Data transmission method and intelligent gateway terminal based on Dianhong IoT operating system
By using the intelligent gateway terminal of Dianhong IoT operating system to encrypt plaintext data in the Internet of Things system and using the powerful capabilities of the branch parent node, the security of data transmission in IoT devices is solved, and more efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510578698.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2045-05-07
AI Technical Summary
In the Internet of Things scenario, how to ensure the security of data transmission between devices, especially in the power system, how to improve the security of data transmission.
The intelligent gateway terminal based on Dianhong IoT operating system is used to encrypt plain text data. Through the ability of the branch parent node is stronger than that of the child node, the plain text data is encrypted by Dianhong IoT operating system, cipher text data is obtained, and sent to the receiving device. The branch parent node supports more complex or more secure encryption methods.
It improves the security of data transmission, improves the operating efficiency of the system, reduces the overhead of data transmission, and enhances information security without increasing the number of communication hops.
Smart Images

Figure CN120090885B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular to a data transmission method and intelligent gateway terminal based on the Dianhong IoT operating system. Background Art
[0002] With the rapid development and widespread application of IoT technology, the power sector has also ushered in significant opportunities for intelligent management. By connecting electrical equipment to the internet, IoT technology enables information exchange and data sharing between devices, significantly improving the operational efficiency and management level of power systems.
[0003] The Internet of Things (IoT) refers to a network that connects any object to the internet through information sensing devices such as radio frequency identification (RFID), infrared sensors, global positioning systems (GPS), and laser scanners, enabling information exchange and communication according to agreed protocols, enabling intelligent identification, location, tracking, monitoring, and management. With rapid socioeconomic development and growing electricity demand, the complexity and management difficulty of power systems are also increasing. Traditional power management methods often rely on manual inspections and operations, which are inefficient and prone to errors. The introduction of IoT technology has brought revolutionary changes to the power sector. For example, IoT technology can monitor the operating status of electrical equipment in real time and collect various data through sensors, providing data support for intelligent management of power systems. The IoT platform enables remote control and management of power equipment, reducing human intervention and improving system automation. IoT technology can provide real-time monitoring and early warning of abnormal conditions, helping maintenance personnel respond to and resolve issues promptly and optimize maintenance strategies. By analyzing power consumption data, IoT technology helps achieve efficient energy utilization and energy conservation and emission reduction.
[0004] However, in the context of the Internet of Things, how to ensure the security of data transmission between devices is a current research issue. Summary of the Invention
[0005] The embodiments of the present application provide a data transmission method and an intelligent gateway terminal based on the Dianhong IoT operating system to improve the security of data transmission.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In the first aspect, an embodiment of the present application provides a data transmission method based on the Dianhong IoT operating system, which is applied to an intelligent gateway terminal, which is one of multiple nodes in an IoT networking tree. The method includes: the intelligent gateway terminal receives plaintext data from a child node of the intelligent gateway terminal, and the intelligent gateway terminal is a branch parent node of the child node. In the IoT networking tree, the plaintext data of a node needs to be encrypted by a branch parent node of a node, and the capability of the branch parent node of a node is stronger than that of a node; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data; the intelligent gateway terminal sends the ciphertext data to a receiving device that communicates with the child node.
[0008] Optionally, a branch parent node is a node located at a fork of at least two branches in the Internet of Things networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the Internet of Things networking tree.
[0009] Optionally, the Dianhong IoT operating system includes an application layer and a protocol adaptation layer, and the intelligent gateway terminal receives plaintext data from the child node of the intelligent gateway terminal, including: the intelligent gateway terminal receives the plaintext data from the protocol adaptation layer of the child node through the protocol adaptation layer of the intelligent gateway terminal, and the plaintext data includes indication information provided by the application layer of the child node, and the indication information is used to indicate that the plaintext data needs to be encrypted; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data, including: in response to the indication information, the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data.
[0010] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal divides the data matrix unevenly into M sub-matrices through a segmentation template provided by the protocol adaptation layer of the intelligent gateway terminal, and any two sub-matrices in the M sub-matrices contain different elements in the data matrix, and M is an integer greater than 2; the intelligent gateway terminal encrypts M-1 sub-matrices in the M sub-matrices through the protocol adaptation layer of the intelligent gateway terminal, and obtains M-1 encrypted sub-matrices accordingly, and the ciphertext data includes the M-1 encrypted sub-matrices and one unencrypted sub-matrix in the M sub-matrices, and the one unencrypted sub-matrix is used for data obfuscation.
[0011] Optionally, the intelligent gateway terminal non-uniformly divides the data matrix into M sub-matrices through a segmentation template provided by a protocol adaptation layer of the intelligent gateway terminal, including: the intelligent gateway terminal determines, through the protocol adaptation layer of the intelligent gateway terminal, a segmentation template whose size matches the size of the data matrix; the intelligent gateway terminal, through the protocol adaptation layer of the intelligent gateway terminal, non-uniformly divides the data matrix into M parts in the row or column direction according to the segmentation pattern of the segmentation template, each of the M parts corresponds to a part in the segmentation pattern, and any part of the M parts has a non-matrix structure; the intelligent gateway terminal uses the element pairs in the segmentation template through the protocol adaptation layer of the intelligent gateway terminal to fill each of the M parts with the structure of the data matrix, thereby obtaining M sub-matrices.
