Identity data encryption method and system of Internet of Things terminal
By using asymmetric encryption algorithms in IoT terminals to generate public-private key pairs and dynamically adjusting the session key strength based on the importance of environmental data, the contradiction between security and resource utilization in IoT terminal data encryption is solved, and the secure transmission of highly sensitive data and efficient use of resources is achieved.
Patent Information
- Application Number
- CN202510452027.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In data encryption, existing IoT terminals have not been fully considered due to differences in environmental data importance, resulting in insufficient redundancy in security of high-sensitive data or waste of low-value data resources.
Asymmetric encryption algorithm is used to generate public and private key pairs, the private key is stored in the hardware security module, and the public key is uploaded to the server for registration; a TLS/DTLS connection is established based on public and private key pair authentication, and temporary session keys of different strengths are matched through the importance of hierarchical environment data, and the terminal resources are dynamically upgraded and downgraded encryption policies.
The security of highly sensitive data is improved, and the consumption of low-sensitive data resources is reduced, ensuring the security of data transmission and efficient utilization of resources.
Smart Images

Figure CN120238355A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data processing, and in particular, relates to an identity data encryption method and system for Internet of Things (IoT) terminals. Background Art
[0002] IoT terminals are the core devices in IoT systems, responsible for real-time collection of physical environment data (such as temperature, location, images, etc.) and transmission to a server through a network (Wi-Fi, 5G, Bluetooth, etc.), and can also receive instructions to perform specific operations (such as switch control, alarm triggering).
[0003] Existing IoT terminals generally use static fixed-strength session keys to implement data encryption. However, due to significant differences in the importance of environmental data (such as critical equipment status monitoring and ordinary temperature and humidity collection), using the same key strength uniformly will not only lead to the risk of insufficient security redundancy for highly sensitive data but also may cause unnecessary consumption of computing power resources for low-value data, thus requiring improvement. Summary of the Invention
[0004] Based on this, it is necessary to provide an identity data encryption method and system for IoT terminals in view of the above problems.
[0005] An embodiment of the present invention is implemented as follows. An identity data encryption method for an IoT terminal includes the following steps:
[0006] Generate a public-private key pair using an asymmetric encryption algorithm (such as RSA, ECC). The private key is stored in the IoT terminal (specifically, it can be in a HSM, i.e., a hardware security module), and the public key is uploaded to the server for registration.
[0007] After establishing a TLS / DTLS connection based on public-private key pair authentication, match different-strength temporary session keys according to the hierarchical importance of environmental data (such as high / low risk), and monitor the resources of the IoT terminal in real time to dynamically upgrade or downgrade the temporary session keys.
[0008] After the terminal encrypts the data using the temporary session key, transmit the encrypted data to the server.
[0009] In one embodiment, the present invention provides an identity data encryption method for an IoT terminal. In the step of generating a public-private key pair using an asymmetric encryption algorithm (such as RSA, ECC), storing the private key in the IoT terminal (specifically, it can be in a HSM, i.e., a hardware security module), and uploading the public key to the server for registration, it specifically includes:
[0010] Call the encryption interface of the HSM (such as the PKCS#11 standard) in the IoT terminal, and select the RSA-2048 or ECC-secp256r1 algorithm to generate a public-private key pair.
[0011] Write the private key directly into the export - protected security area of the HSM for storage;
[0012] Encode the public key into the PEM / DER format, and upload it to the server via HTTPS along with the unique identifier (such as the serial number) of the device (IoT terminals are usually built into the device hardware in the form of chips or others). After the server verifies the format, store it in the database and bind it to the device identity to form a device identity certificate system.
[0013] In one embodiment, the present invention provides an identity data encryption method for IoT terminals. After establishing a TLS / DTLS connection based on public - private key pair authentication, different - strength temporary session keys are matched according to the hierarchical importance of environmental data (such as high / low risk), and the resources of the IoT terminal are monitored in real - time. In the step of dynamically upgrading or downgrading the temporary session key, it specifically includes:
[0014] Control the IoT terminal and the server to perform identity authentication through the public - private key pair and establish a TLS / DTLS connection;
[0015] After establishing the TLS / DTLS connection, judge the importance of the environmental data collected by different sensors and select different - strength temporary session keys;
[0016] Detect the resources of the IoT terminal. When the resources are limited, downgrade the temporary session key; when the resources are sufficient, upgrade the temporary session key. The resources of the IoT terminal include MCU computing power and communication bandwidth.
