Multi-protocol communication system and method of 5G edge computing security control gateway module
By designing a multi-protocol communication system on the 5G edge computing security control gateway module, the problems of protocol integration and communication security between devices are solved, transparent and efficient communication between devices are achieved, and data security and privacy are guaranteed.
Patent Information
- Application Number
- CN202510605441.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There is currently a lack of a mature method that can effectively integrate multiple protocols on the 5G edge computing security control gateway module to achieve interconnection between devices and ensure communication security.
Design a multi-protocol communication system, including protocol resolution module, protocol conversion module, security control module and communication management module. The system can parse data from different protocols, perform protocol conversion and consistency checks, and encrypt data and securely manage them, ultimately achieving transparent and efficient communication between devices.
Access to a variety of different communication protocol devices is realized, transparent and efficient communication between devices is realized, and data security and privacy are guaranteed during the communication process.
Smart Images

Figure CN120151830A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of gateway communication technologies, and particularly relates to a multi-protocol communication system and method for a 5G edge computing security control gateway module. Background Art
[0002] With the wide application of 5G technology and the rapid development of edge computing, a large number of devices of different types and supporting different communication protocols are connected to the edge computing network. For example, there are devices based on protocols such as Modbus and Profibus in industrial sites, and terminals using MQTT and CoAP protocols in the Internet of Things field. However, there is currently a lack of a mature method that can effectively integrate multiple protocols on a 5G edge computing security control gateway module to achieve interconnection and interoperability between devices while ensuring communication security. Summary of the Invention
[0003] The present invention provides a multi-protocol communication system for a 5G edge computing security control gateway module to achieve access to different communication protocols of the gateway, realize interconnection and interoperability between devices, and ensure communication security. Applied to a 5G edge computing security control gateway module, the gateway module is communicatively connected to a plurality of external devices, and the multi-protocol communication system includes: A protocol parsing module for parsing the data to be parsed sent by an external device; A protocol conversion module for performing protocol conversion on the parsed data and performing consistency check on the data after protocol conversion; A security control module for encrypting the data that has passed the consistency check; A communication management module for sending the encrypted data to the external device.
[0004] Preferably, the protocol parsing module includes a protocol identification sub-module and a plurality of protocol parsers, and the protocol parsing module is specifically used for: Based on the data packet header characteristics of the data to be parsed, identifying the protocol type of the data to be parsed through the protocol identification sub-module; Sending the data to be parsed to the protocol parser corresponding to the protocol type, and parsing the data to be parsed through the protocol parser to obtain the parsed data, where the parsed data includes a function code and an address code.
[0005] Preferably, the protocol conversion module is specifically used for: Pre-establishing a protocol conversion rule database, and determining the original protocol type and the target protocol type of the parsed data; Invoking a conversion rule from the protocol conversion rule database based on the original protocol type and the target protocol type; Perform protocol conversion on the parsed data based on the conversion rules, and perform consistency check on the data after protocol conversion.
[0006] Preferably, the protocol conversion module is specifically configured to: When the data after protocol conversion passes the consistency check, send the data after protocol conversion to the security control module; When the data after protocol conversion fails the consistency check, record the error information, and send a correction request to the protocol conversion module to perform the protocol conversion operation again.
[0007] Preferably, the security control module is specifically configured to: Pre-set a key, and distribute the key to the gateway and the external device; Encrypt the data that has passed the consistency check by using the key and the AES - 256 encryption algorithm to obtain encrypted data; Calculate the hash value of the data that has passed the consistency check by using the hash algorithm, and use the hash value as the data signature to form the encrypted data together with the encrypted data.
[0008] Preferably, the security control module is further specifically configured to: When the external device accesses the gateway, verify the authentication request sent by the external device; When the device certificate in the authentication request is legal, pass the access request of the external device; When the device certificate in the authentication request is illegal, reject the access request of the external device.
[0009] Preferably, the communication management module is further specifically configured to: Pre-set a communication resource scheduling table, and record the communication priority and bandwidth requirements of the external device; Based on the communication priority and bandwidth requirements, use the round-robin scheduling algorithm combined with the priority scheduling strategy to allocate communication bandwidth and processing time for each external device.
[0010] Preferably, the communication management module is further specifically configured to: When the external device is an industrial control device, preferentially allocate a preset processing time for data processing and transmission at fixed time intervals; When the external device is an ordinary Internet of Things sensor device, use the remaining resources for processing after the industrial control device has completed processing.
[0011] Preferably, the communication management module is further specifically configured to: Detect the communication link status by periodically sending heartbeat packets. When a link failure is detected, re - establish the connection or switch to the backup link.
