Industrial message sending method and receiving method of C2F application transmission system and related equipment
By setting up conversion devices between the master and slave stations of the C2F application, IP packet encapsulation of industrial message data is solved, and the problem of insufficient transmission flexibility is improved through encryption processing.
Patent Information
- Application Number
- CN202510459017.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-14
AI Technical Summary
The existing C2F application data transmission has limited settings between the master and slave stations, resulting in poor transmission flexibility and inability to conduct long-distance data transmission.
The sending and conversion devices and the receiving and conversion devices are set up between the master and slave stations. Through these devices, the industrial message data applied by C2F is encapsulated, and the data format is converted from the EtherCAT data format to an IP data format suitable for transmission in the IP network, thereby realizing the transmission of data between the sending and receiving stations through the IP network.
The transmission flexibility of C2F application industrial data is improved, so that data can be transmitted over a longer distance, while the security of data transmission is improved through encryption processing.
Smart Images

Figure CN120075311A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technologies, and in particular to an industrial message sending method, a receiving method, and related devices for a C2F application transmission system. Background Art
[0002] With the development of society, a new business model called C2F (customer to factory) has emerged. In this model, customers can place orders directly through a digital platform, and factories produce and deliver according to the order requirements. By directly connecting consumers and manufacturers, it eliminates intermediate links, thereby improving efficiency, reducing costs, and providing more personalized customization services. In the C2F model, factories need to respond to consumers' order requirements in real time and be able to quickly adjust the production line to meet personalized needs. This not only requires factories to have efficient production processes but also strong and flexible hardware infrastructure to support high-speed data transmission and processing.
[0003] In related technologies, based on the C2F model, the information layer switch at the factory end needs to transmit a large amount of C2F application data streams of various industrial devices and business management systems. The mainstream communication protocol for these data streams is EtherCAT. At the factory end, based on the EtherCAT protocol, a master-slave transmission structure is usually adopted, that is, a master station and multiple slave stations are set up to transmit EtherCAT data. One master station (Master) is responsible for controlling and synchronizing the slave stations (Slaves) in the network. The master station sends control commands and data, and the slave stations receive and execute these commands. However, since only EtherCAT type data can be transmitted between the master station and the slave stations, and between the slave stations and the slave stations, the set distance between the master station and the slave stations, and between the slave stations and the slave stations cannot be too far, resulting in poor flexibility in the transmission of existing C2F application data. Summary of the Invention
[0004] Embodiments of this application provide an industrial message sending method, a receiving method, and related devices for a C2F application transmission system, which can improve the flexibility of C2F application industrial data transmission.
[0005] To achieve the above object, a first aspect of the embodiments of this application proposes an industrial message sending method for a C2F application transmission system. The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device, and a receiving station that are connected in sequence. The method is applied to the sending conversion device and includes: Obtain C2F application industrial message data input by the sending station; Based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network, encrypt the C2F application industrial message data to obtain encrypted message data; Based on the register configuration of the receiving and converting device, perform IP packet encapsulation on the encrypted message data to obtain IP encrypted message data; Send the IP encrypted message data through the IP network to the receiving and converting device, so that the receiving and converting device forwards the C2F application industrial message data to the receiving station.
[0006] In some embodiments, the performing IP packet encapsulation on the encrypted message data based on the register configuration of the receiving and converting device to obtain IP encrypted message data includes: Based on the register configuration, obtain an IPv4 packet header, and the IPv4 packet header includes an idle protocol identification value; Obtain the target MAC address of the receiving station, and generate an Ethernet frame header based on the target MAC address; Add the IPv4 packet header and the Ethernet frame header to the head of the encrypted message data to obtain the IP encrypted message data.
[0007] In some embodiments, the encrypting the C2F application industrial message data based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network to obtain encrypted message data includes: Generate an encryption key based on the message data characteristics and the real-time network characteristics; Perform encryption processing on the C2F application industrial message data based on the encryption key to generate encrypted data and a corresponding authentication tag; Generate the encrypted message data based on the combination of the encrypted data, the authentication tag, and the real-time network characteristics.
[0008] In some embodiments, the generating an encryption key based on the message data characteristics and the real-time network characteristics includes: Perform hash processing based on the register configuration to generate an initial key; Perform normalization splicing processing on the message data characteristics and the real-time network characteristics to generate a dynamic factor; Perform hash processing based on the dynamic factor to generate a dynamic key; Perform exclusive OR confusion processing on the dynamic key and the initial key to generate the encryption key.
[0009] In some embodiments, encrypting the C2F application industrial message data based on the encryption key to generate encrypted data and a corresponding authentication tag includes: Obtaining a non - linear mapping table and generating a dislocation processing identifier; Based on the non - linear mapping table, performing non - linear substitution on each byte in the C2F application industrial message data to generate non - linear message data; Based on the dislocation processing identifier and the encryption key, performing dislocation encryption processing on the non - linear message data to obtain the encrypted data; Generating the authentication tag based on the mapping table identifier of the non - linear mapping table and the dislocation processing identifier.
[0010] In some embodiments, the dislocation processing identifier includes a row shift identifier and a column mixing identifier. Based on the dislocation processing identifier and the encryption key, performing dislocation encryption processing on the non - linear message data to obtain the encrypted data includes: Based on the row shift identifier, selecting target row data from the non - linear message data for row shift to obtain first - shifted data; Obtaining the mixing matrix corresponding to the column mixing identifier, selecting target column data from the first - shifted data based on the column mixing identifier, and performing matrix operation on the target column data and the mixing matrix to obtain second - shifted data; Performing exclusive - OR processing on the second - shifted data and the encryption key to obtain the encrypted data.
[0011] To achieve the above object, a second aspect of the embodiments of the present application proposes an industrial message receiving method for a C2F application transmission system. The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device, and a receiving station connected in sequence. The method is applied to the receiving conversion device, and the method includes: Obtaining the IP - encrypted message data transmitted by the sending station through the sending conversion device and the IP network, and obtaining the message data characteristics; Based on the register configuration of the receiving conversion device, performing IP message de - encapsulation on the IP - encrypted message data to obtain encrypted message data; Obtaining the real - time network characteristics of the IP network at the sending moment from the encrypted message data; Based on the message data characteristics and the real - time network characteristics, performing decryption processing on the encrypted message data to obtain the C2F application industrial message data, and forwarding the C2F application industrial message data to the receiving station.
[0012] To achieve the above object, a third aspect of the embodiments of the present application provides an industrial message sending device for a C2F application transmission system. The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device, and a receiving station that are connected in sequence. The device is applied to the sending conversion device and includes: A message data acquisition module for acquiring C2F application industrial message data input by the sending station; An encryption processing module for encrypting the C2F application industrial message data based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network to obtain encrypted message data; A format conversion module for performing IP message encapsulation on the encrypted message data based on the register configuration of the receiving conversion device to obtain IP encrypted message data; A data sending module for sending the IP encrypted message data to the receiving conversion device through the IP network so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
[0013] To achieve the above object, a fourth aspect of the embodiments of the present application provides an electronic device. The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the industrial message sending method of the C2F application transmission system as described in the first aspect or the industrial message receiving method of the C2F application transmission system as described in the second aspect.
