Method and device for realizing DDS (Direct Digital Synthesizer) secure communication middleware

By adding security detection components and authentication service components to the DDS middleware model, combining the secure handshake protocol and the DDS discovery process, the identity authentication, permission control and data encryption and decryption of the DDS secure communication middleware are achieved, which solves the problems of lack of overall security service solutions and inflexible configuration in the existing technology, and improves the security and performance of the system.

CN120128382AActive Publication Date: 2025-06-10BEIJING HUARU TECH

Patent Information

Application Number
CN202510292662.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-10
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

The existing DDS secure communication middleware lacks the overall solution for data distribution security services that integrate multiple elements such as identity authentication, permission control, and data encryption and decryption, which is difficult to meet the security needs in actual engineering applications. At the same time, the user configuration security services are not flexible enough, which increases the complexity and performance losses of the system implementation.

Method used

The security detection component and authentication service component were added to the original DDS middleware model. By combining the secure handshake protocol with the DDS discovery process, the identity authentication, permission control and key negotiation mechanism of the DDS secure communication middleware is designed and implemented, and two-way secure access authentication and data encryption and decryption are realized.

Benefits of technology

It realizes the authenticity, availability and confidentiality of the publishing and subscription process. Combined with the discovery mechanism of DDS and the QoS negotiation mechanism, it realizes the custom configuration of security protection levels and encryption algorithms, and meets the flexibility and efficiency needs of upper-level applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128382A_ABST
    Figure CN120128382A_ABST
Patent Text Reader

Abstract

The invention discloses a DDS (Direct Digital Synthesizer) secure communication middleware implementation method and device. The method comprises the following steps: adding a security detection component and an authentication service component into an original DDS middleware model; performing bidirectional security access authentication between a publisher and a subscriber by using the security detection component; the bidirectional security access authentication comprises authority access control and transmission data encryption; and the authentication service component is utilized to carry out identity authentication on a remote participant. According to the invention, the authenticity, availability and confidentiality of the publishing and subscribing process are realized by comprehensively utilizing the security detection component and the authentication service component. And in combination with a discovery mechanism of the DDS and a QoS negotiation mechanism, custom configuration of a security protection level and an encryption algorithm is realized, and the requirements of flexibility and high efficiency of an upper-layer application are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of secure communication, and in particular to a method and device for implementing a DDS secure communication middleware. Background Art

[0002] The Data Distribution Service (DDS) is a communication middleware specification formulated by the OMG organization. With the data-centric publish-subscribe (DCPS) model as the basic communication mechanism, it controls service behavior through Quality of Service (QoS), providing a loosely coupled, high-performance, highly reliable, and scalable solution for data transmission in distributed real-time systems.

[0003] Regarding security threats such as unauthorized subscriptions, unauthorized publications, and insecure channel transmissions faced in DDS, currently, it is mainly achieved through single methods such as expanding DDS built-in topics, based on Diffie-Hellman key exchange, security domain partitioning methods, QoS policy configuration methods, and participant dynamic access control methods. These related methods still have some problems: 1) Only involve a single element in the DDS security service, lacking an overall data distribution security service solution that integrates multiple elements such as identity authentication, permission control, and data encryption and decryption, and it is difficult to meet the security requirements in actual engineering applications. 2) The user configuration of the security service is not flexible enough, and it is necessary to change the usage habits of DDS application developers. 3) The combination of security elements and the original implementation mechanism of DDS is not tight enough. It is necessary to supplement a security handshake protocol after the DDS discovery process to implement identity authentication and security negotiation, increasing the complexity of system implementation and reducing the performance of DDS. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method and device for implementing a DDS secure communication middleware. Based on the existing DDS communication middleware, a DDS secure communication middleware model including identity authentication, permission control, and data encryption and decryption functions is proposed according to the DDS security specification. This model relies on plug-in design to achieve flexible configuration of security services; by combining the security handshake protocol with the DDS discovery process, the identity authentication, permission control, and key negotiation mechanisms of the DDS secure communication middleware are designed and implemented.

[0005] To solve the above technical problem, in the first aspect, an embodiment of the present invention discloses a method for implementing a DDS secure communication middleware, the method comprising:

[0006] S1, adding a security detection component and an authentication service component to the original DDS middleware model;

[0007] S2. Use the security detection component to perform two-way secure access authentication between the publisher and the subscriber; the two-way secure access authentication includes permission access control and transmission data encryption;

[0008] S3. Use the authentication service component to authenticate the remote participant.

