Internet of Things data transmission security enhancement method combined with quantum random number generation

By combining quantum random number generation technology and dynamic key management, the problem of difficulty in ensuring the security of IoT data transmission in the long term is solved, and high-security data transmission is achieved, common risks in key management are prevented, and the security and efficiency of the system are improved.

CN120165864APending Publication Date: 2025-06-17ZHONGHUITONG ECOLOGICAL TECH (SHANDONG) CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510496977.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

When facing the challenges of cyber attacks and key management, existing IoT data transmission security solutions are difficult to ensure long-term security. Key synchronization and management are complex, and risks such as leakage, synchronization failure and reuse are prone to risks.

Method used

Combining the quantum random number generation technology, dynamic key management and automatic update and destruction mechanism are adopted to generate device binding keys and session keys, dynamic encryption keys are generated in real time for each data logical segment through the quantum random number generator, and data is transmitted through the multi-path randomization protocol.

Benefits of technology

It significantly improves the security of IoT data transmission, prevents risks such as key leakage, synchronization failure and multiplexing, ensures unpredictability and high attack resistance of keys, and reduces human operation errors through automated management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165864A_ABST
    Figure CN120165864A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things data transmission security enhancement method combined with quantum random number generation, which comprises the following steps of: generating a high-security and unpredictable random number seed through a quantum random number generator, and generating a dynamic binding key in combination with a unique identifier of equipment and a timestamp, the binding key is used for generating a shared session key between devices through a quantum secure handshake protocol, so that the confidentiality and integrity of data transmission are ensured, a dynamic key updating mechanism is introduced, the binding key and the session key are updated regularly, the security risk caused by long-term use of the same key is avoided, a key destruction mechanism is designed, and the security of data transmission is ensured. A session key is completely destroyed after a session is ended, a malicious attacker is prevented from recovering the key, and a standby key generation and synchronization mechanism ensures that the system can automatically switch to a standby key when key synchronization fails or communication is abnormal, so that data transmission is not affected. The method has the advantages of good expandability and high safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission security, and particularly to a method for enhancing the security of Internet of Things (IoT) data transmission combined with quantum random number generation. Background Art

[0002] With the wide application of IoT technology, IoT devices have penetrated into various industries, such as smart home, industrial automation, healthcare, intelligent transportation, etc. The popularization of the IoT has greatly improved the data transmission efficiency and information processing ability. However, at the same time, it has also brought challenges in data security and privacy protection. IoT devices usually operate in an open network environment and are vulnerable to various network attacks, such as man-in-the-middle attacks, replay attacks, data tampering, etc. Therefore, how to ensure secure data transmission between IoT devices has become an urgent technical problem to be solved.

[0003] Existing IoT data transmission security solutions mainly rely on encryption technologies and key management methods. Traditional encryption technologies, such as symmetric encryption, asymmetric encryption, and public key infrastructure solutions, are usually used to ensure the confidentiality and integrity of data transmission. However, the application of these technologies in the IoT environment faces some challenges. Most IoT devices have limited resources, and traditional encryption algorithms may cause a large computational and storage burden. Traditional key management schemes often rely on centralized key management systems, which are easy to become targets of attacks. Once the key is leaked or cracked, the entire communication process will face great security risks.

[0004] In addition, random number generation is a crucial part of encryption algorithms. The random numbers generated by traditional pseudo-random number generators have obvious deficiencies in security and unpredictability. Attackers may be able to predict or reproduce these random numbers, thereby compromising the security of the key. Therefore, key management methods based on quantum random number generation are of great significance. Quantum random number generators use the unpredictability of quantum physics to generate truly random numbers. Compared with traditional pseudo-random number generators, they have stronger randomness in the generation process and can effectively avoid the risks of being predicted and cracked.

[0005] Although existing IoT security solutions can prevent common attacks, such as man-in-the-middle attacks and replay attacks, to a certain extent, they usually rely on fixed keys and static encryption mechanisms, which results in the security of the system not being guaranteed in the long term. If the key is used for a long time or not updated in a timely manner, it is extremely easy to be cracked or leaked by attackers, thus affecting the security of the entire system. At the same time, the key synchronization mechanism is often complex and prone to synchronization failures in the case of a large number of devices. With the rapid increase in the number of IoT devices and the complexity of application scenarios, traditional security solutions have become difficult to cope with these challenges.

[0006] Therefore, how to provide a method for enhancing the security of Internet of Things (IoT) data transmission combined with quantum random number generation is an urgent problem that needs to be solved by those skilled in the art. Summary of the Invention

[0007] An object of the present invention is to propose a method for enhancing the security of IoT data transmission combined with quantum random number generation. The present invention makes full use of quantum random number generation technology, dynamic key management, and key automatic update and destruction mechanisms, and details how to achieve secure data transmission between IoT devices. By combining highly secure random numbers generated by a quantum random number generator, device binding keys and session keys are generated, and an automated key update and destruction mechanism is adopted. The present invention significantly improves the security of data transmission and prevents risks such as leakage, synchronization failure, and key reuse in traditional key management.

[0008] A method for enhancing the security of IoT data transmission combined with quantum random number generation according to an embodiment of the present invention includes the following steps:

[0009] S1. Use a quantum random number generator to generate a unique random number seed for the device, and generate a binding key based on the random number seed and the device unique identifier;

[0010] S2. The sender and the receiver execute a secure handshake protocol through the binding key of the device, use a quantum random number generator to generate a negotiated random number, and generate a shared session key by combining a preset negotiation algorithm. The session key is only valid in the current communication session, and is destroyed after key synchronization to avoid long-term storage risks;

[0011] S3. Divide the data to be transmitted into logical segments, and use a quantum random number generator to generate independent dynamic encryption keys for each logical segment in real time. The dynamic key for each segment of data is derived from the session key and bound to a time stamp, so that there is a one-to-one correspondence between data segmentation and key distribution;

[0012] S4. Encrypt the segmented data using the corresponding dynamic keys respectively, and transmit the encrypted data segments through a multi-path randomization protocol in combination with a path selection scheme generated by a quantum random number generator. The path randomization scheme is dynamically adjusted during the transmission process to optimize the path anti-monitoring ability and interception risk;

