Encrypted communication method and system of switch based on time-sensitive network
By generating security values in time-sensitive network switches and dynamically updating the communication keys, combining random numbers and encryption algorithms, the security problem of the switch communication system is solved, and the security and certainty of encrypted communications are achieved.
Patent Information
- Application Number
- CN202510705733.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-18
AI Technical Summary
The existing time-sensitive network switch communication systems have security risks when facing a wide range of communication interfaces and complex environment connections, and it is difficult to effectively ensure the encryption and security of communications.
The key module generates security values based on time-sensitive network switches, dynamically updates the communication keys, and encrypts the communication data using random numbers and encryption algorithms to ensure the security of the communication data.
Encryption of time-sensitive network switch communications is realized, the security of the system is improved, data is prevented from being stolen or cracked, and the certainty and real-time nature of communication is ensured.
Smart Images

Figure CN120342608A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to an encrypted communication method and system for a switch based on a time-sensitive network. Background Art
[0002] Time-Sensitive Networking (TSN) is a set of standards that ensure deterministic communication in standard Ethernet. TSN provides a network traffic management mechanism that clearly defines the upper limit of transmission delay. All TSN devices must maintain time synchronization and adopt a common time framework to ensure real-time communication in industrial automation and control applications.
[0003] With its superior transmission characteristics, TSN is widely used in fields with high requirements for real-time performance. At the same time, with the development of cyber-physical systems, the systems to which TSN is applied are becoming more and more closely connected to the surrounding environment, and the extensive communication interfaces increase the risk of the system being damaged by attackers.
[0004] Therefore, it is necessary to ensure the communication security of TSN, especially switches based on time-sensitive networks. Summary of the Invention
[0005] (1) Technical Problems to be Solved
[0006] In view of the above-mentioned disadvantages and deficiencies of the prior art, the present invention provides an encrypted communication method and system for a switch based on a time-sensitive network.
[0007] (2) Technical Solutions
[0008] To achieve the above object, the main technical solutions adopted by the present invention include:
[0009] In a first aspect, an embodiment of the present invention provides an encrypted communication method for a switch based on a time-sensitive network, the method including:
[0010] A switch based on a time-sensitive network obtains a first communication key; wherein, the first communication key is generated by a key module according to the security value of the switch based on a time-sensitive network; the key module establishes a communication connection with the switch based on a time-sensitive network;
[0011] The switch based on a time-sensitive network encrypts first communication data with the first communication key to obtain a first ciphertext;
[0012] The switch based on a time-sensitive network generates a second ciphertext according to a first random number and the first ciphertext; wherein, the first random number is pre-generated by the key module;
[0013] The switch based on a time-sensitive network sends the second ciphertext.
[0014] Optionally, the method further includes:
[0015] The key module determines whether the communication key update condition for the switch based on the time-sensitive network is satisfied;
[0016] If it is satisfied, the key module generates a first communication key according to the security value of the switch based on the time-sensitive network, generates first encrypted data from the first communication key, and sends the first encrypted data to the switch based on the time-sensitive network, so that the switch based on the time-sensitive network stores the first communication key in the first encrypted data.
[0017] Optionally, generating the first communication key according to the security value of the switch based on the time-sensitive network includes:
[0018] Generating a first random number;
[0019] Generating a first communication key according to the first random number and the security value of the switch based on the time-sensitive network.
[0020] Optionally, the security value of the switch based on the time-sensitive network is determined through the following steps:
[0021] Obtaining the transmission time, the number of lost packets, traffic data, vulnerability information, and the number of connected network devices of each data packet of the switch based on the time-sensitive network;
[0022] According to the transmission time of each data packet, determining the total number of data packets, the average transmission time of data packets, the maximum transmission time, and the minimum transmission time;
[0023] Determining the packet loss rate according to the number of lost packets and the total number of data packets;
[0024] Determining a traffic anomaly value according to the traffic data;
[0025] Determining a first impact value according to the vulnerability information;
[0026] Determining a second impact value according to the number of connected network devices;
[0027] Determining the security value of the switch based on the time-sensitive network according to the packet loss rate, the average transmission time of data packets, the maximum transmission time, the minimum transmission time, the traffic anomaly value, the first impact value, and the second impact value.
[0028] Optionally, determining the traffic anomaly value according to the traffic data includes:
[0029] Sorting the traffic data in descending order of the acquisition time to obtain a traffic sequence;
[0030] Starting from the first element of the traffic sequence up to the third - last element, calculate the first difference of the numerical values between each element and the first subsequent element to obtain a first - difference sequence;
[0031] Starting from the first element of the traffic sequence up to the third - last element, calculate the second difference of the numerical values between each element and the second subsequent element to obtain a second - difference sequence;
[0032] Determine traffic outliers based on the first - difference sequence and the second - difference sequence.
[0033] Optionally, determine a first impact value according to vulnerability information, including:
[0034] Determine the maximum value of the Common Vulnerability Scoring System (CVSS) scores for all vulnerabilities and the number of vulnerabilities with a score of not less than 7 according to the vulnerability information;
[0035] Determine the first impact value based on the maximum score and the number of vulnerabilities with a score of not less than 7.
[0036] Optionally, determine a second impact value according to the number of connected network devices, including:
[0037] Determine the second impact value according to the number of connected network devices and a preset unit weight.
[0038] Optionally, generate first encrypted data from a first communication key, including:
[0039] Transmit a first random number to a switch based on a time - sensitive network so that the switch based on the time - sensitive network stores the first random number, generates and feeds back a second random number;
[0040] Generate a first temporary key according to the first random number and the second random number;
[0041] Encrypt the first communication key with the first temporary key to obtain a third ciphertext;
[0042] Determine a fourth ciphertext according to the first random number and the third ciphertext;
[0043] Encrypt the fourth ciphertext with the public key of the switch based on the time - sensitive network to obtain the first encrypted data.
[0044] Optionally, the method further includes:
[0045] After the switch based on the time-sensitive network receives the fifth ciphertext, it requests the second encrypted data from the key module; wherein, the fifth ciphertext is sent by other switches based on the time-sensitive network, the second encrypted data is encrypted with the public key of the switch based on the time-sensitive network, and the second encrypted data includes the sixth ciphertext, the third random number, and the fourth random number. Among them, the third random number is generated by the key module when generating the second encrypted data, the fourth random number is generated by other switches based on the time-sensitive network triggered by the third random number, and the sixth ciphertext is the ciphertext of the second communication key of other switches based on the time-sensitive network;
[0046] The switch based on the time-sensitive network decrypts the second encrypted data with its private key to obtain the sixth ciphertext, the third random number, and the fourth random number;
[0047] The switch based on the time-sensitive network obtains the seventh ciphertext according to the third random number and the fifth ciphertext;
[0048] The switch based on the time-sensitive network determines the second temporary key according to the third random number and the fourth random number;
[0049] The switch based on the time-sensitive network decrypts the sixth ciphertext with the second temporary key to obtain the second communication key;
[0050] The switch based on the time-sensitive network decrypts the seventh ciphertext with the second communication key to obtain the second communication data.
[0051] In a first aspect, an embodiment of the present invention provides an encrypted communication system for a switch based on a time-sensitive network, the system includes: a plurality of switches based on the time-sensitive network and a key module;
[0052] Each switch based on the time-sensitive network establishes a communication connection with the key module;
[0053] Any switch based on the time-sensitive network is used to execute the steps performed by the switch based on the time-sensitive network in the method described in the first aspect above;
[0054] The key module is used to execute the steps performed by the key module in the method described in the first aspect above.
