Data transmission method and device of 5G edge computing security control gateway module
By monitoring data interaction activities and status information in real time in 5G edge computing, combining ECC encryption algorithm and digital certificate two-way authentication, the stability and security problems of data transmission in the low-power state of gateway modules are solved, and efficient and secure data transmission is achieved.
Patent Information
- Application Number
- CN202510632098.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-05-16
AI Technical Summary
The prior art is difficult to take into account the low power consumption and data security of gateway modules in 5G edge computing, which makes it impossible to meet the needs of real-time processing and low-latency transmission in some application scenarios.
By monitoring the data interaction activity and status information between IoT devices and gateway modules in real time, determining the operating mode of the gateway module, and combining the ECC encryption algorithm and the digital certificate two-way authentication mechanism, data is encrypted and authenticated to ensure stable and secure data transmission in a low-power state.
In 5G edge computing, the stability and security of data transmission in the low power consumption state of the gateway module is realized, which extends the battery life of the equipment, reduces operation and maintenance costs, and meets the high requirements for data security.
Smart Images

Figure CN120186723A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of gateway data transmission, and more specifically, to a data transmission method and device for a 5G edge computing security control gateway module. Background Art
[0002] With the rapid development of 5G technology and the large-scale deployment of Internet of Things (IoT) devices, in many fields such as industrial control, intelligent transportation, and smart home, higher requirements are put forward for real-time data processing and low-latency transmission. 5G edge computing can sink data processing from the cloud to the network edge, reduce data transmission latency, and improve system response speed. For example, in an industrial automation production line, a large amount of data generated by sensors and actuators needs to be processed in a timely manner to ensure the stability and efficiency of the production process.
[0003] As a key node connecting IoT devices and the network, the 5G edge computing security control gateway module faces the dual challenges of power consumption and data transmission efficiency. On the one hand, traditional gateway modules have high power consumption during long-term operation. For some application scenarios that rely on battery power or have strict power consumption restrictions, such as IoT monitoring devices in remote areas, the battery life becomes a bottleneck restricting their wide application. On the other hand, in the process of data transmission, how to achieve efficient and stable data transmission while ensuring data security is also an urgent problem to be solved. Currently, some low-power solutions often sacrifice data transmission performance or have vulnerabilities in data security, and cannot meet the complex and changeable application requirements of 5G edge computing.
[0004] Therefore, there is an urgent need for a better solution. Summary of the Invention
[0005] The present invention provides a data transmission method and device for a 5G edge computing security control gateway module to solve the technical problem in the prior art that it is impossible to balance low power consumption and data security of the gateway module. The method includes: Real-time monitoring of the data interaction activities between the IoT device and the gateway module and the status information of the gateway module, and determining the operating mode of the gateway module based on the data interaction activities and the status information of the gateway module. The operating mode includes a normal operating mode, a light sleep mode, or a deep sleep mode; Obtaining the IoT data sent by the IoT device to the gateway module and preprocessing the IoT data; Encrypting the preprocessed IoT data based on an ECC-based encryption algorithm library to obtain encrypted data; Reading the digital certificates of the gateway module and the IoT device, and obtaining the private key and public key of the gateway module and the IoT device based on the digital certificates; Verify the mutual signature of the gateway module and the IoT device based on a challenge random number and using the private key and public key; After the mutual signature verification passes, encapsulate the encrypted data and send the encapsulated encrypted data to the target device via the 5G network.
[0006] In some specific embodiments, preprocess the IoT data, specifically: Check the data format of the IoT data, remove redundant information from the IoT data, and fill in the data bits in the IoT data.
[0007] In some specific embodiments, read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates. A device certificate storage area is set in the gateway module, specifically: Obtain the first digital certificate of the gateway module and the second digital certificate of the IoT device from the device certificate storage area; Obtain the public key, the first private key of the gateway module, and the second private key of the IoT device based on the first digital certificate and the second digital certificate.
[0008] In some specific embodiments, verify the mutual signature of the gateway module and the IoT device based on a challenge random number and using the private key and public key, specifically: The gateway module sends a randomly generated first challenge random number to the IoT device; The IoT device signs the first challenge random number using the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module; After the gateway module receives the first signature and the first challenge random number, verify the first signature based on the public key; When the verification of the first signature passes, the IoT device sends a second challenge random number to the gateway module; The gateway module signs the second challenge random number using the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the IoT device; The IoT device verifies the second signature value using the public key; When the verification of the second signature value is successful, it is determined that the mutual signature verification passes; If the verification of the first signature value or the second signature value fails, terminate the data communication between the gateway module and the IoT device.
