Embedded smart community home service terminal based on new-generation communication network technology
Through the combination of a multi-level security monitoring system and a new generation of communication modules, the problems of insufficient security and low data transmission efficiency of home terminal equipment are solved, and the security and efficiency of network data are improved, and it is suitable for smart community home service terminals.
Patent Information
- Application Number
- CN202510828796.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-08-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing home terminal devices rely on traditional IPv4/IPv6 networks, lack of security, low data transmission efficiency and complex management, and cannot effectively ensure network data security.
A multi-level security monitoring system is adopted, including security modules, virtual isolation modules and a new generation of communication modules. Through preliminary authentication, virtual isolation network environments and real-time encryption and decryption processing, combined with wireless array modules, the connection quality is optimized, and the encryption key is dynamically allocated using the decimal network protocol.
It has achieved improved security for home networks, improved data transmission efficiency, and simplified management processes, effectively defended against network attacks, and compatible with existing network systems.
Smart Images

Figure CN120455154A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication network technology, and in particular to an embedded smart community home service terminal based on a new generation of communication network technology. Background Art
[0002] The existing Internet has a flexible and loose architecture, which makes its security management capabilities very poor. There are many unauthorized accesses, improper leakage, modification and retention of information on the network. With the rapid development of the Internet of Things and smart cities, home terminal devices are playing an increasingly important role in smart communities.
[0003] The Chinese invention patent with authorization announcement number CN109963357A discloses an ARM9-based embedded wireless smart home gateway, which includes a home gateway, a storage unit, a communication module, a display module and a terminal device. The storage unit, communication module and display module are all connected to the home gateway, and the terminal device communicates with the home gateway through the communication module. The system has high reliability, high protocol conversion efficiency, strong anti-interference ability, and good versatility, making it very suitable for application in smart home systems.
[0004] Currently, the network systems of all smart devices are mostly based on the existing Internet network system, which has poor security management capabilities and is prone to data and information leakage. In addition, my country is the country with the largest Internet access users, and network management signaling / information flows through the United States, so information security cannot be guaranteed. Most existing home terminal devices rely on traditional IPv4 / IPv6 networks. In order to ensure network data security, they generally rely on the installation of security equipment such as firewalls, which has problems such as insufficient security, low data transmission efficiency and complex management. Summary of the Invention
[0005] The purpose of the present invention is to provide an embedded smart community home service terminal based on the new generation of communication network technology, which solves the problem that most existing home terminal devices rely on traditional IPv4 / IPv6 networks. In order to ensure the security of network data, they generally rely on the installation of security devices such as firewalls, which have the problems of insufficient security, low data transmission efficiency and complex management.
[0006] The present invention solves the above technical problems through the following technical solutions. The present invention includes a terminal;
[0007] The terminal is equipped with a multi-level security monitoring system, a wireless array module and a built-in encryption key module;
[0008] The multi-level security monitoring system includes a security module, a virtual isolation module and a new generation communication module;
[0009] The security module is used to perform preliminary identity authentication on all connection requests and screen the access rights of legitimate devices;
[0010] The virtual isolation module is used to direct the verified devices to a dedicated virtual isolation network environment, providing a protected independent communication channel;
[0011] The new generation communication module is used to dynamically distribute encryption keys through the decimal network protocol and use distributed addressing to perform real-time encryption and decryption processing on bidirectional data streams.
[0012] Preferably, the wireless array module is used to efficiently transmit and receive signals, achieve reliable wireless connection with the new generation communication module, is provided with a beamforming mechanism to accurately point to the target base station, supports frequency band switching function to adapt to different network environments and optimize connection quality, and has an adaptive interference cancellation algorithm to reduce the impact of background noise and thereby improve communication reliability and privacy protection performance.
[0013] Preferably, the built-in encryption key module is used to store encryption key pairs, allowing authorized users or devices to read the module content through a specific path after verification, using a decimal network protocol, compatible with existing network systems while ensuring secure transmission of network data.
