Encryption, decryption and communication method
By combining symmetric and asymmetric encryption algorithms in IoT communication, the encrypted symmetric keys, messages and information digests are generated and verified, and the data validity is verified by using timestamps, the problem of lower security in IoT communication is solved and higher data security and integrity is achieved.
Patent Information
- Application Number
- CN202510348830.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-17
AI Technical Summary
The security in existing IoT communications is low, it is difficult to protect the confidentiality and integrity of data, and it is difficult to resist replay attacks.
A symmetric encryption algorithm and asymmetric encryption algorithm are used to generate a symmetric key randomly and encrypt it using the receiving party's public key to generate an encrypted symmetric key, message and information digest. The sender encrypts the data before sending the data and embeds a timestamp in the data to ensure the validity of the data. The receiver uses the private key to decrypt and verify the integrity and validity of the data.
Improves the security of IoT communication, enhances the confidentiality and integrity of data through encryption and timestamp verification, and effectively resists replay attacks.
Smart Images

Figure CN120165855A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things security technologies, and particularly to an encryption, decryption, and communication method. Background Art
[0002] With the development of wireless communication technologies, the Internet of Things has gradually become popular, and information security issues have become increasingly important, especially in the fields of power Internet of Things and industrial Internet of Things. The power industry is the most important basic energy industry, and power security is very important. The data of the power system should also be taken seriously and confidentiality measures should be strengthened.
[0003] In the early days, due to performance problems of the Microcontroller Unit (MCU), using encryption technology would seriously affect communication efficiency. Therefore, in the wireless communication of the Internet of Things industry, most data is transmitted in plain text or only simple symmetric encryption is used, which is difficult to protect the confidentiality and integrity of data, and is also difficult to resist replay attacks, resulting in low security. Summary of the Invention
[0004] The purpose of this application is to provide an encryption, decryption, and communication method to solve the problem of low communication security.
[0005] To achieve the above purpose, this application provides the following solutions:
[0006] In the first aspect, this application provides an encryption method, which is completed by a sender. The sender is a gateway node or an edge node. The encryption method includes:
[0007] Using a symmetric encryption algorithm, randomly generate a symmetric key, add a timestamp to the symmetric key to obtain a symmetric key with a key timestamp;
[0008] Obtain the public key generated by the receiver based on the asymmetric encryption algorithm, and encrypt the symmetric key with the key timestamp based on the public key to obtain an encrypted symmetric key;
[0009] Add a timestamp to the message to be sent to obtain a message with a message timestamp;
[0010] Use the symmetric key to encrypt the message with the message timestamp to obtain an encrypted message;
[0011] Use a message digest algorithm to extract the digest of the message to be sent and generate a first message digest;
[0012] Add a timestamp to the first message digest to obtain a first message digest with a digest timestamp;
[0013] Using the symmetric key, encrypt the first message digest with the digest timestamp to obtain the encrypted first message digest.
[0014] Optionally, the symmetric encryption algorithm is the DSE algorithm, triple DES algorithm or AES algorithm.
[0015] Optionally, the asymmetric encryption algorithm is the RSA algorithm, DSA algorithm or ECC algorithm.
[0016] Optionally, the message digest algorithm is the MD5 algorithm or SHA-1 algorithm.
[0017] In a second aspect, the present application provides a decryption method, which is completed by a receiving party, and the receiving party is a gateway node or an edge node. The decryption method includes:
[0018] Receive the encrypted symmetric key, the encrypted message and the encrypted first message digest;
[0019] Use the private key generated based on the asymmetric encryption algorithm to decrypt the encrypted symmetric key to obtain the decrypted symmetric key and the decrypted key timestamp;
[0020] Use the decrypted symmetric key to decrypt the encrypted message to obtain the decrypted message and the decrypted message timestamp;
[0021] Use the message digest algorithm to extract the digest of the decrypted message to generate a second message digest;
[0022] Use the decrypted symmetric key to decrypt the encrypted first message digest to obtain the decrypted first message digest and the decrypted digest timestamp;
[0023] Determine whether the second message digest is consistent with the decrypted first message digest to obtain a first determination result;
[0024] If the first determination result is negative, send a receive failure response message with a receive timestamp to the sender;
[0025] If the first determination result is positive, send a receive success response message with a receive timestamp to the sender, and determine the validity of the received encrypted symmetric key, encrypted message and encrypted first message digest according to the decrypted key timestamp, decrypted message timestamp and decrypted digest timestamp to obtain a second determination result;
[0026] If the second determination result is positive, send a valid response message with a validity timestamp to the sender;
[0027] If the second judgment result is negative, send a negative response message with a validity timestamp to the sender.