[0009] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the using the security detection component to perform two-way secure access authentication between the publisher and the subscriber includes:

[0010] S21. Use the first authentication model to perform permission access control between the publisher and the subscriber to obtain a permission access control result;

[0011] S22. Use the second authentication model to encrypt the transmission data between the publisher and the subscriber to obtain encrypted data.

[0012] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the using the first authentication model to perform permission access control between the publisher and the subscriber to obtain a permission access control result includes:

[0013] S211. The publisher sends an authentication instruction to the subscriber;

[0014] S212. After receiving the authentication instruction, the subscriber generates a first random number and sends it to the publisher;

[0015] S213. The publisher generates a second random number, encrypts the first random number and the second random number with the subscriber's personalized key to obtain encrypted information, and the publisher sends the encrypted information to the subscriber;

[0016] S214. The subscriber decrypts the encrypted information with the personalized key to obtain a third random number and a fourth random number;

[0017] S215. When the third random number is equal to the first random number, the subscriber sends the fourth random number to the publisher;

[0018] S216. When the second random number is equal to the fourth random number, the permission access control result is two-way passed.

[0019] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the using the second authentication model to encrypt the transmission data between the publisher and the subscriber to obtain encrypted data includes:

[0020] S221. Process the transmission data between the publisher and the subscriber to obtain time-frequency information;

[0021] S222. Transform the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information;

[0022] S223. Encrypt the transformed time-frequency information to obtain an encrypted sequence;

[0023] S224. Encrypt the abridged time-frequency information to obtain encrypted abridged time-frequency information;

[0024] S225. Concatenate the encrypted abridged time-frequency information and the encrypted sequence to obtain encrypted data.

[0025] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the transforming the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information includes:

[0026] S2221. Transform the time-frequency information to obtain transformed time-frequency information;

[0027] S2222. Process the transformed time-frequency information to obtain abridged time-frequency information.

[0028] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the encrypting the transformed time-frequency information to obtain an encrypted sequence includes:

[0029] S2231. Expand the transformed time-frequency information to obtain one-dimensional information;

[0030] S2232. Encode the one-dimensional information to obtain encoded information;

[0031] S2233. Encrypt the encoded information to obtain an encrypted sequence.

[0032] As an optional implementation manner, in the first aspect of the embodiments of the present invention, the encrypting the abridged time-frequency information to obtain encrypted abridged time-frequency information includes:

[0033] S2241. Transform the abridged time-frequency information into a first sub-band, a second sub-band, a third sub-band, and a fourth sub-band;

[0034] S2242. Perform first encryption processing on the first sub-band to obtain a first encrypted sub-band;

[0035] S2243. Perform second encryption processing on the second sub-band, the third sub-band, and the fourth sub-band to obtain a second encrypted sub-band;

[0036] S2244. Transform the first encrypted sub-band and the second encrypted sub-band to obtain encrypted abridged time-frequency information.

[0037] The second aspect of the embodiments of the present invention discloses a DDS secure communication middleware implementation device, which includes:

[0038] A component addition module, configured to add a security detection component and an authentication service component to the original DDS middleware model;

[0039] A two-way secure access authentication module, configured to perform two-way secure access authentication between a publisher and a subscriber by using the security detection component; the two-way secure access authentication includes permission access control and transmission data encryption;

[0040] A remote participant authentication module, configured to authenticate the identity of a remote participant by using the authentication service component.

[0041] As an optional implementation manner, in the second aspect of the embodiments of the present invention, the performing two-way secure access authentication between the publisher and the subscriber by using the security detection component includes:

[0042] S21, performing permission access control between the publisher and the subscriber by using a first authentication model to obtain a permission access control result;

[0043] S22, performing transmission data encryption between the publisher and the subscriber by using a second authentication model to obtain encrypted data.

[0044] As an optional implementation manner, in the second aspect of the embodiments of the present invention, the performing permission access control between the publisher and the subscriber by using the first authentication model to obtain a permission access control result includes:

[0045] S211, the publisher sends an authentication instruction to the subscriber;

[0046] S212, after receiving the authentication instruction, the subscriber generates a first random number and sends it to the publisher;

[0047] S213, the publisher generates a second random number, encrypts the first random number and the second random number by using the personalized key of the subscriber to obtain encrypted information, and the publisher sends the encrypted information to the subscriber;

[0048] S214, the subscriber decrypts the encrypted information by using the personalized key to obtain a third random number and a fourth random number;

[0049] S215, when the third random number is equal to the first random number, the subscriber sends the fourth random number to the publisher;

[0050] S216, when the second random number is equal to the fourth random number, the permission access control result is two-way passed.