[0012] Optionally, some of the M parts are triangular or trapezoidal structures.
[0013] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal determines whether there is a hidden node corresponding to the intelligent gateway terminal in the Internet of Things networking tree; if there is a hidden node, the intelligent gateway terminal instructs the hidden node to encrypt the data matrix through the protocol adaptation layer of the intelligent gateway terminal; the intelligent gateway terminal receives ciphertext data from the hidden node through the protocol adaptation layer of the intelligent gateway terminal, the ciphertext data including M-1 encrypted sub-matrices in the M sub-matrices and one unencrypted sub-matrix in the M sub-matrices, the one unencrypted sub-matrix being used for data obfuscation, the M sub-matrices being obtained by unevenly dividing the data matrix according to a segmentation template provided by the protocol adaptation layer of the hidden node, and M is an integer greater than 2.
[0014] Optionally, the hidden node is a node at the same level as the intelligent gateway terminal but belongs to a different branch in the Internet of Things networking tree.
[0015] Optionally, the intelligent gateway terminal sends ciphertext data to a receiving device communicating with the subnode, including: the intelligent gateway terminal sends the ciphertext data to the receiving device through a protocol adaptation layer of the intelligent gateway terminal, and the ciphertext data does not include indication information.
[0016] In the second aspect, an embodiment of the present application provides an intelligent gateway terminal, which is one of the multiple nodes in the Internet of Things networking tree. The intelligent gateway terminal is configured as follows: the intelligent gateway terminal receives plaintext data from the child node of the intelligent gateway terminal, and the intelligent gateway terminal is the branch parent node of the child node. In the Internet of Things networking tree, the plaintext data of a node needs to be encrypted by the branch parent node of a node, and the capability of the branch parent node of a node is stronger than that of a node; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data; the intelligent gateway terminal sends the ciphertext data to the receiving device that communicates with the child node.
[0017] Optionally, a branch parent node is a node located at a fork of at least two branches in the Internet of Things networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the Internet of Things networking tree.
[0018] Optionally, the Dianhong IoT operating system includes an application layer and a protocol adaptation layer, and the intelligent gateway terminal receives plaintext data from the child node of the intelligent gateway terminal, including: the intelligent gateway terminal receives the plaintext data from the protocol adaptation layer of the child node through the protocol adaptation layer of the intelligent gateway terminal, and the plaintext data includes indication information provided by the application layer of the child node, and the indication information is used to indicate that the plaintext data needs to be encrypted; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data, including: in response to the indication information, the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data.
[0019] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal divides the data matrix unevenly into M sub-matrices through a segmentation template provided by the protocol adaptation layer of the intelligent gateway terminal, and any two sub-matrices in the M sub-matrices contain different elements in the data matrix, and M is an integer greater than 2; the intelligent gateway terminal encrypts M-1 sub-matrices in the M sub-matrices through the protocol adaptation layer of the intelligent gateway terminal, and obtains M-1 encrypted sub-matrices accordingly, and the ciphertext data includes the M-1 encrypted sub-matrices and one unencrypted sub-matrix in the M sub-matrices, and the one unencrypted sub-matrix is used for data obfuscation.
[0020] Optionally, the intelligent gateway terminal non-uniformly divides the data matrix into M sub-matrices through a segmentation template provided by a protocol adaptation layer of the intelligent gateway terminal, including: the intelligent gateway terminal determines, through the protocol adaptation layer of the intelligent gateway terminal, a segmentation template whose size matches the size of the data matrix; the intelligent gateway terminal, through the protocol adaptation layer of the intelligent gateway terminal, non-uniformly divides the data matrix into M parts in the row or column direction according to the segmentation pattern of the segmentation template, each of the M parts corresponds to a part in the segmentation pattern, and any part of the M parts has a non-matrix structure; the intelligent gateway terminal uses the element pairs in the segmentation template through the protocol adaptation layer of the intelligent gateway terminal to fill each of the M parts with the structure of the data matrix, thereby obtaining M sub-matrices.
[0021] Optionally, some of the M parts are triangular or trapezoidal structures.
[0022] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal determines whether there is a hidden node corresponding to the intelligent gateway terminal in the Internet of Things networking tree; if there is a hidden node, the intelligent gateway terminal instructs the hidden node to encrypt the data matrix through the protocol adaptation layer of the intelligent gateway terminal; the intelligent gateway terminal receives ciphertext data from the hidden node through the protocol adaptation layer of the intelligent gateway terminal, the ciphertext data including M-1 encrypted sub-matrices in the M sub-matrices and one unencrypted sub-matrix in the M sub-matrices, the one unencrypted sub-matrix being used for data obfuscation, the M sub-matrices being obtained by unevenly dividing the data matrix according to a segmentation template provided by the protocol adaptation layer of the hidden node, and M is an integer greater than 2.
