Industrial internet covert communication method and system based on MQTT protocol
By using the subscription and publishing mode in the MQTT protocol, confidential data is blocked to the variable header of the PUBLISH message, the problem of insufficient security and effectiveness of hidden communication in the industrial Internet is solved, and the secure transmission of industrial data in open wireless links is realized.
Patent Information
- Application Number
- CN202510727387.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-18
AI Technical Summary
The existing industrial Internet covert communication technology has problems of insufficient security and effectiveness in industrial data transmission, especially in open wireless links, which are susceptible to monitoring and stealing, and existing methods are easily detected.
The MQTT protocol is used as the hidden communication carrier, and its subscription and publishing mode is used to modulate confidential data into the variable header of the PUBLISH message in blocks, and the topic name is shared through the clear channel to realize collaborative hidden communication in the industrial Internet.
It significantly improves the security and detection resistance of hidden communications in the industrial Internet, ensures that industrial data is safely transmitted to the cloud in open wireless links, and does not change the normal communication mode of MQTT to avoid affecting data transmission.
Smart Images

Figure CN120342769A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an industrial Internet covert communication method and system based on the MQTT protocol, and belongs to the technical field of network information security. Background Art
[0002] At present, the industrial Internet integrates various types of acquisition and control sensors or controllers with sensing and control capabilities into all links of the industrial production process through interconnected sensing and communication technologies, so as to reduce costs and increase efficiency, and promote the digital and intelligent transformation of industry. At present, the industrial data collected and transmitted in the industrial Internet mainly includes business data, production data, and environmental data. Among them, data such as the core process parameters of the entire product production process and the operating status of key equipment are the embodiment of value addition in the industrial production process and the core determining the difference of enterprises. However, with the wide application of the industrial Internet, such industrial data, as an important trade secret of manufacturing enterprises, may be monitored and stolen by competitors during the open wireless link transmission process from the industrial gateway to the cloud platform. Once the information is leaked, the enterprise will suffer heavy economic losses, affect its core market competitiveness, and even threaten its survival and development.
[0003] In response to the security threats faced by industrial data, covert communication technology means can be used to ensure its secure transmission. Network covert communication is a type of covert communication technology that uses legal network data streams as carriers for information hiding and modulates secret information in various ways. It can be mainly divided into two categories: storage type and time type. The storage type mainly utilizes the redundancy of network protocols to embed secret information in the protocol header or payload part. Such methods are simple and easy to implement, but most of them are easily detected because they change the original default values or rules of the protocol and lack security. The time type modulates secret information into the time behavior of network data streams. However, existing methods are prone to generate abnormal time characteristics or are easily interfered by network noises such as time delay and packet loss, affecting the effectiveness of covert communication. Therefore, how to improve the security and effectiveness of industrial Internet covert communication and seek a suitable covert communication carrier has become an urgent problem to be solved. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to overcome the deficiencies of the prior art and provide an industrial Internet covert communication method and system based on the MQTT protocol. By using the MQTT protocol as a covert communication carrier and designing an industrial Internet collaborative covert communication method using the subscription and publication modes of the MQTT protocol, the security and effectiveness of industrial Internet covert communication are significantly improved.
[0005] To solve the above technical problems, the technical solution of the present invention is:
[0006] On the one hand, the present invention provides an industrial Internet covert communication method based on the MQTT protocol, which includes the following steps:
[0007] Step S1: The covert communication sender and the covert communication receiver share the normal communication topic name topicj and the covert communication topic name topic^i through a clear channel, where j = 1, 2,..., k, and i = 1, 2,..., m; the covert communication receiver subscribes to the normal communication topic and the covert communication topic;
[0008] Step S2: The covert communication sender filters out the classified industrial data S from all the data collected from the production site;
[0009] Step S3: The covert communication sender divides the classified industrial data S into blocks to obtain classified data blocks s i ;
[0010] Step S4: The covert communication sender uses an encoder to modulate the classified data block s i into the message identifier field of the variable header of the PUBLISH message according to the agreed covert communication format, and encapsulates the encrypted PUBLISH message P_s with the topic name topic^i, and then publishes it to the MQTT server;
[0011] Step S5: The MQTT server pushes the encrypted PUBLISH message P_s to the covert communication receiver that has subscribed to the covert communication topic;
[0012] Step S6: The covert communication sender directly encapsulates the non-classified industrial data N into a normal PUBLISH message P_n with the topic name topicj, and then publishes it to the MQTT server;
[0013] Step S7: The MQTT server pushes the normal PUBLISH message P_n to the covert communication receiver that has subscribed to the normal communication topic;
[0014] Step S8: The covert communication receiver filters out the encrypted PUBLISH message (P_s i )' according to the covert communication topic name topic^i;
[0015] Step S9: The covert communication receiver uses a decoder to parse and obtain the classified industrial data block (s i )';
[0016] Step S10: The covert communication receiver combines the data blocks to obtain the complete classified industrial data S'.