[0014] To achieve the above object, a fifth aspect of the embodiments of the present application provides a storage medium. The storage medium is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the industrial message sending method of the C2F application transmission system as described in the first aspect or the industrial message receiving method of the C2F application transmission system as described in the second aspect.
[0015] The industrial message sending method, receiving method and related devices of the C2F application transmission system proposed in the embodiments of the present application. The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device and a receiving station connected in sequence. The method is applied to the sending conversion device and includes: First, obtain the C2F application industrial message data input by the sending station; Next, based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network, encrypt the C2F application industrial message data to obtain encrypted message data; Then, based on the register configuration of the receiving conversion device, perform IP message encapsulation on the encrypted message data to obtain IP encrypted message data; Finally, send the IP encrypted message data to the receiving conversion device through the IP network, so that the receiving conversion device forwards the C2F application industrial message data to the receiving station. In the embodiments of the present application, a sending conversion device and a receiving conversion device are provided between the master station and the slave station, or between the slave stations, so as to use the sending conversion device to perform IP message encapsulation on the industrial message data of the C2F application, so as to convert the data format from the EtherCAT data format to the IP data format suitable for transmission in the IP network, so as to transmit the industrial message data between the sending station and the receiving station through the IP network, so as to improve the transmission flexibility of the C2F application industrial message data; In addition, before transmission, the C2F application industrial message data is encrypted by using the two random characteristics of the message data characteristics of the C2F application industrial message data and the current real-time network characteristics of the IP network, which greatly avoids the possibility of being stolen during the data transmission process, and thus improves the transmission flexibility of the C2F application industrial message data while also improving the security of data transmission.
[0016] Other features and advantages of the present application will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the specification, claims and drawings. Brief Description of the Drawings
[0017] Figure 1 It is a diagram of the data transmission architecture of the master and slave stations in a C2F application provided by an embodiment of the present application.
[0018] Figure 2 It is a schematic diagram of the structure of EtherCAT data provided by another embodiment of the present application.
[0019] Figure 3 It is a schematic diagram of the message information of EtherCAT data provided by another embodiment of the present application.
[0020] Figure 4It is a schematic diagram of remote transmission of master and slave devices for EtherCAT data provided by another embodiment of the present application.
[0021] Figure 5 It is a schematic structural diagram of a C2F application transmission system provided by another embodiment of the present application.
[0022] Figure 6 It is a schematic structural diagram of a conversion device provided by another embodiment of the present application.
[0023] Figure 7 It is a flowchart of a method for sending industrial messages in a C2F application transmission system provided by another embodiment of the present application.
[0024] Figure 8 It is Figure 7 a flowchart of step 702 in
[0025] Figure 9 It is Figure 8 a flowchart of step 801 in
[0026] Figure 10 It is Figure 8 a flowchart of step 802 in
[0027] Figure 11 It is Figure 10 a flowchart of step 1003 in
[0028] Figure 12 It is Figure 7 a flowchart of step 703 in
[0029] Figure 13 It is a schematic diagram of the protocol number in IP encrypted message data provided by another embodiment of the present application.
[0030] Figure 14 It is a schematic flowchart of industrial message data sending and processing provided by another embodiment of the present application.
[0031] Figure 15 It is a flowchart of a method for receiving industrial messages in a C2F application transmission system provided by another embodiment of the present application.
[0032] Figure 16 It is a schematic flowchart of industrial message data receiving and processing provided by another embodiment of the present application.
[0033] Figure 17 It is a flowchart of processing C2F application industrial message data provided by another embodiment of the present application.
[0034] Figure 18It is a schematic structural diagram of an industrial message sending device of a C2F application transmission system provided by another embodiment of the present application.
[0035] Figure 19 It is a schematic hardware structure diagram of an electronic device provided by another embodiment of the present application. Detailed implementation manners
[0036] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0037] It should be noted that although functional module division is performed in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order from the module division in the device or the order in the flowchart.
[0038] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0039] With the development of society, a new business model of C2F (customer to factory) has emerged. The C2F model eliminates intermediate links by directly connecting consumers and manufacturers, thereby improving efficiency, reducing costs, and providing more personalized customization services. This model is becoming increasingly popular in modern manufacturing, especially in the fields of customized production and intelligent manufacturing. The two core concepts of C2F are "unmanned" and "production capacity release". To achieve "unmanned", the factory must implement precise and rapid automation control of factory equipment. Therefore, a large number of automation devices such as programmable logic controllers (PLCs), robotic arms, and vision inspection systems are widely used inside the factory.
[0040] In this mode, customers can directly place orders through a digital platform, and the factory produces and delivers according to the order requirements. It eliminates intermediate links by directly connecting consumers and manufacturers, thereby improving efficiency, reducing costs, and providing more personalized customization services. In the C2F mode, the factory needs to respond to consumers' order requirements in real time and be able to quickly adjust the production line to meet personalized needs. This requires not only an efficient production process in the factory, but also a powerful and flexible hardware infrastructure to support high-speed data transmission and processing.
[0041] In the related art, in the C2F mode, the information layer switch at the factory end needs to transmit a large amount of C2F application data streams of various industrial devices and business management systems. The mainstream communication protocol for these data streams is EtherCAT. Among them, EtherCAT (Ethernet for control Automation) is an open real-time Ethernet technology, which was first developed by Beckhoff. EtherCAT has set a new standard for the real-time performance and topological flexibility of applications. The EtherCAT network has excellent performance, a flexible network topology, simple system configuration, and is as intuitive and easy to operate as a fieldbus system. In addition, due to the low implementation cost of EtherCAT, the system can be selected in occasions where fieldbus networks could not be applied in the past. For these reasons, EtherCAT is widely used in industrial scenarios such as robots, machine tools, packaging machinery, power plants, steel mills, sawmills, etc.
[0042] Referring to Figure 1 , it is a master-slave station data transmission architecture diagram in a C2F application provided by an embodiment of the present application. As Figure 1 shown, at the factory end, a master-slave transmission structure is usually adopted based on the EtherCAT protocol, where a master station is responsible for controlling and synchronizing slave stations in the network. The master station sends control commands and data, and the slave stations receive and execute these commands. The EtherCAT network can support up to 1000 slave stations, and each slave station has its own network address and unique identifier. Through EtherCAT, slave stations can transmit input and output signals in real time, such as sensor data, actuator status, and control commands.
[0043] Figure 2 It is a schematic diagram of the structure of EtherCAT data provided by an embodiment of the present application. As Figure 2 shown, it shows the detailed structure of the EtherCAT message format, including an Ethernet frame header and an EtherCAT data area. The Ethernet frame header consists of a 6-byte destination address, a 6-byte source address, and a 2-byte frame type (0x88A4). Following that is the EtherCAT header, which contains an 11-bit EtherCAT data length, a 1-bit reserved bit, 4-bit type and sub-message. The EtherCAT data area consists of one or more sub-messages, each sub-message including a 10-byte sub-message header and up to 1486 bytes of data. The sub-message header is further divided into an 8-bit command, an 8-bit index, a 32-bit address area, an 11-bit length, a 4-bit R bit, a 1-bit M bit, and a 16-bit status bit, as well as a 2-byte WKC (working count). The entire message ends with a 6-byte FCS (frame check sequence).
