Cloud data intelligent transceiving encryption and decryption method and system

By using AES encryption algorithm to encrypt and decrypt user data and server instructions in the Internet of Things system, the security risks of user data during transmission are solved, the security of data transmission and the convenience of modular design are achieved, and user trust and development efficiency are improved.

CN120389856APending Publication Date: 2025-07-29WUHAN GUOTIAN ZHIYUAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510522781.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the development of the Internet of Things, user data has security risks in the communication process between the client and the server, especially when sensitive data is transmitted, and the existing plain text transmission methods lack security guarantees.

Method used

The AES encryption algorithm is used to encrypt and decrypt user data and server instructions, and intelligent data transmission and reception are realized between the user and server through modular design. The encryption algorithm includes symmetric encryption and packet password to ensure the security of data during network transmission.

Benefits of technology

Effectively protect the confidentiality of user data during transmission, reduce the risk of stealing or tampering, improve the security and user trust of IoT applications, and at the same time, modular design simplifies the development process, reduces complexity and costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389856A_ABST
    Figure CN120389856A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, and discloses a cloud data intelligent transceiving encryption and decryption method and system, comprising a method for sending a message from a user side to a server side and a method for sending a message from the server side to the user side. The method for sending the message to the server side by the user side comprises the following steps: A1, a user sends a user instruction to an Internet of Things application module through a serial port UART interface of the user side; a2, the AP unit receives user instruction data from a serial port UART and sends the data to a first AES calculation module through an SPI interface; the AES encryption algorithm is used for encrypting and decrypting the user data and the server instruction, it is ensured that plaintext transmission is avoided in network transmission, the risk that the user data is stolen or tampered in the transmission process is greatly reduced, the AES encryption algorithm is a symmetric encryption algorithm, high-strength safety is achieved, the confidentiality of the data can be effectively protected, and the security of the user data is improved. The security of data transmission is improved, and the trust degree and satisfaction degree of the user to the Internet of Things application can be enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and particularly to a method and system for intelligent sending, receiving, encrypting and decrypting of cloud data. Background Technique

[0002] In the process of communication between the client and the server during the development of the Internet of Things, user data is usually exposed to the Internet. In the case of sensitive data, there are great security risks for user data. Therefore, we propose to use encryption for data transmission during the communication between the client and the server, which greatly protects the security of user data and reduces the risk of exposure of user data.

[0003] In the existing development of the Internet of Things, user data is usually transmitted in plain text when sent to the cloud server, which provides no security guarantee for user data. The server also sends instructions to the user side in plain text. When sensitive data is involved, user data is very easy to leak, which may cause inestimable losses to users. Therefore, a method and system for intelligent sending, receiving, encrypting and decrypting of cloud data are proposed. Summary of the Invention

[0004] The purpose of the present invention is to provide a method and system for intelligent sending, receiving, encrypting and decrypting of cloud data to solve the problems raised in the above background technique.

[0005] To achieve the above purpose, the present invention provides the following technical solution: A method for intelligent sending, receiving, encrypting and decrypting of cloud data, including a method for the user side to send a message to the server side and a method for the server side to send a message to the user side.

[0006] Preferably, the method for the user side to send a message to the server side includes the following steps:

[0007] A1. The user sends a user instruction to the Internet of Things application module through the serial port UART interface of the user side;

[0008] A2. The AP unit receives the user instruction data from the serial port UART and sends the data to the first AES calculation module through the SPI interface;

[0009] A3. The first AES calculation module receives the data from the AP unit, encrypts the data using the AES encryption algorithm to generate encrypted data, and then returns the encrypted data to the AP unit through the SPI interface;

[0010] A4. After the AP unit receives the encrypted data returned by the first AES calculation module, it transparently transmits the encrypted data to the CP unit;

[0011] A5. The CP unit receives the encrypted data from the AP unit and sends the encrypted data to the server terminal through the cloud server via the LWM2M protocol;

[0012] A6. The server terminal receives the encrypted data from the CP unit, decrypts the data through the built-in second AES calculation module, restores the plaintext data, and uses the plaintext data for application processing on the server side.

