A data transmission method and device for a 5G edge computing security control gateway module
The 5G edge computing security control gateway module solves the problem of balancing low power consumption and data security through real-time monitoring and dynamic switching of operating modes, combined with ECC encryption and digital certificate authentication, and achieves low power consumption and efficient and secure data transmission, which is suitable for scenarios such as smart transportation and telemedicine.
Patent Information
- Application Number
- CN202510632098.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-05-16
AI Technical Summary
Existing 5G edge computing security control gateway modules have difficulty balancing low power consumption and data security. Traditional solutions often sacrifice data transmission performance or have security vulnerabilities and cannot meet complex and changing application requirements.
By real-time monitoring of data interaction activities and status information, dynamically switching operating modes, and combining ECC encryption algorithm and digital certificate two-way authentication, data encrypted transmission and security verification are achieved, including data preprocessing, encryption, signature verification and encapsulation.
It achieves stable and secure data transmission under low power consumption conditions, reduces power consumption, extends device battery life, and improves data transmission efficiency and security. It is suitable for scenarios with high requirements for real-time and security.
Smart Images

Figure CN120186723B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of gateway data transmission technology, and more specifically, to a data transmission method and device for a 5G edge computing security control gateway module. Background Art
[0002] The rapid development of 5G technology and the widespread deployment of IoT devices are driving higher demands for real-time data processing and low-latency transmission in a wide range of fields, including industrial control, intelligent transportation, and smart homes. 5G edge computing can move data processing from the cloud to the edge of the network, reducing data transmission latency and improving system response speed. For example, in automated industrial production lines, data generated by a large number of sensors and actuators must be processed promptly to ensure stable and efficient production processes.
[0003] As a key node connecting IoT devices to the network, 5G edge computing security control gateway modules face the dual challenges of power consumption and data transmission efficiency. On the one hand, traditional gateway modules consume high power during extended operation. This battery life becomes a bottleneck limiting widespread adoption in battery-powered applications or those with strict power constraints, such as IoT monitoring equipment in remote areas. On the other hand, achieving efficient and stable data transmission while ensuring data security is a pressing issue. Currently, some low-power solutions often sacrifice data transmission performance or suffer from data security vulnerabilities, making them unable to meet the complex and diverse application requirements of 5G edge computing.
[0004] Therefore, a better solution is urgently needed. Summary of the Invention
[0005] The present invention provides a data transmission method and device for a 5G edge computing security control gateway module, which is used to solve the technical problem in the prior art that it is impossible to balance low power consumption and data security of the gateway module. The method includes:
[0006] monitoring data interaction activities between the IoT device and the gateway module and status information of the gateway module in real time, and determining an operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode;
[0007] Obtaining IoT data sent by IoT devices to the gateway module and preprocessing the IoT data;
[0008] Encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data;
[0009] Read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates;
[0010] Based on the challenge random number, the signatures of the gateway module and the IoT device are verified using the private key and the public key;
[0011] When the signatures of both parties are verified, the encrypted data is encapsulated and sent to the target device via the 5G network.
[0012] In some specific embodiments, the IoT data is pre-processed, specifically:
[0013] Perform a data format check on the IoT data, remove redundant information in the IoT data, and fill in data bits in the IoT data.
[0014] In some specific embodiments, the digital certificates of the gateway module and the IoT device are read, and the private key and public key of the gateway module and the IoT device are obtained based on the digital certificates. The gateway module is provided with a device certificate storage area, specifically:
[0015] Obtaining the first digital certificate of the gateway module and the second digital certificate of the IoT device from the device certificate storage area;
[0016] A public key, a first private key of the gateway module, and a second private key of the Internet of Things device are obtained based on the first digital certificate and the second digital certificate.
[0017] In some specific embodiments, based on the challenge random number and using the private key and public key, the signature verification of the gateway module and the IoT device is specifically as follows:
[0018] The gateway module sends a randomly generated first challenge random number to the IoT device;
[0019] The IoT device signs the first challenge random number using the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module;
[0020] After receiving the first signature and the first challenge random number, the gateway module verifies the first signature based on the public key;
[0021] When the first signature verification passes, the IoT device sends a second challenge random number to the gateway module;
[0022] The gateway module signs the second challenge random number using the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the IoT device;
[0023] The IoT device verifies the second signature value using the public key;
[0024] When the second signature value is successfully verified, it is determined that the signature verification of both parties is successful;
[0025] If verification of the first signature value or the second signature value fails, data communication between the gateway module and the IoT device is terminated.
