A low-power hardware encryption system based on a geological disaster monitoring scene
By constructing a low-power hardware encryption system with a layered architecture and quantum key distribution terminal, the security protection problem of geological disaster monitoring equipment has been solved, data confidentiality and battery life have been improved, and offline analysis and real-time early warning have been supported.
Patent Information
- Application Number
- CN202510863696.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-06-26
AI Technical Summary
Existing geological disaster monitoring equipment suffers from several security issues, including single key bindings that are easily cracked, insufficient data confidentiality and integrity, high power consumption and insufficient battery life, reliance on cloud processing leading to delays, high false alarm rates, and a lack of firmware integrity verification.
A layered architecture module is adopted, combining the terminal perception layer and the cloud platform layer. A secure channel is established through the quantum key distribution terminal, a triple binding mechanism is implemented, keys are dynamically managed, random numbers are generated using MEMS vibration entropy source and temperature sensor noise, an edge computing module is deployed for data preprocessing, a three-dimensional risk heat map is constructed, a dynamic compression algorithm is used to manage power consumption, and encryption and decryption are performed by integrating the quantum key distribution terminal and the national cryptographic algorithm.
It enhances the security protection capabilities of geological disaster monitoring equipment, ensures data confidentiality and integrity, reduces transmission load, improves battery life, achieves end-to-end differentiated protection, supports offline analysis, and improves real-time performance and communication security.
Smart Images

Figure CN120434040B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of hardware encryption technology, specifically to a low-power hardware encryption system for geological disaster monitoring scenarios. Background Technology
[0002] In existing technologies, geological disaster monitoring and early warning networks have formed a monitoring and early warning capability covering provinces with high incidence of geological disasters nationwide. This involves multiple potential geological disaster sites, the construction of geological disaster monitoring equipment and monitoring and early warning systems. The geological disaster monitoring equipment includes: GNSS receivers, crack gauges, inclinometers, accelerometers, moisture meters, and rain gauges. Daily monitoring time-series data primarily focuses on surface deformation and rainfall. Monitoring work is carried out on geological disasters, including landslides, collapses, and debris flows, to improve the level of human and technological defenses against geological disasters. However, current geological disaster monitoring equipment lacks safety protection measures that accurately control power consumption based on risk levels, and the data... Confidentiality and integrity have not been effectively protected; traditional geological disaster monitoring equipment often uses fixed key cycles, and the key-device binding method is simple, making it easy to be monitored and cracked over a long period of time; most of them use standard TLS protocols or single national cryptographic algorithms, lacking layered encryption strategies, making them vulnerable to man-in-the-middle attacks or protocol vulnerabilities; most systems rely on the cloud to process raw data, resulting in high latency and the inability to perform local analysis in network outage scenarios; traditional equipment lacks firmware integrity verification at startup, resulting in low detection rates of hardware Trojan implantation; it relies on single-parameter threshold alarms, ignoring the risk of multi-device linkage, resulting in a high false alarm rate; the equipment often uses a fixed power consumption mode, resulting in high standby power consumption and insufficient battery life for field equipment;
[0003] Therefore, there is a need to provide a low-power hardware encryption system for geological disaster monitoring scenarios to enhance the security of existing geological disaster monitoring equipment, ensure the security of collected data, prevent data theft and tampering, provide confidentiality and integrity of collected data transmission, and ensure network transmission performance. Summary of the Invention
[0004] The purpose of this invention is to provide a low-power hardware encryption system for geological disaster monitoring scenarios. To solve the aforementioned problems in the prior art, this invention achieves this through the following technical solution:
[0005] This invention provides a low-power hardware encryption system for geological disaster monitoring scenarios, comprising the following modules:
[0006] Layered architecture module: Constructs terminal perception layer and cloud platform layer, generates 3D risk heat map, and conducts short-term early warning model and emergency simulation;
[0007] Encryption / decryption module: Based on protocol layering and the integration of national cryptographic algorithms, it performs multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing flow, and establishes a secure channel to dynamically negotiate whether encryption or decryption is needed;
[0008] Key management module: Implements a triple binding mechanism to process and assess the risks of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery;
[0009] Security Protection Module: Intelligently manages system power consumption based on system activity status, adopts dynamic compression algorithm, selects compression strategy according to data type, performs security monitoring of hardware and firmware, and performs intrusion detection and automatic repair.
[0010] Furthermore, the method for acquiring the terminal perception layer is as follows:
[0011] Deploy a third-generation embedded security terminal, integrating a dual-core heterogeneous processor, and a built-in independent hardware random number generator based on the hybrid modeling of MEMS vibration entropy source and temperature sensor noise. It can process sensor data in a multi-threaded concurrent manner and add an edge computing micro-module for basic data preprocessing.