[0013] Preferably, the method for the server side to send a message to the user side includes the following steps:

[0014] B1. The server side sends the instruction data to be sent to the user side to its built-in second AES calculation module;

[0015] B2. The second AES calculation module receives the instruction data from the server side, encrypts the data using the AES encryption algorithm to generate the encrypted data, and then sends the encrypted data to the cloud server;

[0016] B3. The cloud server receives the encrypted data from the second AES calculation module and sends the encrypted data to the CP unit in the IoT application module via the LWM2M protocol;

[0017] B4. After receiving the encrypted data from the cloud server, the CP unit transparently transmits the data to the AP unit;

[0018] B5. The AP unit receives the encrypted data from the CP unit and sends the encrypted data to the first AES calculation module through the SPI interface;

[0019] B6. The first AES calculation module receives the encrypted data from the AP unit, decrypts the data, restores the plaintext data, and then returns the decrypted plaintext data to the user side through the serial port UART interface.

[0020] Preferably, in the above-mentioned method for the user side to send a message to the server side and the method for the server side to send a message to the user side, the specific implementation of the AES encryption algorithm includes symmetric encryption and block cipher.

[0021] Preferably, the above-mentioned symmetric encryption and block cipher include the following steps:

[0022] C1. Byte substitution: Replace each byte of the plaintext data with another byte by looking up a table (S-box);

[0023] C2. Row shift: Perform a cyclic left shift operation on the 4×4 byte matrix after byte substitution, and the number of shifts for different rows is different;

[0024] C3. Column mixing: Perform a linear transformation on each column of the matrix to make the data in each column correlated with the data in other columns;

[0025] C4. Round key addition: XOR the matrix after byte substitution, row shift, and column mixing with the round key of the current round to complete one round of encryption.

[0026] The present invention also provides a system for the intelligent transceiver encryption and decryption method of cloud data, including a user terminal, an Internet of Things application module, a first AES calculation module, a cloud server, a server terminal, and a service end;

[0027] The user terminal is used for inputting and sending user instructions;

[0028] The Internet of Things application module is used for processing user instructions and communicating with the cloud server;

[0029] The first AES calculation module is used for encrypting the data received from the AP unit and decrypting the data received from the CP unit;

[0030] The cloud server is used for receiving the data from the Internet of Things application module, storing and forwarding it, and sending data to the Internet of Things application module;

[0031] The server terminal is used for processing the decrypted data, executing the corresponding service logic, and generating the data to be sent to the Internet of Things application module;

[0032] The service end is used for communicating with the CP unit of the Internet of Things application module and transmitting the encrypted data.

[0033] Preferably, the above: the user terminal is connected to the Internet of Things application module, the Internet of Things application module is respectively connected to the first AES calculation module and the cloud server, the cloud server is connected to the server terminal, and the server terminal is connected to the service end.

[0034] Preferably, the above: the Internet of Things application module includes an AP unit and a CP unit;

[0035] The AP unit is used for receiving the user instructions input by the user terminal and communicating with the first AES calculation module and the CP unit;

[0036] The CP unit is used for sending the encrypted data to the cloud server through the communication network and receiving the encrypted data from the cloud server.

[0037] Preferably, the above: the AP unit is connected to the CP unit, the AP unit is connected to the first AES calculation module, and the CP unit is connected to the first AES calculation module.

[0038] Preferably, the server terminal includes a second AES calculation module;

[0039] The second AES calculation module is used to decrypt the data received from the CP unit and encrypt the data sent to the CP unit.

[0040] Compared with the prior art, the present invention adopts the above technical solution and has the following technical effects:

[0041] First, the AES encryption algorithm is used to encrypt and decrypt user data and server instructions to ensure that plaintext transmission is avoided during network transmission, greatly reducing the risk of user data being stolen or tampered with during transmission. The AES encryption algorithm is a symmetric encryption algorithm with high-intensity security, which can effectively protect the confidentiality of data, improve the security of data transmission, and enhance users' trust and satisfaction with Internet of Things applications.

[0042] Second, the present invention adopts a modular design, including modules such as a user terminal, an Internet of Things application module, an AP unit, a CP unit, a first AES calculation module, a cloud server, a server terminal, and a server end. The modular design makes the interfaces between modules clear, easy to integrate and debug, reduces the complexity and cost of Internet of Things development, and also facilitates subsequent function expansion and upgrade. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 It is a schematic diagram of the module connection of the present invention;

[0045] Figure 2 It is a flowchart of the AES algorithm encryption process of the present invention;

[0046] Figure 3 It is a schematic diagram of the first Internet of Things application module of the present invention;

[0047] Figure 4 It is a schematic diagram of the second Internet of Things application module of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] It should be noted that the structures, ratios, sizes, etc. shown in the drawings of this specification are only used to cooperate with the content disclosed in the specification for those who are familiar with this technology to understand and read, and are not used to limit the limiting conditions that can be implemented in this application. Therefore, they do not have substantial technical significance. Any modification of the structure, change of the proportional relationship, or adjustment of the size should still fall within the scope that can be covered by the technical content disclosed in this application without affecting the effects that this application can produce and the purposes that can be achieved.

