Privacy Protection Method and System for Encrypted Transmission of Internet of Things Data
Through the combination of data segmentation encoding, elliptic curve encryption and symmetric encryption strategy selection matrix, the problem of high resource consumption of IoT devices is solved, efficient and secure data encryption transmission and privacy protection is achieved, and data processing efficiency and reliability are improved.
Patent Information
- Application Number
- CN202510593725.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-09
AI Technical Summary
When IoT devices conduct data encryption transmission, the calculation complexity of asymmetric encryption algorithms is high, resulting in large resource consumption, affecting device battery life and data processing efficiency. Moreover, traditional encryption methods cannot effectively protect data privacy.
The method of integrating encrypted data and adding header information is used to optimize data processing by combining dynamic encoding and hash function pools to reduce computing resource consumption and improve encryption efficiency.
Implement efficient and secure data encryption transmission and privacy protection on IoT devices with resource-constrained, reduce computing resource consumption, and improve data processing efficiency and transmission reliability.
Smart Images

Figure CN120110811B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things technology, and in particular, to a privacy protection method and system for encrypted transmission of Internet of Things data. Background Art
[0002] The wide application of Internet of Things technology has made the data interaction between a large number of devices increasingly frequent, and the encryption and privacy protection of data during transmission have become key links. Traditional data transmission methods do not effectively encrypt data, and it is extremely easy to be eavesdropped, intercepted and tampered with during network transmission, resulting in the leakage of user privacy and the loss of enterprise confidential information, and unable to meet the high requirements for data security in the Internet of Things era.
[0003] To address this problem, existing Internet of Things systems often use asymmetric encryption algorithms to encrypt data transmission. The asymmetric encryption algorithm uses the mechanism of public key encryption and private key decryption, and there is no need to distribute the decryption key during the transmission process, effectively avoiding the risk of the decryption key being stolen during transmission and significantly improving the security of data transmission.
[0004] However, in the Internet of Things application scenario, the asymmetric encryption algorithm has the problem of high computational complexity. Internet of Things devices usually have limited resources. Especially for some low-power sensor devices, running the asymmetric encryption algorithm will consume a large amount of computational resources and energy, seriously affecting the battery life and data processing efficiency of the devices, and it is difficult to achieve efficient and secure data encryption transmission and privacy protection. Summary of the Invention
[0005] This application provides a privacy protection method and system for encrypted transmission of Internet of Things data, which is used to achieve the privacy protection of the whole process of data from the sender to the receiver, making the Internet of Things data transmission both safe and efficient.
[0006] In a first aspect, the present application provides a privacy protection method for encrypted transmission of Internet of Things data. The method includes: obtaining the original Internet of Things data to be transmitted; splitting the original Internet of Things data into multiple data puzzles according to a preset data splitting rule, and dynamically encoding the multiple data puzzles to obtain a data puzzle sequence; generating a feature code corresponding to the multiple data puzzles according to the data puzzle sequence; obtaining a temporary key based on the elliptic curve encryption algorithm, and obtaining an encrypted feature code after symmetrically encrypting the feature code with the temporary key; constructing an encryption policy selection matrix according to the data puzzle sequence and the encrypted feature code, where the rows of the encryption policy selection matrix represent different symmetric encryption algorithms, the columns represent different combinations of encryption parameters, and the values of the matrix elements are calculated by weighted summation according to the entropy value of the data puzzle sequence and the checksum of the encrypted feature code; encrypting the data puzzle sequence in combination with the encryption policy selection matrix to obtain encrypted data puzzles; assigning an index number corresponding to each encryption policy in the encryption policy selection matrix, and generating index information according to the index number; integrating the encrypted data puzzles, the encrypted feature code, and the index information according to a preset splicing rule to obtain an encrypted data set; adding header information to the encrypted data set and transmitting it to a receiving end, where the header information at least includes the identity identifiers of the sending and receiving devices, the data splitting rule parameters, and the data integrity checksum.
[0007] By adopting the above technical solution, the original data is first obtained, split, and encoded. After generating the feature code, the elliptic curve encryption algorithm is used to obtain a temporary key to encrypt the feature code, avoiding the direct use of complex asymmetric encryption for a large amount of original data and reducing the consumption of computing resources. An encryption policy selection matrix is constructed, and the data puzzle sequence is encrypted in combination with it, which can select a suitable encryption policy according to the data characteristics and improve the encryption efficiency. The encrypted data is integrated and the header information is added for transmission, ensuring the integrity and traceability of data transmission, so as to achieve efficient and secure data encryption transmission and privacy protection on resource-constrained Internet of Things devices.
[0008] In combination with some embodiments of the first aspect, in some embodiments, in the step of splitting the original Internet of Things data into multiple data puzzles according to a preset data splitting rule and dynamically encoding the multiple data puzzles to obtain a data puzzle sequence, it specifically includes: obtaining the current network bandwidth condition, the remaining battery power of the device, and the security level coefficient of the original Internet of Things data, and determining the puzzle size of each data puzzle through weighted calculation; splitting the original Internet of Things data according to the puzzle size to obtain multiple data puzzles; encoding each data puzzle based on a dynamic coding table of chaotic mapping to obtain a data puzzle sequence.
[0009] By adopting the above technical solution, when splitting and encoding data, the size of each data puzzle is dynamically determined by comprehensively considering the current network bandwidth condition, the remaining power of the device, and the security level coefficient of the original IoT data. In this way, the splitting method can be adjusted according to the real-time resources of the device and the data security requirements, avoiding over-splitting or under-splitting. The data puzzles are encoded using a dynamic coding table of chaotic mapping, increasing the randomness and complexity of the data. This process reduces unnecessary calculations. On resource-constrained IoT devices, it not only ensures the rationality of data splitting but also reduces the consumption of computing resources and improves the data processing efficiency.
[0010] In combination with some embodiments of the first aspect, in some embodiments, the step of generating a feature code corresponding to the plurality of data puzzles according to the data puzzle sequence specifically includes: establishing a hash function pool including a plurality of hash functions, and selecting at least two different hash functions from the hash function pool according to the length and data type of the data puzzle sequence according to a preset selection rule; respectively performing hash operations on the data puzzle sequence using the selected hash functions to obtain a plurality of hash values; performing a bitwise exclusive OR operation on the plurality of hash values to generate a feature code corresponding to the plurality of data puzzles.
[0011] By adopting the above technical solution, when generating a feature code, a hash function pool is established and at least two different hash functions are selected according to the length and data type of the data puzzle sequence. The combined use of different hash functions can extract data features more comprehensively, and the bitwise exclusive OR operation further fuses these features, making the generated feature code more representative. Compared with the traditional method of generating a feature code using a single hash function, this method of combining multiple hash functions can reduce the amount of calculation while ensuring the accuracy and security of the feature code. It avoids complex calculations, is suitable for resource-constrained IoT devices, and improves the data processing efficiency and security.