[0023] Optionally, the hidden node is a node at the same level as the intelligent gateway terminal but belongs to a different branch in the Internet of Things networking tree.
[0024] Optionally, the intelligent gateway terminal sends ciphertext data to a receiving device communicating with the subnode, including: the intelligent gateway terminal sends the ciphertext data to the receiving device through a protocol adaptation layer of the intelligent gateway terminal, and the ciphertext data does not include indication information.
[0025] In a third aspect, an embodiment of the present application provides a computer-readable storage medium having program code stored thereon. When the program code is run by the computer, the method described in the first aspect is executed.
[0026] In summary, the above method and terminal have the following technical effects:
[0027] Taking into account the performance of IoT devices, when networking these devices, the capabilities of a node's branch parent node can be configured to be stronger than that of a node. In this way, when a node wants to send data, it can not encrypt the data, but instead route it to the node's branch parent node for encryption. For example, the smart gateway terminal can encrypt the plaintext data through the Dianhong IoT operating system, obtain the ciphertext data, and send the ciphertext data to the corresponding receiving device. In this case, because the branch parent node has stronger capabilities, it can support more complex or more secure encryption methods, thereby improving the security of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 A schematic diagram of the architecture of an Internet of Things system provided in an embodiment of the present application;
[0029] Figure 2 A schematic diagram of an Internet of Things networking tree in an Internet of Things system provided in an embodiment of the present application;
[0030] Figure 3 A flowchart of a data transmission method based on the Dianhong IoT operating system provided in an embodiment of the present application;
[0031] Figure 4 A schematic diagram of a segmentation template in the method provided in an embodiment of the present application;
[0032] Figure 5 A schematic diagram of the segmentation and filling operations in the method provided in an embodiment of the present application;
[0033] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0034] In the embodiment of the present invention, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, wherein the other information and the information to be indicated have an association relationship. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information that is agreed upon in advance (for example, stipulated by the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0035] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can refer to the existing technology and will not be repeated in this article. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present invention does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present invention should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0036] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending timing of these sub-information can be the same or different. The specific sending method is not limited by the embodiment of the present invention. The sending period and / or sending timing of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the transmitting device through sending configuration information to the receiving device.
[0037] "Pre-definition" or "pre-configuration" can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present invention do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or an electronic device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or an electronic device. The type of memory can be any form of storage medium, which is not limited by the embodiments of the present invention.
[0038] The "protocol" involved in the embodiments of the present invention may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol in a reliable access method system for future Internet of Things devices. The embodiments of the present invention do not specifically limit this.
[0039] In the embodiments of the present invention, descriptions such as "when...", "in the case of...", "if", and "if" all mean that the device will perform corresponding processing under certain objective circumstances. They do not limit the time, nor do they require the device to perform judgment actions during implementation, nor do they mean the existence of other limitations.
[0040] In the description of the embodiments of the present invention, unless otherwise specified, " / " indicates that the associated objects are in an "or" relationship. For example, A / B can mean either A or B. "And / or" in the embodiments of the present invention merely describes an association relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, in the description of the embodiments of the present invention, unless otherwise specified, "multiple" refers to two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural. Furthermore, to facilitate the clear description of the technical solutions of the embodiments of the present invention, the terms "first" and "second" are used in the embodiments of the present invention to distinguish between identical or similar items with substantially the same function or effect. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present invention, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0041] The network architecture and business scenarios described in the embodiments of the present invention are intended to more clearly illustrate the technical solutions of the embodiments of the present invention, and do not constitute a limitation on the technical solutions provided by the embodiments of the present invention. Ordinary technicians in this field can know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present invention are also applicable to similar technical problems.
[0042] The technical solution in this application will be described below with reference to the accompanying drawings.
[0043] See also Figure 1 , an embodiment of the present application provides an Internet of Things system, which may include multiple nodes.
[0044] Each of the multiple nodes can be an intelligent gateway terminal. The intelligent gateway terminal can be responsible for data processing, such as forwarding and encryption. In power scenarios, the intelligent gateway terminal can be attached to power / electrical equipment and collect data from the equipment, such as operating data and status data.
[0045] The intelligent gateway terminal may be a terminal-shaped device, which may also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device. The terminal device in the embodiments of the present application may be a mobile phone, a tablet computer, a computer with wireless transceiver functions, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc.
[0046] Multiple nodes can be networked to obtain an IoT networking tree. The IoT networking tree can contain multiple branches, each branch starting from the root node of the IoT networking tree and ending at a leaf node in the IoT networking tree. In the IoT networking tree, the plaintext data of a node needs to be encrypted by a branch parent node of a node. The capability of a branch parent node of a node is stronger than that of a node. The capability here can indicate the device's ability to process data. For example, the branch parent node has more computing power, thereby supporting more complex encryption processing of the data to improve data security. At the same time, since nodes that are not branch parent nodes do not need to perform encryption processing when sending their own data, the operating efficiency can be improved, thereby improving the overall operating efficiency of the system. A branch parent node can be a node located at the fork of at least two branches in the IoT networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the IoT networking tree.