[0026] In some specific embodiments, the encrypted data is encapsulated and sent to the target device via a 5G network, specifically:
[0027] The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device through the 5G network, where the header information includes the source address, destination address, data length, and serial number.
[0028] In some specific embodiments, the data interaction activities between the IoT device and the gateway module and the status information of the gateway module are monitored in real time, and the operation mode of the gateway module is determined based on the data interaction activities and the status information of the gateway module. The operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode, specifically:
[0029] The data transmission system monitors in real time the data interaction activities between the IoT device and the gateway module and the status information of the gateway module, wherein the status information includes load information and processor indicator information;
[0030] When device activity is detected or the load information or processor indicator information exceeds a first preset threshold, maintaining the gateway module in a normal operating state;
[0031] When the device activity or the load information or processor indicator information is not detected within a first time period and a second preset threshold is not detected, the gateway module is controlled to enter a light sleep mode.
[0032] In some specific embodiments, the method further comprises:
[0033] In the light sleep mode, setting a first duration of the timer;
[0034] When the timer does not exceed the first duration, keeping the gateway module in a light sleep mode;
[0035] When the timer exceeds the first time length, determining whether there is a wake-up signal through a wake-up signal detection circuit;
[0036] If there is no wake-up information, controlling the gateway module to enter deep sleep mode;
[0037] If there is a wake-up message, determining the priority of the wake-up message;
[0038] When the wake-up information is a high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism, so that it returns to the normal operating frequency, and the relevant communication and processing modules are started, so that the gateway module enters the normal operating state;
[0039] When the wake-up information is a low-priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity or the load information or processor indicator information is not detected within the first time period and the second preset threshold is exceeded, the shallow sleep mode is re-entered.
[0040] Accordingly, the present invention also proposes a data transmission device for a 5G edge computing security control gateway module, the device comprising:
[0041] An operation monitoring module monitors the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode;
[0042] A preprocessing module, configured to obtain IoT data sent by IoT devices to the gateway module and preprocess the IoT data;
[0043] An encryption module is used to encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data;
[0044] A reading module, configured to read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates;
[0045] A signature verification module, configured to verify the signatures of the gateway module and the IoT device based on a challenge random number and using the private key and the public key;
[0046] The sending module is used to encapsulate the encrypted data and send the encapsulated encrypted data to the target device through the 5G network after the signature verification of both parties is passed.
[0047] One embodiment of the present invention also provides a computing device, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the data transmission method of the 5G edge computing security control gateway module as described in any one of the above items are implemented.
[0048] One embodiment of the present invention further provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the data transmission method of the 5G edge computing security control gateway module as described in any one of the above.
[0049] By applying the above technical solution, a data transmission method for a 5G edge computing security control gateway module is proposed. The method includes: real-time monitoring of data interaction between an IoT device and the gateway module and status information of the gateway module; and determining the operating mode of the gateway module based on the data interaction and the status information, wherein the operating mode includes normal operation mode, light sleep mode, or deep sleep mode. IoT data sent by the IoT device to the gateway module is obtained and pre-processed; the pre-processed IoT data is encrypted using an ECC encryption algorithm library to obtain encrypted data; the digital certificates of the gateway module and the IoT device are read and, based on the digital certificates, the private and public keys of the gateway module and the IoT device are obtained; signatures of both the gateway module and the IoT device are verified using the private and public keys based on a challenge random number; and when the signatures of both parties are successfully verified, the encrypted data is encapsulated and sent to the target device via the 5G network, thereby achieving stable and secure data transmission while ensuring low power consumption of the gateway module. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0051] Figure 1 This is a flowchart of a data transmission method for a 5G edge computing security control gateway module provided in an embodiment of the present application;
[0052] Figure 2 This is a flow chart of a low-power consumption mechanism of a 5G edge computing security control gateway module provided by an embodiment of the present application;
[0053] Figure 3 This is a structural diagram of a data transmission device of a 5G edge computing security control gateway module provided in an embodiment of the present application;
[0054] Figure 4 This is a structural block diagram of a computing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0055] The following description sets forth many specific details to facilitate a thorough understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0056] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a," "an," and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0057] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0058] like Figure 1 As shown, this application proposes a data transmission method for a 5G edge computing security control gateway module, the method comprising the following steps:
[0059] Step S101: monitor the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determine the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode.