[0009] In some of the specific embodiments, the encrypted data is encapsulated and the encapsulated encrypted data is sent to the target device via the 5G network, specifically: The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device via the 5G network. The header information includes a source address, a destination address, a data length, and a sequence number.
[0010] In some of the specific embodiments, the data interaction activities between the IoT device and the gateway module and the status information of the gateway module are monitored in real time, and the operating mode of the gateway module is determined based on the data interaction activities and the status information of the gateway module. The operating mode includes a normal operating mode, a light sleep mode, or a deep sleep mode, specifically: The data transmission system monitors in real time the data interaction activities between the IoT device and the gateway module and the status information of the gateway module. The status information includes load information and processor metric information; When it is detected that the device activity, or the load information, or the processor metric information exceeds a first preset threshold, the gateway module is maintained in a normal operating state; When the device activity, or the load information, or the processor metric information is not detected to exceed a second preset threshold within a first time period, the gateway module is controlled to enter the light sleep mode.
[0011] In some of the specific embodiments, the method further includes: In the light sleep mode, a first duration of a timer is set; When the timer does not exceed the first duration, the gateway module is maintained in the light sleep mode; When the timer exceeds the first duration, it is determined whether there is a wake-up signal through a wake-up signal detection circuit; If there is no wake-up information, the gateway module is controlled to enter the deep sleep mode; If there is wake-up information, the priority of the wake-up information is judged; When the wake-up information is high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism to restore it to the normal operating frequency, and the relevant communication and processing modules are started, so that the gateway module enters the normal operating state; When the wake-up information is low-priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activities between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity, or the load information, or the processor metric information is not detected to exceed the second preset threshold within the first time period, the light sleep mode is re-entered.
[0012] Correspondingly, the present invention further provides a data transmission device for a 5G edge computing security control gateway module, and the device includes: An operation monitoring module, which monitors in real time the data interaction activities between the Internet of Things device and the gateway module and the status information of the gateway module, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module. The operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode; A preprocessing module, which is used to obtain the Internet of Things data sent by the Internet of Things device to the gateway module and preprocess the Internet of Things data; An encryption module, which is used to encrypt the preprocessed Internet of Things data based on an ECC encryption algorithm library to obtain encrypted data; A reading module, which is used to read the digital certificates of the gateway module and the Internet of Things device, and obtain the private key and public key of the gateway module and the Internet of Things device based on the digital certificates; A signature verification module, which is used to perform two-way signature verification on the gateway module and the Internet of Things device based on a challenge random number and through the private key and public key; A sending module, which is used to encapsulate the encrypted data and send the encapsulated encrypted data to a target device through a 5G network after the two-way signature verification passes.
[0013] One embodiment of the present invention further provides a computing device, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of the above are implemented.
[0014] One embodiment of the present invention further provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by a processor, the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of the above are implemented.
[0015] By applying the above technical solution, a data transmission method for a 5G edge computing security control gateway module is proposed. The method includes: real-time monitoring of the data interaction activities between the Internet of Things devices and the gateway module and the status information of the gateway module, and determining the operating mode of the gateway module based on the data interaction activities and the status information of the gateway module. The operating mode includes a normal operating mode, a light sleep mode, or a deep sleep mode. Obtain the Internet of Things data sent by the Internet of Things device to the gateway module, and preprocess the Internet of Things data; encrypt the preprocessed Internet of Things data based on the ECC encryption algorithm library to obtain encrypted data; read the digital certificates of the gateway module and the Internet of Things device, and obtain the private keys and public keys of the gateway module and the Internet of Things device based on the digital certificates; perform mutual signature verification of the gateway module and the Internet of Things device based on a challenge random number through the private key and the public key; when the mutual signature verification passes, encapsulate the encrypted data and send the encapsulated encrypted data to the target device through the 5G network, realizing stable and secure data transmission while ensuring that the gateway module is in a low-power state. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0017] Figure 1 It is a flowchart of a data transmission method for a 5G edge computing security control gateway module provided by an embodiment of the present application; Figure 2 It is a flowchart of a low-power consumption mechanism for a 5G edge computing security control gateway module provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of a data transmission device for a 5G edge computing security control gateway module provided by an embodiment of the present application; Figure 4 It is a structural block diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] Many specific details are set forth in the following description in order to provide a thorough understanding of this specification. However, this specification can be implemented in many other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of this specification. Therefore, this specification is not limited by the specific implementations disclosed below.