[0047] For ease of understanding, let's take an example. Figure 2As shown, node 1 is the root node, node 2 is a branch parent node, node 8 is another branch parent node, and nodes 5, 7, 10, and 12 are all leaf nodes. This IoT network tree includes four branches: branch 1 includes nodes 1, 2, 4, and 5. Branch 2 includes nodes 1, 2, 6, and 7. Branch 3 includes nodes 1, 3, 8, 9, and 10. Branch 4 includes nodes 1, 3, 8, 11, and 12. Nodes 9 and 10 are both branch parent nodes, i.e., child nodes of node 8. Node 8 is a child node of node 3. Nodes 8 and 3 are both children of node 1, the root node. In other words, in the same branch, any downstream node is a child node of the upstream node.
[0048] The following will describe in detail the interaction of the intelligent gateway terminal in the above system in conjunction with the method.
[0049] See also Figure 3 , the embodiment of the present application provides a data transmission method based on the Dianhong IoT operating system, the process of the method is as follows:
[0050] S301: The intelligent gateway terminal receives plaintext data from a child node of the intelligent gateway terminal.
[0051] The intelligent gateway terminal is the branch parent node of the child node.
[0052] The system of the intelligent gateway terminal is the Dianhong IoT operating system. The Dianhong IoT operating system is the Electric Power Hongmeng OS, also known as the Electric Power IoT operating system. The Dianhong IoT operating system mainly includes an application layer and a protocol adaptation layer. The application layer can obtain application data, such as the aforementioned data collected from the power / electrical equipment, such as operating data and status data, which is obtained through the application layer. The data transmission of the intelligent gateway terminal can be wireless, so the protocol adaptation layer may include the Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), Radio Link Control (RLC), Media Access Control (MAC), and the physical layer (PHY). The application layer data is processed sequentially by SDAP, PDCP, RLC, and MAC, and can be passed to the physical layer in the form of bits. Since the physical layer encrypts the bits and transmits them via signals, the encryption operation performed by the protocol adaptation layer in the embodiments of the present application refers to the physical layer performing the encryption operation.
[0053] After receiving the data, the child node's application layer, based on the encryption rules described in the aforementioned system embodiment, can encapsulate an indication within the data, indicating that the plaintext data requires encryption. The child node's application layer can then pass the data to the intelligent gateway terminal's protocol adaptation layer via the child node's protocol adaptation layer. At this point, the data remains unencrypted, i.e., it remains plaintext. Accordingly, the intelligent gateway terminal receives the plaintext data from the child node's protocol adaptation layer (specifically, the physical layer) via the intelligent gateway terminal's protocol adaptation layer (specifically, the physical layer). This plaintext data includes the indication provided by the child node's application layer, indicating that the plaintext data requires encryption.
[0054] S302, the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data.
[0055] In response to the indication information (ie, encryption is required), and the intelligent gateway terminal knows that it is the branch parent node, the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer (ie, physical layer) of the intelligent gateway terminal to obtain ciphertext data.
[0056] After being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, where each element in the data matrix is a bit. This means that information is transmitted at the physical layer as a bit sequence. The intelligent gateway terminal can construct the received bit sequences into a matrix, i.e., a data matrix. For example, if each bit sequence is 8 bits, 8 bit sequences are received in sequence to construct an 8x8 data matrix. The indication information can be one of the bits, with a value of 1 indicating encryption is required and a value of 0 indicating a null value. The indication information can be carried in a reserved bit position.
[0057] In one possible approach, the intelligent gateway terminal can use a segmentation template provided by the protocol adaptation layer of the intelligent gateway terminal to unevenly divide the data matrix into M sub-matrices, where any two of the M sub-matrices contain different elements in the data matrix, and M is an integer greater than 2. For example, the intelligent gateway terminal determines a segmentation template whose size matches the size of the matrix and the size of the data matrix through the protocol adaptation layer of the intelligent gateway terminal. Since the data transmitted each time may be different, it means that the length of the bit sequence corresponding to the data may also be different. For example, for a certain data transmission, the protocol adaptation layer of the intelligent gateway terminal receives a bit sequence with a length of 8 bits and constructs an 8*8 data matrix. In this way, the intelligent gateway terminal needs to select an 8*8 segmentation template, or the intelligent gateway terminal can configure a larger-sized segmentation model, such as 16*16, and cut it into 8*8, that is, obtain a segmentation template whose size matches the size of the data matrix, where the cutting can be as follows. Figure 4 ,like Figure 4As shown, for a 16*16 segmentation template, the intelligent gateway terminal can cut off portion A, leaving portion B as an 8*8 segmentation template. Alternatively, for another data transmission, the protocol adaptation layer of the intelligent gateway terminal receives a bit sequence of 12 bits and constructs a 12*12 data matrix. In this case, the intelligent gateway terminal needs to select a 12*12 segmentation template. Alternatively, the intelligent gateway terminal can configure a larger segmentation model, such as 16*16, and cut it into 12*12, thus obtaining a segmentation template whose size matches the size of the data matrix. The principle is the same as above and will not be further described.