[0017] In one embodiment, the present invention provides an identity data encryption method for IoT terminals. In the step of judging the importance of the environmental data collected by different sensors and selecting different - strength temporary session keys after establishing the TLS / DTLS connection, it specifically includes:
[0018] After establishing the TLS / DTLS connection, receive the environmental data (such as temperature, humidity, movement, etc.) obtained by various sensors. When the environmental data is normal, the temporary session key adopts the initial encryption strategy (such as ordinary algorithm, long key period);
[0019] Once a certain environmental data exceeds the preset threshold (such as a sudden increase in temperature, a sudden change in humidity, etc.) and is confirmed abnormal through cross - verification of multiple environmental data, immediately dynamically increase the security level of the temporary session key (such as switching to high - strength encryption, shortening the key update frequency);
[0020] After the environmental data returns to normal, control the security level of the temporary session key to automatically gradually downgrade to the initial state.
[0021] In one embodiment, the present invention provides an identity data encryption method for an Internet of Things (IoT) terminal. In the step of encrypting data by the terminal with a temporary session key and then transmitting the encrypted data to the server, it specifically includes:
[0022] After the terminal encrypts data with a temporary session key, generate an HMAC or digital signature and append it to the encrypted data; the HMAC is generated with the same temporary session key; the digital signature is generated with the private key of the server terminal;
[0023] Transmit the encrypted data + HMAC or digital signature to the server.
[0024] In one embodiment, the present invention provides an identity data encryption system for an IoT terminal, including:
[0025] A public-private key pair generation module, which is used to generate a public-private key pair using an asymmetric encryption algorithm (such as RSA, ECC). The private key is stored in the IoT terminal (specifically, it can be in the HSM, that is, the hardware security module), and the public key is uploaded to the server for registration;
[0026] A temporary session key upgrade and downgrade module, which is used to establish a TLS / DTLS connection based on public-private key pair authentication, match different-strength temporary session keys by grading the importance of environmental data (such as high / low risk), and monitor the resources of the IoT terminal in real time to dynamically upgrade and downgrade the temporary session key;
[0027] A data encryption and transmission module, which is used to encrypt data by the terminal with a temporary session key and then transmit the encrypted data to the server.
[0028] In one embodiment, the present invention provides an identity data encryption system for an IoT terminal. The public-private key pair generation module includes:
[0029] A public-private key pair obtaining unit, which is used to call the encryption interface of the HSM (such as the PKCS#11 standard) in the IoT terminal and select the RSA-2048 or ECC-secp256r1 algorithm to generate a public-private key pair;
[0030] A private key writing unit, which is used to directly write the private key into the anti-export security area of the HSM for storage;
[0031] A public key uploading unit, which is used to encode the public key into the PEM / DER format, upload it to the server through HTTPS carrying the unique identifier (such as the serial number) of the device (the IoT terminal is usually built into the device hardware in the form of a chip or other), and after the server verifies the format, store it in the database and bind it to the device identity to form a device identity certificate system.
[0032] In one embodiment, the present invention provides an identity data encryption system for an Internet of Things (IoT) terminal. The temporary session key upgrade / downgrade module includes:
[0033] An identity authentication unit, configured to control the IoT terminal and the server to perform identity authentication through public-private key pairs and establish a TLS / DTLS connection;
[0034] An environmental data key matching unit, configured to, after establishing a TLS / DTLS connection, determine the importance of environmental data collected by different sensors and select temporary session keys of different strengths;
[0035] A key dynamic adjustment unit, configured to detect the resources of the IoT terminal. When the resources are limited, downgrade the temporary session key, and when the resources are sufficient, upgrade the temporary session key. The resources of the IoT terminal include MCU computing power and communication bandwidth.
[0036] In one embodiment, the present invention provides an identity data encryption system for an IoT terminal. The environmental data key matching unit includes:
[0037] An environmental data normal subunit, configured to, after establishing a TLS / DTLS connection, receive environmental data (such as temperature, humidity, movement, etc.) obtained by various sensors. When the environmental data is normal, the temporary session key adopts an initial encryption strategy (such as a normal algorithm, a long key period);
[0038] An environmental data abnormal subunit, configured to, once a certain environmental data exceeds a preset threshold (such as a sudden increase in temperature, a sudden change in humidity, etc.) and is confirmed to be abnormal through cross-verification of multiple environmental data, immediately dynamically increase the security level of the temporary session key (such as switching to high-strength encryption, shortening the key update frequency);
[0039] An environmental data recovery subunit, configured to, after the environmental data returns to normal, control the security level of the temporary session key to automatically gradually degrade to the initial state.
[0040] In one embodiment, the present invention provides an identity data encryption system for an IoT terminal. The data encryption and transmission module includes:
[0041] A data encryption unit, configured to, after encrypting data by the terminal with a temporary session key, generate an HMAC or a digital signature and append it to the encrypted data; the HMAC is generated by the same temporary session key; the digital signature is generated by the private key of the server terminal;
[0042] A data transmission unit, configured to transmit the encrypted data + HMAC or digital signature to the server.