[0055] (III) Beneficial effects
[0056] The beneficial effects of the present invention are as follows: The present invention relates to an encryption communication method and system for a switch based on a time-sensitive network. The method includes: a switch based on a time-sensitive network obtains a first communication key; wherein, the first communication key is generated by a key module according to the security value of the switch based on a time-sensitive network; the key module establishes a communication connection with the switch based on a time-sensitive network; the switch based on a time-sensitive network encrypts first communication data with the first communication key to obtain a first ciphertext; the switch based on a time-sensitive network generates a second ciphertext according to a first random number and the first ciphertext; wherein, the first random number is pre-generated by the key module; the switch based on a time-sensitive network sends the second ciphertext. The method of the present invention ensures the communication security of the switch based on a time-sensitive network by encrypting communication data. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 FIG. is a schematic structural diagram of an encryption communication system for a switch based on a time-sensitive network provided by the present invention;
[0058] Figure 2 FIG. is a schematic flow diagram of an encryption communication method for a switch based on a time-sensitive network provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] In order to better explain the present invention for easy understanding, the present invention will be described in detail below with reference to the accompanying drawings and through specific embodiments.
[0060] Time-Sensitive Networking (TSN) is a set of standards that ensure deterministic communication in standard Ethernet. TSN provides a network traffic management mechanism that clearly defines the upper limit of transmission delay. All TSN devices must maintain time synchronization and adopt a common time framework to ensure real-time communication in industrial automation and control applications.
[0061] With its superior transmission characteristics, TSN is widely used in fields with high requirements for real-time performance. At the same time, with the development of cyber-physical systems, the systems to which TSN is applied are becoming more and more closely connected to the surrounding environment, and a wide range of communication interfaces increase the risk of the system being damaged by attackers.
[0062] Therefore, it is necessary to ensure the communication security of TSN, especially switches based on time-sensitive networks.
[0063] To this end, the present invention relates to an encryption communication method and system for a switch based on a time-sensitive network. The method includes: a switch based on a time-sensitive network obtains a first communication key; wherein, the first communication key is generated by a key module according to the security value of the switch based on a time-sensitive network; the key module establishes a communication connection with the switch based on a time-sensitive network; the switch based on a time-sensitive network encrypts first communication data with the first communication key to obtain a first ciphertext; the switch based on a time-sensitive network generates a second ciphertext according to a first random number and the first ciphertext; wherein, the first random number is pre-generated by the key module; the switch based on a time-sensitive network sends the second ciphertext. The method of the present invention ensures the communication security of the switch based on a time-sensitive network by encrypting communication data.
[0064] This embodiment provides an encryption communication method for a switch based on a time-sensitive network, which is implemented by an encryption communication system of the switch based on a time-sensitive network. As Figure 1 shown, the system includes: a plurality of switches based on a time-sensitive network and a key module.
[0065] Each switch based on a time-sensitive network establishes a communication connection with the key module.
[0066] Any switch based on a time-sensitive network is used to execute the steps performed by the switch based on a time-sensitive network in the encryption communication method for a switch based on a time-sensitive network provided in this embodiment.
[0067] The key module is used to execute the steps performed by the key module in the encryption communication method for a switch based on a time-sensitive network provided in this embodiment.
[0068] In specific implementation, the key module dynamically generates communication keys, and the key module generates corresponding communication keys for each switch of the time-sensitive network. Whenever the key module generates a new communication key, it sends it to the corresponding switch based on a time-sensitive network.
[0069] After receiving the communication key, the switch based on a time-sensitive network overwrites the old communication key and stores the latest communication key. When communication is required, it obtains the stored latest communication key, encrypts the communication data with the latest communication key, and then transmits the encrypted communication data, thereby ensuring the communication security of the switch based on a time-sensitive network.
[0070] In addition, after the switch of the time-sensitive network receives the encrypted data sent by other switches of the time-sensitive network, it obtains the communication key of other switches of the time-sensitive network through the key module, and decrypts the obtained encrypted data with the obtained communication key to obtain the communication data.
[0071] In specific implementation, the key module can periodically determine the security values of switches based on time-sensitive networks, and this security value is the basis for determining the communication key.
[0072] For example, the security value is determined once a week, or once a month, etc. The shorter the determination period, the more accurately the security value can reflect the current real situation of the switch based on the time-sensitive network, and the communication key can be updated more accurately. However, frequent determination of the security value consumes certain resources and time. The longer the determination period, the consumption of resources and time is avoided, but the security value cannot accurately reflect the current real situation of the switch based on the time-sensitive network, affecting the accurate update of the communication key. In specific implementation, the appropriate determination period of the security value can be determined based on the comprehensive assessment of the security risk of the encryption communication system of the switch based on the time-sensitive network.
[0073] When determining the security value each time (for example, when the key module determines the security value of SW1), it can be implemented through the following steps 301-307.
[0074] 301. The key module obtains the transmission time of each data packet, the number of lost data packets, traffic data, vulnerability information, and the number of network devices connected to the switch based on the time-sensitive network (i.e., SW1).
[0075] For example, the key module collects the transmission time of each data packet, the number of lost data packets, traffic data, current vulnerability information, and the number of network devices connected to SW1 during the current period through the built-in software and network protocol of SW1 (such as SNMP protocol).
[0076] 302. The key module determines the total number of data packets, the average transmission time of data packets, the maximum transmission time, and the minimum transmission time according to the transmission time of each data packet.
[0077] For example, according to the transmission time of each data packet, it can be known how many data packets (i.e., the total number of data packets NP) in the most recent period, the average value of the transmission time of each data packet (i.e., the average transmission time of data packets TDP avg ), the maximum value of the transmission time of each data packet (i.e., the maximum transmission time of data packets TDP max ), and the minimum value of the transmission time of each data packet (i.e., the minimum transmission time of data packets TDP min ).
[0078] 303. The key module determines the packet loss rate according to the number of lost data packets and the total number of data packets.
[0079] For example, determine the packet loss rate
[0080] where NLP is the number of lost data packets.
[0081] The PLR is a value between 0 and 1. The larger the value, the worse the current network stability of the switch (such as SW1) based on the time-sensitive network.
[0082] In step 304, the key module determines the traffic outlier Pl based on the traffic data.
[0083] Among them, the implementation process of step 304 is as follows:
[0084] In step 304-1, sort the traffic data in ascending order of the collection time to obtain a traffic sequence.
[0085] For example, the traffic sequence has 10 elements: {traffic 1, traffic 2, traffic 3, traffic 4, traffic 5, traffic 6, traffic 7, traffic 8, traffic 9, traffic 10}.
[0086] If i represents the element label of the traffic sequence and a i represents any element in the traffic sequence, then the corresponding relationship between the element label of the traffic sequence, the element label and the element value is shown in Table 1.
[0087] Table 1
[0088]
[0089] In step 304-2, starting from the first element of the traffic sequence until the third element from the end, calculate the first difference of the element values between each element and the first element after it to obtain a first difference sequence.
[0090] Taking the traffic sequence shown in Table 1 as an example, if i represents the element label of the first difference sequence and a ' i represents any element in the first difference sequence, then the corresponding relationship between the element label of the first difference sequence, the element label and the element value is shown in Table 2.
[0091] Table 2
[0092]
[0093] From the determination scheme of a ' i it can be seen that if a ' i = 0, it means that the traffic at the next moment has not changed. If a ' i > 0, it means that the traffic at the next moment has decreased. If a ' i < 0, it means that the traffic at the next moment has increased.
[0094] 304-3. Starting from the first element of the traffic sequence up to the third-to-last element, calculate the second difference of the numerical values between each element and the second element after it to obtain the second difference sequence.