[0058] The intelligent gateway terminal, through its protocol adaptation layer, non-uniformly divides the data matrix into M parts in the row or column direction according to the segmentation pattern of the segmentation template. Each of the M parts corresponds to a part in the segmentation pattern, and any of the M parts has a non-matrix structure, such as a triangular or trapezoidal structure. The intelligent gateway terminal, through its protocol adaptation layer, uses element pairs in the segmentation template to fill each of the M parts with the data matrix structure, thereby obtaining M sub-matrices.
[0059] For example, assuming the segmentation template is Figure 4 Part B of Figure 5 As shown in (a), the segmentation template is preset to have three parts, namely part 1, part 2 and part 3. Part 2 is a trapezoid, and parts 1 and 3 are irregular quadrilaterals. The data matrix is as follows Figure 5 As shown in (b) in the figure, by covering the segmentation template on the data matrix, we can get the bits included in each part, as shown in the following example: Figure 5 As shown in (c) in . At this time, Figure 5 As shown in (d), each part is filled with the structure of the data matrix using the element pairs in the segmentation template, that is, part 1 in the data matrix remains unchanged. Figure 5 In (c), while the elements in part 1 remain unchanged, replace the elements in part 2 and part 3 in the data matrix Figure 4 The elements in the segmentation template of part B in belong to parts 2 and 3, that is, submatrix 1 is obtained. Similarly, if Figure 5 As shown in (d), Figure 5 In (c), while the elements in part 2 remain unchanged, replace the elements in part 1 and part 3 in the data matrix Figure 4 The elements in the segmentation template of part B in belong to parts 1 and 3, that is, submatrix 1 is obtained. Similarly, in Figure 5 In (c), while the elements in part 3 remain unchanged, replace the elements in part 1 and part 2 in the data matrix Figure 4The elements in the segmentation template of part B in belong to part 1 and part 2, and thus submatrix 3 is obtained.
[0060] It should be understood that the shape of each portion described above is merely an example and is not intended to be limiting. For example, other shapes, such as irregular polygons, such as pentagons and hexagons, are also possible. Any shape that can de-digitize bits in the data matrix is applicable to the embodiments of this application.
[0061] The intelligent gateway terminal, through its protocol adaptation layer, encrypts M-1 submatrices (e.g., the first M-1 submatrices or the last M-1 submatrices) of the M submatrices, resulting in M-1 encrypted submatrices. The encryption can be performed using AES. The ciphertext data includes the M-1 encrypted submatrices and one unencrypted submatrix from the M submatrices, which is used for data obfuscation. In other words, through the aforementioned segmentation, the information structure of each submatrix is obscured. Even if unencrypted, an attacker cannot directly obtain the information. In this case, only a selected submatrix can be encrypted to reduce overhead. Furthermore, since the M-1 submatrices are encrypted and the unencrypted submatrix has no observable information structure, the attacker is confused and misled into believing that the unencrypted submatrix is also encrypted, thus attempting to decrypt it. However, decryption will fail, and even if decryption succeeds, the information obtained will be garbled. In other words, obfuscation through non-encryption can further improve information security.
[0062] In another possible way, the smart gateway terminal determines whether there is a hidden node corresponding to the smart gateway terminal in the IoT networking tree; if there is a hidden node, the smart gateway terminal instructs the hidden node to encrypt the data matrix through the protocol adaptation layer of the smart gateway terminal, that is, to send the data matrix to the hidden node through the physical layer, wherein a tunnel connection is established between the hidden node and the smart gateway terminal. In other words, in the IoT networking tree, for nodes belonging to different branches, only the hidden node and the corresponding node can communicate directly through the tunnel, and the remaining nodes belonging to different branches cannot communicate directly. The hidden node is a node at the same level as the smart gateway terminal that belongs to a different branch in the IoT networking tree, such as Figure 2As shown, node 6 is the hidden node of node 8, node 3 is the hidden node of node 2, and node 1 has no corresponding hidden node. The hidden node can perform the same encryption process as the intelligent gateway terminal. For details, please refer to the above introduction and will not be repeated here. In this way, the intelligent gateway terminal receives the ciphertext data from the hidden node through the protocol adaptation layer of the intelligent gateway terminal. The ciphertext data includes M-1 encrypted sub-matrices in the M sub-matrices and one unencrypted sub-matrix in the M sub-matrices. The one unencrypted sub-matrix is used for data obfuscation. The M sub-matrices are obtained by unevenly dividing the data matrix according to the segmentation template provided by the protocol adaptation layer of the hidden node. M is an integer greater than 2.
[0063] It can be understood that encrypting data by nodes of different branches can further increase the complexity of encryption, that is, even if an attacker steals the key of the smart gateway terminal, he cannot decrypt the data, thereby further improving data security.
[0064] S303: The intelligent gateway terminal sends the encrypted data to the receiving device communicating with the child node.