[0012] In combination with some embodiments of the first aspect, in some embodiments, the step of obtaining a temporary key based on the elliptic curve encryption algorithm and obtaining an encrypted feature code by symmetrically encrypting the feature code with the temporary key specifically includes: combining the feature code, the identity identifier of the sending device, the public key of the receiving device, and the current timestamp to generate a temporary key through elliptic curve point multiplication operation; using the temporary key to symmetrically encrypt the feature code to obtain the encrypted feature code.
[0013] By adopting the above technical solution, a temporary key is generated by combining the feature code, the identity identifier of the sending device, the public key of the receiving device, and the current timestamp, which increases the randomness and timeliness of the key. The elliptic curve point multiplication operation is relatively simple, which reduces the computational complexity while ensuring the security of the key. The feature code is symmetrically encrypted using the temporary key, and the symmetric encryption algorithm has a fast calculation speed and low resource consumption. Compared with directly using asymmetric encryption for a large amount of raw data, this method can significantly reduce the consumption of computing resources and energy on resource-constrained Internet of Things devices, achieving efficient and secure data encryption.
[0014] In combination with some embodiments of the first aspect, in some embodiments, the step of encrypting the data puzzle sequence in combination with the encryption policy selection matrix to obtain the encrypted data puzzle specifically includes: selecting the symmetric encryption algorithm and parameter combination corresponding to the element with the largest value from the encryption policy selection matrix as the encryption policy for the data puzzle sequence; combining the feature code and encrypting the data puzzle sequence according to the encryption policy to obtain the encrypted data puzzle.
[0015] By adopting the above technical solution, selecting the encryption policy corresponding to the element with the largest value from the encryption policy selection matrix can automatically select the most suitable symmetric encryption algorithm and parameter combination according to the entropy value of the data puzzle sequence and the checksum of the encrypted feature code. Encrypting in combination with the feature code further ensures the accuracy and security of the encryption. This method avoids trying all encryption policies, reduces unnecessary calculations, and can quickly determine the best encryption policy on resource-constrained Internet of Things devices, improving the encryption efficiency and achieving efficient and secure data encryption and transmission.
[0016] In combination with some embodiments of the first aspect, in some embodiments, after the step of adding header information to the encrypted data set and transmitting it to the receiving end, the method further includes: obtaining the verification information sent by the receiving end, where the verification information at least includes verifying whether the identity identifiers of the sending and receiving devices match the preset information; if the verification passes, extracting the data integrity check code from the encrypted data set; combining the data integrity check code and performing a data integrity check on the encrypted data set to determine the data integrity of the encrypted data set.
[0017] By adopting the above technical solution, after adding header information and transmitting, obtaining the verification information from the receiving end and verifying the identity identifiers of the sending and receiving devices ensures the legality of data transmission. If the verification passes, extracting the data integrity check code for data integrity check can timely detect whether the data has been tampered with during transmission. This verification and check mechanism ensures the security and integrity of the data without adding too much computational burden. On resource-constrained Internet of Things devices, it effectively monitors the data transmission process at a low computational cost, improving the reliability of data transmission.
[0018] In combination with some embodiments of the first aspect, in some embodiments, after the step of performing data integrity verification on the encrypted data set by combining the data integrity verification code to determine the data integrity of the encrypted data set, the following steps are further included: If the data integrity verification is passed, the receiving end is controlled to decrypt the encrypted feature code by using the private key and the elliptic curve encryption algorithm to obtain the feature code; Restore the encryption policy selection matrix according to the index information, and determine the encryption policy corresponding to the encrypted data puzzle from the matrix in combination with the feature code; Decrypt the encrypted data puzzle according to the encryption policy to obtain the data puzzle sequence; Decode the data puzzle sequence to obtain the multiple data puzzles; Stitch the multiple data puzzles according to a preset data segmentation rule to obtain the original Internet of Things data. If the data integrity verification fails, record the exception information.
[0019] By adopting the above technical solution, if the data integrity verification is passed, the receiving end decrypts the encrypted feature code by using the private key and the elliptic curve encryption algorithm. The elliptic curve encryption algorithm is simple to calculate and can quickly decrypt to obtain the feature code. Restore the encryption policy selection matrix according to the index information, determine the encryption policy in combination with the feature code, then decrypt the encrypted data puzzle, and finally restore the original data. If the verification fails, record the exception information to facilitate subsequent problem troubleshooting. The entire process completes data decryption and restoration in an efficient manner on resource-constrained Internet of Things devices, while ensuring data security and traceability, and realizing efficient and secure data encryption transmission and privacy protection.
[0020] In a second aspect, the present application provides a privacy protection system, which includes: one or more processors and a memory; The memory is coupled to the one or more processors, and the memory is used to store computer program code, and the computer program code includes computer instructions. The one or more processors call the computer instructions to cause the privacy protection system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0021] In a third aspect, the present application provides a computer-readable storage medium, including instructions, when the instructions run on the privacy protection system, causing the privacy protection system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0022] In a fourth aspect, the present application provides a computer program product, when the computer program product runs on the privacy protection system, causing the privacy protection system to execute the method described in the first aspect and any possible implementation manner in the first aspect.
[0023] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0024] 1. Due to the adoption of technical means such as splitting and encoding the original Internet of Things data, generating feature codes, obtaining a temporary key using the elliptic curve encryption algorithm to encrypt the feature codes, constructing an encryption policy selection matrix for encryption, integrating the encrypted data and adding header information for transmission, etc., effectively solves the problems in the prior art of high computational complexity, large consumption of computational resources and energy by Internet of Things devices running asymmetric encryption algorithms, and affecting the battery life and data processing efficiency of the devices. Furthermore, it achieves the technical effect of efficiently and securely performing data encryption transmission and privacy protection on resource-constrained Internet of Things devices.
[0025] 2. Due to the adoption of technical means such as determining the size of the data puzzle by comprehensively considering the network bandwidth, device power, and data security level coefficient, and encoding the data puzzle using the dynamic coding table of chaotic mapping, effectively solves the problem of waste of computational resources caused by unreasonable data segmentation in the prior art. Furthermore, it achieves the technical effect of reasonably segmenting data, reducing computational resource consumption, and improving data processing efficiency on resource-constrained Internet of Things devices.
[0026] 3. Due to the adoption of technical means such as selecting the best encryption policy from the encryption policy selection matrix and encrypting the data puzzle sequence in combination with the feature code, effectively solves the problem of waste of computational resources caused by blindly trying encryption policies in the prior art. Furthermore, it achieves the technical effect of quickly determining the best encryption policy, improving the encryption efficiency, and ensuring the secure transmission of data on resource-constrained Internet of Things devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a schematic flowchart of a privacy protection method for Internet of Things data encryption transmission in an embodiment of the present application;
[0028] Figure 2 is another schematic flowchart of a privacy protection method for Internet of Things data encryption transmission in an embodiment of the present application;
[0029] Figure 3 is a schematic structural diagram of an entity device of a privacy protection system in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular forms "a", "an", "the", "above", "said", "this" are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to and includes any or all possible combinations of one or more of the listed items.