[0095] Taking the traffic sequence shown in Table 1 as an example, if i represents the element label of the second difference sequence and a ' i ' represents any element in the second difference sequence, then the corresponding relationships between the element labels of the second difference sequence, the element labels, and the element values are shown in Table 3.
[0096] Table 3
[0097]
[0098] From the determination scheme of a ' i ' , it can be seen that if a ' i ' = 0, it means that the traffic at the second moment after has not changed. If a ' i ' > 0, it means that the traffic at the next moment has decreased. If a ' i ' < 0, it means that the traffic at the second moment after has increased.
[0099] Regarding why only the third-to-last element of the traffic sequence is processed, it is because in the second difference sequence, a difference operation needs to be performed between an element in the traffic sequence and the second element after it. For the second-to-last element and the last element of the traffic sequence, since there is no second element after them, no difference operation can be done. At the same time, the amount of traffic data is relatively large. Under the premise of a large amount of data, discarding 2 values does not affect the judgment of the overall traffic situation and will not affect the accuracy of subsequent traffic outliers. Therefore, these two elements are discarded without processing.
[0100] 304-4. Determine the traffic outliers based on the first difference sequence and the second difference sequence.
[0101] In step 304-4, three consecutive elements in the first difference sequence and the second difference sequence are used as the minimum determination unit, and the traffic outliers are determined based on the relationships between the minimum determination units, thereby obtaining the traffic outliers. The implementation process is as follows:
[0102] 1. Initialize the processing serial number value i = 0, the first count value n2 = 0, the second count value n3 = 0, and the outlier set is empty.
[0103] Since the minimum determination unit is three elements, for the last minimum determination unit (i.e., the last three elements) in the first difference sequence and the second difference sequence, because there is no subsequent minimum determination unit for comparison, the last minimum determination unit (i.e., the last three elements) will be processed separately. Based on this, there are two count values. The first count value n2 is used to count the abnormal situations obtained from the non-last minimum determination units (i.e., non-last three elements) in the first difference sequence and the second difference sequence, and the second count value n3 is used to count the abnormal situations obtained from the last minimum determination unit (i.e., the last three elements) in the first difference sequence and the second difference sequence.
[0104] The abnormal set stores the identifiers corresponding to the abnormal data when storing the abnormal situations obtained from the non-last minimum determination units (i.e., non-last three elements) in the first difference sequence and the second difference sequence. Finally, the number of different identifiers in the abnormal set is determined as n2.
[0105] 2. Determine the value of n3.
[0106] The value of n3 is determined based on the last three elements of the first difference sequence and the second difference sequence.
[0107] If the values of the last element in the first difference sequence and the last element in the second difference sequence are both negative, then n3 = n3 + 1.
[0108] If the values of the second-to-last element in the first difference sequence and the second-to-last element in the second difference sequence are both negative, then n3 = n3 + 1.
[0109] If the values of the third-to-last element in the first difference sequence and the third-to-last element in the second difference sequence are both negative, then n3 = n3 + 1.
[0110] Taking the flow sequence shown in Table 1, the first difference sequence shown in Table 2, and the second difference sequence shown in Table 3 as examples.
[0111] If a ' 7 and a ' 7 ' are both negative, it means that the two consecutive flow values after a7 in the flow sequence are both increasing. The flow increase may be normal or abnormal, and it is impossible to determine whether it is normal here. Considering that the amount of flow data is relatively large, under the premise of a large amount of data, three values will not affect the accuracy of subsequent flow abnormal values, and at the same time, the subsequent related processing of these three flow data will not significantly increase resource consumption. To ensure that abnormal data will not be misjudged as normal data, it is considered abnormal here. Therefore, n3 = n3 + 1. If a ' 7 and a ' 7 'If both are positive numbers or 0, it indicates that the two consecutive flow values after a7 in the flow sequence are both decreasing or remaining unchanged. A decreasing flow means that there is no abnormal deepening (it may be normal or the abnormal degree remains unchanged), so it is considered to be in a normal state, and in this case, the value of n3 remains unchanged. If a ' 7 and a ' 7 ' one of them is a positive number or 0 and the other is a negative number, it indicates that the two consecutive flow values after a7 in the flow sequence are in a fluctuating state, but there are normal situations among them, so it can still be considered normal, and in this case, the value of n3 remains unchanged.
[0112] Up to this point, the processing of a ' 7 and a ' 7 ' is completed, and n3 may become 1 or may still be 0.
[0113] For the same reason, if a ' 6 and a ' 6 ' are both negative numbers, then n3 = n3 + 1. Otherwise, the value of n3 remains unchanged.
[0114] Up to this point, the processing of a ' 6 and a ' 6 ' is completed, and n3 may become 2, 1, or may still be 0.
[0115] If a ' 5 and a ' 5 ' are both negative numbers, then n3 = n3 + 1. Otherwise, the value of n3 remains unchanged.
[0116] Up to this point, the processing of a ' 5 and a ' 5 ' is completed, and n3 may become 3, 2, 1, or may still be 0.
[0117] n3 characterizes the abnormal conditions of the last minimum determination unit (i.e., the last 3 elements) in the first difference sequence and the second difference sequence. The larger n3 is, the more abnormal elements there are in the last minimum determination unit (i.e., the last 3 elements).
[0118] 3. Determine the value of n2.
[0119] The value of n2 is determined based on the non-last three elements of the first difference sequence and the second difference sequence. For ease of description, the non-last three elements of the first difference sequence form a first difference subsequence (the first difference subsequence corresponding to the first difference sequence shown in Table 2 is shown in Table 4), and the non-last three elements of the second difference sequence form a second difference subsequence (the second difference subsequence corresponding to the second difference sequence shown in Table 3 is shown in Table 5).
[0120] Table 4
[0121]
[0122] Table 5
[0123]
[0124] Here, the value of n2 is determined based on the first difference subsequence and the second difference subsequence. The specific implementation process is as follows:
[0125] 1) Determine a' of the first difference subsequence i and a” of the second difference subsequence i to see if they meet the abnormal condition.
[0126] Among them, the abnormal condition is that both a' i and a” i are negative.
[0127] a' i is the value of the i-th element in the first difference subsequence, and a” i is the value of the i-th element in the second difference subsequence.
[0128] That is to say, if both a' i and a” i are negative, it means that the two consecutive flow values after a i in the flow sequence are both increasing. The flow increase may be normal or abnormal, and it is impossible to determine whether it is normal here. At this time, due to the large amount of data, if it is simply considered normal or abnormal, it will affect the accuracy of the subsequent safety value results. Therefore, only when a' i and a” i meet the abnormal condition, it is confirmed whether it is normal through subsequent steps. If both a' i and a” i are positive or 0, it means that the two consecutive flow values after a i in the flow sequence are both decreasing or unchanged, in a normal state. Therefore, it is considered that a' i and a” iThe abnormal condition is not satisfied. If one of a'7 and a”7 is positive or 0 and the other is negative, it indicates that the two consecutive flow values after a7 in the flow sequence are in a fluctuating state. However, there are normal situations among them, so it can be considered still normal. In this case, a' i and a” i do not satisfy the abnormal condition.
[0129] Through this step, a' i and a” i for which it is uncertain whether they are abnormal can be obtained.
[0130] 2) If a' i and a” i satisfy the abnormal condition, it indicates that they may be normal or abnormal. In this step, it will be confirmed whether a' i and a” i are really normal:
[0131] (1) Determine the abnormal value of serial number i
[0132] Taking i = 0 as an example, its corresponding minimum determination unit is composed of a0, a1, and a2 (for the convenience of explanation, this minimum determination unit is named Unit 0). After executing to this point, only a'0 and a”2 are determined to be less than 0, that is, a0 < a1, a0 < a2. In this step, according to the relationship between Unit 0 and the adjacent Unit 1 (composed of a2, a3, a4), the change situation between i = 0 and the subsequent 4 flow values will be judged. This change situation reflects the abnormal situation of Unit 0 as a whole, and this change situation is characterized by the abnormal value AV0.