[0013] S5. The receiver, based on the dynamic key synchronization mechanism, obtains the corresponding keys in real time and decrypts each segment of encrypted data one by one. Integrity verification is performed on each segment of decrypted data in combination with the embedded data check code. If decryption failure and verification error are detected, a retransmission request is triggered and the sender is notified to generate a backup key for re-encryption and transmission;

[0014] S6. During the communication process, the status of the quantum random number generator, key synchronization, and data transmission integrity are monitored in real time. If abnormal random number generation, key synchronization failure, and path interruption are detected, a backup key generation mechanism is triggered, and at the same time, the data transmission path is adjusted to restore communication and maintain security;

[0015] S7. During the entire life cycle of device communication, the device random number seed, binding key, and dynamic key are regularly updated through the quantum random number generator, and expired and redundant keys are actively destroyed. The complete logs of key generation, data transmission, and exception recovery are recorded and stored in the non-tamperable secure storage area of the device.

[0016] Optionally, the specific content of S1 includes:

[0017] S11. Generate a unique random number seed r for the device through the quantum random number generator. The random number seed r s is a random binary string of length L r . The generation process is carried out through the quantum random number generator QNRG. The random number seed r s has unpredictability and high security;

[0018] S12. Based on the random number seed r s and the device unique identifier UID, generate the binding key K bind . The generation process combines the timestamp T and the session counter C to make the binding key unique and dynamic at the time and session levels:

[0019] K bind = H(H(r s ) || UID || T || C);

[0020] where H is a hash function, || represents the concatenation operation, T is the timestamp when the key is generated, and C is the communication session counter;

[0021] S13. Store the generated binding key K bind in the security module of the device. The security module protects the security of the key through a dual encryption mechanism. The first layer of encryption uses a hardware encryption module, and the second layer of encryption uses the private key of the device for encrypted storage, so that the key cannot be extracted due to physical attacks and unauthorized access;

[0022] S14. During the device communication process, through a regular trigger mechanism, the device random number seed r s and the binding key K bind are updated based on the quantum random number generator to avoid security risks caused by long-term use of the same key. After each update, the binding key K bindGenerate a new key based on a new random number seed and timestamp, and update it in the secure module;

[0023] S15. Each time a binding key is generated, the key is verified through the authentication mechanisms inside and outside the device to ensure the validity of the key. The external authentication mechanism includes verifying the validity of the key through an authentication server, and the internal authentication mechanism performs integrity verification on the generated key to ensure the accuracy of the key and that it has not been tampered with.

[0024] Optionally, the specific steps of S2 are as follows:

[0025] S21. After the sender and receiver execute the secure handshake protocol through the device's binding key K bind a negotiated random number r c is generated. The negotiated random number r c is generated by a quantum random number generator, making it highly secure and unpredictable, and is a random binary string of length L c ;

[0026] S22. Based on the negotiated random number r c , the device binding key K bind , the device unique identifier UID, and the timestamp T of the current session, the sender and receiver jointly generate a shared session key K session through a preset negotiation algorithm. The session key is only valid in the current communication session and has uniqueness and dynamism;

[0027] S23. Immediately after the session key K session is generated, it is verified through the mutual authentication mechanism. The authentication process includes the sender and receiver respectively performing integrity verification on K session and confirming the key consistency and validity, so that the key is not tampered with during the entire session;

[0028] S24. During the session, if an exception occurs during the communication process, the sender and receiver immediately trigger the backup key generation mechanism and simultaneously destroy the current session key K session , so that unauthorized access cannot obtain the original key;

[0029] S25. Whenever the session ends and times out, the destruction mechanism of the session key K session is triggered, and K session is automatically destroyed by the secure module in the device, so that the key is completely cleared after storage and use and cannot be recovered;

[0030] S26. The session key destruction process is controlled by the device secure module and uses a dual verification mechanism to perform in-memory verification on the session key K sessionPerform a clearing operation so that the key is no longer stored in any memory location. Verify the completion of the destruction operation through the hardware encryption module to securely delete the session key and prevent any form of recovery operation.

[0031] Optionally, the S3 specifically includes:

[0032] S31: Divide the data to be transmitted into multiple logical segments according to a predetermined standard. Each logical segment corresponds to an independent data unit, and the standard includes data size, transmission priority, and real-time requirements.

[0033] S32: Generate an independent dynamic encryption key for each logical segment in real time. The key generation is through a quantum random number generator, and the random number seed r provided by the quantum random number generator s is represented by a binary string of length L r and the random number seed r s is highly random and unpredictable.

[0034] S33: Derive the dynamic encryption key K of each logical segment based on the session key K session such that the dynamic key K dynamic combines the timestamp T and the current logical segment identifier ID, making the key of each data segment unique and time-sensitive. dynamic

[0035] S34: Use the generated dynamic key K dynamic to encrypt the corresponding logical segment data. The encryption process uses a symmetric encryption algorithm, and the initialization vector IV for encryption is determined by the quantum random number generator, making the data encryption process of each logical segment highly secure.

[0036] S35: During the transmission of the encrypted data, the data of each logical segment and its dynamic key K dynamic are transmitted through a secure channel, and the dynamic key is automatically destroyed after the data transmission is completed, preventing the key from being stored for a long time and preventing leakage.

[0037] S36: The receiving end decrypts the data segment by segment based on the predetermined decryption algorithm and the corresponding dynamic key K dynamic The decryption process includes integrity check and verification. If anomalies and data tampering are found, trigger the data retransmission mechanism and require the sending end to regenerate a backup key to encrypt the data and retransmit it.