[0017] Furthermore, the classified industrial data S includes product core process parameters and key equipment status information.
[0018] Further, the specific steps of step S4 are as follows:
[0019] Step S41: Set keywords including the core process parameters of the product and the device status information in the filter, and filter out the confidential industrial data S and the non-confidential industrial data N according to the keywords;
[0020] Step S42: For the non-confidential industrial data N = {n j | j = 1, 2, …, k}, directly encapsulate it into a normal PUBLISH message P_n j [topic j] according to the PUBLISH message format, where topic j is the normal communication topic name, and publish it to the MQTT server;
[0021] Step S43: Divide the industrial confidential data S into several data blocks s i according to the size of 8 bits, denoted as S = {s i | i = 1, 2, …, m}, where m is the number of blocks; the representation of each confidential data block s i is expressed as:
[0022]
[0023] where i = 1, 2, …, m; l = 1, 2,..., 8; s il is a binary data taking values of 0 or 1, and s i contains a total of 8 - bit binary numbers;
[0024] Step S44: Use the message identifier in the variable header of the PUBLISH message to construct a covert communication field;
[0025] Step S45: Write the covert communication topic name topic^i into the topic name field of the variable header of the PUBLISH message;
[0026] Step S46: Write the identity information id of the covert communication sender and the block sequence number i into the MSB of the message identifier;
[0027] Step S47: Write the confidential data block s i into the LSB of the message identifier;
[0028] Step S48: Publish the encrypted PUBLISH message P_s i [topic^i] encapsulated according to steps S45 - S47 to the MQTT server;
[0029] Step S49: Repeat steps S45 - S48 until all the confidential industrial data blocks are transmitted.
[0030] Further, the step S44 specifically includes the following steps:
[0031] Divide the most significant bit (MSB) of the message identifier into the identity information ID and the block sequence number Index, and the least significant bit (LSB) of the message identifier corresponds to the classified data block SB. Among them, ID and Index each occupy 4 bits in size, and SB occupies 8 bits in size.
[0032] Further, the step S9 specifically includes the following steps:
[0033] Step S91: The covert communication receiver subscribes to the normal communication topic name topic j and the covert communication topic name topic^;
[0034] Step S92: Receive the PUBLISH message messages of the normal communication topic and the covert communication topic pushed by the MQTT server;
[0035] Step S93: According to the covert communication topic name topic^i, filter the encrypted PUBLISH message message (P_s i [topic^i])';
[0036] Step S94: Analyze the message identifier MSB field in the variable header of the PUBLISH message, and perform identity authentication according to the high four-bit data ID = id;
[0037] Step S95: If the identity authentication fails, return to step S93 for execution;
[0038] Step S96: If the identity authentication passes, analyze the low four-bit data of the message identifier MSB to obtain the block sequence number Index = i;
[0039] Step S97: Analyze the message identifier LSB field in the variable header of the PUBLISH message to obtain the classified data block (s i )';
[0040] Step S98: Repeat steps S93 to S97 until all classified data blocks are decoded;
[0041] Step S99: Combine the data blocks to obtain the complete industrial classified data S' = {(s i )'|i = 1, 2,..., m}.
[0042] On the other hand, the present invention provides a system for an industrial Internet covert communication method based on the MQTT protocol, which includes an industrial gateway, a data middle platform, and an industrial cloud platform. The industrial gateway transmits data to the industrial cloud platform through the data middle platform. The covert communication sender is located inside the industrial gateway, and the covert communication receiver is located inside the industrial cloud platform.
