Internet of Things equipment dynamic encryption communication method, system and equipment and storage medium
Through the IoT device communication method of dynamic selection encryption algorithm, the problem of adapting to the legal and regulatory needs of different network frequency bands and regions in the prior art is solved, and the effect of data security and energy consumption optimization is achieved, and it is suitable for diversified IoT devices.
Patent Information
- Application Number
- CN202510222062.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-03
AI Technical Summary
The existing IoT device communication modules are difficult to adapt to the needs of laws and regulations in different network frequency bands and regions, resulting in manufacturers needing to customize different hardware and software versions, increasing production costs and reducing product flexibility and maintainability. At the same time, existing encryption technologies ignore the diversity of devices and power consumption differences, making it difficult to intelligently choose suitable encryption algorithms.
A dynamic encryption communication method for IoT devices is proposed. By obtaining the geographical location, network performance indicators and service types of devices, dynamically selecting suitable encryption algorithms to ensure data security and reduce energy consumption. The method includes obtaining security requirements level, congestion level parameters and traffic volume level, integrating this information to select an encryption algorithm, and performing encryption and decryption operations on a cloud server.
It realizes dynamic adjustment of encryption algorithms based on real-time situations to ensure the security and privacy of data transmission, while minimizing energy consumption, improving system efficiency and performance, and adapting to the needs of different markets and equipment types.
Smart Images

Figure CN120090834A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encrypted communication technologies, and particularly to a method, system, device, and storage medium for dynamic encrypted communication of Internet of Things (IoT) devices. Background Art
[0002] With the increasing trend of digitalization and numerical control in global consumer electronics products, various household and commercial electronic products, such as coffee machines, public charging devices, etc., are facing unprecedented digital transformation demands. While realizing intelligent functions, these products must also meet the legal requirements of specific countries or regions during data transmission, especially regulations regarding data encryption. There are significant differences in the legal frameworks for information collection and interaction among different countries and regions. For example, the data transmission encryption requirements for IoT devices in the Americas and Europe are quite different from those in Japan, South Korea, and other regions. This regional legal difference poses a severe challenge to electronics manufacturers, requiring them to adjust and optimize the data transmission encryption strategies of their products according to the specific needs of different markets.
[0003] Existing IoT communication modules, although achieving the function of data transmission to a certain extent, often fall short when facing the diverse global encryption requirements. Traditional communication modules lack the adaptability to different network bands and regional laws and regulations, resulting in manufacturers having to customize different hardware and software versions for different markets when developing and deploying products. This not only increases production costs but also reduces the flexibility and maintainability of the products.
[0004] In addition, existing encryption technologies often ignore the diversity and power consumption differences of IoT devices. IoT devices at different price ranges and models have significant differences in processing capabilities and power consumption requirements. Some high-end devices may have stronger processing capabilities and can support complex encryption algorithms, while some low-end devices may not be able to adopt high-level encryption strategies due to power consumption limitations. Therefore, how to intelligently select a suitable encryption algorithm according to the actual performance and power consumption requirements of the device has become an urgent problem to be solved.
[0005] In view of this, this application proposes a method, system, device, and storage medium for dynamic encrypted communication of IoT devices, which can dynamically adjust the encryption algorithm according to real-time situations to minimize energy consumption while ensuring data security and improve the efficiency and performance of the system. Summary of the Invention
[0006] To solve the problems such as the difficulty for existing IoT devices to adaptively select encryption methods, this application provides a method, system, device, and storage medium for dynamic encrypted communication of IoT devices to solve the above technical defect problems.
[0007] A method for dynamically encrypting communication of Internet of Things devices is proposed according to the first aspect of the present application. The method includes the following steps:
[0008] S1. Obtain the current geographical location information of the Internet of Things device, and determine the security requirement level of the Internet of Things device according to the current geographical location information and a preset list of geographical locations with different security levels;
[0009] S2. Obtain the network performance indicators of the mobile network sharing channel at the location where the Internet of Things device is located, and determine the congestion degree parameter of the surrounding network environment according to the network performance indicators;
[0010] S3. Classify according to the service type of the Internet of Things device to obtain the traffic volume level;
[0011] S4. Comprehensively obtain the security requirement level, congestion degree parameter and traffic volume level, dynamically select the corresponding encryption algorithm to encrypt the sensitive data of the Internet of Things device, and transmit the encrypted data to the cloud server.