[0012] Correspondingly, the present invention also proposes a multi - protocol communication method for a 5G edge computing security control gateway module, which is applied to the 5G edge computing security control gateway module. The gateway module is communicatively connected to multiple external devices. The method includes: Parse the data to be parsed sent by the external device; Perform protocol conversion on the parsed data and perform consistency check on the data after protocol conversion; Perform encryption processing on the data that has passed the consistency check; Send the encrypted data to the external device.
[0013] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses a multi - protocol communication system and method for a 5G edge computing security control gateway module. The system includes: a protocol parsing module for parsing the data to be parsed sent by the external device; a protocol conversion module for performing protocol conversion on the parsed data and performing consistency check on the data after protocol conversion; a security control module for performing encryption processing on the data that has passed the consistency check; a communication management module for sending the encrypted data to the external device, which can support the access of multiple different communication protocol devices, realize transparent and efficient communication between devices, and ensure data security and privacy during the communication process. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0015] Figure 1 Shows a schematic structural diagram of a multi - protocol communication system for a 5G edge computing security control gateway module proposed in an embodiment of the present invention; Figure 2 Shows an overall architecture diagram of a multi - protocol communication system for a 5G edge computing security control gateway module proposed in an embodiment of the present invention; Figure 3 Shows a schematic flowchart of a multi - protocol communication method for a 5G edge computing security control gateway module proposed in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts belong to the scope of protection of the present application.
[0017] As described in the background art, the prior art often can only process single or a few protocols, cannot meet the requirements of the increasingly complex multi-protocol hybrid communication scenario, and there are many loopholes in terms of security, such as data transmission being easily stolen and tampered with.
[0018] To solve the above problems, the embodiments of the present application propose a multi-protocol communication system and method for a 5G edge computing security control gateway module. The system includes: a protocol parsing module for parsing the data to be parsed sent by an external device; a protocol conversion module for performing protocol conversion on the parsed data and performing consistency check on the data after protocol conversion; a security control module for encrypting the data that has passed the consistency check; and a communication management module for sending the encrypted data to the external device, which can support the access of multiple different communication protocol devices, realize transparent and efficient communication between devices, and ensure the data security and privacy in the communication process.
[0019] Combined Figure 1 and Figure 2 , a multi-protocol communication system for a 5G edge computing security control gateway module proposed by the embodiments of the present invention is specifically as follows: A protocol parsing module 101 for parsing the data to be parsed sent by an external device.
[0020] In a preferred embodiment of the present application, the protocol parsing module includes a protocol identification sub-module and a plurality of protocol parsers. The protocol parsing module is specifically used for: Through the protocol identification sub-module, identifying the protocol type of the data to be parsed based on the data packet header characteristics of the data to be parsed; Sending the data to be parsed to the protocol parser corresponding to the protocol type, and parsing the data to be parsed through the protocol parser to obtain the parsed data, where the parsed data includes a function code and an address code.
[0021] Specifically, an independent protocol parsing module is set in the gateway module, and a dedicated parser is designed for each supported protocol (such as Modbus, MQTT, CoAP, etc.). When data enters the gateway, first, the protocol recognition sub-module quickly determines the protocol type to which the data belongs based on the characteristics of the data header, and then diverts the data to the corresponding protocol parser. For example, for Modbus protocol data, the parser parses information such as function codes and address codes according to the Modbus protocol specification and extracts the valid data content.
[0022] On the hardware platform of the gateway module, different cores of the multi-core processor are used to run the parsing programs of different protocols respectively. For example, one core is dedicated to running the Modbus protocol parser, and another core runs the MQTT protocol parser. Through the hardware interrupt mechanism, when new data arrives, it quickly triggers the protocol recognition sub-module to work, determines the protocol type based on the fixed characteristic values of the first few bits of the data header, and then transfers the data to the corresponding parser core for processing through the memory sharing mechanism.
[0023] The protocol conversion module 102 is used to perform protocol conversion on the parsed data and perform consistency checks on the data after protocol conversion.
[0024] In a preferred embodiment of the present application, the protocol conversion module is specifically used for: Pre-establish a protocol conversion rule database and determine the original protocol type and target protocol type of the parsed data; Call the conversion rule from the protocol conversion rule database based on the original protocol type and target protocol type; Perform protocol conversion on the parsed data based on the conversion rule and perform consistency checks on the data after protocol conversion.
[0025] In a preferred embodiment of the present application, the protocol conversion module is specifically used for: When the data after protocol conversion passes the consistency check, send the data after protocol conversion to the security control module; When the data after protocol conversion fails the consistency check, record the error information and send a correction request to the protocol conversion module to perform the protocol conversion operation again.
