Internet of Things card security access and data transmission encryption method

By adopting multi-line fuse modules and dual encryption algorithms in IoT cards, the security risks and fragile fuse mechanisms of IoT card key write ports are solved, higher security and stability are achieved, and system resilience and user trust are improved.

CN120296805AInactive Publication Date: 2025-07-11QIBEN TECH GRP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510330907.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The key writing port of the IoT card is still retained after writing, which poses serious security risks. Attackers can obtain or tamper with the key through physical contact, resulting in data leakage and unauthorized access, especially to older devices, and the existing circuit breaker mechanism is prone to single-point failure and cascade effects, affecting system stability and reliability.

Method used

The multi-line fuse strategy and fuse module design are adopted, including fuse and fuse circuit, to ensure that the port connection is quickly cut off after the key is written, and the security of the key and the integrity of the transmission process are enhanced through the encryption engine and dual encryption algorithm. Combined with the independent control of the fuse and the fuse mechanism, it prevents overall fuse caused by a single point of failure.

Benefits of technology

Effectively prevent unauthorized access, prevent data tampering and information leakage, improve system reliability and stability, reduce maintenance costs, enhance user trust and enterprise compliance, and improve the overall security and competitiveness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296805A_ABST
    Figure CN120296805A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of Internet of Things, and particularly relates to an Internet of Things card security access and data transmission encryption method, which comprises the following steps that a fusing module is additionally arranged at a data write-in port of a storage chip, the fusing module at least comprises a fuse wire, the fusing module triggers the fuse wire to fuse after receiving a fusing signal, the fusing module is disconnected, and the data write-in port of the storage chip is connected with the fuse wire; a signal sent after key burning is completed is regarded as a fusing signal of the fusing module, the fusing module triggers the fuse to fuse after receiving the fusing signal, the fusing module is disconnected, the main control chip calls the key in the storage chip, and then the key is sent to a manufacturer server through the communication module to be verified. The key is burnt to the storage chip through the burner, the burner burns the key through the burning port, and the burning port comprises a VPP pin, a CLK pin and a DATA pin which are respectively used for inputting a signal required when the key is written, providing a synchronous clock signal and transmitting key data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of the Internet of Things, and particularly relates to a method for secure access and data transmission encryption of Internet of Things cards. Background Art

[0002] With the rapid development of Internet of Things technology, more and more devices are connected to the Internet through Internet of Things cards, which provides great convenience for realizing intelligent life and industrial automation. However, the subsequent security risks are becoming increasingly prominent, and problems such as data leakage, identity theft, and device attacks are emerging in an endless stream. Therefore, traditional secure access methods are difficult to meet the high security requirements in the Internet of Things environment. In response to this challenge, the zero-trust security model has gradually attracted attention, which emphasizes that every access in the network should be strictly authenticated and device-certified. Against this background, a secure access solution for Internet of Things cards has emerged to solve problems such as information protection, data transmission security, and device identity authentication, so as to provide security guarantees for intelligent applications and help realize a more intelligent and secure Internet of Things ecosystem.

[0003] In the prior art, the key writing port of the Internet of Things card remains after writing, which brings serious security risks. An attacker can easily obtain or overwrite the stored key by physically contacting this port. Once the key is maliciously extracted, the attacker can forge an identity and conduct unauthorized access, which may lead to security incidents such as data tampering and information leakage. In addition, such a writing port always exists during the use of the device, increasing the risk of being attacked. Especially for old and outdated devices that are not updated in time, they are more likely to become targets of attacks. Over time, the lack of security protection measures exacerbates potential threats and will also have a serious impact on the enterprise's compliance and brand reputation. Therefore, it is urgent to improve the design to eliminate this security risk to ensure the overall security of the Internet of Things system. Summary of the Invention

[0004] The object of the present invention is to provide a method for secure access and data transmission encryption of Internet of Things cards, which is used for local writing of the key for identity authentication when the Internet of Things card accesses the Internet of Things. This key is written into the storage chip of the Internet of Things card. When the Internet of Things card accesses, this key is sent to the manufacturer's server for verification through the main control chip. The method includes the following steps: a fusing module is added to the data writing port of the storage chip, and the fusing module at least includes a fuse. After the fusing module receives a fusing signal, the fuse is triggered to fuse, disconnecting the fusing module; the signal sent after the key burning is completed is regarded as the fusing signal of the fusing module. After the fusing module receives the fusing signal, the fuse is triggered to fuse, and by disconnecting the fusing module, the data writing port of the storage chip is damaged; the main control chip calls the key in the storage chip and then sends it to the manufacturer's server for verification through the communication module.