[0133] If the flow change situation of each minimum determination unit is reflected by three features, for example, the three features reflecting the flow change situation in Unit 0 (composed of a0, a1, a2) are: the change situation between a0 and a1 (this change situation is reflected by a'0), the change situation between a0 and a2 (this change situation is reflected by a”0), and the change situation between a1 and a2 (this change situation is reflected by a'1). That is to say, the feature vector of Unit 0 is [a'0, a”0, a'1]. The three features reflecting the flow change situation in Unit 1 (composed of a2, a3, a4) are: the change situation between a2 and a3 (this change situation is reflected by a'2), the change situation between a2 and a4 (this change situation is reflected by a”2), and the change situation between a3 and a4 (this change situation is reflected by a'3). That is to say, the feature vector of Unit 2 is [a'2, a”2, a'3]. And so on, for any minimum determination unit such as Unit i (composed of a i , a i+1 , a i+2The three characteristics of the flow rate change in the i composition are: a i+1 The change between a i and a i is reflected by a' i+2 The change between a i and a i+1 is reflected by a" i+2 The change between a i+1 and a i is reflected by a' i That is to say, the feature vector of unit i is [a' i+1 , a", i+2 , a' i+2 , and the feature vector of its adjacent minimum determination unit (i.e., unit i + 1) is [a' i+3 .
[0134] Then, by the similarity between the three features of two adjacent minimum determination units, the similarity degree of the flow rate change between two adjacent minimum determination units can be known. If the similarity degree is large, it indicates that the change situation is still maintaining, and the subsequent two adjacent minimum determination units (such as the similarity between unit 1 and unit 2, the similarity between unit 2 and unit 3, etc.) will continue to be determined until the minimum determination unit where the change situation occurs is found. In this way, unit 0 and the subsequent consecutive units with higher similarity will all be identified as abnormal traffic. If the similarity degree is not large, it indicates that the change situation has changed. Whether the changed flow rate is normal needs to be judged by the relationship between it and its subsequent minimum determination unit.
[0135] Among them, the similarity is determined by the Euclidean distance. For example, the similarity between unit i and unit i + 1 (i.e., the outlier value of serial number i)
[0136] (2) If AV i ≥ AV, then put i, i + 1, and i + 2 into the abnormal set and execute (3). If AV i < AV, then directly execute (3).
[0137] Among them, AV is the abnormal threshold, which is a preset empirical value with a value range between 0 and 1. For example, AV = 0.95. The larger this value is, the stricter the similarity judgment condition is, the lower the possibility of similarity is, and the minimum determination units that may be similar are judged as dissimilar, and the possibility of consecutive multiple minimum determination units being similar decreases. The smaller this value is, the looser the similarity judgment condition is, the higher the possibility of similarity is, and those that may not be very similar may also be judged as similar. At this time, the possibility of consecutive multiple minimum determination units being similar increases.
[0138] Taking unit 0 and unit 1 as examples, if AV0≥AV, it indicates that the flow rate changes reflected by unit 0 and unit 1 are similar, and there is no obvious change in the flow rate change trend between unit 0 and unit 1. At this point, unit 1 will be abnormal like unit 0 (because the prerequisite for determining AV0 is that a' i and a” i meet the abnormal conditions, and there is no obvious change in the trend of two consecutive minimum determination units. Then it will not occur accidentally and must be abnormal), that is, it is determined that unit 0 is abnormal through unit 1. At this time, the identifiers of each element in unit 0 will be put into the abnormal set (that is, 0, 1, and 2 are put into the abnormal set).
[0139] It should be noted that since there is a same element in two adjacent minimum determination units. For example, the same element in unit 0 and unit 1 is a2, and there is a same element a4 in unit 1 and unit 2. In actual processing, it may occur that the identifier in unit 0 is put into the abnormal set, and the identifier in unit 1 is also put into the abnormal set. At this time, 2 will be put in twice. For this situation, there are two processing methods. One is that if there are duplicate identifiers in the abnormal set, they will not be put in again, so that all element values in the abnormal set are different. Subsequently, when determining n2, n2 is directly determined as the total number of elements in the abnormal set. The other processing method is to directly put it into the abnormal set. In this way, there are duplicate element values in the abnormal set. Subsequently, when determining n2, n2 is determined as the total number of elements with different element values in the abnormal set. In specific implementation, one of the implementation methods can be adopted.
[0140] (3) i = i + 2.
[0141] After executing to this point, the confirmation of the minimum determination unit with a i as the leading element has been completed. For example, the confirmation of unit 0 (composed of a0, a1, a2) has been completed. Subsequently, unit 1 (composed of a2, a3, a4) will be confirmed through unit 2 (composed of a4, a5, a6).
[0142] At this time, i will be updated from the current 0 to 2, that is, i = i + 2.
[0143] (4) If the current i < n1 - 4, repeat the steps of determining whether a' i of the first difference subsequence and a” i of the second difference subsequence meet the abnormal conditions (that is, 1)) and subsequent steps.
[0144] If the current i ≥ n1 - 4, execute 3) to process the abnormal conditions of the last 4 elements in the first difference subsequence and the second difference subsequence.
[0145] Among them, n1 is the total number of elements in the second difference subsequence.
[0146] Because each processing is based on the minimum determination unit, it is necessary to ensure that there must be a minimum determination unit in the subsequent when entering the next loop. Each minimum determination unit is composed of 3 elements, and two adjacent minimum determination units have one same element. Therefore, the maximum value of the current i is n1 - 4, so as to ensure that there are two elements after a i forming a minimum determination unit with a, and there are two elements after a i forming another minimum determination unit with a. i+2 communicating with another minimum determination unit.
[0147] 3) Process the abnormal situations of the last 4 elements in the first difference subsequence and the second difference subsequence.
[0148] For the last 4 elements in the first difference subsequence and the second difference subsequence, such as
[0149] (1) If and are both negative, it means that the two consecutive flow values in the flow sequence after are both increasing. Here, they are all considered abnormal to ensure that abnormal data will not be misjudged as normal data. Therefore, put n1 - 3 into the abnormal set.
[0150] If and are both positive or 0, it means that the two consecutive flow values in the flow sequence after are both decreasing or unchanged, and the decrease in flow indicates that there is no deepening of the abnormality (it may be normal or the degree of abnormality has not changed), then it is considered to present a normal situation. In this case, do not put n1 - 3 into the abnormal set.
[0151] If and one is positive or 0 and the other is negative, it means that the two consecutive flow values in the flow sequence after are in a fluctuating state. To ensure that abnormal data will not be misjudged as normal data, here they are all considered abnormal. Therefore, put n1 - 3 into the abnormal set.
[0152] (2) If and are both negative, it means that the two consecutive flow values in the flow sequence after are both increasing. Here, they are all considered abnormal to ensure that abnormal data will not be misjudged as normal data. Therefore, put n1 - 2 into the abnormal set.
[0153] If and are both positive or 0, it indicates that the two consecutive flow values in the flow sequence after are both decreasing or remaining unchanged. And the decreasing flow indicates that there is no abnormal deepening (it may be normal or the abnormal degree has not changed), then it is considered to present a normal state. In this case, n1-2 is not put into the abnormal set.
[0154] If and one of them is positive or 0 and the other is negative, it indicates that the two consecutive flow values in the flow sequence after are in a fluctuating state. To ensure that abnormal data will not be misjudged as normal data, here they are all considered abnormal. Therefore, n1-2 is put into the abnormal set.