[0031] Hereinafter, the terms "first" and "second" are for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more.
[0032] For ease of understanding, the method provided in this embodiment will be described in terms of a process below. Please refer to Figure 1 , which is a schematic flowchart of a privacy protection method for encrypted transmission of Internet of Things data in an embodiment of the present application.
[0033] S101. Obtain the original Internet of Things data to be transmitted;
[0034] The privacy protection system will first connect through interfaces with various Internet of Things devices to obtain the original Internet of Things data to be transmitted. In the Internet of Things environment, there are a wide variety of device types, and data formats and transmission protocols vary. To successfully obtain the original data, the system needs to have broad compatibility.
[0035] For sensor devices, the system will establish corresponding communication links according to their communication protocols, such as common ones like Modbus, ZigBee, etc. Taking the ZigBee protocol as an example, the communication module in the system will set specific channels and PANIDs (Personal Area Network Identifiers) to pair with the sensors. Once the connection is successful, the sensors will send the collected data to the privacy protection system at preset time intervals or trigger conditions. For devices such as smart home appliances, the system may obtain data through a home network (such as Wi-Fi, Bluetooth). Taking a smart refrigerator as an example, it may send internal temperature, food storage information, etc. to the home network via Wi-Fi. The privacy protection system will obtain the data sent by the smart refrigerator by connecting to the home router. In addition, for some industrial devices, more complex communication protocols may be used, such as OPC UA (Open Platform Communications Unified Architecture). The privacy protection system needs to configure the corresponding OPC UA client to connect to the OPC UA server of the industrial device. During the connection process, identity authentication and permission management are required to ensure that only authorized systems can obtain device data. The system will subscribe to relevant data nodes of the device according to the OPC UA protocol specification. When the device data changes, the system can receive the updated data in a timely manner and perform parsing and storage.
[0036] S102. Divide the original Internet of Things data into multiple data puzzles according to a preset data splitting rule, and perform dynamic encoding on the multiple data puzzles to obtain a data puzzle sequence;
[0037] The privacy protection system first obtains the current network bandwidth status, the remaining battery power of the device, and the security level coefficient of the original Internet of Things data to determine the size of each data puzzle. The system obtains the network bandwidth status in real time through the network monitoring module, which uses network traffic monitoring technology to collect real-time data of the network bandwidth at regular intervals by listening to the data transmission rate of the network interface, with the unit of Mbps (megabits per second). For the remaining battery power of the device, the system obtains relevant information according to the device type and hardware interface. For example, for Internet of Things devices powered by batteries, the system obtains parameters such as the voltage and current of the battery through the battery power monitoring chip, and then converts these parameters into a percentage value of the remaining battery power according to the characteristic curve of the battery. The security level coefficient of the original data is set during the data collection or configuration phase, and the system obtains this coefficient from the device's configuration file or management platform, and its value range can be set from 1 to 5, where the larger the number, the higher the security level.
[0038] After obtaining the above information, the system determines the size of each data puzzle through weighted calculation. Set the weight of the network bandwidth status as and the weight of the remaining battery power of the device as and the weight of the security level coefficient as , and . For example, = 0.4, = 0.3, = 0.3. The formula for calculating the puzzle size is: Puzzle size = (Network bandwidth status × + Remaining battery power of the device × + Security level coefficient × ) × Reference value, where the reference value is a constant set according to the system experience and is used to convert the calculation result into an appropriate number of bytes. Assume the reference value is 100 bytes. Through such calculation, the system can dynamically adjust the size of each data puzzle according to the real-time resources of the device and the data security requirements.
[0039] After determining the puzzle size, the system divides the original Internet of Things data. If the original data is in the form of a byte stream, the system starts from the starting position of the byte stream and sequentially intercepts byte blocks of the corresponding length as a data puzzle according to the determined puzzle size. During the division process, the system records information such as the starting position and length of each data puzzle in the original data, and these information will be used for subsequent data restoration.
[0040] Next, the system encodes each data puzzle based on the dynamic coding table of chaotic mapping. The system uses the chaotic mapping algorithm to generate the dynamic coding table. Taking the Logistic mapping as an example, its formula is , where is a control parameter, and its value range is usually between (3.5699456, 4). is the current iteration value. The system will determine the initial value according to some random factors, such as system time, device ID, etc. and the control parameter , and generate a chaotic sequence by iterating the Logistic mapping formula multiple times.
[0041] The system encodes the chaotic sequence and the data puzzle. Assume that the data puzzle consists of N bytes, and the chaotic sequence also generates N corresponding values (map the values of the chaotic sequence to the byte value range of 0 - 255). For each byte in the data puzzle (i = 1, 2,..., N), the system performs an exclusive OR operation on it with the corresponding byte in the chaotic sequence to obtain the encoded byte . After such an operation, the encoding of the entire data puzzle is completed. Combine all the encoded bytes to obtain the data puzzle sequence. This dynamic encoding method based on chaotic mapping makes full use of the randomness and unpredictability of the chaotic sequence, increases the security of the data. At the same time, since the calculation of the chaotic mapping algorithm is relatively simple, it is suitable for resource - constrained Internet of Things devices and effectively reduces the consumption of computing resources.
[0042] S103. Generate a feature code corresponding to the multiple data puzzles according to the data puzzle sequence;
[0043] When the privacy protection system executes this step, it first establishes a hash function pool containing multiple hash functions. The hash function pool is a functional module of the system, which integrates various common hash functions, such as MD5, SHA - 256, SHA - 512, etc. These hash functions are loaded into the hash function pool during the system initialization phase, and the system assigns a unique identifier to each hash function for subsequent calls according to requirements.
[0044] The system selects at least two different hash functions from the hash function pool according to the length and data type of the data puzzle sequence. The system will count the length of the data puzzle sequence in bytes. At the same time, the system determines its data type by analyzing the content characteristics of the data puzzle sequence, such as text type, numerical type, image type, etc. The system formulates a preset selection rule. When the length of the data puzzle sequence is less than 1024 bytes and it is of text type, select MD5 and SHA - 256 hash functions; when the length is greater than or equal to 1024 bytes and it is of numerical type, select SHA - 256 and SHA - 512 hash functions. Such a selection rule is formulated based on the characteristics and applicable scenarios of different hash functions. Shorter data is suitable for hash functions with faster calculation speed, while longer data requires hash functions with higher security.
[0045] After selecting the hash functions, the system uses these hash functions to perform hash operations on the data puzzle sequence respectively. Taking the MD5 hash function as an example, it groups the data puzzle sequence into 512-bit (64-byte) chunks. If the data length is not an integer multiple of 512 bits, padding is required. The padding method is to add a 1 at the end of the data, and then add several 0s until the data length meets the multiple of 512 bits. Then, MD5 performs a series of complex bit operations on each chunk, including circular left shift, exclusive OR, AND, OR, etc. After four rounds of operations, a 128-bit hash value is generated. For the SHA-256 hash function, it also pads the data to make its length a multiple of 512 bits. Then, SHA-256 performs multiple rounds of compression function operations. Each round of operation involves bit operations on the data and the use of constants. Finally, a 256-bit hash value is generated. The system will record the hash values generated by each hash function.