[0043] Compared with the prior art, the beneficial effects of the present invention are as follows: By matching different intensities of temporary session keys according to the importance of hierarchical environmental data, the present invention makes highly sensitive environmental data more secure and consumes less computing power resources for low-sensitive environmental data; and it monitors the resources of IoT terminals in real time and dynamically upgrades and downgrades the temporary session keys to ensure the normal transmission of data. Brief Description of the Drawings
[0044] Figure 1 It is a schematic flowchart of an identity data encryption method for an IoT terminal provided by an embodiment of the present invention.
[0045] Figure 2 It is a schematic flowchart of the generation and distribution of public and private key pairs provided by an embodiment of the present invention.
[0046] Figure 3 It is a schematic flowchart of the adjustment of the intensity of the temporary session key provided by an embodiment of the present invention.
[0047] Figure 4 It is a schematic flowchart of adjusting the intensity of the temporary session key according to environmental data provided by an embodiment of the present invention.
[0048] Figure 5 It is a schematic flowchart of data encrypted transmission provided by an embodiment of the present invention.
[0049] Figure 6 It is a schematic diagram of an identity data encryption system for an IoT terminal provided by an embodiment of the present invention.
[0050] Figure 7 It is a schematic diagram of a public and private key pair generation module provided by an embodiment of the present invention.
[0051] Figure 8 It is a schematic diagram of a temporary session key upgrade and downgrade module provided by an embodiment of the present invention.
[0052] Figure 9 It is a schematic diagram of an environmental data key matching unit provided by an embodiment of the present invention.
[0053] Figure 10 It is a schematic diagram of a data encrypted transmission module provided by an embodiment of the present invention. Detailed Embodiments
[0054] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0055] In one embodiment, as Figure 1 shown, an identity data encryption method for an IoT terminal includes the following steps:
[0056] Step S1, use an asymmetric encryption algorithm (such as RSA, ECC) to generate a public-private key pair, the private key is stored in the IoT terminal (specifically, it can be in the HSM, i.e., the hardware security module), and the public key is uploaded to the server for registration;
[0057] Step S2: After establishing a TLS / DTLS connection based on public-private key pair authentication, temporary session keys of different strengths are matched by grading the importance of environmental data (such as high / low risk), and IoT terminal resources are monitored in real time to dynamically upgrade or downgrade temporary session keys;
[0058] Step S3: After the terminal encrypts the data using the temporary session key, the encrypted data is transmitted to the server.
[0059] In the IoT secure communication scenario, three core steps form a closed-loop protection system:
[0060] Step S1, first, the IoT terminal generates an asymmetric public-private key pair through a hardware security module (HSM). The HSM calls the PKCS#11 standard interface and selects the RSA-2048 or ECC-secp256r1 algorithm to generate the key, where the private key is directly written into the HSM's anti-export security zone to ensure that it cannot be leaked even under physical attacks. The public key is encoded in PEM or DER format and uploaded to the server after being bound to the device's unique identifier (such as the chip serial number) via the HTTPS protocol. After the server verifies the legitimacy of the public key format, it stores it in the database and builds a device identity certificate system to form a trusted terminal identity authentication basis. This step provides an unalterable identity credential for subsequent communications through hardware-level secure storage and standard encryption algorithms.
[0061] Step S2: Based on the public and private key pair of S1, the IoT terminal and the server establish a TLS / DTLS encrypted channel through two-way authentication (TLS is used in TCP scenarios and DTLS is used in UDP low-power scenarios). After the connection is established, the session key strength is dynamically adjusted according to the importance of the environmental data: for example, ordinary temperature and humidity data are encrypted in AES-128-CTR mode with a key update cycle of 1 hour; while key device status data is upgraded to AES-256-GCM mode, and the key cycle is shortened to 10 minutes. At the same time, the system monitors the MCU computing power and communication bandwidth of the terminal in real time: if resources are tight (such as CPU occupancy rate exceeds 80%), the key strength is downgraded (such as switching to AES-128-ECB) and the key cycle is extended; when resources are sufficient, the key strength is increased in the opposite direction. In abnormal scenarios (such as a sudden temperature rise triggering multiple sensor alarms), the system immediately upgrades the encryption strategy and shortens the key cycle after confirming the risk through cross-validation, achieving a real-time balance between security and resource consumption.