[0028] Thirdly, the present application provides a communication method, which is completed through a transmission system. The transmission system includes: a gateway node and an edge node. When the gateway node is the sender, the edge node is the receiver; when the gateway node is the receiver, the edge node is the sender. The communication method includes:
[0029] The sender generates an encrypted symmetric key, an encrypted message, and an encrypted first information digest, and sends the encrypted symmetric key, the encrypted message, and the encrypted first information digest to the receiver. Among them, the process of generating the encrypted symmetric key, the encrypted message, and the encrypted first information digest includes:
[0030] Using a symmetric encryption algorithm, randomly generate a symmetric key, add a timestamp to the symmetric key to obtain a symmetric key with a key timestamp.
[0031] Obtain the public key generated by the receiver based on the asymmetric encryption algorithm, and encrypt the symmetric key with the key timestamp based on the public key to obtain an encrypted symmetric key.
[0032] Add a timestamp to the message to be sent to obtain a message with a message timestamp.
[0033] Use the symmetric key to encrypt the message with the message timestamp to obtain an encrypted message.
[0034] Use an information digest algorithm to extract a digest of the message to be sent to generate a first information digest.
[0035] Add a timestamp to the first information digest to obtain a first information digest with a digest timestamp.
[0036] Use the symmetric key to encrypt the first information digest with the digest timestamp to obtain an encrypted first information digest.
[0037] The receiver receives the encrypted symmetric key, the encrypted message, and the encrypted first information digest, and decrypts the encrypted symmetric key, the encrypted message, and the encrypted first information digest to achieve communication. Among them, the process of decrypting the encrypted symmetric key, the encrypted message, and the encrypted first information digest includes:
[0038] Use the private key generated based on the asymmetric encryption algorithm to decrypt the encrypted symmetric key to obtain a decrypted symmetric key and a decrypted key timestamp.
[0039] Use the decrypted symmetric key to decrypt the encrypted message to obtain the decrypted message and the decrypted message timestamp;
[0040] Use the information digest algorithm to extract the digest of the decrypted message to generate the second information digest;
[0041] Use the decrypted symmetric key to decrypt the encrypted first information digest to obtain the decrypted first information digest and the decrypted digest timestamp;
[0042] Determine whether the second information digest is consistent with the decrypted first information digest to obtain the first judgment result;
[0043] If the first judgment result is no, send a receive failure response message with the receive timestamp to the sender;
[0044] If the first judgment result is yes, send a receive success response message with the receive timestamp to the sender, and determine the validity of the received encrypted symmetric key, encrypted message, and encrypted first information digest according to the decrypted key timestamp, decrypted message timestamp, and decrypted digest timestamp to obtain the second judgment result;
[0045] If the second judgment result is yes, send a valid response message with the validity timestamp to the sender;
[0046] If the second judgment result is no, send an invalid response message with the validity timestamp to the sender.
[0047] According to the specific embodiments provided in this application, the following technical effects are disclosed in this application:
[0048] This application discloses an encryption, decryption, and communication method. The communication method includes: the sender uses symmetric encryption algorithms, asymmetric encryption algorithms, and information digest algorithms to generate an encrypted symmetric key, an encrypted message, and an encrypted first information digest, and sends the encrypted symmetric key, the encrypted message, and the encrypted first information digest to the receiver; the receiver uses symmetric encryption algorithms, asymmetric encryption algorithms, and information digest algorithms to decrypt and determine the validity of the encrypted symmetric key, the encrypted message, and the encrypted first information digest, and sends a response message to achieve communication. This application combines symmetric encryption algorithms and asymmetric encryption algorithms for encryption and decryption, and determines the validity of the communication messages, improving communication security. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] To more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0050] Figure 1 Schematic diagram of the encryption method flow provided by an embodiment of the present application;
[0051] Figure 2 Schematic diagram of the decryption method flow provided by an embodiment of the present application;
[0052] Figure 3 Schematic diagram of the communication method flow provided by an embodiment of the present application;
[0053] Figure 4 Schematic diagram of the communication method architecture;
[0054] Figure 5 Schematic diagram of the gateway node structure;
[0055] Figure 6 Schematic diagram of the edge node structure. Detailed implementation manners
[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.
[0057] The purpose of the present application is to provide an encryption, decryption and communication method, aiming to improve communication security.