[0046] The system performs a bitwise exclusive OR operation on multiple hash values to generate a feature code corresponding to multiple data puzzles. Suppose n hash functions (n≥2) are used to perform hash operations on the data puzzle sequence, and the obtained hash values are respectively , ,...., . The system converts these hash values into binary form, and then performs an exclusive OR operation bit by bit starting from the lowest bit. For example, for two hash values and , if the lowest bit of is 0 and the lowest bit of is 1, then the lowest bit of the exclusive OR result is 1. In this way, an exclusive OR operation is performed on each bit of all hash values. Finally, a new binary sequence is obtained. Converting it into an appropriate encoding form (such as hexadecimal) gives the feature code corresponding to multiple data puzzles. This method of generating feature codes by combining multiple hash functions can extract the features of the data puzzle sequence from multiple dimensions. Compared with a single hash function, the generated feature code is more representative and secure. At the same time, by reasonably selecting hash functions and optimizing the operation process, the computational complexity is reduced, meeting the operating requirements of resource-constrained IoT devices.
[0047] S104. Obtain a temporary key based on the elliptic curve encryption algorithm, and after symmetrically encrypting the feature code with the temporary key, obtain an encrypted feature code;
[0048] When the privacy protection system executes step S104, it will first combine the feature code, the identity identifier of the sending device, the public key of the receiving device, and the current timestamp to generate a temporary key through elliptic curve point multiplication operation. The identity identifier of the sending device is stored in the system. This is a unique identifier assigned and registered when the device accesses the Internet of Things system. Usually, it is a string of codes in a specific format, such as containing device type, manufacturer information, and device serial number, etc., for accurately identifying the identity of the sending device.
[0049] The public key of the receiving device is obtained in advance through a secure key exchange mechanism. For example, a certificate-based key exchange method can be adopted. The public key of the receiving device is digitally signed and authenticated by an authoritative certification authority (CA). When the privacy protection system receives the public key, it will verify the digital signature of the CA to ensure the authenticity and legality of the public key. The current timestamp is obtained from the system clock, accurate to the millisecond level, to ensure the accuracy and uniqueness of time.
[0050] The system combines the feature code, the identity identifier of the sending device, the public key of the receiving device, and the current timestamp. Specifically, these information will be encoded in a specific format to form a unified input data block. For example, first encode the identity identifier of the sending device in binary, then concatenate the binary representation of the current timestamp, then concatenate the binary data of the public key of the receiving device, and finally concatenate the binary content of the feature code, so as to obtain a complete binary data stream.
[0051] Based on the principle of the elliptic curve encryption algorithm, the system will select a suitable elliptic curve. Common elliptic curves include secp256k1, etc., which define the parameters of the curve, including the size of the finite field, the coefficients of the curve equation, etc. After selecting the elliptic curve, the system uses the combined input data block as the input parameter of the elliptic curve point multiplication operation. The elliptic curve point multiplication operation is usually expressed as kP, where k is a large integer generated by the input data block through a specific hash function or key derivation function, and P is a base point on the elliptic curve. The system will use a secure hash function, such as SHA-256, to perform a hash operation on the combined input data block to obtain a 256-bit hash value, and then convert this hash value into a large integer k. The base point P is a special point predefined on the elliptic curve. Through the elliptic curve point multiplication operation, the system finally generates a temporary key.
[0052] After generating the temporary key, the system uses this temporary key to symmetrically encrypt the feature code to obtain the encrypted feature code. The system will select an efficient symmetric encryption algorithm, such as AES (Advanced Encryption Standard). The AES algorithm supports multiple key lengths, such as 128 bits, 192 bits, and 256 bits, etc. The system selects an appropriate AES key length according to the length of the temporary key and the actual requirements. Assuming the temporary key length is 256 bits, the system selects the AES-256 algorithm for encryption.
[0053] During the encryption process, the system groups the feature code according to the requirements of the AES algorithm. The block length of the AES algorithm is fixed at 128 bits. If the length of the feature code is not an integer multiple of 128 bits, padding is required. The padding method can use PKCS7 padding, that is, several bytes are filled at the end of the feature code, and the value of each byte is equal to the number of bytes to be filled. For example, if the feature code length is 200 bits and 48 bits need to be filled, then the filled content is to add 3 bytes with a value of 0x03 after the feature code.
[0054] The system uses the temporary key and the selected AES algorithm to encrypt the grouped feature code. The AES algorithm performs encryption processing on each block through multiple rounds of complex transformations, including byte substitution, row shift, column mixing, and round key addition operations. After multiple rounds of encryption, all the encrypted blocks are combined to obtain the encrypted feature code. This encryption method uses the elliptic curve encryption algorithm to generate the temporary key and combines the symmetric encryption algorithm to encrypt the feature code, which not only ensures the security and randomness of the key but also improves the encryption efficiency, meeting the encryption requirements of resource-constrained devices in the Internet of Things.
[0055] S105. Construct an encryption policy selection matrix according to the data puzzle sequence and the encrypted feature code. The rows of the encryption policy selection matrix represent different symmetric encryption algorithms, the columns represent different combinations of encryption parameters, and the values of the matrix elements are calculated by weighted summation according to the entropy value of the data puzzle sequence and the checksum of the encrypted feature code;
[0056] When the privacy protection system constructs the encryption policy selection matrix, it first needs to calculate the entropy value of the data puzzle sequence. The entropy value is an index used to measure the uncertainty or chaos degree of data. The higher the entropy value, the stronger the randomness of the data. The system processes the data puzzle sequence through a specific entropy calculation algorithm. Taking the data puzzle sequence in the form of a byte stream as an example, the system will count the frequency of each byte value in the sequence. Assuming the data puzzle sequence consists of a large number of bytes, the system traverses the entire sequence and records the number of occurrences of each byte (0 - 255). Then according to the information entropy calculation formula , where is the frequency of occurrence of the i-th byte value, and the entropy value of the data puzzle sequence is calculated. This entropy value reflects the inherent randomness and complexity of the data puzzle sequence.
[0057] For the checksum calculation of the encrypted feature code, the system adopts an efficient checksum algorithm, such as the Cyclic Redundancy Check (CRC) algorithm. The system divides the encrypted feature code into groups of a certain length. For example, the common CRC-32 algorithm divides the data into groups of 32 bits. The system performs specific bit operations on each group of data and calculates a checksum value through polynomial division. During the calculation process, the system initializes a checksum register and inputs the encrypted feature code bit by bit for calculation. Each time a bit of data is input, the value of the checksum register is updated according to the specific CRC polynomial rule, and finally the checksum of the entire encrypted feature code is obtained.