[0062] In step S3, after the terminal encrypts the data using the dynamically generated session key, it attaches an HMAC (a hash-based message authentication code) or a digital signature to ensure integrity. The HMAC is generated through the temporary session key (such as SHA-256-HMAC), which has high computational efficiency but relies on the secrecy of the key; the digital signature is generated by the terminal's private key (such as ECDSA), which provides non-repudiation but has a relatively large overhead. The encrypted data and the authentication tag are transmitted to the server through the TLS / DTLS channel. After the server decrypts the data, it verifies the HMAC or the signature to ensure that the data has not been tampered with. If an authentication failure is detected, a key reset or an alarm mechanism is triggered. By combining dynamic keys with multiple authentication methods, this method can meet the resource constraints and diverse security requirements of IoT terminals while ensuring data confidentiality, integrity, and identity credibility.
[0063] In one embodiment, as Figure 2 shown, a method for encrypting identity data of an IoT terminal, in step S1, an asymmetric encryption algorithm (such as RSA, ECC) is used to generate a public-private key pair. The private key is stored in the IoT terminal (specifically, it can be in the HSM, i.e., the hardware security module), and the public key is uploaded to the server for registration. Specifically, it includes:
[0064] In step S11, the encryption interface of the HSM (such as the PKCS#11 standard) is called in the IoT terminal, and the RSA-2048 or ECC-secp256r1 algorithm is selected to generate a public-private key pair;
[0065] In step S12, the private key is directly written into the anti-export security area of the HSM for storage;
[0066] In step S13, the public key is encoded in the PEM / DER format and uploaded to the server through HTTPS along with the unique identifier (such as the serial number) of the device (the IoT terminal is usually built into the device hardware in the form of a chip or other form). After the server verifies the format, it is stored in the database and bound to the device identity, forming a device identity certificate system.
[0067] In step S11, the IoT terminal calls the PKCS#11 standard interface of the hardware security module (HSM) to generate an asymmetric encryption public-private key pair. The algorithms supported are RSA-2048 (with strong compatibility) or ECC-secp256r1 (such as the NIST P-256 curve, with low resource consumption). After the private key is generated, it is directly entrusted by the HSM to avoid exposure in the ordinary storage area of the terminal, thus eliminating the risk of key leakage from the source.
[0068] Step S12, the private key is stored in the anti-export security area of the HSM. This area has a physical anti-tampering design (such as anti-side channel attack and anti-chip dissection). Even if the device is physically stolen, the private key cannot be extracted. This mechanism provides hardware-level protection for the identity of IoT terminals, ensuring that the private key is only used for internal signature or decryption operations within the HSM and cannot be copied or exported.
[0069] Step S13, after the public key is formatted by PEM (text encoding) or DER (binary encoding), it is uploaded to the server through an HTTPS encrypted channel and strongly bound to the unique device identifier (such as the chip serial number). After the server verifies the legality of the public key format, it stores it in the database and issues a device identity certificate, forming a "one device, one certificate" system to establish a trusted identity chain for subsequent mutual authentication. HTTPS transmission and format verification jointly resist man-in-the-middle attacks and forged public key injection.
[0070] In one embodiment, as Figure 3 shown, for an identity data encryption method of an IoT terminal, in step S2, after establishing a TLS / DTLS connection based on public-private key pair authentication, different strengths of temporary session keys are matched by grading the importance of environmental data (such as high / low risk), and the resources of the IoT terminal are monitored in real time. In the step of dynamically upgrading and downgrading the temporary session key, it specifically includes:
[0071] Step S21, control the IoT terminal and the server to perform identity authentication through the public-private key pair and establish a TLS / DTLS connection;
[0072] Step S22, after establishing the TLS / DTLS connection, judge the importance of the environmental data collected by different sensors and select different strengths of temporary session keys;
[0073] Step S23, detect the resources of the IoT terminal. When the resources are limited, downgrade the temporary session key. When the resources are sufficient, upgrade the temporary session key. The resources of the IoT terminal include MCU computing power and communication bandwidth.
[0074] For example, when the distribution IoT terminal in the urban smart grid is transmitting data:
[0075] Step S21, the IoT terminal establishes mutual authentication with the server through the DTLS protocol. The IoT terminal uses the generated ECC private key to sign the handshake message. After the server verifies the IoT terminal certificate, it negotiates a temporary session key (AES-128) using the ECDHE algorithm. Even if the long-term key of the distribution network is leaked in the future, the historical voltage fluctuation data is still protected by forward secrecy.
[0076] Step S22: Normal current data (low risk) is encrypted using AES-128-CTR (key rotation every 1 hour); when a 20% sudden increase in current is detected and 3 adjacent nodes synchronously alarm (high risk), immediately switch to AES-256-GCM encryption (key rotation every 10 minutes), add HMAC-SHA384 verification, and exclude false alarms through multi-terminal data cross-verification to ensure the anti-tampering of power-off warning information.
