Smart park communication data secure transmission method based on Internet of Things

By identifying attacked IoT devices in a smart park, calculating their attacked risk indicators, and dynamically adjusting the communication key update frequency, the problem of determining the key update frequency of IoT devices is solved, and data communication security and communication efficiency are improved.

CN120074953APending Publication Date: 2025-05-30HUAXIN CONSULTATING CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510520244.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In smart parks, how to determine the dynamic update frequency of communication keys of IoT devices remains to be studied.

Method used

By determining the sensor device attacked by a centralized network as the first Internet of Things device, the attack risk indicator is calculated, and the communication key replacement frequency is dynamically determined.

Benefits of technology

Dynamically adjust the key update frequency according to the risk indicators of IoT devices to ensure data communication security, reduce communication bandwidth usage, save network resources, and improve Internet of Things communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074953A_ABST
    Figure CN120074953A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital information transmission, in particular to a smart park communication data secure transmission method based on the Internet of Things. The method comprises the following steps: determining a first Internet of Things device, wherein the first Internet of Things device is one or more sensor devices subjected to centralized network attack in the smart park; determining an attacked risk index of second Internet of Things equipment, wherein the second Internet of Things equipment is any sensor equipment in the first Internet of Things equipment; and determining the communication key replacement frequency of the second Internet of Things device according to the attacked risk index. According to the embodiment of the invention, the key updating frequency of the Internet of Things equipment of different risk levels is dynamically determined according to the risk index of the Internet of Things equipment attacked by the network in the smart park, so that the communication bandwidth occupation is reduced, the network resources are saved, and the communication efficiency of the Internet of Things is improved under the condition of ensuring the data communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of digital information transmission, and particularly relates to a method for secure transmission of communication data in an intelligent park based on the Internet of Things. Background Art

[0002] In an intelligent park, the access of Internet of Things devices is crucial for data transmission security. Dynamic key management and dynamic permission control are effective means to ensure the secure access of devices to the network. The dynamic key management system can update the device keys through the authentication center, dynamically replace the keys, and ensure the security of Internet of Things devices against external network attacks. When the dynamic key management system detects abnormal behavior of a device, the key management system can trigger the key update mechanism of the authentication center to regenerate new keys, and the device side automatically updates them to protect the communication security of device data.

[0003] However, how to determine the dynamic update frequency of the communication keys of Internet of Things devices in an intelligent park still remains to be studied. Summary of the Invention

[0004] To solve the above problems, an embodiment of this application provides a method for secure transmission of communication data in an intelligent park based on the Internet of Things. The method includes: Determine a first Internet of Things device, where the first Internet of Things device is one or more sensor devices in the intelligent park that are centrally network attacked; Determine the attack risk index of a second Internet of Things device, where the second Internet of Things device is any one of the sensor devices in the first Internet of Things device; According to the attack risk index, determine the communication key replacement frequency of the second Internet of Things device.

[0005] Optionally, determining the first Internet of Things device includes: Determine the Internet of Things devices in the intelligent park that are network attacked; Determine the Internet of Things devices that are attacked in the same time period among the network attacked Internet of Things devices; Determine the Internet of Things devices that are attacked by the same attacker among the Internet of Things devices that are attacked in the same time period; Determine the Internet of Things devices that are attacked by the same attacker among the Internet of Things devices that are attacked in the same time period as the first Internet of Things device.

[0006] Optionally, determining the Internet of Things devices in the intelligent park that are network attacked includes: Obtain the sampling anomaly degree of the sensors of the Internet of Things devices in the intelligent park; According to the sampling anomaly degree, determine the Internet of Things devices that are network attacked.

[0007] Optionally, obtaining the sampling anomaly degree of the sensors of the Internet of Things devices in the smart park includes: Obtaining the abnormal sampling time interval of the current sensor; Obtaining the total number of abnormal sampling time intervals of the current sensor; Obtaining the number of sampling points in the abnormal sampling time interval of the current sensor; Obtaining the overall sampling time of the current sensor; Obtaining the normal sampling time interval of the current sensor; According to the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval, obtaining the sampling anomaly degree of the sensors of the Internet of Things devices in the smart park.

[0008] Optionally, determining the Internet of Things devices attacked by the same attacker among the Internet of Things devices attacked by the same time period includes: Obtaining the time aggregation of the abnormal sampling time intervals of the Internet of Things devices attacked by the network; According to the time aggregation, determining the Internet of Things devices attacked by the same attacker among the Internet of Things devices attacked by the network.