[0058] After obtaining the entropy value of the data puzzle sequence and the checksum of the encrypted feature code, the system starts to construct an encryption policy selection matrix. The system pre-sets different symmetric encryption algorithms, such as AES, DES, 3DES, etc., and sets different encryption parameter combinations for each algorithm. For example, for the AES algorithm, the encryption parameter combinations can include different key lengths (128 bits, 192 bits, 256 bits), different encryption modes (CBC, ECB, CTR, etc.), and different padding methods.
[0059] The system performs a weighted sum of the entropy value and the checksum according to the preset weights. Assume the weight of the entropy value of the data puzzle sequence is and the weight of the checksum of the encrypted feature code is and . The system determines the value of the matrix element by calculating where Value is the value of the matrix element, Entropy is the entropy value of the data puzzle sequence, and Checksum is the checksum of the encrypted feature code. In this way, the system can construct a complete encryption policy selection matrix. Each element in the matrix comprehensively considers the characteristics of the data puzzle sequence and the checksum information of the encrypted feature code, providing a basis for selecting an appropriate encryption policy in the future.
[0060] S106. Encrypt the data puzzle sequence in combination with the encryption policy selection matrix to obtain an encrypted data puzzle;
[0061] When the privacy protection system encrypts the data puzzle sequence in combination with the encryption policy selection matrix, it first selects the symmetric encryption algorithm and parameter combination corresponding to the element with the largest value from the encryption policy selection matrix as the encryption policy. The system traverses the entire encryption policy selection matrix and finds the maximum value by comparing the values of the matrix elements. Assume that a certain element in the matrix The value is the largest, where i represents the row (corresponding to different symmetric encryption algorithms) and j represents the column (corresponding to different combinations of encryption parameters). Then the system selects the i-th symmetric encryption algorithm and the j-th combination of encryption parameters to encrypt the data puzzle sequence.
[0062] After determining the encryption strategy, the system encrypts the data puzzle sequence in combination with the feature code. Taking the selection of the AES algorithm with the CBC (Cipher Block Chaining) encryption mode as an example, the system first uses the feature code as the initialization vector. In the CBC mode, each data block needs to be XORed with the previous ciphertext block before encryption, and the first data block is XORed with the initialization vector. The system divides the data puzzle sequence according to the block length (128 bits) of the AES algorithm.
[0063] If the length of the data puzzle sequence is not an integer multiple of 128 bits, the system will use an appropriate padding method, such as PKCS7 padding. After padding, the system starts from the first data block, XORs it with the feature code (used as the initialization vector), and then encrypts the XOR result using the selected AES algorithm and key to obtain the first ciphertext block. Then, for subsequent data blocks, the system XORs the previous ciphertext block with the current data block and then encrypts it using the AES algorithm and key, and so on until the encryption of the entire data puzzle sequence is completed to obtain the encrypted data puzzle. This encryption method that combines the encryption strategy selection matrix and the feature code can select the optimal encryption strategy according to the characteristics of the data, improving the efficiency and security of encryption.
[0064] S107. Assign an index number to each encryption strategy in the encryption strategy selection matrix and generate index information based on the index number;
[0065] When the privacy protection system assigns an index number to each encryption strategy in the encryption strategy selection matrix, it first numbers each row (corresponding to different symmetric encryption algorithms) and each column (corresponding to different combinations of encryption parameters) in the matrix. The system starts from 0 and assigns numbers to the rows and columns in sequence. For example, for a matrix containing 3 symmetric encryption algorithms (AES, DES, 3DES) and 4 combinations of encryption parameters, the row numbers are 0, 1, 2 in sequence, and the column numbers are 0, 1, 2, 3 in sequence.
[0066] The system determines the index number of each encryption strategy through the combination of the row number and the column number. Suppose the row number corresponding to a certain encryption strategy is i and the column number is j, then the index number of this encryption strategy can be expressed as Index = i × n + j, where n is the total number of columns. In this way, each encryption strategy has a unique index number.
[0067] After generating the index numbers, the system generates index information based on these index numbers. The index information is a data structure that contains the correspondence between encryption policies and index numbers. The system creates an index table, and each row in the table records the index number of an encryption policy, the name of the corresponding symmetric encryption algorithm, and a detailed description of the encryption parameter combination. For example, for the encryption policy with index number 5, it is recorded in the index table as: index number 5, the symmetric encryption algorithm is AES, and the encryption parameter combination is a key length of 256 bits, an encryption mode of CTR, and a padding method of PKCS7. The system serializes the index information for easy storage and transmission. Serialization can use various formats such as JSON, XML, etc. Taking the JSON format as an example, the system converts the index table into a JSON string. In this way, during subsequent data transmission and decryption, the receiving end can quickly restore the encryption policy selection matrix based on the index information, determine the corresponding encryption policy, and achieve the correct decryption of the encrypted data puzzle.
[0068] S108. Integrate the encrypted data puzzle, the encrypted feature code, and the index information according to a preset splicing rule to obtain an encrypted data set;
[0069] When the privacy protection system performs the integration operation, it will first clarify the preset splicing rule. This rule is determined during the system design phase, and its purpose is to ensure that the encrypted data puzzle, the encrypted feature code, and the index information can be combined in an orderly and recognizable manner, facilitating the receiving end to parse and process.
[0070] For the encrypted data puzzle, the system will arrange it in the order of generation. When the system generates the encrypted data puzzle, it will assign a sequence identifier to each puzzle, such as an incrementing numerical number starting from 0. During integration, according to these numbers, the encrypted data puzzles are arranged in sequence. At the same time, to facilitate the distinction of different puzzles, the system will also add specific identification information, such as the length information of the puzzle, at the beginning or end of each puzzle, so that the receiving end can accurately know the boundaries of each puzzle when parsing.
[0071] For the encrypted feature code, the system will place it after the encrypted data puzzle sequence. To ensure the integrity and accuracy of the encrypted feature code, the system will add a header identifier with a fixed length before the encrypted feature code, which is used to indicate that this part of the data is the encrypted feature code. The header identifier can contain key information such as the length information of the encrypted feature code and the type of encryption algorithm used. In this way, after receiving the data, the receiving end can quickly locate and accurately parse the encrypted feature code.
[0072] The integration of index information also follows specific rules. The system will serialize the index information and convert it into a byte stream form. During the serialization process, the system will, in the order recorded in the index table, sequentially convert the index number of each encryption policy, the corresponding symmetric encryption algorithm name, the description of the encryption parameter combination, and other information into byte sequences. Then, a header identifier for the index information is added before the serialized index information to identify that this part of the data is index information and contains metadata such as the total length of the index information.
[0073] After completing the processing of the encrypted data puzzle, the encrypted feature code, and the index information, the system concatenates them in sequence. When concatenating, the system will ensure that there is no data loss or overlap between the data parts. After concatenation, the system will perform an integrity check on the integrated encrypted data set to ensure that no errors occur during the integration process. The system can use the hash check method to perform a hash operation on the entire encrypted data set to obtain a hash value and compare this hash value with the expected hash value. If the two are consistent, it means that the integrated encrypted data set is complete and error-free; if they are inconsistent, the system will recheck the integration process to find and correct possible errors.