[0077] Step S23: When the CPU load of the terminal reaches 85% during the peak summer electricity consumption period, automatically degrade to the AES-128-ECB mode and extend the key cycle to 2 hours to reduce encryption latency; after the load drops back to 30% at night, resume AES-256-CTR encryption (key rotation every 30 minutes) to balance encryption strength and real-time response requirements and prevent delays in protection device control commands caused by overload.
[0078] In one embodiment, as Figure 4 shown, for an identity data encryption method of an IoT terminal, in the step S22 of establishing a TLS / DTLS connection and then judging the importance of environmental data collected by different sensors and selecting different-strength temporary session keys, it specifically includes:
[0079] Step S221: After establishing a TLS / DTLS connection, receive environmental data obtained by various sensors (such as temperature, humidity, movement, etc.). When the environmental data is normal, the temporary session key adopts the initial encryption policy (such as ordinary algorithm, long key cycle).
[0080] Step S222: Once a certain environmental data exceeds the preset threshold (such as a sudden increase in temperature, a sudden change in humidity, etc.) and is confirmed to be abnormal through cross-verification of multiple environmental data, immediately dynamically upgrade the security level of the temporary session key (such as switching to high-strength encryption, shortening the key update frequency).
[0081] Step S223: After the environmental data returns to normal, control the security level of the temporary session key to automatically degrade to the initial state step by step.
[0082] Taking the data transmission of the distribution IoT terminal of the urban smart grid as an example:
[0083] Data classification triggers key switching: The IoT terminal is built with a risk assessment module that continuously analyzes the current data fluctuation - normal load data (low risk) maintains AES-128-CTR encryption (key cycle 1 hour); when a 30% sudden increase in current (high-risk event) is detected and lasts for 5 seconds, immediately trigger the key upgrade condition.
[0084] Multi-level key pool dynamic call: After a high-risk event is triggered, the terminal calls the AES-256-GCM high-strength encryption algorithm from the pre-stored key pool and generates a temporary session key with a validity period of only 10 minutes. At the same time, the HMAC-SHA384 verification code is activated to ensure the integrity of the alarm data. The key pool is updated regularly by the master station to prevent the risk of local key leakage due to long-term storage.
[0085] Regional terminal collaborative verification: For three adjacent Internet of Things terminals (such as A / B / C nodes) in the same power supply area, the master station requires synchronous submission of the encrypted current data hash values. If terminal A issues an alarm, the master station compares the data hash values of terminals B / C. After confirming a regional anomaly, it decrypts the complete data of terminal A and performs power-off protection. This mechanism avoids misoperations caused by malicious tampering of single-point data and reduces the computing power pressure on high-load terminals.
[0086] In one embodiment, as Figure 5 shown, for an identity data encryption method of an Internet of Things terminal, in step S3, after the terminal encrypts the data with the temporary session key and transmits the encrypted data to the server, it specifically includes:
[0087] Step S31, after the terminal encrypts the data with the temporary session key, generate an HMAC or digital signature and attach it to the encrypted data; the HMAC is generated with the same temporary session key; the digital signature is generated with the private key of the server terminal;
[0088] Step S32, transmit the encrypted data + HMAC or digital signature to the server.
[0089] Taking the data transmission of the distribution Internet of Things terminal in the urban smart grid as an example:
[0090] Data integrity and source authentication: After the terminal encrypts the current data with the temporary session key (such as AES-256), it needs to attach a verification label. If HMAC is selected, a hash verification code (such as HMAC-SHA256) is generated based on the same temporary session key to quickly verify whether the data has been tampered with. If identity authentication is required, switch to digital signature, that is, sign the hash value of the encrypted data with the private key of the terminal (such as ECDSA) to ensure that the data source is non-repudiable. Both are bound to the encrypted data to form a double protection of "encryption + anti-counterfeiting".
[0091] Secure Transmission and Verification: The terminal transmits the combination of "encrypted data + HMAC or digital signature" to the server. After receiving it, if it is HMAC, the server recalculates and compares the verification code with the temporary session key; if it is a digital signature, the server decrypts the signature with the public key pre-stored in the terminal and verifies the consistency of the hash value. In high-risk scenarios such as power grid alarms, this mechanism prevents data tampering at the transport layer (such as malicious interception and modification of current waveforms) and avoids forging the terminal identity to send false power-off instructions, taking into account both efficiency and credibility.