[0051] As an alternative implementation, in the second aspect of the embodiments of the present invention, using the second authentication model to encrypt the data transmitted between the publisher and the subscriber to obtain encrypted data includes:

[0052] S221, process the data transmitted between the publisher and the subscriber to obtain time-frequency information;

[0053] S222, transform the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information;

[0054] S223, perform an encryption process on the transformed time-frequency information to obtain an encrypted sequence;

[0055] S224, encrypt the abridged time-frequency information to obtain encrypted abridged time-frequency information;

[0056] S225, splice the encrypted abridged time-frequency information and the encrypted sequence to obtain encrypted data.

[0057] As an alternative implementation, in the second aspect of the embodiments of the present invention, the transforming the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information includes:

[0058] S2221, transform the time-frequency information to obtain transformed time-frequency information;

[0059] S2222, process the transformed time-frequency information to obtain abridged time-frequency information.

[0060] As an alternative implementation, in the second aspect of the embodiments of the present invention, the performing an encryption process on the transformed time-frequency information to obtain an encrypted sequence includes:

[0061] S2231, expand the transformed time-frequency information to obtain one-dimensional information;

[0062] S2232, encode the one-dimensional information to obtain encoded information;

[0063] S2233, encrypt the encoded information to obtain an encrypted sequence.

[0064] As an alternative implementation, in the second aspect of the embodiments of the present invention, the encrypting the abridged time-frequency information to obtain encrypted abridged time-frequency information includes:

[0065] S2241, transform the abridged time-frequency information into the first sub-band, the second sub-band, the third sub-band, and the fourth sub-band;

[0066] S2242, perform a first encryption process on the first sub-band to obtain a first encrypted sub-band;

[0067] S2243. Perform a second encryption process on the second sub-band, the third sub-band, and the fourth sub-band to obtain a second encrypted sub-band;

[0068] S2244. Transform the first encrypted sub-band and the second encrypted sub-band to obtain encrypted thumbnail time-frequency information.

[0069] The third aspect of the present invention discloses another DDS secure communication middleware implementation device, which includes:

[0070] A memory storing executable program code;

[0071] A processor coupled to the memory;

[0072] The processor calls the executable program code stored in the memory and executes some or all of the steps in the DDS secure communication middleware implementation method disclosed in the first aspect of the embodiments of the present invention.

[0073] The fourth aspect of the present invention discloses a computer-readable storage medium storing computer instructions, which are used to execute some or all of the steps in the DDS secure communication middleware implementation method disclosed in the first aspect of the embodiments of the present invention when the computer instructions are called.

[0074] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0075] The present invention comprehensively utilizes the security detection component and the authentication service component to achieve the authenticity, availability, and confidentiality of the publishing and subscribing processes. Combining the discovery mechanism and the QoS negotiation mechanism of DDS, it realizes the custom configuration of the security protection level and the encryption algorithm, meeting the flexibility and efficiency requirements of the upper-layer applications. The following will be described in detail respectively. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0077] Figure 1 is a flowchart of a DDS secure communication middleware implementation method disclosed in an embodiment of the present invention;

[0078] Figure 2 is a schematic diagram of a method for transforming time-frequency information disclosed in an embodiment of the present invention;

[0079] Figure 3It is a schematic diagram of unauthorized publish-subscribe disclosed in the embodiments of the present invention;

[0080] Figure 4 It is a schematic diagram of secure negotiation publish-subscribe disclosed in the embodiments of the present invention;

[0081] Figure 5 It is a schematic diagram of adding a security detection component and an authentication service component to the original DDS middleware model in the embodiments of the present invention;

[0082] Figure 6 It is a schematic diagram of the structure of a DDS secure communication middleware implementation device disclosed in the embodiments of the present invention;

[0083] Figure 7 It is a schematic diagram of the structure of another DDS secure communication middleware implementation device disclosed in the embodiments of the present invention. Detailed implementation manners

[0084] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0085] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or equipment.

