TCP user-defined protocol communication method and system based on AES encryption
By using the TCP custom protocol with AES encryption in automated production, the information leakage and complex process parameter transmission problems in communication between lower and upper computers are solved, and the secure and accurate data transmission is achieved, and the adaptability and efficiency of the communication protocol are improved.
Patent Information
- Application Number
- CN202510879813.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-15
AI Technical Summary
In the field of automated production, there are problems in the communication between lower and upper computers, and the traditional TCP communication protocol cannot meet the needs of complex process parameter transmission, resulting in process parameter leakage and information transmission errors.
The TCP custom protocol with AES encryption is adopted to transmit data through a long TCP connection between the client and the server, and AES encryption is performed on the data area, combining CRC checks and custom keys to ensure data confidentiality and accuracy.
It realizes the security and reliability of data transmission, ensures that data arrives at the receiving end in an incorrect manner, improves the scalability, security and flexibility of communication protocols, and adapts to the data content needs of different products.
Smart Images

Figure CN120498877A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a TCP custom protocol communication method and system based on AES encryption. Background Art
[0002] In the field of automated production, the main problems faced by communication between the lower computer (PLC) and the upper computer include: traditional interactive information is not encrypted or is simply encrypted, which can easily lead to information leakage during the information transmission process; in this case, during the automated production process of a certain product, the product uses a new type of automated welding robot, which receives production process instructions through the network, resulting in the process instruction information being cracked, thereby causing the process parameters to be leaked.
[0003] In addition, during the automated production of this product, due to the complexity of the process parameters, the traditional TCP communication protocol cannot meet the complexity of the information transmission process, resulting in the inability to transmit all process information; in the traditional information interaction process, due to the lack of verification or insufficient verification of the received data, errors occur during the information transmission process, resulting in model product quality problems.
[0004] Therefore, how to provide a TCP custom protocol communication method based on AES encryption to achieve confidentiality and flexibility in the communication process between the lower and upper computers and the accuracy of complex process parameters in the automated production process has become a technical problem that needs to be solved urgently. Summary of the Invention
[0005] In response to the above problems, the present invention provides a TCP custom protocol communication method and system based on AES encryption. By performing AES encryption on the data sent by the client and the server and using a custom key during encryption, the confidentiality of the data is guaranteed, and the accuracy of the data is guaranteed by performing multiple verifications on the data.
[0006] To achieve the above object, the present invention provides a TCP custom protocol communication method based on AES encryption, comprising:
[0007] Establish a TCP communication connection between the client and the server;
[0008] The client or the server transmits data via a TCP long connection, the data format adopts the data format of the TCP custom protocol, and the data area of the transmitted data is encrypted by AES;
[0009] The client or the server verifies the received data, and if the verification fails, stops the processing flow and responds to the client or the server;
[0010] If the verification is successful, the client or server performs AES decryption on the successfully verified data, processes the data according to the instruction type in the decrypted data, and responds to the client or server after the processing is completed.
[0011] As a further improvement of the present invention, establishing a TCP communication connection between the client and the server includes:
[0012] The server obtains the IP address and port number of the local machine and starts TcpServer to asynchronously monitor the client's connection;
[0013] The client sends a connection request, and the server verifies the IP address and port number of the client. If the client is legitimate, the server sends the local IP address and port number to the client to establish a connection.
[0014] As a further improvement of the present invention, the data format of the TCP custom protocol includes a frame header, a frame length, a frame type, a source, a destination, a time, a frame count, a data area, a check code and a frame tail, and the check code is calculated using CRC checksum.
[0015] As a further improvement of the present invention, the data area of the transmitted data is encrypted with AES, including:
[0016] The transmission data is padded according to the AES algorithm, and the length of the padded data is an integer multiple of 16 bytes;
[0017] The padded data is encrypted using the CBC working mode and a custom key, and the ciphertext is sent to the client or the server through the TCP custom protocol.
[0018] As a further improvement of the present invention, an initial vector IV is added to the encrypted ciphertext, and the ciphertext and the initial vector IV are sent to the client or the server through a TCP custom protocol.
[0019] As a further improvement of the present invention, a different initialization vector IV is used in each communication.
[0020] As a further improvement of the present invention, the client or the server verifies the received data, including:
[0021] The frame header, frame tail, frame length and check code are checked respectively. The frame header is defined as $START and the frame tail is defined as $END. The frame header and frame tail are converted into ASCII codes and stored at the beginning and end of the transmitted data respectively. The frame length is defined as the data length excluding the frame header and the frame tail. The check code is generated by CRC check.