[0043] Adopting the above technical solution, the present invention has the following beneficial effects:
[0044] The present invention uses the MQTT protocol as the carrier for covert communication in the industrial Internet of Things. It itself has advantages such as low overhead, low bandwidth occupancy, low power consumption, low latency, and high reliability. On the premise of ensuring the normal transmission of industrial field data from the gateway to the cloud platform, according to the publish / subscribe communication mode of the MQTT protocol, the classified industrial data is modulated into the variable header of the PUBLISH message in blocks, without changing the normal communication mode of MQTT and the default attributes of the protocol fields, and does not affect the transmission of industrial data to the cloud, and can effectively resist the detection of various steganalysis methods. Therefore, the present invention can significantly improve the anti-detection ability and security of the covert communication system in the industrial Internet of Things. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 is a flowchart of the method for covert communication in the industrial Internet of Things based on the MQTT protocol of the present invention;
[0046] Figure 2 is a schematic diagram of the covert communication process based on the PUBLISH message of the present invention;
[0047] Figure 3 is the covert communication field format based on the variable header of the PUBLISH message of the present invention;
[0048] Figure 4 is a flowchart of the encoding algorithm for step S4 of the present invention;
[0049] Figure 5 is a flowchart of the decoding algorithm for step S0 of the present invention;
[0050] Figure 6 is a schematic block diagram of the principle of the covert communication system in the industrial Internet of Things based on the MQTT protocol of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] In order to make the content of the present invention easier to be clearly understood, the present invention will be further described in detail below according to specific embodiments in conjunction with the accompanying drawings.
[0052] Embodiment 1
[0053] This embodiment provides an industrial Internet covert communication method based on the MQTT protocol. MQTT is a lightweight message transmission protocol based on the publish / subscribe model, specifically designed for industrial Internet applications with low bandwidth and unstable network environments. It can provide real-time and reliable message services for networked devices with minimal code and limited bandwidth. It is an instant messaging protocol with low overhead and low bandwidth occupancy and has currently become the main transmission means for industrial Internet data to be uploaded to the cloud. Therefore, the MQTT protocol has become a potential excellent carrier for industrial Internet covert communication.
[0054] The industrial Internet covert communication method based on the MQTT protocol in this embodiment utilizes the subscription / publish model of the MQTT protocol to design a covert communication method: the publisher constructs a covert communication data format in the variable header of the PUBLISH control message, and under different topics, embeds the classified industrial data in chunks into the most significant bit (MSB) and least significant bit (LSB) of the message identifier field. Multiple subscribers parse and jointly combine the data according to the covert communication data format to obtain the complete classified data.
[0055] Since this method does not change the normal communication mode of MQTT and the default attributes of the protocol fields, it fully meets the normal mode of MQTT protocol message publishing and does not affect the transmission of industrial data to the cloud. Therefore, it can effectively resist the detection of various steganalysis methods. Therefore, the present invention aims to provide an industrial Internet covert communication technical means with strong anti-detection ability to improve the security of classified industrial data transmission to the cloud in an open wireless link.
[0056] The industrial Internet covert communication method based on the MQTT protocol in this embodiment, as Figure 1 shown, includes the following steps:
[0057] Step S1: The covert communication sender and the covert communication receiver share the normal communication topic name topicj and the covert communication topic name topic^i through a clear channel, where j = 1, 2,... k, i = 1, 2,..., m; the covert communication receiver subscribes to the normal communication topic and the covert communication topic;
[0058] Step S2: The covert communication sender filters out the classified industrial data S from all the data collected from the production site;
[0059] Step S3: The covert communication sender divides the classified industrial data S into chunks. The classified industrial data S includes product core process parameters and key equipment status information, and obtains the classified data chunks s i ;
[0060] Step S4: The covert communication sender uses an encoder to, according to the agreed covert communication format, process the classified data chunks s iModulate it into the message identifier field of the PUBLISH message variable header, encapsulate the encrypted PUBLISH message P_s with the topic name topic^i, and then publish it to the MQTT server;
[0061] Step S5: The MQTT server pushes the encrypted PUBLISH message P_s to the covert communication receiver that has subscribed to the covert communication topic;
[0062] Step S6: The covert communication sender directly encapsulates the general non-confidential industrial data N into a normal PUBLISH message P_n with the topic name topicj, and then publishes it to the MQTT server;
[0063] Step S7: The MQTT server pushes the normal PUBLISH message P_n to the covert communication receiver that has subscribed to the normal communication topic;
[0064] Step S8: The covert communication receiver filters out the encrypted PUBLISH message (P_s i )' according to the covert communication topic name topic^i;
[0065] Step S9: The covert communication receiver uses the decoder to parse and obtain the classified industrial data block (s i )';
[0066] Step S10: The covert communication receiver combines the data blocks to obtain the complete classified industrial data S'.