[0012] Preferably, a method for dynamically encrypting communication of Internet of Things devices proposed by the present application further includes:
[0013] The Internet of Things device initializes the encryption chip, and the encryption chip generates an asymmetric key pair, which includes a public key and a private key. The public key is sent to the cloud server for registration, and the private key is stored in the encryption chip;
[0014] The Internet of Things device communicates with the cloud server, and performs identity authentication through the public key and identity confirmation through the private key.
[0015] Preferably, in step S1, obtaining the current geographical location information of the Internet of Things device and determining the security requirement level of the Internet of Things device according to the current geographical location information and a preset list of geographical locations with different security levels specifically includes:
[0016] Obtain the country parameter information through the location update process of the LTE modem, compare the country parameter information with the preset low-security geographical list, medium-security geographical list or high-security geographical list, and determine the security requirement level of the Internet of Things device at the current location.
[0017] Further preferably, in step S1, it further includes:
[0018] In response to determining that the current geographical location information cannot be obtained through the LTE modem, obtain the latitude and longitude information in the NMEA protocol data format through the GPS or Beidou system;
[0019] According to the latitude and longitude information, query the corresponding country, province and city names in the Geojson map library;
[0020] Compare the queried national, provincial, and city names with the longitude and latitude ranges of the preset low-security geographical list, medium-security geographical list, or high-security geographical list to determine the security requirement level of the Internet of Things device at the current location.
[0021] Preferably, in step S2, obtain the network performance indicators of the mobile network shared channel where the Internet of Things device is located, and determine the congestion degree parameter of the surrounding network environment according to the network performance indicators, specifically including:
[0022] Obtain the network performance indicators of the mobile network shared channel where the Internet of Things device is located, and obtain the congestion degree parameter value by comparing the network performance indicators with the preset threshold, where the network performance indicators include: acquisition probability, system information block parameter, and reference signal received power.
[0023] Preferably, in step S3, divide the traffic volume into at least two traffic volume levels according to the service type of the Internet of Things device, and the service types include: device operation status heartbeat packet download, OTA basic packet download, full packet download, and emergency patch download.
[0024] Preferably, an Internet of Things device dynamic encryption communication method proposed in this application further includes: determining the traffic volume level according to the service type of the Internet of Things device, and the traffic volume levels include: high-secrecy service, emergency service, high traffic volume, and low traffic volume;
[0025] If the traffic volume level is a high-secrecy service, directly encrypt the data using a secure encryption algorithm;
[0026] If the traffic volume level is an emergency service, perform traffic services according to the minimum encryption communication requirements of the geographical location information where the Internet of Things device is located;
[0027] If the traffic volume level is high traffic volume, calculate the processing time required to use a high-secrecy encryption algorithm or a low-secrecy encryption algorithm, and further calculate the upload and download time of the service based on the transmission rate that the current channel environment can provide;
[0028] If the service can complete upload or download within the preset time limit, further judge the congestion degree parameter of the current channel:
[0029] If the congestion degree parameter is high, use the high-secrecy encryption algorithm preset corresponding to the current geographical location information;
[0030] If the congestion degree parameter is low, use the low-secrecy encryption algorithm preset corresponding to the current geographical location information;
[0031] If the traffic volume level is low, a probability threshold p is calculated based on the signal congestion degree, the number of data retransmissions, and the transmission rate information allocated by the base station within the previous time window period. A uniformly distributed random number a is generated, and the encryption algorithm is selected according to the following rules:
[0032] If the random number a is less than the probability threshold p, a high-level encryption algorithm corresponding to the current geographical location information is used;
[0033] If the random number a is not less than the probability threshold p, a low-level encryption algorithm corresponding to the current geographical location information is used.