[0022] As a further improvement of the present invention, the client or server performs AES decryption on the successfully verified data, including:
[0023] The data is decrypted using the same CBC working mode and the same custom key as the data AES encryption process to obtain plaintext.
[0024] As a further improvement of the present invention, the data area is the business logic and specific communication content to be sent, and has a variable length.
[0025] The present invention also provides a TCP custom protocol communication system based on AES encryption, comprising: a connection establishment module, a data encryption transmission module, a data verification module and a data decryption execution module;
[0026] The connection establishment module is used to:
[0027] Establish a TCP communication connection between the client and the server;
[0028] The data encryption transmission module is used to:
[0029] The client or the server transmits data via a TCP long connection, the data format adopts the data format of the TCP custom protocol, and the data area of the transmitted data is encrypted by AES;
[0030] The data verification module is used to:
[0031] The client or the server verifies the received data, and if the verification fails, stops the processing flow and responds to the client or the server;
[0032] The data decryption execution module is used to:
[0033] If the verification is successful, the client or server performs AES decryption on the successfully verified data, processes the data according to the instruction type in the decrypted data, and responds to the client or server after the processing is completed.
[0034] Compared with the prior art, the present invention has the following beneficial effects:
[0035] The present invention adopts the TCP protocol between the client and the server. The TCP protocol itself has the characteristics of reliable transmission. By customizing the data format, multiple data verifications are implemented during the data transmission process, which can ensure that the data reaches the receiving end accurately. The present invention also integrates AES encryption into the TCP custom protocol. AES encryption realizes the security of data transmission. That is, the present invention realizes the combination of data transmission security and reliability, ensures the complete transmission of data, avoids problems such as decryption failure caused by data loss or disorder, greatly improves the scalability, security and flexibility of the communication protocol, and improves data transmission efficiency.
[0036] The data sent between the client and the server of the present invention is encrypted by AES, and a custom 128-bit key is used during encryption, which greatly improves the confidentiality of the data and makes the sent data impossible to crack, thereby increasing the confidentiality of the data; when data is exchanged, the data length of the data area is variable, which makes the custom protocol more flexible and can adapt to the data content of different products in automated production, making the protocol more adaptable; the exchanged data, including the frame header, frame tail, frame length and check code, are verified to ensure the accuracy of the data exchanged between the client and the server.
[0037] The TCP custom protocol of the present invention can flexibly adjust the content and format of the protocol according to the needs of actual application scenarios. The TCP custom protocol based on AES encryption can select AES key lengths of different lengths according to data sensitivity, achieving a balance between security and performance. Customized header information can also be added to identify the data type, encryption version, verification information, etc., to facilitate processing by the data recipient. In addition, as technology develops and security requirements change, the AES encryption algorithm can be upgraded, such as adopting more advanced encryption modes (such as CBC and GCM), without requiring large-scale changes to the entire communication architecture, making the protocol more adaptable and resilient.
[0038] The present invention constructs a data accuracy assurance system through CRC16 check and format check of frame header, frame tail, frame length, etc., combining the dual mechanisms of "format legitimacy verification" and "data integrity check" to ensure the accuracy of transmitted data. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 A flowchart of a TCP custom protocol communication method based on AES encryption disclosed in an embodiment of the present invention;
[0040] Figure 2 This is a configuration diagram of an embodiment of the present invention using Siemens PLC S7-1200 as a client;
[0041] Figure 3This is a parameter configuration diagram of the Siemens AES encryption instruction CIPHER function block disclosed in one embodiment of the present invention;
[0042] Figure 4 The present invention discloses an embodiment of the AES encryption and decryption method of the TCP custom protocol based on AES encryption. DETAILED DESCRIPTION
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0044] The present invention is described in further detail below with reference to the accompanying drawings:
[0045] like Figure 1 As shown, the present invention provides a TCP custom protocol communication method based on AES encryption, including:
[0046] S1. Establish a TCP communication connection between the client and the server;
[0047] in,
[0048] The client and server are connected asynchronously via TCP;
[0049] Further,
[0050] The server obtains the local IP address and port number, and starts TcpServer to asynchronously listen for client connections;
[0051] The client sends a connection request, and the server verifies the client's IP address and port number. If the client is legitimate, the server sends the local IP address and port number to the client to establish a connection.