[0038] Optionally, the S4 specifically includes:

[0039] S41: After receiving the encrypted data, the receiving end, based on the dynamic key K dynamic, decrypt the data segment by segment through a predetermined decryption algorithm. The decryption process includes integrity verification of each data segment, and the verification code is generated by the sender during encryption and transmitted along with the data;

[0040] S42. If the verification fails and the data is tampered with, trigger the data retransmission mechanism. The sender regenerates the backup key K according to the current session key K session and the quantum random number generator, and re-encrypt the data; dynamic

[0041] S43. The encrypted data is retransmitted to the receiver through a secure channel, and the dynamic key K of the retransmitted data dynamic is immediately destroyed after the data is successfully received, so that the key is not stored for a long time and leakage is prevented;

[0042] S44. During the data transmission process, the receiver dynamically adjusts the data transmission path according to the real-time network status. The path adjustment is based on the network status function:

[0043] P select = F(B path , L path , F path );

[0044] where P select is the path selection priority, B path is the path bandwidth, L path is the path delay, F path is the path load, and F is the weighting function;

[0045] S45. If the network status changes, resulting in the performance index of the path exceeding the predetermined threshold, trigger the path re-selection mechanism, so that the data transmission always passes through the optimal path.

[0046] Optionally, the S5 specifically includes:

[0047] S51. After the receiver receives the encrypted data, based on the dynamic key K dynamic , decrypt the data segment by segment through a predetermined decryption algorithm, and perform integrity verification on each data segment. The verification code is generated by the sender during encryption and transmitted along with the data;

[0048] S52. The data integrity verification is performed through the following verification function. The verification code C data is the encrypted hash value of the data segment D i and the key K dynamic ;

[0049] S53. If the data verification fails and the data is tampered with, trigger the data retransmission mechanism. The sender regenerates the backup key K according to the current session key K sessionRegenerate the backup dynamic key K with the quantum random number generator dynamic , and re - encrypt the data through the encryption algorithm and then transmit it;

[0050] S54. The encrypted data is re - transmitted to the receiving end through a secure channel. The re - transmitted data and its corresponding dynamic key K dynamic will be immediately destroyed after successful reception to avoid long - term storage and leakage of the key;

[0051] S55. During the data transmission process, the receiving end dynamically adjusts the data transmission path according to the real - time network conditions. The path selection is optimized through the path selection priority function:

[0052]

[0053] where P select is the priority of path selection, ω i is the weight factor of path i, B path (i) is the bandwidth of path i, L path (i) is the delay of path i, F path (i) is the load of path i, α i and β i are adjustment factors;

[0054] S56. If the network state changes, resulting in the path performance index exceeding the predetermined threshold, trigger the path re - selection mechanism to ensure that data transmission always occurs through the optimal path. The trigger mechanism is triggered by the following path selection adjustment equation:

[0055] ΔP adjust =G(|P current - P optimal |,T);

[0056] where ΔP adjust is the path priority adjustment amount, P current is the current path priority, P optimal is the optimal path priority, T is the dynamic threshold of network load and delay, and G is the path adjustment function.

[0057] Optionally, the specific content of S6 includes:

[0058] S61. During the communication process, the receiving end monitors the status of the quantum random number generator, the key synchronization situation, and the integrity of data transmission in real - time. If abnormal random number generation, key synchronization failure, and path interruption are detected, trigger the backup key generation mechanism;

[0059] S62. The backup key K backup is generated through the following formula:

[0060] K backup = G(K session , T′, ε(r temp ), C env );

[0061] Wherein, G is a key generation function, K session is the current session key, T′ is a newly generated timestamp, ε(r temp ) is an operation for entropy expansion of the temporary random number r temp , and C env is the weighted state value of the environmental conditions;

[0062] S63. After the backup key K backup is generated, the receiver and the sender perform key synchronization through a secure channel to ensure the effectiveness and consistency of the backup key. If the synchronization is successful, data transmission continues;

[0063] S64. If the synchronization fails, a new backup key is regenerated according to the new network conditions and the path adjustment mechanism is triggered to ensure that data transmission is not interrupted;

[0064] S65. The data transmission path is optimized through the following dynamic selection function:

[0065]

[0066] Wherein, P adjusted is the adjusted path priority, is the traffic state of the current path, is the path load change amount, T threshold is the threshold parameter for dynamic path selection, is the path selection adjustment function;

[0067] S66. When the path priority and the synchronization mechanism are abnormal, resulting in a decline in network performance, the backup key update and path re-selection mechanism are triggered to ensure the continuous security of communication.

[0068] Optionally, the S7 specifically includes:

[0069] S71. During the entire life cycle of device communication, new random number seeds are regularly generated through a quantum random number generator, and the binding key K bind and the dynamic key K dynamic of the device are updated based on the seeds;

[0070] S72. After the key is updated, the expired and redundant keys are actively destroyed, and the destruction process is completed through a hardware encryption module, so that the keys are completely cleared after storage and use, and will not be recovered and misused again;

[0071] S73. During the key update and destruction process, the device makes an integrity record for each step of the key update. The record includes the timestamp, generation algorithm, parameters involved in the calculation, and their encryption verification information of each generated key. All the recorded data forms a complete log.

[0072] S74. The log data is encrypted using a symmetric encryption algorithm, and the key K log is generated by the security module in the device and updated regularly. The encrypted log will be stored in the non-tamperable area of the device, which is protected by a hardware encryption module to ensure the security and integrity of the log and prevent any form of unauthorized access and modification.

[0073] S75. The content of the log record includes processes such as key generation, key update, data transmission, and exception recovery. And the device regularly verifies the content of the log. If an anomaly is found during the verification, the log verification mechanism will be triggered.

[0074] S76. After the log data is stored, the device synchronizes the encrypted log to an external secure storage unit through a redundant backup mechanism, so that in case of device failure and attack, the log will not be lost or damaged, and can be restored through a secure recovery mechanism.

[0075] The beneficial effects of the present invention are as follows:

[0076] By combining the quantum random number generation technology and the dynamic key management mechanism, the present invention effectively improves the security of IoT data transmission. In the traditional IoT data transmission process, key management faces multiple potential security risks, such as key leakage, key reuse, synchronization failure, and data tampering during communication. The present invention uses a quantum random number generator to generate random numbers with high security, ensuring the unpredictability and high anti-attack ability of the key, thus greatly enhancing the communication security between IoT devices.

