Data security transmission method and system for edge intelligent control platform based on Internet of Things

By filtering out the encryption update group with the largest average encryption force and the most edge servers in the Internet of Things system, dynamically update the encryption method, the computing burden and data security problems of cloud servers are solved, and the real-time and security of task execution are improved.

CN120263414BActive Publication Date: 2025-08-26SHAANXI MEDICAL STANDARD ZHILIAN DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510734117.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-08-26
Estimated Expiration
2045-06-04

AI Technical Summary

Technical Problem

In the Internet of Things system, cloud servers need to decrypt different encryption methods for different edge devices, resulting in an increase in computing burden, affecting real-time, and encryption methods are difficult to manage, posing a security risk for data transmission.

Method used

By filtering out the encryption update group with the maximum average encryption force and the most edge servers, dynamically update the encryption method to ensure the real-time and security of cloud servers.

Benefits of technology

While ensuring data security, it reduces the real-time impact of the encryption and decryption process on task execution, avoids the risks of frequent decryption operations and data leakage, and improves the processing efficiency of cloud servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263414B_ABST
    Figure CN120263414B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data transmission technology, and specifically to a data security transmission method and system for an edge intelligent control platform based on the Internet of Things, including: an edge device publishes a message to a message topic in the same edge server, and a cloud server subscribes to messages of the message topic from the edge server; an encryption update group is obtained, and the edge servers where the encryption update groups of different tasks are located have minimal differences. All message topics belonging to the encryption update group and on the same edge server are recorded as the first message group, and the edge server where the first message group is located is recorded as the encryption update device. According to the average encryption strength of the first message group and the real-time performance of each task, the encryption method for re-encryption of the encryption update device is selected. The present invention ensures data security through the dynamic update of the encryption method while avoiding the impact of the encryption and decryption process on the real-time performance of task execution as much as possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission technology, and in particular to a method and system for secure data transmission on an edge intelligent control platform based on the Internet of Things. Background Art

[0002] In IoT applications (such as smart wards), there are a plethora of edge devices (e.g., edge devices protecting ambient temperature sensors, vital sign monitoring devices, and handheld terminals). Each edge device may have different functions, collected data, factory settings, and computing power, leading to different data encryption methods for different edge devices. When cloud servers and edge devices communicate directly or indirectly (for example, using the MQTT protocol), the cloud server must use different decryption methods for different data, increasing the computing burden and impacting the cloud server's ability to execute various tasks in real time. Furthermore, the varying encryption methods of different edge devices make it difficult to manage encryption methods (e.g., difficult to update encryption methods), leading to security risks in data transmission. Summary of the Invention

[0003] To solve the above problems, the present invention provides a data security transmission method and system for an edge intelligent control platform based on the Internet of Things.

[0004] The data security transmission method and system of the edge intelligent control platform based on the Internet of Things of the present invention adopts the following technical solutions:

[0005] One embodiment of the present invention provides a method for securely transmitting data on an edge intelligent control platform based on the Internet of Things, the method comprising the following steps:

[0006] Several edge devices publish messages to several message topics in the same edge server, and the cloud server transmits data by subscribing to message topics from several edge servers;

[0007] Obtaining the real-time performance of each task processed by the cloud server, where the real-time performance is negatively correlated with the encryption strength of the subscribed message topic;

[0008] Filter several message topics from all message topics subscribed by each task and record them as the message group of each task; record the message group with the highest average encryption strength and the most edge servers as the encryption update group of each task, and at the same time, the edge servers where the encryption update groups of different tasks are located have the smallest difference;

[0009] All message topics belonging to the encryption update group and on the same edge server are denoted as the first message group of each task. The edge server where the first message group is located is denoted as the encryption update device. Based on the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold th, the encryption method for re-encrypting all messages in the encryption update device and the decryption method for decrypting messages on the cloud server are selected from the encryption methods used when the edge device publishes messages to the encryption update device.

[0010] th is positively correlated with the real-time performance of each task. The encryption strength of the message topic is the total time it takes for the messages under the message topic to be encrypted and decrypted in the edge server and the cloud server.

[0011] Preferably, the message group with the largest average encryption strength and the largest number of edge servers is recorded as the encryption update group of each task, and the edge servers where the encryption update groups of different tasks are located have the smallest difference, including the following specific steps:

[0012] For each message group, the number of edge servers corresponding to the message topics is N. For any one of the corresponding edge servers, the average encryption strength of all message topics in the edge server and belonging to each message group is obtained, which is M. The product of N and M is recorded as the first evaluation indicator for each message group.

[0013] A message group corresponding to each task in all tasks constitutes a message group set, and the differences between all edge servers corresponding to all message groups in the message group set are obtained; the difference between the mean of the first evaluation index of all message groups in the message group set and the difference between the edge servers is recorded as the second evaluation index of the message group set;

[0014] Among all message group sets of all tasks, each message group in the message group set with the largest second evaluation index is used as the encryption update group of each task.