[0005] Furthermore, the key is burned into the storage chip through a burner. The burner burns the key through a burn port, and this burn port includes a VPP pin, a CLK pin, and a DATA pin, which are respectively used for signal input required when writing the key, providing a synchronous clock signal, and transmitting key data. There are respectively a fuse one, a fuse two, and a fuse three between the VPP pin, the CLK pin, and the DATA pin and the storage chip, and the fuse one, the fuse two, and the fuse three are all controlled to be fused through the fusing module. In the prior art, the fusing mechanism of the chip port usually only implements fusing for a single line. This design has an obvious single-point failure risk. When the fusing module of a certain line fails, the entire fusing will be paralyzed and the complete fusing of the port cannot be achieved. This limitation makes the overall fusing extremely vulnerable when facing unexpected problems, resulting in the inability to finally achieve the fusing of the port. In addition, the fusing of a single line will trigger a cascading effect, further affecting the normal operation of other modules or devices, thereby increasing the overall instability of the system. This risk not only reduces the reliability of the system but also leads to an increase in maintenance costs. To address such problems, the present invention adopts a multi-line simultaneous fusing strategy. By burning the key into the storage chip and using the VPP, CLK, and DATA pins of the burner for efficient management, where there are respectively independent fuse one, fuse two, and fuse three between each pin and the storage chip. The core lies in independently controlling each fuse through the fusing module to ensure that when the fusing of a certain line fails, the other lines can still continue to be fused. Specifically, if fuse one is fused due to a fault, the system can still continue to be fused through fuse two and fuse three, thereby avoiding the problem of the overall fusing failure caused by single-point fusing. By implementing fusing in multiple independent lines, it is ensured that when a certain fusing line fails, the other fusing lines can still be normally fused, thus avoiding the paralysis of the overall fusing mechanism. This local fusing method significantly reduces the risk of the cascading effect, prevents the failure from affecting other modules or devices, and enables the fusing of the port to maintain higher reliability and stability. By promptly responding to failures, the maintenance time and cost are reduced, and the overall maintenance efficiency is improved. In addition, when there are unexpected problems during the fusing of a certain line, there are still other lines for fusing to ensure the normal progress of fusing. This not only enhances the resilience of the technical system but also reduces the operation risk, thereby enhancing user trust and compatibility with industry standards, greatly promoting the improvement of technological innovation and competitiveness.

[0006] Further, the fusing module includes a power supply VCC, a protection resistor R1, an N-channel MOSFET transistor, and a protection resistor R2. One end of the fuse is provided with the power supply VCC, a protection resistor R1 is connected between the power supply VCC and the fuse, the other end of the fuse is connected to the drain of the N-channel MOSFET transistor, the gate of the N-channel MOSFET transistor is used to receive the fusing signal, the source of the N-channel MOSFET transistor is grounded after passing through the protection resistor R2, and a diode is connected to one end of the fuse close to the programming port. Through a suitable and efficient fusing circuit, it can be ensured that the writing port can be completely fused after the key writing is completed, further guaranteeing the secure access of the IoT card.

[0007] Further, the fusing voltage of the fuse is 5V to 12V, the fusing current of the fuse is 50mA to 500mA, and the fuse cannot be restored after fusing. By defining the fusing parameters of the fuse, it can be ensured that the fuse can respond quickly and fuse the port when the fusing condition is reached.

[0008] Further, the voltage of the power supply VCC is 5V to 12V, and the protection resistors R1 and R2 satisfy the condition: R1 + R2 = V 熔断 / I 熔断 , the total resistance of the protection resistors R1 and R2 is 16Ω to 96Ω, and the conduction condition of the N-channel MOSFET transistor is: V gs = V 栅极 - I 熔断 ·R2 ≥ V th , where V gs is the voltage difference between the gate and the source of the MOSFET, V 栅极 is the gate power supply, I 熔断 is the fusing current, V th is the threshold voltage, the source voltage of the N-channel MOSFET transistor is 3V to 5V, the range of the protection resistor R1 is 15Ω to 90Ω, and the range of the protection resistor R2 is 1Ω to 6Ω. By defining the parameters of each component in the circuit, it can be further ensured that when the fusing module receives the fusing signal, the port can be accurately and quickly fused.