[0012] Furthermore, the method for obtaining the cloud platform layer is as follows:
[0013] It adopts a three-tier architecture of regional central cloud + provincial core cloud + national disaster recovery cloud. The regional central cloud deploys edge nodes to perform real-time abnormal data cleaning and equipment status monitoring.
[0014] Furthermore, the method for dynamically managing the key is as follows:
[0015] Deploy quantum key distribution terminals in high-risk monitoring areas, establish a quantum-secure channel between the gateway and the platform, and set up key update cycles in both regular and high-risk modes.
[0016] Furthermore, the method for optimizing the data processing flow is as follows:
[0017] Based on the need to use the secure transmission function provided by the encryption / decryption module, the module initialization interface, the send processing interface, and the receive processing interface are called to process the hardware data.
[0018] A joint regression model of temperature sensor noise and MEMS vibration entropy source is established, and the result is obtained through the formula... Predict the zero-point drift of the sensor, where... This represents the rate of temperature change. This represents the amplitude of vibration acceleration. and All of these represent preset time-varying coefficients;
[0019] Each calibration cycle triggers a self-calibration, which uses a hardware random number generator to generate a random excitation signal and updates the compensation parameters using the least squares method.
[0020] The module initialization interface completes the security parameter negotiation between the IoT terminal and the IoT security gateway, encrypts and decrypts the data based on the security parameters, and sends the notification payload after decryption.
[0021] Furthermore, the method for obtaining the excitation signal is as follows:
[0022] The background noise in the 0.5-2kHz frequency band output by the MEMS vibration sensor is set as the primary entropy source, and the LSB bit noise of the temperature sensor is set as the secondary entropy source. This is achieved using the formula... Synthetic excitation signal ,in, This represents the dynamic amplitude, which is dynamically adjusted based on the real-time temperature. This indicates a time interval. , This represents a hardware random number stream;
[0023] Based on the excitation signal, the original data is denoised using an improved wavelet threshold.
[0024] Furthermore, the improved wavelet thresholding denoising method is as follows:
[0025] Based on the excitation signal, through the formula Calculate the denoised data ,in, This represents the standard deviation of noise. This represents the number of data points. This represents the vibration energy regulation factor. This represents the real-time vibration energy integral value. This represents the preset critical energy threshold.
[0026] Based on the notification payload, the network data packet sending interface is called when the IoT terminal sends data. After the network data packet is encapsulated and before it is sent to the Ethernet / 4G network port, the network data packet sending interface determines whether the network data packet needs to be encrypted.
[0027] Furthermore, the method for risk assessment is as follows:
[0028] Using a 1-hour sliding window with a 10-minute step, the number of device anomalies is counted. The anomaly frequency of the i-th device is calculated using a formula. A circular grid with radius R is constructed centered on the target device to identify effective neighboring devices, forming an adjacency matrix. The proportion of anomaly devices is obtained by dividing the number of devices in a high-anomaly state within the neighborhood by the total number of devices in the neighborhood. ,like If so, it is considered that there is abnormal regional linkage;
[0029] Based on the obtained core parameters, the overlap of abnormal parameters among devices in the neighborhood is calculated by dividing the number of devices in the neighborhood with the same abnormal parameters as the target device by the total number of devices in the neighborhood. ,like This indicates that the anomaly was caused by the same type of factor, and the risk correlation is higher;
[0030] Furthermore, the method of employing a dynamic key cycle is as follows:
[0031] The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting.
[0032] The edge gateway encrypts and stores key logs for 60 days, with blockchain-based notarization, supporting traceability of key usage records;
[0033] The cloud platform establishes a key history database, supports cross-device key association analysis, and identifies abnormal key reuse behavior;
[0034] If the device detects a decryption failure, it will automatically switch to the next newest key version. If the decryption fails three times in a row, it will trigger a key audit on the gateway side to verify the validity of the certificate and the matching degree of the key version. If the audit is passed, an emergency key will be reissued through an out-of-band channel.
[0035] Furthermore, the method for security monitoring is as follows:
[0036] Deploy a lightweight IDS based on DPI deep packet inspection and AI behavior analysis; identify anomalies in ESP encapsulation fields;
[0037] By learning the normal communication mode of the device through LSTM, a secondary warning is triggered for behaviors with a deviation > 3σ, where σ represents the standard deviation;
[0038] Network interruption handling has been enhanced, local caching has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, an ACK confirmation mechanism has been introduced, and out-of-order reordering is supported.