[0014] Preferably, the establishment of the multi-level security monitoring system specifically includes the following steps:
[0015] Step S1: Perform fine-grained behavior analysis based on encrypted data traffic to detect potential security threats;
[0016] Step S2: Calculate the device access duration D and the average session duration M. A threshold is determined based on the formula A = (D − M) / T, where T represents the tolerance range. If A < k, the communication state is considered normal. Otherwise, a warning signal is triggered, where k is the risk factor.
[0017] Step S3: Dynamically adjust the response level of the defense mechanism according to the threat level L.
[0018] Preferably, the calculation of the device access duration D in step S2 specifically includes the following steps:
[0019] Step M1: Monitor the first and last connection time points T of each legitimate device start and T end , calculate the duration T active = T end -T start ;
[0020] Step M2: The longest continuous access time T of the same device in history HistoryMax and the shortest duration THistoryMin was used to establish comparisons;
[0021] Step M3: Set the dynamic baseline T based on the above information Baseline =θ(T HistoryMin , T HistoryMax ), where the θ function takes into account the factors of time and frequency;
[0022] Step M4: Current duration exceeds T Baseline When the range is within ±δ (δ represents the floating tolerance), an alarm is generated.
[0023] Preferably, adjusting the defense mechanism according to the threat level in step S3 specifically includes the following steps:
[0024] Step N1: Define a series of pre-designed policy sets P set , each strategy P i for specific types of risks;
[0025] Step N2: Summarize the various evaluation scores generated in the previous steps to form a comprehensive score S overall ;
[0026] Step N3: Select the best strategy based on the comprehensive score, satisfying the rule max (P rofit (P i )), P rofit (P i ) refers to the effectiveness and cost ratio of the strategy;
[0027] Step N4: Implement the selected package of policy solutions to maximize network security performance and ensure that user experience is not seriously affected.
[0028] Preferably, a user interaction module is installed outside the terminal, and the user interaction module is used to provide a user interface and support multiple interaction modes such as voice control and touch screen operation.
[0029] Preferably, the terminal is specifically a mobile phone, a tablet, a computer, a router or a surveillance camera.
[0030] Compared with the prior art, the beneficial effects of the present invention are:
[0031] A multi-level security monitoring system built through security modules, virtual isolation modules and new-generation communication modules is used to monitor abnormal traffic and respond to various types of online violent crimes. The new-generation communication module uses a decimal network protocol to dynamically allocate encryption keys in the built-in encryption key module, and uses distributed addressing to perform real-time encryption and decryption of bidirectional data streams. The address can be encrypted, and authentication is performed before communication. It is compatible with the existing network system to achieve unified planning and optimization of the overall network. While having the basic functions of a tablet, other home use devices can be selected according to usage needs. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 Schematic diagram of the structure of the terminal in the present invention;
[0033] Figure 2 It is a structural diagram of the multi-level security monitoring system of the present invention;
[0034] Figure 3 Schematic diagram of the network structure in the present invention. DETAILED DESCRIPTION
[0035] In order to safeguard national information security, the Ministry of Information Industry (now transferred to the Ministry of Industry and Information Technology) established the Decimal Network Standard Working Group in 2002. It has now completed the formulation of the Decimal Network standard and the design, planning and implementation of a new generation of secure and controllable information network platform demonstration projects.
[0036] The new generation of communication network technology was independently developed by national scientists. Its technology, equipment, and facilities, including the parent root server and root domain name server, are all located in China and are owned by the state. Due to the uniqueness of the algorithm technology used in the design of this network, it is compatible with the currently used IPv4 and IPv6 networks. IPv4 and IPv6 networks cannot access this network through abnormal channels, let alone analyze the data of this network. The technical design of this network is currently the safest. After the network is fully launched, the data of our country, including party, government, military, police agencies and various industries, will no longer run to foreign equipment, will no longer cause data leaks, and will no longer have network security vulnerabilities and hidden dangers.