[0009] Further, an encryption engine is provided inside the storage chip, and the encryption engine encrypts the key stored in the storage chip. This encryption engine can perform efficient encryption processing on the key to ensure data security and privacy protection. This design not only improves the security of key management but also effectively prevents potential unauthorized access, ensuring the security of sensitive information in the storage chip during transmission and storage.

[0010] Further, the encryption engine receives a random number sequence sent by the main control chip. The key generates an initial transmission key based on the random number sequence. The encryption engine returns the random number sequence and the initial transmission key to the main control chip, and the main control chip sends the initial transmission key and the random number sequence to the manufacturer server for verification. This mechanism enhances the randomness and complexity of the key. Sending this information to the manufacturer server for verification ensures the legitimacy and effectiveness of the key, thereby effectively preventing attackers from obtaining the key through guessing or replay attacks. This dual verification process greatly improves the security of the system and helps protect the user's data privacy and its security.

[0011] Further, the key is symmetrically encrypted based on the random number sequence to generate a double key. Introducing randomness into the key generation process ensures the uniqueness of the key and its ability to resist potential attacks, thereby protecting the privacy of user data and the overall security of the system. The use of the double key further enhances the encryption strength, making any unauthorized access extremely difficult.

[0012] An Internet of Things card security access and data transmission encryption method, which includes the following steps:

[0013] Step 1. Based on a preset key and a random number sequence, generate an initial transmission key through a hashing algorithm;

[0014] Step 2. After passing the authentication and accessing the Internet of Things, divide the data to be transmitted into multiple data blocks according to a dynamic chunking strategy. The dynamic chunking strategy dynamically calculates the chunking threshold according to the original data size and the current network latency;

[0015] Step 3. Perform double encryption on each data block in sequence: first encrypt using a symmetric encryption algorithm in combination with the initial transmission key, and then use an asymmetric encryption algorithm to perform secondary encryption on the symmetric key to generate an encrypted data packet;

[0016] Step 4. During the data transmission process, monitor the transmission link status in real time. When a preset trigger condition is reached, dynamically generate a new transmission key based on the previous transmission key and an update factor through a key derivation function;

[0017] Step 5. Repeat Step 3 to encrypt the uncompleted data blocks using the new transmission key and update the key synchronization status at the receiving end until the data transmission is completed.

[0018] Further, the specific implementation of the dynamic chunking strategy includes:

[0019] According to the total data length L and the network real-time latency t, through the formula Block_size = K ×

[0020] Calculate the block threshold as (L / (t + 1)), where K is a configurable coefficient and Block_size is the block threshold;

[0021] When the data stream is a real-time streaming media, adopt a fixed time slicing strategy and intercept data blocks according to a preset time window;

[0022] Attach a check code and a sequence identifier to each data block. The check code is generated using the CRC-32 algorithm, and the sequence identifier includes the block sequence number and the session ID to which it belongs.

[0023] The technical effects achieved by the present invention are as follows:

[0024] First, the key writing port of the IoT card remains after writing, which brings serious security risks. An attacker can easily obtain or overwrite the stored key by physically contacting this port. Once the key is maliciously extracted, the attacker can forge an identity and conduct unauthorized access, which may lead to security incidents such as data tampering and information leakage. In addition, this writing port exists throughout the device's use, increasing the risk of being attacked, especially for old devices that are not updated in a timely manner, which are more likely to become targets of attacks. Over time, the lack of security protection measures exacerbates potential threats and will also have a serious impact on the enterprise's compliance and brand reputation. Therefore, it is urgent to improve the design to eliminate this security risk to ensure the overall security of the IoT system. To address such problems, the present invention adopts a strategy of fusing the key writing port of the IoT card, which can ensure that the key is quickly disconnected from the external interface after writing, reducing the possibility for an attacker to obtain or tamper with the stored key through physical contact. This measure will effectively prevent unauthorized access and prevent security incidents such as data tampering and information leakage. In addition, combined with regular security updates and an automated management mechanism, it can timely repair vulnerabilities against new security threats and continuously improve the device's protection capabilities. By improving the device's security, it can not only protect users' data privacy but also enhance the enterprise's compliance and avoid legal risks and financial losses caused by security incidents. This improved design not only eliminates potential risks at the technical level but also guarantees user trust and brand reputation at the commercial level, helping the enterprise gain an advantage in the increasingly competitive market and create sustainable commercial value, and significantly improving the overall security of the IoT system.