[0044] Figure 3 It is a schematic diagram of the message information of EtherCAT data provided by an embodiment of the present application. As Figure 3 shown, it provides the names and meanings of each field in the EtherCAT message domain. Figure 3 Six fields are listed: destination address (receiver MAC address), source address (sender MAC address), frame type (0x88A4), data length in the EtherCAT header (indicating the length of the EtherCAT data area, that is, the total length of all sub-messages), type in the EtherCAT header (where 1 indicates communication with the slave station, and the rest of the values are reserved), and FCS (Frame Check Sequence). These fields together constitute the structure of the EtherCAT message, which is used to ensure the accuracy and integrity of data transmission.
[0045] The industrial production control rooms of traditional factories are divided into three levels, namely the on-site operation room, the dispatching room in the factory headquarters, and the general dispatching room in the base. Among them, the operation room is at the on-site production front line. The on-site operation environments in many industries such as chemical engineering and metallurgy are harsh or dangerous. Implementing the remote centralized control mode to achieve less or no personnel on-site operation has become a trend. However, the existing industrial control systems generally adopt local area network architectures such as industrial Ethernet and industrial bus, which cannot meet the requirements of remote centralized control.
[0046] Refer to Figure 4 , it is a schematic diagram of the remote transmission of the master and slave devices of EtherCAT data provided by an embodiment of the present application. As Figure 4 shown, since only EtherCAT type data can be transmitted between the master station and the slave station, and between the slave stations under the EtherCAT protocol, and remote data transmission cannot be carried out using the IP network, the set distance between the master station and the slave station, and between the slave stations cannot be too far. As a result, the transmission flexibility of the existing C2F application data is poor, making long-distance data transmission impossible.
[0047] To improve the transmission flexibility of industrial data in the C2F application, in the embodiments of the present application, a sending conversion device and a receiving conversion device are provided between the master station and the slave station, or between the slave stations, so as to use the sending conversion device to encapsulate the industrial message data of the C2F application into IP messages, convert the data format from the EtherCAT data format to the IP data format suitable for transmission in the IP network, and thus transmit the industrial message data between the sending station and the receiving station through the IP network to improve the transmission flexibility of the industrial message data in the C2F application; in addition, before transmission, the industrial message data of the C2F application is encrypted using two random features, namely, the message data features of the industrial message data of the C2F application and the current real-time network features of the IP network, which greatly avoids the possibility of being stolen during data transmission, and further improves the security in data transmission while improving the transmission flexibility of the industrial message data in the C2F application.
[0048] The industrial message sending method, receiving method and related devices of the C2F application transmission system provided by the embodiments of the present application will be further described below. First, the C2F application transmission system provided by the embodiments of the present application will be described. Refer to Figure 5 , which is a schematic structural diagram of a C2F application transmission system provided by the embodiments of the present application. As Figure 5 shown, in the C2F application transmission system, a sending station, a sending conversion device, a receiving conversion device and a receiving station are sequentially connected. The method is applied to the sending conversion device. The sending station can be an EtherCAT master station or an EtherCAT slave station as shown in Figure 1 ; similarly, the receiving station can also be an EtherCAT master station or an EtherCAT slave station as shown in Figure 1 ; then, a sending conversion device and a receiving conversion device are provided between the sending station and the receiving station. These two conversion devices are used to convert the EtherCAT type data sent by the sending station into IP type data that can be transmitted in the IP network, and convert the IP type data into EtherCAT type data.
[0049] Refer to Figure 6 , which is a schematic structural diagram of a conversion device provided by the embodiments of the present application. As Figure 6As shown in , the conversion device includes: Ethernet interface (including Ethernet interface 1 and Ethernet interface 2), which is used to realize the sending and receiving of Ethernet messages. It receives messages from EtherCAT master / slave stations or IP network devices and sends messages to the other party; bus, which is the interconnection module of various modules in the whole system, which can be AXI4 bus interface; DDR controller, DDR PHY realizes the conversion of bus timing to DDR interface timing, and DDR is used to store messages; protocol conversion (including protocol conversion 1 and protocol conversion 2), adds IP message header to the encrypted EtherCAT message, and then adds Ethernet header to form a complete Ethernet frame; encryption module, encrypts the received EtherCAT message to obtain ciphertext, and can use AES (Advanced Encryption Standard) encryption algorithm; decryption module: decrypts the received ciphertext to obtain the original EtherCAT message. The AES decryption algorithm can also be used; the CPU is responsible for register configuration and software execution; the registers are used to configure encryption and decryption keys, the destination and source IP addresses in the IP message header, the protocol number in the IP header, etc.; other interfaces include the serial port for debugging, the I2C interface of the temperature sensor, etc.
[0050] Based on the above-mentioned C2F application transmission system, the industrial message sending method of the C2F application transmission system in the embodiment of the present application will be described in detail below. Figure 7 , which is an optional flowchart of the industrial message sending method of the C2F application transmission system provided in the embodiment of the present application, Figure 7 The method in the embodiment may include but is not limited to steps 701 to 704. Figure 7 The order of step 701 to step 704 is not specifically limited, and the order of steps can be adjusted or some steps can be reduced or added according to actual needs. The industrial message sending method of the C2F application transmission system provided in the embodiment of the present application can be applied to the sending conversion device in the C2F application transmission system.
[0051] Step 701: Acquire C2F application industrial message data input by a sending station.
[0052] The following is a detailed description of step 701.
[0053] At the factory side in the C2F scenario, in response to the sending request of the C2F application industrial message data sent by the sending station to the receiving station, the sending conversion device first receives the C2F application industrial message data of the EtherCAT protocol type, so as to facilitate the subsequent encryption processing and data type conversion of the C2F application industrial message data, so that the C2F application industrial message data can be remotely transmitted through the IP network while ensuring the security of data transmission.
[0054] In addition, the sending conversion device also parses the C2F application industrial message data to extract message data features, such as extracting the command type (Command field): 0x01 (write operation), 0x04 (read operation), etc.; extracting the device identifier: the master station MAC address (MAC_master), the target slave station address (32-bit logical address); extracting the data field: control instructions (such as motion parameters) or sensor status data, etc.
[0055] Step 702: Based on the message data features of the C2F application industrial message data and the real-time network features of the IP network, encrypt the C2F application industrial message data to obtain encrypted message data.
[0056] The following details step 702.
[0057] In some embodiments, when obtaining the input C2F application industrial message data, it is also necessary to extract the network features of the connected IP network to extract the real-time network features of the IP network corresponding to the message data sending moment. The real-time network features include delay value, jitter value, bandwidth utilization rate, packet loss rate, throughput, etc.
[0058] Next, using these two random feature data, namely the message data features of the C2F application industrial message data and the real-time network features of the IP network, perform more random encryption processing on the C2F application industrial message data, thereby effectively improving the security during the data transmission process of the C2F application industrial message data. How to perform the encryption processing of the industrial message data will be further described below.