[0039] The beneficial effects of this invention are:
[0040] 1. Enhance the security protection capabilities of existing geological disaster monitoring equipment. By binding physical, environmental, and temporal dimensions, enhance the uniqueness of equipment identity, adapt to security requirements in different scenarios, and achieve end-to-end differentiated protection. The quantum key terminal identifies eavesdropping through bit error rate mutations, reduces transmission load, and improves real-time performance. It achieves preprocessing by eliminating high-frequency noise and using a 3σ outlier removal algorithm through sliding window filtering. It locally caches encrypted data and supports offline feature analysis. It uses temperature sensor noise and vibration background noise to construct a hybrid entropy source model to improve the quality of random number generation. It constructs an adjacency matrix, calculates the proportion of abnormal devices and parameter overlap, identifies regional linkage risks, identifies abnormal hardware behavior through current ripple characteristics, and dynamically adjusts power consumption modes to ensure security protection while improving battery life.
[0041] 2. Deploy a third-generation embedded security terminal, utilizing a dual-core heterogeneous processor paired with multiple sensors to collect data, ensuring data security. Add an edge computing micro-module to enhance autonomy and real-time performance; perform real-time data cleaning and equipment monitoring; integrate multi-source data to generate a 3D risk heatmap; based on protocol layering and the integration of national cryptographic algorithms, different encryption protocols are selected for different communication levels to improve communication security and encryption efficiency; deploy quantum key distribution terminals in high-risk areas to establish secure channels, with terminal devices pre-stored with quantum key seeds and capable of monitoring quantum attacks; set dynamic key cycles according to risk levels, establish a key backup system with intelligent key recovery processes, construct a risk assessment model, and generate risk levels by combining single-device anomaly frequency and local grid correlation to provide a basis for key management; achieve precise power consumption control based on system activity status; adopt a dynamic compression algorithm to select compression strategies according to data type, provide early warning of abnormal behavior, and establish a self-repair mechanism for the key system and data links. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] Figure 1 This is a schematic diagram of a low-power hardware encryption system based on a geological disaster monitoring scenario, provided in Embodiment 1 of the present invention.
[0044] Figure 2 This is a flowchart of the steps of a low-power hardware encryption system based on a geological disaster monitoring scenario provided in Embodiment 2 of the present invention;
[0045] Figure 3 This is a schematic diagram of the encryption and decryption module logic connection of a low-power hardware encryption system based on a geological disaster monitoring scenario, provided in Embodiment 1 of the present invention. Detailed Implementation
[0046] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0047] Example 1: As Figure 1 As shown in the figure, the low-power hardware encryption system based on geological disaster monitoring scenarios provided by this invention specifically includes the following modules:
[0048] Layered architecture module: Constructs terminal perception layer and cloud platform layer, integrates multi-source data fusion algorithm to generate 3D risk heat map, and conducts short-term early warning model and emergency simulation;
[0049] Building a terminal perception layer: Deploying a third-generation embedded security terminal, integrating a dual-core heterogeneous processor, and a built-in independent hardware random number generator based on the hybrid modeling of MEMS vibration entropy source and temperature sensor noise, and processing sensor data in a multi-threaded concurrent manner. The sensor data includes, but is not limited to: GNSS displacement, crack gauge deformation, tilt angle, acceleration, moisture content and rainfall.
[0050] Add edge computing micro-modules to perform basic data preprocessing, including but not limited to sliding window filtering and outlier detection, locally cache encrypted raw data for 30 minutes, and perform offline encrypted raw data feature analysis in offline scenarios.
[0051] Specifically, a joint regression model of temperature sensor noise and MEMS vibration entropy source is established, using the formula... Predict the zero-point drift of the sensor, where... This represents the rate of temperature change. This represents the amplitude of vibration acceleration. and All of these represent preset time-varying coefficients;
[0052] Each calibration cycle triggers a self-calibration, which uses a hardware random number generator to generate a random excitation signal and updates the compensation parameters using the least squares method.
[0053] Specifically, the background noise in the 0.5-2kHz frequency band output by the MEMS vibration sensor is set as the primary entropy source, and the LSB bit noise of the temperature sensor is set as the secondary entropy source, using the formula... Synthetic excitation signal ,in, This represents the dynamic amplitude, which is dynamically adjusted based on the real-time temperature. This indicates a time interval. , This represents a hardware random number stream;
[0054] Based on the excitation signal, the original data is denoised using an improved wavelet threshold, according to the formula. Calculate the denoised data ,in, This represents the standard deviation of noise. This represents the number of data points. This represents the vibration energy regulation factor. This represents the real-time vibration energy integral value. This represents the preset critical energy threshold.