[0060] In one possible implementation, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are monitored in real time, and the operation mode of the gateway module is determined based on the data interaction activity and the status information of the gateway module. The operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode, specifically:
[0061] The data transmission system monitors in real time the data interaction activities between the IoT device and the gateway module and the status information of the gateway module, wherein the status information includes load information and processor indicator information;
[0062] When device activity is detected or the load information or processor indicator information exceeds a first preset threshold, maintaining the gateway module in a normal operating state;
[0063] When the device activity or the load information or processor indicator information is not detected within a first time period and a second preset threshold is not detected, the gateway module is controlled to enter a light sleep mode.
[0064] In a possible implementation, the method further includes:
[0065] In the light sleep mode, setting a first duration of the timer;
[0066] When the timer does not exceed the first duration, keeping the gateway module in a light sleep mode;
[0067] When the timer exceeds the first time length, determining whether there is a wake-up signal through a wake-up signal detection circuit;
[0068] If there is no wake-up information, controlling the gateway module to enter deep sleep mode;
[0069] If there is a wake-up message, determining the priority of the wake-up message;
[0070] When the wake-up information is a high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism, so that it returns to the normal operating frequency, and the relevant communication and processing modules are started, so that the gateway module enters the normal operating state;
[0071] When the wake-up information is a low-priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity or the load information or processor indicator information is not detected within the first time period and the second preset threshold is exceeded, the shallow sleep mode is re-entered.
[0072] In this embodiment, the gateway module sets multiple sleep modes, including light sleep and deep sleep modes. During the system idle period, it automatically switches to light sleep mode based on the preset time threshold and activity monitoring mechanism. At this time, some non-critical circuit modules enter a low-power state. For example, the RF part of the wireless communication module reduces the transmission power, and the processor enters a low-frequency operation state, but still maintains the ability to monitor specific wake-up signals. If no wake-up signal is detected within a period of time (such as 10 minutes) and the system load is extremely low, it further switches to deep sleep mode. Except for the wake-up circuit and a small number of key registers, most circuit modules are powered off to minimize power consumption.
[0073] In this embodiment, a variety of wake-up signal detection circuits are designed to detect trigger signals from IoT devices, control instructions from the network side, and specific event signals collected by sensors. For example, in a smart home scenario, when the door and window sensor detects an abnormal opening action, it will send a wake-up signal to the gateway module. The wake-up signal is input to the gateway module through a dedicated wake-up pin. After the wake-up circuit receives the signal, it first pre-processes the signal to determine the legitimacy and priority of the signal. For high-priority wake-up signals, such as emergency alarm signals, the gateway module is immediately awakened to enter normal working mode; for low-priority signals, such as periodic device status reporting signals, if the gateway module is in light sleep mode, the wake-up module performs corresponding processing. After the processing is completed, if the system still meets the sleep conditions, it re-enters sleep mode.
[0074] In this embodiment, Figure 2 As shown, the low power consumption mechanism in the present invention is described in detail.
[0075] Low power wake-up process:
[0076] ① System initialization: After the 5G edge computing security control gateway module is powered on, the system is initialized first, including hardware circuit initialization, software module loading, and parameter configuration. The time threshold for switching to sleep mode, parameters of the wake-up signal detection circuit, and the initial working status of each module are set.
[0077] ② Normal operation and monitoring: During normal operation, the gateway module monitors the activity status, network connection status, and sensor data of IoT devices in real time. Simultaneously, it regularly checks system load based on pre-set monitoring mechanisms. For example, it collects statistics on processor utilization and memory usage every minute.
[0078] ③ Sleep Mode Switching: When the system detects no IoT device data interaction for a period of time (e.g., 1 minute), a stable network connection, and low system load, it determines that the light sleep conditions are met and switches the gateway module to light sleep mode. In light sleep mode, a timer is started and set to 10 minutes. If no wake-up signal is detected within 10 minutes and the system load remains extremely low, the system switches to deep sleep mode.
[0079] ④ Wake-up processing: When the wake-up circuit receives a wake-up signal, it first samples and digitizes the signal, then uses a pre-set signal recognition algorithm to determine the signal type and priority. For high-priority wake-up signals, such as those sent by fire alarm sensors, the gateway module's processor is immediately awakened through an interrupt mechanism, restoring it to its normal operating frequency and starting the relevant communication and processing modules. For low-priority signals, such as periodic reports from ambient temperature sensors, if the gateway module is in light sleep mode, the processor is awakened for data processing. After processing is complete, the system load and activity status are checked again. If the sleep conditions are met, light sleep mode is re-entered.