[0058] To make the above objects, features and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0059] In an exemplary embodiment, as Figure 1 shown, an encryption method is provided. The encryption method is completed by the sender, and the sender is a gateway node or an edge node. The encryption method includes:
[0060] Step 11: Use the symmetric encryption algorithm to randomly generate a symmetric key, add a timestamp to the symmetric key, and obtain a symmetric key with a key timestamp.
[0061] Specifically, considering the limited strength of the symmetric encryption algorithm and its vulnerability to cracking, a symmetric key is randomly generated each time for encryption.
[0062] Step 12: Obtain the public key generated by the recipient based on the asymmetric encryption algorithm, and encrypt the symmetric key with the key timestamp based on the public key to obtain the encrypted symmetric key.
[0063] Step 13: Add a timestamp to the message to be sent to obtain a message with a message timestamp.
[0064] Step 14: Use the symmetric key to encrypt the message with the message timestamp to obtain the encrypted message.
[0065] Step 15: Use the information digest algorithm to extract the digest of the message to be sent and generate the first information digest.
[0066] Step 16: Add a timestamp to the first information digest to obtain the first information digest with a digest timestamp.
[0067] Step 17: Use the symmetric key to encrypt the first information digest with the digest timestamp to obtain the encrypted first information digest.
[0068] As an alternative implementation, the symmetric encryption algorithm is the DSE algorithm, the triple DES algorithm, or the AES algorithm.
[0069] As an alternative implementation, the asymmetric encryption algorithm is the RSA algorithm, the DSA algorithm, or the ECC algorithm.
[0070] As an alternative implementation, the information digest algorithm is the MD5 algorithm or the SHA-1 algorithm.
[0071] In an exemplary embodiment, as Figure 2 shown, a decryption method is provided. The decryption method is completed by the recipient, and the recipient is a gateway node or an edge node. The decryption method includes:
[0072] Step 201: Receive the encrypted symmetric key, the encrypted message, and the encrypted first information digest.
[0073] Step 202: Use the private key generated based on the asymmetric encryption algorithm to decrypt the encrypted symmetric key to obtain the decrypted symmetric key and the decrypted key timestamp.
[0074] Step 203: Use the decrypted symmetric key to decrypt the encrypted message to obtain the decrypted message and the decrypted message timestamp.
[0075] Step 204: Use the information digest algorithm to extract the digest of the decrypted message and generate the second information digest.
[0076] Step 205: Use the decrypted symmetric key to decrypt the encrypted first message digest to obtain the decrypted first message digest and the decrypted digest timestamp.
[0077] Step 206: Determine whether the second message digest is the same as the decrypted first message digest to obtain a first determination result.
[0078] Step 207: If the first determination result is negative, send a reception failure response message with the reception timestamp to the sender.
[0079] Step 208: If the first determination result is positive, send a reception success response message with the reception timestamp to the sender, and determine the validity of the received encrypted symmetric key, encrypted message, and encrypted first message digest according to the decrypted key timestamp, decrypted message timestamp, and decrypted digest timestamp to obtain a second determination result.
[0080] Step 209: If the second determination result is positive, send a valid response message with the validity timestamp to the sender.
[0081] Step 210: If the second determination result is negative, send an invalid response message with the validity timestamp to the sender.
[0082] Specifically, to prevent an intruder from performing a replay attack, each piece of data is accompanied by a timestamp, and the receiver determines the validity through the timestamp.
[0083] As an alternative implementation, the asymmetric encryption algorithm is the RSA algorithm, DSA algorithm, or ECC algorithm.
[0084] As an alternative implementation, the message digest algorithm is the MD5 algorithm or SHA-1 algorithm.
[0085] In an exemplary embodiment, as Figure 3 and Figure 4 shown, a communication method is provided. The communication method is completed through a transmission system. The transmission system includes: a gateway node as shown in Figure 5 and an edge node as shown in Figure 6 . When the gateway node is the sender, the edge node is the receiver; when the gateway node is the receiver, the edge node is the sender. The edge node includes an MCU, a wireless communication module, and a data acquisition module. The gateway node includes a wireless reception module and a northbound interface based on wired communication to implement the transmission of the edge node's data to a higher-level device. The communication is two-way communication, and data can be sent from the gateway node to the edge node or from the edge node to the gateway node. The communication method includes:
[0086] Step 31: The sender generates an encrypted symmetric key, an encrypted message, and an encrypted first message digest, and sends the encrypted symmetric key, the encrypted message, and the encrypted first message digest to the receiver; wherein, the process of generating the encrypted symmetric key, the encrypted message, and the encrypted first message digest includes:
[0087] Step 311: Use a symmetric encryption algorithm to randomly generate a symmetric key, add a timestamp to the symmetric key to obtain a symmetric key with a key timestamp.