[0015] Preferably, the obtaining of the differences between all edge servers corresponding to all message groups in the message group set includes the following specific steps:

[0016] For each message group in each message group set, the edge servers corresponding to all message topics in each message group are recorded as the edge server set of each message group; for all edge server sets corresponding to all message groups in each message group set, any edge server in all edge server sets is recorded as edge server A;

[0017] Obtain the number of times edge server A appears in all edge server sets, and the ratio of the number of times to the number of edge server sets is recorded as the recurrence rate of edge server A;

[0018] In edge server A, all topic messages belonging to the same message group are recorded as the second message group; edge server A corresponds to several second message groups, each from a different task;

[0019] In edge server A, the target encryption method is obtained according to the relationship between the encryption strength of all message topics in each second message group and the threshold th; the selection priority of each target encryption method in edge server A is obtained, and the average of the selection priorities of all target encryption methods in edge server A is recorded as the attention coefficient of edge server A; in the set of all edge servers in each message group set, the number of edge servers is recorded as N1, and the attention coefficient of the i-th edge server is recorded as , the recurrence rate of the i-th edge server is recorded as ,Will Denote it as indicator Q1; denote exp(-Q1) as the difference between all edge servers corresponding to all message groups in the message group set, and exp() represents an exponential function with a natural constant as the base.

[0020] Preferably, the encryption method for re-encrypting all messages in the encryption update device and the decryption method for decrypting messages in the cloud server are selected from the encryption methods for encrypting messages when the edge device publishes messages to the encryption update device based on the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold value th, and the specific steps include the following:

[0021] Each encryption update device corresponds to a number of first message groups, each from a different task;

[0022] In the encryption update device, a target encryption method is obtained based on the relationship between the encryption strength of all message topics in each first message group and the threshold value th; and a selection priority of each target encryption method in the encryption update device is obtained;

[0023] The target encryption method with the highest priority is selected in the encryption update device as the encryption method when re-encrypting all messages in the encryption update device, and the decryption method corresponding to the target encryption method with the highest priority is selected as the decryption method when decrypting on the cloud server.

[0024] Preferably, the specific steps of obtaining the target encryption method are as follows:

[0025] For any one of all edge servers including edge server A and the encryption update device, and any one of all message groups including the second message group and the first message group;

[0026] The encryption strength of messages under all message topics in the message group is normalized to obtain the normalized encryption strength of each message topic. Among all message topics with normalized encryption strength less than or equal to the threshold th, the message topic with the largest normalized encryption strength is recorded as the target message topic, and the encryption method used by the edge device when publishing messages to the target message topic is obtained as the target encryption method.

[0027] Preferably, the specific steps for obtaining the selection priority of each target encryption method are as follows:

[0028] Any edge server among the encryption update device and edge server A is recorded as a reference edge server;

[0029] Obtain the cumulative sum of the real-time performance of all tasks corresponding to each target encryption method in the reference edge server. Obtain the decryption duration of the message encrypted using each target encryption method when decrypted in the reference edge server. Denote the sum of the cumulative sum and the decryption duration as x. Denote exp(-x) as the selection priority of each target encryption method. Exp() represents an exponential function with a natural constant as the base.

[0030] Preferably, the specific calculation formula of th is as follows:

[0031]

[0032] Where d represents the real-time performance of each task, and max and min represent the maximum and minimum values ​​of all real-time performance of the same task in the recent period, respectively.

[0033] Preferably, the real-time performance of each task processed by the cloud server is obtained, and the real-time performance is negatively correlated with the encryption strength of the subscribed message topic, and the specific steps include the following:

[0034] The total duration of encryption and decryption of messages under each message topic subscribed to from the start to the end of each task is recorded as the encryption strength of each message topic; the cumulative sum of the encryption strengths of all message topics subscribed to during this process is recorded as y, and exp(-y) is recorded as the real-time performance of each task; exp() represents an exponential function with a natural constant as the base.

[0035] Preferably, before re-encrypting all messages in the encryption update device, all messages under the message subject are decrypted and the decrypted messages are re-encrypted.

[0036] Another embodiment of the present invention provides an edge intelligent control platform data security transmission system based on the Internet of Things, which includes: a number of edge servers and cloud servers, and a computer program running on each edge server and cloud server, and the computer program executes all steps of the above-mentioned edge intelligent control platform data security transmission method based on the Internet of Things when running.

[0037] The beneficial effects of the technical solution of the present invention are:

[0038] When publishing messages from an edge device to an encryption update device, the present invention encrypts each message. From the encryption methods corresponding to all published messages, the encryption method used for re-encrypting all messages within the encryption update device and the decryption method used for decryption by the cloud server are selected. This process re-encrypts all messages within the edge server and enables real-time updates of the encryption method. This eliminates the need to transmit the encryption method between the edge server and the cloud server during the update, ensuring transmission security.

[0039] Furthermore, the encryption update device achieved by the present invention not only maximizes average encryption strength and the largest number of edge servers, but also minimizes differences in the edge servers used by encryption update groups for different tasks. This allows the encryption methods of edge servers (i.e., encryption update devices) that affect the real-time performance of task execution to be updated, thereby preventing excessive encryption and decryption times that affect real-time performance. Furthermore, when updating encryption methods, as many encryption update devices as possible can be updated, avoiding the risk of leaking too much data at once. Furthermore, while ensuring the maximum number of encryption update devices is updated, frequent decryption operations within a large number of encryption update devices can be avoided, further ensuring the real-time performance of cloud server task processing.

[0040] Furthermore, in the present invention, the encryption method for re-encryption is obtained by calculating the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold value th. This allows the re-encryption encryption method to be obtained by taking into account not only data transmission security but also the impact of the message on the real-time performance of each task during the encryption and decryption process.