[0037] The above and other technical features and advantages of the present invention are described in more detail below with reference to the accompanying drawings.
[0038] The present invention provides a technical solution: an embedded smart community home service terminal based on a new generation of communication network technology, such as Figure 1-3 As shown, including terminal;
[0039] The terminal is equipped with a multi-level security monitoring system, a wireless array module and a built-in encryption key module;
[0040] The multi-level security monitoring system includes a security module, a virtual isolation module, and a new generation of communication modules;
[0041] The security module is used to perform preliminary identity authentication on all connection requests and screen the access permissions of legitimate devices;
[0042] The built-in security module performs preliminary authentication on all connection requests and screens the access rights of legitimate devices. The terminal collects basic information of any device attempting to establish a network connection, such as the MAC address and hardware ID, and compares it with the legitimate user records pre-stored in the database. If the detection results match, temporary access rights are granted for a certain period of time.
[0043] During the first configuration, the home network will pre-register the information of smartphones and other confirmed safe devices in the home, and will verify the corresponding unique identification code every time it receives an external Internet access application.
[0044] The virtual isolation module is used to direct verified devices to a dedicated virtual isolation network environment, providing a protected independent communication channel. Specifically, through technologies such as VPN (Virtual Private Network) or VLAN (Virtual Local Area Network), each legitimate device is provided with an independent and protected communication channel, reducing potential risks and preventing unauthorized access.
[0045] Verified devices are directed to a dedicated virtual isolated network environment, providing a protected independent communication channel. Once a device successfully passes the initial identity review process, a unique isolated space is automatically established.
[0046] Each new object that enters and proves to be trustworthy is assigned an independent operating space, where it has a dedicated path to interact with other resources but cannot directly access the external public network. This effectively prevents potential external threats from invading and causing damage within the local area.
[0047] The new generation of communication modules is used to dynamically distribute encryption keys through the decimal network protocol and use distributed addressing to perform real-time encryption and decryption of bidirectional data streams;
[0048] To ensure the secure transmission of information without tampering or leakage, each time a communication is established, a long and unique secret code is randomly generated between the two nodes based on advanced mathematical theory algorithms as the encryption key for subsequent communications. The form and content of this key are constantly changed in random sessions to increase the difficulty and prevent illegal elements from deciphering it.
[0049] The wireless array module is used to efficiently transmit and receive signals, achieving reliable wireless connections with the next-generation communication module. It features a beamforming mechanism for precise pointing to the target base station and supports frequency band switching to adapt to different network environments and optimize connection quality. It also features an adaptive interference cancellation algorithm to reduce the impact of background noise, thereby improving communication reliability and privacy protection, enhancing the terminal's wireless communication capabilities, and supporting multiple wireless protocols such as Wi-Fi, Zigbee, and LoRa.
[0050] The built-in encryption key module is used to store encryption key pairs, allowing authorized users or devices to read the module contents through specific channels after verification. It uses the decimal network protocol, which is compatible with the existing network system while ensuring the secure transmission of network data.
[0051] Furthermore, the establishment of a multi-level security monitoring system specifically includes the following steps:
[0052] Step S1: Perform fine-grained behavior analysis based on encrypted data traffic to detect potential security threats;
[0053] Step S2: Calculate the device access duration D and the average session duration M. A threshold is determined based on the formula A = (D − M) / T, where T represents the tolerance range. If A < k, the communication state is considered normal. Otherwise, a warning signal is triggered, where k is the risk factor.
[0054] Step S3: Dynamically adjust the response level of the defense mechanism according to the threat level L.