[0034] It should be understood that in an emergency, the system will give priority to the real-time performance and reliability of communication rather than the encryption strength. However, this does not mean that encryption is not used. Emergency services will adopt lightweight or fast encryption algorithms to ensure basic security. Such as AES-128 or ChaCha20, these algorithms can provide fast encryption and decryption operations in resource-constrained environments while ensuring a certain level of security, minimizing the time overhead of encryption processing.
[0035] In a second aspect, the present application proposes an Internet of Things device dynamic encryption communication system, which includes:
[0036] A security requirement level acquisition module, configured to obtain the current geographical location information of the Internet of Things device, and determine the security requirement level of the Internet of Things device according to the current geographical location information and a preset list of geographical locations with different security levels;
[0037] A congestion degree parameter acquisition module, configured to obtain the network performance indicators of the mobile network shared channel where the Internet of Things device is located, and determine the congestion degree parameter of the surrounding network environment according to the network performance indicators;
[0038] A traffic volume level acquisition module, configured to classify according to the service type of the Internet of Things device to obtain the traffic volume level;
[0039] A dynamic encryption module, configured to comprehensively obtain the security requirement level, the congestion degree parameter, and the traffic volume level, dynamically select the corresponding encryption algorithm to encrypt the sensitive data of the Internet of Things device, and transmit the encrypted data to the cloud server.
[0040] In a third aspect, the present application proposes a terminal device, including a processor, a memory, and a computer program stored in the memory. The computer program is executed by the processor to implement the Internet of Things device dynamic encryption communication method as described in any one of the above.
[0041] Fourthly, the present application proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the IoT device dynamic encryption communication method as described in any one of the above.
[0042] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0043] (1) Dynamic encryption strategy enhances security: The present invention can intelligently select an encryption algorithm according to the geographical location, network environment, and traffic volume level of IoT devices. This strategy not only effectively protects the privacy and sensitivity of data, preventing unauthorized access and data leakage, but also flexibly adjusts the encryption strength according to actual needs, ensuring the security of data transmission throughout the process.
[0044] (2) Energy efficiency optimization and cost savings: By dynamically selecting an encryption algorithm, the present invention can minimize energy consumption while ensuring data security. This feature is particularly important for power-sensitive IoT devices. In addition, the intelligent selection of encryption algorithms also avoids unnecessary resource consumption and reduces the operating costs of enterprises.
[0045] (3) Easy integration and expansion: The modular design of the present invention makes it easy to integrate into various IoT devices. Whether it is a household coffee machine or a cross-border shipping container, the data encryption function can be easily implemented. At the same time, the system has good scalability and can be flexibly adjusted as the business needs grow, meeting the future scalability requirements of enterprise users.
[0046] (4) Compliance and legal compliance: In response to different laws and regulations on data transmission encryption in different countries and regions, the present invention provides a flexible solution. By intelligently identifying the geographical location and selecting the corresponding encryption algorithm, it ensures the compliance operation of enterprises globally and avoids potential risks caused by legal compliance issues.
[0047] (5) Self-learning and optimization ability: The present invention also has the ability of self-learning and optimization, which can continuously observe the security requirements and device power consumption at different locations and make dynamic adjustments based on this information. This ability enables the system to continuously optimize its security and energy efficiency, thus better adapting to the changing environment and requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objectives, and advantages of the present application will become more apparent:
[0049] Figure 1 is a flowchart of the IoT device dynamic encryption communication method according to the present application;
[0050] Figure 2 Schematic diagram of the security communication implementation process according to an embodiment of the present application;
[0051] Figure 3 Schematic diagram of the encryption algorithm selection process according to an embodiment of the present application;
[0052] Figure 4 Schematic diagram of the encryption algorithm selection logic according to an embodiment of the present application;
[0053] Figure 5 Data simulation and actual measurement results graph for each encryption algorithm of the 608 encryption chip;
[0054] Figure 6 Structural diagram of the Internet of Things device dynamic encryption communication system according to the present application;
[0055] Figure 7 Structural schematic diagram of the computer system of the electronic device suitable for implementing the embodiments of the present application. Detailed implementation manners
[0056] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the convenience of description, only parts related to the relevant invention are shown in the drawings.
[0057] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.