[0059] Refer to Figure 8 , based on the message data features of the C2F application industrial message data and the real-time network features of the IP network, encrypt the C2F application industrial message data to obtain encrypted message data, including the following steps 801 to step 803.
[0060] Step 801: Generate an encryption key based on the message data features and the real-time network features.
[0061] The following details step 801.
[0062] In some embodiments, after obtaining these two random feature data, namely the message data features of the C2F application industrial message data and the real-time network features of the IP network, use these two random feature data to generate an encryption key with a relatively large randomness, so that when the C2F application industrial message data is encrypted using this encryption key subsequently, the security of the data can be effectively improved. How to generate an encryption key based on the message data features and the real-time network features will be further described below.
[0063] Refer to Figure 9 , an encryption key is generated based on the message data characteristics and real-time network characteristics, including the following steps 901 to 904.
[0064] Step 901: Generate an initial key through hash processing based on the register configuration.
[0065] Step 902: Perform normalization splicing processing on the message data characteristics and real-time network characteristics to generate a dynamic factor.
[0066] Step 903: Generate a dynamic key through hash processing based on the dynamic factor.
[0067] Step 904: Perform exclusive-or confusion processing on the dynamic key and the initial key to generate an encryption key.
[0068] The following is a detailed description of steps 901 to 904.
[0069] In some embodiments, first, hash processing is performed based on the information in the register configuration of the receiving conversion device to generate a corresponding hash value, and this hash value is used as a fixed initial key.
[0070] It can be understood that the information in the register configuration of the receiving conversion device mainly includes: DEC_KEY[0-3] (stores a 256-bit dynamic decryption key, which is synchronized and updated with the sending end), IP_SRC_MAP (the mapping table address from the source IP to the EtherCAT master MAC, used to restore the broadcast address), IP_PROTOCOL_FILTER (protocol number filter mask, only processes specified encrypted messages), GCM_TAG_THRESH (authentication tag tolerance threshold, discards messages exceeding the limit), CYCLE_COUNTER_SYNC (cycle counter synchronization value, aligns with the master station timing), NET_JITTER_MAX (maximum allowed network jitter, triggers redundant fault tolerance), and CRC_CHECK_EN (CRC check enable), etc.
[0071] In addition, the hash function used for hash processing can be a general hash function, such as MD5, SHA series, etc.
[0072] Next, perform numerical normalization processing on the relevant data in the message data characteristics and real-time network characteristics to map all these data to the same numerical range. For example, if the delay t ∈ [0, 255], then the delay t is normalized to t / 255, and the processing of the remaining data is similar to this.
[0073] Then, all the normalized feature data are concatenated to obtain a vector containing all the feature data, and this vector is used as the dynamic factor. Then, the dynamic factor is hashed using a hash function to obtain a dynamic key with the same format as the initial key but different values.
[0074] After that, the dynamic key and the initial key are subjected to XOR confusion processing (i.e., XOR operation), and then the first 256 bits are intercepted as the encryption key.
[0075] Through the above steps 901 to 904, dynamic keys with strong randomness are generated using the message feature data unique to each C2F application industrial message data and the real-time network features that are time-varying and random in the IP network, and the fixed initial key is subjected to XOR confusion processing using the dynamic keys with strong randomness, further improving the randomness of the generated encryption key, thereby greatly enhancing the security of the subsequent transmission of the C2F application industrial message data encrypted using this encryption key.
[0076] Step 802: Encrypt the C2F application industrial message data based on the encryption key to generate encrypted data and corresponding authentication tags.
[0077] Step 803: Generate encrypted message data based on the combination of the encrypted data, the authentication tags, and the real-time network features.
[0078] The following provides a detailed description of steps 802 to 803.
[0079] In some embodiments, after generating an encryption key with strong confidentiality using the message feature data with high randomness and the real-time network features, the C2F application industrial message data is further encrypted using this encryption key to obtain highly secure encrypted data and corresponding authentication tags. Then, the encrypted data and the corresponding authentication tags are combined as the encrypted message data for transmission. After the data is transmitted to the receiving conversion device through the IP network, the receiving conversion device can use the authentication tags to decrypt the encrypted data to obtain the corresponding C2F application industrial message data.
[0080] The following will further describe how to encrypt the C2F application industrial message data using the encryption key.
[0081] Refer to Figure 10 , encrypting the C2F application industrial message data based on the encryption key to generate encrypted data and corresponding authentication tags includes the following steps 1001 to 1004.
[0082] Step 1001: Obtain the non-linear mapping table and generate the dislocation processing identifier.
[0083] Step 1002: Based on the non-linear mapping table, perform non-linear substitution on each byte in the industrial message data of C2F to generate non-linear message data.
[0084] Step 1003: Based on the dislocation processing identifier and the encryption key, perform dislocation encryption processing on the non-linear message data to obtain encrypted data.
[0085] Step 1004: Generate an authentication tag based on the mapping table identifier and the dislocation processing identifier of the non-linear mapping table.
[0086] The following gives a detailed description of Steps 1001 to 1004.
[0087] In some embodiments, after obtaining the encryption key, determine the non-linear mapping table and the dislocation processing identifier corresponding to the current encryption process. The non-linear mapping table is an S-Box (a multi-order lookup table), which contains the non-linear mapping relationships of multiple character data. The dislocation processing identifier includes a row shift identifier and a column shift identifier. The row shift identifier includes the target rows corresponding to multiple row transformation processes and the corresponding processing methods. The column shift identifier includes the target columns corresponding to multiple column transformation processes and the corresponding processing methods.
[0088] Next, based on the non-linear mapping table, perform non-linear substitution on each byte in the industrial message data of C2F to generate non-linear message data. When using an FPGA in the conversion device, the S-Box module can be used in parallel to perform parallel acceleration processing on this non-linear substitution process.
[0089] After performing the non-linear substitution processing, further perform dislocation encryption processing on the non-linear message data based on the dislocation processing identifier and the encryption key to obtain encrypted data, which is described in detail as follows.
[0090] Refer to Figure 11 , based on the dislocation processing identifier and the encryption key, perform dislocation encryption processing on the non-linear message data to obtain encrypted data, including the following Steps 1101 to 1103.
[0091] Step 1101: Select target row data from the non-linear message data based on the row shift identifier and perform row shift to obtain the first shifted data.
[0092] Step 1102: Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain the second shifted data.
[0093] Step 1103: Perform exclusive OR processing on the second shifted data and the encryption key to obtain encrypted data.
[0094] The following provides a detailed description of steps 1101 to 1103.
[0095] In some embodiments, after obtaining the dislocation processing identifier, the encryption key, and the non-linear message data, first, based on the row shift identifier in the dislocation processing identifier, target row data is selected from the non-linear message data for row shifting to obtain the first shifted data. For example, the first row of the non-linear message data is shifted left by 1 byte, the second row is shifted right by 2 bytes, and so on.