[0041] In summary, the present invention ensures data security through dynamic updating of encryption methods while avoiding the impact of encryption and decryption processes on the real-time performance of task execution as much as possible. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0043] Figure 1 This is a diagram showing the framework of a data security transmission system for an edge intelligent control platform based on the Internet of Things, provided by one embodiment of the present invention;

[0044] Figure 2 A flowchart of the steps of a method for securely transmitting data on an edge intelligent control platform based on the Internet of Things provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0045] In order to further illustrate the technical means and effects adopted by the present invention to achieve the predetermined purpose of the invention, the following, in combination with the accompanying drawings and preferred embodiments, describes in detail the specific implementation methods, structures, features and effects of the edge intelligent control platform data security transmission method and system based on the Internet of Things proposed by the present invention. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.

[0046] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0047] The following describes in detail the specific scheme of the data security transmission method and system of the edge intelligent control platform based on the Internet of Things provided by the present invention with reference to the accompanying drawings.

[0048] Example 1:

[0049] like Figure 1 As shown, an embodiment of the present invention provides an edge intelligent control platform data security transmission system based on the Internet of Things, which includes several edge devices, several edge servers, and an edge intelligent control platform.

[0050] Different edge devices are used to collect different data. For example, when the system is used in a smart ward, ambient temperature sensors, surveillance cameras, electronic blood pressure monitors, blood glucose meters, oximeters and other vital signs monitoring devices, handheld terminals such as tablets, case query devices, triage equipment, etc. can all be used as edge devices to collect temperature, images, blood pressure, blood glucose, blood oxygen and other data.

[0051] The edge intelligent control platform includes a cloud server, which is used to obtain data collected by all edge devices and use this data to perform different tasks, such as emergency warnings, nursing plan generation, energy consumption management, graphic report generation and update, message push, etc.

[0052] Furthermore, due to the large number of edge devices, the data collected and the data used are different, and the edge devices are distributed in different locations. It is not possible for all edge devices to communicate directly with the cloud server, otherwise it will make the edge devices difficult to manage. In this embodiment, the edge server is used to integrate and transfer the data collected by different edge devices, and then transmit it to the cloud server.

[0053] Specifically:

[0054] Multiple edge devices are directly connected to an edge server. For example, each ward, medical room, nurse station, etc. is equipped with an edge server and connected to the edge devices therein. In this embodiment, all edge devices are connected to multiple edge servers, and all edge servers are directly connected to the cloud server; so that the edge devices are indirectly connected (or indirectly communicate) with the cloud server through the edge server.

[0055] In this embodiment, the MQTT (Message Queuing Telemetry Transport) communication protocol is used to enable indirect communication between edge devices and cloud servers. MQTT is a lightweight IoT communication protocol based on the publish / subscribe model. Its core principle is to achieve efficient and reliable data transmission by decoupling message producers (publishers) and consumers (subscribers). In this embodiment, each edge device is a publisher, and the cloud server is a subscriber.

[0056] Each edge server has several message topics. The communication process between each edge device and the edge server is essentially: each edge device publishes a message (or transmits data) to the message topic in the edge server.

[0057] For example, a message topic in an edge server is: ward201 / ambient_temp; which represents the ambient temperature of Ward 201; then the ambient temperature sensor in Ward 201 publishes messages to this message topic in real time, that is, the data collected by the ambient temperature sensor is transmitted to the edge server in real time and stored under this message topic.

[0058] When performing different tasks, the cloud server will subscribe to messages from the edge server. For example, when the cloud server issues an alert for ambient temperature, it will subscribe to the message topic ward* / ambient_temp from all edge servers (the * in ward* represents a wildcard). After the message topic is subscribed, each edge server transmits the message under the message topic (that is, the data collected by the ambient temperature sensor in the ward) to the cloud server.

[0059] Since MQTT is a well-known technology, it will not be described in further detail in this embodiment.

[0060] In addition, the system also includes a computer program for secure data transmission, which runs on edge devices, edge servers, and cloud servers and is used to encrypt data to be transmitted and decrypt received data.

[0061] For example, before an edge device publishes a message to a message topic on an edge server, it first encrypts the message (or data). Another example is when a cloud server subscribes to a message from an edge server, it needs to decrypt the subscribed message (or data).

[0062] The system also includes an executable computer program that runs on the edge server and the cloud server without blocking the main process of the edge server and the cloud server. When the program runs, it executes the data security transmission method of the edge intelligent control platform based on the Internet of Things.

[0063] This approach takes into account that different edge devices have varying computing power and encryption capabilities (methods). Some edge devices may even be unable to encrypt data, making the encryption process difficult to manage (for example, encryption methods can be difficult to update in a timely manner). This, in turn, impacts the secure transmission of data or messages. Furthermore, the encryption and decryption of data collected by different edge devices can affect the real-time performance of tasks executed by cloud servers. Consequently, faced with data collected by numerous edge devices, cloud servers cannot optimally perform secure, real-time task processing.

[0064] The method for secure data transmission of the edge intelligent control platform based on the Internet of Things ensures the security and real-time performance of the cloud server when performing tasks as much as possible by updating the encryption method for different edge servers and cloud servers in real time.

[0065] Example 2:

[0066] like Figure 2 As shown, the method for secure data transmission on an edge intelligent control platform based on the Internet of Things provided in this embodiment includes the following steps:

[0067] Step S201: The edge device publishes a message to the message topic of the edge server, and the cloud server transmits data by subscribing to the message topics from several edge servers.

[0068] The edge device in this embodiment transmits data (or publishes messages) to the edge server through Wi-Fi6 / 6E communication technology. In other embodiments, communication technologies such as Bluetooth / Zigbee, CAN bus or 5G can be used. This embodiment is not limited to this. The edge server transmits data to the cloud server through 5G communication technology (that is, the cloud server subscribes to messages under the message topic from the edge server through 5G communication technology).

