Intelligent park communication data security transmission method based on internet of things

CN120074953BActive Publication Date: 2026-10-09HUAXIN CONSULTATING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510520244.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2026-10-09
Estimated Expiration
2045-04-24

AI Technical Summary

Technical Problem

[0003]然而,如何确定智慧园区物联网设备的通信密钥的动态更新频率,目前仍然有待研究

Benefits of technology

[0014]In summary, this application provides a method for secure data transmission in a smart park based on the Internet of Things (IoT). The method includes: identifying a first IoT device, which is one or more sensor devices in the smart park that are subject to centralized network attacks; determining an attack risk index for a second IoT device, which is any one of the sensor devices in the first IoT device; and determining the communication key replacement frequency of the second IoT device based on the attack risk index. This application dynamically determines the key update frequency of IoT devices with different risk levels based on the magnitude of the network attack risk index, thereby reducing communication bandwidth consumption, saving network resources, and improving the communication efficiency of the IoT while ensuring data communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074953B_ABST
    Figure CN120074953B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of digital information transmission, in particular to a smart park communication data security transmission method based on Internet of Things. The method comprises the following steps: determining a first Internet of Things device, wherein the first Internet of Things device is one or more sensor devices in the smart park which are attacked by a centralized network attack; determining an attack risk index of a second Internet of Things device, wherein the second Internet of Things device is any sensor device in the first Internet of Things device; and determining a communication key replacement frequency of the second Internet of Things device according to the attack risk index. According to the application, the key update frequency of the Internet of Things devices with different risk levels is dynamically determined according to the risk index of the network attack on the Internet of Things devices in the smart park, so that the communication bandwidth occupation is reduced, the network resources are saved, and the communication efficiency of the Internet of Things is improved under the condition of ensuring the data communication security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of digital information transmission technology, specifically relating to a method for secure transmission of communication data in a smart park based on the Internet of Things. Background Technology

[0002] In smart parks, the access of IoT devices is crucial for data transmission security. Dynamic key management and dynamic access control are effective means to ensure secure network access for devices. A dynamic key management system can update device keys through an authentication center, dynamically changing keys to ensure the security of IoT devices against external network attacks. When the dynamic key management system detects abnormal behavior from a device, it can trigger the authentication center's key update mechanism to regenerate a new key, which is then automatically updated on the device to protect the communication security of device data.

[0003] However, determining the dynamic update frequency of communication keys for IoT devices in smart parks still requires further research. Summary of the Invention

[0004] To address the aforementioned problems, this application provides a method for secure transmission of communication data in a smart park based on the Internet of Things (IoT). The method includes: Identify a first Internet of Things (IoT) device, which is one or more sensor devices in the smart park that are subjected to a centralized network attack; Determine the attack risk indicators of the second IoT device, which is any sensor device among the first IoT devices; Based on the attack risk indicators, the communication key replacement frequency of the second IoT device is determined.

[0005] Optionally, determining the first IoT device includes: Identify the IoT devices in the smart park that have been subjected to cyberattacks; Identify the IoT devices that were attacked within the same time period among the IoT devices that were attacked by the network; Identify the IoT devices attacked by the same attacker among those attacked during the same time period; The IoT device attacked by the same attacker among the IoT devices attacked during the same time period is identified as the first IoT device.

[0006] Optionally, determining the IoT devices in the smart park that have been attacked by the network includes: The degree of sampling anomaly of the sensors of the IoT devices in the smart park is obtained; Based on the degree of sampling anomaly, the IoT device that was attacked by the network is identified.

[0007] Optionally, obtaining the sampling anomaly level of the sensors of the IoT devices in the smart park includes: Obtain the current abnormal sampling time range of the sensor; Obtain the total number of abnormal sampling time intervals of the current sensor; Obtain the number of sampling points in the current abnormal sampling time interval of the sensor; Obtain the current total sampling time of the sensor; Obtain the current normal sampling time interval of the sensor; The degree of sampling anomaly of the sensors of the IoT devices in the smart park is obtained based on the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval.

[0008] Optionally, determining the IoT devices among those attacked during the same time period includes: Obtain the temporal clustering of the abnormal sampling time intervals of the IoT devices under network attack; Based on the time clustering, identify the IoT devices that were attacked within the same time period among the IoT devices that were attacked by the network.