[0009] Optionally, obtaining the time aggregation of the abnormal sampling time intervals of the Internet of Things devices attacked by the network includes: Obtaining the number of sensors with abnormal sampling time intervals in the current time period; Obtaining the number of sensors with abnormal sampling time intervals in the overall sampling time; Obtaining the abnormal sampling time interval of the current sensor in the current time period; According to the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time interval of the current sensor in the current time period, obtaining the time aggregation of the abnormal sampling time intervals of the Internet of Things devices attacked by the network.

[0010] Optionally, determining the Internet of Things devices attacked by the same attacker among the Internet of Things devices attacked by the same time period includes: Obtaining the possibility that the Internet of Things devices attacked by the same time period are attacked by the same attacker; According to the possibility, determining the Internet of Things devices attacked by the same attacker among the Internet of Things devices attacked by the same time period.

[0011] Optionally, obtaining the probability that the IoT devices attacked in the same time period are attacked by the same attacker includes: Obtaining the abnormal sampling time interval of the current sensor in the current time period; Obtaining the average length of the abnormal sampling time intervals of all sensors in the current time period; Obtaining the number of sampling data of the current sensor in the abnormal sampling time interval; Obtaining the average value of the sampling interval times of all sensors in the current time period; Obtaining the probability that the IoT devices attacked in the same time period are attacked by the same attacker according to the abnormal sampling time interval, the average length, the number of sampling data, and the average value of the current sensor in the current time period.

[0012] Optionally, determining the attack risk index of the second IoT device includes: Obtaining the number of times the sensors of the second IoT device are intensively attacked in the abnormal sampling time interval; Obtaining the number of abnormal sampling time intervals of the sensors of the second IoT device; Obtaining the duration of the abnormal sampling time interval of the sensors of the second IoT device being intensively attacked at any time; Obtaining the total abnormal sampling time interval of the sensors of the second IoT device; Determining the attack risk index of the second IoT device according to the number of intensive attacks, the number of abnormal sampling time intervals of the sensors of the second IoT device, the duration, and the total interval.

[0013] Optionally, determining the communication key replacement frequency of the second IoT device according to the attack risk index includes: Obtaining the benchmark communication key replacement frequency of the IoT devices in the smart park; Obtaining the adjustment coefficient of the benchmark communication key replacement frequency; Determining the communication key replacement frequency of the second IoT device according to the attack risk index, the benchmark communication key replacement frequency, and the adjustment coefficient.

[0014] In summary, the embodiments of the present application provide a method for secure transmission of communication data in a smart park based on the Internet of Things. The method includes: determining a first Internet of Things device, where the first Internet of Things device is one or more sensor devices in the smart park that are centrally network-attacked; determining the attack risk index of a second Internet of Things device, where the second Internet of Things device is any one of the sensor devices in the first Internet of Things device; and determining the communication key replacement frequency of the second Internet of Things device according to the attack risk index. The embodiments of the present application dynamically determine the key update frequencies of Internet of Things devices with different risk levels according to the magnitudes of the risk indexes of network attacks on Internet of Things devices in a smart park, thereby reducing the communication bandwidth occupancy, saving network resources, and improving the communication efficiency of the Internet of Things while ensuring data communication security. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] To more clearly illustrate the implementation embodiments of the present application, the accompanying drawings required for use in the implementation will be briefly introduced below. It should be understood that the accompanying drawings only show some implementation embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained according to the accompanying drawings without creative efforts.

[0016] Figure 1 is a flowchart of a method for secure transmission of communication data in a smart park based on the Internet of Things shown according to an exemplary embodiment.

[0017] Figure 2 is a flowchart of a method for determining a first Internet of Things device shown according to an exemplary embodiment.

[0018] Figure 3 is a flowchart of a method for determining Internet of Things devices in a smart park that are network-attacked shown according to an exemplary embodiment.

[0019] Figure 4 is a flowchart of a method for obtaining the sampling anomaly degree of sensors of Internet of Things devices in a smart park shown according to an exemplary embodiment.

[0020] Figure 5 is a flowchart of a method for determining Internet of Things devices that are attacked in the same time period among Internet of Things devices that are network-attacked shown according to an exemplary embodiment.

[0021] Figure 6 is a flowchart of a method for obtaining the time aggregation of the abnormal sampling time interval of Internet of Things devices that are network-attacked shown according to an exemplary embodiment.

[0022] Figure 7It is a flowchart of a method for determining Internet of Things devices attacked by the same attacker among Internet of Things devices attacked during the same time period, shown according to an exemplary embodiment.

[0023] Figure 8 It is a flowchart of a method for obtaining the possibility that Internet of Things devices attacked during the same time period are attacked by the same attacker, shown according to an exemplary embodiment.

[0024] Figure 9 It is a flowchart of a method for determining the attack risk index of a second Internet of Things device, shown according to an exemplary embodiment.