[0096] Next, the mixing matrix corresponding to the column shift identifier in the dislocation processing identifier is obtained. Then, based on the column shift identifier, target column data is selected from the first shifted data. Then, matrix multiplication is performed on the target column data and the mixing matrix to obtain the second shifted data. Finally, the obtained second shifted data and the encryption key are subjected to an XOR confusion process (XOR operation) again to obtain encrypted data with strong randomness and confidentiality.
[0097] Finally, the mapping table identifier and the dislocation processing identifier (including the row transformation identifier and the column transformation identifier) in the non-linear mapping table are combined to generate an authentication tag, so that when the subsequent receiving conversion device receives the encrypted data, it can use the authentication tag to perform corresponding decryption processing on the encrypted data.
[0098] Through the above steps 1001 to 1004, and steps 1101 to 1103, through the synergistic effect of the dynamic non-linear confusion and multi-level diffusion mechanism, the security of the C2F industrial message is significantly improved. Byte substitution based on the non-linear mapping table is used to destroy the statistical characteristics of the message data to resist side-channel attacks based on pattern analysis. Dynamic row shifting and mixing matrix operations are used to introduce a spatial diffusion effect. A single-byte modification will trigger a chain change of multiple columns of data, effectively suppressing differential attacks. Combining the confusion parameters of the dynamic identifiers (row shift identifier, column mixing identifier), a dynamic encryption strategy of "one message, one key" is realized. Even if the key is leaked, it is still impossible to reverse-derive historical messages. Then, by using the authentication tag to generate a deep integration of the non-linear mapping table features and the dislocation identifier, data integrity protection and traceability of the encryption process are synchronously realized, preventing replay attacks and man-in-the-middle tampering.
[0099] After obtaining the encrypted data and the corresponding authentication tag, the encrypted data, the corresponding authentication tag, and the real-time network characteristics corresponding to the sending time are combined to generate encrypted message data, so that after the encrypted message data is sent to the receiving conversion device, the receiving conversion device can perform corresponding decryption processes on the encrypted data based on the authentication tag and the real-time network characteristics.
[0100] Step 703: Based on the register configuration of the receiving conversion device, perform IP packet encapsulation on the encrypted message data to obtain IP encrypted packet data.
[0101] The following provides a detailed description of step 703.
[0102] In some embodiments, after generating the encrypted message data, IP packet encapsulation is further performed on the encrypted message data based on the information items in the register configuration of the aforementioned receiving conversion device to obtain IP encrypted message data that can be transmitted in the IP network. The conversion process of this message format will be further described below.
[0103] Refer to Figure 12 , based on the register configuration of the receiving conversion device, IP packet encapsulation is performed on the encrypted message data to obtain IP encrypted message data, including the following steps 1201 to 1203.
[0104] Step 1201: Obtain an IPv4 packet header based on the register configuration.
[0105] Step 1202: Obtain the target MAC address of the receiving station and generate an Ethernet frame header based on the target MAC address.
[0106] Step 1203: Add the IPv4 packet header and the Ethernet frame header to the head of the encrypted message data to obtain IP encrypted message data.
[0107] The following provides a detailed description of steps 1201 to 1203.
[0108] In some embodiments, after encrypting the C2F application industrial message data to obtain encrypted message data, the entire encrypted message data is used as the payload of the IPv4 packet. Then, an IPv4 packet header is obtained according to the information in the register configuration, and the target MAC address of the receiving station is determined and used as the Ethernet frame header.
[0109] Next, the IPv4 packet header and the Ethernet frame header are added to the head of the encrypted message data to perform IP packet format conversion to form a new Ethernet packet, that is, IP encrypted message data. Finally, this new packet is sent to the IP network through the second Ethernet interface of the device. Since this packet has an IP header, it can be transmitted within the IP network.
[0110] Refer to Figure 13 , which is a schematic diagram of the protocol number in the IP encrypted message data provided by an embodiment of the present application. As Figure 13 shown in, in order to indicate that the payload of the IP packet is this encrypted EtherCAT packet, the IPv4 packet header includes an idle protocol identification value, that is, a value that is not used can be used for the protocol number in the IPv4 header, such as a value between 147 and 252. This value can be configured through the register.
[0111] Through the above steps 1201 to 1203, through protocol identifier dynamicization and hardware-level encapsulation optimization, seamless compatibility between industrial encrypted messages and standard network protocols is achieved. An IPv4 message header carrying an idle protocol identifier value is generated using register configuration, which not only avoids standard protocol conflicts but also retains the protocol extension ability. Then, based on the target MAC address, an Ethernet frame header is dynamically constructed, and the encrypted data is precisely encapsulated into unicast / multicast frames, avoiding network storms caused by traditional broadcast transmissions. Moreover, the IP message header and Ethernet frame header are used to perform data format conversion on the encrypted message data to obtain IP-encrypted message data in IP format that can be transmitted in the IP network, thereby facilitating subsequent long-distance transmission of the IP-encrypted message data in the IP network and improving the transmission flexibility of C2F application industrial message data.
[0112] Step 704: Send the IP-encrypted message data through the IP network to the receiving conversion device, so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
[0113] The following provides a detailed description of step 704.
[0114] Refer to Figure 14 , which is a schematic flowchart of the industrial message data sending and processing provided by an embodiment of the present application. As shown in Figure 14 , the sending station sends C2F application industrial message data in EtherCAT message format. The sending conversion device receives the C2F application industrial message data, performs encryption processing, and then performs format conversion to obtain IP-encrypted message data in IP message format, and then sends it to the IP network. The IP-encrypted message data is forwarded through the IP network and sent to the receiving conversion device. This device performs format conversion and decryption processing on the IP-encrypted message data to restore the original C2F application industrial message data in EtherCAT message format, and finally sends it to the receiving station. GATE_DMAC is the target MAC address, and GATE_SMAC is the source address.
[0115] In addition, an embodiment of the present application also provides an industrial message receiving method for a C2F application transmission system. Refer to Figure 15 , which is an optional flowchart of the industrial message receiving method for the C2F application transmission system provided by an embodiment of the present application. Figure 15 The method in Figure 15 may include but is not limited to steps 1501 to 1504. At the same time, it can be understood that the order of steps 1501 to 1504 in this embodiment is not specifically limited, and the order of steps can be adjusted according to actual needs, or some steps can be reduced or added. The industrial message sending method for the C2F application transmission system provided in the embodiment of the present application can be applied to the receiving conversion device in the C2F application transmission system.
[0116] Step 1501: Obtain the IP encrypted message data transmitted by the sending station through the sending conversion device and the IP network, and obtain the message data characteristics.
[0117] Step 1502: Based on the register configuration of the receiving conversion device, perform IP message decapsulation on the IP encrypted message data to obtain the encrypted message data.
[0118] Step 1503: Obtain the real-time network characteristics of the IP network at the sending moment from the encrypted message data.
[0119] Step 1504: Perform decryption processing on the encrypted message data based on the message data characteristics and the real-time network characteristics to obtain the C2F application industrial message data, and forward the C2F application industrial message data to the receiving station.
[0120] The following is a detailed description of Steps 1501 to 1504.