[0065] The smart gateway terminal sends encrypted data to the receiving device through its protocol adaptation layer (i.e., the physical layer). This encrypted data does not include any indication information. When the encrypted data is forwarded by other upstream nodes in the IoT network tree, these upstream nodes will not perform encryption operations due to the lack of indication information, ensuring that the encrypted data can be properly delivered to the receiving device. The encrypted data is ultimately sent to the receiving device by the root node.
[0066] In the case of hidden nodes, the hidden node can also send encrypted data to the receiving device. Because the hidden node and the smart gateway terminal belong to the same layer of the IoT network tree but belong to different branches, this method has the advantage of not adding additional routing hops. In other words, the number of hops from the hidden node to the root node is the same as the number of hops from the smart gateway terminal to the root node. This improves information security while minimizing the increase in communication overhead.
[0067] The receiving device is pre-configured with the decryption rules corresponding to the aforementioned encryption rules, as well as the corresponding keys, so that the receiving device can perform the reverse process of the aforementioned encryption. For example, the receiving device can be a device in a control center, a device with higher management authority. The receiving device can be pre-configured with information about the IoT network tree, that is, information about each node in the IoT network tree. In this way, the receiving device can determine that the ciphertext data originated from the aforementioned child node based on the source address, and thus can determine that the ciphertext data was encrypted by the aforementioned intelligent gateway terminal or its corresponding hidden node. The receiving device can then use the key of the intelligent gateway terminal or its corresponding hidden node to decrypt the ciphertext data, obtaining M sub-matrices. The M sub-matrices are then restored into M parts based on a cutting template, and the M parts are then spliced together to obtain a data matrix.
[0068] In summary, considering the performance of IoT devices, when networking these devices, the capabilities of a node's branch parent node can be configured to be stronger than the capabilities of a node. In this way, when a node wants to send data, it can not encrypt the data, but instead route it to the node's branch parent node for encryption. For example, the smart gateway terminal can encrypt the plaintext data through the Dianhong IoT operating system, obtain the ciphertext data, and send the ciphertext data to the corresponding receiving device. At this time, because the branch parent node has stronger capabilities, it can support more complex or more secure encryption methods, thereby improving the security of data transmission.
[0069] Combination of the above Figure 3 The method provided by the embodiment of the present application is described in detail. The following describes an intelligent gateway terminal for executing the method provided by the embodiment of the present application. The intelligent gateway terminal is one of multiple nodes in the Internet of Things networking tree. The intelligent gateway terminal is configured as follows: the intelligent gateway terminal receives plaintext data from a child node of the intelligent gateway terminal, the intelligent gateway terminal is a branch parent node of the child node, in the Internet of Things networking tree, the plaintext data of a node needs to be encrypted by a branch parent node of a node, and the capability of the branch parent node of a node is stronger than that of the node; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data; the intelligent gateway terminal sends the ciphertext data to a receiving device communicating with the child node.
[0070] Optionally, a branch parent node is a node located at a fork of at least two branches in the Internet of Things networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the Internet of Things networking tree.
[0071] Optionally, the Dianhong IoT operating system includes an application layer and a protocol adaptation layer, and the intelligent gateway terminal receives plaintext data from the child node of the intelligent gateway terminal, including: the intelligent gateway terminal receives the plaintext data from the protocol adaptation layer of the child node through the protocol adaptation layer of the intelligent gateway terminal, and the plaintext data includes indication information provided by the application layer of the child node, and the indication information is used to indicate that the plaintext data needs to be encrypted; the intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data, including: in response to the indication information, the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data.
[0072] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal divides the data matrix unevenly into M sub-matrices through a segmentation template provided by the protocol adaptation layer of the intelligent gateway terminal, and any two sub-matrices in the M sub-matrices contain different elements in the data matrix, and M is an integer greater than 2; the intelligent gateway terminal encrypts M-1 sub-matrices in the M sub-matrices through the protocol adaptation layer of the intelligent gateway terminal, and obtains M-1 encrypted sub-matrices accordingly, and the ciphertext data includes the M-1 encrypted sub-matrices and one unencrypted sub-matrix in the M sub-matrices, and the one unencrypted sub-matrix is used for data obfuscation.
[0073] Optionally, the intelligent gateway terminal non-uniformly divides the data matrix into M sub-matrices through a segmentation template provided by a protocol adaptation layer of the intelligent gateway terminal, including: the intelligent gateway terminal determines, through the protocol adaptation layer of the intelligent gateway terminal, a segmentation template whose size matches the size of the data matrix; the intelligent gateway terminal, through the protocol adaptation layer of the intelligent gateway terminal, non-uniformly divides the data matrix into M parts in the row or column direction according to the segmentation pattern of the segmentation template, each of the M parts corresponds to a part in the segmentation pattern, and any part of the M parts has a non-matrix structure; the intelligent gateway terminal uses the element pairs in the segmentation template through the protocol adaptation layer of the intelligent gateway terminal to fill each of the M parts with the structure of the data matrix, thereby obtaining M sub-matrices.
[0074] Optionally, some of the M parts are triangular or trapezoidal structures.