[0155] (3) If and are both negative, it indicates that the two consecutive flow values in the flow sequence after are both increasing. Here they are all considered abnormal to ensure that abnormal data will not be misjudged as normal data. Therefore, n1-1 is put into the abnormal set.
[0156] If and are both positive or 0, it indicates that the two consecutive flow values in the flow sequence after are both decreasing or remaining unchanged. And the decreasing flow indicates that there is no abnormal deepening (it may be normal or the abnormal degree has not changed), then it is considered to present a normal state. In this case, n1-1 is not put into the abnormal set.
[0157] If and one of them is positive or 0 and the other is negative, it indicates that the two consecutive flow values in the flow sequence after are in a fluctuating state. To ensure that abnormal data will not be misjudged as normal data, here they are all considered abnormal. Therefore, n1-1 is put into the abnormal set.
[0158] (4) If and are both negative, it indicates that the two consecutive flow values in the flow sequence after are both increasing. Here they are all considered abnormal to ensure that abnormal data will not be misjudged as normal data. Therefore, n1 is put into the abnormal set.
[0159] If and are both positive or 0, it indicates that the two consecutive flow values in the flow sequence after If the next two consecutive flow values are both decreasing or remaining unchanged, and a decreasing flow indicates that there is no abnormal deepening (it may be normal or the abnormal degree remains unchanged), then it is considered to be in a normal state. In this case, n1 is not put into the abnormal set.
[0160] If and one of them is positive or 0 and the other is negative, it means that the two consecutive flow values after in the flow sequence are in a fluctuating state. To ensure that abnormal data is not misjudged as normal data, both are considered abnormal here. Therefore, n1 is put into the abnormal set.
[0161] So far, the determination of abnormal conditions for non - last minimum determination units (i.e., non - last 3 elements) in the first difference sequence and the second difference sequence is completed. And the identifiers of all abnormal elements are put into the abnormal set.
[0162] 4) Determine n2 as the number of different element values in the abnormal set.
[0163] 4. Determine the flow anomaly value
[0164] where n0 is the total number of elements in the flow sequence.
[0165] n2 is the number of abnormal elements corresponding to non - last minimum determination units (i.e., non - last 3 elements) in the first difference sequence and the second difference sequence, and n3 is the number of abnormal elements corresponding to the last minimum determination unit (i.e., the last 3 elements) in the first difference sequence and the second difference sequence. n2 + n3 is the number of abnormal elements corresponding to all elements in the first difference sequence and the second difference sequence.
[0166] Since the last two values in the flow sequence are discarded in 304 - 2 and 304 - 3, n0 - 2 is the total number of all elements for which abnormal determination is made in the flow sequence.
[0167] That is, the proportion of abnormal elements corresponding to the flow sequence, which is a value between 0 and 1. The larger this value is, the more abnormal the switch (such as SW1) based on the time - sensitive network is.
[0168] 305. The key module determines the first impact value ω1 according to the vulnerability information.
[0169] Among them, the implementation process of step 305 is as follows:
[0170] 305 - 1. Determine the maximum value CVSS of the Common Vulnerability Scoring System for all vulnerabilities and the number n4 of vulnerabilities with a score greater than 7 points according to the vulnerability information. max and the number n4 of vulnerabilities with a score greater than 7 points.
[0171] CVSS (Common Vulnerability Scoring System) is an industry-wide open standard designed to evaluate the severity of vulnerabilities and help determine the urgency and importance of the required responses. The value range of CVSS is [0, 1]. The larger the CVSS value of a vulnerability, the more severe the vulnerability. For example, a vulnerability with a CVSS less than 4 is not severe, a vulnerability with a CVSS between 4 and 7 is of medium severity, and a vulnerability with a CVSS greater than 7 is severe.
[0172] n4 is the number of severe vulnerabilities, and CVSS max represents the most severe degree of vulnerabilities in switches (such as SW1) based on time-sensitive networks.
[0173] 305 - 2. Determine the first impact value according to the maximum score and the number of vulnerabilities with a score not lower than 7.
[0174] For example, determine the first impact value
[0175] where n5 is the total number of vulnerabilities.
[0176] is the CVSS max normalized value, which is a value between 0 and 1. The larger this value, the more severe the vulnerability in switches (such as SW1) based on time-sensitive networks, the greater the security risk, and the less secure. is the proportion of severe vulnerabilities. The larger this value, the larger the data of severe vulnerabilities among the vulnerabilities in switches (such as SW1) based on time-sensitive networks, the greater the security risk, and the less secure.
[0177] The first impact value ω1 is a value between 0 and 1. The larger this value, the greater the security risk and the less secure the switch (such as SW1) based on time-sensitive networks from the perspective of vulnerability information.
[0178] 306. The key module determines the second impact value ω2 according to the number of network devices connected.
[0179] Among them, the implementation process of step 306 is: determine the second impact value according to the number of network devices connected and the preset unit weight.
[0180] For example, determine the second impact value
[0181] where n6 is the number of network devices connected, n7 is the preset minimum threshold value (this value is a positive integer), and β is the adjustment coefficient. is the ceiling function.
[0182] n7 is the maximum number of network devices that are normally connected to a time-sensitive network-based switch, and this value is determined by relevant personnel according to the actual situation. It is the ratio of the network devices actually connected to a time-sensitive network-based switch (such as SW1) to the maximum number of network devices that are normally connected. If this value is greater than 1, it indicates that the time-sensitive network-based switch (such as SW1) currently has more connected devices. The more devices are connected, the greater the possibility of being attacked and the less secure it is. If this value is not greater than 1, it means that the number of devices currently connected to the time-sensitive network-based switch (such as SW1) is normal.
[0183] is a positive integer with a minimum value of 1. If it means that the number of devices currently connected to the time-sensitive network-based switch (such as SW1) is normal. If it means that the number of devices currently connected to the time-sensitive network-based switch (such as SW1) is abnormal, and the larger it is, the more abnormal it is.
[0184] β is an adjustment coefficient used to normalize. β can evaluate the maximum number of devices that a time-sensitive network-based switch may connect according to the configuration, network conditions, service conditions, abnormal conditions, etc. of the time-sensitive network-based switch, and determine β by adding 1 to the maximum number.
[0185] In this way, the second influence value ω2 is a value between 0 and 1. The larger this value is, the greater the security risk of the time-sensitive network-based switch (such as SW1) from the perspective of the number of connected network devices, and the less secure it is.
[0186] 307. The key module determines the security value of the time-sensitive network-based switch according to the packet loss rate, average packet transmission time, maximum transmission time, minimum transmission time, traffic anomaly value, first influence value, and second influence value.
[0187] For example, the security value of SW1 is
[0188] PLR is the packet loss rate, which is a value between 0 and 1, and ω1 is a value between 0 and 1. Therefore, ω1×PLR is a value between 0 and 1, and the larger this value is, the less secure it is.
[0189] is the normalized value of the average packet transmission time, which is a value between 0 and 1. The larger this value is, the longer the average packet transmission time of the time-sensitive network-based switch (such as SW1), indicating that the time-sensitive network-based switch (such as SW1) is more abnormal, such as network congestion, high load, etc.
[0190] ω2 is a value between 0 and 1, and PL is a value between 0 and 1. It is also a value between 0 and 1.
[0191] From this, it can be known that is a value between 0 and 1, that is, the safety value is between 0 and 1, and the larger this value is, the less safe it is.
[0192] The following details the process by which the key module generates the communication key of the time-sensitive network-based switch for executing the encryption communication method of the time-sensitive network-based switch provided in this embodiment.