[0019] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and encompasses any and all possible combinations of one or more of the associated listed items.
[0020] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".
[0021] As Figure 1 shown, this application proposes a data transmission method for a 5G edge computing security control gateway module, and the method includes the following steps: Step S101, real-time monitor the data interaction activities between the Internet of Things device and the gateway module and the status information of the gateway module, and determine the operating mode of the gateway module based on the data interaction activities and the status information of the gateway module, where the operating mode includes a normal operating mode, a light sleep mode, or a deep sleep mode.
[0022] In a possible implementation, real-time monitor the data interaction activities between the Internet of Things device and the gateway module and the status information of the gateway module, and determine the operating mode of the gateway module based on the data interaction activities and the status information of the gateway module, where the operating mode includes a normal operating mode, a light sleep mode, or a deep sleep mode, specifically: The data transmission system real-time monitors the data interaction activities between the Internet of Things device and the gateway module and the status information of the gateway module, where the status information includes load information and processor metric information; When it is detected that the device activity or the load information or the processor metric information exceeds a first preset threshold, keep the gateway module in a normal operating state; When the device activity or the load information or the processor metric information is not detected within a first time period and is less than a second preset threshold, control the gateway module to enter the light sleep mode.
[0023] In a possible implementation, the method further includes: In the light sleep mode, set the first duration of the timer; When the timer does not exceed the first duration, keep the gateway module in the light sleep mode; When the timer exceeds the first duration, determine whether there is a wake-up signal through the wake-up signal detection circuit; If there is no wake-up information, control the gateway module to enter the deep sleep mode; If there is wake-up information, determine the priority of the wake-up information; When the wake-up information is high-priority wake-up information, wake up the processor of the gateway module through a preset interrupt mechanism, restore it to the normal operating frequency, and start relevant communication and processing modules to make the gateway module enter the normal operating state; When the wake-up information is low-priority wake-up information, wake up the processor of the gateway module and perform data processing. After the data processing is completed, check the data interaction activity between the Internet of Things device and the gateway module and the status information of the gateway module again. When no device activity or the second preset threshold of the carrier information or processor metric information is detected within the first time period, re-enter the light sleep mode.
[0024] In this embodiment, the gateway module is set with multiple sleep modes, including light sleep and deep sleep modes. During the idle period of the system, according to the preset time threshold and activity monitoring mechanism, it automatically switches to the light sleep mode. At this time, some non-critical circuit modules enter the low-power state. For example, the radio frequency part of the wireless communication module reduces the transmission power, and the processor enters the low-frequency operating state, but still maintains the ability to monitor specific wake-up signals. If no wake-up signal is detected within a period of time (such as 10 minutes) and the system load is extremely low, it further switches to the deep sleep mode. Except for the wake-up circuit and a small number of key registers, most circuit modules are powered off to minimize power consumption.
[0025] In this embodiment, multiple wake-up signal detection circuits are designed, which can detect trigger signals from Internet of Things devices, control instructions from the network side, and specific event signals collected by sensors. For example, in a smart home scenario, when a door and window sensor detects an abnormal opening action, it will send a wake-up signal to the gateway module. The wake-up signal is input to the gateway module through a dedicated wake-up pin. After the wake-up circuit receives the signal, it first preprocesses the signal to judge the legality and priority of the signal. For high-priority wake-up signals, such as emergency alarm signals, immediately wake up the gateway module to enter the normal working mode; for low-priority signals, such as periodic device status reporting signals, if the gateway module is in the light sleep mode, wake up the module for corresponding processing, and if the system still meets the sleep conditions after the processing is completed, re-enter the sleep mode.
[0026] In this embodiment, as Figure 2 shown, the low-power mechanism in the present invention will be described in detail.
[0027] Low-power wake-up process: ① System initialization: After the 5G edge computing security control gateway module is powered on, system initialization is first performed, including hardware circuit initialization, software module loading, and parameter configuration, etc. Set the time threshold for sleep mode switching, the parameters of the wake-up signal detection circuit, and the initial working states of each module, etc.