[0074] S109. Add header information to the encrypted data set and transmit it to the receiving end. The header information includes at least the identity identifiers of the sending and receiving devices, the data segmentation rule parameters, and the data integrity verification code.
[0075] When the privacy protection system adds header information, it will obtain the identity identifiers of the sending device and the receiving device. The sending device identity identifier is the unique identifier assigned and registered when the device accesses the Internet of Things system and is stored in the device information database of the system. The system directly reads it from the database. The receiving device identity identifier is determined during the target setting stage of data transmission and is stored in the relevant configuration file or database. The system obtains it from the corresponding location. For the data segmentation rule parameters, the system will organize the parameter information used in the data segmentation stage, such as the network bandwidth status, the remaining battery power of the device, the weight of the security level coefficient, and the reference value involved in determining the size of the data puzzle. The system serializes these parameters and converts them into a byte stream form. During the serialization process, to ensure that the receiving end can accurately parse, the system will add corresponding identifiers to each parameter to explain the meaning represented by the parameter.
[0076] Calculating the data integrity check code is crucial in this step. The system adopts a reliable check algorithm, such as the Cyclic Redundancy Check (CRC) algorithm. The system takes the encrypted data set as input and calculates it through the CRC algorithm. During the calculation process, the system divides the encrypted data set into groups according to a specific length, performs specific bit operations on each group of data, and generates a checksum value through polynomial division. This checksum value is the data integrity check code.
[0077] Next, the system combines the receiving device identity identifier, the serialized data segmentation rule parameters, and the data integrity check code into the header information. When combining, the system also adds corresponding identifiers to each part of the header information to clarify the meaning and boundary of each part. For example, an identifier is added before the sending device identity identifier to indicate that this is the identity information of the sending device, and an identifier is added before the data segmentation rule parameters to explain the type and length of the parameters, etc.
[0078] After completing the construction of the header information, the system adds the header information to the beginning of the encrypted data set. When adding, the system ensures that the connection between the header information and the encrypted data set is tight and accurate, without data loss or incorrect connection. In the transmission link, the system will select a suitable transmission method according to the current network environment and the communication capabilities of the device. If the device supports wireless communication and the network signal is good, the system may choose wireless communication protocols such as Wi-Fi, Bluetooth, or ZigBee for transmission. When using these protocols, the system will perform corresponding encapsulation and modulation on the data to make it meet the specification requirements of the protocol.
[0079] In some embodiments, after adding the header information and transmitting the encrypted data set to the receiving end, the privacy protection system will continuously monitor the feedback from the receiving end. When obtaining the verification information sent by the receiving end, the system first checks whether the sending and receiving device identity identifiers in it match the preset information. The device identity identifier has been registered and stored when the device accesses the system. The system confirms by comparing each bit of the identifier in the verification information with the preset identifier stored locally. If the device identity identifier does not match, the system will immediately interrupt the data transmission, issue an alarm, and record the abnormality. If the verification passes, the system will locate the storage location of the data integrity check code according to the identifier in the header information and accurately extract it. Before sending the data, the system has calculated the encrypted data set with a specific check algorithm to obtain a check code. When the receiving end verifies, the system will recalculate the received encrypted data set with the same algorithm to obtain a new check code. Compare the new check code with the extracted check code. If they are the same, it indicates that the data has not changed during transmission and the integrity is guaranteed; if they are different, the system will require the receiving end to resend the verification information or resend the data to ensure the data integrity.
[0080] In the embodiments of the present application, since a series of technical means are adopted, starting from obtaining the original Internet of Things data, sequentially performing data segmentation and encoding, generating feature codes, elliptic curve encryption combined with symmetric encryption, constructing an encryption policy selection matrix for encryption, integrating encrypted data and adding header information for transmission, and subsequent verification and integrity check, etc., the advantages of different encryption algorithms and data processing methods can be fully utilized to ensure the security and integrity of data in each link. This effectively solves the problems in the prior art that data transmission is easily eavesdropped, intercepted, and tampered with, and that the operation of complex encryption algorithms by Internet of Things devices causes excessive consumption of computing resources and energy. Furthermore, it realizes the technical effect of efficiently and securely performing data encryption transmission and privacy protection in a resource-constrained Internet of Things environment, while improving data transmission efficiency, traceability, and accuracy.
[0081] After combining the above content, the following further and more specific process description of the method provided in this embodiment will be given. Please refer to Figure 2 , which is another process schematic diagram of the privacy protection method for Internet of Things data encryption transmission in the embodiments of the present application.
[0082] S201. If the data integrity check is passed, control the receiving end to decrypt the encrypted feature code using the private key and the elliptic curve encryption algorithm to obtain the feature code;
[0083] When the privacy protection system confirms that the data integrity check is passed, it starts to perform the decryption operation on the encrypted feature code. The system first obtains the private key of the receiving device from the key storage area of the receiving end. In the Internet of Things environment, the private key is usually securely stored in the encrypted storage module of the device to prevent leakage. The privacy protection system reads the stored private key through a specific key reading interface according to the preset secure access rules.
[0084] At the same time, the system calls the decryption module of the elliptic curve encryption algorithm. Based on the mathematical properties of the elliptic curve, this module decrypts the encrypted feature code. The system takes the encrypted feature code and the obtained private key as the input parameters of the decryption module. During the decryption process, the system will perform a series of mathematical operations on the encrypted feature code according to the rules of the elliptic curve encryption algorithm. These operations involve point operations and inverse operations on the elliptic curve, etc. Through these operations, the original feature code is gradually restored.
[0085] During the operation process, the system will perform calculations and verifications of multiple intermediate results to ensure the accuracy of decryption. Each intermediate result of the operation will undergo strict verification. If any abnormality is found, the system will immediately stop the decryption operation and perform error handling.
[0086] S202. Restore the encryption policy selection matrix according to the index information, and determine the encryption policy corresponding to the encrypted data puzzle from the matrix in combination with the feature code;
[0087] After the privacy protection system obtains the decrypted feature code, it starts to restore the encryption policy selection matrix according to the index information. The index information is generated and transmitted at the sending end and contains the key structure and element information of the encryption policy selection matrix. The system first parses the received index information, extracts the row and column number information of the matrix from it, as well as the name of the symmetric encryption algorithm and the description of the encryption parameter combination corresponding to each encryption policy.
[0088] Based on this information, the system reconstructs the structure of the encryption policy selection matrix. For each encryption policy corresponding to an index number, the system fills the corresponding position of the matrix according to the parsed information. For example, determine the symmetric encryption algorithm corresponding to each row in the matrix and the encryption parameter combination corresponding to each column. During the filling process, the system will perform data type and format verification to ensure the accuracy of the matrix elements.