[0069] To ensure data security during transmission, data must be encrypted before transmission. Common encryption algorithms include lightweight symmetric algorithms such as XTEA / Blowfish, AES, asymmetric encryption algorithms such as RSA / ECC, and encryption algorithms derived by iterating or hybridizing the above encryption algorithms. These encryption algorithms are well known and will not be described in detail in this embodiment.

[0070] In this embodiment, numerous edge devices are used to collect different data. Since the computing power of the edge devices, the importance of the collected data, and even the manufacturers and factory configurations may be different, the encryption algorithms used may also be different. Some edge devices may not even require encryption. It is difficult to unify all encryption algorithms during the actual procurement, configuration, and installation of edge devices. This embodiment does not limit the encryption algorithm used by edge devices when transmitting data.

[0071] In this embodiment, the data (or data packet, message content) to be transmitted by the edge device includes at least the following fields: the edge device ID, authentication information (username / password), and the message body (e.g., the temperature sequence collected by the temperature sensor). It should be noted that this data must be encrypted before transmission; in some embodiments, some fields within the data may be encrypted (e.g., fields other than the edge device ID and username).

[0072] After receiving the encrypted data transmitted by the edge device, the edge server stores the data under the corresponding message subject; for example, according to the edge device ID or user name in the data, the message subject of the data is searched in the database, and then the data is stored under the message subject.

[0073] When the cloud server subscribes to the message topic from the edge server, the edge server transmits the data to the cloud server.

[0074] In this embodiment, the process of transmitting data from the edge server to the cloud server takes into account the following considerations: if the edge server directly transmits encrypted data to the cloud server, then faced with numerous edge devices, the cloud server would need to manage numerous encryption methods and separately decrypt encrypted data generated by different encryption algorithms, placing a computational burden on the cloud server. Therefore, in this embodiment, before transmitting data to the cloud server, each edge server decrypts the data under all message topics on it, then re-encrypts all decrypted data using the same encryption algorithm, such as a preset encryption algorithm (e.g., RSA algorithm), before transmitting the data to the cloud server, where it is decrypted using a decryption algorithm (e.g., RSA algorithm).

[0075] During this process, each edge server uses a unified encryption algorithm and key through re-encryption. This ensures that the same edge server uses a single encryption method when transmitting data to the cloud server, and the cloud server also uses a single decryption method when decrypting data transmitted from the same edge server. Furthermore, one advantage of this re-encryption is that for edge devices that don't encrypt the data they collect, re-encryption ensures the secure transmission of this data.

[0076] Step S202: Obtain the real-time performance of the cloud server when processing each task.

[0077] The cloud server in this embodiment uses data collected from a large number of edge devices to process different tasks. When processing each task, it needs to go through at least the following processes in sequence: (1) the edge server decrypts the messages published under different message topics, (2) the edge server re-encrypts the messages corresponding to the message topics, (3) the cloud server subscribes to the required messages (or data) from the edge server, (4) decrypts the data, and (5) uses the decrypted data to execute each task. The data encryption and decryption process not only consumes a certain amount of computing time and computing power, but also affects the real-time performance of the cloud server when processing each task. In particular, when data encryption or decryption is difficult, it may cause the cloud server process to be blocked for a long time when processing each task, making it impossible to complete each task in time, and even affecting the processing of other tasks.

[0078] The cloud server obtains the real-time performance of each task when processing it.

[0079] As an optional example, the acquisition method of each task includes:

[0080] During the program development phase of the cloud server, the computer programs running on the cloud server (excluding the computer programs corresponding to this implementation) are artificially divided into several tasks. For example, computer programs related to emergency warning, nursing plan generation, energy consumption management, graphic report generation and update, and message push are each considered a task.

[0081] As a preferred example, the method for obtaining each task includes:

[0082] During the operation of the cloud server, one or several task queues need to be opened in the computer memory. In the task queue, there are several program fragments waiting to seize computing resources or waiting to be executed. In this embodiment, the program fragments that seize computing resources or are executed in each task queue within the recent period of time (for example, within one second) are recorded as one task.

[0083] In other embodiments, other methods may be used to divide the tasks of the cloud server, which is not specifically limited in this embodiment.

[0084] As an example, the method for obtaining the real-time performance of each task includes:

[0085] For each task, from the start to the end, the total encryption and decryption time for messages in each subscribed message topic is recorded as the encryption strength of each message topic. The cumulative sum of the encryption strengths of all subscribed message topics during this process is recorded as y, and exp(-y) is recorded as the real-time performance of each task. exp() represents an exponential function with a natural constant as its base. When y is greater than or equal to 0, the maximum value of exp(-y) is 1.

[0086] In other examples, the ratio of the above-mentioned cumulative sum to the duration of the process is used as the value of y.

[0087] In some other examples, certain tasks or tasks to be executed in certain time periods are manually specified. When the real-time performance of these tasks obtained using the above examples is greater than the preset threshold T, they are regarded as tasks without real-time performance issues. The real-time performance of these tasks in these examples is defined as a constant 1.0.

[0088] In this embodiment, the longer the total time for encrypting and decrypting a message is, the lower the real-time performance of each task is, and the more difficult it is to complete the task in a timely manner.

[0089] Step S203: Filter out the encrypted update group of each task from all message topics subscribed when processing each task.