[0086] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0087] The present invention discloses a method and device for implementing a DDS secure communication middleware. The method includes: adding a security detection component and an authentication service component to the original DDS middleware model; using the security detection component to perform two-way secure access authentication between a publisher and a subscriber; the two-way secure access authentication includes permission access control and transmission data encryption; using the authentication service component to authenticate remote participants. The present invention comprehensively utilizes the security detection component and the authentication service component to achieve the authenticity, availability, and confidentiality of the publishing and subscribing processes. Combining with the discovery mechanism and QoS negotiation mechanism of DDS, it realizes the custom configuration of the security protection level and encryption algorithm, meeting the flexibility and efficiency requirements of upper-layer applications. The following will be described in detail respectively.

[0088] Embodiment 1

[0089] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a method for implementing a DDS secure communication middleware disclosed in an embodiment of the present invention. Among them, Figure 1 the described method for implementing a DDS secure communication middleware is applied to the field of secure communication technology, and the embodiments of the present invention do not make limitations. As Figure 1 shown, the method for implementing a DDS secure communication middleware may include the following operations:

[0090] S1, adding a security detection component and an authentication service component to the original DDS middleware model;

[0091] The original DDS middleware model is the prior art in this field;

[0092] S2, using the security detection component to perform two-way secure access authentication between a publisher and a subscriber; the two-way secure access authentication includes permission access control and transmission data encryption;

[0093] S3, using the authentication service component to authenticate remote participants.

[0094] The implementation method of S3 is: the authentication service component verifies the publishing and subscribing permissions of remote participants according to the access control permission file issued by the CA center.

[0095] Optionally, the using the security detection component to perform two-way secure access authentication between a publisher and a subscriber includes:

[0096] S21, using a first authentication model to perform permission access control between a publisher and a subscriber to obtain a permission access control result;

[0097] S22, using a second authentication model to perform transmission data encryption between a publisher and a subscriber to obtain encrypted data.

[0098] Optionally, using the first authentication model to perform permission access control between the publisher and the subscriber to obtain a permission access control result, including:

[0099] S211. The publisher sends an authentication instruction to the subscriber;

[0100] The subscriber first sets a personalized key K;

[0101] S212. After receiving the authentication instruction, the subscriber generates a first random number and sends it to the publisher;

[0102] S213. The publisher generates a second random number, encrypts the first random number and the second random number using the subscriber's personalized key to obtain encrypted information, and the publisher sends the encrypted information to the subscriber;

[0103] The specific encryption method is not limited in this embodiment, such as the SM1 symmetric cryptography algorithm, etc.;

[0104] S214. The subscriber decrypts the encrypted information using the personalized key to obtain a third random number and a fourth random number;

[0105] S215. When the third random number is equal to the first random number, the subscriber sends the fourth random number to the publisher;

[0106] S216. When the second random number is equal to the fourth random number, the permission access control result is two-way pass.

[0107] Steps S211 to S216 are the working process of the first authentication model.

[0108] Optionally, using the second authentication model to encrypt the transmitted data between the publisher and the subscriber to obtain encrypted data, including:

[0109] S221. Process the transmitted data between the publisher and the subscriber to obtain time-frequency information;

[0110] The specific method is

[0111]

[0112] where C x is the time-frequency information, the integration range is -∞ to ∞, u and t are time variables, τ is the time shift variable, Ω is the frequency variable corresponding to u, θ is the frequency variable corresponding to τ, and k(θ,τ) = A x (θ,τ)g(θ,τ), k(θ,τ) is the optimized kernel function, and g(θ,τ) is the preset kernel function, x(t) is the transmission data between the publisher and the subscriber, A x (θ,τ) is the fuzzy parameter information, t is the time variable, τ is the displacement variable, θ is the frequency variable corresponding to τ, and * represents taking the conjugate.

[0113] S222. Transform the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information;

[0114] 1) Divide the time-frequency information digital image of size M×N into 8×8 blocks. If M or N is not divisible by 8, pad 0s to the rows or columns that are not divisible by 8 until they are divisible by 8.

[0115] 2) Take the difference in the direction of the arrow in Figure 2 (a) to obtain Figure 2 (b), and then rearrange the difference results, that is, arrange the pixels of the same color in Figure 2 (b) together to obtain Figure 2 (c).

[0116] 3) On the yellow sub-block in Figure 2 (d), take the difference in the direction of the arrow to obtain Figure 2 (e), and then rearrange the difference results to obtain Figure 2 (f).