[0193] For convenience of description, in this embodiment, the time-sensitive network-based switch that executes the encryption communication method of the time-sensitive network-based switch provided in this embodiment is denoted as SW1, and the communication key of SW1 is denoted as the first communication key. Other time-sensitive network-based switches are denoted as SW2, and the communication key of SW2 is denoted as the second communication key. That is to say, both the first communication key and the second communication key are communication keys, and the "first" and "second" here are only used to distinguish the communication keys of different time-sensitive network-based switches, without any other substantial meaning.
[0194] 401. The key module determines whether the communication key update condition of the time-sensitive network-based switch (i.e., SW1) is satisfied.
[0195] Among them, the communication key update condition of SW1 is: T1 - TK0 ≥ ΔtK, or, Sa1 > Sa, or, Sa1 ≤ Sa0, and
[0196] T1 is the current moment, TK0 is the moment when the communication key of SW1 was generated most recently, ΔtK is the communication key update duration threshold. Sa1 is the safety value of SW1 determined in the most recent period, Sa is the safety value threshold, and the safety value is determined periodically by the key module. The determination process is as described in steps 301 - 307 and will not be elaborated here. Sa0 is the safety value of SW1 determined most recently before Sa1, and ΔSa is the safety value change threshold. ε is a preset extremely small value used to prevent anomalies caused by a denominator of 0.
[0197] Whenever the key module generates a communication key, it records the generation moment of the communication key and the identifier of the time-sensitive network-based switch to which it corresponds. In this step 101, it will find the generation moments of all communication keys corresponding to SW1, and determine the generation moment closest to the current time (i.e., T1) as the moment when the communication key of SW1 was generated most recently (i.e., TK0). If it is the first time to generate a communication key for SW1, then TK0 can be considered as 0.
[0198] T1 - TK0 characterizes how long it has been since the communication key of SW1 was last updated. If T1 - TK0 ≥ ΔtK, it means that the communication key of SW1 has not been updated for a relatively long time and needs to be updated. Therefore, it is determined that the communication key update condition of SW1 is met.
[0199] Among them, ΔtK is pre - set, such as 1 week, 1 month, etc. The longer this time is, the lower the update frequency of the communication key, because the possibility of security risks due to the theft of the communication key is greater. The shorter this time is, the higher the update frequency of the communication key, because the possibility of security risks due to the theft of the communication key is lower, but the resource consumption required to update the communication key is higher. In specific implementation, the appropriate value of ΔtK can be determined according to the comprehensive assessment of the security risks of the encryption communication system of the switch based on the time - sensitive network.
[0200] Sa1 is the security value of SW1 determined in the most recent period, that is, among all the security values of SW1, the one with the latest determination time. Sa0 is the security value of SW1 determined most recently before Sa1, that is, among all the security values of SW1, the one with the second - latest determination time. Therefore, Sa1 and Sa0 are the two adjacent security values determined closest to the current time.
[0201] Sa is the security value threshold, which is a value between 0 and 1 and is used to characterize the maximum value of the security value when the switch based on the time - sensitive network is secure. It can be determined by relevant personnel through comprehensive assessment.
[0202] If Sa1 > Sa, it means that the security value of the switch based on the time - sensitive network (i.e., SW1) has exceeded the maximum value of the security value, which is unsafe. At this time, the communication key needs to be updated to prevent the current communication key from being stolen or cracked, etc., affecting communication security.
[0203] Characterizes the ratio of the most recent security value to its previous security value. If this value is less than 1, it means that the security of the switch based on the time - sensitive network (i.e., SW1) is improving. If this value is equal to 1, it means that the security of the switch based on the time - sensitive network (i.e., SW1) has not changed. If this value is greater than 1, it means that the security of the switch based on the time - sensitive network (i.e., SW1) is deteriorating. Characterizes the change in the security of the switch based on the time - sensitive network (i.e., SW1). The smaller this value is, the more the security is improving, and the larger this value is, the more the security is deteriorating. In specific implementation, the security may fluctuate. It is not that as long as the security deteriorates, it must be unsafe. By setting the security value change threshold ΔSa, the degree of deterioration of the fluctuating security is provided. If It shows that the degree of security degradation is higher than the normal level, which means it is insecure. At this time, the communication key needs to be updated to prevent the current communication key from being stolen or cracked, etc., which may affect communication security.
[0204] Among them, is a number greater than or equal to 0, is a number greater than or equal to -1, and ΔSa can be set as a number greater than or equal to -1. For example, ΔSa = 0.1. The smaller ΔSa is, the greater the possibility of satisfying the relationship is, and the more frequent the communication key update is. At this time, the security will be increased. However, the update of the communication key consumes certain resources, so it will increase the resource consumption of the encryption communication method of the switch based on the time-sensitive network provided in this embodiment. The larger ΔSa is, the smaller the possibility of satisfying the relationship is, and the smaller the communication key update frequency is. Although it reduces the resource consumption of the encryption communication method of the switch based on the time-sensitive network provided in this embodiment, the too long unified communication key usage time will increase the risks of being stolen, cracked, etc., increasing the security risks. Therefore, the value of ΔSa can be comprehensively evaluated according to the resource situation and network situation of the device implementing the encryption communication method of the switch based on the time-sensitive network provided in this embodiment.
[0205] Therefore, if Sa1 ≤ Sa, it means that the security value of the switch based on the time-sensitive network (i.e., SW1) does not exceed the maximum value of the security value. However, it shows that the security of the switch based on the time-sensitive network (i.e., SW1) has decreased, and the communication key also needs to be updated.
[0206] 402. If it is satisfied, the key module generates the first communication key according to the security value of the switch based on the time-sensitive network (i.e., SW1), generates the first encrypted data from the first communication key, and sends the first encrypted data to the switch based on the time-sensitive network (i.e., SW1) so that the switch based on the time-sensitive network (i.e., SW1) stores the first communication key in the first encrypted data.
[0207] In specific implementation, the implementation process of step 402 is as follows:
[0208] 402-1. The key module generates the first communication key according to the security value of SW1.
[0209] For example, the key module generates the first random number and generates the first communication key according to the first random number and the security value of SW1.
[0210] Among them, the key module periodically determines the security values of each switch based on the time-sensitive network (for example, determining the security value once every month). Whenever a new security value is determined, the determination time of the security value is recorded and the security value is stored. The key module can determine the security value through steps 301-307, which will not be elaborated here.
[0211] The implementation process of step 402-1 is as follows:
[0212] 1. Determine the moment TS0 when the security value of SW1 was determined in the most recent period.
[0213] 2. If T1 - TS0 > ΔtS, it means that the determination time of the currently stored security value is relatively far from the current time, and the time when it was generated and stored by the key module is relatively long. The longer this time is, the greater the possibility of leakage such as being stolen, cracked, or intercepted, increasing the security risk of obtaining the communication key through this value. At this time, steps 301-307 need to be executed to determine the latest security value and determine it as the target security value Sa'.
[0214] If T1 - TS0 ≤ ΔtS, it means that the determination time of the currently stored security value is relatively close to the current time, and the leakage risk is relatively small. The security value of SW1 determined in the most recent period can be reused, that is, the security value of SW1 determined in the most recent period is determined as Sa'.
[0215] Among them, ΔtS is the security value update duration threshold. The larger this value is, the greater the risk of reusing a leaked security value, increasing the security risk. The smaller this value is, the more likely it is to re-determine the security value, and re-determining the security value requires consuming certain resources. In specific implementation, the value of ΔtS can be comprehensively determined according to actual business requirements, network conditions, etc.
[0216] 3. Generate the first random number RN1.