[0090] The encryption update group described in this embodiment includes several message topics, and these message topics come from multiple edge servers.

[0091] In order to increase the real-time performance when processing each task and increase the security of data transmission when subscribing to messages, this embodiment needs to update the encryption method of messages under all message topics in the encryption update group (that is, the encryption method for re-encryption described in step S201). On the one hand, the real-time performance when processing each task is guaranteed by updating the encryption method, and on the other hand, data security issues are avoided by dynamically updating the encryption method. The data security issues come from the fact that although the same edge server uses one encryption method to encrypt messages of all message topics therein, thereby ensuring the computing burden of the cloud server, since there is only one fixed encryption method, it is relatively easy to be cracked, thereby reducing data security to a certain extent.

[0092] Furthermore, for any message topic in the encryption update group of each task, the total time it takes to decrypt and encrypt the message of the topic message in the edge server, and the total time it takes to decrypt in the cloud server, is recorded as the encryption strength of the message topic (substantially the same as the encryption strength of the message topic described in step S202).

[0093] It should be noted that the decryption time of the cloud server needs to be transmitted to the edge server.

[0094] The average encryption strength corresponding to all message topics in the same edge server and in the encryption update group is recorded as the average encryption strength. The encryption update group obtained in this embodiment has the largest possible average encryption strength, while the message topics contained therein are as many as possible from different edge servers.

[0095] Among them, having the largest possible average encryption strength can ensure that when the encryption method is subsequently updated in the edge server, the encryption method corresponding to the message with a longer encryption and decryption time will be updated and replaced, thereby effectively increasing the real-time performance of the cloud server when processing each task.

[0096] The message topics included in this group originate from different edge servers, and each edge server requires an encryption method update. When the encryption update group includes as many message topics as possible from different edge servers, each task can simultaneously update the encryption methods of more edge servers. This allows the encryption method update process to cover a wider range and avoid leaking too much data at once. On the other hand, as mentioned above, updating and replacing the encryption methods corresponding to messages with longer encryption and decryption times may be accompanied by a decrease in encryption strength. In this case, when the message topics originate from as many different edge servers as possible, the risk of excessive data leakage caused by the decrease in encryption strength can be avoided to a certain extent.

[0097] Each task corresponds to an encryption update group. As described above, for the encryption update groups obtained for all tasks, the message topics contained in each encryption update group come from different edge servers. Furthermore, in this embodiment, the edge servers where the encryption update groups for different tasks reside are minimized. This process primarily takes into account the need to decrypt messages published by edge devices before encrypting them, i.e., the edge servers must perform decryption operations before encryption. Minimizing the differences between the edge servers where the encryption update groups reside can minimize the possibility of excessive edge servers frequently decrypting encrypted data published by edge devices, preventing the edge servers from transmitting the data to the cloud server in a timely manner.

[0098] As an optional example, the specific method for obtaining the encryption update group of each task mentioned above includes:

[0099] From all message topics subscribed to by each task, obtain several message topics, denoted as a message group for each task. The message topics in this message group come from different edge servers, the number of which is denoted as N. For one edge server, obtain all message topics within this edge server that belong to this message group, and obtain the average encryption strength of these message topics, denoted as the average encryption strength M for this message group. The product of N and M is recorded as the first evaluation metric for the message group.

[0100] At this point, for all message groups that can be obtained for each task, each message group has a first evaluation indicator.

[0101] For all tasks (including all tasks that have been completed and tasks that have not yet been completed) within a recent period of time (for example, within the last 2 seconds), a message group corresponding to each task in all tasks constitutes a message group set.

[0102] For each message group in the message group set, each message group corresponds to a number of edge servers (i.e., the message topics in the message group originate from these edge servers), denoted as the edge server set. For all edge server sets corresponding to all message groups in the message group set, obtain the intersection-and-union ratio (IOR) of any two edge server sets. The mean of the IORs across all edge server sets is denoted as Q, and exp(-Q) is denoted as the edge server variance for the message group set. The difference between the mean of the first evaluation metric for all message groups in the message group set and the edge server variance is denoted as the second evaluation metric for the message group set.

[0103] From all message group sets of all tasks, a message group set with the largest second evaluation index is obtained, wherein each message group in the message group set is an encryption update group for each task.

[0104] The encryption update group in this example can ensure the maximum average encryption strength and corresponds to the largest edge server, while the edge servers where the encryption update groups of different tasks are located have the minimum difference.

[0105] In other examples, in order to reduce the amount of calculation, when obtaining the message groups for each task, only the message groups containing message topics less than or equal to 5 are retained.

[0106] Step S204: Use the encryption update group of each task to update the encryption method in the edge device and the decryption method in the cloud server.

[0107] All message topics belonging to the same encryption update group and on the same edge server are recorded as a first message group, and the edge server where the first message group is located is recorded as an encryption update device.

[0108] In this embodiment, the message published to the first message group is re-encrypted, and an encryption method for re-encryption is obtained according to the encryption strength of the first message group and the real-time nature of each task.

[0109] As an example, obtaining an encryption method for re-encryption based on the encryption strength of the first message group and the real-time nature of each task includes:

[0110] First, it should be noted that in the same encryption update device, each task corresponds to one first message group, and multiple tasks correspond to multiple first message groups. That is, each encryption update device corresponds to multiple first message groups, which come from multiple different tasks.

