Data encryption transmission method and system based on TSN

By dividing the encryption time window on the device clock cycle and configuring dynamic keys, the problem of data transmission delay in the existing technology is solved, and the security and real-time performance of data transmission are both taken into account. It is suitable for data encryption transmission in the field of industrial control.

CN120602177APending Publication Date: 2025-09-05EVOC SMART IOT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510832030.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing encryption technologies cannot meet the high real-time requirements of the industrial control field while ensuring data transmission security. In particular, when processing large amounts of data, it will cause data transmission delays, affecting the real-time monitoring and control of the production process.

Method used

By dividing the encryption time window based on the device's clock cycle and configuring a dynamic key for each window, the time-aware shaping protocol is used to complete the sending and receiving of data within the same time window. The dynamic key is calculated based on the specific time point within the encryption time window and the device identification information, ensuring the encryption and decryption of data at the sending and receiving ends.

Benefits of technology

It ensures the security of data transmission while improving the real-time performance of data transmission and reducing delays, thus meeting the real-time requirements of the industrial control field.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602177A_ABST
    Figure CN120602177A_ABST
Patent Text Reader

Abstract

The invention provides a TSN-based data encryption transmission method and system, and the method comprises the steps: dividing a plurality of encryption time windows in a clock period of a current device through a time perception shaping protocol, and enabling the current device and a safety device to complete the sending and receiving of the same data in the same encryption time window, the security device is a device which is divided with the same encryption time window as the current device on a clock period; a dynamic key is configured for each encryption time window, so that when the current equipment sends data through the encryption time window, the sent data is encrypted through the dynamic key, and when the data is received through the encryption time window, the data is decrypted by using the same dynamic key as the data sending end; wherein the dynamic key is obtained by calculating a specific time point in the encryption time window and the equipment identification information of the data sending end. According to the invention, the real-time performance of data transmission can be improved while the security of data transmission is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data encryption technology, and in particular to a TSN-based data encryption transmission method and system. Background Art

[0002] In the industrial control sector, real-time data transmission is crucial. However, existing encryption technologies often fail to meet the requirements of high-speed data transmission due to factors such as algorithm complexity and network latency. For example, some encryption technologies can cause data transmission delays when processing large amounts of data, hindering real-time monitoring and control of production processes.

[0003] Therefore, how to improve the real-time performance of data transmission while ensuring the security of data transmission has become an urgent problem that needs to be solved. Summary of the Invention

[0004] To solve the above problems, the present invention provides a TSN-based data encryption transmission method and system, which divides the encryption time window on the clock cycle of the device and configures a dynamic key for each encryption time window. This can ensure the security of data transmission while improving the real-time performance of data transmission.

[0005] In a first aspect, the present invention provides a data encryption transmission method based on TSN, the method comprising:

[0006] The time-aware shaping protocol divides the clock cycle of the current device into multiple encryption time windows. The current device and the security device can send and receive the same data within the same encryption time window. The security device is a device with the same encryption time window divided into the clock cycle as the current device.

[0007] Configure a dynamic key for each encryption time window. When the current device sends data during the encryption time window, it uses the dynamic key to encrypt the data it sends. When receiving data during the encryption time window, it uses the same dynamic key as the data sender to decrypt the data.

[0008] The dynamic key is calculated based on the specific time point within the encryption time window and the device identification information of the data sending end.

[0009] Optionally, before the step of dividing the clock cycle of the current device into multiple encryption time windows using the time-aware shaping protocol, the method further includes:

[0010] Synchronize the clock cycle of the current device with the clock cycle of the security device.

[0011] Optionally, the step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes:

[0012] Determine whether the current device is a master device, which is one of all security devices;

[0013] If not, receive the synchronization operation message sent by the master device and record the time t2 when the synchronization operation message is received; receive the follow message sent by the master device, which carries the time t1 when the master device sent the synchronization operation message; send a delay request message and record the time t3 when the delay request message is sent; receive the delay response message sent by the master device, which carries the time t4 when the master device received the delay request message;

[0014] Calculate the clock offset of the current device relative to the master device based on time t1, time t2, time t3, and time t4.

[0015] The clock cycle of the current device is adjusted according to the clock offset so that the clock cycle of the current device is synchronized with the clock cycle of the master device.