[0117] 4) Finally, take the difference in the direction of the arrow in Figure 2 (f) to obtain the final result Figure 2 (g), where the upper left 4×4 sub-block is LT, the upper right sub-block is RT, the lower left sub-block is LB, and the lower right sub-block is RB.

[0118] The transformed time-frequency information Y1 is as shown in Figure 2 (g). There is an unchanged pixel in the LT sub-band. Extract all such pixels in all 8×8 blocks of the image to obtain the abridged time-frequency information Y2 with a size of one-eighth of the original image.

[0119] S223. Encrypt the transformed time-frequency information to obtain an encrypted sequence;

[0120] S224. Encrypt the abridged time-frequency information to obtain an encrypted abridged time-frequency information;

[0121] S225. Concatenate the encrypted abridged time-frequency information and the encrypted sequence to obtain encrypted data.

[0122] Optionally, the transforming the time-frequency information to obtain transformed time-frequency information and abridged time-frequency information includes:

[0123] S2221. Transform the time-frequency information to obtain transformed time-frequency information;

[0124] S2222. Process the transformed time-frequency information to obtain abridged time-frequency information.

[0125] Optionally, the encrypting the transformed time-frequency information to obtain an encrypted sequence includes:

[0126] S2231. Expand the transformed time-frequency information to obtain one-dimensional information;

[0127] Expand the transformed time-frequency information Y1 into a one-dimensional sequence from left to right and top to bottom to obtain Y11;

[0128] S2232. Encode the one-dimensional information to obtain encoded information;

[0129] Perform DC encoding on Y11 to obtain encoded information;

[0130] S2233. Encrypt the encoded information to obtain an encrypted sequence.

[0131] Perform SM7 encryption on the encoded information to obtain Y12;

[0132] The secret key adopted in this implementation is:

[0133] Take the SHA-256 hash value of the time-frequency information, a total of 256 bits, and divide it into 32 parts, each part being 8 bits, denoted as k 1 , k 2 , …, k 32 , and calculate to obtain:

[0134] x 0 = mod((h 1 + h 2 ) × 10 14 ) / 255

[0135] y 0 = mod((h 3 + h 2 ) × 10 14 ) / 255

[0136] z 0 = mod((h 3 + h 4 ) × 10 14 ) / 255

[0137] h 0 = mod((h 1 + h 2 + h 3 + h 4 ) × 10 14 ) / 255

[0138]

[0139] Among them, is the exclusive OR operation, LC t is a left circular shift of t bits, and mod is a modulo 256 operation. Using the fractional-order chaotic system, for h 1 , h 2 , h 3 , h 4 are processed to obtain the chaotic sequence H, and H is transformed to obtain H1:

[0140] H1 = floor(mod((H × 10 16 ), 256))

[0141] Among them, floor represents taking the integer part;

[0142] An exclusive OR calculation is performed on H1 and Y12 to obtain the encrypted sequence Y13.

[0143] Optionally, encrypting the abbreviated time-frequency information to obtain encrypted abbreviated time-frequency information includes:

[0144] S2241, transforming the abbreviated time-frequency information into the first sub-band, the second sub-band, the third sub-band, and the fourth sub-band;

[0145] The abbreviated time-frequency information is divided into blocks to obtain 4 sub-blocks, and each sub-block is subjected to a discrete cosine transform to obtain the first sub-band L 1 , the second sub-band T 1 , the third sub-band B 1 and the fourth sub-band R 1 ;

[0146] S2242, performing a first encryption process on the first sub-band to obtain a first encrypted sub-band;

[0147] The calculation is as follows:

[0148] L 2 = boxr(boxr((L 1 , T 1 ) B 1 ), R 1 )

[0149] T 2 = boxr(boxr(L 2 , T 1 )

[0150] B 2 = boxr(boxr(L 2 , B 1 )

[0151] R 2 = boxr(boxr(L 2 , R 1 ))

[0152] where bxor represents bitwise exclusive OR operation. Use H1 to perform DC encoding on L 2 to obtain the first encrypted subband L 3 .

[0153] S2243, perform a second encryption process on the second subband, the third subband, and the fourth subband to obtain a second encrypted subband;

[0154] Combine T 2 , B 2 and R 2 into sequence W 2 , and use H1 to perform DNA encryption on W 2 to obtain the second encrypted subband W 3 ;

[0155] S2244, perform a transformation on the first encrypted subband and the second encrypted subband to obtain encrypted thumbnail time-frequency information.

