Dynamic hybrid encryption communication method and application thereof in trusted edge data gateway

By adopting a dynamic hybrid encryption communication method in an edge computing environment, the limitations of encryption technology in the prior art in terms of security, performance and flexibility in the edge computing environment are solved, and efficient and secure data transmission is achieved.

CN120128419APending Publication Date: 2025-06-10CHENGDU YISHI XINKE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510427067.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-12-31
Filing Date
2025-04-07
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Existing encryption technologies have limitations in security, performance, and flexibility in edge computing environments, especially when dealing with the need for large-scale, dynamically changing network environments and the collaborative work of multiple devices.

Method used

The dynamic hybrid encryption communication method is adopted to generate and distribute the keys through the server. The edge device symmetrically encrypts and signs the data and transmits it to the receiver through the network. The receiver verifies and decrypts the ciphertext and restores the original plaintext data.

Benefits of technology

It significantly improves the security of data transmission, combined with the advantages of symmetric encryption and asymmetric encryption, improves performance and flexibility, and prevents man-in-the-middle attacks and replay attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128419A_ABST
    Figure CN120128419A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission security, in particular to a dynamic hybrid encryption communication method and application thereof in a trusted edge data gateway, firstly, a server generates a secret key and distributes the secret key to an edge device, and after the edge device receives the secret key, the edge device performs symmetric encryption and signature on data through the received secret key; the edge device symmetrically encrypts and signs the data and then transmits the data to a receiver through a network, the receiver verifies the received ciphertext and decrypts the received ciphertext, and original plaintext data is recovered; the receiver verifies the decrypted plaintext, and the data can be used for subsequent service processing after the verification is completed, so that the problem that the encryption technology in the prior art cannot be applied to the edge computing environment, especially to the large-scale and dynamically changing network environment and the requirement of multi-device cooperative work is solved. And certain limitations exist in the aspects of safety, performance and flexibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission security technology, and in particular to a dynamic hybrid encryption communication method and an application thereof in a trusted edge data gateway. Background Art

[0002] With the rapid development of the Internet of Things and edge computing technologies, more and more data processing and computing tasks are assigned to the edge nodes of the network. This distributed computing architecture not only reduces the burden on data centers, but also reduces the latency of data transmission and improves real-time performance. However, this trend also brings new challenges, especially in terms of data security and privacy protection. Since edge devices are usually located in open or semi-open environments, they are vulnerable to various cyber attacks and physical attacks.

[0003] In the prior art, data encryption and communication encryption are two commonly used means of protecting data. Data encryption is mainly used to protect data stored in the device. Even if the device is hacked or lost, the attacker cannot directly obtain the information therein. Common data encryption methods include symmetric encryption and asymmetric encryption. Symmetric encryption uses a single key for encryption and decryption. Its advantage is fast speed and is suitable for encryption tasks with large amounts of data; but its disadvantage is that key management is complex. Once the key is leaked, data security will be seriously threatened. Asymmetric encryption uses paired keys (public key and private key), and different keys are used for encryption and decryption. This method has high security. However, due to its high computational complexity and slow processing speed, it is not suitable for encryption of large-scale data.

[0004] Communication encryption is used to protect the security of data during transmission and prevent data from being intercepted or tampered with when transmitted over the network. Existing communication encryption technologies mainly rely on protocols such as SSL / TLS, which establish an encrypted channel before data transmission, exchange symmetric encryption keys through asymmetric encryption technology, and then use symmetric encryption technology to encrypt the communication content. However, this method is not completely applicable in edge computing environments. First, the resources of edge devices are usually limited, and frequent asymmetric encryption calculations will take up a lot of processing power and affect the performance of the device. Secondly, in a highly distributed network environment, traditional communication encryption methods are difficult to cope with dynamically changing network topologies and key management between multiple devices.

[0005] In summary, existing encryption technologies have certain limitations in terms of security, performance, and flexibility when applied in edge computing environments, especially when dealing with large-scale, dynamically changing network environments and the needs of multi-device collaboration. Summary of the invention

[0006] The purpose of the present invention is to provide a dynamic hybrid encryption communication method and its application in a trusted edge data gateway, aiming to solve the technical problem that the encryption technology in the prior art has certain limitations in security, performance and flexibility when applied in an edge computing environment, especially when dealing with large-scale, dynamically changing network environments and the needs of multi-device collaboration.