[0052] Specifically,
[0053] Taking the automated production process of a certain product as an example, the Siemens PLC S7-1200 is used as the client. The Siemens PLC S7-1200 is configured as the client. The client, as the lower computer (PLC), needs to communicate with the upper computer server. The Siemens PLC S7-1200 sends a connection request to the server. The server monitors the connection request of the Siemens PLC S7-1200, obtains the IP address and port number of the Siemens PLC S7-1200, and determines whether the client is a legal client based on the IP address and port number. If it is an illegal client, the connection is prohibited. If it is a legal client, the server sends the local IP address and port number to the client. The Siemens PLC S7-1200 actively connects to the server based on the server's IP address and port number, and uses TSEND-C and TRCV to receive and send instructions; the server is opened through SocketServer on the server, and an asynchronous connection is used to wait for the client's connection.
[0054] S2. The client or server transmits data through a TCP long connection. The data format adopts the data format of the TCP custom protocol and the data area of the transmitted data is encrypted with AES.
[0055] in,
[0056] TCP persistent connection is a network communication mode in which, after establishing a TCP connection between the client and the server, the connection is maintained for a long time, allowing multiple two-way data transmissions, rather than immediately disconnecting after each communication. This can reduce the connection establishment overhead and improve real-time performance and interaction efficiency.
[0057] The server or client splices the sent data according to the data format of the TCP custom protocol. The data format of the TCP custom protocol includes the frame header, frame length, frame type, source, destination, time, frame count, data area, check code and frame tail. The check code is calculated using CRC checksum.
[0058] The data area of the transmitted data is AES encrypted, including:
[0059] The transmitted data is padded according to the AES algorithm, and the length of the padded data is an integer multiple of 16 bytes;
[0060] The padded data is encrypted using the CBC working mode (Cipher Block Chaining mode) and a custom key, and the ciphertext is sent to the client or server through the TCP custom protocol.
[0061] Further,
[0062] Append the initial vector IV to the encrypted ciphertext, and send the ciphertext and the initial vector IV to the client or server through the TCP custom protocol.
[0063] Each communication uses a different initialization vector IV to avoid the same plaintext generating the same ciphertext.
[0064] Specifically,
[0065] In the data format of the TCP custom protocol, the frame header has a total of six bytes, which is a fixed identifier, which is the ASCII six-letter "$START" in the present invention; the frame length is two bytes, indicating the length of the entire frame, the frame type is one byte long, indicating whether the data is in a sending or receiving state; the source is one byte long, indicating the sending object of the data; the destination is one byte long, indicating the receiving object of the data; the time is eight bytes long, indicating the time when the data is sent; the frame count is eight bytes long, indicating the number of times the data is sent; the length of the data area is variable, indicating the business logic to be sent and the specific communication content; the check code is two bytes, and the check code is calculated by the CRC16 algorithm; the frame tail is four bytes, which is a fixed identifier, which is the ASCII six-letter "$END" in the present invention.
[0066] After concatenating the data according to the TCP custom protocol data format, PKCS#7 padding is used to ensure that the data length is an integer multiple of 16 bytes. The data is encrypted using the CBC working mode and the custom key, and the initial vector (IV) is appended. Finally, the ciphertext and initial vector (IV) are sent to the server or client via the TCP protocol.
[0067] S3. The client or server verifies the received data. If the verification fails, the processing flow is stopped and a response is given to the client or server.
[0068] in,
[0069] The client or server verifies the received data, including: verifying the frame header, frame tail, frame length and check code respectively;
[0070] The frame header is defined as $START and the frame tail is defined as $END. The frame header and frame tail are converted into ASCII codes and stored at the beginning and end of the transmitted data respectively. The frame length is defined as the data length excluding the frame header and frame tail. The check code is generated by CRC check.
[0071] The verification process is:
[0072] Verify the frame header and compare it with the ASCII code of "$START" to see if it matches exactly.
[0073] Verify the end of the frame and compare it with the ASCII code of "$END" to see if it matches exactly.
[0074] Through the received data, determine whether the frame length matches the length of the received data;
[0075] Use CRC16 to check whether the check code is correct.
[0076] S4. If the verification is successful, the client or server performs AES decryption on the successfully verified data, processes the data according to the instruction type in the decrypted data, and responds to the client or server after the processing is completed.
[0077] The client or server performs AES decryption on the successfully verified data, including:
[0078] The data is decrypted using the same CBC working mode and the same custom key as the data AES encryption process to obtain plaintext.