[0156] Diffuse, scramble, and scramble L 3 and W 3 , and then perform odd-even exchange to obtain encrypted thumbnail time-frequency information.

[0157] The decryption process is the reverse of the encryption process.

[0158] It can be seen that the present invention comprehensively utilizes the security detection component and the authentication service component to achieve the authenticity, availability, and confidentiality of the publish and subscribe processes. Combining the discovery mechanism and QoS negotiation mechanism of DDS, it realizes the custom configuration of the security protection level and encryption algorithm, meeting the flexibility and efficiency requirements of upper-layer applications. The following will be described in detail respectively.

[0159] Embodiment 2

[0160] Based on the existing DDS communication middleware and the DDS security specification, this embodiment proposes a DDS security communication middleware model that includes identity authentication, permission control, and data encryption and decryption functions. This model relies on plug-in design to achieve flexible configuration of security services; by combining the security handshake protocol with the DDS discovery process, it designs and implements the identity authentication, permission control, and key negotiation mechanisms of the DDS security communication middleware. Figure 3 is an unauthorized publish-subscribe schematic diagram disclosed in an embodiment of the present invention; Figure 4 is a publish-subscribe schematic diagram of security negotiation disclosed in an embodiment of the present invention; Figure 5It is a schematic diagram of adding a security detection component and an authentication service component to the original DDS middleware model disclosed in the embodiments of the present invention;

[0161] The CA center is a trusted third party outside the DDS, which is the basis of secure communication. It issues digital certificates for each participant through a secure channel and distributes the access control permission file with the CA integrity signature formulated by the system administrator in the DDS domain to each participant within the domain. The remaining modules cooperate with the DDS entity in the form of service plugins inside the DDS communication middleware to provide a complete data distribution security service for the user program.

[0162] The identity authentication component authenticates the remote participants;

[0163] The security detection component performs two-way secure access authentication between the publisher and the subscriber; the two-way secure access authentication includes permission access control and transmission data encryption.

[0164] Embodiment III

[0165] Please refer to Figure 6 , Figure 6 It is a schematic diagram of the structure of a DDS secure communication middleware implementation device disclosed in the embodiments of the present invention. Among them, Figure 6 The described DDS secure communication middleware implementation device is applied to the field of secure communication technology, and the embodiments of the present invention do not make limitations. As Figure 6 shown, the DDS secure communication middleware implementation device may include the following operations:

[0166] S301, a component addition module, is used to add a security detection component and an authentication service component to the original DDS middleware model;

[0167] S302, a two-way secure access authentication module, is used to use the security detection component to perform two-way secure access authentication between the publisher and the subscriber; the two-way secure access authentication includes permission access control and transmission data encryption;

[0168] S303, a remote participant authentication module, is used to use the authentication service component to authenticate the remote participants.

[0169] Embodiment IV

[0170] Please refer to Figure 7 , Figure 7 It is a schematic diagram of the structure of another DDS secure communication middleware implementation device disclosed in the embodiments of the present invention. Among them, Figure 7 The described DDS secure communication middleware implementation device is applied to the field of secure communication technology, and the embodiments of the present invention do not make limitations. As Figure 7 shown, the DDS secure communication middleware implementation device may include the following operations:

[0171] A memory 401 storing executable program codes;

[0172] A processor 402 coupled to the memory 401;

[0173] The processor 402 calls the executable program codes stored in the memory 401 for executing the steps in the DDS secure communication middleware implementation method described in Embodiment 1 and Embodiment 2.

[0174] Embodiment 5

[0175] An embodiment of the present invention discloses a computer-readable storage medium storing a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps in the DDS secure communication middleware implementation method described in Embodiment 1 and Embodiment 2.

[0176] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative efforts.

[0177] Through the specific descriptions of the above embodiments, those skilled in the art can clearly understand that each implementation can be achieved by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, and the storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other medium that can be used to carry or store data and is computer-readable.

[0178] Finally, it should be noted that: The DDS security communication middleware implementation method and device disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A DDS secure communication middleware implementation method, characterized in that: The method comprises: S1, adding security detection components and authentication service components to the original DDS middleware model; S2, using the security detection component to perform two-way security access authentication between the publisher and the subscriber; the two-way security access authentication includes permission access control and transmission data encryption; S3, using the authentication service component to authenticate the remote participant.