[0007] To achieve the above object, the present invention adopts a dynamic hybrid encryption communication method, comprising the following steps:

[0008] Step 1: Generate keys based on the server and distribute them to edge devices;

[0009] Step 2: After the edge device receives the key, it symmetrically encrypts and signs the data using the received key;

[0010] Step 3: After the edge device symmetrically encrypts and signs the data, it transmits it to the recipient through the network;

[0011] Step 4: The receiver verifies the received ciphertext and decrypts it to recover the original plaintext data.

[0012] Step 5: The receiver verifies the decrypted plaintext. After verification, the data can be used for subsequent business processing.

[0013] In step 1, the server generates a key and distributes it to the edge device in the following way:

[0014] The server generates a pair of asymmetric encryption keys, including a public key and a private key. The server retains the private key for decryption operations and sends the public key to the edge device.

[0015] The server then generates a set of symmetric encryption keys for encrypting data transmission; these symmetric keys are encrypted with the server's public key, and the generated ciphertext is sent to the edge device.

[0016] Among them, in step 2, after the edge device receives the key, the specific method of symmetrically encrypting and signing the data using the received key is as follows:

[0017] The edge device receives the encrypted symmetric key and decrypts it using the private key to obtain the symmetric key. It then uses the obtained symmetric key to encrypt the plaintext data to generate ciphertext.

[0018] At the same time, the edge device uses its own private key to digitally sign the ciphertext.

[0019] Among them, in step three, when the edge device sends the signature and ciphertext to the recipient, the symmetric key encrypted with the recipient's public key is also transmitted.

[0020] Among them, in step 4, the receiver verifies the received ciphertext and decrypts the received ciphertext to restore the original plaintext data in the following specific manner:

[0021] After receiving the ciphertext and signature, the receiver uses the sender's public key to verify the signature to ensure that the data has not been tampered with and indeed comes from the sender;

[0022] After confirming that the data has not been tampered with and indeed comes from the sender, the receiver uses its own private key to decrypt the transmitted encrypted symmetric key, and then uses the symmetric key to decrypt the ciphertext, and finally restores the original plaintext data.

[0023] Among them, during the communication process, the server monitors the key usage during the communication process, regularly updates the symmetric key, and after the new key is generated, it will be redistributed to the edge device through asymmetric encryption.

[0024] The application of the dynamic hybrid encryption communication method described above in a trusted edge data gateway.

[0025] The present invention discloses a dynamic hybrid encryption communication method and its application in a trusted edge data gateway. First, a server generates a key and distributes it to an edge device. After the edge device receives the key, it symmetrically encrypts and signs the data using the received key. The edge device symmetrically encrypts and signs the data and transmits it to the receiver through the network. The receiver verifies the received ciphertext and decrypts the received ciphertext to restore the original plaintext data. The receiver verifies the decrypted plaintext, and after the verification is completed, the data can be used for subsequent business processing. In this way, the technical problem that the encryption technology in the prior art has certain limitations in security, performance and flexibility when applied in an edge computing environment, especially in response to large-scale, dynamically changing network environments and the needs of multi-device collaboration, is solved.

[0026] In the present invention, a unified digest algorithm and key selection need to be used:

[0027] The two communicating parties need to negotiate in advance and use the same digest algorithm. This digest algorithm will be used to calculate the digest value of the network communication quintuple. Since both parties use the same digest algorithm and the same quintuple information, the digest values ​​they generate must be the same;

[0028] This digest value can be used as an index in the keystore to select the symmetric encryption key to be used in the current session / stream. Both parties select the same key from the keystore based on this common digest value, ensuring that the keys used for encryption and decryption are consistent.

[0029] At the same time, in the present invention, session initialization and key negotiation are required:

[0030] At the beginning of the communication, the two parties exchange the key library through the pre-negotiated asymmetric encryption technology. This key library contains multiple groups of symmetric keys, each of which may correspond to different encryption strengths or uses.

[0031] After the session is initialized, both parties perform a digest calculation on the current network communication quintuple (source IP, destination IP, source port, destination port, and protocol number) based on the agreed digest algorithm. The calculated digest value determines the specific key in the key library selected by both parties.

[0032] Because the digest algorithm and quintuple are fixed, both parties will select the same key in the key library to perform encryption operations in the session. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0034] Figure 1 It is a schematic diagram of a communication scenario of the present invention.

[0035] Figure 2 It is a flow chart of the dynamic hybrid encryption communication method of the present invention. DETAILED DESCRIPTION

[0036] Embodiments of the present invention are described in detail below. Examples of the embodiments are shown in the accompanying drawings. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, but should not be construed as limiting the present invention.