[0088] Step 312: Obtain the public key generated by the receiver based on the asymmetric encryption algorithm, and encrypt the symmetric key with the key timestamp based on the public key to obtain an encrypted symmetric key.
[0089] Step 313: Add a timestamp to the message to be sent to obtain a message with a message timestamp.
[0090] Step 314: Use the symmetric key to encrypt the message with the message timestamp to obtain an encrypted message.
[0091] Step 315: Use a message digest algorithm to extract a digest from the message to be sent to generate a first message digest.
[0092] Step 316: Add a timestamp to the first message digest to obtain a first message digest with a digest timestamp.
[0093] Step 317: Use the symmetric key to encrypt the first message digest with the digest timestamp to obtain an encrypted first message digest.
[0094] Step 32: The receiver receives the encrypted symmetric key, the encrypted message, and the encrypted first message digest, and decrypts the encrypted symmetric key, the encrypted message, and the encrypted first message digest to achieve communication; wherein, the process of decrypting the encrypted symmetric key, the encrypted message, and the encrypted first message digest includes:
[0095] Step 321: Use the private key generated based on the asymmetric encryption algorithm to decrypt the encrypted symmetric key to obtain a decrypted symmetric key and a decrypted key timestamp.
[0096] Step 322: Use the decrypted symmetric key to decrypt the encrypted message to obtain a decrypted message and a decrypted message timestamp.
[0097] Step 323: Use a message digest algorithm to extract a digest from the decrypted message to generate a second message digest.
[0098] Step 324: Use the decrypted symmetric key to decrypt the encrypted first message digest to obtain the decrypted first message digest and the decrypted digest timestamp.
[0099] Step 325: Determine whether the second message digest is consistent with the decrypted first message digest to obtain a first determination result.
[0100] Step 326: If the first determination result is negative, send a reception failure response message with the reception timestamp to the sender.
[0101] Step 327: If the first determination result is positive, send a reception success response message with the reception timestamp to the sender, and determine the validity of the received encrypted symmetric key, encrypted message, and encrypted first message digest according to the decrypted key timestamp, decrypted message timestamp, and decrypted digest timestamp to obtain a second determination result.
[0102] Step 328: If the second determination result is positive, send a valid response message with the validity timestamp to the sender.
[0103] Step 329: If the second determination result is negative, send an invalid response message with the validity timestamp to the sender.
[0104] As an optional implementation manner, the symmetric encryption algorithm is the DSE algorithm, triple DES algorithm, or AES algorithm.
[0105] As an optional implementation manner, the asymmetric encryption algorithm is the RSA algorithm, DSA algorithm, or ECC algorithm.
[0106] As an optional implementation manner, the message digest algorithm is the MD5 algorithm or SHA-1 algorithm.
[0107] The technical features of the above embodiments can be combined arbitrarily. For the sake of brief description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0108] Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. An encryption method, wherein the encryption method is performed by a sender, wherein the sender is a gateway node or an edge node, wherein: The encryption method comprises: Using a symmetric encryption algorithm, randomly generating a symmetric key, adding a timestamp to the symmetric key, and obtaining a symmetric key with a key timestamp; Obtaining a public key generated by the recipient based on an asymmetric encryption algorithm, and encrypting the symmetric key with a key timestamp based on the public key to obtain an encrypted symmetric key; Add a timestamp to the message to be sent, and obtain a message with a message timestamp; Using the symmetric key, encrypting the message with the message timestamp to obtain an encrypted message; Using an information digest algorithm, extracting a summary of the message to be sent to generate a first information digest; Adding a timestamp to the first information digest to obtain a first information digest with a digest timestamp; The first information digest with the digest timestamp is encrypted using the symmetric key to obtain the encrypted first information digest.
2. The encryption method according to claim 1, characterized in that: The symmetric encryption algorithm is a DSE algorithm, a triple DES algorithm or an AES algorithm.
3. The encryption method according to claim 1, characterized in that: The asymmetric encryption algorithm is an RSA algorithm, a DSA algorithm or an ECC algorithm.
4. The encryption method according to claim 1, characterized in that: The information digest algorithm is the MD5 algorithm or the SHA-1 algorithm.