[0009] Optionally, obtaining the temporal clustering of the abnormal sampling time interval of the IoT device under network attack includes: Obtain the number of sensors with abnormal sampling time intervals in the current time period; Obtain the number of sensors with abnormal sampling time intervals within the overall sampling time; Obtain the abnormal sampling time interval of the current sensor in the current time period; Based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period, the temporal clustering of the abnormal sampling time intervals of the IoT device under network attack is obtained.

[0010] Optionally, determining which IoT devices among those attacked within the same time period were attacked by the same attacker includes: To determine the probability that the IoT devices attacked during the same time period were attacked by the same attacker; Based on the aforementioned probability, identify the IoT devices attacked by the same attacker among those attacked during the same time period.

[0011] Optionally, obtaining the probability that the IoT devices attacked in the same time period were attacked by the same attacker includes: Obtain the abnormal sampling time interval of the current sensor in the current time period; Obtain the average length of the abnormal sampling time intervals for all sensors in the current time period; Obtain the number of sampled data points of the sensor during the abnormal sampling time interval; Obtain the average sampling interval time of all sensors in the current time period; Based on the abnormal sampling time interval of the current sensor in the current time period, the average length, the number of sampled data, and the mean, the probability that the IoT devices attacked in the same time period are attacked by the same attacker is obtained.

[0012] Optionally, determining the attack risk indicators of the second IoT device includes: Obtain the number of times the sensor of the second IoT device was subjected to concentrated attacks during the abnormal sampling time interval; Obtain the number of abnormal sampling time intervals of the sensors of the second IoT device; Obtain the duration of the abnormal sampling time interval of the sensor of the second IoT device under any concentrated attack; Obtain the total abnormal sampling time interval of the sensors of the second IoT device; The attack risk index of the second IoT device is determined based on the number of times it was attacked, the number of abnormal sampling time intervals of the sensors of the second IoT device, the duration, and the total interval.

[0013] Optionally, determining the communication key replacement frequency of the second IoT device based on the attack risk index includes: Obtain the reference communication key replacement frequency of the IoT devices in the smart park; Obtain the adjustment coefficient for the reference communication key replacement frequency; The communication key replacement frequency of the second IoT device is determined based on the attack risk index, the baseline communication key replacement frequency, and the adjustment coefficient.

[0014] In summary, this application provides a method for secure data transmission in a smart park based on the Internet of Things (IoT). The method includes: identifying a first IoT device, which is one or more sensor devices in the smart park that are subject to centralized network attacks; determining an attack risk index for a second IoT device, which is any one of the sensor devices in the first IoT device; and determining the communication key replacement frequency of the second IoT device based on the attack risk index. This application dynamically determines the key update frequency of IoT devices with different risk levels based on the magnitude of the network attack risk index, thereby reducing communication bandwidth consumption, saving network resources, and improving the communication efficiency of the IoT while ensuring data communication security. Attached Figure Description

[0015] To more clearly illustrate the implementation schemes of this application, the accompanying drawings used in the implementation schemes will be briefly introduced below. It should be understood that the accompanying drawings only show some implementation schemes of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained from the accompanying drawings without creative effort.

[0016] Figure 1 This is a flowchart illustrating a secure data transmission method for smart park communication based on the Internet of Things, according to an exemplary embodiment.

[0017] Figure 2 This is a flowchart illustrating a method for determining a first Internet of Things (IoT) device according to an exemplary embodiment.

[0018] Figure 3 This is a flowchart illustrating a method for identifying IoT devices in a smart park that have been subjected to cyberattacks, according to an exemplary embodiment.

[0019] Figure 4 This is a flowchart illustrating a method for obtaining the degree of sampling anomalies of sensors in IoT devices in a smart park, according to an exemplary embodiment.

[0020] Figure 5 This is a flowchart illustrating a method for identifying IoT devices that were attacked simultaneously within the same time period, according to an exemplary embodiment.

[0021] Figure 6 This is a flowchart illustrating a method for obtaining the temporal clustering of abnormal sampling time intervals of an IoT device under network attack, according to an exemplary embodiment.

[0022] Figure 7This is a flowchart illustrating a method for identifying IoT devices attacked by the same attacker during the same time period, according to an exemplary embodiment.

[0023] Figure 8 This is a flowchart illustrating a method for obtaining the probability that IoT devices attacked during the same time period are attacked by the same attacker, according to an exemplary embodiment.

[0024] Figure 9 This is a flowchart illustrating a method for determining an attack risk indicator for a second Internet of Things (IoT) device according to an exemplary embodiment.