[0058] Figure 1 The flowchart of the Internet of Things device dynamic encryption communication method of the present application is shown, as Figure 1 shown, the method includes the following steps:
[0059] S1. Obtain the current geographical location information of the Internet of Things device, and determine the security requirement level of the Internet of Things device according to the current geographical location information and the preset geographical location list of different security levels.
[0060] S2. Obtain the network performance indicators of the mobile network shared channel where the Internet of Things device is located, and determine the congestion degree parameter of the surrounding network environment according to the network performance indicators.
[0061] S3. Classify according to the service type of the Internet of Things device to obtain the traffic volume level.
[0062] S4. Based on the comprehensively obtained security requirement level, congestion degree parameter, and traffic volume level, dynamically select the corresponding encryption algorithm to encrypt the sensitive data of the IoT device, and transmit the encrypted data to the cloud server.
[0063] Figure 2 The schematic diagram of the security communication implementation process of an embodiment of the present application is shown. As Figure 2 shown, the communication connection between the IoT device and the server is achieved through the following steps:
[0064] 1) Device initialization: The IoT device initializes the encryption chip, and a pair of asymmetric keys (public key and private key) are generated inside the chip.
[0065] 2) Key management: The public key is sent to the cloud server for registration, and the private key is securely stored inside the chip without being exposed externally.
[0066] 3) Network connection: The 4G module connects to the 4G network to establish a reliable network connection.
[0067] 4) TLS handshake: The device conducts a TLS handshake process with the cloud server through the 4G module. During this process, the device uses the public key provided by the chip for identity authentication, and the private key is used for signing to prove the legitimacy of the identity.
[0068] 5) Data encryption: Before sending sensitive data, the IoT device encrypts the data using the encryption chip.
[0069] 6) Secure transmission: The encrypted data is transmitted to the cloud server through the 4G module in a secure TLS tunnel.
[0070] 7) Data decryption: After receiving the data, the cloud server decrypts the data using the corresponding public key. This process ensures that the data transmission from the device to the cloud is encrypted and securely authenticated throughout the whole process, greatly enhancing the security of data transmission.
[0071] Figure 3 The schematic diagram of the encryption algorithm selection process of an embodiment of the present application is shown. As Figure 3 shown, during the LTE connection process, the signaling process for obtaining the device's territorial information is usually the location update process (Location Update Procedure). In the LTE network, when the IoT device moves from one location area to another, it needs to send a location update request to the network to notify the network of its current location. The network will return the location area information where the device is located in the location update response, thereby obtaining the device's territorial information.
[0072] 1). High-security locations: Located in bustling commercial areas or financial centers in Europe, where policies and regulations have relatively high security requirements. These locations may be targets for data theft, so stronger encryption algorithms are needed to protect transactions and user data. In such cases, the system selects high-level encryption algorithms to ensure data confidentiality and integrity. Since high-level encryption algorithms usually consume more computing resources and energy, IoT devices require higher-power IoT device models to support the operation of these algorithms.
[0073] 2). Low-security locations: Located in suburban areas or places with low foot traffic in countries or regions with less strict supervision, the security risks are relatively low. At these locations, the system selects lighter-weight encryption algorithms to reduce energy consumption and improve the performance of the coffee machine. These algorithms can be selected according to the power consumption requirements of the IoT device model to ensure that the encryption operation does not affect the normal operation of the IoT device.
[0074] 3). Dynamic adjustment: Over time, the location and environment of the product may change. For example, a certain area may change from a commercial area to a residential area (the land use nature changes, from no requirements to implementing ISO 14001 or even equal protection requirements), or the device is sold as a second-hand device from one country to another. Then the rigid requirements for encryption algorithms will also change accordingly. By regularly interacting with the LTE Modem through signaling, the system obtains location information in real time and dynamically adjusts the encryption algorithm according to the current environment. This real-time response ability enables the system to flexibly adapt to the security requirements of different locations while minimizing energy consumption.
[0075] In a specific embodiment, the system interacts with the LTE Modem to obtain the geographical information of the current location of the device, preferably through a network signal base station or GPS, etc. Further, the system analyzes according to the security requirements of the current location and the power consumption requirements of the device. This involves the assessment of the security threat levels of different locations and the consideration of the energy required by the device.