[0080] 1. System Power-On: The 5G Edge Computing Security Control Gateway module is powered on, initiating the workflow. At this point, the module's hardware and software systems begin booting up, preparing for subsequent normal operation and functionality.
[0081] 2. System initialization:
[0082] Hardware circuit initialization: Initialize the various hardware components within the gateway module, such as the processor, communication module, and storage device. Configure the hardware operating parameters to ensure that each hardware module can work properly, such as setting the initial operating frequency of the processor and the operating frequency band of the communication module.
[0083] Software module loading: Loading the operating system kernel, drivers, and various functional software modules. These software modules are responsible for implementing various functions of the gateway, such as data processing, communication management, and device control.
[0084] Parameter configuration: Set key parameters related to low-power wake-up, including the time threshold for sleep mode switching, the sensitivity and trigger conditions of the wake-up signal detection circuit, and the power consumption parameters of each module in different sleep modes.
[0085] 3. Determine whether there is device activity or high load:
[0086] The system continuously monitors data interaction between IoT devices and the gateway module, such as new data requests and device status updates. It also monitors the gateway module's own load in real time, including metrics like processor occupancy and memory usage.
[0087] If device activity is detected (such as receiving data sent by a device) or the system load is high (the processor usage exceeds a certain threshold, such as 70%), the judgment is "yes" and the system enters normal operation.
[0088] If there is no device activity and the system load is low (processor usage is less than 30%, memory usage is less than 50%, etc.) for a period of time (such as the set detection period is 1 minute), it is judged as "No" and enters light sleep mode.
[0089] 4. Normal Operation: When operating normally, the gateway module fully processes data requests from IoT devices, network communication tasks, and various edge computing functions. For example, it receives and parses data uploaded by devices, performs data preprocessing and encryption, and then forwards the data to a designated server or other device. Simultaneously, it receives control commands from the network and controls IoT devices accordingly.
[0090] 5. Monitoring device activity, network, and load: During normal operation, the gateway module continuously monitors device activity, network connection status, and its own load in real time.
[0091] Device activity monitoring: Real-time monitoring of IoT devices to see if there is new data being sent, device status change notifications, etc.
[0092] Network monitoring: Check the stability of the 5G network connection, including indicators such as signal strength, network latency, and packet loss rate. If the network is abnormal, take appropriate measures in a timely manner, such as reconnecting to the network or adjusting communication parameters.
[0093] Load monitoring: Periodically (e.g., every 10 seconds) obtain information such as processor occupancy and memory usage to assess the current load level of the system.
[0094] The monitoring results will be used as the basis for determining whether to enter sleep mode, and the system will continuously loop back to the step of "determining whether there is device activity or high load".
[0095] 6. Entering light sleep mode and starting the timer: When the system determines that the conditions for entering light sleep mode are met, the gateway module begins to perform a series of operations to reduce power consumption.
[0096] Some non-critical circuit modules enter a low-power state: for example, the RF part of the wireless communication module reduces the transmit power, and the processor reduces the operating frequency, but still maintains the ability to monitor specific wake-up signals.
[0097] Start timer: Set the timer duration, such as 10 minutes. During the timer running, if no other events occur, the system will further decide whether to enter deep sleep mode based on the timer expiration situation.
[0098] 7. Determine whether the timer has timed out: In light sleep mode, the system checks the status of the timer in real time.
[0099] If the timer has not timed out, the system continues to remain in light sleep mode, waiting for the timer to end or the wake-up signal to arrive.
[0100] When the timer reaches the set duration, that is, times out, the next step is to determine whether there is a wake-up signal.
[0101] 8. Determine whether there is a wake-up signal:
[0102] The wake-up signal detection circuit continuously monitors trigger signals from IoT devices, control instructions from the network side, and specific event signals collected by sensors.
[0103] If a wake-up signal is detected, the system determines that it is "yes" and immediately executes the operation of waking up the gateway module to restore it to normal operating mode.
[0104] If no wake-up signal is detected, the determination is "No" and the system enters deep sleep mode.