[0026] Specifically, according to the semantic mapping relationship between different protocols, the parsed data is subjected to protocol conversion. Taking Modbus to MQTT as an example, the register address in Modbus can be mapped to specific fields in the MQTT message, and the data value is used as the message content. By establishing a detailed protocol conversion rule table, flexible and accurate protocol conversion is achieved. At the same time, the data format is adapted during the conversion process to ensure that the target protocol can correctly receive and process the converted data.
[0027] At the software level, a detailed protocol conversion rule database is established and maintained in advance. When the parsed data needs to be subjected to protocol conversion, the protocol conversion module queries the corresponding conversion rules from the rule database according to the source protocol and target protocol information. For example, for converting Modbus data to CoAP data, the function code in Modbus is converted into specific options in the CoAP message according to the rules, and the data value is encapsulated in the CoAP data format. After the conversion is completed, a consistency check is performed on the converted data to ensure compliance with the target protocol specification.
[0028] The security control module 103 is used to encrypt the data that has passed the consistency check.
[0029] In a preferred embodiment of the present application, the security control module specifically is used for: Pre-set a secret key and distribute the secret key to the gateway and the external device; Use the secret key and adopt the AES - 256 encryption algorithm to encrypt the data that has passed the consistency check to obtain encrypted data; Use the hash algorithm to calculate the hash value of the data that has passed the consistency check, and use the hash value as the data signature to form the encrypted data together with the encrypted data.
[0030] In a preferred embodiment of the present application, the security control module is also specifically used for: When the external device accesses the gateway, verify the authentication request sent by the external device; When the device certificate in the authentication request is legal, pass the access request of the external device; When the device certificate in the authentication request is illegal, reject the access request of the external device.
[0031] Specifically, security checks are performed at all stages of data transmission, including before protocol parsing, during protocol conversion, and before data transmission after conversion. The transmission data is encrypted using a symmetric encryption algorithm (such as AES), and the corresponding key is used for decryption at the receiving end. At the same time, digital signature technology is used to verify data integrity and prevent data tampering. For devices accessing the gateway, an identity authentication mechanism (such as certificate-based authentication) is used to ensure the legitimacy of the devices, and only devices that pass the authentication can communicate.
[0032] Specifically, when data enters the gateway, the security control module first authenticates the device. When the device accesses, it needs to send an authentication request containing the device certificate to the gateway, and the gateway verifies the legitimacy of the certificate by interacting with the authentication server. For devices that pass the authentication, during data transmission, the AES - 256 encryption algorithm is used to encrypt the data. At the sending end, the data is encrypted using the pre-negotiated key, and the same key is used for decryption at the receiving end. At the same time, to verify data integrity, at the sending end, the hash value of the data is calculated using a hash algorithm (such as SHA - 256) and attached as a digital signature to the data and sent together. After receiving the data, the receiving end recalculates the hash value of the data and compares it with the received digital signature. If they are the same, it indicates that the data has not been tampered with.
[0033] The communication management module 104 is used to send the encrypted data to the external device.
[0034] In a preferred embodiment of the present application, the communication management module is further specifically used for: Pre-set a communication resource scheduling table and record the communication priorities and bandwidth requirements of the external devices; Based on the communication priorities and bandwidth requirements, use a polling scheduling algorithm combined with a priority scheduling strategy to allocate communication bandwidth and processing time for each external device.
[0035] In a preferred embodiment of the present application, the communication management module is further specifically used for: When the external device is an industrial control device, allocate a preset processing time at fixed time intervals for data processing and transmission with priority; When the external device is an ordinary Internet of Things sensor device, use the remaining resources for processing after the industrial control device has completed processing.
[0036] In a preferred embodiment of the present application, the communication management module is further specifically used for: Detect the communication link status by periodically sending heartbeat packets. When a link failure is detected, re-establish the connection or switch to an alternative link.
[0037] Specifically, the communication management module is responsible for coordinating the communication processes between different protocol devices. According to the communication requirements and resource status of the devices, it reasonably allocates communication bandwidth and processing time. For example, for industrial control protocol data with high real-time requirements, resources are preferentially allocated for processing and transmission; for non-real-time Internet of Things device data, it is processed when resources are idle. At the same time, it monitors the status of the communication link. When a link failure or congestion occurs, it promptly conducts fault diagnosis and recovery processing to ensure the continuity and stability of communication.