[0037] See also Figure 1 and Figure 2 ,in Figure 1 is a schematic diagram of a communication scenario of the present invention, Figure 2 It is a flow chart of the dynamic hybrid encryption communication method of the present invention

[0038] The present invention provides a dynamic hybrid encryption communication method, comprising the following steps:

[0039] S101, generating a key based on the server and distributing it to the edge device;

[0040] For this specific implementation, the server generates a pair of asymmetric encryption keys, including a public key and a private key; the server retains the private key for decryption operations and sends the public key to the edge device;

[0041] The server then generates a set of symmetric encryption keys for encrypting data transmission; these symmetric keys are encrypted with the server's public key, and the generated ciphertext is sent to the edge device.

[0042] S102, after the edge device receives the key, the data is symmetrically encrypted and signed using the received key;

[0043] According to this specific implementation method, the edge device receives the encrypted symmetric key and decrypts it using the private key to obtain the symmetric key; then the obtained symmetric key is used to encrypt the plaintext data to generate ciphertext;

[0044] At the same time, the edge device uses its own private key to digitally sign the ciphertext.

[0045] S103, after the edge device symmetrically encrypts and signs the data, it transmits it to the recipient through the network;

[0046] For this specific implementation, when the edge device sends the signature together with the ciphertext to the recipient, the symmetric key encrypted using the recipient's public key is also transmitted.

[0047] S104, the receiving party verifies the received ciphertext and decrypts the received ciphertext to restore the original plaintext data;

[0048] For this specific implementation, after receiving the ciphertext and signature, the receiver uses the sender's public key to verify the signature to ensure that the data has not been tampered with and indeed comes from the sender;

[0049] After confirming that the data has not been tampered with and indeed comes from the sender, the receiver uses its own private key to decrypt the transmitted encrypted symmetric key, and then uses the symmetric key to decrypt the ciphertext, and finally restores the original plaintext data.

[0050] S105: The receiver verifies the decrypted plaintext, and after verification, the data can be used for subsequent business processing.

[0051] In addition, during the communication process, the server monitors the key usage during the communication process and regularly updates the symmetric key. After the new key is generated, it will be redistributed to the edge device through asymmetric encryption.

[0052] A dynamic hybrid encryption communication method and its application in a trusted edge data gateway using the present embodiment, first the server generates a key and distributes it to the edge device, after the edge device receives the key, it symmetrically encrypts and signs the data using the received key, the edge device symmetrically encrypts and signs the data and transmits it to the receiver through the network, the receiver verifies the received ciphertext and decrypts the received ciphertext to restore the original plaintext data; the receiver verifies the decrypted plaintext, and after the verification is completed, the data can be used for subsequent business processing, in this way, the technical problem that the encryption technology in the prior art has certain limitations in security, performance and flexibility when applied in an edge computing environment, especially in response to large-scale, dynamically changing network environments and the needs of multi-device collaboration, is solved.

[0053] In the present invention, a unified digest algorithm and key selection need to be used:

[0054] The two communicating parties need to negotiate in advance and use the same digest algorithm. This digest algorithm will be used to calculate the digest value of the network communication quintuple. Since both parties use the same digest algorithm and the same quintuple information, the digest values ​​they generate must be the same;

[0055] This digest value can be used as an index in the keystore to select the symmetric encryption key to be used in the current session / stream. Both parties select the same key from the keystore based on this common digest value, ensuring that the keys used for encryption and decryption are consistent.

[0056] At the same time, in the present invention, session initialization and key negotiation are required:

[0057] At the beginning of the communication, the two parties exchange the key library through the pre-negotiated asymmetric encryption technology. This key library contains multiple groups of symmetric keys, each of which may correspond to different encryption strengths or uses.

[0058] After the session is initialized, both parties perform a digest calculation on the current network communication quintuple (source IP, destination IP, source port, destination port, and protocol number) based on the agreed digest algorithm. The calculated digest value determines the specific key in the key library selected by both parties.

[0059] Because the digest algorithm and quintuple are fixed, both parties will select the same key in the key library to perform encryption operations in the session.

[0060] The application of the dynamic hybrid encryption communication method described above in a trusted edge data gateway.