[0105] 9. Entering Deep Sleep Mode: In Deep Sleep Mode, most circuit modules are powered off, except for the wake-up circuit and a few key registers, to minimize power consumption. At this point, the gateway module's power consumption is reduced to extremely low levels, but it still retains the ability to be awakened by a specific wake-up signal.
[0106] 10. Wake up the gateway and resume normal operation: When a wake-up signal is detected, the wake-up circuit first pre-processes the signal to determine its legitimacy and priority. For legitimate wake-up signals, the circuit then processes them based on their priority.
[0107] For high-priority wake-up signals, such as emergency alarm signals, the gateway module's processor is immediately awakened through the interrupt mechanism, allowing it to quickly recover to its normal operating frequency, and start related communication and processing modules, allowing the gateway module to quickly enter normal operating state and respond to emergency events as soon as possible.
[0108] For low-priority wake-up signals, such as periodic device status reporting signals, the processor is also woken up for data processing. After processing is completed, the system load and activity status are checked again. If the sleep conditions are met, the processor re-enters light sleep mode.
[0109] Step S102: obtaining IoT data sent by the IoT device to the gateway module and preprocessing the IoT data.
[0110] In a possible implementation, the IoT data is preprocessed as follows:
[0111] Perform a data format check on the IoT data, remove redundant information in the IoT data, and fill in data bits in the IoT data.
[0112] In this embodiment, in 5G edge computing applications, IoT devices (such as sensors and smart terminals) send collected data to the 5G edge computing security control gateway module. This data, which may include device status information, environmental monitoring data, user operation instructions, and other different types of information, is the starting point of the entire data transmission process.
[0113] In this embodiment, after the 5G edge computing security control gateway module receives data sent by the IoT device, it first pre-processes the data. This step mainly includes data format checking to ensure that the data conforms to the predetermined format specifications, such as the byte length and field order of the data; removing redundant information to streamline the data content to improve subsequent processing efficiency; and padding data bits. If there are any missing data bits during the data transmission process, the corresponding padding operation is performed to ensure data integrity.
[0114] Step S103: Encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data.
[0115] In this embodiment, after preprocessing, the gateway module invokes an encryption algorithm library based on elliptic curve cryptography (ECC). The ECC algorithm leverages the mathematical properties of elliptic curves to generate a public and private key pair. The gateway then uses the private key to encrypt the preprocessed data, converting the original data into ciphertext. Due to its short key length, minimal computational effort, and high security, the ECC algorithm is particularly well-suited for use in resource-constrained 5G edge computing gateway modules. It effectively ensures data confidentiality during transmission and prevents data theft or tampering.
[0116] Step S104 , reading the digital certificates of the gateway module and the IoT device, and obtaining the private key and public key of the gateway module and the IoT device based on the digital certificates.
[0117] In one possible implementation, the digital certificates of the gateway module and the IoT device are read, and the private key and public key of the gateway module and the IoT device are obtained based on the digital certificates. The gateway module is provided with a device certificate storage area, specifically:
[0118] Obtaining the first digital certificate of the gateway module and the second digital certificate of the IoT device from the device certificate storage area;
[0119] A public key, a first private key of the gateway module, and a second private key of the Internet of Things device are obtained based on the first digital certificate and the second digital certificate.
[0120] In this embodiment, to authenticate both communicating parties, the gateway module retrieves the IoT device's digital certificate from its internal device certificate storage area and also obtains its own digital certificate. Digital certificates, issued by a trusted certificate authority (CA), contain the device or gateway's identity information and its corresponding public key, and are crucial for the authentication process.
[0121] Step S105 : Based on the challenge random number, the signatures of the gateway module and the IoT device are verified using the private key and the public key.
[0122] In one possible implementation, based on the challenge random number and using the private key and public key, the signatures of the gateway module and the IoT device are verified, specifically:
[0123] The gateway module sends a randomly generated first challenge random number to the IoT device;
[0124] The IoT device signs the first challenge random number using the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module;
[0125] After receiving the first signature and the first challenge random number, the gateway module verifies the first signature based on the public key;
[0126] When the first signature verification passes, the IoT device sends a second challenge random number to the gateway module;
[0127] The gateway module signs the second challenge random number using the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the IoT device;
[0128] The IoT device verifies the second signature value using the public key;
[0129] When the second signature value is successfully verified, it is determined that the signature verification of both parties is successful;
[0130] If verification of the first signature value or the second signature value fails, data communication between the gateway module and the IoT device is terminated.