[0038] Specifically, by setting up a communication resource scheduling table in the gateway module to record information such as the communication priorities and bandwidth requirements of each device. The communication management module allocates communication bandwidth and processing time for different protocol devices according to the scheduling table, using a polling scheduling algorithm combined with a priority scheduling strategy. For example, for industrial control devices (with high priority), a certain duration of processing time is preferentially allocated at fixed time intervals for data processing and transmission; for ordinary Internet of Things sensor devices (with low priority), after the high-priority devices have completed processing, the remaining resources are used for processing. At the same time, the communication link status is detected by periodically sending heartbeat packets. When a link failure is detected, the fault recovery mechanism is quickly activated, and an attempt is made to re-establish the connection or switch to an alternative link to ensure the uninterrupted progress of communication.
[0039] In summary, external devices send data of different protocols to the protocol parsing module. After the module identifies and parses the data, the parsed data is transmitted to the protocol conversion module. The protocol conversion module performs protocol conversion based on the protocol conversion rule library, and the converted data enters the security control module. The security control module performs security processing on the data with reference to the security policy library, and finally the communication management module is responsible for data interaction with external devices, including receiving and sending data.
[0040] It should be noted that the relationships between the modules in this system are specifically as follows: The protocol parsing module provides a processable data format for the protocol conversion module; the protocol conversion module provides the converted data for the security control module based on the protocol conversion rule library; the security control module ensures data security with the help of the security policy library and provides secure data for the communication management module; the communication management module is responsible for the overall data transmission coordination. At the same time, the modules cooperate closely to jointly achieve multi-protocol communication of the 5G edge computing security control gateway module.
[0041] By applying the above technical solutions, parsing the data to be parsed sent by external devices; performing protocol conversion on the parsed data and conducting consistency checks on the data after protocol conversion; encrypting the data that has passed the consistency check; and sending the encrypted data to the external device, it can support the access of multiple different communication protocol devices, achieve transparent and efficient communication between devices, and ensure data security and privacy during the communication process.
[0042] Based on the above system, the present application also proposes a multi - protocol communication method for a 5G edge computing security control gateway module, as Figure 3 shown. The method includes: Step S301, parse the data to be parsed sent by an external device.
[0043] Specifically, in the embodiment of the present application, an independent protocol parsing module is set in the gateway module, and a dedicated parser is designed for each supported protocol (such as Modbus, MQTT, CoAP, etc.). When data enters the gateway, first, the protocol recognition sub - module quickly determines the protocol type to which the data belongs according to the data packet header characteristics, and then diverts the data to the corresponding protocol parser. For example, for Modbus protocol data, the parser parses information such as function codes and address codes according to the Modbus protocol specification, and extracts the valid data content.
[0044] Step S302, perform protocol conversion on the parsed data and perform consistency check on the data after protocol conversion.
[0045] Specifically, a detailed protocol conversion rule database is established and maintained in advance. When the parsed data needs to be protocol - converted, the protocol conversion module queries the corresponding conversion rules from the rule database according to the source protocol and target protocol information. For example, for converting Modbus data to CoAP data, the function code in Modbus is converted into a specific option in the CoAP message according to the rule, and the data value is encapsulated according to the CoAP data format. After the conversion is completed, a consistency check is performed on the converted data to ensure compliance with the target protocol specification. Step S303, perform encryption processing on the data that has passed the consistency check.
[0046] In this embodiment, when data enters the gateway, the security control module first authenticates the device. When the device accesses, it needs to send an authentication request containing the device certificate to the gateway, and the gateway verifies the legality of the certificate by interacting with the authentication server. For devices that pass the authentication, during the data transmission process, the AES - 256 encryption algorithm is used to encrypt the data. At the sending end, the data is encrypted using the pre - negotiated key, and the same key is used for decryption at the receiving end. At the same time, to verify the data integrity, at the sending end, the hash value of the data is calculated using a hash algorithm (such as SHA - 256) and attached as a digital signature to the data and sent together. After the receiving end receives the data, it recalculates the hash value of the data and compares it with the received digital signature. If they are the same, it indicates that the data has not been tampered with.
[0047] Step S304, send the encrypted data to the external device.
[0048] Through the description of the above embodiments, those skilled in the art can clearly understand that the present invention can be implemented by hardware or by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), and includes several instructions to cause a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various implementation scenarios of the present invention.
[0049] Those skilled in the art can understand that the drawings are only schematic diagrams of a preferred implementation scenario, and the modules or processes in the drawings are not necessarily essential for implementing the present invention.