[0025] Figure 10 It is a flowchart of a method for determining the communication key replacement frequency of a second Internet of Things device according to the attack risk index, shown according to an exemplary embodiment. Detailed implementation manners

[0026] To clearly illustrate the technical features of this solution, the present application will be elaborated in detail below through specific implementation manners and in combination with the accompanying drawings.

[0027] Embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.

[0028] It should be understood that the various steps recorded in the method embodiments of the present application can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this regard.

[0029] The term "including" and its variations used herein are open-ended, that is, "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0030] It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0031] It should be noted that the modifications of "one" and "multiple" mentioned in this application are illustrative rather than restrictive. Those skilled in the art should understand that, unless clearly specified otherwise in the context, it should be understood as "one or more". In the description of this application, unless otherwise stated, "multiple" means two or more, and other quantifiers are similar; "at least one (piece)", "one (piece) or more (pieces)" or similar expressions refer to any combination of these items (pieces), including any combination of a single item (piece) or plural items (pieces). For example, at least one (piece) of a can represent any number of a; for another example, one (piece) or more (pieces) of a, b, and c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple; "and / or" is a relationship describing associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural.

[0032] In the embodiments of this application, although operations or steps are described in a specific order in the drawings, it should not be understood that these operations or steps are required to be executed in the specific order shown or in a serial order, nor that all the operations or steps shown are required to be executed to obtain the desired result. In the embodiments of this application, these operations or steps can be executed serially; they can also be executed in parallel; or a part of these operations or steps can be executed.

[0033] At the same time, it can be understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of data) should comply with the requirements of corresponding laws, regulations and related provisions.

[0034] First, the application scenario of this application is described. In a smart park, since the data collection frequencies of various sensors in Internet of Things devices are different, and when the devices are under cyber attacks, it may lead to abnormal sampling data. Therefore, when performing dynamic communication key updates, the sensor devices with more obvious abnormal behaviors need to update keys more frequently to ensure the secure transmission of data. The present invention determines the risk index size of the cyber attack on the currently abnormal sensors according to the sampling frequencies and the amounts of collected data of different sensors, and dynamically determines the key update frequencies of Internet of Things devices with different risk levels, thereby reducing the communication bandwidth occupancy, saving network resources, and improving the communication efficiency of the Internet of Things while ensuring data communication security. The following describes this application with specific embodiments.

[0035] Figure 1 is a flowchart of a method for secure transmission of communication data in a smart park based on the Internet of Things shown according to an exemplary embodiment. As Figure 1As shown in the figure, an embodiment of the present application provides a method for secure transmission of communication data in a smart park based on the Internet of Things, which may include the following steps: In step S10, a first Internet of Things device is determined, and the first Internet of Things device is one or more sensor devices in the smart park that are centrally attacked by a network.

[0036] In this step, a first Internet of Things device is determined. The first Internet of Things device is one or more sensor devices in the smart park that are centrally attacked by a network. Exemplarily, the Internet of Things devices in the smart park that are attacked by a network can be determined first, then the Internet of Things devices that are attacked in the same time period among the Internet of Things devices that are attacked by a network can be determined, then the Internet of Things devices that are attacked by the same attacker among the Internet of Things devices that are attacked in the same time period can be determined, and finally the Internet of Things devices that are attacked by the same attacker among the Internet of Things devices that are attacked in the same time period are determined as the first Internet of Things device.

[0037] In step S20, the attack risk index of a second Internet of Things device is determined, and the second Internet of Things device is any one of the sensor devices in the first Internet of Things device.

[0038] In this step, the attack risk index of the second Internet of Things device is determined. The second Internet of Things device is any one of the sensor devices in the first Internet of Things device. Exemplarily, the number of times the sensor of the second Internet of Things device is centrally attacked in the abnormal sampling time interval can be obtained first, then the number of abnormal sampling time intervals of the sensor of the second Internet of Things device can be obtained, then the duration of the abnormal sampling time interval of any one central attack of the sensor of the second Internet of Things device can be obtained, then the total abnormal sampling time interval of the sensor of the second Internet of Things device can be obtained, and finally the attack risk index of the second Internet of Things device is determined according to the number of times of the central attack, the number of abnormal sampling time intervals of the sensor of the second Internet of Things device, the duration, and the total interval.

[0039] In step S30, according to the attack risk index, the communication key replacement frequency of the second Internet of Things device is determined.

[0040] In this step, according to the attack risk index, the communication key replacement frequency of the second Internet of Things device is determined. Exemplarily, the reference communication key replacement frequency of the Internet of Things devices in the smart park can be obtained first, then the adjustment coefficient of the reference communication key replacement frequency can be obtained, and finally the communication key replacement frequency of the second Internet of Things device is determined according to the attack risk index, the reference communication key replacement frequency, and the adjustment coefficient.