[0025] Figure 10 This is a flowchart illustrating a method for determining the communication key replacement frequency of a second Internet of Things (IoT) device based on an attack risk indicator, according to an exemplary embodiment. Detailed Implementation

[0026] To clearly illustrate the technical features of this solution, the following detailed description, in conjunction with specific implementation methods and accompanying drawings, will provide a comprehensive explanation of this application.

[0027] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.

[0028] It should be understood that the steps described in the method embodiments of this application may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this application is not limited in this respect.

[0029] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0030] It should be noted that the concepts of "first" and "second" mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0031] It should be noted that the terms "one" and "multiple" used in this application are illustrative rather than restrictive. Those skilled in the art should understand that, unless explicitly stated in the context, they should be interpreted as "one or more". In the description of this application, unless otherwise stated, "multiple" refers to two or more than two, and other quantifiers are similar; "at least one item", "one item or multiple items", or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one item 'a' can represent any number of 'a's; as another example, one or more of a, b, and c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple; "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural.

[0032] Although operations or steps are described in a specific order in the accompanying drawings in the embodiments of this application, this should not be construed as requiring these operations or steps to be performed in the specific order or serial order shown, or requiring all of the shown operations or steps to be performed to obtain the desired result. In the embodiments of this application, these operations or steps may be performed serially; they may be performed in parallel; or a portion of these operations or steps may be performed.

[0033] Meanwhile, it is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0034] First, the application scenario of this application is described. In smart parks, because the data acquisition frequencies of various sensors in IoT devices differ, and when devices are subjected to network attacks, the sampled data may become abnormal. Therefore, during dynamic communication key updates, sensors exhibiting more obvious abnormal behavior require more frequent key updates to ensure secure data transmission. This invention determines the risk index of network attacks on currently abnormal sensors based on their sampling frequencies and the amount of data collected, and dynamically determines the key update frequency for IoT devices with different risk levels. This reduces communication bandwidth consumption, saves network resources, and improves IoT communication efficiency while ensuring data communication security. The following describes this application with specific embodiments.

[0035] Figure 1 This is a flowchart illustrating a secure data transmission method for smart park communication based on the Internet of Things, according to an exemplary embodiment. Figure 1As shown in the figure, this application provides a method for secure transmission of communication data in a smart park based on the Internet of Things, which may include the following steps: In step S10, a first IoT device is identified, which is one or more sensor devices in the smart park that are subjected to centralized network attacks.

[0036] In this step, a first IoT device is identified, which is one or more sensor devices in the smart park that have been subjected to a concentrated network attack. For example, the IoT devices in the smart park that have been attacked can be identified first, then those IoT devices attacked within the same time period can be identified, then those IoT devices attacked within the same time period can be identified as being attacked by the same attacker, and finally, the IoT devices attacked within the same time period and attacked by the same attacker are identified as the first IoT device.

[0037] In step S20, the attack risk index of the second IoT device is determined, where the second IoT device is any sensor device among the first IoT devices.

[0038] In this step, the attack risk index of the second IoT device is determined. The second IoT device is any sensor device in the first IoT device. For example, the attack risk index of the second IoT device can be determined by first obtaining the number of times the sensor of the second IoT device was attacked in an abnormal sampling time interval, then obtaining the number of abnormal sampling time intervals of the sensor of the second IoT device, then obtaining the duration of any abnormal sampling time interval of the sensor of the second IoT device under any concentrated attack, then obtaining the total abnormal sampling time interval of the sensor of the second IoT device, and finally determining the attack risk index of the second IoT device based on the number of concentrated attacks, the number of abnormal sampling time intervals of the sensor of the second IoT device, the duration, and the total interval.

[0039] In step S30, the communication key replacement frequency of the second IoT device is determined based on the attack risk index.

[0040] In this step, the communication key replacement frequency of the second IoT device is determined based on the attack risk indicators. For example, the baseline communication key replacement frequency of the IoT devices in the smart park can be obtained first, then an adjustment factor for the baseline communication key replacement frequency can be obtained, and finally, the communication key replacement frequency of the second IoT device can be determined based on the attack risk indicators, the baseline communication key replacement frequency, and the adjustment factor.