[0055] Building a cloud platform layer: Adopting a three-tier architecture of regional central cloud + provincial core cloud + national disaster recovery cloud, with edge nodes deployed in the regional central cloud to perform real-time abnormal data cleaning and equipment status monitoring;
[0056] It should be noted that the provincial core cloud constructs a digital twin model based on the Unity digital twin engine, integrates multi-source data fusion algorithms, and generates a three-dimensional risk heat map; the national disaster recovery cloud adopts cross-regional distributed storage and deploys a federated learning system for cross-regional model collaborative training.
[0057] It has a built-in AI platform for disaster prediction, enabling short-term early warning models and emergency simulations.
[0058] It should be noted that the short-term early warning model is based on the spatiotemporal attention mechanism, supports emergency early warning within 1 hour, and integrates a cellular automata model for emergency simulation to simulate the evolution of disasters and output the optimal evacuation route for personnel.
[0059] Encryption / decryption module: Based on protocol layering and the integration of national cryptographic algorithms, it performs multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing flow, and establishes a secure channel to dynamically negotiate and determine whether encryption or decryption is needed.
[0060] The terminal-gateway adopts the lightweight ESPv4+SM4 protocol and uses dynamic payload compression technology to support quantum key pre-distribution;
[0061] The gateway platform adopts the national cryptographic TLS1.3+SM2 / SM3 protocol, introduces a dynamic certificate chain verification mechanism, supports differential privacy protection, and has the ability to resist man-in-the-middle attacks;
[0062] The platform-terminal reverse authentication uses SM2 digital signature + SM9 identification password, and the control commands use two-factor authentication, supporting location-based access control.
[0063] Deploy quantum key distribution terminals in high-risk monitoring areas, and establish a quantum secure channel between the gateway and the platform based on the BB84 protocol and decoy state technology. For example, the key update cycle is 1 minute in normal mode and 10 seconds in high-risk mode.
[0064] The terminal device has a pre-stored quantum key seed, which automatically generates a 256-bit symmetric key each time it is powered on, and supports quantum attack monitoring that identifies eavesdropping behavior by detecting changes in bit error rate.
[0065] The encryption / decryption module is attached to the network processing module of the IoT terminal.
[0066] When sending data, after the network processing module completes the encapsulation of the network data packet and before the data packet is sent to the Ethernet / 4G network port, the network data packet processing interface provided by the encryption / decryption module is called to encrypt the data and encapsulate the ESP packet. The network processing module then sends the encrypted data packet out from the Ethernet / 4G network port.
[0067] When receiving data, the network processing module first receives network data packets from the Ethernet / 4G network port, then calls the network data packet processing interface provided by the encryption / decryption module to decrypt and decapsulate ESP packets, and then the network processing module performs subsequent processing on the decrypted data.
[0068] The encryption / decryption module provides four types of interfaces: certificate management interface, module initialization interface, network data packet sending and processing interface, and network data packet receiving and processing interface, which facilitates the integration of IoT terminals with the encryption / decryption software module;
[0069] For example, based on the need to negotiate security parameters with a remote IoT security gateway, and the negotiation process requires the use of digital certificates, the encryption and decryption module provides a certificate management interface to process certificates, including but not limited to: certificate request generation, certificate import, and certificate deletion.
[0070] Based on the need to use the secure transmission function provided by the encryption / decryption module, the module initialization interface, sending processing interface and receiving processing interface are called to process the data;
[0071] The module initialization interface completes the negotiation of security parameters between the IoT terminal and the IoT security gateway. The security parameters are used for subsequent data encryption and decryption.
[0072] Specifically, the dialogue is based on the message sequence. Message 1: The initiator sends the device's identification code to the responder. The identification code includes, but is not limited to, the device ID, device SN, and device PN, ensuring that the information is unique across the entire network.
[0073] Message 2: The responder sends exchange data to the initiator. The exchanged data content is the session key. The session key is encrypted and protected using an identity code and the SM4 symmetric encryption algorithm. The session key is generated by the responder using a random number generator. The data exchanged by the responder is as follows:
[0074] XCHr=symmetric_Encrypt(key,SN / PN)
[0075] After receiving the request from the initiator, the responder will check whether the identity code matches the rules and whether the corresponding device is registered.
[0076] Message 3: After successful verification by the initiator, a notification payload and an HMAC payload are sent.