[0041] In summary, the embodiments of the present application provide a method for secure transmission of communication data in an intelligent park based on the Internet of Things. The method includes: determining a first Internet of Things device, where the first Internet of Things device is one or more sensor devices in the intelligent park that are centrally attacked by a network; determining the attack risk index of a second Internet of Things device, where the second Internet of Things device is any one of the sensor devices in the first Internet of Things device; and determining the communication key replacement frequency of the second Internet of Things device according to the attack risk index. The embodiments of the present application dynamically determine the key update frequencies of Internet of Things devices with different risk levels according to the magnitudes of the risk indicators of Internet of Things devices being attacked by a network in an intelligent park, thereby reducing the communication bandwidth occupancy, saving network resources, and improving the communication efficiency of the Internet of Things while ensuring data communication security.

[0042] Figure 2 is a flowchart of a method for determining a first Internet of Things device shown according to an exemplary embodiment. As Figure 2 shown, the determining of the first Internet of Things device may include the following steps: In step S101, determine the Internet of Things devices in the intelligent park that are attacked by a network.

[0043] In this step, determine the Internet of Things devices in the intelligent park that are attacked by a network. Exemplarily, the sampling anomaly degree of the sensors of the Internet of Things devices in the intelligent park may be obtained first, and then the Internet of Things devices that are attacked by a network may be determined according to the sampling anomaly degree.

[0044] In step S102, determine the Internet of Things devices among the Internet of Things devices attacked by a network that are attacked in the same time period.

[0045] In this step, determine the Internet of Things devices among the Internet of Things devices attacked by a network that are attacked in the same time period. Exemplarily, the time aggregation of the abnormal sampling time intervals of the Internet of Things devices attacked by a network may be obtained first, and then the Internet of Things devices among the Internet of Things devices attacked by a network that are attacked in the same time period may be determined according to the time aggregation.

[0046] In step S103, determine the Internet of Things devices among the Internet of Things devices attacked in the same time period that are attacked by the same attacker.

[0047] In this step, determine the Internet of Things devices among the Internet of Things devices attacked in the same time period that are attacked by the same attacker. Exemplarily, the possibility of the Internet of Things devices attacked in the same time period being attacked by the same attacker may be obtained first, and then the Internet of Things devices among the Internet of Things devices attacked in the same time period that are attacked by the same attacker may be determined according to the possibility.

[0048] In step S104, the IoT devices among the IoT devices attacked within the same time period and attacked by the same attacker are determined as the first IoT devices.

[0049] In this step, the IoT devices among the IoT devices attacked within the same time period and attacked by the same attacker can be determined as the first IoT devices.

[0050] Figure 3 It is a flowchart of a method for determining IoT devices under cyber attack in a smart park shown according to an exemplary embodiment. As Figure 3 shown, the determination of the IoT devices under cyber attack in the smart park may include the following steps: In step S1011, obtain the sampling anomaly degree of the sensors of the IoT devices in the smart park.

[0051] In this step, obtain the sampling anomaly degree of the sensors of the IoT devices in the smart park. Exemplarily, first obtain the abnormal sampling time interval of the current sensor, then obtain the total number of the abnormal sampling time intervals of the current sensor, then obtain the number of sampling points in the abnormal sampling time interval of the current sensor, then obtain the overall sampling time of the current sensor, then obtain the normal sampling time interval of the current sensor, and then obtain the sampling anomaly degree of the sensors of the IoT devices in the smart park according to the abnormal sampling time interval, the total number of the abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval.

[0052] In step S1012, determine the IoT devices under cyber attack according to the sampling anomaly degree.

[0053] In this step, determine the IoT devices under cyber attack according to the sampling anomaly degree. Exemplarily, the IoT devices with a sampling anomaly degree greater than the first threshold can be determined as the IoT devices under cyber attack. Among them, the first threshold can be 0.7.

[0054] Figure 4 It is a flowchart of a method for obtaining the sampling anomaly degree of the sensors of the IoT devices in the smart park shown according to an exemplary embodiment. As Figure 4 shown, the obtaining of the sampling anomaly degree of the sensors of the IoT devices in the smart park may include the following steps: In step S10111, obtain the abnormal sampling time interval of the current sensor.

[0055] In this step, obtain the i-th abnormal sampling time interval of the current sensor v. Exemplarily, the following sub-steps can be taken to determine the abnormal sampling time interval of the sensor: 1. Obtain the frequency acquisition time points of the sensors and determine the sampling intervals of the sensors. Determine the frequency acquisition time points of any current sensor, and use the time difference between the acquisition time points as the interval time of the current sensor.