[0041] In summary, this application provides a method for secure data transmission in a smart park based on the Internet of Things (IoT). The method includes: identifying a first IoT device, which is one or more sensor devices in the smart park that are subject to centralized network attacks; determining an attack risk index for a second IoT device, which is any one of the sensor devices in the first IoT device; and determining the communication key replacement frequency of the second IoT device based on the attack risk index. This application dynamically determines the key update frequency of IoT devices with different risk levels based on the magnitude of the network attack risk index, thereby reducing communication bandwidth consumption, saving network resources, and improving the communication efficiency of the IoT while ensuring data communication security.

[0042] Figure 2 This is a flowchart illustrating a method for determining a first Internet of Things (IoT) device according to an exemplary embodiment. Figure 2 As shown, determining the first IoT device may include the following steps: In step S101, the IoT devices in the smart park that have been attacked by the network are identified.

[0043] In this step, the IoT devices in the smart park that have been attacked by the network are identified. For example, the sampling anomaly level of the sensors of the IoT devices in the smart park can be obtained first, and then the IoT devices that have been attacked by the network can be identified based on the sampling anomaly level.

[0044] In step S102, the IoT devices that were attacked during the same time period among the IoT devices attacked by the network are identified.

[0045] In this step, it is necessary to identify the IoT devices that were attacked within the same time period among the IoT devices under cyberattack. For example, the temporal clustering of the abnormal sampling time intervals of the IoT devices under cyberattack can be obtained first, and then the IoT devices that were attacked within the same time period can be identified based on the temporal clustering.

[0046] In step S103, the IoT devices attacked by the same attacker during the same time period are identified.

[0047] In this step, it is necessary to identify which IoT devices were attacked by the same attacker within the same time period. For example, the probability that IoT devices attacked within the same time period were attacked by the same attacker can be obtained first, and then, based on this probability, the IoT devices attacked within the same time period that were attacked by the same attacker can be identified.

[0048] In step S104, the IoT device attacked by the same attacker among the IoT devices attacked in the same time period is identified as the first IoT device.

[0049] In this step, the IoT device attacked by the same attacker among the IoT devices attacked at the same time period can be identified as the first IoT device.

[0050] Figure 3 This is a flowchart illustrating a method for identifying IoT devices in a smart park that have been subjected to a cyberattack, according to an exemplary embodiment. Figure 3 As shown, identifying IoT devices in the smart park that have been subjected to cyberattacks may include the following steps: In step S1011, the sampling anomaly level of the sensors of the IoT devices in the smart park is obtained.

[0051] In this step, the sampling anomaly level of the sensors of IoT devices in the smart park is obtained. For example, the abnormal sampling time interval of the current sensor can be obtained first, then the total number of abnormal sampling time intervals of the current sensor can be obtained, then the number of sampling points in the abnormal sampling time interval of the current sensor can be obtained, then the overall sampling time of the current sensor can be obtained, then the normal sampling time interval of the current sensor can be obtained, and then the sampling anomaly level of the sensors of IoT devices in the smart park can be obtained based on the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval.

[0052] In step S1012, the IoT device that was attacked by the network is determined based on the degree of sampling anomaly.

[0053] In this step, IoT devices that have been subjected to network attacks are identified based on the degree of sampling anomaly. For example, IoT devices with a sampling anomaly degree greater than a first threshold can be identified as IoT devices subjected to network attacks. The first threshold can be 0.7.

[0054] Figure 4 This is a flowchart illustrating a method for obtaining the sampling anomaly level of sensors in IoT devices within a smart park, according to an exemplary embodiment. Figure 4 As shown, obtaining the sampling anomaly level of the sensors of the IoT devices in the smart park may include the following steps: In step S10111, the abnormal sampling time interval of the current sensor is obtained.

[0055] In this step, the i-th abnormal sampling time interval of the current sensor v is obtained. For example, the abnormal sampling time interval of the sensor can be determined by the following sub-steps: 1. Obtain the frequency acquisition time points of the sensor and determine the acquisition interval of the sensor; Determine the frequency acquisition time point of any given sensor, and use the time difference between acquisition time points as the current interval time for that sensor.

[0056] 2. Classify the sensor acquisition intervals and identify abnormal sampling points; The DBSCAN clustering algorithm is used to cluster the current interval times of each sensor. The interval times in the largest cluster of the current sensor interval times are the normal interval times of the current sensor, and the interval times outside the cluster are the abnormal interval times of the sensor, which are caused by abnormal sampling points.