[0111] In the same encryption update device, the first message group corresponding to each task is processed as follows:

[0112] The encryption strength of each message topic in the first message group is obtained, and the encryption strength of the messages under all message topics in the first message group is linearly normalized (the softmax algorithm can also be used for normalization in other embodiments) to obtain the normalized encryption strength of each message topic. Among all message topics with normalized encryption strength less than or equal to th, the message topic with the largest normalized encryption strength is recorded as the target message topic, and the encryption method (and decryption method) when the edge device publishes a message to the target message topic is obtained as the target encryption method (and target decryption method).

[0113] In particular, if the edge device does not perform encryption when publishing a message to the target message topic, the encryption method is recorded as an empty encryption method.

[0114] In this process, th is positively correlated with the real-time performance of each task. When the real-time performance is smaller, th is smaller, and the encryption strength of the target encryption method is relatively smaller, thus avoiding the impact of encryption and decryption time on real-time performance. When the real-time performance is greater, th is larger, and the encryption strength of the target encryption method is relatively greater, thus increasing the security of data transmission.

[0115] Thus, in the same encryption update device, each task corresponds to a target encryption method. When the same encryption update device corresponds to multiple tasks, multiple target encryption methods can be obtained.

[0116] Furthermore, the selection priority of each target encryption method in the same encryption update device is obtained. The higher the selection priority, the more preferentially that encryption method is selected for encryption, further ensuring real-time processing of different tasks. In this embodiment, the target encryption method (and target decryption method) with the highest priority is selected as the final encryption method (and final encryption method) for the same encryption update device.

[0117] At this point, each encryption update device corresponds to a final encryption method. All messages within each encryption update device are re-encrypted using each final encryption method before being transmitted to the cloud server. It should be noted that before re-encrypting, the encryption update device must decrypt the messages published by the edge device and then encrypt them using the final encryption method.

[0118] It should also be noted that this step can be run on both the cloud server and the encryption update device. That is, both the cloud server and the encryption update device can use the method in this step to obtain the final encryption method (and final decryption method) for each encryption update device. Furthermore, the cloud server also stores the decryption method corresponding to the encryption method used when encrypting messages on all edge devices. Therefore, in this embodiment, the encryption update device does not need to transmit the final encryption method to the cloud server, nor does the cloud server need to transmit the final encryption method to the encryption update device, thus avoiding the risk of encryption method leakage due to transmission. When the cloud server subscribes to messages from the encryption update device again, it uses the final decryption method for decryption.

[0119] It's also important to note that before running this step on the encryption update device, the cloud server must transmit data such as the real-time nature of each task and the decryption duration of each message to each edge server. Furthermore, when the cloud server subscribes to messages from the edge server during each task, the edge server records the task corresponding to each message topic.

[0120] At this point, all the above steps have completed an update of the encryption method, that is, the encryption method on the encryption update device and the corresponding decryption method on the cloud server are updated.

[0121] For edge servers other than the encryption update device, re-encryption is performed using a preset encryption algorithm (such as the RSA algorithm).

[0122] Furthermore, in this embodiment, all the above steps are re-executed every one minute, thereby achieving real-time update of the encryption method.

[0123] This concludes the present embodiment.

[0124] In this embodiment, the encryption method used when publishing messages from the edge device to the encryption update device is used to re-encrypt all messages within the encryption update device, as well as the decryption method used by the cloud server. This process re-encrypts all messages within the edge server and updates the encryption method in real time. This eliminates the need to transmit the encryption method between the edge server and the cloud server when updating the encryption method, thus ensuring transmission security.

[0125] Furthermore, the encryption update device obtained in this embodiment not only has the highest average encryption strength and the largest number of edge servers, but also ensures minimal differences in the edge servers used by encryption update groups for different tasks. This allows the encryption methods of edge servers (i.e., encryption update devices) that affect the real-time performance of task execution to be updated, thereby preventing excessive encryption and decryption times that affect real-time performance. Furthermore, when updating the encryption method, as many encryption update devices as possible can be updated, avoiding the risk of leaking too much data at once. Furthermore, while ensuring that as many encryption update devices as possible are updated, frequent decryption operations within a large number of encryption update devices can be avoided, further ensuring the real-time performance of cloud server task processing.

[0126] Furthermore, in the process of obtaining the encryption method during re-encryption, this embodiment obtains the encryption method based on the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold value th. Therefore, when obtaining the encryption method during re-encryption, not only is data transmission security considered, but also the impact of the message on the real-time performance of each task during the encryption and decryption process.

[0127] In summary, this embodiment ensures data security through dynamic updating of the encryption method while avoiding the impact of the encryption and decryption processes on the real-time performance of task execution as much as possible.

[0128] In particular, in some embodiments, when the encryption method obtained during re-encryption is a null encryption method, the AES algorithm can be used as the encryption method during re-encryption.

[0129] Example 3:

[0130] This embodiment provides a preferred method for obtaining an encryption update group for each task, including the following methods:

[0131] For all tasks (including all tasks that have been completed and tasks that have not yet been completed) within a recent period of time (for example, within the last 2 seconds), a message group corresponding to each task in all tasks constitutes a message group set.

[0132] For each message group in each message group set, all message topics in each message group come from multiple edge servers, and the set formed by these edge servers is recorded as the edge server set of each message group.

[0133] All edge server sets corresponding to all message groups in the message group set, and any edge server in all edge server sets, are recorded as edge server A;

[0134] The number of times edge server A appears in all edge server sets is obtained, and the ratio of this number to the number of edge server sets (that is, the number of tasks) is recorded as the recurrence rate of edge server A.