[0028] ② Normal operation and monitoring: During the normal operation stage, the gateway module monitors the activity status of IoT devices, network connection status, and sensor data in real time. At the same time, according to the preset monitoring mechanism, the system load situation is regularly checked. For example, the occupancy rate of the processor and memory usage are statistically calculated every 1 minute.
[0029] ③ Sleep mode switching: When the system detects that there is no data interaction with IoT devices, the network connection is stable, and the system load is low within a certain period (such as 1 minute), it is determined that the light sleep condition is met, and the gateway module is switched to the light sleep mode. In the light sleep mode, a timer is started, and the timer duration is set to 10 minutes. If no wake-up signal is detected within 10 minutes and the system load remains extremely low, it is further switched to the deep sleep mode.
[0030] ④ Wake-up processing: When the wake-up circuit receives a wake-up signal, the signal is first sampled and digitized, and then the type and priority of the signal are judged through a pre-set signal recognition algorithm. For high-priority wake-up signals, such as the signals sent by the fire alarm sensor, the processor of the gateway module is immediately awakened through the interrupt mechanism, restored to the normal working frequency, and the relevant communication and processing modules are started. For low-priority signals, such as the periodic reporting signals of the environmental temperature sensor, if the gateway module is in the light sleep mode, the processor is awakened for data processing. After the processing is completed, the system load and activity status are checked again. If the sleep condition is met, it re-enters the light sleep mode.
[0031] 1. System power-on: The 5G edge computing security control gateway module is powered on to start the work process. At this time, the hardware circuit and software system of the module start, preparing for subsequent normal operation and function implementation.
[0032] 2. System initialization: Hardware circuit initialization: Initialize various hardware components in the gateway module, such as the processor, communication module, storage device, etc. Configure the working parameters of the hardware to ensure that each hardware module can work properly. For example, set the initial operating frequency of the processor and the working frequency band of the communication module.
[0033] Software module loading: Load the operating system kernel, drivers, and various functional software modules. These software modules are responsible for implementing various functions of the gateway, such as data processing, communication management, device control, etc.
[0034] Parameter configuration: Set the key parameters related to low-power wake-up, including the time threshold for sleep mode switching, the sensitivity and trigger conditions of the wake-up signal detection circuit, the power consumption parameters of each module in different sleep modes, etc.
[0035] 3. Determine whether there is device activity or high load: The system continuously monitors the data interaction activities between the IoT devices and the gateway module, such as whether there are new data requests, device status updates, etc. At the same time, it real-time monitors the load situation of the gateway module itself, including indicators such as the occupancy rate of the processor and the memory usage.
[0036] If device activity is detected (such as receiving data sent by the device) or the system load is high (the processor occupancy rate exceeds a certain threshold, such as 70%), it is determined as "yes" and enters the normal operation state.
[0037] If there is no device activity and the system load is at a low level (the processor occupancy rate is below 30%, the memory usage rate is below 50%, etc.) within a certain period of time (such as the set detection period is 1 minute), it is determined as "no" and enters the light sleep mode.
[0038] 4. Normal operation: In the normal operation state, the gateway module fully processes the data requests of IoT devices, network communication tasks, and various edge computing functions. For example, it receives and parses the data uploaded by the device, performs data preprocessing, encryption, etc. operations, and then forwards the data to the specified server or other devices; at the same time, it receives control instructions from the network side and controls the IoT devices accordingly.
[0039] 5. Monitor device activity, network, and load situation: During normal operation, the gateway module continuously monitors the device activity, network connection status, and its own load situation in real time.
[0040] Device activity monitoring: Real-time listen for whether there are new data sent by IoT devices, device status change notifications, etc.
[0041] Network monitoring: Check whether the 5G network connection is stable, including indicators such as signal strength, network latency, packet loss rate, etc. If the network is abnormal, take corresponding measures in time, such as reconnecting the network, adjusting communication parameters, etc.
[0042] Load monitoring: Regularly (such as every 10 seconds) obtain information such as the occupancy rate of the processor and the memory usage, and evaluate the current load level of the system.
[0043] The monitoring results will be used as the basis for determining whether to enter the sleep mode, and it will continuously loop back to the step of "judging whether there is device activity or high load".
[0044] 6. Enter the light sleep mode and start the timer: When the system determines that the conditions for entering the light sleep mode are met, the gateway module starts to perform a series of operations to reduce power consumption.