[0077] Specifically, after receiving message 2, the initiator will parse the corresponding message and decrypt the session key using the identity code; after decryption, the initiator will send the notification payload.
[0078] Based on the notification payload, the network data packet sending interface is called when the IoT terminal sends data. After the network data packet is encapsulated and before it is sent to the Ethernet / 4G network port, the network data packet sending interface determines whether the network data packet needs to be encrypted.
[0079] If encryption is required, the security parameters obtained during initialization are used to perform encryption and integrity calculations, and the network data packets are encapsulated in ESP format. Finally, the processed data packets are returned to the caller.
[0080] After returning the data to the caller, the network processing module sends the ESP data packet out from the Ethernet / 4G port;
[0081] The encrypted file formats are shown in Table 1:
[0082] Table 1. Illustration of Encrypted File Formats
[0083]
[0084] Based on the encrypted network data packets, the network data packet receiving interface is invoked when the IoT terminal receives data. After receiving network data via Ethernet / 4G network port and before sending it to the network protocol stack, the network data packet receiving interface determines whether the network data packets need to be decrypted.
[0085] If decryption is required, perform integrity verification on the network data packet, use the security parameters obtained during initialization to decrypt and decapsulate the ESP format to obtain the original network data packet, and finally return the processing result to the caller;
[0086] The network processing module sends the raw network data packets to the protocol stack for processing;
[0087] Key management module: Implements a triple binding mechanism to process and assess the risks of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery;
[0088] The device registration phase employs a triple binding mechanism, including physical binding, environmental binding, and time binding.
[0089] Specifically, the physical binding method is as follows: the unique identification code of the hardware encryption module is burned into the chip fuse bit, which cannot be tampered with;
[0090] The specific method for environment binding is as follows: the latitude, longitude and altitude of the deployment location are calibrated in real time using BeiDou / GNSS;
[0091] The specific method for time binding is as follows: obtain and bind the registration timestamp and certificate validity period, and use blockchain timestamp service to prevent replay attacks;
[0092] Monitoring data is acquired based on geological disaster monitoring equipment deployed at geological disaster monitoring sites. Geological disaster monitoring equipment includes, but is not limited to: GNSS receivers, crack gauges, inclinometers, accelerometers, moisture meters, and rain gauges.
[0093] The feature vector is obtained by performing lightweight preprocessing on the original data based on the edge computing micro-module built into the terminal device.
[0094] Specifically, outliers are eliminated based on the 3σ principle, and high-frequency noise is eliminated based on sliding window filtering; the deformation gradients in the horizontal and vertical directions within a unit period based on the horizontal plane are obtained, the rainfall in 72 hours is obtained, and the average hourly rainfall is calculated; the stress change in a unit period is obtained, and the stress change rate is calculated.
[0095] The output feature vector is transmitted to the smart gateway via an encrypted link.
[0096] A lightweight risk assessment model for the NPU neural network processor of a smart gateway is built based on LSTM and sliding window, enabling real-time analysis of single-device data.
[0097] Monitor single-parameter anomalies, construct a local risk mesh based on LoRaMesh networking data, and analyze the parameter correlation of more than N adjacent devices. For example, multiple devices may experience deformation acceleration at the same time.
[0098] A preliminary risk level is generated based on the frequency of anomalies in individual devices and the correlation of local grids.
[0099] Specifically, based on the core parameters of geological disaster monitoring equipment, three levels of anomaly thresholds are set;
[0100] For example, the core parameters of a GNSS receiver are shown in Table 2:
[0101] Table 2. Statistical Table of Core Parameters of GNSS Receivers by Level
[0102]
[0103] Using a 1-hour sliding window with a 10-minute step, the number of equipment malfunctions was counted and calculated using a formula. The frequency of anomalies of the i-th device was calculated. ,in, This represents the number of data points within the sliding window. This represents the total number of core parameters. This represents the core parameters. The weight,
[0104] A circular mesh with radius R is constructed centered on the target device. Effective neighboring devices are determined through Delaunay triangulation, forming an adjacency matrix. ;
[0105] The proportion of abnormal devices is obtained by dividing the number of devices in a high-abnormal state within the neighborhood by the total number of devices in the neighborhood. ,like If so, it is considered that there is abnormal regional linkage;
[0106] Based on the obtained core parameters, the overlap of abnormal parameters among devices in the neighborhood is calculated by dividing the number of devices in the neighborhood with the same abnormal parameters as the target device by the total number of devices in the neighborhood. ,like This indicates that the anomaly was caused by the same type of factor, and the risk correlation is higher;
[0107] like or If so, the association level will be marked as weak association, and the single device will be an anomaly.