[0121] Corresponding to the industrial message sending method of the C2F application transmission system described above, refer to Figure 16 , which is provided by an embodiment of the present application. As Figure 16 shown in , after the receiving conversion device receives the IP encrypted message data transmitted by the sending station through the sending conversion device and the IP network through the IP network, first use the register configuration of the receiving conversion device to perform IP message decapsulation on the IP encrypted message data to remove the IP message header and the Ethernet frame header in the IP encrypted message data, so as to leave the encrypted message data corresponding to the payload.
[0122] Next, generate a highly random encryption key based on the message data characteristics corresponding to the IP encrypted message data and the real-time network characteristics of the IP network in the encrypted message data, and then use the encryption key and the authentication tag in the encrypted message data to perform decryption processing on the encrypted data in the encrypted message data to restore the C2F application industrial message data originally sent by the sending station, and then forward the C2F application industrial message data to the receiving station.
[0123] Refer to Figure 17 , which is a processing flow chart of the C2F application industrial message data provided by an embodiment of the present application. As Figure 17 shown in , this process includes the following steps.
[0124] S01: The Ethernet interface of the sending conversion device receives an Ethernet frame, which may be a message sent by an EtherCAT device or a message sent by an IP network device.
[0125] S02: The sending conversion device performs protocol parsing on the message, and parses out the Ethernet frame header and the IPv4 message header.
[0126] S03: The sending conversion device determines whether the message is an EtherCAT message according to the parsing result in step S02. If it is an EtherCAT frame, it indicates that the device connected to the other end is an EtherCAT device. Judgment method: Check whether the value of the Ethernet type field is equal to 0x88A4. If it is equal, it means it is an EtherCAT message; otherwise, it is not.
[0127] S04: If it is an EtherCAT frame, the sending conversion device encrypts the message through the above-mentioned encryption algorithm to obtain the encrypted ciphertext.
[0128] S05: The sending conversion device uses the ciphertext encrypted in step S04 as the payload of the IP message, and adds the IPV4 message header according to the register configuration information. Note the setting of the protocol field in the IPV4 message header. Use an unused protocol identification value between 147 and 252, and this value can be flexibly configured through the register.
[0129] S06: The sending conversion device adds the Ethernet frame header to the message data. At this time, the destination MAC address added is the MAC address of the IP network device port connected to the protocol conversion device, and this address is not a broadcast address, so it overcomes the defect of the original EtherCAT message broadcast address.
[0130] S07: The sending conversion device sends the complete data frame assembled in step S06 through another Ethernet interface. This network interface is connected to the IP network device.
[0131] S08: After receiving the data frame, the receiving conversion device makes a judgment. If the message is not an EtherCAT message, it indicates that the device connected to the other end of this interface is an IP network device. The sending conversion device continues to judge whether it is an IPV4 message.
[0132] S09: If it is an IPV4 message, the receiving conversion device continues to judge whether the value of the protocol field in the IPV4 header is the specially set value (this value is made configurable through the register). If it is, it means the payload content is the encrypted EtherCAT message.
[0133] S10: The receiving conversion device strips the Ethernet frame header of the message.
[0134] S11: The receiving conversion device strips the IP header of the message to obtain the payload of the IP message. This payload is the encrypted EtherCAT message.
[0135] S12: The receiving conversion device decrypts the ciphertext of the payload, and the decrypted data is the original EtherCAT message.
[0136] S13: The receiving conversion device sends the original EtherCAT message out through another interface.
[0137] S14: If the message is not an IPV4 message or the payload of the IPV4 message is not an encrypted EtherCAT message, the receiving conversion device continues with other processing (for example, if the message is an ARP message, ARP message response processing needs to be done, etc.).
[0138] In summary, through this industrial protocol conversion device, the conversion between EtherCAT messages and IPV4 messages is realized, thus overcoming the defect that existing EtherCAT devices cannot be connected to the IP network. With this solution, existing EtherCAT devices can continue to be used without modification, which not only maximally protects the user's investment but also supports the evolution of the industrial control network, and is of great significance. This is conducive to the realization of the C2F application mode.
[0139] The industrial message sending method, receiving method, and related devices of the C2F application transmission system proposed in the embodiments of this application. The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device, and a receiving station connected in sequence. The method is applied to the sending conversion device and includes: First, obtain the C2F application industrial message data input by the sending station; Next, perform hash processing based on the register configuration to generate an initial key, perform normalization splicing processing on the message data characteristics and real-time network characteristics to generate a dynamic factor, perform hash processing based on the dynamic factor to generate a dynamic key, perform exclusive OR confusion processing on the dynamic key and the initial key to generate an encryption key, obtain the non-linear mapping table and generate a dislocation processing identifier, and based on the non-linear mapping table, perform non-linear substitution on each byte in the C2F application industrial message data to generate non-linear message data. Based on the row shift identifier, select target row data from the non-linear message data for row shift to obtain the first shifted data. Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain the second shifted data. Perform exclusive OR processing on the second shifted data and the encryption key to obtain encrypted data. Generate an authentication tag based on the mapping table identifier and dislocation processing identifier of the non-linear mapping table, and generate encrypted message data based on the encrypted data, authentication tag, and real-time network characteristics combination; Then, based on the register configuration, obtain the IPV4 message header. The IPV4 message header includes an idle protocol identifier value, obtain the target MAC address of the receiving station, and generate an Ethernet frame header based on the target MAC address. Add the IPV4 message header and the Ethernet frame header to the head of the encrypted message data to obtain the IP encrypted message data; Finally, send the IP encrypted message data to the receiving conversion device through the IP network so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
[0140] In the embodiments of the present application, a sending conversion device and a receiving conversion device are provided between the master station and the slave station, or between the slave stations, so as to use the sending conversion device to encapsulate the industrial message data of the C2F application into IP messages, so as to convert the data format from the EtherCAT data format to the IP data format suitable for transmission in the IP network, so that the industrial message data can be transmitted between the sending station and the receiving station through the IP network, so as to improve the transmission flexibility of the industrial message data of the C2F application; in addition, before transmission, the industrial message data of the C2F application is encrypted using two random features, namely, the message data features of the industrial message data of the C2F application and the current real-time network features of the IP network, which greatly avoids the possibility of being stolen during the data transmission process, and further improves the security in data transmission while improving the transmission flexibility of the industrial message data of the C2F application; in addition, the message feature data unique to each industrial message data of the C2F application and the time-varying random real-time network features of the IP network are used to generate a dynamic key with strong randomness, and the fixed initial key is XOR-obfuscated using the dynamic key with strong randomness, further improving the randomness of the generated encryption key, thereby greatly improving the security of subsequent transmission after encrypting the industrial message data of the C2F application using the encryption key; and, through the synergistic effect of the dynamic non-linear obfuscation and multi-level diffusion mechanism, the security of the C2F industrial message is significantly improved. The statistical features of the message data are destroyed by byte substitution based on the non-linear mapping table to resist side-channel attacks based on pattern analysis. The dynamic row shift and mixed matrix operations are used to introduce a spatial diffusion effect, and a single-byte modification will trigger a chain change of multiple-column data, effectively suppressing differential attacks. Combining the obfuscation parameters of the dynamic identifiers (row shift identifier, column mixing identifier), a dynamic encryption strategy of "one message, one key" is realized. Even if the key is leaked, the historical messages cannot be deduced reversely. Then, the authentication tag is used to generate a deep fusion of the non-linear mapping table features and the misalignment identifier, synchronously realizing data integrity protection and traceability of the encryption process, preventing replay attacks and man-in-the-middle tampering; and, through protocol identifier dynamicization and hardware-level encapsulation optimization, seamless compatibility between industrial encrypted messages and standard network protocols is achieved. The IPv4 message header carrying the idle protocol identifier value is generated using register configuration, which not only avoids standard protocol conflicts but also retains the protocol extension ability. Then, based on the target MAC address, the Ethernet frame header is dynamically constructed, and the encrypted data is accurately encapsulated into a unicast / multicast frame, avoiding network storms caused by traditional broadcast transmissions. The IP message header and the Ethernet frame header are used to perform data format conversion on the encrypted message data to obtain the IP-encrypted message data in IP format that can be transmitted in the IP network, so as to facilitate subsequent long-distance transmission of the IP-encrypted message data in the IP network, and further improve the transmission flexibility of the industrial message data of the C2F application.