[0092] In one embodiment, as Figure 6 shown, an identity data encryption system for an Internet of Things (IoT) terminal includes:
[0093] A public-private key pair generation module 1, which is used to generate a public-private key pair using an asymmetric encryption algorithm (such as RSA, ECC). The private key is stored in the IoT terminal (specifically, it can be in the HSM, i.e., the hardware security module), and the public key is uploaded to the server for registration;
[0094] A temporary session key upgrade and downgrade module 2, which is used to match different-strength temporary session keys based on the importance of hierarchical environmental data (such as high / low risk) after establishing a TLS / DTLS connection based on public-private key pair authentication, and to dynamically upgrade and downgrade the temporary session key by monitoring the resources of the IoT terminal in real time;
[0095] A data encryption and transmission module 3, which is used to encrypt the data with the temporary session key at the terminal and then transmit the encrypted data to the server.
[0096] When the resources of the IoT terminal are scarce but it is still necessary to maintain a high-strength key, the built-in encryption engine of the terminal (such as HSM or AES-NI instruction set) can be used to efficiently execute high-strength algorithms (such as AES-256) to reduce the CPU load; or the forward secrecy mechanism (such as ECDHE) can be used to reduce the key negotiation overhead, or the core data can be segmented and encrypted, and only the non-keyword fields are verified without encryption; or the TLS session can be reused, edge pre-computation can be enabled, or task priority scheduling can be performed to ensure that the encryption task is executed first. The above methods can be used in combination or alone, and there is no limitation on them.
[0097] In one embodiment, as Figure 7 shown, for an identity data encryption system of an IoT terminal, the public-private key pair generation module 1 includes:
[0098] A public-private key pair acquisition unit 11, which is used to call the encryption interface of the HSM (such as the PKCS#11 standard) in the IoT terminal and select the RSA-2048 or ECC-secp256r1 algorithm to generate a public-private key pair;
[0099] A private key writing unit 12, which is used to directly write the private key into the anti-export security area of the HSM for storage;
[0100] The public key upload unit 13 is used to encode the public key in PEM / DER format, and upload it to the server via HTTPS carrying the unique identifier (such as the serial number) of the device (the Internet of Things terminal is usually built into the device hardware in the form of a chip or other form). After the server verifies the format, it is stored in the database and bound to the device identity, forming a device identity certificate system.
[0101] In the public and private key pair acquisition unit 11, the HSM session is initialized through the PKCS#11 library (such as OpenSC), the C_GenerateKeyPair function is called, the mechanism (CKM_RSA_PKCS_KEY_PAIR_GEN or CKM_EC_KEY_PAIR_GEN) and the template (such as RSA-2048 modulus length, secp256r1 curve OID) are specified. After generating the key pair, the private key is marked as CKA_PRIVATE and stored in the HSM security area, and the public key is exported for encryption or signature verification, protecting the key security through hardware throughout the process.
[0102] In one embodiment, as Figure 8 shown, an identity data encryption system for an Internet of Things terminal, the temporary session key upgrade and downgrade module 2 includes:
[0103] The identity authentication unit 21 is used to control the Internet of Things terminal and the server to perform identity authentication through the public and private key pairs, and establish a TLS / DTLS connection;
[0104] The environmental data key matching unit 22 is used to judge the importance of the environmental data collected by different sensors after establishing a TLS / DTLS connection, and select temporary session keys of different strengths;
[0105] The key dynamic adjustment unit 23 is used to detect the resources of the Internet of Things terminal. When the resources are limited, the temporary session key is downgraded, and when the resources are sufficient, the temporary session key is upgraded. The resources of the Internet of Things terminal include MCU computing power and communication bandwidth.
[0106] In the identity authentication unit 21, the terminal and the server preset the root certificate, exchange certificates during two-way authentication, the terminal calls the HSM private key to sign the handshake random number, and the server verifies the signature with the terminal public key; conversely, the server certificate is verified by the terminal. Generate a temporary session key based on the ECDHE algorithm, negotiate the encryption suite (such as TLS_ECDHE_ECDSA_WITH_AES_128_GCM), and establish an encrypted channel after completing the TLS / DTLS handshake to ensure the credibility of the identity and the confidentiality of the data.
[0107] In one embodiment, as Figure 9 shown, an identity data encryption system for an Internet of Things terminal, the environmental data key matching unit 22 includes:
[0108] The environmental data normal subunit 221 is used to receive environmental data (such as temperature, humidity, movement, etc.) obtained by various sensors after establishing a TLS / DTLS connection. When the environmental data is normal, the temporary session key adopts the initial encryption policy (such as ordinary algorithms, long key periods).
[0109] The environmental data abnormal subunit 222 is used to immediately and dynamically enhance the security level of the temporary session key (such as switching to high-strength encryption, shortening the key update frequency) once a certain environmental data exceeds the preset threshold (such as a sudden increase in temperature, a sudden change in humidity, etc.) and is confirmed abnormal through cross-verification of multiple environmental data.
[0110] The environmental data recovery subunit 223 is used to control the security level of the temporary session key to automatically and gradually degrade to the initial state after the environmental data returns to normal.