[0108] like and If so, the association level will be marked as strong association, and the region will be abnormally linked;
[0109] The frequency of anomalies in a single device is cross-mapped with the correlation of the local grid to form a risk level of 1-3, including: normal mode, early warning mode and disaster mode;
[0110] Dynamic key cycles are adopted based on risk levels;
[0111] In normal mode, the session SM4 key is updated every 7 days, and the key version number is generated using the HMAC-SM3 algorithm;
[0112] In early warning mode, updates are provided 24 hours a day, and a new temporary emergency key is added to support pre-distribution when the device is offline;
[0113] In disaster mode, a real-time dynamic key is used and destroyed after each communication. A 256-bit random key is generated based on TRNG. In addition to timed updates, the key update trigger conditions include: three consecutive data integrity verification failures, device location offset exceeding the threshold, and abnormal power consumption fluctuations.
[0114] The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting.
[0115] The edge gateway encrypts and stores key logs for 60 days, with blockchain-based notarization, supporting traceability of key usage records;
[0116] The cloud platform establishes a key history database, supports cross-device key association analysis, and identifies abnormal key reuse behavior;
[0117] If the device detects a decryption failure, it will automatically switch to a slightly newer key version.
[0118] If decryption fails three times in a row, the gateway-side key audit is triggered to verify the validity of the certificate and the matching degree of the key version. After the audit is passed, the emergency key is reissued through the out-of-band channel.
[0119] Security protection module: Intelligent management of system power consumption based on system activity status, dynamic compression algorithm, selection of compression strategy according to data type, security monitoring of hardware and firmware, intrusion detection and automatic repair of the system;
[0120] Specifically, it is triggered during data transmission / reception / key negotiation, with power consumption ≤50mW, full-function operation, 20MHz cryptographic chip, and full-rate sensor sampling;
[0121] Timed heartbeat / status reporting trigger, power consumption ≤15mW, cryptographic chip frequency reduced to 10MHz, sensor sampling rate reduced to 1Hz, only handling necessary communication;
[0122] Triggered when no data transmission exceeds 30 seconds, power consumption ≤5mW, the password chip enters clock hold mode, the sensor is powered off, only the RF wake-up circuit is maintained, wake-up time 200ms;
[0123] Triggered by manual setting or long-term lack of data, power consumption ≤100μW, all modules are powered off except for the RTC real-time clock, external interrupt is required to wake up, wake-up time is 5s;
[0124] A dynamic compression algorithm is adopted, and the compression strategy is selected according to the data type.
[0125] For example, GNSS coordinate data uses differential decompression with a compression ratio of 8:1; image data uses the nationally certified SM256 compression algorithm; and supports batch encryption of data blocks up to 1024 bytes.
[0126] Detecting hardware Trojans through power consumption fingerprint analysis;
[0127] Each time the system boots up, the firmware hash is calculated using the SM3 algorithm and compared with the pre-stored value in the secure storage area to verify firmware integrity.
[0128] It should be noted that the SM3 algorithm represents a cryptographic hash algorithm. The message is padded to a length that is a multiple of 512 bits. The padding method involves adding a 1 and several 0s to the end of the message until the length requirement is met. The padded message is then divided into 512-bit blocks, and each block is processed sequentially. A compression function is used to process each block, and this compression function consists of multiple round functions. Each round function contains a series of logical operations and shift operations. By repeatedly calculating the message blocks and intermediate states, new intermediate states are generated. The output of the previous round is used as the input of the next round, and all message blocks are processed iteratively. The output of the final round is the hash value of the SM3 algorithm.
[0129] Deploy a lightweight IDS based on DPI deep packet inspection and AI behavior analysis; identify anomalies in ESP encapsulation fields;
[0130] It should be noted that DPI (Deep Packet Inspection) refers to the ability to identify application layer protocols and content characteristics carried in network data packets through in-depth inspection of the packet payload; while Lightweight IDS refers to a technical system used to monitor unauthorized activities and potential security threats in computer networks.
[0131] By learning the normal communication mode of the device through LSTM, a secondary warning is triggered for behaviors with a deviation > 3σ, where σ represents the standard deviation;
[0132] If a key leakage risk is detected: immediately freeze the key and generate a temporary emergency key; initiate the device certificate revocation process; trigger a hardware module self-test, reset the secure storage area, and re-inject a new certificate;
[0133] Network outage handling has been enhanced, and the local cache has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, supporting 72-hour power outage retention.