2. The DDS secure communication middleware implementation method according to claim 1, characterized in that: The method of using the security detection component to perform two-way security access authentication between the publisher and the subscriber includes: S21, using the first authentication model, performing permission access control between the publisher and the subscriber, and obtaining a permission access control result; S22, using the second authentication model, encrypting the transmitted data between the publisher and the subscriber to obtain encrypted data.

3. The DDS secure communication middleware implementation method according to claim 2, characterized in that: The first authentication model is used to perform permission access control between the publisher and the subscriber to obtain permission access control results, including: S211, the publisher sends an authentication instruction to the subscriber; S212, after receiving the authentication instruction, the subscriber generates a first random number and sends it to the publisher; S213, the publisher generates a second random number, encrypts the first random number and the second random number with the subscriber's personalized key to obtain encrypted information, and sends the encrypted information to the subscriber; S214, the subscriber decrypts the encrypted information using the personalized key to obtain a third random number and a fourth random number; S215, when the third random number is equal to the first random number, the subscriber sends the fourth random number to the publisher; S216: When the second random number is equal to the fourth random number, the permission access control result is bidirectional pass.

4. The DDS secure communication middleware implementation method according to claim 2, characterized in that: The second authentication model is used to encrypt the transmitted data between the publisher and the subscriber to obtain the encrypted data, including: S221, processing the transmission data between the publisher and the subscriber to obtain time-frequency information; S222, transform the time-frequency information to obtain transformed time-frequency information and abbreviated time-frequency information; S223, encrypting the transformed time-frequency information to obtain an encrypted sequence; S224, encrypting the abbreviated time-frequency information to obtain encrypted abbreviated time-frequency information; S225, concatenating the encrypted abbreviated time-frequency information and the encrypted sequence to obtain encrypted data.

5. The DDS secure communication middleware implementation method according to claim 4, characterized in that: The step of transforming the time-frequency information to obtain transformed time-frequency information and abbreviated time-frequency information includes: S2221, transform the time-frequency information to obtain transformed time-frequency information; S2222: Process the transformed time-frequency information to obtain abbreviated time-frequency information.

6. The DDS secure communication middleware implementation method according to claim 4, characterized in that: The step of encrypting the transformed time-frequency information to obtain an encrypted sequence includes: S2231, expanding the transformed time-frequency information to obtain one-dimensional information; S2232, encoding the one-dimensional information to obtain encoded information; S2233, encrypt the coded information to obtain an encrypted sequence.

7. The DDS secure communication middleware implementation method according to claim 4, characterized in that: The step of encrypting the abbreviated time-frequency information to obtain the encrypted abbreviated time-frequency information includes: S2241, transforming the abbreviated time-frequency information into a first sub-band, a second sub-band, a third sub-band and a fourth sub-band; S2242, performing a first encryption process on the first subband to obtain a first encrypted subband; S2243, performing a second encryption process on the second sub-band, the third sub-band, and the fourth sub-band to obtain a second encrypted sub-band; S2244: transform the first encrypted sub-band and the second encrypted sub-band to obtain encrypted abbreviated time-frequency information.

8. A DDS secure communication middleware implementation device, characterized in that: The device comprises: Component adding module, used to add security detection component and authentication service component to the original DDS middleware model; A two-way security access authentication module, used to use the security detection component to perform two-way security access authentication between the publisher and the subscriber; the two-way security access authentication includes permission access control and transmission data encryption; The remote participant authentication module is used to perform identity authentication on the remote participant using the authentication service component.

9. A DDS secure communication middleware implementation device, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the DDS secure communication middleware implementation method as described in any one of claims 1-7.

10. A computer storable medium, characterized in that: The computer storable medium stores computer instructions, and when the computer instructions are called, they are used to execute the DDS secure communication middleware implementation method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Image compression method based on sub-band encryption

    CN104967860A

  • Safety verification method and device based on cloud computing and electronic equipment

    CN113098685A

  • DDS secure communication middleware design method based on attribute strategy

    CN113949541A

  • Mobile terminal real-time vehicle control method and system based on whole vehicle DDS protocol and automobile

    CN114979231A

  • Edge enhanced image compression and encryption method and device, medium and product

    CN118612354A

Cited By

  • DDS security plug-in and heterogeneous chip

    CN121193545A