[0131] In this embodiment, the gateway module sends a randomly generated challenge number to the IoT device. This random number is unique and time-sensitive during the authentication process. The purpose of sending the challenge number is to allow the device to sign it with its own private key, thereby verifying its authenticity.
[0132] After receiving the challenge random number from the gateway, the IoT device signs it using its own private key. The signing process uses a specific encryption algorithm to calculate the random number and the device's private key to generate a signature value. After signing, the device transmits the signed random number back to the gateway module.
[0133] After receiving the signed random number from the device, the gateway module verifies the signature using the public key in the device's digital certificate. This verification process uses a specific algorithm to calculate the received signature value, the random number, and the device's public key to determine if the signature is valid. If verification succeeds, the device's identity is authentic, as only a device holding the corresponding private key can correctly sign the random number. If verification fails, the device's identity is considered flawed, potentially indicating an illegal device or tampering with the certificate.
[0134] After the gateway successfully verifies the device's signature, it is the device's turn to authenticate the gateway. At this point, the device sends a new challenge random number to the gateway module. This random number is also unique and time-sensitive and is used for gateway authentication.
[0135] After receiving the random challenge number sent by the device, the gateway module uses its own private key to sign the random number to generate a signature value. After completing the signature, it returns the signed random number to the IoT device.
[0136] After receiving the signed random number from the gateway, the IoT device verifies the signature using the public key in the gateway's digital certificate. A specific verification algorithm is used to determine the validity of the signature. If verification succeeds, it indicates the gateway's identity is authentic and the authentication process is successfully completed. If verification fails, it indicates a problem with the gateway's identity, suggesting an unauthorized gateway may be attempting to access communications.
[0137] Step S106: After the signatures of both parties are verified, the encrypted data is encapsulated and sent to the target device via the 5G network.
[0138] In one possible implementation, encapsulating the encrypted data and sending the encapsulated encrypted data to the target device via the 5G network is as follows:
[0139] The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device through the 5G network, where the header information includes the source address, destination address, data length, and serial number.
[0140] In this embodiment, after data encapsulation and header information addition, the gateway module transmits the data via the 5G network. The 5G network offers high bandwidth and low latency, enabling rapid and stable data transmission to the target server or other receiving end. During transmission, data encryption and identity authentication ensure data security and the legitimacy of both communicating parties.
[0141] In summary, the present invention has the following advantages:
[0142] 1. Reduced power consumption: Through the rational switching of sleep modes and an efficient wake-up mechanism, the power consumption of the 5G edge computing security control gateway module is greatly reduced, extending the battery life of the device. It is particularly suitable for power-sensitive IoT application scenarios such as smart water meters and electricity meters. It reduces the frequency of battery replacement or charging and reduces operation and maintenance costs.
[0143] 2. Ensure data security: The ECC-based encryption algorithm and digital certificate two-way authentication mechanism provide high-intensity security for data transmission, effectively preventing data theft, tampering, and forgery, and meeting the application needs of 5G edge computing in fields such as finance, rail transportation, and industrial control that have extremely high data security requirements.
[0144] 3. Improve data transmission efficiency: The lightweight data transmission protocol can dynamically adjust the transmission strategy according to the network environment, fully leveraging the advantages of the 5G network to achieve efficient and stable data transmission, reduce data transmission delays, and improve the overall performance of the system. It is of great significance in scenarios with high real-time requirements such as intelligent transportation and telemedicine.
[0145] The embodiment of the present application also proposes a data transmission device of a 5G edge computing security control gateway module, such as Figure 3 As shown, the device includes:
[0146] An operation monitoring module 10 monitors the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode;
[0147] The preprocessing module 20 is used to obtain the IoT data sent by the IoT device to the gateway module and preprocess the IoT data;
[0148] An encryption module 30 is used to encrypt the pre-processed IoT data based on an ECC encryption algorithm library to obtain encrypted data;
[0149] The reading module 40 is used to read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates;
[0150] A signature verification module 50 is configured to verify the signatures of the gateway module and the IoT device using the private key and the public key based on a random challenge number;
[0151] The sending module 60 is used to encapsulate the encrypted data and send the encapsulated encrypted data to the target device through the 5G network after the signature verification of both parties is passed.
[0152] Figure 4 The block diagram of a computing device 400 according to one embodiment of the present disclosure is shown. Components of the computing device 400 include, but are not limited to, a memory 410 and a processor 420. The processor 420 is connected to the memory 410 via a bus 430, and a database 450 is used to store data.