[0057] 3. Determine the current abnormal points of the sensor based on the concentration and deviation of the abnormal sampling points in the sensor, and determine the abnormal sampling time interval of the sensor based on the abnormal points; When a sensor experiences circuit problems or data reading issues during sampling, some samples may not be collected, leading to abnormal sampling intervals that are mistakenly identified as anomalous sampling points. These anomalous sampling points are typically scattered over time, with relatively small differences in their sampling intervals. However, when a sensor is subjected to an anomalous attack, anomalous sampling points will appear frequently and will be concentrated within a specific time interval. Furthermore, the sampling frequency of anomalous sampling points differs significantly from that of normal sampling points, resulting in a substantial difference in the anomalous sampling intervals compared to the normal sampling intervals.

[0058] Determine the time point of each abnormal sampling point. If the time points of abnormal sampling points are adjacent, then the time points can be merged to determine that the time period is the abnormal sampling time interval.

[0059] In step S10112, the total number of abnormal sampling time intervals of the current sensor is obtained.

[0060] In this step, the total number of abnormal sampling time intervals of the current sensor v is obtained.

[0061] In step S10113, the number of sampling points in the current abnormal sampling time interval of the sensor is obtained.

[0062] In this step, the number of sampling points in the abnormal sampling time interval i of the current sensor v is obtained. This number of sampling points is not zero.

[0063] In step S10114, the overall sampling time of the current sensor is obtained.

[0064] In this step, the overall sampling time of the current sensor v is obtained, and this overall sampling time is not zero.

[0065] In step S10115, the normal sampling time interval of the current sensor is obtained.

[0066] In this step, the normal sampling time interval of the current sensor v is obtained.

[0067] In step S10116, the sampling anomaly degree of the sensors of the IoT devices in the smart park is obtained based on the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval.

[0068] In this step, the sampling anomaly level of sensor v in the IoT devices of the smart park is obtained based on the abnormal sampling time intervals, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval. For example, the sampling anomaly level of sensor v in the IoT devices of the smart park can be obtained by the following formula: Here, softmax is the weight normalization function.

[0069] This indicates the percentage of abnormal sampling time intervals relative to the current total sampling time. This represents the average time interval of abnormal sampling within the current sampling interval. This represents the difference between the average of abnormal sampling intervals and the normal sampling intervals within the current sampling range. The larger the value, the greater the degree of sampling abnormality r of the sensors v in the IoT devices of the smart park. v The larger.

[0070] Figure 5 This is a flowchart illustrating a method for identifying IoT devices that were attacked simultaneously within the same time period, according to an exemplary embodiment. Figure 5 As shown, determining which IoT devices were attacked within the same time period among the IoT devices under network attack may include the following steps: In step S1021, the temporal clustering of the abnormal sampling time interval of the IoT device under network attack is obtained.

[0071] In this step, the temporal clustering of abnormal sampling time intervals of the IoT devices under network attack is obtained. For example, the number of sensors with abnormal sampling time intervals in the current time period can be obtained first, then the number of sensors with abnormal sampling time intervals in the overall sampling time can be obtained, then the abnormal sampling time interval of the current sensor in the current time period can be obtained, and finally, based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time interval of the current sensor in the current time period, the temporal clustering of abnormal sampling time intervals of the IoT devices under network attack is obtained.

[0072] In step S1022, based on the time clustering, the IoT devices among the IoT devices attacked by the network are identified that were attacked in the same time period.

[0073] In this step, IoT devices attacked within the same time period are identified based on temporal clustering. For example, IoT devices with a temporal clustering greater than a second threshold can be identified as those attacked within the same time period. The second threshold can be 0.7.

[0074] Figure 6 This is a flowchart illustrating a method for obtaining the temporal clustering of abnormal sampling time intervals of an IoT device under network attack, according to an exemplary embodiment. Figure 6 As shown, obtaining the temporal clustering of the abnormal sampling time interval of the IoT device under network attack may include the following steps: In step S10211, the number of sensors with abnormal sampling time intervals in the current time period is obtained.

[0075] In this step, the number n of sensors with abnormal sampling time intervals in the current time period is obtained.

[0076] In step S10212, the number of sensors with abnormal sampling time intervals in the overall sampling time is obtained.

[0077] In this step, the number N of sensors with abnormal sampling time intervals in the overall sampling time is obtained.

[0078] In step S10213, the abnormal sampling time interval of the current sensor in the current time period is obtained.