[0134] It should be noted that non-volatile RAM (NVRAM) storing encrypted data refers to a type of computer memory that retains its stored contents even after power is lost.
[0135] The system features optimized resume capability, an ACK confirmation mechanism, and support for out-of-order reordering.
[0136] The technical solution of this invention is as follows: A third-generation embedded security terminal is deployed, utilizing a dual-core heterogeneous processor paired with multiple sensors to collect data. A built-in hardware random number generator based on a hybrid modeling of MEMS vibration entropy sources and temperature sensor noise ensures data security. An edge computing micro-module is added for data preprocessing and caching, enabling offline analysis during network outages to enhance autonomy and real-time performance. Real-time data cleaning and equipment monitoring are also implemented. A model is built using the Unity digital twin engine, fusing multi-source data to generate a 3D risk heatmap. A national-level disaster recovery cloud enables secure data storage and cross-regional model collaborative training. Emergency simulations utilize cellular automata models to model disaster evolution and provide evacuation routes. Based on protocol layering and the fusion of national cryptographic algorithms, different encryption protocols are selected for different communication levels to improve communication security and encryption efficiency. Quantum key distribution terminals are deployed in high-risk areas to establish secure channels. Terminal devices pre-store quantum key seeds and can monitor quantum attacks. During device registration... A triple binding approach of physical, environmental, and temporal factors is adopted. Dynamic key cycles are set according to risk levels, and a key backup system with an intelligent key recovery process is established. Data from geological disaster monitoring equipment is preprocessed and feature vectors are extracted to construct a risk assessment model. Risk levels are generated by combining the frequency of single-device anomalies and the correlation of local grids, providing a basis for key management. A four-level energy efficiency mode switching is implemented based on system activity, from active to deep sleep, precisely controlling power consumption. A dynamic compression algorithm selects compression strategies according to data type. Simultaneously, hardware malware is monitored through power fingerprint analysis, firmware integrity is verified, and a lightweight IDS based on DPI deep packet inspection and AI behavior analysis is deployed. LSTM learns normal communication patterns to warn of abnormal behavior, establishing a self-healing mechanism for the key system and data links.
[0137] Example 2: Figure 2 As shown in the figure, the low-power hardware encryption method for geological disaster monitoring scenarios provided by this invention specifically includes the following steps:
[0138] S1: Construct a terminal perception layer and a cloud platform layer, generate a three-dimensional risk heat map, and conduct short-term early warning models and emergency simulations;
[0139] S2: Multi-dimensional identity verification is performed based on the integration of protocol layering and national cryptographic algorithms. Keys are dynamically managed and eavesdropping is monitored. Data processing flow is optimized and a secure channel is established to dynamically negotiate whether encryption or decryption is required.
[0140] S3: Implement a triple binding mechanism to process and assess the risks of monitoring data, and use dynamic key cycles based on the generated risk level, and perform key backup and recovery;
[0141] S4: Intelligent management of system power consumption based on system activity status, using dynamic compression algorithms, selecting compression strategies according to data types, performing security monitoring of hardware and firmware, and performing intrusion detection and automatic repair on the system.
[0142] The above provides a detailed description of one embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and should not be considered as limiting the scope of the present invention. The above formulas are all dimensionless numerical calculations, and the formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world situation. The preset parameters in the formulas are set by those skilled in the art based on actual conditions and historical experience, and can be adjusted according to actual conditions. The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. All equivalent changes and improvements made in accordance with the scope of the present invention should still fall within the patent coverage of the present invention.