[0045] Some non-critical circuit modules enter the low-power state: For example, the radio frequency part of the wireless communication module reduces the transmission power, and the processor reduces the operating frequency, but still maintains the ability to listen for specific wake-up signals.
[0046] Start the timer: Set the duration of the timer, such as 10 minutes. During the operation of the timer, if no other events occur, the system will further decide whether to enter the deep sleep mode according to the timeout of the timer.
[0047] 7. Judge whether the timer times out: In the light sleep mode, the system checks the status of the timer in real time.
[0048] If the timer has not timed out, the system continues to maintain the light sleep mode, waiting for the timer to end or the arrival of a wake-up signal.
[0049] When the timer reaches the set duration, that is, times out, it enters the next step of judging whether there is a wake-up signal.
[0050] 8. Judge whether there is a wake-up signal: The wake-up signal detection circuit continuously listens for trigger signals from IoT devices, control instructions from the network side, and specific event signals collected by sensors, etc.
[0051] If a wake-up signal is detected, the system determines it as "yes" and immediately performs the operation to wake up the gateway module to restore it to the normal operation mode.
[0052] If no wake-up signal is detected, it is determined as "no" and enters the deep sleep mode.
[0053] 9. Enter the deep sleep mode: In the deep sleep mode, except for the wake-up circuit and a small number of key registers, most circuit modules are powered off to minimize power consumption. At this time, the power consumption of the gateway module drops to an extremely low level, but it still retains the ability to be woken up by a specific wake-up signal.
[0054] 10. Wake up the gateway and restore normal operation: When a wake-up signal is detected, the wake-up circuit first preprocesses the signal to judge the legality and priority of the signal. For legal wake-up signals, corresponding processing is performed according to their priorities.
[0055] For high-priority wake-up signals, such as emergency alarm signals, the processor of the gateway module is immediately awakened through the interrupt mechanism, so that it quickly resumes to the normal operating frequency, and the relevant communication and processing modules are started, enabling the gateway module to quickly enter the normal operating state to respond to emergency events as soon as possible.
[0056] For low-priority wake-up signals, such as periodic device status reporting signals, the processor is also awakened for data processing. After the processing is completed, the system load and activity status are checked again. If the sleep conditions are met, the gateway module re-enters the light sleep mode.
[0057] Step S102: Obtain the Internet of Things data sent by the Internet of Things device to the gateway module, and preprocess the Internet of Things data.
[0058] In a possible implementation, preprocessing the Internet of Things data specifically includes: Check the data format of the Internet of Things data, remove redundant information from the Internet of Things data, and fill in the data bits in the Internet of Things data.
[0059] In this embodiment, in the application scenario of 5G edge computing, Internet of Things devices (such as sensors, smart terminals, etc.) send the collected data to the 5G edge computing security control gateway module. These data may include different types of information such as device status information, environmental monitoring data, and user operation instructions, which is the starting point of the entire data transmission process.
[0060] In this embodiment, after the 5G edge computing security control gateway module receives the data sent by the Internet of Things device, it first preprocesses the data. This step mainly includes checking the data format to ensure that the data conforms to the predetermined format specifications, such as the byte length and field order of the data; removing redundant information to streamline the data content and improve the subsequent processing efficiency; filling in the data bits. If there may be missing data bits during the data transmission process, corresponding filling operations are performed to ensure the integrity of the data.
[0061] Step S103: Encrypt the preprocessed Internet of Things data based on the ECC encryption algorithm library to obtain encrypted data.
[0062] In this embodiment, after the preprocessing is completed, the gateway module calls the encryption algorithm library based on the Elliptic Curve Cryptosystem (ECC). The ECC algorithm uses the mathematical properties of elliptic curves to generate a public key and a private key pair. The gateway uses the private key to encrypt the preprocessed data, converting the original data into ciphertext form. Due to its characteristics of short key length, small computational amount, and high security, the ECC algorithm is particularly suitable for application in 5G edge computing gateway modules with relatively limited resources, effectively ensuring the confidentiality of data during transmission and preventing data from being stolen or tampered with.
[0063] Step S104: Read the digital certificates of the gateway module and the Internet of Things device, and obtain the private keys and public keys of the gateway module and the Internet of Things device based on the digital certificates.