[0077] The dynamic key update and destruction mechanism proposed by the present invention can ensure the uniqueness of the session key in each communication process and automatically destroy it when the session ends or an exception occurs, preventing the security risks brought by long-term key storage. This mechanism effectively avoids the attack risks caused by the long-term immutability of the key or key synchronization failure in the traditional method.

[0078] The present invention also improves the key generation and distribution efficiency by combining multiple steps such as quantum random number generation, device-bound key generation, session key negotiation and verification, making the entire communication process smoother and more efficient. At the same time, the automated key management and verification process further reduces human operation errors, ensuring that the key is always in an effective and secure state in the IoT environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0079] The accompanying drawings are used to provide a further understanding of the present invention and form a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the accompanying drawings:

[0080] Figure 1 is a flowchart of a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation proposed by the present invention;

[0081] Figure 2 is a flowchart of the generation and verification of binding keys based on quantum random number generation of the present invention;

[0082] Figure 3 is a flowchart of the generation and destruction of session keys proposed by the present invention. Detailed implementation manners

[0083] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only showing the basic structure of the present invention in a schematic manner, so they only show the components related to the present invention.

[0084] Refer to Figures 1-3 , a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation, comprising the following steps:

[0085] S1. Use a quantum random number generator to generate a unique random number seed for the device, and generate a binding key based on the random number seed and the unique device identifier;

[0086] S2. The sender and the receiver execute a secure handshake protocol through the binding key of the device, use quantum random numbers to generate negotiation random numbers, and generate a shared session key in combination with a preset negotiation algorithm. The session key is only valid in the current communication session, and is destroyed after key synchronization to avoid long-term storage risks;

[0087] S3. Divide the data to be transmitted into logical segments, and use a quantum random number generator to generate independent dynamic encryption keys for each logical segment in real time. The dynamic key for each segment of data is derived from the session key and bound to a time stamp, so that there is a one-to-one correspondence between the data segments and the key distribution;

[0088] S4. Encrypt the segmented data respectively using the corresponding dynamic keys, and transmit the encrypted data segments through a multi-path randomization protocol in combination with the path selection scheme generated by the quantum random number generator. The path randomization scheme is dynamically adjusted during the transmission process to optimize the path anti-monitoring ability and interception risk;

[0089] S5. The receiving end, based on the dynamic key synchronization mechanism, obtains the corresponding key in real time and decrypts each segment of the encrypted data segment by segment. It performs integrity verification on each decrypted data segment in combination with the embedded data check code. If decryption failure and verification error are detected, a retransmission request is triggered and the sending end is notified to generate a backup key for re-encryption and transmission.

[0090] S6. During the communication process, the status of the quantum random number generator, key synchronization situation, and data transmission integrity are monitored in real time. If abnormal random number generation, key synchronization failure, and path interruption are detected, a backup key generation mechanism is triggered, and at the same time, the data transmission path is adjusted to restore communication and maintain security.

[0091] S7. During the entire life cycle of device communication, the device random number seed, bound key, and dynamic key are updated regularly through the quantum random number generator, and expired and redundant keys are actively destroyed. The complete logs of key generation, data transmission, and exception recovery are recorded and stored in the non-tamperable secure storage area of the device.

[0092] In this embodiment, the S1 specifically includes:

[0093] S11. Generate a device-unique random number seed r through the quantum random number generator. The random number seed r s is a random binary string with a length of L r . The generation process is carried out through the quantum random number generator QNRG. The random number seed r s has unpredictability and high security.

[0094] S12. Based on the random number seed r s and the device unique identifier UID, generate the bound key K bind . The generation process combines the timestamp T and the session counter C, making the bound key unique and dynamic at the time and session levels:

[0095] K bind = H(H(r s ) || UID || T || C);

[0096] where H is a hash function, || represents the concatenation operation, T is the timestamp when the key is generated, and C is the communication session counter.

[0097] S13. Store the generated bound key K bind in the security module of the device. The security module protects the security of the key through a dual encryption mechanism. The first layer of encryption uses a hardware encryption module, and the second layer of encryption uses the private key of the device for encrypted storage, so that the key cannot be extracted due to physical attacks and unauthorized access.

[0098] S14. During the device communication process, through a regular triggering mechanism, update the random number seed r of the device based on a quantum random number generator s and the binding key K bind , to avoid security risks caused by long-term use of the same key. After each update, the binding key K bind generates a new key based on the new random number seed and timestamp, and updates and stores it in the security module;

[0099] S15. Each time a binding key is generated, the key is verified through the authentication mechanisms inside and outside the device, so as to ensure the validity of the key. The external authentication mechanism includes verifying the validity of the key through an authentication server, and the internal authentication mechanism performs integrity verification on the generated key to ensure the accuracy and integrity of the key.

[0100] In this embodiment, the S2 specifically includes:

[0101] S21. After the sender and the receiver execute the secure handshake protocol through the device binding key K bind , generate a negotiation random number r c , and the negotiation random number r c is generated by a quantum random number generator, making it highly secure and unpredictable, and is a random binary string with a length of L c ;

[0102] S22. Based on the negotiation random number r c , the device binding key K bind , the device unique identifier UID, and the timestamp T of the current session, the sender and the receiver jointly generate a shared session key K session through a preset negotiation algorithm. The session key is only valid in the current communication session and has uniqueness and dynamics;

[0103] S23. Immediately after the session key K session is generated, it is verified through the mutual authentication mechanism. The authentication process includes that the sender and the receiver respectively perform integrity verification on K session , and confirm the key consistency and validity, so that the key is not tampered with during the entire session;

[0104] S24. During the session, if an abnormality occurs during the communication process, the sender and the receiver immediately trigger the backup key generation mechanism, and at the same time destroy the current session key K session , so that unauthorized access cannot obtain the original key;

[0105] S25. Whenever the session ends and times out, trigger the destruction mechanism of the session key K session , and automatically destroy K session, so that the key is completely cleared after storage and use and cannot be recovered;

[0106] S26. The session key destruction process is controlled by the device security module, using a dual-verification mechanism to clear the session key K in memory, so that the key is no longer stored in any memory location, and the destruction operation is verified by the hardware encryption module to securely delete the session key and prevent any form of recovery operation. session Perform a clearing operation on it, so that the key is no longer stored in any memory location, verify the completion of the destruction operation through the hardware encryption module, securely delete the session key, and prevent any form of recovery operation.