[0067] As Figure 4 shown, step S4 of this embodiment specifically includes the following steps:
[0068] Step S41: Set keywords containing the product core process parameters and equipment status information in the filter, and filter out the classified industrial data S and non-classified industrial data N according to the keywords;
[0069] Step S42: As Figure 2 shown, for the non-classified industrial data N = {n j |j = 1, 2,..., k}, directly encapsulate it into a normal PUBLISH message P_n j [topic j] according to the PUBLISH message format, where topic j is the normal communication topic name, and publish it to the MQTT server;
[0070] Step S43: Divide the industrial classified data S into several data blocks s i according to 8-bit size, denoted as S = {s i |i = 1, 2,..., m}, where m is the number of blocks; the representation of each classified data block s i is in the formula:
[0071]
[0072] where i = 1, 2, …, m; l = 1, 2, …, 8; s il is binary data taking values 0 or 1, and s i in total contains 8 bits of binary numbers;
[0073] Step S44, as Figure 3 shown, use the message identifier in the variable header of the PUBLISH message to construct a covert communication field, specifically: divide the MSB of the message identifier into the identity information ID and the block sequence number Index, and the LSB of the message identifier corresponds to the classified data block SB, where ID and Index each occupy 4 bits in size, and SB occupies 8 bits in size;
[0074] Step S45, write the covert communication topic name topic^i into the topic name field of the variable header of the PUBLISH message;
[0075] Step S46, write the identity information id of the covert communication sender and the sequence number i into the MSB of the message identifier;
[0076] Step S47, write the classified data block s i into the LSB of the message identifier;
[0077] Step S48, as Figure 2 shown, publish the encrypted PUBLISH message P_s i [topic^i] encapsulated according to Steps S45 to S47 to the MQTT server;
[0078] Step S49, repeatedly execute Steps S45 to S48 until all classified industrial data blocks are transmitted.
[0079] As Figure 5 shown, Step S9 in this embodiment specifically includes the following steps:
[0080] Step S91, the covert communication receiver subscribes to the normal communication topic name topoc j and the covert communication topic name topoc^i;
[0081] Step S92, receive the PUBLISH message of the normal communication topic and the covert communication topic pushed by the MQTT server;
[0082] Step S93, filter the encrypted PUBLISH message (P_s i [topic^i]) according to the covert communication topic name topic^i;
[0083] Step S94: Analyze the message identifier MSB field in the variable header of the PUBLISH message, and perform identity authentication based on the high four-bit data ID = id;
[0084] Step S95: If the identity authentication fails, return to Step S93 for execution;
[0085] Step S96: If the identity authentication passes, analyze the low four-bit data of the message identifier MSB to obtain the block sequence number Index = i;
[0086] Step S97: Analyze the message identifier LSB field in the variable header of the PUBLISH message to obtain the classified data block (s i )';
[0087] Step S98: Repeat Steps S93 to S97 until all classified data blocks are decoded;
[0088] Step S99: Combine the data blocks to obtain the complete industrial classified data S' = {(s i )'|i = 1, 2,..., m}.
[0089] Embodiment 2
[0090] As Figure 6 shown, this embodiment provides a system that applies the industrial Internet covert communication method based on the MQTT protocol in Embodiment 1. Taking the MQTT protocol as the covert communication carrier in the industrial Internet, based on the in-depth analysis of its system structure, communication mode, and protocol, a collaborative covert communication system for the industrial Internet based on the MQTT protocol is designed.
[0091] The system includes an industrial gateway, a data middle platform, and an industrial cloud platform. The industrial gateway transmits data to the industrial cloud platform through the data middle platform. The covert communication sender is located inside the industrial gateway and is the message publisher of the MQTT client; the covert communication receiver is located inside the industrial cloud platform and is the message subscriber of the MQTT client; both parties use this system to achieve the secure transmission of industrial classified data.