[0064] In a possible implementation, when reading the digital certificates of the gateway module and the Internet of Things device and obtaining the private keys and public keys of the gateway module and the Internet of Things device based on the digital certificates, a device certificate storage area is set in the gateway module, specifically: Obtain the first digital certificate of the gateway module and the second digital certificate of the Internet of Things device from the device certificate storage area; Obtain the public key, the first private key of the gateway module, and the second private key of the Internet of Things device based on the first digital certificate and the second digital certificate.
[0065] In this embodiment, in order to implement the identity authentication of both communication parties, the gateway module reads the digital certificate of the Internet of Things device from the device certificate storage area stored inside it, and also obtains its own digital certificate. The digital certificate is issued by a trusted certificate authority (CA) and contains the identity information of the device or gateway and the corresponding public key, etc., which is the key basis for the identity authentication process.
[0066] Step S105: Based on the challenge random number, verify the signatures of both the gateway module and the Internet of Things device through the private key and public key.
[0067] In a possible implementation, when verifying the signatures of both the gateway module and the Internet of Things device based on the challenge random number through the private key and public key, specifically: The gateway module sends a randomly generated first challenge random number to the Internet of Things device; The Internet of Things device signs the first challenge random number with the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module; After receiving the first signature and the first challenge random number, the gateway module verifies the first signature based on the public key; When the first signature verification passes, the Internet of Things device sends a second challenge random number to the gateway module; The gateway module signs the second challenge random number with the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the Internet of Things device; The Internet of Things device verifies the second signature value through the public key; When the verification of the second signature value is successful, it is determined that the signature verification of both parties passes; When the verification of the first signature value or the second signature value fails, terminate the data communication between the gateway module and the Internet of Things device.
[0068] In this embodiment, the gateway module sends a randomly generated challenge random number to the Internet of Things device. This random number is a unique value, which is random and time-sensitive during this authentication process. The purpose of sending the challenge random number is to allow the device to sign it using its own private key, so as to verify the authenticity of the device's identity.
[0069] After receiving the challenge random number sent by the gateway, the Internet of Things device signs the random number using its own private key. The signing process is based on a specific encryption algorithm, which operates on the random number and the device's private key to generate a signature value. After completing the signature, the device sends the signed random number back to the gateway module.
[0070] After receiving the signed random number sent back by the device, the gateway module verifies the signature using the public key in the device's digital certificate. The verification process is to operate on the received signature value, random number, and the device's public key through a specific verification algorithm to determine whether the signature is valid. If the verification passes, it indicates that the identity of the device is authentic and trustworthy, because only the device holding the corresponding private key can correctly sign the random number; if the verification fails, it is determined that there is a problem with the device's identity, which may be an illegal device or the certificate has been tampered with.
[0071] When the gateway successfully verifies the device's signature, it's the device's turn to authenticate the gateway. At this time, the device sends a new challenge random number to the gateway module. Similarly, this random number is also unique and time-sensitive, and is used for the gateway's identity verification.
[0072] After receiving the challenge random number sent by the device, the gateway module signs the random number using its own private key to generate a signature value. After completing the signature, it sends the signed random number back to the Internet of Things device.
[0073] After receiving the signed random number sent back by the gateway, the Internet of Things device verifies the signature using the public key in the gateway's digital certificate. By a specific verification algorithm, it judges the validity of the signature. If the verification passes, it indicates that the identity of the gateway is authentic and reliable, and the mutual identity authentication process is successfully completed; if the verification fails, it means there is a problem with the gateway's identity, and there may be an illegal gateway attempting to access the communication.
[0074] Step S106, after the mutual signature verification passes, encapsulate the encrypted data and send the encapsulated encrypted data to the target device through the 5G network.
[0075] In a possible implementation, the encrypted data is encapsulated and the encapsulated encrypted data is sent to the target device via a 5G network, specifically as follows: The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device via a 5G network. The header information includes a source address, a destination address, a data length, and a sequence number.
[0076] In this embodiment, after data encapsulation and header information addition are completed, the gateway module sends the data via a 5G network. The 5G network has the characteristics of high bandwidth and low latency, and can transmit data to the target server or other receivers quickly and stably. During the transmission process, since the data has been encrypted and authenticated, the security of the data and the legality of both communication parties are guaranteed.
[0077] In summary, the present invention has the following advantages: 1. Power consumption reduction: Through the reasonable switching of the sleep mode and the efficient wake-up mechanism, the power consumption of the 5G edge computing security control gateway module is greatly reduced, and the battery life of the device is extended. It is especially suitable for power-sensitive Internet of Things application scenarios, such as intelligent water meters, electricity meters and other devices, reducing the frequency of battery replacement or charging, and reducing the operation and maintenance costs.