[0107] In this embodiment, the specific steps of S3 are as follows:

[0108] S31. Divide the data to be transmitted into multiple logical segments according to a predetermined standard, and each logical segment corresponds to an independent data unit. The standards include data size, transmission priority, and real-time requirements;

[0109] S32. Generate an independent dynamic encryption key for each logical segment in real time. The key generation is performed by a quantum random number generator, and the random number seed r provided by the quantum random number generator s is represented by a binary string of length L r The random number seed r s is highly random and unpredictable;

[0110] S33. Derive the dynamic encryption key K of each logical segment based on the session key K session The dynamic key K dynamic combines the timestamp T and the current logical segment identifier ID to make the key of each data segment unique and time-sensitive; dynamic Combined with the timestamp T and the current logical segment identifier ID, the key of each data segment has uniqueness and timeliness;

[0111] S34. Use the generated dynamic key K dynamic to encrypt the corresponding logical segment data. The encryption process uses a symmetric encryption algorithm, and the initialization vector IV for encryption is determined by the quantum random number generator, making the data encryption process of each logical segment highly secure;

[0112] S35. During the transmission of the encrypted data, the data of each logical segment and its dynamic key K dynamic are transmitted through a secure channel, and the dynamic key is automatically destroyed after the data transmission is completed, so that the key is not stored for a long time and leakage is prevented;

[0113] S36. The receiving end decrypts the data segment by segment based on a predetermined decryption algorithm and the corresponding dynamic key K dynamic The decryption process includes integrity check and verification. If anomalies and data tampering are found, a data retransmission mechanism is triggered, and the sending end is required to regenerate a backup key to encrypt the data and retransmit it.

[0114] In this embodiment, S4 specifically includes:

[0115] S41. After the receiving end receives the encrypted data, based on the dynamic key K dynamic , decrypt the data segment by segment through a predetermined decryption algorithm. The decryption process includes integrity verification of each data segment, and the verification code is generated by the sending end during encryption and transmitted along with the data;

[0116] S42. If the verification fails and the data is tampered with, trigger the data retransmission mechanism. The sending end regenerates the backup key K session according to the current session key K dynamic and the quantum random number generator, and re-encrypt the data;

[0117] S43. The encrypted data is retransmitted to the receiving end through a secure channel. The dynamic key K dynamic of the retransmitted data is immediately destroyed after the data is successfully received, so that the key is not stored for a long time and leakage is prevented;

[0118] S44. During the data transmission process, the receiving end dynamically adjusts the data transmission path according to the real-time network status. The path adjustment is based on the network status function:

[0119] P select = F(B path , L path , F path );

[0120] where, P select is the path selection priority, B path is the path bandwidth, L path is the path delay, F path is the path load, and F is the weighting function;

[0121] S45. If the network status changes, resulting in the performance index of the path exceeding the predetermined threshold, trigger the path re-selection mechanism, so that the data transmission always proceeds through the optimal path.

[0122] In this embodiment, S5 specifically includes:

[0123] S51. After the receiving end receives the encrypted data, based on the dynamic key K dynamic , decrypt the data segment by segment through a predetermined decryption algorithm, and perform integrity verification on each data segment. The verification code is generated by the sending end during encryption and transmitted along with the data;

[0124] S52. The data integrity verification is performed through the following verification function. The verification code C data is the encrypted hash value of the data segment D i and the key K dynamic ;

[0125] S53. If the data verification fails and the data is tampered with, trigger the data retransmission mechanism. The sender regenerates the backup dynamic key K according to the current session key K session and the quantum random number generator, and re - encrypts the data through the encryption algorithm and then transmits it; dynamic

[0126] S54. The encrypted data is re - transmitted to the receiver through a secure channel. The re - transmitted data and its corresponding dynamic key K dynamic will be destroyed immediately after successful reception to avoid long - term storage and leakage of the key;

[0127] S55. During the data transmission process, the receiver dynamically adjusts the data transmission path according to the real - time network conditions. The path selection is optimized through the path selection priority function:

[0128]

[0129] where P select is the priority of path selection, ω i is the weight factor of path i, B path (i) is the bandwidth of path i, L path (i) is the delay of path i, F path (i) is the load of path i, α i and β i are adjustment factors;

[0130] S56. If the network state changes, resulting in the path performance index exceeding the predetermined threshold, trigger the path re - selection mechanism to ensure that the data transmission always occurs through the optimal path. The trigger mechanism is triggered by the following path selection adjustment equation:

[0131] ΔP adjust =G(|P current -P optimal |,T);

[0132] where ΔP adjust is the path priority adjustment amount, P current is the current path priority, P optimal is the optimal path priority, T is the dynamic threshold of network load and delay, and G is the path adjustment function.

[0133] In this embodiment, the specific content of S6 includes:

[0134] ​S61. During the communication process, the receiving end monitors the status of the quantum random number generator, the key synchronization situation, and the integrity of data transmission in real time. If abnormal random number generation, key synchronization failure, and path interruption are detected, a backup key generation mechanism is triggered;

[0135] S62. The backup key K backup is generated through the following formula:

[0136] K backup = G(K session , T′, ε(r temp ), C env );

[0137] where G is the key generation function, K session is the current session key, T′ is the newly generated timestamp, ε(r temp ) is the operation of entropy expansion on the temporary random number r temp , and C env is the weighted state value of the environmental conditions;

[0138] S63. After the backup key K backup is generated, the receiving end and the sending end perform key synchronization through a secure channel to ensure the effectiveness and consistency of the backup key. If the synchronization is successful, data transmission continues;

[0139] S64. If the synchronization fails, a backup key is regenerated according to the new network conditions and a path adjustment mechanism is triggered to ensure that data transmission is not interrupted;

[0140] S65. The data transmission path is optimized through the following dynamic selection function:

[0141]

[0142] where P adjusted is the adjusted path priority, is the traffic status of the current path, is the path load change amount, T threshold is the threshold parameter for dynamic path selection, is the path selection adjustment function;

[0143] S66. When abnormalities occur in the path priority and synchronization mechanism, resulting in a decline in network performance, a backup key update and path re-selection mechanism is triggered to ensure the continuous security of communication.