[0056] 2. Classify the sampling intervals of the sensors and determine the abnormal sampling points. Use the DBSCAN clustering algorithm to cluster the interval times of the current sensors. Determine that the interval times in the largest cluster of the current sensor's interval times are the normal interval times of the current sensor, and the interval times outside this cluster are the abnormal interval times of the sensor, which are caused by abnormal sampling points.

[0057] 3. Determine the abnormal points of the current sensor according to the concentration and deviation degree of the abnormal sampling points in the sensor, and determine the abnormal sampling time interval of the sensor according to the abnormal points. Due to circuit problems or data reading problems during the sampling process of the sensor, some samples cannot be obtained, resulting in abnormal sampling intervals, which are misidentified as abnormal sampling points. Generally, such sampling points are relatively scattered in time and the differences in sampling intervals are relatively small. When there is an abnormal attack on the sensor, abnormal sampling points will appear frequently, and the abnormal sampling points will be concentrated in a certain time interval; at the same time, compared with normal sampling points, the sampling frequency differences of abnormal sampling points are relatively large, so the differences in abnormal sampling intervals of abnormal sampling are also relatively large compared with normal sampling intervals.

[0058] Determine the time points of each abnormal sampling point. If the time points of the abnormal sampling points are adjacent time points, the time points can be merged to determine that this time period is the abnormal sampling time interval.

[0059] In step S10112, obtain the total number of abnormal sampling time intervals of the current sensor.

[0060] In this step, obtain the total number of abnormal sampling time intervals of the current sensor v.

[0061] In step S10113, obtain the number of sampling points in the abnormal sampling time interval of the current sensor.

[0062] In this step, obtain the number of sampling points in the abnormal sampling time interval i of the current sensor v. The number of sampling points is not zero.

[0063] In step S10114, obtain the overall sampling time of the current sensor.

[0064] In this step, obtain the overall sampling time of the current sensor v, and this overall sampling time is not zero.

[0065] In step S10115, obtain the normal sampling time interval of the current sensor.

[0066] In this step, obtain the normal sampling time interval of the current sensor v.

[0067] In step S10116, according to the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval, obtain the sampling abnormality degree of the sensor of the Internet of Things device in the smart park.

[0068] In this step, according to the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval, obtain the sampling abnormality degree of the sensor v of the Internet of Things device in the smart park. Exemplarily, the sampling abnormality degree of the sensor v of the Internet of Things device in the smart park can be obtained by the following formula: where softmax is a weight normalization function.

[0069] represents the proportion of the abnormal sampling time interval in the current overall sampling time, represents the average value of the abnormal sampling interval time in the current sampling interval, represents the difference between the average value of the abnormal sampling interval time and the normal sampling time interval in the current sampling interval. The larger this value is, the greater the sampling abnormality degree r of the sensor v of the Internet of Things device in the smart park v is greater.

[0070] Figure 5 is a flowchart of a method for determining Internet of Things devices attacked by the same time period in Internet of Things devices under cyber attack according to an exemplary embodiment. As Figure 5 shown, determining the Internet of Things devices attacked by the same time period among the Internet of Things devices under cyber attack may include the following steps: In step S1021, obtain the time aggregation of the abnormal sampling time interval of the Internet of Things device under cyber attack.

[0071] In this step, obtain the time clustering of the abnormal sampling time intervals of the Internet of Things devices under cyberattacks. Exemplarily, first obtain the number of sensors with abnormal sampling time intervals in the current time period, then obtain the number of sensors with abnormal sampling time intervals in the overall sampling time, then obtain the abnormal sampling time intervals of the current sensor in the current time period, and finally, based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period, obtain the time clustering of the abnormal sampling time intervals of the Internet of Things devices under cyberattacks.

[0072] In step S1022, based on the time clustering, determine the Internet of Things devices in the Internet of Things devices under cyberattacks that are attacked in the same time period.

[0073] In this step, based on the time clustering, determine the Internet of Things devices in the Internet of Things devices under cyberattacks that are attacked in the same time period. Exemplarily, the Internet of Things devices with a time clustering greater than a second threshold can be determined as the Internet of Things devices attacked in the same time period. Among them, the second threshold can be 0.7.

[0074] Figure 6 is a flowchart of a method for obtaining the time clustering of the abnormal sampling time intervals of the Internet of Things devices under cyberattacks shown according to an exemplary embodiment. As Figure 6 shown, obtaining the time clustering of the abnormal sampling time intervals of the Internet of Things devices under cyberattacks may include the following steps: In step S10211, obtain the number of sensors with abnormal sampling time intervals in the current time period.

[0075] In this step, obtain the number n of sensors with abnormal sampling time intervals in the current time period.