[0025] Second, the fusing mechanism of the chip ports usually only applies to a single line. This design has an obvious single-point failure risk. When the fusing module of a certain line fails, the entire fusing will be paralyzed and the complete fusing of the port cannot be achieved. This limitation makes the overall fusing extremely vulnerable when facing unexpected problems, resulting in the inability to finally achieve the fusing of the port. In addition, the fusing of a single line will trigger a cascading effect, further affecting the normal operation of other modules or devices, thereby increasing the overall instability of the system. This risk not only reduces the reliability of the system but also leads to an increase in maintenance costs. To address such problems, the present invention adopts a multi-line simultaneous fusing strategy, achieving the fusing of multiple independent lines to ensure that when a certain fusing line fails, other fusing lines can still be normally fused, thus avoiding the paralysis of the overall fusing mechanism. This local fusing method significantly reduces the risk of the cascading effect, preventing the failure from affecting other modules or devices and maintaining higher reliability and stability in the fusing of the port. By promptly responding to failures, reducing the repair time and cost, the overall maintenance efficiency is improved. In addition, when a sudden problem occurs during the fusing of a certain line, there are still other lines for fusing to ensure the normal progress of fusing. This not only enhances the resilience of the technical system but also reduces the operational risk, thereby enhancing user trust and compatibility with industry standards, greatly promoting the effect of technological innovation and competitiveness improvement. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a schematic flowchart of a method for secure access and data transmission encryption of an Internet of Things card according to the present invention;

[0027] Figure 2 is a schematic circuit diagram of the fusing module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following detailed description of the specific embodiments of the present invention will be given with reference to the accompanying drawings of the specification. Specific Embodiment 1:

[0030] Refer to Figure 1 and Figure 2, this embodiment provides a method for secure access and data transmission encryption of Internet of Things (IoT) cards. This method is used for local writing of the key for identity authentication when an IoT card accesses the IoT. The key is written into the storage chip of the IoT card. When the IoT card accesses, the key is sent to the manufacturer's server for verification through the main control chip. The method includes the following steps: A fusing module is added to the data writing port of the storage chip. The fusing module at least includes a fuse. When the fusing module receives a fusing signal, it triggers the fuse to blow and disconnects the fusing module. The signal sent after the key burning is completed is regarded as the fusing signal of the fusing module. After the fusing module receives the fusing signal, it triggers the fuse to blow, and by disconnecting the fusing module, it destroys the data writing port of the storage chip. The main control chip calls the key in the storage chip and then sends it to the manufacturer's server through the communication module for verification. In the prior art, the key writing port of the IoT card remains after writing, which brings serious security risks. An attacker can easily obtain or overwrite the stored key by physically contacting the port. Once the key is maliciously extracted, the attacker can forge an identity and conduct unauthorized access, which may lead to security incidents such as data tampering and information leakage. In addition, this writing port always exists during the use of the device, increasing the risk of being attacked, especially for old and unupdated devices, which are more likely to become targets of attack. Over time, the lack of security protection measures exacerbates potential threats and will also have a serious impact on the enterprise's compliance and brand reputation. Therefore, there is an urgent need to improve the design to eliminate this security risk to ensure the overall security of the IoT system. To address such problems, the present invention adopts a strategy of fusing the key writing port of the IoT card. A fusing module is set at the key writing port of the storage chip of the IoT card. This module consists of a fuse and other components. Its main function is to cut off the circuit by receiving a specific fusing signal after the key writing is completed. Once the key burning is completed, a fusing signal will be generated. After the fusing module receives this signal, it immediately triggers the fusing and burns the fuse. Then, the main control chip can call the key in the storage chip and securely send it to the manufacturer's server through the communication module for identity authentication. This process not only ensures the integrity and confidentiality of the key during transmission but also enhances the secure connection between the IoT card and the server. Compared with not using this method:

[0031]