[0144] In this embodiment, the S7 specifically includes:

[0145] S71. During the entire life cycle of device communication, new random number seeds are regularly generated through the quantum random number generator, and the binding key K of the device is updated based on the seedsbind with the dynamic key K dynamic ;

[0146] S72. After the key is updated, actively destroy the expired and redundant keys. The destruction process is completed through the hardware encryption module, so that the keys are completely cleared after storage and use, and will not be recovered and misused again;

[0147] S73. During the key update and destruction process, the device records the integrity of each step of the key update. The records include the timestamp, generation algorithm, parameters involved in the calculation, and their encryption verification information of each generated key. All the recorded data forms a complete log;

[0148] S74. The log data is encrypted by the symmetric encryption algorithm. The key K log is generated by the security module in the device and updated regularly. The encrypted log will be stored in the non-tamperable area of the device, which is protected by the hardware encryption module, so as to ensure the security and integrity of the log and prevent any form of unauthorized access and modification;

[0149] S75. The content of the log record includes processes such as key generation, key update, data transmission, and exception recovery. And the device regularly verifies the content of the log. If an anomaly is found during the verification, the log verification mechanism is triggered;

[0150] S76. After the log data is stored, the device synchronizes the encrypted log to the external secure storage unit through the redundant backup mechanism, so that in case of device failure and attack, the log will not be lost or damaged, and can be restored through a secure recovery mechanism.

[0151] Embodiment 1:

[0152] To verify the feasibility of the present invention in practice, the present invention is applied to a certain home smart home Internet of Things system as an example, and details how to improve the security of data transmission by combining quantum random number generation technology. In this smart home system, smart devices in the home, such as smart lights, smart temperature controls, smart door locks, and security cameras, exchange data through the central control system. Due to the network access and remote control characteristics of Internet of Things devices, the system faces severe security threats. Especially in the data transmission process, there may be problems such as replay attacks, key leakage, and information tampering. Therefore, in order to effectively solve these security hazards, the present invention proposes an Internet of Things data transmission security enhancement method combined with quantum random number generation to ensure that the data transmission of each communication session is under high security protection.

[0153] In this scenario, the security enhancement method of the present invention first generates an initial binding key for the device through a quantum random number generator to ensure the randomness and unpredictability of the key. The generation process combines the device's unique identifier and the quantum random number seed. This key is stored in the device's hardware security module and protected by double encryption to prevent physical attacks or extraction by unauthorized visitors. When data is transmitted between the device and the gateway, the system executes a secure handshake protocol to generate a negotiated random number and generates a shared session key based on this random number and the binding key. The session key is used to encrypt data during the communication process to ensure the confidentiality and integrity of the data. In each data transmission, the system authenticates the transmitted data using the HMAC algorithm to ensure that the data has not been tampered with during transmission. In addition, to prevent replay attacks, the system updates the key in each communication session and uses quantum random numbers to generate a new key seed, thus ensuring the uniqueness and unpredictability of each transmission.

[0154] When the communication session ends or times out, the system automatically triggers a key destruction mechanism to clear the stored key through the hardware encryption module, ensuring that the key cannot be recovered or misused. The key destruction operation is completed within 1 second, and a double verification mechanism is used to ensure the success of the destruction operation.

[0155] To verify the effectiveness of the method of the present invention, the experiment was conducted in a household in a certain city. The smart devices in the household are connected to the central gateway via Wi-Fi. In this experiment, we verified the effect of the method of the present invention in enhancing data transmission security through a comparison between simulated attacks and normal data transmission. In a traditional system without using the method of the present invention, after 5 days of testing, a total of 3 replay attacks occurred, and the attack success rate reached 60%. However, after adopting the method of the present invention, the system successfully prevented all replay attacks and key leakage incidents. The experimental data shows that the system security has been improved by approximately 95%.

[0156] The experiment also shows that although the method of the present invention introduces key update and authentication steps during the data transmission process, the transmission delay only increases by approximately 20 milliseconds. Although there is a certain performance overhead, this delay is acceptable under the premise of ensuring security.

[0157] In terms of key update and destruction, the method of the present invention uses the hardware security module and an automated mechanism to ensure that the key can be securely destroyed after each session ends, and the success rate of the destruction operation reaches 100%. These experimental data fully prove the remarkable effect of the method of the present invention in enhancing the security of IoT data transmission and reducing security risks, and it can provide effective security protection without significantly affecting performance.

[0158] Table 1 Comparison of Security Protection Effects

[0159]

[0160] Table 2 Performance Comparison (Latency and Key Destruction Process)

[0161]

[0162] According to the table data, the method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is significantly superior to the traditional scheme in terms of processing time and data transmission latency. By improving the key generation speed and verification efficiency, this method significantly reduces the system processing time and effectively reduces the data transmission latency. In multiple key update and high-concurrency scenarios, this scheme shows strong stability and reliability, and at the same time has strong security, which can effectively prevent security risks such as replay attacks and side-channel attacks. The quantum random number generation technology improves the speed and security of Internet of Things data transmission and has good application prospects.

[0163] In summary, the present invention proposes a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation. By using the highly secure random numbers provided by the quantum random number generator and combining dynamic key generation, update and destruction mechanisms, the present invention can effectively solve the problems existing in the traditional methods, such as key leakage, untimely key update, and key synchronization failure, and significantly improve the security of Internet of Things data transmission. By introducing an automatic key destruction mechanism, it is ensured that the key can be completely cleared after use, preventing the risk of key reuse or leakage. By adopting a key management method based on quantum random number generation, the present invention provides a more secure and efficient Internet of Things data transmission scheme, which can effectively address various security challenges faced in the current Internet of Things field during the data transmission process.