[0050] Embodiment

[0051] Please refer to Figures 1-4 , the present invention provides a technical solution: a cloud data intelligent transceiver encryption and decryption method, including a method for the user terminal to send a message to the server terminal and a method for the server terminal to send a message to the user terminal.

[0052] The method for the user terminal to send a message to the server terminal includes the following steps:

[0053] A1. The user sends a user instruction to the Internet of Things application module through the serial port UART interface of the user terminal;

[0054] A2. The AP unit receives the user instruction data from the serial port UART and sends the data to the first AES calculation module through the SPI interface;

[0055] A3. The first AES calculation module receives the data from the AP unit, encrypts the data using the AES encryption algorithm to generate encrypted data, and then returns the encrypted data to the AP unit through the SPI interface;

[0056] A4. After the AP unit receives the encrypted data returned by the first AES calculation module, it transparently transmits the encrypted data to the CP unit;

[0057] A5. The CP unit receives the encrypted data from the AP unit and sends the encrypted data to the server terminal through the cloud server using the LWM2M protocol;

[0058] A6. The server terminal receives the encrypted data from the CP unit, decrypts the data using the built-in second AES calculation module to restore the plaintext data, and uses the plaintext data for application processing on the server side.

[0059] The method for the server to send messages to the client includes the following steps:

[0060] B1. The server sends the instruction data to be sent to the client to its built-in second AES calculation module.

[0061] B2. The second AES calculation module receives the instruction data from the server, encrypts the data using the AES encryption algorithm to generate encrypted data, and then sends the encrypted data to the cloud server.

[0062] B3. The cloud server receives the encrypted data from the second AES calculation module and sends the encrypted data to the CP unit in the IoT application module through the LWM2M protocol.

[0063] B4. After receiving the encrypted data from the cloud server, the CP unit transparently transmits the data to the AP unit.

[0064] B5. The AP unit receives the encrypted data from the CP unit and sends the encrypted data to the first AES calculation module through the SPI interface.

[0065] B6. The first AES calculation module receives the encrypted data from the AP unit, decrypts the data to recover the plaintext data, and then sends the decrypted plaintext data back to the client through the serial port UART interface.

[0066] The specific implementation of the AES encryption algorithm in the method for the client to send messages to the server and the method for the server to send messages to the client includes symmetric encryption and block cipher.

[0067] Symmetric encryption: It belongs to the symmetric encryption algorithm, which means that the same key is used for encryption and decryption. During the encryption process, the plaintext is converted into ciphertext through a specific algorithm and key; during decryption, the ciphertext is restored to the plaintext through the same key and inverse algorithm.

[0068] Block cipher: It is a block cipher algorithm that divides the plaintext data into fixed-length blocks, and each block is independently encrypted. The block length of AES is fixed at 128 bits, that is, 16 bytes. The AES encryption algorithm is respectively built inside the first AES calculation module and the second AES calculation module.

[0069] The AES encryption algorithm is mainly used to implement the functions of encrypting and decrypting user data or server instructions, and avoid transmitting plaintext in network transmission to ensure the security of user data; the AES encryption algorithm supports the following functions in terms of hardware: supporting decryption key expansion; supporting key lengths of 128bit / 192bit / 256bit; supporting ECB, CBC, CTR, GCM; supporting DMA for automatic data transmission; supporting multiplication in the GF(2^128) field and supporting GMAC.

[0070] Symmetric encryption and block ciphers include the following steps:

[0071] C1. Byte substitution: Each byte of the plaintext data is replaced by another byte through a lookup table (S-box) to achieve confusion of the plaintext data;

[0072] C2. Row shift: Perform a left circular shift operation on the 4×4 byte matrix after byte substitution. The number of shifts for different rows is different to further disrupt the order of the data;

[0073] C3. Column mixing: Perform a linear transformation on each column of the matrix to make the data in each column related to the data in other columns, increasing the complexity of the ciphertext;

[0074] C4. Round key addition: Perform an exclusive OR operation on the matrix after byte substitution, row shift, and column mixing with the round key of the current round to complete one round of encryption.