[0135] In edge server A, all topic messages belonging to the same message group are recorded as a second message group.

[0136] In the edge server A, each task corresponds to a second message group, and multiple tasks correspond to multiple second message groups. That is, the edge server A corresponds to multiple second message groups, which come from multiple different tasks.

[0137] In edge server A, the second message group corresponding to each task is processed as follows: the encryption strength of the message under each message topic in the second message group is obtained, and the encryption strength of the messages under all message topics in the second message group is linearly normalized (the softmax algorithm can also be used for normalization in other embodiments) to obtain the normalized encryption strength of each message topic. Among all message topics with normalized encryption strength less than or equal to th, the message topic with the largest normalized encryption strength is recorded as the target message topic, and the encryption method used by the edge device when publishing a message to the target message topic is obtained as the target encryption method.

[0138] In this process, th is positively correlated with the real-time performance of each task.

[0139] At this point, each task in edge server A corresponds to a target encryption method. When edge server A corresponds to multiple tasks, multiple target encryption methods can be obtained.

[0140] The above process is the same as step S204.

[0141] The selection priority of each target encryption method in edge server A.

[0142] The average of the selection priorities of all target encryption methods in edge server A is recorded as the attention coefficient of edge server A.

[0143] In the set of all edge servers for each message group set, the number of edge servers is recorded as N1, and the attention coefficient of the i-th edge server is recorded as , the recurrence rate of the i-th edge server is recorded as ,Will Denote it as the indicator Q1. Denote exp(-Q1) as the edge server difference. Denote the difference between the mean of the first evaluation indicator of all message groups in the message group set and the edge server difference as the second evaluation indicator of the message group set.

[0144] From all message group sets of all tasks, a message group set with the largest second evaluation index is obtained, wherein each message group in the message group set is an encryption update group for each task.

[0145] The above process is similar to step S203 in the second embodiment, except that the process of obtaining the edge server difference is different.

[0146] This embodiment further considers the situation where different target encryption methods are used for different tasks within the same edge server during the acquisition process. The encryption priorities of these target encryption methods are used to accurately and specifically determine the differences in the edge servers in the encryption update groups for different tasks. This further avoids the situation where too many edge servers frequently decrypt encrypted data published by edge devices, preventing them from timely transmitting the data to the cloud server. This also ensures the reliability of step S204, when the target encryption method with the highest priority is selected as the final encryption method for the encryption update device.

[0147] As a preferred example, a method for obtaining the selection priority of each target encryption method includes:

[0148] For the same encryption update device described in the second embodiment and the edge server A described in this embodiment, any one of them is recorded as a reference edge server.

[0149] For multiple target encryption methods obtained in the reference edge server, each target encryption method may correspond to one or more tasks, and the cumulative sum of the real-time performance of all tasks corresponding to each target encryption method is obtained.

[0150] It should also be noted that each target encryption method refers to the encryption method used by the edge device when publishing a message to the reference edge server. The decryption time of the message encrypted by the encryption method is obtained when it is decrypted in the reference edge server. The sum of the above cumulative sum and the decryption time is recorded as x, and exp(-x) is recorded as the selection priority of each target encryption method.

[0151] The higher the priority, the shorter the corresponding real-time performance and decryption time, which is more conducive to the fast and real-time operation of the entire Internet of Things. Therefore, this encryption method is used for encryption first.

[0152] As an example, th is positively correlated with the real-time performance of each task, including the calculation formula:

[0153] Let th=d×f; where f represents the real-time performance of each task, and d represents the prediction parameter. This embodiment is described using d=1 as an example, and in other embodiments, it can be set to other values. This embodiment does not specifically limit this.

[0154] As another example, th is positively correlated with the real-time performance of each task, including the calculation formula:

[0155] Get the maximum and minimum real-time values ​​of the same task in the recent period (for example, the last hour), denoted as max and min respectively, and let This calculation method takes into account the real-time fluctuation of each task within a local time period, avoiding the problem of inaccurate th values ​​due to large differences in the real-time fluctuation of different tasks within a local time period (for example, the problem that th cannot filter out suitable target message topics).

[0156] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A data security transmission method for an edge intelligent control platform based on the Internet of Things, characterized in that: The method comprises the following steps: Several edge devices publish messages to several message topics in the same edge server, and the cloud server transmits data by subscribing to message topics from several edge servers; Obtaining the real-time performance of each task processed by the cloud server, where the real-time performance is negatively correlated with the encryption strength of the subscribed message topic; Filter several message topics from all message topics subscribed by each task and record them as the message group of each task; record the message group with the largest average encryption strength and the largest number of edge servers as the encryption update group of each task, and at the same time, the edge servers where the encryption update groups of different tasks are located have the smallest difference; wherein, for the edge service corresponding to the message topics in each message group, the corresponding number of edge servers is recorded as N, and for any edge server among the corresponding edge servers, obtain the average encryption strength of all message topics in the edge server and belonging to each message group and record it as M; record the product of N and M as the first evaluation index of each message group; a message group corresponding to each task in all tasks constitutes a message group set, and obtain the difference between all edge servers corresponding to all message groups in the message group set; record the difference between the average of the first evaluation index of all message groups in the message group set and the difference between the edge servers as the second evaluation index of the message group set; among all message group sets of all tasks, each message group in the message group set with the largest second evaluation index is respectively used as the encryption update group of each task; All message topics belonging to the encryption update group and on the same edge server are denoted as the first message group of each task. The edge server where the first message group is located is denoted as the encryption update device. Based on the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold th, the encryption method for re-encrypting all messages in the encryption update device and the decryption method for decrypting messages on the cloud server are selected from the encryption methods used when the edge device publishes messages to the encryption update device. th is positively correlated with the real-time performance of each task. The encryption strength of the message topic is the total time it takes for the messages under the message topic to be encrypted and decrypted in the edge server and the cloud server.