[0078] 2. Data security guarantee: Based on the ECC encryption algorithm and the digital certificate two-way authentication mechanism, high-strength security guarantee is provided for data transmission, effectively preventing data from being stolen, tampered with and forged, and meeting the application requirements of 5G edge computing in fields with extremely high data security requirements, such as finance, rail transit, industrial control, etc.
[0079] 3. Data transmission efficiency improvement: The lightweight data transmission protocol can dynamically adjust the transmission strategy according to the network environment, make full use of the advantages of the 5G network, achieve efficient and stable data transmission, reduce data transmission latency, improve the overall performance of the system, and is of great significance in scenarios with high real-time requirements, such as intelligent transportation and remote medical treatment.
[0080] This application embodiment also proposes a data transmission device for a 5G edge computing security control gateway module, as Figure 3 shown. The device includes: An operation monitoring module 10 that monitors in real time the data interaction activities between the Internet of Things device and the gateway module and the status information of the gateway module, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module. The operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode; A preprocessing module 20 for obtaining the Internet of Things data sent by the Internet of Things device to the gateway module and preprocessing the Internet of Things data; An encryption module 30, configured to encrypt the preprocessed Internet of Things data based on an ECC-based encryption algorithm library to obtain encrypted data; A reading module 40, configured to read digital certificates of the gateway module and the Internet of Things device, and obtain private keys and public keys of the gateway module and the Internet of Things device based on the digital certificates; A signature verification module 50, configured to perform two-way signature verification on the gateway module and the Internet of Things device based on a challenge random number and through the private key and the public key; A sending module 60, configured to encapsulate the encrypted data and send the encapsulated encrypted data to a target device through a 5G network after the two-way signature verification passes.
[0081] Figure 4 FIG. shows a structural block diagram of a computing device 400 provided according to an embodiment of the present specification. Components of the computing device 400 include, but are not limited to, a memory 410 and a processor 420. The processor 420 is connected to the memory 410 through a bus 430, and a database 450 is used to store data.
[0082] The computing device 400 further includes an access device 440, and the access device 440 enables the computing device 400 to communicate via one or more networks 460. Examples of these networks include a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 440 may include one or more of any type of wired or wireless network interfaces (for example, a network interface card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC).
[0083] In an embodiment of the present specification, the above components of the computing device 400 and Figure 4Other components not shown may also be connected to each other, for example, via a bus. It should be understood that Figure 4 The block diagram of the computing device shown is for illustrative purposes only and is not a limitation on the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0084] The computing device 400 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.) or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). The computing device 400 can also be a mobile or stationary server.
[0085] Among them, the processor 420 is used to execute the following computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the data transmission method of the above 5G edge computing security control gateway module are implemented. The above is a schematic solution of a computing device in this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the data transmission method of the above 5G edge computing security control gateway module belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the data transmission method of the above 5G edge computing security control gateway module.
[0086] An embodiment of this specification also provides a computer-readable storage medium, which stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the steps of the data transmission method of the above 5G edge computing security control gateway module are implemented.
[0087] The above is a schematic solution of a computer-readable storage medium in this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the data transmission method of the above 5G edge computing security control gateway module belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the data transmission method of the above 5G edge computing security control gateway module.
[0088] An embodiment of this specification also provides a computer program, wherein when the computer program is executed on a computer, the computer is made to execute the steps of the data transmission method of the above 5G edge computing security control gateway module.
[0089] The above is a schematic solution of a computer program according to this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the data transmission method of the above 5G edge computing security control gateway module belong to the same concept. For the details not described in the technical solution of the computer program, reference can be made to the description of the technical solution of the data transmission method of the above 5G edge computing security control gateway module.
[0090] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0091] The computer instructions include computer program code, which may be in the form of source code, object code, executable files, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice within the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0092] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of this specification are not limited by the described action sequence, because according to the embodiments of this specification, certain steps may be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.
[0093] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0094] The preferred embodiments of the present specification disclosed above are only used to help explain the present specification. The alternative embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of the embodiments of the present specification. The present specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of the present specification, so that those skilled in the art can well understand and utilize the present specification. The present specification is only limited by the claims and their full scope and equivalents.