[0153] Computing device 400 also includes an access device 440 that enables computing device 400 to communicate via one or more networks 460. Examples of such networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. Access device 440 may include one or more of any type of network interface (e.g., a network interface controller (NIC)) whether wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, or a near field communication (NFC) interface.
[0154] In one embodiment of the present specification, the above components of the computing device 400 and Figure 4 Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 4 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0155] Computing device 400 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, personal digital assistant, laptop computer, notebook computer, netbook computer, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or personal computer (PC). Computing device 400 can also be a mobile or stationary server.
[0156] The processor 420 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the data transmission method for the 5G edge computing security control gateway module. The above is a schematic diagram of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the data transmission method for the 5G edge computing security control gateway module described above are based on the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the data transmission method for the 5G edge computing security control gateway module described above.
[0157] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the data transmission method of the above-mentioned 5G edge computing security control gateway module.
[0158] The above is a schematic scheme of a computer-readable storage medium of this embodiment. It should be noted that the technical scheme of this storage medium and the technical scheme of the data transmission method of the aforementioned 5G edge computing security control gateway module are based on the same concept. For details not described in detail in the technical scheme of the storage medium, please refer to the description of the technical scheme of the data transmission method of the aforementioned 5G edge computing security control gateway module.
[0159] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the data transmission method of the above-mentioned 5G edge computing security control gateway module.
[0160] The above is a schematic scheme of a computer program of this embodiment. It should be noted that the technical scheme of this computer program and the technical scheme of the data transmission method of the aforementioned 5G edge computing security control gateway module are based on the same concept. For details not described in detail in the technical scheme of the computer program, please refer to the description of the technical scheme of the data transmission method of the aforementioned 5G edge computing security control gateway module.
[0161] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0162] The computer instructions include computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. It should be noted that the content of the computer-readable medium may be appropriately increased or decreased based on the requirements of legislation and patent practice within a jurisdiction. For example, in some jurisdictions, based on legislation and patent practice, computer-readable media does not include electric carrier signals and telecommunication signals.
[0163] It should be noted that for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0164] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0165] The preferred embodiments disclosed above are intended only to help illustrate this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made based on the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A data transmission method for a 5G edge computing security control gateway module, characterized in that: Applied to a data transmission system including a 5G edge computing security control gateway module and several IoT devices, the method includes: monitoring data interaction activities between the IoT device and the gateway module and status information of the gateway module in real time, and determining an operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode; Obtaining IoT data sent by IoT devices to the gateway module and preprocessing the IoT data; Encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data; Read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates; Based on the challenge random number, the signatures of the gateway module and the IoT device are verified using the private key and the public key; When the signatures of both parties are verified, the encrypted data is encapsulated and sent to the target device via the 5G network; The data interaction activities between the IoT device and the gateway module and the status information of the gateway module are monitored in real time, and the operation mode of the gateway module is determined based on the data interaction activities and the status information of the gateway module. The operation mode includes a normal operation mode, a light sleep mode or a deep sleep mode, specifically: The data transmission system monitors in real time the data interaction activities between the IoT device and the gateway module and the status information of the gateway module, wherein the status information includes load information and processor indicator information; When device activity is detected or the load information or processor indicator information exceeds a first preset threshold, maintaining the gateway module in a normal operating state; When no device activity is detected within a first time period or the load information or processor indicator information is lower than a second preset threshold, controlling the gateway module to enter a light sleep mode; The method further comprises: In the light sleep mode, setting a first duration of the timer; When the timer does not exceed the first duration, keeping the gateway module in a light sleep mode; When the timer exceeds the first time length, determining whether there is a wake-up signal through a wake-up signal detection circuit; If there is no wake-up information, controlling the gateway module to enter deep sleep mode; If there is a wake-up message, determining the priority of the wake-up message; When the wake-up information is a high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism, so that it returns to the normal operating frequency, and the relevant communication and processing modules are started, so that the gateway module enters the normal operating state; When the wake-up information is low-priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity is not detected within the first time period or the load information or processor indicator information is lower than the second preset threshold, the shallow sleep mode is re-entered.
2. The method according to claim 1, characterized in that The IoT data is preprocessed, specifically: Perform a data format check on the IoT data, remove redundant information in the IoT data, and fill in data bits in the IoT data.