[0079] If a custom 128-bit key is used for encryption and decryption, the same 128-bit key is used for decryption, using the CBC working mode and an initialization vector (IV). After the data is decrypted, it is processed according to the TCP custom protocol and responded to the server or client after the processing is completed.
[0080] The present invention also provides a TCP custom protocol communication system based on AES encryption, comprising: a connection establishment module, a data encryption transmission module, a data verification module and a data decryption execution module;
[0081] Connection establishment module, used to:
[0082] Establish a TCP communication connection between the client and the server;
[0083] Data encryption transmission module, used for:
[0084] The client or server transmits data through a TCP long connection. The data format adopts the data format of the TCP custom protocol, and the data area of the transmitted data is encrypted with AES.
[0085] Data verification module, used for:
[0086] The client or server verifies the received data. If the verification fails, the processing flow is stopped and a response is given to the client or server.
[0087] Data decryption execution module, used to:
[0088] If the verification is successful, the client or server will perform AES decryption on the verified data, process it according to the instruction type in the decrypted data, and respond to the client or server after the processing is completed.
[0089] Example:
[0090] To ensure confidentiality, accuracy, and flexibility in data exchange during the automated production process of a certain product model, a Siemens PLC S7-1200 acts as a client. The client establishes a TCP connection with the server and sends data for two-way communication. The specific steps include:
[0091] Step 1: Open the TIAPortal V16 software of the Siemens PLC S7-1200 and select CPU1215C DCDCDC as the control core in the device configuration;
[0092] Step 2: Call the TSEND-C function block and TRCV function block in the Siemens PLC S7-1200 to perform TCP communication with the server. The TSEND-C function block configuration is as follows: Figure 2 As shown, it includes local configuration and remote configuration. Local configuration mainly includes the configuration of connection type, connection ID, connection data and port number, and remote configuration mainly includes the configuration of the server's IP address.
[0093] Step 3: The server obtains the local IP and port number through the GetLocalIP() and GetLocalPort() functions, then starts the server by instantiating the SocketServer object and listens for client connections in an asynchronous listening manner;
[0094] Step 4: When the server detects a client connection, it determines whether the client is legitimate by obtaining the client's IP address and port number. If it is a legitimate client, it sends the local IP and port number to the client, and the client actively establishes a connection with the server;
[0095] Step 5. Siemens PLC S7-1200 establishes an FC function block. This function block is mainly used to splice the data format of the custom protocol. The data format includes the frame header, frame length, frame type, source, destination, time, frame count, data area, check code, and frame tail.
[0096] Step 6. Call the AES encryption instruction CIPHER function block and encrypt the data area of the transmitted data by setting the parameters of the encryption instruction function block. The setting parameters include MODE, ALGORITHM, KEY, IV, IN, OUT, ERROR and STATUS. The parameter configuration meaning of each pin is as follows: Figure 3 As shown;
[0097] Step 7. Create an object on the server side and splice the data in the object according to the data format of the TCP custom protocol. The data format is the same as that in the Siemens PLC S7-1200.
[0098] Step 8. On the server side, call ICryptoTransform.TransformFinalBlock() function to perform AES encryption on the data area of the sent data. The encryption process is as follows: Figure 4 As shown;
[0099] Step 9. The server or client verifies the received data, verifies the frame header, and compares it with the ASCII of "$START" to see if it matches completely; verifies the frame tail, and compares it with the ASCII of "$END" to see if it matches completely; determines whether the frame length matches the length of the received data based on the received data; and finally verifies through CRC16 to determine whether the checksum is correct.
[0100] Step 10: The server or client performs AES decryption on the received data. The key is the same as the sender's key, which is 128 bits. The working mode is Cipher Block Chaining (CBC) mode, and it is used with an initialization vector. After the data is decrypted, it is processed according to the custom protocol and responded to the server or client after the processing is completed.
[0101] Advantages of the present invention:
[0102] The present invention adopts the TCP protocol between the client and the server. The TCP protocol itself has the characteristics of reliable transmission. By customizing the data format, multiple data verifications are implemented during the data transmission process, which can ensure that the data reaches the receiving end accurately. The present invention also integrates AES encryption into the TCP custom protocol. AES encryption realizes the security of data transmission. That is, the present invention realizes the combination of data transmission security and reliability, ensures the complete transmission of data, avoids problems such as decryption failure caused by data loss or disorder, greatly improves the scalability, security and flexibility of the communication protocol, and improves data transmission efficiency.