[0079] In this step, the abnormal sampling time interval T of the current sensor j in the current time period is obtained. j .

[0080] In step S10214, the temporal clustering of the abnormal sampling time intervals of the IoT device under network attack is obtained based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period.

[0081] In this step, based on the number n of sensors with abnormal sampling time intervals in the current time period, the number N of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time interval T of the current sensor in the current time period... j The temporal clustering E of the abnormal sampling time intervals of the IoT device under network attack is obtained. For example, the temporal clustering E of the abnormal sampling time intervals of the IoT device under network attack can be obtained by the following formula: in, For intersection operations, For the union operation, And it is not zero. This indicates the concentration of abnormal sampling time intervals of IoT devices that have been subjected to cyberattacks.

[0082] Figure 7 This is a flowchart illustrating a method for identifying IoT devices attacked by the same attacker within the same time period, according to an exemplary embodiment. Figure 7 As shown, determining which IoT devices were attacked by the same attacker among those attacked during the same time period may include the following steps: In step S1031, the probability that the IoT devices attacked in the same time period were attacked by the same attacker is obtained.

[0083] In this step, the probability that IoT devices attacked during the same time period are attacked by the same attacker is determined. For example, this can be achieved by first obtaining the abnormal sampling time interval of the current sensor within the current time period, then obtaining the average length of the abnormal sampling time intervals of all sensors within the current time period, then obtaining the number of sampled data points of the current sensor within the abnormal sampling time interval, then obtaining the average sampling interval time of all sensors within the current time period, and finally, based on the abnormal sampling time interval of the current sensor within the current time period, the average length, the number of sampled data points, and the average value, the probability that IoT devices attacked during the same time period are attacked by the same attacker is determined.

[0084] In step S1032, based on the probability, the IoT devices attacked by the same attacker among the IoT devices attacked in the same time period are identified.

[0085] In this step, based on the probability that IoT devices attacked within the same time period are attacked by the same attacker, the IoT devices that were attacked by the same attacker within the same time period are identified. For example, IoT devices with a probability greater than a third threshold can be identified as those attacked by the same attacker within the same time period. The third threshold can be 0.7.

[0086] Figure 8 This is a flowchart illustrating a method for obtaining the probability that IoT devices attacked simultaneously within the same time period are attacked by the same attacker, according to an exemplary embodiment. Figure 8 As shown, obtaining the probability that the IoT devices attacked in the same time period were attacked by the same attacker may include the following steps: In step S10311, the abnormal sampling time interval of the current sensor in the current time period is obtained.

[0087] In this step, the abnormal sampling time interval T of the current sensor p in the current time period is obtained. p .

[0088] In step S10312, the average length of the abnormal sampling time interval of all sensors in the current time period is obtained.

[0089] In this step, the average length T of the abnormal sampling time intervals of all sensors in the current time period is obtained.

[0090] In step S10313, the number of sampled data points of the current sensor in the abnormal sampling time interval is obtained.

[0091] In this step, the number m of sampled data from the current sensor p within the abnormal sampling time interval is obtained. p The number of sampled data is m. p Not zero.

[0092] In step S10314, the average sampling interval time of all sensors in the current time period is obtained.

[0093] In this step, the average sampling interval ΔT of all sensors in the current time period is obtained. e .

[0094] In step S10315, based on the abnormal sampling time interval of the current sensor in the current time period, the average length, the number of sampled data, and the mean, the probability that the IoT devices attacked in the same time period are attacked by the same attacker is obtained.

[0095] In this step, based on the abnormal sampling time interval T of the current sensor p in the current time period... p Average length T, number of sampled data m p and mean ΔT e The probability C of IoT devices attacked within the same time period being attacked by the same attacker can be obtained. For example, the probability C of IoT devices attacked within the same time period being attacked by the same attacker can be obtained by the following formula: Where softmax is the weight normalization function, and n is the number of sensors with abnormal sampling time intervals in the current time period. This value indicates whether the duration of various network attacks is similar. The smaller the value, the more likely that the network attacks are from the same attacker. This represents the average abnormal sampling interval time of the current abnormal sampling time interval and the average sampling interval time of all sensors in the current time period. The larger this value is, the greater the possibility of being attacked.

[0096] Figure 9 This is a flowchart illustrating a method for determining attack risk indicators of a second Internet of Things (IoT) device according to an exemplary embodiment. Figure 9 As shown, determining the attack risk indicators of the second IoT device may include the following steps: In step S201, the number of times the sensor of the second IoT device was attacked in a concentrated manner during the abnormal sampling time interval is obtained.