3. The method according to claim 2, characterized in that Read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates. The gateway module is provided with a device certificate storage area, specifically: Obtaining the first digital certificate of the gateway module and the second digital certificate of the IoT device from the device certificate storage area; A public key, a first private key of the gateway module, and a second private key of the Internet of Things device are obtained based on the first digital certificate and the second digital certificate.
4. The method according to claim 3, characterized in that Based on the challenge random number and using the private key and public key, the signature verification of the gateway module and the IoT device is specifically as follows: The gateway module sends a randomly generated first challenge random number to the IoT device; The IoT device signs the first challenge random number using the second private key to obtain a first signature value, and sends the first signature value and the first challenge random number back to the gateway module; After receiving the first signature and the first challenge random number, the gateway module verifies the first signature based on the public key; When the first signature verification passes, the IoT device sends a second challenge random number to the gateway module; The gateway module signs the second challenge random number using the first private key to obtain a second signature value, and sends the second signature value and the second challenge random number back to the IoT device; The IoT device verifies the second signature value using the public key; When the second signature value is successfully verified, it is determined that the signature verification of both parties is successful; If verification of the first signature value or the second signature value fails, data communication between the gateway module and the IoT device is terminated.
5. The method according to claim 3, characterized in that Encapsulating the encrypted data and sending the encapsulated encrypted data to the target device via the 5G network, specifically: The encrypted data is encapsulated, header information is added to the encrypted data, and the encapsulated encrypted data is sent to the target device through the 5G network, where the header information includes the source address, destination address, data length, and serial number.
6. A data transmission device for a 5G edge computing security control gateway module, characterized in that: Applied to a data transmission system including a 5G edge computing security control gateway module and several IoT devices, the device includes: An operation monitoring module monitors the data interaction activities between the IoT device and the gateway module and the status information of the gateway module in real time, and determines the operation mode of the gateway module based on the data interaction activities and the status information of the gateway module, wherein the operation mode includes a normal operation mode, a light sleep mode, or a deep sleep mode; A preprocessing module, configured to obtain IoT data sent by IoT devices to the gateway module and preprocess the IoT data; An encryption module is used to encrypt the pre-processed IoT data based on the ECC encryption algorithm library to obtain encrypted data; A reading module, configured to read the digital certificates of the gateway module and the IoT device, and obtain the private key and public key of the gateway module and the IoT device based on the digital certificates; A signature verification module, configured to verify the signatures of the gateway module and the IoT device based on a challenge random number and using the private key and the public key; A sending module is used to encapsulate the encrypted data and send the encapsulated encrypted data to the target device via the 5G network after the signature verification of both parties is passed; The operation monitoring module is specifically used to: The data transmission system monitors in real time the data interaction activities between the IoT device and the gateway module and the status information of the gateway module, wherein the status information includes load information and processor indicator information; When device activity is detected or the load information or processor indicator information exceeds a first preset threshold, maintaining the gateway module in a normal operating state; When no device activity is detected within a first time period or the load information or processor indicator information is lower than a second preset threshold, controlling the gateway module to enter a light sleep mode; Wherein, the device is also used for: In the light sleep mode, setting a first duration of the timer; When the timer does not exceed the first duration, keeping the gateway module in a light sleep mode; When the timer exceeds the first time length, determining whether there is a wake-up signal through a wake-up signal detection circuit; If there is no wake-up information, controlling the gateway module to enter deep sleep mode; If there is a wake-up message, determining the priority of the wake-up message; When the wake-up information is a high-priority wake-up information, the processor of the gateway module is woken up through a preset interrupt mechanism, so that it returns to the normal operating frequency, and the relevant communication and processing modules are started, so that the gateway module enters the normal operating state; When the wake-up information is low-priority wake-up information, the processor of the gateway module is woken up and data processing is performed. After the data processing is completed, the data interaction activity between the IoT device and the gateway module and the status information of the gateway module are checked again. When the device activity is not detected within the first time period or the load information or processor indicator information is lower than the second preset threshold, the shallow sleep mode is re-entered.
7. A computing device, characterized in that include: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the data transmission method of the 5G edge computing security control gateway module described in any one of claims 1 to 5.
Citation Information
Patent Citations
Internet-of-things identity authentication method and device, electronic equipment, system and storage medium
CN110879879A
Control method and device for system chip of vehicle
CN119645215A
Vehicle control method and device based on Internet of Things equipment, vehicle and storage medium
CN119906742A
Terminal state transition method, network device and terminal
US20210410067A1