[0050] Those skilled in the art can understand that the modules in the device can be distributed in the device of the implementation scenario according to the description of the implementation scenario, or can be correspondingly changed and located in one or more devices different from the present implementation scenario. The modules of the above implementation scenario can be combined into one module, or further split into multiple sub-modules.
[0051] The above serial numbers of the present invention are only for description and do not represent the advantages or disadvantages of the implementation scenarios.
[0052] The above discloses only several specific implementation scenarios of the present invention. However, the present invention is not limited thereto, and any changes that can be conceived by those skilled in the art should fall within the protection scope of the present invention.
Claims
1. A multi-protocol communication system of a 5G edge computing security control gateway module, applied to a 5G edge computing security control gateway module, wherein the gateway module is communicatively connected with multiple external devices, and the multi-protocol communication system comprises: The protocol parsing module is used to parse the data to be parsed sent by the external device; The protocol conversion module is used to perform protocol conversion on the parsed data and to perform consistency check on the data after protocol conversion; A security control module is used to encrypt the data that has passed the consistency check; The communication management module is used to send the encrypted data to the external device.
2. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 1, wherein the protocol parsing module includes a protocol identification submodule and a plurality of protocol parsers, and the protocol parsing module is specifically used for: Identify the protocol type of the data to be parsed based on the data packet header features of the data to be parsed by the protocol identification submodule; The data to be parsed is sent to a protocol parser corresponding to the protocol type, and the data to be parsed is parsed by the protocol parser to obtain parsed data, wherein the parsed data includes a function code and an address code.
3. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 1, characterized in that: The protocol conversion module is specifically used for: Pre-establishing a protocol conversion rule database and determining the original protocol type and target protocol type of the parsed data; Calling a conversion rule from the protocol conversion rule database based on the original protocol type and the target protocol type; The parsed data is subjected to protocol conversion based on the conversion rule, and the data subjected to protocol conversion is subjected to consistency check.
4. The multi-protocol communication system of the 5G edge computing security control gateway module as claimed in claim 3, characterized in that: The protocol conversion module is specifically used for: When the data after the protocol conversion passes the consistency check, the data after the protocol conversion is sent to the security control module; When the data after the protocol conversion fails to pass the consistency check, the error information is recorded, and a correction request is sent to the protocol conversion module to perform the protocol conversion operation again.
5. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 1, characterized in that: The safety control module is specifically used for: Presetting a key and distributing the key to the gateway and the external device; Encrypting the data after the consistency check by using the key and the AES-256 encryption algorithm to obtain encrypted data; A hash algorithm is used to calculate the hash value of the data that has undergone consistency check, and the hash value is used as a data signature to form the encrypted data together with the encrypted data.
6. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 5, characterized in that: The safety control module is also specifically used for: When the external device accesses the gateway, verifying the authentication request sent by the external device; When the device certificate in the authentication request is legitimate, approving the access request of the external device; When the device certificate in the authentication request is illegal, the access request of the external device is rejected.
7. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 1, characterized in that: The communication management module is further specifically used for: Pre-setting a communication resource scheduling table and recording the communication priority and bandwidth requirements of the external device; Based on the communication priority and bandwidth requirements, a polling scheduling algorithm combined with a priority scheduling strategy is used to allocate communication bandwidth and processing time to each of the external devices.
8. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 7, characterized in that: The communication management module is further specifically used for: When the external device is an industrial control device, a processing time of a preset duration is preferentially allocated at fixed time intervals for data processing and transmission; When the external device is a common Internet of Things sensor device, after the industrial control device completes the processing, the remaining resources are used for processing.
9. The multi-protocol communication system of the 5G edge computing security control gateway module according to claim 1, characterized in that: The communication management module is further specifically used for: The communication link status is detected by sending heartbeat packets periodically. When a link failure is detected, the connection is reestablished or switched to a backup link.
10. A multi-protocol communication method for a 5G edge computing security control gateway module, characterized in that: Applied to a 5G edge computing security control gateway module, the gateway module is communicatively connected with a plurality of external devices, and the method includes: Parse the data to be parsed sent by the external device; Perform protocol conversion on the parsed data and perform consistency check on the data after protocol conversion; Encrypt the data that has passed the consistency check; The encrypted data is sent to the external device.
Citation Information
Patent Citations
Internet-of-things proxy device based on edge computing and data decision-making method
CN111901381A
Multi-chain intelligent security gateway for application of Internet of Things and implementation method of multi-chain intelligent security gateway
CN112804310A
Lithium battery production line data platform construction method and system based on cloud edge collaboration
CN116485136A
Cited By
Multi-protocol conversion gateway data interaction method, system and device and storage medium
CN121173882A