[0141] The embodiment of the present application also provides an industrial message sending device for a C2F application transmission system, which can implement the industrial message sending method of the above C2F application transmission system. Refer to Figure 18 , the device 1800 includes: A message data acquisition module 1810, configured to acquire C2F application industrial message data input by a sending station; An encryption processing module 1820, configured to encrypt the C2F application industrial message data based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network to obtain encrypted message data; A format conversion module 1830, configured to perform IP message encapsulation on the encrypted message data based on the register configuration of the receiving conversion device to obtain IP encrypted message data; A data sending module 1840, configured to send the IP encrypted message data to the receiving conversion device through the IP network, so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
[0142] In some embodiments, the format conversion module 1830 is further configured to: Obtain an IPv4 message header based on the register configuration, where the IPv4 message header includes an idle protocol identification value; Obtain the target MAC address of the receiving station, and generate an Ethernet frame header based on the target MAC address; Add the IPv4 message header and the Ethernet frame header to the head of the encrypted message data to obtain IP encrypted message data.
[0143] In some embodiments, the encryption processing module 1820 is further configured to: Generate an encryption key based on the message data characteristics and the real-time network characteristics; Encrypt the C2F application industrial message data based on the encryption key to generate encrypted data and a corresponding authentication tag; Generate encrypted message data based on the combination of the encrypted data, the authentication tag, and the real-time network characteristics.
[0144] In some embodiments, the encryption processing module 1820 is further configured to: Perform a hash process based on the register configuration to generate an initial key; Perform a normalization splicing process on the message data characteristics and the real-time network characteristics to generate a dynamic factor; Perform a hash process based on the dynamic factor to generate a dynamic key; Perform an exclusive OR confusion process on the dynamic key and the initial key to generate an encryption key.
[0145] In some embodiments, the encryption processing module 1820 is further configured to: Obtain a non-linear mapping table and generate a misalignment processing identifier; Based on the non-linear mapping table, perform non-linear substitution on each byte in the industrial message data of the C2F application to generate non-linear message data; Based on the misalignment processing identifier and the encryption key, perform misalignment encryption processing on the non-linear message data to obtain encrypted data; Generate an authentication tag based on the mapping table identifier and the misalignment processing identifier of the non-linear mapping table.
[0146] In some embodiments, the encryption processing module 1820 is further configured to: Based on the row shift identifier, select target row data from the non-linear message data for row shift to obtain first shifted data; Obtain the mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform matrix operation on the target column data and the mixing matrix to obtain second shifted data; Perform exclusive OR processing on the second shifted data and the encryption key to obtain encrypted data.
[0147] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, the specific implementation manners of the industrial message sending device of the C2F application transmission system are basically the same as the specific implementation manners of the above-mentioned industrial message sending method of the C2F application transmission system, and will not be elaborated here.
[0148] In the embodiments of the present application, a sending conversion device and a receiving conversion device are provided between the master station and the slave station, or between the slave stations in the industrial message sending device of the C2F application transmission system, so as to use the sending conversion device to encapsulate the industrial message data of the C2F application into IP messages, so as to convert the data format from the EtherCAT data format into an IP data format suitable for transmission in the IP network, so that the industrial message data can be transmitted between the sending station and the receiving station through the IP network, so as to improve the transmission flexibility of the industrial message data of the C2F application; in addition, before transmission, the industrial message data of the C2F application is encrypted using two random features, namely, the message data characteristics of the industrial message data of the C2F application and the current real-time network characteristics of the IP network, which greatly avoids the possibility of being stolen during the data transmission process. Furthermore, while improving the transmission flexibility of the industrial message data of the C2F application, the security of data transmission is also improved; in addition, the message characteristic data that is different for each industrial message data of the C2F application and the time-varying random real-time network characteristics of the IP network are used to generate a dynamic key with strong randomness, and the fixed initial key is XOR-obfuscated using the dynamic key with strong randomness, further improving the randomness of the generated encryption key, thereby greatly improving the security of subsequent transmission after encrypting the industrial message data of the C2F application using the encryption key; and, through the synergistic effect of the dynamic non-linear obfuscation and multi-level diffusion mechanism, the security of the C2F industrial message is significantly improved. The statistical characteristics of the message data are destroyed by byte substitution based on the non-linear mapping table to resist side-channel attacks based on pattern analysis. The dynamic row shift and mixed matrix operation are used to introduce a spatial diffusion effect. A single-byte modification will cause a chain change of multiple-column data, effectively suppressing differential attacks. Combining the obfuscation parameters of the dynamic identifier (row shift identifier, column mixing identifier), a dynamic encryption strategy of "one message, one cipher" is realized. Even if the key is leaked, the historical message cannot be reverse-derived. Then, the authentication tag is used to generate a deep fusion of the non-linear mapping table characteristics and the misalignment identifier, synchronously realizing data integrity protection and the traceability of the encryption process, preventing replay attacks and man-in-the-middle tampering; and, through the dynamicization of the protocol identifier and the optimization of the hardware-level encapsulation, seamless compatibility between the industrial encrypted message and the standard network protocol is realized. The IPv4 message header carrying the idle protocol identifier value is generated by register configuration, which not only avoids standard protocol conflicts but also retains the protocol extension ability. Then, based on the target MAC address, the Ethernet frame header is dynamically constructed, and the encrypted data is accurately encapsulated into a unicast / multicast frame, avoiding network storms caused by traditional broadcast transmission. The IP message header and the Ethernet frame header are used to perform data format conversion on the encrypted message data to obtain the IP-encrypted message data in IP format that can be transmitted in the IP network, so as to facilitate subsequent long-distance transmission of the IP-encrypted message data in the IP network, thereby improving the transmission flexibility of the industrial message data of the C2F application.