[0217] 4. Generate the first communication key as
[0218] where hash(·) is a hash function, is the exclusive OR operator.
[0219] 402-2. The key module generates the first encrypted data from the first communication key.
[0220] The generation process of the first encrypted data is as follows:
[0221] 1. Transmit the first random number to the switch based on the time-sensitive network so that the switch based on the time-sensitive network stores the first random number, generates and feeds back the second random number.
[0222] For example, 1) the key module transmits RN1 to SW1; 2) after receiving RN1, SW1 stores RN1; 3) SW1 generates a random number (for convenience of description, this random number is named the second random number, such as RN2); 4) SW1 sends RN2 to the key module.
[0223] It should be noted that whether it is the key module or SW1, each time the communication key is generated by executing steps 401 and 402, an RN1 and an RN2 will be generated, and only the latest generated RN1 and RN2 need to be stored during storage.
[0224] In addition, in specific implementation, the transmitted data can be encrypted through existing encryption schemes to ensure the data security during the transmission process.
[0225] 2. Generate the first temporary key according to the first random number and the second random number.
[0226] For example, the generated first temporary key is
[0227] 3. Encrypt the first communication key with the first temporary key to obtain the third ciphertext.
[0228] For example, using an existing encryption algorithm, the first communication key is symmetrically encrypted with the first temporary key to obtain the third ciphertext.
[0229] 4. Determine the fourth ciphertext according to the first random number and the third ciphertext.
[0230] For example, it is determined that the fourth ciphertext is the third ciphertext
[0231] 5. Encrypt the fourth ciphertext with the public key of the switch based on the time-sensitive network to obtain the first encrypted data.
[0232] For example, encrypt the fourth ciphertext with the public key of SW1 to obtain the first encrypted data.
[0233] The public key here can be obtained through the CA (certification authority in the field of network security) when the switch based on the time-sensitive network is first configured, and the corresponding private key will also be obtained. Since the public key is public, after the public key of the switch based on the time-sensitive network is obtained, it can be sent to the key module for storage, and the key module can directly read this public key here.
[0234] 402-3. The key module sends the first encrypted data to SW1.
[0235] 402-4. SW1 decrypts the first encrypted data to obtain the first communication key.
[0236] For example, (1) SW1 obtains RN1 generated and sent by the key module and stored during the process of step 402-2, and RN2 generated during the process of step 402-2; (2) SW1 decrypts the first encrypted data with the corresponding private key to obtain the fourth ciphertext. (3) SW1 determines that the third ciphertext is the fourth ciphertext. The fourth ciphertext here is the one obtained in (2), and RN1 is the one obtained in (1). (4) SW1 generates the first temporary key as Both RN1 and RN2 here are the ones obtained in (1). (5) SW1 decrypts the third ciphertext determined in (3) with the first temporary key generated in (4) to obtain the first communication key. (6) SW1 stores the first communication key.
[0237] It can be seen from the above description that the key module periodically determines the security values of each switch based on the time-sensitive network. When the key module determines that the communication key of a certain switch based on the time-sensitive network needs to be updated, it will update the communication key and send the new communication key to the corresponding switch based on the time-sensitive network.
[0238] Subsequently, the switch based on the time-sensitive network can perform encrypted communication based on the latest communication key. Whenever the switch based on the time-sensitive network needs to send communication data, it will execute an encrypted communication method for a switch based on the time-sensitive network provided in this embodiment. The implementation process of this method is as Figure 2 shown, including:
[0239] 201, The switch based on the time-sensitive network obtains the first communication key.
[0240] Among them, the first communication key is generated by the key module according to the security value of the switch based on the time-sensitive network. The key module establishes a communication connection with the switch based on the time-sensitive network.
[0241] Taking the time-sensitive network switch SW1 that executes the encryption communication method of the time-sensitive network switch provided in this embodiment as an example, since the key module sends a new communication key of SW1 (to distinguish it from the communication keys of other time-sensitive network switches, the communication key of the time-sensitive network switch (such as SW1) that executes the encryption communication method of the time-sensitive network switch provided in this embodiment is denoted as the first communication key) to SW1 every time it generates one, and SW1 stores the first communication key. Therefore, in step 201, the time-sensitive network switch (such as SW1) can directly read the stored first communication key. If the first communication key is not stored, the time-sensitive network switch (such as SW1) can send a communication key generation request to the key module, and call the key module to execute steps 401 and 402 to generate a first communication key.
[0242] 202, The time-sensitive network switch encrypts the first communication data with the first communication key to obtain the first ciphertext.
[0243] For example, using an existing encryption algorithm, the first communication data is symmetrically encrypted with the first communication key to obtain the first ciphertext.
[0244] 203, The time-sensitive network switch generates a second ciphertext based on the first random number and the first ciphertext.
[0245] Among them, the first random number is pre-generated by the key module.
[0246] For example, SW1 obtains the RN1 generated and sent by the key module and stored during the process of step 402-2. SW1 generates the second ciphertext as the first ciphertext
[0247] 204, The time-sensitive network switch sends the second ciphertext.
[0248] This second ciphertext can be sent to other time-sensitive network switches.
[0249] The encryption communication method of the time-sensitive network switch provided in this embodiment encrypts and transmits the communication data through the communication key, ensuring the communication security of the time-sensitive network switch.
[0250] In addition, the time-sensitive network switch may also receive ciphertexts (such as the fifth ciphertext) sent by other time-sensitive network switches. At this time, the following steps 501-506 can be used to decrypt it to obtain the communication data.
[0251] The decryption process is the reverse of the encryption process in the above steps 201-204, and will not be elaborated here.
[0252] 501. After receiving the fifth ciphertext, the switch based on the time-sensitive network requests the second encrypted data from the key module.
[0253] The fifth ciphertext is sent by other switches based on the time-sensitive network. The second encrypted data is encrypted with the public key of the switch based on the time-sensitive network. The second encrypted data includes the sixth ciphertext, the third random number, and the fourth random number. The third random number is generated by the key module when generating the second encrypted data, and the fourth random number is generated by other switches based on the time-sensitive network triggered by the third random number. The sixth ciphertext is the ciphertext of the second communication key of other switches based on the time-sensitive network.
[0254] For example, the fifth ciphertext is generated and sent by SW2 by executing steps 201-204. After receiving the fifth ciphertext, SW1 will send the SW2 identifier to the key module, triggering the key module to 1) obtain, through the SW2 identifier, the communication key (here denoted as the second communication key) generated by the key module for SW2 through step 402, and the two random numbers involved when sending this communication key to SW2, namely the third random number (such as RN3) and the fourth random number (such as RN4), and encrypt the second communication key to obtain the ciphertext (here denoted as the sixth ciphertext); 2) the key module encrypts the sixth ciphertext, the third random number (such as RN3), and the fourth random number (such as RN4) with the public key of SW1 to form the second encrypted data; 3) the key module sends the second encrypted data to SW1.
[0255] 502. The switch based on the time-sensitive network decrypts the second encrypted data with its private key to obtain the sixth ciphertext, the third random number, and the fourth random number.
[0256] For example, SW1 decrypts the second encrypted data with the corresponding private key to obtain the sixth ciphertext, the third random number (such as RN3), and the fourth random number (such as RN4).
[0257] 503. The switch based on the time-sensitive network obtains the seventh ciphertext according to the third random number and the fifth ciphertext.
[0258] For example, SW1 determines that the seventh ciphertext is the fifth ciphertext The fifth ciphertext here is received in step 501, and RN3 is obtained in step 502.
[0259] 504. The switch based on the time-sensitive network determines the second temporary key according to the third random number and the fourth random number.