[0089] After completing the matrix restoration, the system determines the encryption policy corresponding to the encrypted data puzzle from the matrix in combination with the feature code. The system will recalculate the entropy value of the data puzzle sequence again (if the previous entropy value calculation information is not completely retained), and at the same time recalculate the checksum of the encrypted feature code. Then, according to the preset weighted summation rule, calculate the value of each element in the matrix. By comparing these values, the system finds the element with the largest value, and the symmetric encryption algorithm and parameter combination corresponding to this element are the encryption policy corresponding to the encrypted data puzzle. This encryption policy will be used for subsequent decryption operations on the encrypted data puzzle to ensure that the data puzzle sequence can be accurately restored.
[0090] S203. Decrypt the encrypted data puzzle according to the encryption policy to obtain the data puzzle sequence;
[0091] After determining the encryption policy, the privacy protection system starts the decryption operation on the encrypted data puzzle to obtain the data puzzle sequence. If the AES algorithm is selected for the encryption policy, the system first identifies the encryption mode of the encrypted data puzzle, such as CBC, ECB or CTR, etc. According to different encryption modes, the system adopts the corresponding decryption process. For the CBC mode, the system will first extract the initialization vector in the encrypted data puzzle (acted as by the feature code during encryption). Then, according to the decryption rules of the AES algorithm, decrypt each encrypted data block in turn. During the decryption process, the system uses the previously determined key to perform inverse operations on the encrypted data block, including inverse operations such as byte substitution, row shift, column confusion and round key addition. After decrypting each data block, the system will perform an exclusive OR operation on it with the previous decrypted data block (for the first data block, it is the initialization vector) to obtain the decrypted intermediate data block. After decrypting and performing exclusive OR operations on all encrypted data blocks, the system obtains the complete data puzzle sequence.
[0092] During the decryption process, the system will conduct strict verification on each decryption step to ensure the accuracy of decryption. For example, it checks whether the length of the decrypted data block meets the expectation, and whether the decryption result conforms to the requirements of data type and format. If any error is found during the decryption process, the system will record the error information and attempt error recovery operations, such as re-obtaining the encrypted data puzzle pieces or re-determining the encryption strategy.
[0093] S204. Decode the data puzzle sequence to obtain multiple data puzzle pieces;
[0094] After obtaining the data puzzle sequence, the privacy protection system needs to decode it to restore multiple data puzzle pieces. The system first identifies the encoding method adopted by the data puzzle sequence, which is dynamic encoding based on chaotic mapping in this solution. The system regenerates the chaotic mapping sequence according to the same rules for generating the dynamic encoding table before. This requires the system to obtain the initial value and control parameters used to generate the chaotic sequence before (this information can be obtained from the header information transmitted by the sender or other relevant configurations).
[0095] The system decodes each byte in the data puzzle sequence according to the reverse process of dynamic encoding. For the data puzzle pieces encoded by XOR operation, the system performs XOR operation on the encoded byte and the corresponding byte of the chaotic sequence again. Through such operations, the system gradually restores the original data puzzle pieces. During the decoding process, the system will split the decoded byte stream into multiple data puzzle pieces according to the boundary information of the data puzzle pieces (recorded and transmitted during data segmentation).
[0096] During the decoding and splitting process, the system will conduct integrity and accuracy verification on each data puzzle piece. For example, it checks whether the length of the data puzzle piece is consistent with the previously recorded one, and whether the decoded data conforms to the format requirements of the original data. If any abnormality is found, the system will mark the data puzzle piece and attempt to recover it through other means, such as obtaining it from the backup data or requesting the sender to re-transmit the relevant data.
[0097] S205. Stitch multiple data puzzle pieces together according to the preset data segmentation rules to obtain the original Internet of Things data;
[0098] After obtaining multiple data puzzle pieces, the privacy protection system stitches the data according to the preset data segmentation rules to restore the original Internet of Things data. The system reads the data segmentation rules recorded during the data segmentation stage from the storage module. These rules contain key information such as the starting position and length of each data puzzle piece in the original data.
[0099] Based on this information, the system arranges the data puzzle pieces in the correct order. It creates a buffer for storing the original data and then writes each data puzzle piece into the buffer in sequence according to its starting position in the original data. During the writing process, the system checks whether the boundaries of each data puzzle piece are accurate to ensure that there is no overlap or gap in the splicing between data puzzle pieces. If the boundary information of a certain data puzzle piece is found to be abnormal, the system will re-check the index information and data segmentation rules and, if necessary, request the sender to re-transmit the relevant data puzzle piece to ensure the accuracy of splicing.
[0100] After completing the writing of the data puzzle pieces, the system performs integrity and consistency verification on the spliced original data. It adopts corresponding verification methods according to the characteristics and types of the original data. For structured data, such as data with a fixed format collected by sensors, the system checks whether the structure of the data is complete and whether the values of each field are within a reasonable range; for unstructured data, such as text data, the system verifies the integrity of the data by calculating the hash value of the data and comparing it with the hash value calculated by the sender before transmission. If the verification passes, the system successfully restores the accurate original data of the Internet of Things.
[0101] S206. If the data integrity verification fails, record the abnormal information.
[0102] When the privacy protection system performs data integrity verification and finds that the data integrity verification fails, it will immediately start the process of recording abnormal information. The system first determines the type and source of the abnormality. It checks the calculation process of the data integrity verification code to determine whether the data is tampered with during transmission or the verification fails due to an error in the calculation of the verification code. If the data is tampered with, the system will record the possible time points and location information where the data is tampered with, and these information can be obtained by analyzing the transmission log and the time stamp of data verification.
[0103] The system stores the abnormal information in a dedicated log file or database. When recording, it will detail the time when the data integrity verification fails, the identity identifiers of the sending and receiving devices involved, the relevant identification information of the encrypted data set, and any other data related to the abnormality, such as the value of the incorrect verification code, the data segment that may be tampered with, etc. These detailed information helps with subsequent problem troubleshooting and security auditing.
[0104] After recording the abnormal information, the system will take corresponding measures according to the preset policies. If the system has an automatic repair function, it will try to obtain the correct data from the backup data or request the sender to resend the data. When requesting the resending of data, the system will clearly inform the sender of the data range and reason for resending, so as to improve the efficiency of data transmission. At the same time, the system will send an alarm message to the administrator or relevant monitoring system to notify them of the abnormal data transmission, so that manual intervention and processing can be carried out in a timely manner.
[0105] In the embodiments of the present application, by using a series of technical means such as decrypting the encrypted signature using a private key and an elliptic curve encryption algorithm after passing the data integrity verification, determining the encryption policy based on the index information to restore the encryption policy selection matrix, decrypting, decoding, and splicing the encrypted data puzzle to restore the original data, and recording abnormal information when the data integrity verification fails, it is possible to efficiently implement the whole process processing of data from encrypted transmission to accurate restoration on the basis of ensuring data security. This effectively solves the problems in the prior art that it is difficult to accurately restore the data after transmission and it is impossible to timely detect and process data anomalies. Furthermore, it realizes ensuring the security, integrity, and accuracy of data transmission, improving the data processing efficiency and traceability in the resource-constrained Internet of Things environment, and providing a strong support for the reliable transmission and privacy protection of Internet of Things data.