[0075] In different encryption modes, the number of rounds of the AES algorithm is different. Generally, it is 10 rounds, 12 rounds, or 14 rounds.

[0076] The key length of the AES algorithm can be 128 bits, 192 bits, or 256 bits. The purpose of key expansion is to generate the round keys required for each round in the encryption process from the initial key;

[0077] The key expansion algorithm is based on a non-linear transformation and circular shift operation to expand the initial key into a key sequence, where each round key is a part of this sequence.

[0078] Through strict security analysis and testing, no effective cracking method has been found for the AES algorithm so far. It can effectively resist various known cryptographic attacks, such as differential attacks, linear attacks, etc. The AES algorithm has high efficiency in both software and hardware implementations, can quickly complete encryption and decryption operations, is suitable for encrypting a large amount of data, and the AES supports multiple key lengths. Users can choose an appropriate key length according to actual needs to balance security and performance.

[0079] The present invention also provides a system for an intelligent cloud data sending, receiving, encrypting, and decrypting method, including a user terminal, an Internet of Things application module, a first AES calculation module, a cloud server, a server terminal, and a service end; the user terminal is connected to the Internet of Things application module, the Internet of Things application module is respectively connected to the first AES calculation module and the cloud server, the cloud server is connected to the server terminal, and the server terminal is connected to the service end.

[0080] The user terminal is used for inputting and sending user instructions;

[0081] The Internet of Things application module is used to process user instructions and communicate with the cloud server;

[0082] The Internet of Things application module includes an AP unit and a CP unit;

[0083] The AP unit is used to receive user instructions input by the user terminal and communicate with the first AES calculation module and the CP unit;

[0084] The CP unit is used to send the encrypted data to the cloud server through the communication network and receive the encrypted data from the cloud server.

[0085] The AP unit is connected to the CP unit, the AP unit is connected to the first AES calculation module, and the CP unit is connected to the first AES calculation module.

[0086] The first AES calculation module is used to encrypt the data received from the AP unit and decrypt the data received from the CP unit;

[0087] The cloud server is used to receive the data from the Internet of Things application module, store and forward it, and send data to the Internet of Things application module;

[0088] The server terminal is used to process the decrypted data, execute the corresponding service logic, and generate the data to be sent to the Internet of Things application module;

[0089] The server terminal includes a second AES calculation module;

[0090] The second AES calculation module is used to decrypt the data received from the CP unit and encrypt the data sent to the CP unit.

[0091] The server is used to communicate with the CP unit of the Internet of Things application module and transmit the encrypted data.

[0092] The AP unit is connected to the first AES calculation module through the SPI interface, and the CP unit is responsible for data transmission with the cloud server through the communication network, such as the LWM2M protocol.

[0093] In summary, the AES encryption algorithm is used to encrypt and decrypt user data and server instructions to ensure that plaintext transmission is avoided during network transmission, greatly reducing the risk of user data being stolen or tampered with during transmission. The AES encryption algorithm is a symmetric encryption algorithm with high-intensity security, which can effectively protect the confidentiality of data, improve the security of data transmission, and enhance users' trust and satisfaction with the Internet of Things application.

[0094] The present invention adopts a modular design, including a user terminal, an Internet of Things application module, an AP unit, a CP unit, a first AES calculation module, a cloud server, a server terminal, a service end and other modules. The modular design makes the interfaces between the various modules clear, easy to integrate and debug, reduces the complexity and cost of Internet of Things development, and also facilitates subsequent function expansion and upgrade.

[0095] Those skilled in the art can understand that the features recited in the various embodiments and / or claims of the present invention can be combined or combined in various ways, even if such combinations or combinations are not explicitly recited in the present invention. In particular, without departing from the spirit and teachings of the present invention, the features recited in the various embodiments and / or claims of the present invention can be combined and combined in various ways. All such combinations and / or combinations fall within the scope of the present invention.

Claims

1. A method for intelligent transceiver encryption and decryption of cloud data, characterized in that, It includes a method for the client to send messages to the server and a method for the server to send messages to the client.