[0260] If SW1 determines that the second temporary key is Both RN3 and RN4 here are obtained in step 502.
[0261] 505. The switch based on the time-sensitive network decrypts the sixth ciphertext with the second temporary key to obtain the second communication key.
[0262] For example, SW1 decrypts the sixth ciphertext obtained in step 502 with the second temporary key generated in step 504 to obtain the second communication key.
[0263] 506. The switch based on the time-sensitive network decrypts the seventh ciphertext with the second communication key to obtain the second communication data.
[0264] For example, SW1 decrypts the seventh ciphertext obtained in step 503 with the second communication key obtained in step 505 to obtain the second communication data.
[0265] Thus, the decryption of the received ciphertext is completed, and the corresponding communication data (such as the second communication data) is obtained.
[0266] This embodiment provides an encrypted communication method for a switch based on a time-sensitive network. The switch based on the time-sensitive network obtains a first communication key; wherein, the first communication key is generated by a key module according to the security value of the switch based on the time-sensitive network; the key module establishes a communication connection with the switch based on the time-sensitive network; the switch based on the time-sensitive network encrypts the first communication data with the first communication key to obtain a first ciphertext; the switch based on the time-sensitive network generates a second ciphertext according to the first random number and the first ciphertext; wherein, the first random number is pre-generated by the key module; the switch based on the time-sensitive network sends the second ciphertext. This method ensures the communication security of the switch based on the time-sensitive network by encrypting the communication data.
[0267] Since the system / apparatus described in the above embodiments of the present invention is the system / apparatus adopted for implementing the method in the above embodiments of the present invention, based on the method described in the above embodiments of the present invention, those skilled in the art can understand the specific structure and variations of the system / apparatus, and thus will not be described in detail here. Any system / apparatus adopted by the method in the above embodiments of the present invention falls within the scope of protection of the present invention.
[0268] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0269] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions.
[0270] It should be noted that in the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the claims listing several means, several of these means can be embodied by the same piece of hardware. The use of the words first, second, third, etc. is only for convenience of expression and does not denote any order. These words can be understood as part of the name of the element.
[0271] In addition, it should be noted that in the description of this specification, the descriptions of terms such as "an embodiment", "some embodiments", "embodiments", "examples", "specific examples", or "some examples", etc. refer to the specific features, structures, materials, or characteristics described in connection with the embodiment or example being included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0272] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications after learning the basic creative concepts. Therefore, the claims should be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present invention.
[0273] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention should also cover these modifications and variations.
Claims
1. An encryption communication method for a switch based on a time-sensitive network, characterized in that, The method includes: A switch based on a time-sensitive network obtains a first communication key; wherein, the first communication key is generated by a key module according to the security value of the switch based on the time-sensitive network; the key module establishes a communication connection with the switch based on the time-sensitive network; The switch based on the time-sensitive network encrypts first communication data with the first communication key to obtain a first ciphertext; The switch based on the time-sensitive network generates a second ciphertext according to a first random number and the first ciphertext; wherein, the first random number is pre-generated by the key module; The switch based on the time-sensitive network sends the second ciphertext.
2. The method according to claim 1, wherein The method further includes: The key module determines whether the communication key update condition of the switch based on the time-sensitive network is satisfied; If it is satisfied, the key module generates a first communication key according to the security value of the switch based on the time-sensitive network, generates first encrypted data from the first communication key, and sends the first encrypted data to the switch based on the time-sensitive network, so that the switch based on the time-sensitive network stores the first communication key in the first encrypted data.
3. The method according to claim 2, characterized in that The generating the first communication key according to the security value of the switch based on the time-sensitive network includes: Generating a first random number; Generating a first communication key according to the first random number and the security value of the switch based on the time-sensitive network.
4. The method according to claim 2 or 3, characterized in that, The security value of the switch based on the time-sensitive network is determined through the following steps: Obtaining the transmission time of each data packet of the switch based on the time-sensitive network, the number of lost data packets, traffic data, vulnerability information, and the number of connected network devices; According to the transmission time of each data packet, determining the total number of data packets, the average transmission time of data packets, the maximum transmission time, and the minimum transmission time; Determining the packet loss rate according to the number of lost data packets and the total number of data packets; Determining a traffic anomaly value according to the traffic data; Determining a first impact value according to the vulnerability information; Determining a second impact value according to the number of connected network devices; Determining the security value of the switch based on the time-sensitive network according to the packet loss rate, the average transmission time of data packets, the maximum transmission time, the minimum transmission time, the traffic anomaly value, the first impact value, and the second impact value.
5. The method according to claim 4, wherein The determining the traffic anomaly value according to the traffic data includes: Sorting the traffic data in ascending order of the acquisition time to obtain a traffic sequence; Starting from the first element of the traffic sequence until the third element from the end, calculating the first difference of the numerical values between each element and the first element after it to obtain a first difference sequence; Starting from the first element of the traffic sequence until the third element from the end, calculating the second difference of the numerical values between each element and the second element after it to obtain a second difference sequence; Determining the traffic anomaly value according to the first difference sequence and the second difference sequence.
6. The method according to claim 4, wherein The determining the first impact value according to the vulnerability information includes: Determining the maximum value of the Common Vulnerability Scoring System scores of all vulnerabilities and the number of vulnerabilities with a score of not less than 7 according to the vulnerability information; Determining the first impact value according to the maximum score and the number of vulnerabilities with a score of not less than 7.
7. The method according to claim 4, wherein The determining the second impact value according to the number of connected network devices includes: Determine a second influence value according to the number of connected network devices and a preset unit weight.
8. The method according to claim 2, wherein The generating the first encrypted data from the first communication key includes: Transmit a first random number to a switch based on a time-sensitive network, so that the switch based on the time-sensitive network stores the first random number, generates and feeds back a second random number; Generate a first temporary key according to the first random number and the second random number; Encrypt the first communication key with the first temporary key to obtain a third ciphertext; Determine a fourth ciphertext according to the first random number and the third ciphertext; Encrypt the fourth ciphertext with the public key of the switch based on the time-sensitive network to obtain the first encrypted data.
9. The method according to claim 1, characterized in that The method further includes: After receiving a fifth ciphertext, the switch based on the time-sensitive network requests the second encrypted data from the key module; wherein, the fifth ciphertext is sent by other switches based on the time-sensitive network, the second encrypted data is encrypted with the public key of the switch based on the time-sensitive network, the second encrypted data includes a sixth ciphertext, a third random number and a fourth random number, wherein, the third random number is generated when the key module generates the second encrypted data, the fourth random number is generated by other switches based on the time-sensitive network triggered by the third random number, and the sixth ciphertext is the ciphertext of the second communication key of other switches based on the time-sensitive network; The switch based on the time-sensitive network decrypts the second encrypted data with its private key to obtain the sixth ciphertext, the third random number and the fourth random number; The switch based on the time-sensitive network obtains a seventh ciphertext according to the third random number and the fifth ciphertext; The switch based on the time-sensitive network determines a second temporary key according to the third random number and the fourth random number; The switch based on the time-sensitive network decrypts the sixth ciphertext with the second temporary key to obtain the second communication key; The switch based on the time-sensitive network decrypts the seventh ciphertext with the second communication key to obtain the second communication data.
10. An encryption communication system for a switch based on a time-sensitive network, characterized in that, The system includes: a plurality of switches based on the time-sensitive network and a key module; Each switch based on the time-sensitive network establishes a communication connection with the key module; Any switch based on the time-sensitive network is used to execute the steps executed by the switch based on the time-sensitive network in the method according to any one of claims 1-9; The key module is used to execute the steps executed by the key module in the method according to any one of claims 1-9.