[0097] In this step, the number of times k of the second IoT device's sensor being attacked in a concentrated manner during the abnormal sampling time interval is obtained.

[0098] In step S202, the number of abnormal sampling time intervals of the sensors of the second IoT device is obtained.

[0099] In this step, the number K of abnormal sampling time intervals of the sensors of the second IoT device is obtained. This number K is not zero.

[0100] In step S203, the duration of the abnormal sampling time interval of the sensor of the second IoT device under any concentrated attack is obtained.

[0101] In this step, the duration T of the abnormal sampling time interval of the sensor of the second IoT device during the q-th centralized attack is obtained. q .

[0102] In step S204, the total abnormal sampling time interval of the sensor of the second IoT device is obtained.

[0103] In this step, the total abnormal sampling time interval T of the sensor of the second IoT device is obtained. ea The total interval T ea Not zero.

[0104] In step S205, the attack risk index of the second IoT device is determined based on the number of times it was attacked, the number of abnormal sampling time intervals of the sensors of the second IoT device, the duration, and the total interval.

[0105] In this step, based on the number of times k is attacked, the number K of abnormal sampling time intervals of the second IoT device's sensors, and the duration T... q and the total interval T ea The attack risk index h of the second IoT device is determined. For example, the attack risk index of the second IoT device can be obtained by the following formula: Here, softmax is the weight normalization function.

[0106] In the current IoT communication environment, if an attacker launches a collective cyberattack against multiple IoT devices, the more attacks there are and the longer they last, the stronger the attack becomes, the greater the impact on the attacked IoT devices, and the higher the risk index of the IoT devices being attacked.

[0107] When communicating in a smart park, if the risk index of IoT devices being attacked is higher, the frequency of changing the communication key needs to be increased. Therefore, the communication key change frequency of the current IoT devices can be determined based on the baseline normal frequency of changing the communication key and the current attack risk index of each IoT device.

[0108] Figure 10 This is a flowchart illustrating a method for determining the communication key replacement frequency of a second Internet of Things (IoT) device based on an attack risk indicator, according to an exemplary embodiment. Figure 10 As shown, determining the communication key replacement frequency of the second IoT device based on the attack risk index may include the following steps: In step S301, the reference communication key replacement frequency of the IoT devices in the smart park is obtained.

[0109] In this step, the reference communication key replacement frequency M1 of the IoT devices in the smart park is obtained.

[0110] In step S302, the adjustment coefficient of the reference communication key replacement frequency is obtained.

[0111] In this step, the adjustment factor p for the reference communication key replacement frequency is obtained.

[0112] In step S303, the communication key replacement frequency of the second IoT device is determined based on the attack risk index, the baseline communication key replacement frequency, and the adjustment coefficient.

[0113] In this step, the communication key change frequency M2 of the second IoT device (e.g., times / day) is determined based on the attack risk index h, the baseline communication key change frequency M1 (e.g., times / day), and the adjustment coefficient p. For example, the communication key change frequency M2 of the second IoT device can be obtained by the following formula: Here, softmax is the weight normalization function.

[0114] In summary, this application provides a method for secure data transmission in a smart park based on the Internet of Things (IoT). The method includes: identifying a first IoT device, which is one or more sensor devices in the smart park that are subject to centralized network attacks; determining an attack risk index for a second IoT device, which is any one of the sensor devices in the first IoT device; and determining the communication key replacement frequency of the second IoT device based on the attack risk index. This application dynamically determines the key update frequency of IoT devices with different risk levels based on the magnitude of the network attack risk index, thereby reducing communication bandwidth consumption, saving network resources, and improving the communication efficiency of the IoT while ensuring data communication security.

[0115] This application also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement the steps of the IoT-based smart park communication data secure transmission method provided in this application.

[0116] In another exemplary embodiment, a computer program product is also provided, which includes a computer program executable by a programmable electronic device, the computer program having a code portion for executing the above-described IoT-based smart park communication data secure transmission method when executed by the programmable electronic device.

[0117] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these modifications and improvements all fall within the protection scope of this application.