[0164] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A method for enhancing the security of Internet of Things data transmission combined with quantum random number generation, characterized in that: The steps include: S1. Generate a random number seed unique to the device using a quantum random number generator, and generate a binding key based on the random number seed and the device unique identifier; S2. The sender and the receiver execute a secure handshake protocol through the binding key of the device, use quantum random numbers to generate negotiation random numbers, and combine the preset negotiation algorithm to generate a shared session key. The session key is only valid in the current communication session and is destroyed after key synchronization is completed to avoid long-term storage risks. S3, divide the data to be transmitted into logical segments, and generate independent dynamic encryption keys for each logical segment in real time through a quantum random number generator. The dynamic key of each segment of data is derived from the session key and bound to the timestamp, so that the data segmentation and key distribution have a one-to-one correspondence; S4. Encrypt the segmented data using the corresponding dynamic keys respectively, and transmit the encrypted data in segments through a multi-path randomization protocol in combination with the path selection scheme generated by the quantum random number generator. The path randomization scheme is dynamically adjusted during the transmission process to optimize the path anti-monitoring capability and interception risk; S5. Based on the dynamic key synchronization mechanism, the receiving end obtains the corresponding key in real time to decrypt each encrypted data segment by segment, and performs integrity check on each decrypted data segment in combination with the embedded data verification code. If decryption failure and verification error are detected, a retransmission request is triggered and the sending end is notified to generate a backup key for re-encryption transmission; S6. During the communication process, the status of the quantum random number generator, key synchronization and data transmission integrity are monitored in real time. If anomalies in random number generation, key synchronization failure and path interruption are detected, the backup key generation mechanism is triggered and the data transmission path is adjusted to restore communication and maintain security. S7. During the entire life cycle of device communication, the device random number seed, binding key and dynamic key are regularly updated through the quantum random number generator, and expired and redundant keys are actively destroyed. The complete log of key generation, data transmission and abnormal recovery is recorded, and the log is stored in a secure storage area of ​​the device that cannot be tampered with.

2. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S1 specifically includes: S11, generating a random number seed unique to the device through a quantum random number generator, the random number seed r s The length is L r The random binary string is generated by a quantum random number generator QNRG. The random number seed r s Unpredictable and highly secure; S12, based on the random number seed r s Generate a binding key K with the device's unique identifier UID bind , the generation process combines the timestamp T and the session counter C to make the binding key unique and dynamic at the time and session level: K bind =H(H(r s )||UID||T||C); Where H is a hash function, || represents a connection operation, T is a timestamp when the key is generated, and C is a communication session counter; S13, the generated binding key K bind The key is stored in the device's security module, which uses a dual encryption mechanism to protect the key's security. The first layer of encryption uses a hardware encryption module, and the second layer of encryption uses the device's private key for encrypted storage, so that the key cannot be extracted due to physical attacks and unauthorized access; S14. During device communication, the random number seed r of the device is updated based on the quantum random number generator through a periodic trigger mechanism. s and binding key K bind To avoid the security risks caused by long-term use of the same key, after each update, the binding key K bind Generate a new key based on the new random number seed and timestamp, and update and store it in the security module; S15. Each time a binding key is generated, the key will be verified through an authentication mechanism inside and outside the device to verify the validity of the key. The external authentication mechanism includes verifying the validity of the key through an authentication server, and the internal authentication mechanism performs an integrity check on the generated key to ensure the accuracy of the key and that it has not been tampered with.

3. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S2 specifically includes: S21, at the sending end and the receiving end, the binding key K of the device is used bind After executing the security handshake protocol, a negotiation random number r is generated c , the negotiated random number r c Generated by a quantum random number generator, making it highly secure and unpredictable, with a length of L c A random binary string; S22, based on the negotiated random number r c 、Device binding key K bind , the device unique identifier UID and the timestamp T of the current session, the sender and the receiver jointly generate a shared session key K through a preset negotiation algorithm session , the session key is only valid in the current communication session and is unique and dynamic; S23, session key K session After being generated, it is verified by a two-way authentication mechanism. The authentication process includes the sender and the receiver respectively checking K session Perform integrity check and confirm key consistency and validity to ensure that the key is not tampered with during the entire session; S24. During the session, if an abnormality occurs during the communication, the sender and the receiver immediately trigger the backup key generation mechanism and destroy the current session key K. session , so that unauthorized access cannot obtain the original key; S25. Whenever a session ends or times out, the session key K is triggered. session The destruction mechanism automatically destroys K through the security module in the device session , so that the key is completely cleared after storage and use, and cannot be recovered; S26, the session key destruction process is controlled by the device security module, using a double verification mechanism to verify the session key K in memory. session Perform a clear operation so that the key is no longer stored in any memory location. Verify the destruction operation is complete through the hardware encryption module, so that the session key is safely deleted and any form of recovery operation is prevented.

4. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S3 specifically includes: S31, dividing the data to be transmitted into a plurality of logical segments according to a predetermined standard, each logical segment corresponding to an independent data unit, wherein the standard includes data size, transmission priority and real-time requirements; S32, generating an independent dynamic encryption key for each logical segment in real time, wherein the key is generated by a quantum random number generator, and the random number seed r provided by the quantum random number generator is s By length L r The binary string represents the random number seed r s is highly random and unpredictable; S33, based on session key K session Derive the dynamic encryption key K for each logical segment dynamic , the dynamic key K dynamic Combine the timestamp T and the current logical segment identifier ID to make the key of each data segment unique and time-effective; S34, the generated dynamic key K dynamic Used to encrypt the corresponding logical segment data. The encryption process adopts a symmetric encryption algorithm and determines the encryption initialization vector IV through a quantum random number generator, so that the data encryption process of each logical segment has high security; S35, during the encrypted data transmission process, the data of each logical segment and its dynamic key K dynamic The key is transmitted through a secure channel, and the dynamic key is automatically destroyed after the data transmission is completed, so that the key will not be stored for a long time and prevent leakage; S36: The receiving end decrypts the data based on a predetermined decryption algorithm and the corresponding dynamic key K. dynamic The data is decrypted segment by segment. The decryption process includes integrity check and verification. If anomalies and data tampering are found, the data retransmission mechanism is triggered and the sender is required to regenerate a backup key to encrypt the data and then retransmit it.

5. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S4 specifically includes: S41, after receiving the encrypted data, the receiving end uses the dynamic key K dynamic , decrypting the data segment by segment using a predetermined decryption algorithm, wherein the decryption process includes an integrity check on each data segment, wherein the check code is generated by the sender during encryption and transmitted in conjunction with the encryption; S42: If the verification fails and the data is tampered with, the data retransmission mechanism is triggered, and the sender retransmits the data according to the current session key K. session and the quantum random number generator to regenerate the backup key K dynamic , and re-encrypt the data; S43, the encrypted data is retransmitted to the receiving end through a secure channel, and the dynamic key K of the retransmitted data is used. dynamic Destroy the data immediately after it is successfully received, so that the key is not stored for a long time and prevents leakage; S44. During the data transmission process, the receiving end dynamically adjusts the data transmission path according to the real-time network status. The path adjustment is performed according to the network status function: P select =F(B path ,L path ,F path ); Among them, P select Select a priority for the path, B path is the path bandwidth, L path is the path delay, F path is the path load, F is the weighting function; S45. If the network status changes, causing the performance index of the path to exceed a predetermined threshold, a path reselection mechanism is triggered to ensure that data transmission is always performed through the optimal path.

6. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S5 specifically includes: S51, after receiving the encrypted data at the receiving end, based on the dynamic key K dynamic , decrypt the data segment by segment using a predetermined decryption algorithm, and perform integrity check on each segment of data, wherein the check code is generated by the sender during encryption and transmitted in conjunction with the encryption; S52, data integrity check is performed by the following check function, the check code C data Data segment D i and key K dynamic The encrypted hash value of S53: If the data verification fails and the data is tampered with, the data retransmission mechanism is triggered, and the sender retransmits the data according to the current session key K. session and the quantum random number generator to regenerate the backup dynamic key K dynamic , and re-encrypt the data through the encryption algorithm before transmission; S54, the encrypted data is retransmitted to the receiving end through a secure channel, and the retransmitted data and its corresponding dynamic key K dynamic It will be destroyed immediately after successful receipt to avoid long-term storage and leakage of keys; S55. During the data transmission process, the receiving end dynamically adjusts the data transmission path according to the real-time network status, and the path selection is optimized by the path selection priority function: Among them, P select is the priority of path selection, ω i is the weight factor of path i, B path (i) is the bandwidth of path i, L path (i) is the delay of path i, F path (i) is the load of path i, α i and β i is the regulating factor; S56. If the network status changes, causing the path performance index to exceed a predetermined threshold, a path reselection mechanism is triggered so that data transmission is always performed through the optimal path. The trigger mechanism is triggered by the following path selection adjustment equation: ΔP adjust =G(|P current -P optimal |,T); Among them, ΔP adjust is the path priority adjustment amount, P current is the current path priority, P optimal is the optimal path priority, T is the dynamic threshold of network load and delay, and G is the path adjustment function.

7. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S6 specifically includes: S61. During the communication process, the receiving end monitors the status of the quantum random number generator, key synchronization, and the integrity of data transmission in real time. If anomalies in random number generation, key synchronization failure, and path interruption are detected, the backup key generation mechanism is triggered; S62, backup key K backup Generated by the following formula: K backup =G(K session ,T′,ε(r temp ),C env ); Among them, G is the key generation function, K session is the current session key, T′ is the newly generated timestamp, ε(r temp ) is the temporary random number r temp Perform entropy expansion operation, C env is the weighted state value of the environmental condition; S63, spare key K backup After generation, the receiving end and the sending end synchronize the key through a secure channel to ensure the validity and consistency of the backup key. If the synchronization is successful, data transmission continues; S64. If synchronization fails, regenerate the backup key according to the new network status and trigger the path adjustment mechanism to ensure that data transmission is not interrupted; S65, data transmission path is optimized through the following dynamic selection function: Among them, P adjusted is the adjusted path priority, is the flow status of the current path, is the path load change, T threshold The threshold parameter selected for the dynamic path, Selecting a regulation function for the path; S66. When the path priority and synchronization mechanism are abnormal, resulting in a decrease in network performance, the backup key update and path reselection mechanism is triggered to ensure the continued security of communications.

8. According to claim 1, a method for enhancing the security of Internet of Things data transmission combined with quantum random number generation is characterized in that: The S7 specifically includes: S71. During the entire life cycle of device communication, a new random number seed is regularly generated through the quantum random number generator, and the device binding key K is updated based on the seed. bind With dynamic key K dynamic ; S72. After the key is updated, the expired and redundant keys are actively destroyed. The destruction process is completed through the hardware encryption module, so that the keys are completely cleared after storage and use, and will not be restored or abused; S73. During the key update and destruction process, the device records the integrity of each step of the key update, including the timestamp of each key generated, the generation algorithm, the parameters involved in the calculation and its encryption verification information, and all the recorded data constitute a complete log; S74. Log data is encrypted using a symmetric encryption algorithm, using the key K log Generated by the security module in the device and updated regularly, the encrypted logs will be stored in a tamper-proof area of ​​the device, which is protected by a hardware encryption module to ensure the security and integrity of the logs and prevent any form of unauthorized access and modification; S75. The content recorded in the log includes key generation, key update, data transmission, abnormal recovery and other processes, and the device regularly verifies the log content. If the verification finds an abnormality, the log verification mechanism is triggered; S76. After the log data is stored, the device synchronizes the encrypted log to an external secure storage unit through a redundant backup mechanism, so that when the device fails or is attacked, the log will not be lost or damaged, and can be restored through a secure recovery mechanism.

Citation Information

Cited By

  • Data communication method and device between different label pages of same source and same browser

    CN120880659A

  • Method and device for data communication between homologous tabs in different browser pages

    CN120880659B

  • Cross-domain data security sharing method and system

    CN121396658A

  • Serial communication network dynamic key updating method and device for ship environment

    CN121567319A