Claims
1. A data transmission method for a 5G edge computing security control gateway module, characterized in that: Applied to a data transmission system including a 5G edge computing security control gateway module and several IoT devices, the method includes: Monitor the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determine the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode; Obtaining IoT data sent by an IoT device to the gateway module, and preprocessing the IoT data; The pre-processed IoT data is encrypted based on the ECC encryption algorithm library to obtain encrypted data; Read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates; Based on the challenge random number and through the private key and public key, the signature verification of both the gateway module and the IoT device is performed; When the signatures of both parties are verified, the encrypted data is encapsulated and sent to the target device via the 5G network.
2. The method according to claim 1, characterized in that The IoT data is preprocessed, specifically: A data format check is performed on the IoT data, redundant information in the IoT data is removed, and data bits in the IoT data are completed.
3. The method according to claim 2, characterized in that Read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates. The gateway module is provided with a device certificate storage area, specifically: Acquire the first digital certificate of the gateway module and the second digital certificate of the IoT device from the device certificate storage area; A public key, a first private key of the gateway module, and a second private key of the Internet of Things device are obtained based on the first digital certificate and the second digital certificate.
4. The method according to claim 3, characterized in that Based on the challenge random number and through the private key and the public key, the signature verification of the gateway module and the IoT device is specifically as follows: The gateway module sends a randomly generated first challenge random number to the IoT device; The IoT device signs the first challenge random number by using the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module; After receiving the first signature and the first challenge random number, the gateway module verifies the first signature based on the public key; When the first signature verification passes, the IoT device sends a second challenge random number to the gateway module; The gateway module signs the second challenge random number by using the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the IoT device; The IoT device verifies the second signature value by using the public key; When the second signature value is successfully verified, it is deemed that the signature verification of both parties is successful; If the verification of the first signature value or the second signature value fails, the data communication between the gateway module and the IoT device is terminated.
5. The method according to claim 3, characterized in that: Encapsulating the encrypted data and sending the encapsulated encrypted data to the target device through the 5G network, specifically: The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device through the 5G network, where the header information includes a source address, a destination address, a data length, and a sequence number.
6. The method according to claim 1, characterized in that Monitor the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determine the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode, specifically: The data transmission system monitors the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, wherein the status information includes load information and processor indicator information; When device activity is detected or the load information or processor indicator information exceeds a first preset threshold, keeping the gateway module in a normal operating state; When the device activity or the load information or the processor indicator information is not detected within the first time period and the second preset threshold is not detected, the gateway module is controlled to enter the light sleep mode.
7. The method according to claim 6, characterized in that The method further comprises: In the light sleep mode, setting a first duration of the timer; When the timer does not exceed the first duration, keeping the gateway module in a light sleep mode; When the timer exceeds the first duration, determining whether there is a wake-up signal through a wake-up signal detection circuit; If there is no wake-up information, controlling the gateway module to enter a deep sleep mode; If there is a wake-up message, determining the priority of the wake-up message; When the wake-up information is high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism to restore it to a normal operating frequency, and related communication and processing modules are started to put the gateway module into a normal operating state; When the wake-up information is low priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity or the load information or processor indicator information is not detected within the first time period when the second preset threshold is reached, the shallow sleep mode is re-entered.
8. A data transmission device for a 5G edge computing security control gateway module, characterized in that: Applied to a data transmission system including a 5G edge computing security control gateway module and several IoT devices, the device includes: An operation monitoring module monitors the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode; A preprocessing module, used to obtain the IoT data sent by the IoT device to the gateway module and preprocess the IoT data; An encryption module is used to encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data; A reading module, used to read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates; A signature verification module, used to verify the signatures of the gateway module and the IoT device based on a challenge random number and through the private key and the public key; The sending module is used to encapsulate the encrypted data and send the encapsulated encrypted data to the target device through the 5G network after the signature verification of both parties is passed.
9. A computing device, characterized in that include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of claims 1 to 7.
Citation Information
Patent Citations
Internet of things terminal, network side equipment and system
CN102196539A
Internet of Things Bluetooth gateway equipment
CN107466003A
Internet-of-things identity authentication method and device, electronic equipment, system and storage medium
CN110879879A
Data security authentication transmission method and device for Internet of Things terminal
CN112291230A
Control method and device for system chip of vehicle
CN119645215A