[0111] In the environmental data normal subunit 221, it should be noted that there are significant differences in the importance of environmental data (such as key device status monitoring and ordinary temperature and humidity collection). The initial encryption policy strength of some data is low, and the initial encryption policy strength of some data is high.
[0112] The environmental data abnormal subunit 222 monitors the sensor data stream (such as temperature, humidity, etc.) in real time. When a certain index exceeds the threshold, it triggers a multi-source cross-verification mechanism (such as when the temperature is abnormal, linking the humidity and movement sensors to verify the logical relevance). After confirming the abnormality, it calls the key management interface, immediately terminates the current session key, forcibly upgrades the encryption algorithm based on HKDF (a key derivation function based on HMAC) (such as AES-128 → AES-256-GCM), shortens the key period (such as 30 minutes → 5 minutes), and synchronously updates the key exchange algorithm (such as ECDHE-RSA → ECDHE-ECDSA) to enhance forward security, and at the same time triggers an alarm log.
[0113] After the environmental data recovery subunit 223 has been continuously stable within the threshold for a certain period (such as 3 monitoring cycles), it starts a progressive degradation strategy: in the first stage, the key period is extended to 15 minutes and the stability is verified. In the second stage, it switches to the initial algorithm (reserving the temporary high-strength key for backup). Finally, it restores the original configuration. The degradation process dynamically evaluates the data fluctuation risk through a sliding window mechanism. If an abnormality occurs midway, it rolls back to the high-security mode to ensure a smooth transition of the strategy and no single-point failure risk.
[0114] In one embodiment, as Figure 10 shown, an identity data encryption system for an Internet of Things terminal, the data encryption transmission module 3 includes:
[0115] A data encryption unit 31, which is used to generate an HMAC or a digital signature after the data is encrypted by the terminal with a temporary session key and append it to the encrypted data; the HMAC is generated with the same temporary session key; the digital signature is generated with the private key of the server terminal.
[0116] A data transmission unit 32, which is used to transmit the encrypted data + HMAC or digital signature to the server.
[0117] It can perform dynamic algorithm selection, automatically switch the HMAC / signature type (such as replacing ECDSA with RSA-PSS) and adapt the key strength according to data sensitivity or network status, enhancing the scenario adaptability.
[0118] It can perform anti-replay attack extension, embed a timestamp + random number in the HMAC / signature data, and the server side verifies the timeliness and uniqueness to intercept duplicate or expired data packets.
[0119] The above two extended contents can be used alone or in combination.
[0120] It should be understood that although the steps in the flowcharts of the embodiments of the present invention are shown in sequence according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0121] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0122] The above-described embodiments only express several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.
[0123] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
[0124] In addition, it should be understood that although this specification is described in accordance with the embodiments, not every embodiment only contains an independent technical solution. This narrative manner of the specification is only for clarity. Those skilled in the art should regard the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A method for encrypting identity data of an Internet of Things terminal, characterized in that: The identity data encryption method of the Internet of Things terminal includes the following steps: Use an asymmetric encryption algorithm to create a public-private key pair, with the private key stored in the IoT terminal and the public key uploaded to the server for registration; After establishing a TLS / DTLS connection based on public-private key pair authentication, temporary session keys of different strengths are matched by grading the importance of environmental data, and IoT terminal resources are monitored in real time to dynamically upgrade or downgrade temporary session keys. After the terminal encrypts the data using the temporary session key, the encrypted data is transmitted to the server.
2. The method for encrypting identity data of an Internet of Things terminal according to claim 1, characterized in that: The step of using an asymmetric encryption algorithm to generate a public-private key pair, storing the private key in the IoT terminal, and uploading the public key to the server registration step specifically includes: Call the HSM encryption interface in the IoT terminal and select the RSA-2048 or ECC-secp256r1 algorithm to generate a public and private key pair; Write the private key directly into the HSM anti-export security zone for storage; The public key is encoded into PEM / DER format, uploaded to the server via HTTPS with the device's unique identifier, and after the server verifies the format, it is stored in the database and bound to the device identity to form a device identity certificate system.
3. The identity data encryption method of the Internet of Things terminal according to claim 1, characterized in that: After the TLS / DTLS connection is established based on the public-private key pair authentication, temporary session keys of different strengths are matched by grading the importance of environmental data, and the IoT terminal resources are monitored in real time. The steps of dynamically upgrading and downgrading the temporary session keys specifically include: Control IoT terminals and servers to authenticate through public and private key pairs and establish TLS / DTLS connections; After establishing a TLS / DTLS connection, determine the importance of environmental data collected by different sensors and select temporary session keys of different strengths; Detect the resources of the IoT terminal. When resources are limited, downgrade the temporary session key. When resources are sufficient, upgrade the temporary session key. The IoT terminal resources include MCU computing power and communication bandwidth.