[0076] The security of the location is classified. In the current example, the SL (Location Security Level) is divided into three levels: LSL (Low Location Security), MSL (Medium Location Security), and HSL (High Location Security). The SL level is a function of geographical location information and the surrounding wireless environment conditions, and its expression is: SL = f(Geo, Chnnel crowd , traffic)
[0077] where Geo represents the security requirement level of the geographical location, and the Geo parameter can be obtained through the following methods:
[0078] By obtaining specific country parameter information, comparing it with the preset low-security geographical list, medium-security geographical list, or high-security geographical list, the priority information of geographical information is obtained to determine the security requirement level: Geo ∈ {0, 1, 2, non-defined}
[0079] If the country parameter information cannot be obtained, then when using the base station geographical service, the latitude and longitude information obtained through the NMEA (National Marine Electronics Association) protocol data format in GNSS systems such as GPS and Beidou is used, and the country, province, and city names are obtained from the Geojson map library and jointly compared with the latitude and longitude ranges in the low-security geographical list, medium-security geographical list, or high-security geographical list under complex latitude and longitude conditions to determine: Geo ∈ {0, 1, 2, non-defined}
[0080] The security geographical lists at each level are pre-burned according to the legal permission conditions of each country or can be OTA-updated through the OTA cloud server according to the latest situation. The following is a comparison of the requirements for personal data privacy and encryption algorithms in the GDPR (General Data Protection Regulation), CCPA (California Consumer Privacy Act), LGPD (Brazilian General Data Protection Law), and HIPAA (Health Insurance Portability and Accountability Act):
[0081] GDPR:
[0082] Personal data privacy requirements: The GDPR imposes strict restrictions and protection requirements on the processing of personal data of EU citizens, including clear data processing purposes, the rights of data subjects, data protection and security measures, data retention periods, etc.
[0083] Encryption algorithm requirements: The GDPR does not have clear requirements for encryption, but emphasizes the protection and security of personal data. Encryption technology can be an important means to protect personal data, so it is recommended to adopt appropriate encryption measures in data processing and transmission.
[0084] CCPA:
[0085] Personal data privacy requirements: The CCPA stipulates the transparency and control rights for the collection and processing of personal data of California residents, including the right to know, the right to access, the right to delete, etc.
[0086] Encryption algorithm requirements: The CCPA does not clearly stipulate the use of encryption algorithms, but requires data controllers to take reasonable security measures to protect the security and privacy of personal data. Therefore, in this case, basic MD5 can be one of the security measures.
[0087] LGPD:
[0088] Personal data privacy requirements: The LGPD is similar to the GDPR and stipulates requirements regarding the legality, transparency, purpose limitation, rights of data subjects, data security, etc. for the processing of personal data of Brazilian citizens.
[0089] Encryption algorithm requirements: The LGPD does not explicitly require the use of specific encryption algorithms, but requires data controllers to adopt appropriate technical and organizational measures to protect the security and privacy of personal data, including encryption technologies higher than MD5.
[0090] HIPAA:
[0091] Personal data privacy requirements: HIPAA mainly targets the healthcare industry in the United States and stipulates requirements for the protection of personal health information (PHI), including the protection of the confidentiality, integrity, and availability of data.
[0092] Encryption algorithm requirements: HIPAA requires healthcare institutions and related organizations to adopt appropriate technologies and measures to protect the security of PHI, including encryption, access control, authentication, etc. Encryption technology is considered one of the important means to protect the security of PHI, and HIPAA recommends using encryption algorithms that comply with the FIPS140-2 standard.
[0093] Channel in the location security level function crowd represents the congestion degree parameter. The congestion degree parameter information determines the congestion degree of other surrounding users by whether indicators such as the acquisition probability of the shared channel of the mobile network, the system information block (SIB), and the reference signal received power (RSRP) are higher than the threshold, and obtains at least two levels of congestion degree parameters. Typically, there are three levels of congestion degree parameters, such as Channel crowd ∈ {0, 1, 2} congestion degree parameter.