[0032] In this embodiment, the secret key is burned into the storage chip through a burner. The burner burns the secret key through a burn port, and the burn port includes a VPP pin, a CLK pin, and a DATA pin, which are respectively used for signal input required when writing the secret key, providing a synchronous clock signal, and transmitting the secret key data. There are respectively a fuse one, a fuse two, and a fuse three between the VPP pin, the CLK pin, and the DATA pin and the storage chip, and the fuse one, the fuse two, and the fuse three are all controlled to be blown through a blowing module. In the prior art, the fusing mechanism of the chip port usually only implements for a single line. This design has an obvious single-point failure risk. When the fusing module of a certain line fails, the entire fusing will be paralyzed and the complete fusing of the port cannot be achieved. This limitation makes the overall fusing extremely vulnerable when facing unexpected problems, resulting in the inability to finally achieve the fusing of the port. In addition, the fusing of a single line will cause a cascading effect, further affecting the normal operation of other modules or devices, and thus increasing the overall instability of the system. This risk not only reduces the reliability of the system but also leads to an increase in maintenance costs. To solve such problems, the present invention adopts a multi-line simultaneous fusing strategy. By burning the secret key into the storage chip and using the VPP, CLK, and DATA pins of the burner for efficient management, there are respectively independent fuse one, fuse two, and fuse three between each pin and the storage chip. The core lies in independently controlling each fuse through the fusing module to ensure that when the fusing of a certain line fails, the other lines can still continue to be fused. Specifically, if fuse one is blown due to a fault, the system can still continue to be fused through fuse two and fuse three, thus avoiding the problem that the overall fusing fails due to single-point fusing. Compared with not using this method:

[0033]

[0034]

[0035] In this embodiment, as Figure 2 shown, the fusing module includes a power supply VCC, a protection resistor R1, an N-channel MOSFET transistor, and a protection resistor R2. One end of the fuse is provided with the power supply VCC, a protection resistor R1 is connected between the power supply VCC and the fuse, the other end of the fuse is connected to the drain of the N-channel MOSFET transistor, the gate of the N-channel MOSFET transistor is used to receive the fusing signal, the source of the N-channel MOSFET transistor is grounded after passing through the protection resistor R2, and a diode is connected to one end of the fuse close to the burn port. The burner writes the secret key into the storage chip through the fusing module.

[0036] During the stage of writing the secret key: The burner directly writes the secret key into the storage chip through the fuse. At this time, the gate (G) of the N-channel MOSFET has no driving signal and is in the off state. The power supply VCC circuit is disconnected, and the diode prevents the burner from being damaged by reverse voltage from the outside. At the same time, it is necessary to satisfy R1≥(VCC - V芯片(max) ) / I 熔断 -R 熔丝 , where V 芯片(max) Indicates the maximum load voltage of the chip, R 熔丝 is the fuse resistance;

[0037] Fusing stage: After the key is written, the programmer sends a high-level signal to the MOSFET gate to turn it on, power supply VCC → resistor R1 → fuse → MOSFET drain (D) → source (S) → resistor R2 → ground, forming a large current loop. The fuse blows due to overcurrent, permanently cutting off the physical connection between the programmer and the memory chip. R1 limits the fusing current of the power supply VCC during this process to avoid device damage. After the fuse blows, only the chip power supply interface is retained to achieve hardware anti-tampering protection.

[0038] In this embodiment, during the IoT card production stage, after the key is written into the storage chip through the VPP, CLK, and DATA pins of the burning port by the burner, the main control chip sends a 5V high-level fuse signal to the fuse module. The fuse in the fuse module is made of lead-antimony alloy with a melting point of 200°C and a resistivity of 1.5×10 -7 Ω·m, response time <10ms. At this time, the gate voltage of the N-channel MOSFET (Vgate = 5V) triggers conduction, and the fuse circuit forms a closed loop: the power supply VCC (12V) supplies power to the fuse through the protection resistor R1 (18Ω), and the current Ifuse = 500mA flows through the fuse, through the MOSFET drain to the source, and then through the protection resistor R2 (6Ω) to the ground. Both ends of the fuse are quickly melted due to Joule heat, and at the same time, the source voltage Vs = Ifuse × R2 = 3V, Vgs = Vgate-Vs = 2V (satisfying the MOSFET conduction threshold V th =2V). After the fuse is blown, the electrical connection between the VPP, CLK, DATA pins and the memory chip is permanently disconnected, blocking secondary writing or signal theft. The main control chip then calls the key solidified in the memory chip, encrypts it and sends it to the manufacturer's server for verification, realizing secure access to the IoT card and encrypted data transmission. Specific embodiment 2:

[0040] like Figure 1 This embodiment provides a data transmission encryption method, which is based on the data encryption of the data transmission process in embodiment 1. The method includes the following steps:

[0041] Step 1. Generate an initial transmission key through a hash algorithm based on a preset key and a random number sequence;

[0042] Step 2. After the identity authentication is passed and the IoT is connected, the data to be transmitted is divided into multiple data blocks according to the dynamic block strategy. The dynamic block strategy dynamically calculates the block threshold according to the original data size and the current network delay;

[0043] Step 3. Perform double encryption on each data block in sequence: First, encrypt using a symmetric encryption algorithm in combination with the initial transmission key, and then perform secondary encryption on the symmetric key using an asymmetric encryption algorithm to generate encrypted data packets;

[0044] Step 4. Monitor the transmission link status in real time during data transmission. When the preset trigger condition is reached, dynamically generate a new transmission key through a key derivation function based on the previous transmission key and the update factor;

[0045] Step 5. Repeat the encryption in Step 3 for the data blocks that have not completed transmission using the new transmission key, and update the key synchronization status at the receiving end until the data transmission is completed.

[0046] Specifically, the specific implementation of the dynamic block strategy includes:

[0047] According to the total data length L and the network real-time delay t, calculate the block threshold through the formula Block_size = K ×

[0048] (L / (t + 1)), where K is a configurable coefficient and Block_size is the block threshold;

[0049] When the data stream is a real-time streaming media, adopt a fixed-time slicing strategy to intercept data blocks according to a preset time window;

[0050] Attach a check code and a sequence identifier to each data block. The check code is generated using the CRC-32 algorithm, and the sequence identifier includes the block number and the session ID to which it belongs.

[0051] The working principle of the present invention:

[0052] A fusing module is set at the key writing port of the storage chip of the Internet of Things card. This module consists of a fuse and other components. Its main function is to cut off the circuit by receiving a specific fusing signal after the key writing is completed. Once the key is burned, a fusing signal will be generated. After receiving this signal, the fusing module will immediately trigger fusing and burn the fuse. Then, the main control chip can call the key in the storage chip and securely send it to the manufacturer's server through the communication module for identity verification. This process not only ensures the integrity and confidentiality of the key during transmission but also enhances the secure connection between the Internet of Things card and the server. By burning the key into the storage chip, the VPP, CLK, and DATA pins of the burner are used for efficient management. Independent fuses one, two, and three are respectively provided between each pin and the storage chip. The core lies in independently controlling each fuse through the fusing module to ensure that when a certain circuit fails to fuse, other circuits can still continue to fuse. Specifically, if fuse one fuses due to a fault, the system can still continue to fuse through fuses two and three, thus avoiding the problem of overall fusing failure caused by single-point fusing.

[0053] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention, unless otherwise specifically stated and limited, are implemented according to the conventional means in this field.

Claims

1. A method for secure access and data transmission encryption of Internet of Things (IoT) cards, which is used for local writing of keys for identity authentication when IoT cards access the IoT. The keys are written into the storage chips of the IoT cards. When the IoT cards access the IoT, the keys are sent to the manufacturer's server through the main control chip for verification. It is characterized in that: The method includes the following steps: Step 1. A fusing module is added to the data writing port of the storage chip. The fusing module at least includes a fuse. After receiving a fusing signal, the fuse is triggered to fuse, and the fusing module is disconnected. Step 2. The signal sent after the key programming is completed is regarded as the fusing signal of the fusing module. After receiving the fusing signal, the fusing module triggers the fuse to fuse, and by disconnecting the fusing module, the data writing port of the storage chip is damaged. Step 3. The main control chip calls the key in the storage chip and then sends it to the manufacturer's server via the communication module for verification.

2. The security access and data transmission encryption method of an Internet of Things card according to claim 1, characterized in that: The key is programmed into the storage chip through a programmer. The programmer programs the key through a programming port. The programming port includes a VPP pin, a CLK pin, and a DATA pin, which are respectively used for signal input required for writing the key, providing a synchronous clock signal, and transmitting key data. A fuse one, a fuse two, and a fuse three are respectively provided between the VPP pin, the CLK pin, and the DATA pin and the storage chip. The fuse one, the fuse two, and the fuse three are all controlled to fuse through the fusing module.