2. The intelligent receiving, sending, encrypting and decrypting method for cloud data according to claim 1, wherein: The method for the client to send messages to the server includes the following steps: A1. The user sends a user instruction to the Internet of Things application module through the serial port UART interface of the client. A2. The AP unit receives the user instruction data from the serial port UART and sends the data to the first AES calculation module through the SPI interface. A3. The first AES calculation module receives the data from the AP unit, encrypts the data using the AES encryption algorithm to generate encrypted data, and then returns the encrypted data to the AP unit through the SPI interface. A4. After receiving the encrypted data returned by the first AES calculation module, the AP unit transparently transmits the encrypted data to the CP unit. A5. The CP unit receives the encrypted data from the AP unit and sends the encrypted data to the server terminal through the cloud server using the LWM2M protocol. A6. The server terminal receives the encrypted data from the CP unit, decrypts the data using the built-in second AES calculation module to recover the plaintext data, and uses the plaintext data for application processing on the server side.

3. A cloud data intelligent transceiver encryption and decryption method according to claim 2, characterized in that: The method for the server to send messages to the client includes the following steps: B1. The server sends the instruction data to be sent to the client to its built-in second AES calculation module. B2. The second AES calculation module receives the instruction data from the server, encrypts the data using the AES encryption algorithm to generate encrypted data, and then sends the encrypted data to the cloud server. B3. The cloud server receives the encrypted data from the second AES calculation module and sends the encrypted data to the CP unit in the Internet of Things application module through the LWM2M protocol. B4. After receiving the encrypted data from the cloud server, the CP unit transparently transmits the data to the AP unit. B5. The AP unit receives the encrypted data from the CP unit and sends the encrypted data to the first AES calculation module through the SPI interface. B6. The first AES calculation module receives the encrypted data from the AP unit, decrypts the data to recover the plaintext data, and then returns the decrypted plaintext data to the client through the serial port UART interface.

4. A cloud data intelligent transceiver encryption and decryption method according to claim 3, characterized in that: The specific implementation of the AES encryption algorithm in the method for the client to send messages to the server and the method for the server to send messages to the client includes symmetric encryption and block ciphers.

5. The intelligent cloud data transceiver encryption and decryption method according to claim 4, characterized in that: The symmetric encryption and block ciphers include the following steps: C1. Byte substitution: Each byte of the plaintext data is replaced by another byte through a lookup table (S-box). C2. Row shift: Perform a row cyclic left shift operation on the 4×4 byte matrix after byte substitution, and the number of shifts for different rows is different. C3. Column mixing: Perform a linear transformation on each column of the matrix to make the data in each column related to the data in other columns. C4. Round key addition: Perform an exclusive OR operation on the matrix after byte substitution, row shift, and column mixing with the round key of the current round to complete one round of encryption.

6. A system for the intelligent transceiver encryption and decryption method of cloud data according to any one of claims 1-5, characterized in that, It includes a client, an Internet of Things application module, a first AES calculation module, a cloud server, a server terminal, and a server. The client is used for inputting and sending user instructions; The Internet of Things application module is used for processing user instructions and communicating with the cloud server; The first AES calculation module is used for encrypting the data received from the AP unit and decrypting the data received from the CP unit; The cloud server is used for receiving the data from the Internet of Things application module, storing and forwarding it, and sending data to the Internet of Things application module; The server terminal is used for processing the decrypted data, executing the corresponding service logic, and generating the data to be sent to the Internet of Things application module; The server is used for communicating with the CP unit of the Internet of Things application module and transmitting the encrypted data.

7. The system of an intelligent cloud data transceiver encryption and decryption method according to claim 6, characterized in that: The client is connected to the Internet of Things application module. The Internet of Things application module is respectively connected to the first AES calculation module and the cloud server. The cloud server is connected to the server terminal. The server terminal is connected to the server.

8. The system of a cloud data intelligent transceiver encryption and decryption method according to claim 7, characterized in that: The Internet of Things application module includes an AP unit and a CP unit; The AP unit is used for receiving the user instructions input by the client and communicating with the first AES calculation module and the CP unit; The CP unit is used for sending the encrypted data to the cloud server through the communication network and receiving the encrypted data from the cloud server.

9. The system of an intelligent cloud data transceiver encryption and decryption method according to claim 8, characterized in that: The AP unit is connected to the CP unit. The AP unit is connected to the first AES calculation module. The CP unit is connected to the first AES calculation module.

10. The system of a cloud data intelligent transceiver encryption and decryption method according to claim 9, characterized in that: The server terminal includes a second AES calculation module; The second AES calculation module is used for decrypting the data received from the CP unit and encrypting the data sent to the CP unit.