5. A decryption method, wherein the decryption method is performed by a receiver, wherein the receiver is a gateway node or an edge node, wherein: The decryption method comprises: Receiving an encrypted symmetric key, an encrypted message, and an encrypted first information digest; Using the private key generated based on the asymmetric encryption algorithm, the encrypted symmetric key is decrypted to obtain the decrypted symmetric key and the decrypted key timestamp; Decrypt the encrypted message using the decrypted symmetric key to obtain the decrypted message and the decrypted message timestamp; Using the information digest algorithm, extracting the digest of the decrypted message to generate a second information digest; Decrypting the encrypted first information digest using the decrypted symmetric key to obtain the decrypted first information digest and the decrypted digest timestamp; Determine whether the second information digest is consistent with the decrypted first information digest, and obtain a first determination result; If the first judgment result is no, sending a reception failure response message with a reception timestamp to the sender; If the first judgment result is yes, a successful reception response message with a reception timestamp is sent to the sender, and the validity of the received encrypted symmetric key, the encrypted message and the encrypted first information digest is judged according to the decrypted key timestamp, the decrypted message timestamp and the decrypted summary timestamp to obtain a second judgment result; If the second judgment result is yes, sending a valid response message with a validity timestamp to the sender; If the second judgment result is no, an invalid response message with a validity timestamp is sent to the sender.
6. The decryption method according to claim 5, characterized in that: The asymmetric encryption algorithm is an RSA algorithm, a DSA algorithm or an ECC algorithm.
7. The decryption method according to claim 5, characterized in that: The information digest algorithm is the MD5 algorithm or the SHA-1 algorithm.
8. A communication method, the communication method being performed by a transmission system, the transmission system comprising: A gateway node and an edge node, when the gateway node is a sender, the edge node is a receiver, when the gateway node is a receiver, the edge node is a sender, characterized in that the communication method includes: The sender generates an encrypted symmetric key, an encrypted message, and an encrypted first information digest, and sends the encrypted symmetric key, the encrypted message, and the encrypted first information digest to the receiver; wherein the process of generating the encrypted symmetric key, the encrypted message, and the encrypted first information digest includes: Using a symmetric encryption algorithm, randomly generating a symmetric key, adding a timestamp to the symmetric key, and obtaining a symmetric key with a key timestamp; Obtaining a public key generated by the recipient based on an asymmetric encryption algorithm, and encrypting the symmetric key with a key timestamp based on the public key to obtain an encrypted symmetric key; Add a timestamp to the message to be sent, and obtain a message with a message timestamp; Using the symmetric key, encrypting the message with the message timestamp to obtain an encrypted message; Using an information digest algorithm, extracting a summary of the message to be sent to generate a first information digest; Adding a timestamp to the first information digest to obtain a first information digest with a digest timestamp; Using the symmetric key, encrypting the first information digest with the digest timestamp to obtain an encrypted first information digest; The receiving party receives the encrypted symmetric key, the encrypted message and the encrypted first information digest, and decrypts the encrypted symmetric key, the encrypted message and the encrypted first information digest to achieve communication; wherein the process of decrypting the encrypted symmetric key, the encrypted message and the encrypted first information digest includes: Using the private key generated based on the asymmetric encryption algorithm, the encrypted symmetric key is decrypted to obtain the decrypted symmetric key and the decrypted key timestamp; Decrypt the encrypted message using the decrypted symmetric key to obtain the decrypted message and the decrypted message timestamp; Using the information digest algorithm, extracting the digest of the decrypted message to generate a second information digest; Decrypting the encrypted first information digest using the decrypted symmetric key to obtain the decrypted first information digest and the decrypted digest timestamp; Determine whether the second information digest is consistent with the decrypted first information digest, and obtain a first determination result; If the first judgment result is no, sending a reception failure response message with a reception timestamp to the sender; If the first judgment result is yes, a successful reception response message with a reception timestamp is sent to the sender, and the validity of the received encrypted symmetric key, the encrypted message and the encrypted first information digest is judged according to the decrypted key timestamp, the decrypted message timestamp and the decrypted summary timestamp to obtain a second judgment result; If the second judgment result is yes, sending a valid response message with a validity timestamp to the sender; If the second judgment result is no, an invalid response message with a validity timestamp is sent to the sender.
9. The communication method according to claim 8, characterized in that: The symmetric encryption algorithm is a DSE algorithm, a triple DES algorithm or an AES algorithm.
10. The communication method according to claim 8, characterized in that: The asymmetric encryption algorithm is an RSA algorithm, a DSA algorithm or an ECC algorithm.