[0106] The privacy protection system in the embodiments of the present invention application will be described from the perspective of hardware processing. Please refer to Figure 3 , which is a schematic structural diagram of an entity device of the privacy protection system in the embodiments of the present application.
[0107] It should be noted that Figure 3 The structure of the privacy protection system shown is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present invention.
[0108] As Figure 3 shown, the privacy protection system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage section 308 into the random access memory (RAM) 303, such as executing the methods described in the above embodiments. In the RAM 303, various programs and data required for system operation are also stored. The CPU 301, ROM 302, and RAM 303 are connected to each other through a bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.
[0109] The following components are connected to the I / O interface 305: an input section 306 including an audio input device, a button switch, etc.; an output section 307 including a liquid crystal display (LCD), an audio output device, an indicator light, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed so that a computer program read from it can be installed into the storage section 308 as needed.
[0110] Specifically, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 309, and / or installed from the removable medium 311. When the computer program is executed by a central processing unit (CPU) 301, various functions defined in the present invention are executed.
[0111] It should be noted that specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, apparatus, or device.
[0112] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings.
[0113] Specifically, the privacy protection system of this embodiment includes a processor and a memory. A computer program is stored on the memory. When the computer program is executed by the processor, the privacy protection method based on encrypted transmission of Internet of Things data provided in the above embodiment is implemented.
[0114] On the other hand, the present invention also provides a computer-readable storage medium. This storage medium may be included in the privacy protection system described in the above embodiment; or it may exist alone without being assembled into the privacy protection system. The above storage medium carries one or more computer programs. When the above one or more computer programs are executed by a processor of the privacy protection system, the privacy protection system implements the privacy protection method based on encrypted transmission of Internet of Things data provided in the above embodiment.
Claims
1. A privacy protection method for encrypted transmission of Internet of Things data, characterized in that, The method includes: Obtaining the original Internet of Things data to be transmitted; Dividing the original Internet of Things data into multiple data puzzles according to a preset data segmentation rule, and dynamically encoding the multiple data puzzles to obtain a data puzzle sequence; Generating a feature code corresponding to the multiple data puzzles according to the data puzzle sequence; Obtaining a temporary key based on the elliptic curve encryption algorithm, and symmetrically encrypting the feature code through the temporary key to obtain an encrypted feature code; Constructing an encryption policy selection matrix according to the data puzzle sequence and the encrypted feature code, where the rows of the encryption policy selection matrix represent different symmetric encryption algorithms, the columns represent different combinations of encryption parameters, and the values of the matrix elements are calculated by weighted summation according to the entropy value of the data puzzle sequence and the checksum of the encrypted feature code; Encrypting the data puzzle sequence in combination with the encryption policy selection matrix to obtain encrypted data puzzles; Assigning an index number to each encryption policy in the encryption policy selection matrix, and generating index information according to the index number; Integrating the encrypted data puzzles, the encrypted feature code, and the index information according to a preset splicing rule to obtain an encrypted data set; Adding header information to the encrypted data set and transmitting it to the receiving end, where the header information at least includes the identity identifiers of the sending and receiving devices, the data segmentation rule parameters, and the data integrity checksum.
2. The method according to claim 1, wherein In the step of dividing the original Internet of Things data into multiple data puzzles according to a preset data segmentation rule, and dynamically encoding the multiple data puzzles to obtain a data puzzle sequence, specifically includes: Obtaining the current network bandwidth status, the remaining battery power of the device, and the security level coefficient of the original Internet of Things data, and determining the puzzle size of each data puzzle through weighted calculation; Dividing the original Internet of Things data according to the puzzle size to obtain multiple data puzzles; Encoding each data puzzle based on a dynamic coding table of chaotic mapping to obtain a data puzzle sequence.
3. The method according to claim 1, characterized in that, In the step of generating a feature code corresponding to the multiple data puzzles according to the data puzzle sequence, specifically includes: Establishing a hash function pool containing multiple hash functions, and selecting at least two different hash functions from the hash function pool according to the length and data type of the data puzzle sequence according to a preset selection rule; Respectively performing hash operations on the data puzzle sequence using the selected hash functions to obtain multiple hash values; Performing a bitwise exclusive OR operation on the multiple hash values to generate a feature code corresponding to the multiple data puzzles.
4. The method according to claim 1, characterized in that, In the step of obtaining a temporary key based on the elliptic curve encryption algorithm, and symmetrically encrypting the feature code through the temporary key to obtain an encrypted feature code, specifically includes: Combining the feature code, the identity identifier of the sending device, the public key of the receiving device, and the current timestamp to generate a temporary key through elliptic curve point multiplication operation; Symmetrically encrypting the feature code using the temporary key to obtain the encrypted feature code.
5. The method according to claim 1, characterized in that, In the step of encrypting the data puzzle sequence in combination with the encryption policy selection matrix to obtain encrypted data puzzles, specifically includes: Select the symmetric encryption algorithm and parameter combination corresponding to the element with the largest value from the encryption policy selection matrix as the encryption policy for the data puzzle sequence; Combine the feature code and encrypt the data puzzle sequence according to the encryption policy to obtain encrypted data puzzles.
6. The method according to claim 1, characterized in that, After the step of adding header information to the encrypted data set and transmitting it to the receiving end, the following steps are further included: Obtain the verification information sent by the receiving end, where the verification information at least includes verifying whether the identity identifiers of the sending and receiving devices match the preset information; If the verification passes, extract the data integrity check code from the encrypted data set; Combine the data integrity check code to perform data integrity verification on the encrypted data set to determine the data integrity of the encrypted data set.
7. The method according to claim 1, characterized in that After the step of combining the data integrity check code to perform data integrity verification on the encrypted data set to determine the data integrity of the encrypted data set, the following steps are further included: If the data integrity verification passes, control the receiving end to decrypt the encrypted feature code using the private key and the elliptic curve encryption algorithm to obtain the feature code; Restore the encryption policy selection matrix according to the index information, and combine the feature code to determine the encryption policy corresponding to the encrypted data puzzle from the matrix; Decrypt the encrypted data puzzle according to the encryption policy to obtain the data puzzle sequence; Decode the data puzzle sequence to obtain the multiple data puzzles; Stitch the multiple data puzzles according to the preset data segmentation rule to obtain the original Internet of Things data; If the data integrity verification fails, record the abnormal information.
8. A privacy protection system, characterized in that, The privacy protection system includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the privacy protection system to execute the method according to any one of claims 1-7.
9. A computer-readable storage medium, comprising instructions, characterized in that, When the instruction runs on the privacy protection system, enable the privacy protection system to execute the method according to any one of claims 1-7.
10. A computer program product, characterized in that, When the computer program product runs on the privacy protection system, enable the privacy protection system to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Dynamic identity information desensitization method and system based on SM4 and SM9 algorithms
CN119397582A
A computer software security encryption management system and method
CN119783142A