[0103] The data sent between the client and the server of the present invention is encrypted by AES, and a custom 128-bit key is used during encryption, which greatly improves the confidentiality of the data and makes the sent data impossible to crack, thereby increasing the confidentiality of the data; when data is exchanged, the data length of the data area is variable, which makes the custom protocol more flexible and can adapt to the data content of different products in automated production, making the protocol more adaptable; the exchanged data, including the frame header, frame tail, frame length and check code, are verified to ensure the accuracy of the data exchanged between the client and the server.
[0104] The TCP custom protocol of the present invention can flexibly adjust the content and format of the protocol according to the needs of actual application scenarios. The TCP custom protocol based on AES encryption can select AES key lengths of different lengths according to data sensitivity, achieving a balance between security and performance. Customized header information can also be added to identify the data type, encryption version, verification information, etc., to facilitate processing by the data recipient. In addition, as technology develops and security requirements change, the AES encryption algorithm can be upgraded, such as adopting more advanced encryption modes (such as CBC and GCM), without requiring large-scale changes to the entire communication architecture, making the protocol more adaptable and resilient.
[0105] The present invention constructs a data accuracy assurance system through CRC16 check and format check of frame header, frame tail, frame length, etc., combining the dual mechanisms of "format legitimacy verification" and "data integrity check" to ensure the accuracy of transmitted data.
[0106] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A TCP custom protocol communication method based on AES encryption, characterized in that: include: Establish a TCP communication connection between the client and the server; The client or the server transmits data via a TCP long connection, the data format adopts the data format of the TCP custom protocol, and the data area of the transmitted data is encrypted by AES; The client or the server verifies the received data, and if the verification fails, stops the processing flow and responds to the client or the server; If the verification is successful, the client or server performs AES decryption on the successfully verified data, processes the data according to the instruction type in the decrypted data, and responds to the client or server after the processing is completed.
2. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: The TCP communication connection is established between the client and the server, including: The server obtains the IP address and port number of the local machine and starts TcpServer to asynchronously monitor the client's connection; The client sends a connection request, and the server verifies the IP address and port number of the client. If the client is legitimate, the server sends the local IP address and port number to the client to establish a connection.
3. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: The data format of the TCP custom protocol includes a frame header, a frame length, a frame type, a source, a destination, a time, a frame count, a data area, a check code and a frame tail, wherein the check code is calculated using CRC check.
4. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: AES encryption is performed on the data area of the transmitted data, including: The transmission data is padded according to the AES algorithm, and the length of the padded data is an integer multiple of 16 bytes; The padded data is encrypted using the CBC working mode and a custom key, and the ciphertext is sent to the client or the server through the TCP custom protocol.
5. The TCP custom protocol communication method based on AES encryption according to claim 4, characterized in that: An initial vector IV is added to the encrypted ciphertext, and the ciphertext and the initial vector IV are sent to the client or the server through a TCP custom protocol.
6. The TCP custom protocol communication method based on AES encryption according to claim 5, characterized in that: Each communication uses a different initialization vector IV.
7. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: The client or the server verifies the received data, including: The frame header, frame tail, frame length and check code are checked respectively. The frame header is defined as $START and the frame tail is defined as $END. The frame header and frame tail are converted into ASCII codes and stored at the beginning and end of the transmitted data respectively. The frame length is defined as the data length excluding the frame header and the frame tail. The check code is generated by CRC check.
8. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: The client or server performs AES decryption on the successfully verified data, including: The data is decrypted using the same CBC working mode and the same custom key as the data AES encryption process to obtain plaintext.
9. The TCP custom protocol communication method based on AES encryption according to claim 1, characterized in that: The data area is the business logic and specific communication content to be sent, and its length is variable.
10. A TCP custom protocol communication system based on AES encryption, implementing a TCP custom protocol communication method based on AES encryption as claimed in any one of claims 1 to 9, characterized in that: include: Connection establishment module, data encryption transmission module, data verification module and data decryption execution module; The connection establishment module is used to: Establish a TCP communication connection between the client and the server; The data encryption transmission module is used to: The client or the server transmits data via a TCP long connection, the data format adopts the data format of the TCP custom protocol, and the data area of the transmitted data is encrypted by AES; The data verification module is used to: The client or the server verifies the received data, and if the verification fails, stops the processing flow and responds to the client or the server; The data decryption execution module is used to: If the verification is successful, the client or server performs AES decryption on the successfully verified data, processes the data according to the instruction type in the decrypted data, and responds to the client or server after the processing is completed.