[0061] The beneficial effects of the present invention are as follows: through the dynamic hybrid encryption technology, the advantages of symmetric encryption and asymmetric encryption are combined to significantly improve the security of data transmission. The present invention uses asymmetric encryption technology to securely exchange symmetric encryption key libraries, thereby retaining the high efficiency of symmetric encryption in large data volume transmission and solving the problem of key security distribution through asymmetric encryption technology. Through the dynamic encryption mechanism, the use of keys is dynamically selected based on the summary of the network communication quintuple. As the session changes, the keys used are constantly changing, so that even if the keys at a certain moment are compromised, it is difficult for an attacker to obtain the keys for subsequent data, thereby effectively preventing common security threats such as man-in-the-middle attacks and replay attacks.

[0062] A balance is found between the two through dynamic hybrid encryption technology. First, during the session initialization phase, the system securely exchanges the key library through asymmetric encryption technology, and then uses symmetric encryption technology to encrypt data during the actual data transmission process. Symmetric encryption technology has significant performance advantages when processing large-scale data, and can ensure data security without sacrificing communication speed. By introducing the summary value of the network communication quintuple as a key selection factor, the system can dynamically select the appropriate encryption key while maintaining high efficiency. This mechanism not only reduces the frequency of key exchange, but also greatly reduces the computational overhead of encryption processing, ensuring the overall performance of encrypted communication.

[0063] By designing multiple confirmation and error handling mechanisms, the robustness and fault tolerance of the system are greatly improved. In the case of complex network environment or poor communication quality, the system can ensure that the keys and encryption algorithms selected by both parties are consistent through a double confirmation mechanism. Specifically, when the session is initialized, both parties will confirm with each other whether the summary value and key selection match, thereby preventing key asynchrony problems caused by network jitter or data packet loss. The present invention also introduces a retry mechanism. When the system detects that decryption fails or data is inconsistent, the system can automatically fall back to the previous key or regenerate the summary value for re-encryption to ensure the continuity and correctness of data transmission. This automatic recovery function enables the system to quickly return to normal when encountering an unexpected failure, reducing the risk of communication interruption.

[0064] What is disclosed above is only a preferred embodiment of the present invention, and it certainly cannot be used to limit the scope of rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of the above embodiment and equivalent changes made according to the claims of the present invention still fall within the scope of the invention.

Claims

1. A dynamic hybrid encryption communication method, It is characterized in that The following steps are involved: Step 1: Generate keys based on the server and distribute them to edge devices; Step 2: After the edge device receives the key, it symmetrically encrypts and signs the data using the received key; Step 3: After the edge device symmetrically encrypts and signs the data, it transmits it to the recipient through the network; Step 4: The receiver verifies the received ciphertext and decrypts it to recover the original plaintext data. Step 5: The receiver verifies the decrypted plaintext. After verification, the data can be used for subsequent business processing.

2. The dynamic hybrid encryption communication method according to claim 1, characterized in that: In step 1, the server generates keys and distributes them to edge devices in the following way: The server generates a pair of asymmetric encryption keys, including a public key and a private key. The server retains the private key for decryption operations and sends the public key to the edge device. The server then generates a set of symmetric encryption keys for encrypting data transmission; these symmetric keys are encrypted with the server's public key, and the generated ciphertext is sent to the edge device.

3. The dynamic hybrid encryption communication method according to claim 2, characterized in that: In step 2, after the edge device receives the key, the specific method of symmetrically encrypting and signing the data using the received key is as follows: The edge device receives the encrypted symmetric key and decrypts it using the private key to obtain the symmetric key. It then uses the obtained symmetric key to encrypt the plaintext data to generate ciphertext. At the same time, the edge device uses its own private key to digitally sign the ciphertext.

4. The dynamic hybrid encryption communication method according to claim 3, characterized in that: In step three, when the edge device sends the signature and ciphertext to the recipient, the symmetric key encrypted with the recipient's public key is also transmitted.

5. The dynamic hybrid encryption communication method according to claim 4, characterized in that: In step 4, the receiver verifies and decrypts the received ciphertext to recover the original plaintext data in the following way: After receiving the ciphertext and signature, the receiver uses the sender's public key to verify the signature to ensure that the data has not been tampered with and indeed comes from the sender; After confirming that the data has not been tampered with and indeed comes from the sender, the receiver uses its own private key to decrypt the transmitted encrypted symmetric key, and then uses the symmetric key to decrypt the ciphertext, and finally restores the original plaintext data.

6. The dynamic hybrid encryption communication method according to claim 5, characterized in that: During the communication process, the server monitors the key usage during the communication process and regularly updates the symmetric key. After the new key is generated, it will be redistributed to the edge device through asymmetric encryption.

7. The dynamic hybrid encryption communication method according to claim 6, characterized in that: Application in trusted edge data gateway.