[0092] The above specific embodiments have further elaborated on the technical problems solved, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. An industrial Internet covert communication method based on the MQTT protocol, characterized in that, It includes the following steps: Step S1: The sender of covert communication and the receiver of covert communication share the normal communication topic name topic j and the covert communication topic name topic^i through the clear channel, where j = 1, 2,..., k and i = 1, 2,..., m; the receiver of covert communication subscribes to the normal communication topic and the covert communication topic; Step S2: From all the data collected by the sender of covert communication from the production site, filter out the classified industrial data S; Step S3: The sender of the covert communication divides the classified industrial data S into blocks to obtain classified data blocks s i ; Step S4: The covert communication sender uses an encoder to modulate the classified data block s into the message identifier field of the variable header of the PUBLISH message according to the agreed covert communication format, and encapsulates the encrypted PUBLISH message P_s with the topic name topic^i, and then publishes it to the MQTT server; i Modulate it into the message identifier field of the variable header of the PUBLISH message according to the agreed covert communication format, and encapsulate the encrypted PUBLISH message P_s with the topic name topic^i, and then publish it to the MQTT server; Step S5: The MQTT server pushes the encrypted PUBLISH message P_s to the receiver of covert communication that has subscribed to the covert communication topic; Step S6: For the non-classified industrial data N, the sender of covert communication directly encapsulates it into a normal PUBLISH message P_n with the topic name topic j, and then publishes it to the MQTT server; Step S7: The MQTT server pushes the normal PUBLISH message P_n to the receiver of covert communication that has subscribed to the normal communication topic; Step S8: The covert communication receiver filters out the encrypted PUBLISH messages (P_s i )' according to the covert communication topic name topic^i; Step S9: The covert communication receiver uses a decoder to parse and obtain the classified industrial data chunks (s i )'. Step S10: The receiver of covert communication combines the data in chunks to obtain the complete classified industrial data S'; 2. The industrial Internet covert communication method based on the MQTT protocol according to claim 1, characterized in that: The classified industrial data S includes product core process parameters and key equipment status information.
3. The industrial Internet covert communication method based on the MQTT protocol according to claim 1, characterized in that, The specific steps of step S4 are as follows: Step S41: Set keywords containing product core process parameters and equipment status information in the filter, and filter out the classified industrial data S and the non-classified industrial data N according to the keywords; Step S42. For non-confidential industrial data N = {n j | j = 1, 2,..., k}, directly encapsulate it into a normal PUBLISH message P_n j [topic j] according to the PUBLISH message format, where topic j is the normal communication topic name, and publish it to the MQTT server; Step S43: Divide the industrial confidential data S into several data blocks s according to the size of 8 bits i , denoted as S = {s i | i = 1, 2,..., m}, where m is the number of blocks; the representation of each confidential data block s i is given by the formula: where i = 1, 2, …, m; l = 1, 2, ..., 8; s il is binary data taking values of 0 or 1, and s i altogether contains 8 bits of binary numbers; Step S44: Use the message identifier in the variable header of the PUBLISH message to construct the covert communication field; Step S45: Write the covert communication topic name topic^i into the topic name field of the variable header of the PUBLISH message; Step S46: Write the identity information id of the sender of covert communication and the chunk sequence number i into the most significant bits (MSB) of the message identifier; Step S47: Divide the classified data into blocks s i Write to the least significant bit of the message identifier; Step S48: Publish the encrypted PUBLISH message P_s encapsulated according to Steps S45 - S47 i to the MQTT server on [topic^i]; Step S49: Repeat steps S45 to S48 until all chunks of classified industrial data are transmitted; 4. The industrial Internet covert communication method based on the MQTT protocol according to claim 3, characterized in that, The specific steps of step S44 are as follows: Divide the message identifier MSB into the identity information ID and the chunk sequence number Index, and the least significant bits (LSB) of the message identifier correspond to the classified data chunk SB, where ID and Index each occupy 4 bits in size, and SB occupies 8 bits in size.
5. The industrial Internet covert communication method based on the MQTT protocol according to claim 1, characterized in that The specific steps of step S9 are as follows: Step S91: The receiver of covert communication subscribes to the normal communication topic name topic j and the covert communication topic name topic^i; Step S92: Receive the PUBLISH message of the normal communication topic and the covert communication topic pushed by the MQTT server; Step S93. Screen the encrypted PUBLISH message (P_s i [topoc^i])' according to the covert communication topic name topic^i; Step S94: Parse the message identifier MSB field in the variable header of the PUBLISH message, and perform identity authentication according to the high four-bit data ID = id; Step S95: If the identity authentication fails, return to step S93 for execution; Step S96: If the identity authentication passes, parse the low four-bit data of the message identifier MSB to obtain the chunk sequence number Index = i; Step S97: Analyze the least significant bit (LSB) field of the message identifier in the variable header of the PUBLISH message to obtain the classified data block (s i )'; Step S98: Repeat steps S93 to S97 until all chunks of classified data are decoded; Step S99: Combine the data in chunks to obtain the complete industrial confidential data S' = {(s i )'| i = 1, 2,..., m}.
6. A system applying the industrial Internet covert communication method based on the MQTT protocol as described in any one of claims 1 to 5, characterized in that: It includes an industrial gateway, a data middle platform, and an industrial cloud platform. The industrial gateway transmits data to the industrial cloud platform through the data middle platform. The sender of the covert communication is located within the industrial gateway, and the receiver of the covert communication is located within the industrial cloud platform.