[0094] Traffic in the location security level function represents the traffic volume level. The Traffic information is classified according to the service type of the Internet of Things device itself and includes at least two levels of traffic volume levels such as the upload of basic device self-check information, the heartbeat packet of the device operating state, the OTA basic packet, the complete packet, and the download of emergency patches. Specifically, it can be divided into four levels, that is, Traffic ∈ {0, 1, 2, 3}, which represent low traffic volume, high traffic volume, emergency service, and high-secrecy service respectively. This priority can be determined by the preset list uploaded or implemented by another M2M negotiation process during upload and download.
[0095] Figure 4 shows a schematic diagram of the encryption algorithm selection logic of an embodiment of the present application, as Figure 4As shown, first, it is determined whether the service type of the Internet of Things device is a high-security-level service. If so, the SL (Location Security Level) is directly determined to be high, and a secure encryption algorithm is adopted. It should be understood that transmitting users' personal sensitive information, such as personal models, personal identities, biological information, etc., belongs to high-security-level services. In the case of emergency services, the uplink and downlink traffic services are carried out according to the minimum requirements of Geo information. In high-traffic scenarios, the time required for the encryption algorithm is calculated, and the rate that can be obtained in the current channel environment is used to calculate the service upload and download time. If it is within the time limit, the degree of congestion is judged. If the degree of congestion is high, the high-security-level algorithm preset under this Geo condition is used; otherwise, the low-security-level algorithm preset under this Geo condition is used. In low-traffic service scenarios, the probability threshold is calculated based on information such as the signal congestion degree, the number of retransmissions, and the base station allocation rate in the previous time window period, and a uniformly distributed random number a is generated. If a < p, the high-security-level algorithm under the current Geo condition is used; otherwise, the low-security-level algorithm under the current Geo condition is used.
[0096] For locations with high security requirements, in the HSL (High Location Security) scenario, more complex and secure encryption algorithms are selected, such as ECDSA and AES-256. While for locations with lower security requirements, lighter-weight algorithms, such as MD5, can be selected to reduce energy consumption.
[0097] In addition, the system regularly obtains location information and dynamically adjusts the encryption algorithm according to the real-time situation. If it is found that the security requirements of the location where the device is located have changed, the system can make timely adjustments to ensure data security. The system also accumulates experience and conducts self-learning by continuously observing the security requirements and device power consumption in different locations, and dynamically adjusts the threshold parameters in SL = f(Geo, Channel crowd , traffic), etc. In this way, the system can more accurately select the encryption algorithm in future decisions to further optimize security and energy efficiency.
[0098] In summary, the adaptive encryption algorithm based on different services and device power consumption requirements, combined with the positioning information interaction of the LTE Modem, can provide an intelligent security strategy for the embedded system. By dynamically selecting the encryption algorithm and adjusting according to the location information, the system can balance security and energy efficiency in different scenarios, thus providing more reliable data protection and more efficient system operation.
[0099] As Figure 5As shown, data simulations and actual measurements were carried out for each encryption algorithm (including MD5, SHA256, SHA512, and ECDSA) in the 608 encryption chip solution. Through simulations and actual measurements, it was found that there is a positive correlation between the data packet size and the algorithm running time, that is, the larger the data packet, the longer the time required for the algorithm to run. In particular, the running times of the MD5 and SHA512 algorithms are relatively long among these encryption algorithms. Based on the currently collected data, the machine power consumption required for running these different algorithms can be further calculated.
[0100] The present invention realizes the development and scenario research of an Internet of Things device adaptive encryption Internet of Things communication module. By integrating the incoming network frequency bands, compatibility with 3GPP and subsequent versions is achieved, ensuring normal operation and interconnection in different network environments. This design provides a user with an M2M design solution, and users can use this module to build product functions, providing great convenience and economic benefits to enterprise users in terms of reusability, flexibility, easy expandability, and maintainability.
[0101] The encryption algorithm in software performs complex mathematical transformations on the original data, so that unauthorized individuals or entities cannot interpret its true content even if they intercept the data, thus effectively protecting the privacy and sensitivity of the data. It effectively protects business secrets and prevents economic losses and reputational damage caused by data leakage.