[0055] Furthermore, the calculation of the device access duration D in step S2 specifically includes the following steps:
[0056] Step M1: Monitor the first and last connection time points T of each legitimate device start and T end , calculate the duration T active = T end -T start ;
[0057] Step M2: The longest continuous access time T of the same device in history HistoryMax and the shortest duration T HistoryMin was used to establish comparisons;
[0058] Step M3: Set the dynamic baseline T based on the above information Baseline =θ(T HistoryMin , T HistoryMax ), where the θ function takes into account the factors of time and frequency;
[0059] Step M4: Current duration exceeds T BaselineWhen the range is within ±δ (δ represents the floating tolerance), an alarm is generated.
[0060] Furthermore, adjusting the defense mechanism according to the threat level in step S3 specifically includes the following steps:
[0061] Step N1: Define a series of pre-designed policy sets P set , each strategy P i for specific types of risks;
[0062] Policies can include firewall rules, intrusion detection and prevention system configuration, access control lists, and encryption method selection.
[0063] Strategy examples:
[0064] Strategy P1: Protection against phishing, including email filtering and user warnings.
[0065] Strategy P2: Response strategies for denial of service (DoS) attacks, including traffic limiting and load balancing.
[0066] Strategy P3: Protection measures against data leakage, including data encryption, access control and monitoring.
[0067] Step N2: Summarize the various evaluation scores generated in the previous steps to form a comprehensive score S overall ;
[0068] Step N3: Select the best strategy based on the comprehensive score, satisfying the rule max (P rofit (P i )), P rofit (P i ) refers to the effectiveness and cost ratio of the strategy, evaluating the benefit-cost ratio of each strategy and seeking the lowest cost solution with the same security benefit;
[0069] Step N4: Implement the selected package of policy solutions to maximize network security performance and ensure that user experience is not seriously affected.
[0070] Furthermore, a user interaction module is installed on the outside of the terminal. The user interaction module is used to provide a user interface and support multiple interaction methods such as voice control and touch screen operation. While having the basic functions of a tablet, it ensures the security of data transmission network and is compatible with the existing network system.
[0071] Furthermore, the terminal is specifically a mobile phone, tablet, computer, router or surveillance camera, and the home use device can be selected according to the use needs.
[0072] When in use, the terminal will collect basic information about any device attempting to establish a network connection, such as the MAC address and hardware ID, and compare it with the legitimate user records pre-stored in the database through the security module. If the detection results match, temporary access rights will be granted for a certain period of time to prevent data from being stolen, tampered with, or destroyed, thereby improving security performance.
[0073] When a device successfully passes the initial identity review process, the virtual isolation module directs the verified device to a dedicated virtual isolated network environment, providing a protected independent communication channel and automatically building a unique isolated space. In this special environment, data streams from different sources do not affect each other. They use specially established paths to interact with other resources and do not directly contact the external public network. This effectively prevents potential external threats from invading and causing damage within the local area, avoiding network congestion and paralysis of the entire network due to failure of certain key devices in the network.
[0074] The new generation of communication modules dynamically allocates encryption keys from the built-in encryption key module through a decimal network protocol and uses distributed addressing to perform real-time encryption and decryption of bidirectional data streams. At the end of each cycle, both parties must renegotiate and establish a new password string applicable to the next time period, and immediately update and save it in their own memory units. The entire process is fully automated and can be completed without human intervention, with extremely low time overhead and guaranteed efficiency.
[0075] By building a multi-level security monitoring system to monitor abnormal traffic and respond to various types of online violent crimes, the new generation of communication modules uses the decimal network protocol to dynamically allocate encryption keys in the built-in encryption key module, and adopts distributed addressing to perform real-time encryption and decryption of bidirectional data streams. The address can be encrypted, and authentication is performed before communication. It is compatible with the existing network system to achieve unified planning and optimization of the overall network. While having the basic functions of a tablet, other home use devices can be selected according to usage needs.
[0076] The above are only preferred embodiments of the present invention and are merely illustrative, not restrictive, of the present invention. Those skilled in the art will appreciate that many changes, modifications, and even equivalents may be made to the embodiments within the spirit and scope of the claims, all of which fall within the scope of protection of the present invention.