[0149] An embodiment of the present application further provides an electronic device, including: At least one memory; At least one processor; At least one program; The program is stored in the memory, and the processor executes the at least one program to implement the industrial message sending method of the C2F application transmission system described above in the embodiments of the present application. The electronic device can be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (Personal Digital Assistant, abbreviated as PDA), an in-vehicle computer, etc.
[0150] Please refer to Figure 19 , Figure 19 which shows the hardware structure of an electronic device in another embodiment. The electronic device includes: A processor 1901, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit, central processor), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application; A memory 1902, which can be implemented in forms such as ROM (Read Only Memory, read-only memory), a static storage device, a dynamic storage device, or RAM (Random Access Memory, random access memory). The memory 1902 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1902 and are called by the processor 1901 to execute the industrial message sending method of the C2F application transmission system of the embodiments of the present application; An input / output interface 1903, which is used to implement information input and output; A communication interface 1904, which is used to implement communication interaction between this device and other devices, and can implement communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.); A bus 1905, which transmits information between various components of the device (such as the processor 1901, the memory 1902, the input / output interface 1903, and the communication interface 1904); Among them, the processor 1901, the memory 1902, the input / output interface 1903, and the communication interface 1904 are communicatively connected to each other inside the device through the bus 1905.
[0151] The embodiment of the present application also provides a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the industrial message sending method of the above C2F application transmission system.
[0152] As a non-transitory computer-readable storage medium, a memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory can optionally include a memory remotely provided relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0153] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0154] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0155] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0156] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0157] In the description of this application and the above-mentioned accompanying drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0158] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist simultaneously. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expression refers to any combination of these items, including any combination of single items (ones) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0159] In several embodiments provided by this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above-mentioned division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical, or other forms.
[0160] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0161] In addition, in each embodiment of the present application, each functional unit can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0162] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. The foregoing storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0163] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, and thus do not limit the scope of rights of the embodiments of the present application. Any modification, equivalent replacement, and improvement made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of rights of the embodiments of the present application.
Claims
1. An industrial message sending method for a C2F application transmission system, characterized in that: The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device and a receiving station connected in sequence, and the method is applied to the sending conversion device, and the method includes: Acquiring C2F application industrial message data input by the sending station; Based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network, the C2F application industrial message data is encrypted to obtain encrypted message data; Based on the register configuration of the receiving conversion device, the encrypted message data is encapsulated into an IP message to obtain the IP encrypted message data; The IP encrypted message data is sent to a receiving conversion device through the IP network, so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
2. The industrial message sending method of the C2F application transmission system according to claim 1, characterized in that: The step of encapsulating the encrypted message data into an IP message based on the register configuration of the receiving conversion device to obtain the IP encrypted message data comprises: Based on the register configuration, an IPv4 message header is obtained, wherein the IPv4 message header includes an idle protocol identification value; Obtaining a target MAC address of the receiving station, and generating an Ethernet frame header based on the target MAC address; The IPV4 message header and the Ethernet frame header are added to the header of the encrypted message data to obtain the IP encrypted message data.
3. The industrial message sending method of the C2F application transmission system according to claim 1 is characterized in that: The method of encrypting the C2F application industrial message data based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network to obtain the encrypted message data includes: Generate an encryption key based on the message data characteristics and the real-time network characteristics; Encrypting the C2F application industrial message data based on the encryption key to generate encrypted data and a corresponding authentication tag; The encrypted message data is generated based on the encrypted data, the authentication tag and the real-time network feature combination.
4. The industrial message sending method of the C2F application transmission system according to claim 3 is characterized in that: The generating an encryption key based on the message data feature and the real-time network feature comprises: Performing hash processing based on the register configuration to generate an initial key; Performing normalization and splicing processing on the message data features and the real-time network features to generate a dynamic factor; Performing hash processing based on the dynamic factor to generate a dynamic key; The dynamic key and the initial key are subjected to XOR confusion processing to generate the encryption key.
5. The industrial message sending method of the C2F application transmission system according to claim 3 is characterized in that: The encrypting the C2F application industrial message data based on the encryption key to generate encrypted data and a corresponding authentication tag includes: Obtaining a nonlinear mapping table and generating a dislocation processing identifier; Based on the nonlinear mapping table, nonlinearly replace each byte in the C2F application industrial message data to generate nonlinear message data; Based on the staggered processing identifier and the encryption key, performing staggered encryption processing on the nonlinear message data to obtain the encrypted data; The authentication tag is generated based on the mapping table identifier of the nonlinear mapping table and the misalignment processing identifier.
6. The industrial message sending method of the C2F application transmission system according to claim 5, characterized in that: The staggered processing identifier includes a row shift identifier and a column mixing identifier, and performing staggered encryption processing on the nonlinear message data based on the staggered processing identifier and the encryption key to obtain the encrypted data includes: Selecting target row data from the nonlinear message data based on the row shift identifier to perform row shift to obtain first shifted data; Acquire a mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform a matrix operation on the target column data and the mixing matrix to obtain second shifted data; The second shifted data is XOR-ed with the encryption key to obtain the encrypted data.
7. An industrial message receiving method for a C2F application transmission system, characterized in that: The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device and a receiving station connected in sequence, and the method is applied to the receiving conversion device, and the method includes: Acquire IP encrypted message data transmitted by the sending station through the sending conversion device and the IP network, and acquire message data characteristics; Based on the register configuration of the receiving conversion device, the IP encrypted message data is decapsulated to obtain the encrypted message data; Acquire the real-time network characteristics of the IP network at the time of sending from the encrypted message data; The encrypted message data is decrypted based on the message data characteristics and the real-time network characteristics to obtain the C2F application industrial message data, and the C2F application industrial message data is forwarded to the receiving station.
8. An industrial message sending device for a C2F application transmission system, characterized in that: The C2F application transmission system includes a sending station, a sending conversion device, a receiving conversion device and a receiving station connected in sequence, and the device is applied to the sending conversion device, and the device includes: A message data acquisition module, used to acquire C2F application industrial message data input by the sending station; An encryption processing module, used for encrypting the C2F application industrial message data based on the message data characteristics of the C2F application industrial message data and the real-time network characteristics of the IP network to obtain encrypted message data; A format conversion module, used for performing IP message encapsulation on the encrypted message data based on the register configuration of the receiving conversion device to obtain IP encrypted message data; The data sending module is used to send the IP encrypted message data to the receiving conversion device through the IP network, so that the receiving conversion device forwards the C2F application industrial message data to the receiving station.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the industrial message sending method of the C2F application transmission system according to any one of claims 1 to 6 or the industrial message receiving method of the C2F application transmission system according to claim 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the industrial message sending method of the C2F application transmission system according to any one of claims 1 to 6 or the industrial message receiving method of the C2F application transmission system according to claim 7 is implemented.
Citation Information
Patent Citations
Intrinsically secure industrial control network's dynamic defense method
CN107065750A
Network data encryption and decryption device and method
CN114666047A
Message processing method and device, electronic equipment and storage medium
CN115065736A
Key generation method and device, electronic equipment and storage medium
CN117527238A
Communication method, device and system, electronic equipment and storage medium
CN119728637A
Cited By
C2F scene-oriented message forwarding method, device, equipment and medium
CN120416134A