2. The method for secure data transmission of an edge intelligent control platform based on the Internet of Things according to claim 1 is characterized in that: The specific steps of obtaining the differences between all edge servers corresponding to all message groups in the message group set are as follows: For each message group in each message group set, the edge servers corresponding to all message topics in each message group are recorded as the edge server set of each message group; for all edge server sets corresponding to all message groups in each message group set, any edge server in all edge server sets is recorded as edge server A; Obtain the number of times edge server A appears in all edge server sets, and the ratio of the number of times to the number of edge server sets is recorded as the recurrence rate of edge server A; In edge server A, all topic messages belonging to the same message group are recorded as a second message group; edge server A corresponds to several second message groups, each from a different task; In edge server A, a target encryption method is obtained according to the relationship between the encryption strength of all message topics of each second message group and the threshold th; Obtain the selection priority of each target encryption method in edge server A, and record the average of the selection priorities of all target encryption methods in edge server A as the attention coefficient of edge server A; in the set of all edge servers in each message group set, the number of edge servers is recorded as N1, and the attention coefficient of the i-th edge server is recorded as , the recurrence rate of the i-th edge server is recorded as ,Will Denote it as indicator Q1; denote exp(-Q1) as the difference between all edge servers corresponding to all message groups in the message group set, and exp() represents an exponential function with a natural constant as the base.

3. The method for secure data transmission of an edge intelligent control platform based on the Internet of Things according to claim 1 is characterized in that: The method of selecting, based on the relationship between the average encryption strength corresponding to the first message groups from different tasks in the encryption update device and the threshold value th, an encryption method for re-encrypting all messages in the encryption update device and a decryption method for decrypting messages in the cloud server from the encryption methods for encrypting messages when the edge device publishes messages to the encryption update device, includes the following specific steps: Each encryption update device corresponds to a number of first message groups, each from a different task; In the encryption update device, a target encryption method is obtained based on the relationship between the encryption strength of all message topics in each first message group and the threshold value th; and a selection priority of each target encryption method in the encryption update device is obtained; The target encryption method with the highest priority is selected in the encryption update device as the encryption method when re-encrypting all messages in the encryption update device, and the decryption method corresponding to the target encryption method with the highest priority is selected as the decryption method when decrypting on the cloud server.

4. The method for secure data transmission on an edge intelligent control platform based on the Internet of Things according to claim 2 or 3, characterized in that: The specific steps of obtaining the target encryption method are as follows: For any one of all edge servers including edge server A and the encryption update device, and any one of all message groups including the second message group and the first message group; The encryption strength of messages under all message topics in the message group is normalized to obtain the normalized encryption strength of each message topic. Among all message topics with normalized encryption strength less than or equal to the threshold th, the message topic with the largest normalized encryption strength is recorded as the target message topic, and the encryption method used by the edge device when publishing messages to the target message topic is obtained as the target encryption method.

5. The method for secure data transmission of an edge intelligent control platform based on the Internet of Things according to claim 2 or 3, characterized in that: The specific steps for obtaining the selection priority of each target encryption method are as follows: Any edge server among the encryption update device and edge server A is recorded as a reference edge server; Obtain the cumulative sum of the real-time performance of all tasks corresponding to each target encryption method in the reference edge server. Obtain the decryption duration of the message encrypted using each target encryption method when decrypted in the reference edge server. Denote the sum of the cumulative sum and the decryption duration as x. Denote exp(-x) as the selection priority of each target encryption method. Exp() represents an exponential function with a natural constant as the base.

6. The method for secure data transmission on an edge intelligent control platform based on the Internet of Things according to any one of claims 1, 2 or 3, characterized in that: The specific calculation formula of th is as follows: Where d represents the real-time performance of each task, and max and min represent the maximum and minimum values ​​of all real-time performance of the same task in the recent period, respectively.

7. The method for secure data transmission of an edge intelligent control platform based on the Internet of Things according to claim 1 is characterized in that: The real-time performance of each task processed by the cloud server is obtained, and the real-time performance is negatively correlated with the encryption strength of the subscribed message topic. The specific steps include the following: The total duration of encryption and decryption of messages under each message topic subscribed to from the start to the end of each task is recorded as the encryption strength of each message topic; the cumulative sum of the encryption strengths of all message topics subscribed to during this process is recorded as y, and exp(-y) is recorded as the real-time performance of each task; exp() represents an exponential function with a natural constant as the base.

8. The method for secure data transmission of an edge intelligent control platform based on the Internet of Things according to claim 3 is characterized in that: Before re-encrypting all messages in the encryption update device, all messages under the message topic are decrypted and the decrypted messages are re-encrypted.

9. An IoT-based edge intelligent control platform data security transmission system, which includes: Several edge servers and cloud servers, and a computer program running on each edge server and cloud server, characterized in that the computer program, when running, executes all steps of the method for secure data transmission of an edge intelligent control platform based on the Internet of Things as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Intelligent household appliance encryption control system and method based on MQTT

    CN109587178A

  • Offshore drilling platform video intelligent identification algorithm self-updating system and method

    CN118409772A