[0102] Further referring to Figure 6 , as an implementation of the above method, in a second aspect, the present application provides a structural diagram of an embodiment of an Internet of Things device dynamic encryption communication system 600, and this system can be specifically applied to various electronic devices. This system 600 includes the following modules:
[0103] A security requirement level acquisition module 610, configured to acquire the current geographical location information of the Internet of Things device, and determine the security requirement level of the Internet of Things device according to the current geographical location information and a preset list of geographical locations with different security levels;
[0104] A congestion degree parameter acquisition module 620, configured to acquire the network performance indicators of the mobile network shared channel at the location where the Internet of Things device is located, and determine the congestion degree parameter of the surrounding network environment according to the network performance indicators;
[0105] A traffic volume level acquisition module 630, configured to classify according to the service type of the Internet of Things device to obtain the traffic volume level;
[0106] A dynamic encryption module 640, configured to comprehensively obtain the security requirement level, congestion degree parameter, and traffic volume level, dynamically select the corresponding encryption algorithm to encrypt the sensitive data of the Internet of Things device, and transmit the encrypted data to the cloud server.
[0107] In a third aspect, the present application provides a terminal device, including a processor, a memory, and a computer program stored in the memory. The computer program is executed by the processor to implement the dynamic encryption communication method for Internet of Things devices as described in any one of the above.
[0108] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program which, when executed by a processor, implements the dynamic encryption communication method for Internet of Things devices as described in any one of the above.
[0109] Reference is now made to Figure 7 , which shows a schematic structural diagram of a computer system 700 of a terminal device or a server suitable for implementing the embodiments of the present application. Figure 7 The shown terminal device or server is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0110] As Figure 7 shown, the computer system 700 includes a central processing unit (CPU) 701 which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the system 700 are also stored. The CPU 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0111] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, a modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as required. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as required so that a computer program read therefrom is installed into the storage section 708 as required.
[0112] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 709 and / or installed from the removable medium 711. When the computer program is executed by the central processing unit (CPU) 701, the above functions defined in the methods of the present application are performed. It should be noted that the computer-readable medium described in the present application can be a computer-readable signal medium, a computer-readable medium, or any combination of the two. The computer-readable medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable medium that can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0113] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0114] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A dynamic encryption communication method for Internet of Things devices, characterized in that: The method comprises the following steps: S1. Obtain the current geographic location information of the IoT device, and determine the security requirement level of the IoT device according to the current geographic location information and a preset geographic location list with different security levels; S2. Obtain a network performance indicator of a mobile network shared channel at a location where the IoT device is located, and determine a congestion parameter of a surrounding network environment according to the network performance indicator; S3. Classify the IoT devices according to their service types to obtain service volume levels; S4. Comprehensively obtain the security requirement level, congestion parameter and traffic volume level, dynamically select a corresponding encryption algorithm to encrypt the sensitive data of the IoT device, and transmit the encrypted data to the cloud server.
2. The method for dynamic encryption communication of IoT devices according to claim 1, characterized in that: Also includes: The IoT device initializes an encryption chip, which generates an asymmetric key pair, the asymmetric key pair comprising a public key and a private key, wherein the public key is sent to the cloud server for registration, and the private key is stored in the encryption chip; The IoT device is connected to the cloud server for communication, and performs identity authentication through the public key and identity confirmation through the private key.
3. The method for dynamic encryption communication of IoT devices according to claim 1, characterized in that: In step S1, the current geographic location information of the IoT device is obtained, and the security requirement level of the IoT device is determined according to the current geographic location information and a preset geographic location list of different security levels, specifically including: The national parameter information is obtained through the location update process of the LTE modem, and the national parameter information is compared with a preset low-security geographic list, a medium-security geographic list, or a high-security geographic list to determine the security requirement level of the IoT device at the current location.