[0076] In step S10212, obtain the number of sensors with abnormal sampling time intervals in the overall sampling time.

[0077] In this step, obtain the number N of sensors with abnormal sampling time intervals in the overall sampling time.

[0078] In step S10213, obtain the abnormal sampling time intervals of the current sensor in the current time period.

[0079] In this step, obtain the abnormal sampling time interval T of the current sensor j in the current time period j .

[0080] In step S10214, based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period, obtain the time aggregation of the abnormal sampling time intervals of the Internet of Things device under cyber attack.

[0081] In this step, based on the number n of sensors with abnormal sampling time intervals in the current time period, the number N of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time interval T of the current sensor in the current time period j , obtain the time aggregation E of the abnormal sampling time intervals of the Internet of Things device under cyber attack. Exemplarily, the time aggregation E of the abnormal sampling time intervals of the Internet of Things device under cyber attack can be obtained by the following formula: Where is the intersection operation, is the union operation, and is not zero. represents the concentration of the abnormal sampling time intervals of the Internet of Things device under cyber attack.

[0082] Figure 7 is a flowchart showing a method for determining Internet of Things devices attacked by the same attacker among Internet of Things devices attacked in the same time period according to an exemplary embodiment. As Figure 7 shown, determining Internet of Things devices attacked by the same attacker among Internet of Things devices attacked in the same time period may include the following steps: In step S1031, obtain the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker.

[0083] In this step, obtain the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker. Exemplarily, first obtain the abnormal sampling time intervals of the current sensor in the current time period, then obtain the average length of the abnormal sampling time intervals of all sensors in the current time period, then obtain the number of sampling data of the current sensor in the abnormal sampling time intervals, then obtain the average value of the sampling interval times of all sensors in the current time period, and finally, based on the abnormal sampling time intervals of the current sensor in the current time period, this average length, this number of sampling data, and this average value, obtain the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker.

[0084] In step S1032, based on the possibility, determine Internet of Things devices attacked by the same attacker among Internet of Things devices attacked in the same time period.

[0085] In this step, according to the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker, determine the Internet of Things devices among the Internet of Things devices attacked in the same time period that are attacked by the same attacker. Exemplarily, the Internet of Things devices with a possibility greater than the third threshold can be determined as the Internet of Things devices among the Internet of Things devices attacked in the same time period that are attacked by the same attacker. Among them, the third threshold can be 0.7.

[0086] Figure 8 is a flowchart of a method for obtaining the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker shown according to an exemplary embodiment. As Figure 8 shown, obtaining the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker may include the following steps: In step S10311, obtain the abnormal sampling time interval of the current sensor in the current time period.

[0087] In this step, obtain the abnormal sampling time interval T of the current sensor p in the current time period p .

[0088] In step S10312, obtain the average length of the abnormal sampling time intervals of all sensors in the current time period.

[0089] In this step, obtain the average length T of the abnormal sampling time intervals of all sensors in the current time period.

[0090] In step S10313, obtain the number of sampling data of the current sensor in the abnormal sampling time interval.

[0091] In this step, obtain the number of sampling data m of the current sensor p in the abnormal sampling time interval p . This number of sampling data m p is not zero.

[0092] In step S10314, obtain the mean value of the sampling interval times of all sensors in the current time period.

[0093] In this step, obtain the mean value ΔT of the sampling interval times of all sensors in the current time period e .

[0094] In step S10315, according to the abnormal sampling time interval of the current sensor in the current time period, the average length, the number of sampling data, and the mean value, obtain the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker.

[0095] In this step, according to the abnormal sampling time interval T of the current sensor p in the current time period p , the average length T, the number m of sampling data p , and the mean value ΔT e , the possibility C that the Internet of Things devices attacked in the same time period are attacked by the same attacker is obtained. Exemplarily, the possibility C that the Internet of Things devices attacked in the same time period are attacked by the same attacker can be obtained by the following formula: where softmax is a weight normalization function, and n is the number of sensors with abnormal sampling time intervals in the current time period. can indicate whether the lengths of various network attack times are relatively close. The smaller this value is, the closer the lengths of various network attack durations are, and the higher the possibility of being the same attacker. represents the average abnormal sampling interval time of the current abnormal sampling time interval and the mean value of the sampling interval times of all sensors in the current time period. The larger this value is, the greater the possibility of being attacked.

[0096] Figure 9 is a flowchart of a method for determining the attack risk index of a second Internet of Things device shown according to an exemplary embodiment. As Figure 9 shown, the determination of the attack risk index of the second Internet of Things device may include the following steps: In step S201, obtain the number of times the sensors of the second Internet of Things device are concentratedly attacked in the abnormal sampling time interval.