[0075] Optionally, after being processed by the protocol adaptation layer of the child node, the plaintext data becomes a data matrix with a row-column structure, and each element in the data matrix is one bit; the intelligent gateway terminal encrypts the plaintext data through the protocol adaptation layer of the intelligent gateway terminal to obtain ciphertext data, including: the intelligent gateway terminal determines whether there is a hidden node corresponding to the intelligent gateway terminal in the Internet of Things networking tree; if there is a hidden node, the intelligent gateway terminal instructs the hidden node to encrypt the data matrix through the protocol adaptation layer of the intelligent gateway terminal; the intelligent gateway terminal receives ciphertext data from the hidden node through the protocol adaptation layer of the intelligent gateway terminal, the ciphertext data including M-1 encrypted sub-matrices in the M sub-matrices and one unencrypted sub-matrix in the M sub-matrices, the one unencrypted sub-matrix being used for data obfuscation, the M sub-matrices being obtained by unevenly dividing the data matrix according to a segmentation template provided by the protocol adaptation layer of the hidden node, and M is an integer greater than 2.
[0076] Optionally, the hidden node is a node at the same level as the intelligent gateway terminal but belongs to a different branch in the Internet of Things networking tree.
[0077] Optionally, the intelligent gateway terminal sends ciphertext data to a receiving device communicating with the subnode, including: the intelligent gateway terminal sends the ciphertext data to the receiving device through a protocol adaptation layer of the intelligent gateway terminal, and the ciphertext data does not include indication information.
[0078] The following combination Figure 6 The components of the electronic device 500 are described in detail.
[0079] The processor 501 is the control center of the electronic device 500 and can be a single processor or a collective term for multiple processing elements. For example, the processor 501 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (digital signal processors, DSPs) or one or more field programmable gate arrays (FPGAs).
[0080] Optionally, the processor 501 can execute various functions of the electronic device 500 by running or executing the software program stored in the memory 502 and calling the data stored in the memory 502, as described above. Figure 3 Function in the method shown.
[0081] In a specific implementation, as an embodiment, the processor 501 may include one or more CPUs, such as Figure 6 CPU0 and CPU1 are shown in FIG.
[0082] In a specific implementation, as an example, the electronic device 500 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0083] Among them, the memory 502 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 501. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0084] Alternatively, the memory 502 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or
[0085] Other types of dynamic storage devices that can store information and instructions may also be electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these. The memory 502 can be integrated with the processor 501 or exist independently and the electronic device 500
[0086] Interface circuit ( Figure 6 (not shown) is coupled to the processor 501, which is not specifically limited in this embodiment of the present application.
[0087] The transceiver 503 is used for communicating with other devices. For example, if the multi-beam positioning device is a terminal, the transceiver 503 can be used to communicate with a network device or another terminal.
[0088] Optionally, the transceiver 503 may include a receiver and a transmitter ( Figure 6The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0089] Optionally, the transceiver 503 may be integrated with the processor 501 or may exist independently and communicate with the electronic device 500 through the interface circuit ( Figure 6 (not shown) is coupled to the processor 501, which is not specifically limited in this embodiment of the present application.
[0090] It should be noted that Figure 6 The structure of the electronic device 500 shown in the figure does not constitute a limitation on the device. The actual electronic device 500 may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0091] In addition, the technical effects based on the electronic device 500 can refer to the technical effects of the method in the above method embodiment, which will not be repeated here.
[0092] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), but may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0093] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0094] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. A computer program product comprises one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the processes or functions according to the embodiments of the present application are fully or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). A computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0095] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0096] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0097] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0098] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0099] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0100] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some feature fields can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0101] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0102] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0103] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the existing technology, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.
[0104] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A data transmission method based on the Dianhong IoT operating system, characterized in that: The method is applied to an intelligent gateway terminal, which is one of multiple nodes in an Internet of Things networking tree. The method includes: The intelligent gateway terminal receives plaintext data from a child node of the intelligent gateway terminal, the intelligent gateway terminal being a branch parent node of the child node, wherein in the IoT networking tree, the plaintext data of a node needs to be encrypted by the branch parent node of the node, and the capability of the branch parent node of the node is stronger than that of the node; The intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data; The intelligent gateway terminal sends the ciphertext data to a receiving device communicating with the sub-node; Wherein, a branch parent node is a node located at a fork of at least two branches in the Internet of Things networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the Internet of Things networking tree; The Dianhong IoT operating system includes an application layer and a protocol adaptation layer, and the smart gateway terminal receives plaintext data from a child node of the smart gateway terminal, including: The intelligent gateway terminal receives, through the protocol adaptation layer of the intelligent gateway terminal, plaintext data from the protocol adaptation layer of the child node, wherein the plaintext data includes indication information provided by the application layer of the child node, and the indication information is used to indicate that the plaintext data needs to be encrypted; The smart gateway terminal encrypts the plaintext data through the Dianhong IoT operating system, and the obtained ciphertext data includes: In response to the indication information, the intelligent gateway terminal encrypts the plaintext data through a protocol adaptation layer of the intelligent gateway terminal to obtain the ciphertext data.