Claims
1. The embedded smart community home service terminal based on the new generation of communication network technology is characterized by: Including terminals; The terminal is equipped with a multi-level security monitoring system, a wireless array module and a built-in encryption key module; The multi-level security monitoring system includes a security module, a virtual isolation module and a new generation communication module; The security module is used to perform preliminary identity authentication on all connection requests and screen the access rights of legitimate devices; The virtual isolation module is used to direct the verified devices to a dedicated virtual isolation network environment, providing a protected independent communication channel; The new generation communication module is used to dynamically distribute encryption keys through the decimal network protocol and use distributed addressing to perform real-time encryption and decryption processing on bidirectional data streams.
2. The embedded smart community home service terminal based on the new generation communication network technology according to claim 1, characterized in that: The wireless array module is used to efficiently transmit and receive signals, achieving a reliable wireless connection with the new generation communication module. It is equipped with a beamforming mechanism to accurately point to the target base station, supports frequency band switching to adapt to different network environments and optimize connection quality, and has an adaptive interference cancellation algorithm to reduce the impact of background noise, thereby improving communication reliability and privacy protection performance.
3. The embedded smart community home service terminal based on the new generation communication network technology according to claim 1, characterized in that: The built-in encryption key module is used to store encryption key pairs, allowing authorized users or devices to read the module content through a specific path after verification. It adopts the decimal network protocol, is compatible with the existing network system, and ensures the secure transmission of network data.
4. The embedded smart community home service terminal based on the new generation communication network technology according to claim 1, characterized in that: The establishment of the multi-level security monitoring system specifically includes the following steps: Step S1: Perform fine-grained behavior analysis based on encrypted data traffic to detect potential security threats; Step S2: Calculate the device access duration D and the average session duration M. A threshold is determined based on the formula A = (D − M) / T, where T represents the tolerance range. If A < k, the communication state is considered normal. Otherwise, a warning signal is triggered, where k is the risk factor. Step S3: Dynamically adjust the response level of the defense mechanism according to the threat level L.
5. The embedded smart community home service terminal based on the new generation communication network technology as claimed in claim 4, characterized in that: The calculation of the device access duration D in step S2 specifically includes the following steps: Step M1: Monitor the first and last connection time points T of each legitimate device start and T end , calculate the duration T active = T end -T start ; Step M2: The longest continuous access time T of the same device in history HistoryMax and the shortest duration T HistoryMin was used to establish comparisons; Step M3: Set the dynamic baseline T based on the above information Baseline =θ(T HistoryMin , T HistoryMax ), where the θ function takes into account the factors of time and frequency; Step M4: Current duration exceeds T Baseline When the range is within ±δ (δ represents the floating tolerance), an alarm is generated.
6. The embedded smart community home service terminal based on the new generation communication network technology according to claim 4, characterized in that: Adjusting the defense mechanism according to the threat level in step S3 specifically includes the following steps: Step N1: Define a series of pre-designed policy sets P set , each strategy P i for specific types of risk; Step N2: Summarize the various evaluation scores generated in the previous steps to form a comprehensive score S overall ; Step N3: Select the best strategy based on the comprehensive score, satisfying the rule max (P rofit (P i )), P rofit (P i ) refers to the effectiveness and cost ratio of the strategy; Step N4: Implement the selected package of policy solutions to maximize network security performance and ensure that user experience is not seriously affected.
7. The embedded smart community home service terminal based on the new generation communication network technology according to claim 1, characterized in that: The terminal is externally provided with a user interaction module, which is used to provide a user interface and supports multiple interaction modes such as voice control and touch screen operation.
8. The embedded smart community home service terminal based on the new generation communication network technology according to claim 1, characterized in that: The terminal is specifically a mobile phone, tablet, computer, router or surveillance camera.
Citation Information
Patent Citations
Embedded wireless smart home gateway based on ARM9
CN109963357A