[0097] In this step, obtain the number k of times the sensors of the second Internet of Things device are concentratedly attacked in the abnormal sampling time interval.

[0098] In step S202, obtain the number of abnormal sampling time intervals of the sensors of the second Internet of Things device.

[0099] In this step, obtain the number K of abnormal sampling time intervals of the sensors of the second Internet of Things device. This number K is not zero.

[0100] In step S203, obtain the duration of the abnormal sampling time interval when the sensors of the second Internet of Things device are concentratedly attacked any time.

[0101] In this step, obtain the duration T of the abnormal sampling time interval when the sensors of the second Internet of Things device are concentratedly attacked for the qth time. q .

[0102] In step S204, obtain the total abnormal sampling time interval of the sensors of the second Internet of Things device.

[0103] In this step, obtain the total abnormal sampling time interval T of the sensors of the second Internet of Things device. ea . This total interval T ea is not zero.

[0104] In step S205, determine the attack risk index of the second Internet of Things device according to the number of concentrated attacks, the number of abnormal sampling time intervals of the sensors of the second Internet of Things device, the duration, and the total interval.

[0105] In this step, according to the number of concentrated attacks k, the number of abnormal sampling time intervals K of the sensors of the second Internet of Things device, the duration T q , and the total interval T ea , determine the attack risk index h of the second Internet of Things device. Exemplarily, the attack risk index of the second Internet of Things device can be obtained by the following formula: where softmax is a weight normalization function.

[0106] In the current Internet of Things communication environment, if there is an attacker conducting a collective network attack on multiple current Internet of Things devices, the more times and the longer the time of the attack, the greater the intensity of the current attack, the greater the impact on the attacked Internet of Things devices, and the greater the attack risk index of the Internet of Things devices.

[0107] When communicating in a smart park, if the attack risk index of an Internet of Things device is greater, the frequency of replacing the communication key needs to be accelerated. Therefore, the communication key replacement frequency of the current Internet of Things device can be determined according to the benchmark normal frequency of replacing the communication key and the attack risk index of each current Internet of Things device.

[0108] Figure 10 is a flowchart of a method for determining the communication key replacement frequency of a second Internet of Things device according to an attack risk index shown in an exemplary embodiment. As Figure 10 shown, the determining the communication key replacement frequency of the second Internet of Things device according to the attack risk index may include the following steps: In step S301, obtain the benchmark communication key replacement frequency of the Internet of Things devices in the smart park.

[0109] In this step, obtain the benchmark communication key replacement frequency M1 of the Internet of Things devices in the smart park.

[0110] In step S302, obtain the adjustment coefficient of the benchmark communication key replacement frequency.

[0111] In this step, obtain the adjustment coefficient p of the benchmark communication key replacement frequency.

[0112] In step S303, determine the communication key replacement frequency of the second Internet of Things device according to the attacked risk index, the benchmark communication key replacement frequency, and the adjustment coefficient.

[0113] In this step, according to the attacked risk index h, the benchmark communication key replacement frequency M1 (for example, the unit can be times / day), and the adjustment coefficient p, determine the communication key replacement frequency M2 (for example, the unit can be times / day) of the second Internet of Things device. Exemplarily, the communication key replacement frequency M2 of the second Internet of Things device can be obtained by the following formula: where softmax is a weight normalization function.

[0114] In summary, the embodiments of the present application provide a method for secure transmission of communication data in an intelligent park based on the Internet of Things. The method includes: determining a first Internet of Things device, where the first Internet of Things device is one or more sensor devices that are centrally network-attacked in the intelligent park; determining the attacked risk index of a second Internet of Things device, where the second Internet of Things device is any sensor device among the first Internet of Things devices; and determining the communication key replacement frequency of the second Internet of Things device according to the attacked risk index. The embodiments of the present application dynamically determine the key update frequencies of Internet of Things devices with different risk levels according to the size of the risk index of network attacks on Internet of Things devices in an intelligent park, thereby reducing the occupancy of communication bandwidth, saving network resources, and improving the communication efficiency of the Internet of Things while ensuring data communication security.

[0115] The present application also provides a computer-readable storage medium, on which computer program instructions are stored, and when the program instructions are executed by a processor, the steps of the method for secure transmission of communication data in an intelligent park based on the Internet of Things provided by the present application are implemented.

[0116] In another exemplary embodiment, a computer program product is also provided, which includes a computer program that can be executed by a programmable electronic device, and the computer program has a code part for executing the above-mentioned method for secure transmission of communication data in an intelligent park based on the Internet of Things when executed by the programmable electronic device.

[0117] The above-described embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but should not be construed as a limitation on the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application.