2. The method according to claim 1, characterized in that The plaintext data is processed by the protocol adaptation layer of the child node into a data matrix with a row and column structure, and each element in the data matrix is one bit; The intelligent gateway terminal encrypts the plaintext data through a protocol adaptation layer of the intelligent gateway terminal to obtain the ciphertext data, including: The intelligent gateway terminal non-uniformly divides the data matrix into M sub-matrices using a segmentation template provided by a protocol adaptation layer of the intelligent gateway terminal, wherein any two sub-matrices of the M sub-matrices contain different elements in the data matrix, and M is an integer greater than 2; The intelligent gateway terminal encrypts M-1 submatrices in the M submatrices through the protocol adaptation layer of the intelligent gateway terminal, and obtains M-1 encrypted submatrices respectively. The ciphertext data includes the M-1 encrypted submatrices and an unencrypted submatrix in the M submatrices, and the unencrypted submatrix is used for data obfuscation.
3. The method according to claim 2, characterized in that The intelligent gateway terminal non-uniformly divides the data matrix into M sub-matrices using a segmentation template provided by a protocol adaptation layer of the intelligent gateway terminal, including: The intelligent gateway terminal determines, through a protocol adaptation layer of the intelligent gateway terminal, the segmentation template whose matrix size matches the size of the data matrix; The intelligent gateway terminal divides the data matrix non-uniformly into M parts in a row or column direction according to the segmentation pattern of the segmentation template through a protocol adaptation layer of the intelligent gateway terminal, each of the M parts corresponds to a part in the segmentation pattern, and any part of the M parts has a non-matrix structure; The intelligent gateway terminal uses the element pairs in the segmentation template to fill each of the M parts into the structure of the data matrix through the protocol adaptation layer of the intelligent gateway terminal, thereby obtaining the M sub-matrices.
4. The method according to claim 3, characterized in that Some of the M parts have a triangular structure or a trapezoidal structure.
5. The method according to claim 1, characterized in that The plaintext data is processed by the protocol adaptation layer of the child node into a data matrix with a row and column structure, and each element in the data matrix is one bit; The intelligent gateway terminal encrypts the plaintext data through a protocol adaptation layer of the intelligent gateway terminal to obtain the ciphertext data, including: The intelligent gateway terminal determines whether there is a hidden node corresponding to the intelligent gateway terminal in the Internet of Things networking tree; If the hidden node exists, the intelligent gateway terminal instructs the hidden node to encrypt the data matrix through the protocol adaptation layer of the intelligent gateway terminal; The intelligent gateway terminal receives ciphertext data from the hidden node through the protocol adaptation layer of the intelligent gateway terminal, where the ciphertext data includes M-1 encrypted sub-matrices in the M sub-matrices and one unencrypted sub-matrix in the M sub-matrices, where the one unencrypted sub-matrix is used for data obfuscation, and the M sub-matrices are obtained by unevenly dividing the data matrix according to a segmentation template provided by the protocol adaptation layer of the hidden node, where M is an integer greater than 2.
6. The method according to claim 5, characterized in that The hidden node is a node at the same level as the intelligent gateway terminal but belongs to a different branch in the Internet of Things networking tree.
7. The method according to any one of claims 1 to 6, characterized in that The intelligent gateway terminal sends the ciphertext data to a receiving device communicating with the sub-node, including: The intelligent gateway terminal sends the ciphertext data to the receiving end device through the protocol adaptation layer of the intelligent gateway terminal, and the ciphertext data does not include the indication information.
8. An intelligent gateway terminal, characterized in that: The intelligent gateway terminal is one of the multiple nodes in the Internet of Things networking tree, and the intelligent gateway terminal is configured as follows: The intelligent gateway terminal receives plaintext data from a child node of the intelligent gateway terminal, the intelligent gateway terminal being a branch parent node of the child node, wherein in the IoT networking tree, the plaintext data of a node needs to be encrypted by the branch parent node of the node, and the capability of the branch parent node of the node is stronger than that of the node; The intelligent gateway terminal encrypts the plaintext data through the Dianhong IoT operating system to obtain ciphertext data; The intelligent gateway terminal sends the ciphertext data to a receiving device communicating with the sub-node; A branch parent node is a node located at a fork of at least two branches in the Internet of Things networking tree, and the child nodes of a branch parent node include different child nodes from at least two branches in the Internet of Things networking tree; The Dianhong IoT operating system includes an application layer and a protocol adaptation layer, and the smart gateway terminal receives plaintext data from a child node of the smart gateway terminal, including: The intelligent gateway terminal receives, through the protocol adaptation layer of the intelligent gateway terminal, plaintext data from the protocol adaptation layer of the child node, wherein the plaintext data includes indication information provided by the application layer of the child node, and the indication information is used to indicate that the plaintext data needs to be encrypted; The smart gateway terminal encrypts the plaintext data through the Dianhong IoT operating system, and the obtained ciphertext data includes: In response to the indication information, the intelligent gateway terminal encrypts the plaintext data through a protocol adaptation layer of the intelligent gateway terminal to obtain the ciphertext data.
Citation Information
Patent Citations
Data encryption sending method and device based on intermediate node
CN113938883A