algorithm according to the extracted key frame data header; Step S05: Store the generated permutation table, the encryption keys of different data blocks, and the initialization vector IV, and send the encrypted data blocks, the recorded permutation table, and the key information to the receiving end; Step S06: The receiving end performs hierarchical decryption on the received data, decrypts the key frame and ordinary frame data blocks respectively, extracts the lengths and numbers of the split data blocks of the key frame and the ordinary frame from the received permutation table, and restores the data blocks to the original data.

2. The data encryption method based on TSN bus transmission of an avionics system according to claim 1, characterized in that: In the step S02, if the length of the data after splitting is not an integer multiple of the generated block size, fill in empty positions for it, and perform padding processing on the insufficient data blocks. The filled parts are all 0.

3. A data encryption method based on TSN bus transmission of an avionics system according to claim 1, characterized in that: In the step S02, each key frame data block contains lenx / x bytes, and each ordinary frame data block contains leny / y bytes, where each byte corresponds one-to-one to the content definition of the on-board system.

4. A data encryption method based on TSN bus transmission of an avionics system according to claim 3, characterized in that: The one-to-one correspondence between each byte and the content definition of the on-board system includes the start bit, end bit, message type, header configuration information defined by the message, and the message body content information interpreted through the ICD.

5. A data encryption method based on TSN bus transmission of an avionics system according to claim 1, characterized in that: In the step S03, the permutation table is updated regularly.

6. A data encryption method based on TSN bus transmission of an avionics system according to claim 1, characterized in that: In the step S06, for the filled data, remove the filled empty bytes to restore the original data.

Citation Information

Patent Citations

  • TSN encryption method and system based on software definition

    CN115225333A

  • Streaming media storage system-oriented data security management method and system

    CN114302177A

  • Encryption apparatus and method for synchronizing multiple encryption keys with a data stream

    US7242772B1