Claims
1. A low-power hardware encryption system for geological disaster monitoring scenarios, characterized in that, Includes the following modules: Layered architecture module: Constructs terminal perception layer and cloud platform layer, generates 3D risk heat map, and conducts short-term early warning model and emergency simulation; Encryption / decryption module: Based on protocol layering and the integration of national cryptographic algorithms, it performs multi-dimensional identity verification, dynamically manages keys and monitors eavesdropping, optimizes data processing flow, and establishes a secure channel to dynamically negotiate whether encryption or decryption is needed; Key management module: Implements a triple binding mechanism to process and assess the risks of monitoring data, adopts dynamic key cycles based on the generated risk level, and performs key backup and recovery; The specific method for implementing the triple binding mechanism is as follows: based on the device registration stage, triple binding is adopted, including: physical binding, environmental binding and time binding; The specific method of physical binding is as follows: the unique identification code of the hardware encryption module is burned into the chip fuse bit, which cannot be tampered with; The specific method for environment binding is as follows: the latitude, longitude, and altitude of the deployment location are calibrated in real time using BeiDou / GNSS; The specific method for time binding is as follows: obtain and bind the registration timestamp and certificate validity period, and use blockchain timestamp service to prevent replay attacks; The risk assessment method is as follows: Using a 1-hour sliding window with a 10-minute step, the number of device anomalies is counted. The anomaly frequency of the i-th device is calculated using a formula. A circular grid with radius R is constructed centered on the target device to identify effective neighboring devices, forming an adjacency matrix. The proportion of anomaly devices is obtained by dividing the number of devices in a high-anomaly state within the neighborhood by the total number of devices in the neighborhood. ,like If so, it is considered that there is abnormal regional linkage; Based on the obtained core parameters, the overlap of abnormal parameters among devices in the neighborhood is calculated by dividing the number of devices in the neighborhood with the same abnormal parameters as the target device by the total number of devices in the neighborhood. ,like This indicates that the anomaly was caused by the same type of factor, and the risk correlation is higher; The method using dynamic key cycles is as follows: The device's local secure storage area retains the three most recent versions of the key, using copy-on-write technology to prevent overwriting. The edge gateway encrypts and stores key logs for 60 days, with blockchain-based notarization, supporting traceability of key usage records; The cloud platform establishes a key history database, supports cross-device key association analysis, and identifies abnormal key reuse behavior; If the device detects a decryption failure, it will automatically switch to the next newest key version. If the decryption fails three times in a row, it will trigger a key audit on the gateway side to verify the validity of the certificate and the matching degree of the key version. If the audit is passed, an emergency key will be reissued through an out-of-band channel. Security Protection Module: Intelligently manages system power consumption based on system activity status, adopts dynamic compression algorithm, selects compression strategy according to data type, performs security monitoring of hardware and firmware, and performs intrusion detection and automatic repair.
2. The low-power hardware encryption system for geological disaster monitoring scenarios according to claim 1, characterized in that, The method for acquiring the terminal perception layer is as follows: Deploy a third-generation embedded security terminal, integrating a dual-core heterogeneous processor, and a built-in independent hardware random number generator based on hybrid modeling of MEMS vibration entropy source and temperature sensor noise. It can process sensor data concurrently in multiple threads and adds an edge computing micro-module for basic data preprocessing.
3. The low-power hardware encryption system for geological disaster monitoring scenarios according to claim 1, characterized in that, The method for obtaining the cloud platform layer is as follows: It adopts a three-tier architecture of regional central cloud + provincial core cloud + national disaster recovery cloud. The regional central cloud deploys edge nodes to perform abnormal data cleaning and equipment status monitoring in real time.
4. A low-power hardware encryption system for geological disaster monitoring scenarios according to claim 1, characterized in that, The method for dynamically managing the key is as follows: Deploy quantum key distribution terminals in high-risk monitoring areas, establish a quantum-secure channel between the gateway and the platform, and set up key update cycles in both regular and high-risk modes.
5. A low-power hardware encryption system for geological disaster monitoring scenarios according to claim 1, characterized in that, The method for optimizing the data processing flow is as follows: Based on the need to use the secure transmission function provided by the encryption / decryption module, the module initialization interface, the send processing interface, and the receive processing interface are called to process the hardware data. A joint regression model of temperature sensor noise and MEMS vibration entropy source is established, and the result is obtained through the formula... Predict the zero-point drift of the sensor, where... This represents the rate of temperature change. This represents the amplitude of vibration acceleration. and All of these represent preset time-varying coefficients; Each calibration cycle triggers a self-calibration, which uses a hardware random number generator to generate a random excitation signal and updates the compensation parameters using the least squares method. The module initialization interface completes the negotiation of security parameters between the IoT terminal and the IoT security gateway, encrypts and decrypts the data based on the security parameters, and sends the notification payload after decryption.
6. A low-power hardware encryption system for geological disaster monitoring scenarios according to claim 1, characterized in that, The method for security monitoring is as follows: Deploy a lightweight IDS based on DPI deep packet inspection and AI behavior analysis; identify anomalies in ESP encapsulation fields; By learning the normal communication mode of the device through LSTM, a secondary warning is triggered for behaviors with a deviation > 3σ, where σ represents the standard deviation; Network interruption handling has been enhanced, local caching has been upgraded to use non-volatile RAM (NVRAM) to store encrypted data, an ACK confirmation mechanism has been introduced, and out-of-order reordering is supported.
Citation Information
Patent Citations
Geological disaster system based on national secret algorithm
CN113904877A
Data encryption transmission method based on zero-trust architecture
CN119966746A