4. The method for dynamic encryption communication of IoT devices according to claim 2, characterized in that: In step S1, it also includes: In response to determining that the current geographic location information cannot be obtained through the LTE modem, obtaining the latitude and longitude information in the NMEA protocol data format through the GPS or Beidou system; According to the latitude and longitude information, query the corresponding country, province and city name in the Geojson map library; The queried country, province and city names are jointly and collaboratively compared with the latitude and longitude ranges of the preset low-security geographic list, medium-security geographic list or high-security geographic list to determine the security requirement level of the IoT device at the current location.
5. The method for dynamic encryption communication of IoT devices according to claim 1, characterized in that: In step S2, a network performance index of a mobile network shared channel at a location of the IoT device is obtained, and a congestion degree parameter of a surrounding network environment is determined according to the network performance index, specifically including: Obtain a network performance indicator of a shared channel of a mobile network at a location where the IoT device is located, and obtain a congestion parameter value by comparing the network performance indicator with a preset threshold, wherein the network performance indicator includes: acquisition probability, system information block parameter, and reference signal receiving power.
6. The method for dynamic encryption communication of IoT devices according to claim 1, characterized in that: In step S3, the traffic volume is divided into at least two traffic volume levels according to the service type of the IoT device, and the service type includes: device operation status heartbeat package download, OTA basic package download, complete package download and emergency patch download.
7. The method for dynamic encryption communication of IoT devices according to claim 1, characterized in that: Also includes: Determine the traffic level according to the traffic type of the IoT device, where the traffic level includes: high-density traffic, emergency traffic, high traffic volume, and low traffic volume; If the business volume level is high-security business, the data is directly encrypted using a secure encryption algorithm; If the traffic level is an emergency service, the traffic service is performed according to the minimum encrypted communication requirements of the geographical location information of the IoT device; If the traffic level is high traffic, the processing time required for using a high-level encryption algorithm or a low-level encryption algorithm is calculated, and based on the transmission rate that can be provided by the current channel environment, the upload and download time of the service is further calculated; If the service can be uploaded or downloaded within the preset time limit, the congestion level parameters of the current channel are further determined: If the congestion parameter is high, a high-level encryption algorithm preset corresponding to the current geographic location information is used; If the congestion level parameter is low, a low-level encryption algorithm preset corresponding to the current geographic location information is used; If the traffic level is low traffic, a probability threshold p is calculated based on the signal congestion level, the number of data retransmissions, and the transmission rate information assigned by the base station in the previous time window period, and a uniformly distributed random number a is generated, and the encryption algorithm is selected according to the following rules: If the random number a is less than the probability threshold p, a high-level encryption algorithm corresponding to the current geographic location information is used; If the random number a is not less than the probability threshold p, a low-level encryption algorithm corresponding to the current geographic location information is used.
8. A dynamic encryption communication system for IoT devices, characterized in that: The system comprises: A security requirement level acquisition module is configured to acquire current geographic location information of the IoT device, and determine the security requirement level of the IoT device according to the current geographic location information and a preset geographic location list with different security levels; A congestion parameter acquisition module is configured to acquire a network performance index of a mobile network shared channel at a location where the IoT device is located, and determine a congestion parameter of a surrounding network environment according to the network performance index; A traffic level acquisition module is configured to classify the traffic types of the IoT devices to obtain traffic levels; The dynamic encryption module is configured to comprehensively obtain the security requirement level, congestion parameters and business volume level, dynamically select a corresponding encryption algorithm to encrypt the sensitive data of the IoT device, and transmit the encrypted data to the cloud server.
9. A terminal device, characterized in that: It includes a processor, a memory and a computer program stored in the memory, wherein the computer program is executed by the processor to implement the dynamic encryption communication method for an Internet of Things device as described in any one of claims 1 to 7.
10. A computer-readable storage medium, wherein a computer program is stored in the medium, and when the computer program is executed by a processor, the dynamic encryption communication method for an Internet of Things device as described in any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Intelligent analysis system and method for secure transmission of chip data
CN120434049A
An intelligent analysis system and method for secure transmission of chip data
CN120434049B
Multi-dimensional security management method and system based on API gateway, and medium
CN120729601A
Internet of Things equipment self-adaptive secure communication method and system based on dynamic negotiation, Internet of Things equipment and storage medium
CN121567402A