3. A method for secure access and data transmission encryption of an Internet of Things card according to claim 1, characterized in that: The fusing module includes a power supply VCC, a protection resistor R1, an N-channel MOSFET transistor, and a protection resistor R2. One end of the fuse is provided with the power supply VCC. A protection resistor R1 is connected between the power supply VCC and the fuse. The other end of the fuse is connected to the drain of the N-channel MOSFET transistor. The gate of the N-channel MOSFET transistor is used to receive the fusing signal. The source of the N-channel MOSFET transistor is grounded after passing through the protection resistor R2. A diode is connected to one end of the fuse close to the programming port.

4. A method for secure access and data transmission encryption of an IoT card according to claim 3, characterized in that: The fusing voltage of the fuse is 5V to 12V, the fusing current of the fuse is 50mA to 500mA, and the fuse cannot be restored after fusing.

5. A method for secure access and data transmission encryption of an Internet of Things card according to claim 3, characterized in that: The voltage of the power supply VCC is 5V to 12V. The protection resistor R1 and the protection resistor R2 satisfy the conditions: The total resistance of the protection resistor R1 and the protection resistor R2 is 16Ω to 96Ω. The conduction condition of the N-channel MOSFET transistor is: Vgs = Vgate - Ifusing·R2 ≥ Vth, Among them, V gs is the voltage difference between the gate and the source of the MOSFET, V 栅极 is the gate power supply, I 熔断 is the fusing current, V th is the threshold voltage. The source voltage of the N-channel MOSFET transistor is 3V to 5V. The range of the protection resistor R1 is 15Ω to 90Ω, and the range of the protection resistor R2 is 1Ω to 6Ω.

6. A method for secure access and data transmission encryption of an Internet of Things card according to claim 1, characterized in that: An encryption engine is provided inside the storage chip. The encryption engine encrypts the key stored in the storage chip.

7. A method for secure access and data transmission encryption of an Internet of Things card according to claim 6, characterized in that: The encryption engine receives a random number sequence sent by the main control chip. The key generates an initial transmission key according to the random number sequence. The encryption engine returns the random number sequence and the initial transmission key to the main control chip. The main control chip sends the initial transmission key and the random number sequence to the manufacturer's server for verification.

8. A method for secure access and data transmission encryption of an Internet of Things card according to claim 7, characterized in that: The key is symmetrically encrypted based on the random number sequence to generate a double key.

9. The security access and data transmission encryption method for an Internet of Things card according to claim 1, characterized in that: The method includes the following steps: Step 1. Based on a preset key and a random number sequence, an initial transmission key is generated through a hashing algorithm. Step 2. After passing the identity verification and accessing the Internet of Things, the data to be transmitted is divided into multiple data blocks according to a dynamic chunking strategy. The dynamic chunking strategy dynamically calculates the chunking threshold according to the size of the original data and the current network latency. Step 3. Perform double encryption on each data block in sequence: first encrypt using a symmetric encryption algorithm in combination with the initial transmission key, and then perform secondary encryption on the symmetric key using an asymmetric encryption algorithm to generate an encrypted data packet; Step 4. Monitor the transmission link status in real time during data transmission. When the preset trigger condition is reached, dynamically generate a new transmission key through a key derivation function based on the previous transmission key and the update factor; Step 5. Repeat the encryption in Step 3 for the data blocks that have not completed transmission using the new transmission key, and update the key synchronization status at the receiving end until the data transmission is completed.

10. A method for secure access and data transmission encryption of an Internet of Things card according to claim 9, characterized in that: The specific implementation of the dynamic block strategy includes: Calculate the block threshold according to the total data length L and the network real-time delay t through the formula Block_size = K × (L / (t + 1)), where K is a configurable coefficient and Block_size is the block threshold; When the data stream is a real-time streaming media, adopt a fixed time slicing strategy to intercept data blocks according to a preset time window; Attach a checksum and a sequence identifier to each data block. The checksum is generated using the CRC-32 algorithm, and the sequence identifier includes the block number and the session ID to which it belongs.

Citation Information

Patent Citations

  • Secure communication system and method of main control chip and encryption chip

    CN108234132A

  • Equipment connection method and system and corresponding Internet of Things equipment

    CN112448970A

  • Distributed key updating and recovering mechanism using method for security of Internet of Things

    CN118802139A

  • Communication data transmission and temporary storage method and device and storage medium

    CN119299393A

  • Quantum key chip

    CN205945769U