Claims

1. A method for secure transmission of communication data in a smart park based on the Internet of Things, characterized in that: The method comprises: Determine a first IoT device, where the first IoT device is one or more sensor devices in the smart park that are attacked by a centralized network; Determine an attack risk indicator of a second Internet of Things device, where the second Internet of Things device is any sensor device in the first Internet of Things device; According to the attack risk indicator, a communication key replacement frequency of the second Internet of Things device is determined.

2. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 1 is characterized in that: The determining the first IoT device includes: Identify IoT devices in the smart park that are attacked by a network attack; Determine the IoT devices attacked in the same time period among the IoT devices attacked by the network; Determine the IoT devices attacked by the same attacker among the IoT devices attacked in the same time period; The IoT devices attacked by the same attacker among the IoT devices attacked in the same time period are determined as the first IoT devices.

3. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 2 is characterized in that: The determining of the IoT devices attacked by the network in the smart park includes: Obtaining the sampling anomaly degree of sensors of the Internet of Things devices in the smart park; The IoT device attacked by the network is determined according to the degree of sampling anomaly.

4. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 3 is characterized in that: The obtaining of the sampling abnormality degree of the sensor of the IoT device in the smart park includes: Get the abnormal sampling time interval of the current sensor; Get the total number of abnormal sampling time intervals of the current sensor; Get the number of sampling points in the abnormal sampling time interval of the current sensor; Get the overall sampling time of the current sensor; Get the normal sampling time interval of the current sensor; According to the abnormal sampling time interval, the total number of the abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval, the sampling abnormality degree of the sensor of the Internet of Things device in the smart park is obtained.

5. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 2 is characterized in that: The determining of the IoT devices attacked in the same time period among the IoT devices attacked by the network includes: Obtaining the time aggregation of abnormal sampling time intervals of the IoT device attacked by the network; According to the time aggregation, the IoT devices attacked in the same time period are determined among the IoT devices attacked by the network.

6. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 5 is characterized in that: The step of obtaining the time aggregation of the abnormal sampling time interval of the IoT device attacked by the network includes: Get the number of sensors with abnormal sampling time intervals in the current time period; Obtain the number of sensors with abnormal sampling time intervals in the overall sampling time; Get the abnormal sampling time interval of the current sensor in the current time period; According to the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period, the time clustering of the abnormal sampling time intervals of the Internet of Things device attacked by the network is obtained.

7. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 2 is characterized in that: The determining the IoT devices attacked by the same attacker among the IoT devices attacked in the same time period includes: Obtain the possibility that the IoT devices attacked in the same time period are attacked by the same attacker; According to the possibility, the IoT devices attacked by the same attacker among the IoT devices attacked in the same time period are determined.

8. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 7 is characterized in that: The obtaining of the possibility that the IoT devices attacked in the same time period are attacked by the same attacker includes: Get the abnormal sampling time interval of the current sensor in the current time period; Get the average length of the abnormal sampling time interval of all sensors in the current time period; Get the number of sampling data of the current sensor in the abnormal sampling time interval; Get the average sampling interval of all sensors in the current time period; According to the abnormal sampling time interval of the current sensor in the current time period, the average length, the number of sampled data, and the mean, the possibility that the Internet of Things devices attacked in the same time period are attacked by the same attacker is obtained.

9. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 1 is characterized in that: Determining the attack risk indicator of the second IoT device includes: Obtaining the number of times the sensor of the second IoT device is attacked in a concentrated manner during the abnormal sampling time interval; Obtaining the number of abnormal sampling time intervals of the sensor of the second Internet of Things device; Obtaining the duration of an abnormal sampling time interval of the sensor of the second IoT device being attacked by any concentrated attack; Obtaining a total abnormal sampling time interval of the sensor of the second IoT device; An attack risk index of the second Internet of Things device is determined according to the number of concentrated attacks, the number of abnormal sampling time intervals of the sensor of the second Internet of Things device, the duration, and the total interval.

10. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 9 is characterized in that: The determining, according to the attack risk indicator, a frequency of changing the communication key of the second IoT device includes: Obtaining a benchmark communication key replacement frequency of the IoT devices of the smart park; Obtaining an adjustment coefficient for the reference communication key replacement frequency; The communication key replacement frequency of the second Internet of Things device is determined according to the attack risk indicator, the benchmark communication key replacement frequency, and the adjustment coefficient.

Citation Information

Patent Citations

  • Self-powered passive Internet of Things intelligent control monitoring method and system

    CN117997587A

  • 5G network real-time encryption technology based on artificial intelligence

    CN119421152A

  • Personal transportation device having steering function

    KR102133955B1

  • Hybrid network intrusion detection system for IoT attacks

    US11075934B1

  • Key management method, key usage apparatus and key management apparatus

    WO2024055303A1