4. The identity data encryption method of the Internet of Things terminal according to claim 3 is characterized in that: After establishing the TLS / DTLS connection, the importance of the environmental data collected by different sensors is judged, and the step of selecting temporary session keys of different strengths specifically includes: After establishing a TLS / DTLS connection, the environmental data obtained by various sensors is received. When the environmental data is normal, the temporary session key adopts the initial encryption strategy; Once a piece of environmental data exceeds the preset threshold and is confirmed abnormal through cross-verification of multiple environmental data, the security level of the temporary session key is dynamically increased immediately; After the environmental data returns to normal, the security level of the control temporary session key is automatically and gradually downgraded to the initial state.
5. The identity data encryption method of the Internet of Things terminal according to claim 1, characterized in that: After the terminal encrypts the data using the temporary session key, the step of transmitting the encrypted data to the server specifically includes: After the terminal encrypts the data using the temporary session key, it generates an HMAC or digital signature and attaches it to the encrypted data; the HMAC is generated using the same temporary session key; the digital signature is generated using the server terminal private key; Transmit the encrypted data + HMAC or digital signature to the server.
6. An identity data encryption system for an Internet of Things terminal, characterized in that: The identity data encryption system of the Internet of Things terminal includes: The public-private key pair generation module is used to generate a public-private key pair using an asymmetric encryption algorithm. The private key is stored in the IoT terminal, and the public key is uploaded to the server for registration. The temporary session key upgrade and downgrade module is used to dynamically upgrade and downgrade the temporary session key by matching temporary session keys of different strengths according to the importance of graded environmental data after establishing a TLS / DTLS connection based on public-private key pair authentication, and monitor IoT terminal resources in real time; The data encryption transmission module is used to transmit the encrypted data to the server after the terminal encrypts the data using the temporary session key.
7. The identity data encryption system of the Internet of Things terminal according to claim 6, characterized in that: The public and private key pair generation module includes: The public and private key pair obtaining unit is used to call the encryption interface of the HSM in the IoT terminal and select the RSA-2048 or ECC-secp256r1 algorithm to generate the public and private key pair; The private key writing unit is used to write the private key directly into the HSM anti-export security zone storage; The public key upload unit is used to encode the public key into PEM / DER format, upload it to the server via HTTPS with the device's unique identifier, store it in the database after the server verifies the format and binds it to the device identity, forming a device identity certificate system.
8. The identity data encryption system of the Internet of Things terminal according to claim 6, characterized in that: The temporary session key upgrade and downgrade module includes: The identity authentication unit is used to control the IoT terminal and the server to authenticate through the public and private key pairs and establish a TLS / DTLS connection; The environmental data key matching unit is used to determine the importance of environmental data collected by different sensors and select temporary session keys of different strengths after establishing a TLS / DTLS connection; The key dynamic adjustment unit is used to detect the resources of the IoT terminal. When the resources are limited, the temporary session key is downgraded. When the resources are sufficient, the temporary session key is upgraded. The IoT terminal resources include MCU computing power and communication bandwidth.
9. The identity data encryption system of the Internet of Things terminal according to claim 8, characterized in that: The environment data key matching unit includes: The normal environment data subunit is used to receive environment data obtained by various sensors after establishing a TLS / DTLS connection. When the environment data is normal, the temporary session key adopts the initial encryption strategy; An environmental data anomaly subunit is used to dynamically improve the security level of the temporary session key immediately once a certain environmental data exceeds a preset threshold and is confirmed to be abnormal through cross-validation of multiple environmental data; The environment data recovery subunit is used to control the security level of the temporary session key to automatically and gradually downgrade to the initial state after the environment data returns to normal.
10. The identity data encryption system of the Internet of Things terminal according to claim 6, characterized in that: The data encryption transmission module includes: A data encryption unit is used to generate an HMAC or digital signature to attach to the encrypted data after the terminal encrypts the data using a temporary session key; the HMAC is generated using the same temporary session key; the digital signature is generated using the server terminal private key; Data transmission unit, used to transmit encrypted data + HMAC or digital signature to the server.
Citation Information
Patent Citations
Mobile terminal equipment credibility authentication method and system based on Internet of Things
CN118631570A
5G network information security authority authentication method and system based on asymmetric algorithm
CN118714568A
Hybrid encryption method based on industrial bus
CN119363455A
Cited By
BMS Bluetooth security communication method and system based on SM2 key negotiation
CN121510006A
A BMS Bluetooth secure communication method and system based on SM2 key agreement
CN121510006B