Claims

1. A method for secure transmission of communication data in a smart park based on the Internet of Things, characterized in that, The method includes: Identify a first Internet of Things (IoT) device, which is one or more sensor devices in the smart park that are subjected to a centralized network attack; Determine the attack risk index of a second IoT device, wherein the second IoT device is any sensor device among the first IoT devices, wherein determining the attack risk index of the second IoT device includes: obtaining the number of times the sensor of the second IoT device was subjected to concentrated attacks during abnormal sampling time intervals; obtaining the number of abnormal sampling time intervals of the sensor of the second IoT device; obtaining the duration of any abnormal sampling time interval of the sensor of the second IoT device subjected to concentrated attacks; obtaining the total abnormal sampling time intervals of the sensor of the second IoT device; and determining the attack risk index of the second IoT device based on the number of concentrated attacks, the number of abnormal sampling time intervals of the sensor of the second IoT device, the duration, and the total intervals. Determining the communication key replacement frequency of the second IoT device based on the attack risk index includes: obtaining the baseline communication key replacement frequency of the IoT devices in the smart park; obtaining the adjustment coefficient of the baseline communication key replacement frequency; and determining the communication key replacement frequency of the second IoT device based on the attack risk index, the baseline communication key replacement frequency, and the adjustment coefficient. The process of determining the first IoT device includes: Identify the IoT devices in the smart park that have been subjected to cyberattacks; Identify the IoT devices that were attacked within the same time period among the IoT devices that were attacked by the network; Identify the IoT devices attacked by the same attacker among those attacked during the same time period; The IoT device attacked by the same attacker among the IoT devices attacked during the same time period is identified as the first IoT device.

2. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 1, characterized in that, The process of identifying IoT devices in the smart park that have been subjected to cyberattacks includes: The degree of sampling anomaly of the sensors of the IoT devices in the smart park is obtained; Based on the degree of sampling anomaly, the IoT device that was attacked by the network is identified.

3. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 2, characterized in that, The process of obtaining the sampling anomaly level of the sensors of the IoT devices in the smart park includes: Obtain the current abnormal sampling time range of the sensor; Obtain the total number of abnormal sampling time intervals of the current sensor; Obtain the number of sampling points in the current abnormal sampling time interval of the sensor; Obtain the current total sampling time of the sensor; Obtain the current normal sampling time interval of the sensor; The degree of sampling anomaly of the sensors of the IoT devices in the smart park is obtained based on the abnormal sampling time interval, the total number of abnormal sampling time intervals, the number of sampling points, the overall sampling time, and the normal sampling time interval.

4. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 1, characterized in that, The process of identifying IoT devices attacked within the same time period among the IoT devices subjected to network attacks includes: Obtain the temporal clustering of the abnormal sampling time intervals of the IoT devices under network attack; Based on the time clustering, identify the IoT devices that were attacked within the same time period among the IoT devices that were attacked by the network.

5. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 4, characterized in that, The acquisition of the temporal clustering of the abnormal sampling time intervals of the IoT devices under network attack includes: Obtain the number of sensors with abnormal sampling time intervals in the current time period; Obtain the number of sensors with abnormal sampling time intervals within the overall sampling time; Obtain the abnormal sampling time interval of the current sensor in the current time period; Based on the number of sensors with abnormal sampling time intervals in the current time period, the number of sensors with abnormal sampling time intervals in the overall sampling time, and the abnormal sampling time intervals of the current sensor in the current time period, the temporal clustering of the abnormal sampling time intervals of the IoT device under network attack is obtained.

6. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 1, characterized in that, The step of identifying IoT devices attacked by the same attacker within the same time period includes: To determine the probability that the IoT devices attacked during the same time period were attacked by the same attacker; Based on the aforementioned probability, identify the IoT devices attacked by the same attacker among those attacked during the same time period.

7. The method for secure transmission of communication data in a smart park based on the Internet of Things according to claim 6, characterized in that, The method of obtaining the probability that the IoT devices attacked in the same time period were attacked by the same attacker includes: Obtain the abnormal sampling time interval of the current sensor in the current time period; Obtain the average length of the abnormal sampling time intervals for all sensors in the current time period; Obtain the number of sampled data points of the sensor during the abnormal sampling time interval; Obtain the average sampling interval time of all sensors in the current time period; Based on the abnormal sampling time interval of the current sensor in the current time period, the average length, the number of sampled data, and the mean, the probability that the IoT devices attacked in the same time period are attacked by the same attacker is obtained.

Citation Information

Patent Citations

  • 5G network real-time encryption technology based on artificial intelligence

    CN119421152A