[0016] Optionally, the method further comprises:

[0017] When it is determined that the current device is the master device, it sends a synchronization operation message and records the time t1 of sending the synchronization operation message; sends a follow message; receives a delay request message and records the time t4 of receiving the delay request message; and sends a delay response message.

[0018] Optionally, before synchronizing the clock cycle of the current device with the clock cycle of the security device, the method further includes:

[0019] Send a MAC address registration request to register the current device, and when the current device is successfully registered, the current device is added to the flow whitelist. The MAC address registration request contains the MAC address of the current device.

[0020] The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow table whitelist.

[0021] Optionally, the method further comprises:

[0022] A heartbeat packet is sent every preset time, and the heartbeat packet contains timestamp information;

[0023] Receive heartbeat packets sent by other devices, and calculate the delay time of receiving the heartbeat packets sent by other devices based on the timestamp information in the heartbeat packets received from other devices;

[0024] Determine whether the delay time exceeds the preset delay threshold. If so, trigger an alarm operation.

[0025] In a second aspect, the present invention provides a data encryption transmission system based on TSN, the system comprising:

[0026] a partitioning module configured to partition a clock cycle of a current device into multiple encryption time windows using a time-aware shaping protocol, so that the current device and a security device can complete transmission and reception of the same data within the same encryption time window, where the security device is a device having the same encryption time window partitioned on the clock cycle as the current device;

[0027] a configuration module configured to configure a dynamic key for each encryption time window, so that when the current device sends data through the encryption time window, the current device encrypts the data sent by using the dynamic key, and when the current device receives data through the encryption time window, the current device decrypts the data by using the same dynamic key as the data sender;

[0028] The dynamic key is calculated based on the specific time point within the encryption time window and the device identification information of the data sending end.

[0029] Optionally, the system further includes:

[0030] The clock synchronization module is configured to synchronize the clock cycle of the current device with the clock cycle of the security device before executing the partitioning module.

[0031] Optionally, the clock synchronization module includes:

[0032] A determination submodule is configured to determine whether the current device is a master device, where the master device is one of all the security devices;

[0033] A first receiving submodule is configured to receive a synchronization operation message sent by the master device when the judging submodule determines that the current device is not the master device, and record a time t2 at which the synchronization operation message is received;

[0034] The second receiving submodule is configured to receive a follow message sent by the master device, wherein the follow message carries the time t1 at which the master device sends the synchronization operation message;

[0035] A first sending submodule is configured to send a delay request message and record a time t3 at which the delay request message is sent;

[0036] A third receiving submodule is configured to receive a delay response message sent by the master device, where the delay response message carries a time t4 at which the master device receives the delay request message;

[0037] The calculation submodule is configured to calculate a clock offset of the current device relative to the master device based on time t1, time t2, time t3, and time t4;

[0038] an adjustment submodule, configured to adjust a clock period of the current device according to the clock offset so as to synchronize the clock period of the current device with the clock period of the master device;

[0039] The second sending submodule is configured to send a synchronization operation message when the judging submodule determines that the current device is the master device, and record the time t1 of sending the synchronization operation message;

[0040] a third sending submodule, configured to send a follow message;

[0041] a fourth receiving submodule, configured to receive the delay request message and record a time t4 at which the delay request message is received;

[0042] The fourth sending submodule is configured to send a delay response message.

[0043] Optionally, the system further includes:

[0044] The registration request module is configured to send a MAC address registration request to register the current device before executing the clock synchronization module, and when the current device is successfully registered, the current device is added to the flow whitelist, and the MAC address registration request includes the MAC address of the current device;

[0045] The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow table whitelist.

[0046] The TSN-based data encryption transmission method and system provided by the embodiment of the present invention divides the clock cycle of the current device into encryption time windows and configures a dynamic key for each encryption time window. In this way, when the data sent by the data sending end passes through the encryption time window, the device can encrypt the data using the corresponding dynamic key. At the same time, the data receiving end will use the same dynamic key to decrypt the corresponding data in the same encryption time window. The dynamic key will change continuously over time to realize encrypted transmission of data, thereby ensuring the security of data transmission while improving the real-time performance of data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the conventional technology, the following briefly introduces the drawings required for use in the embodiments or the conventional technology descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0048] Figure 1This is a schematic flowchart of a TSN-based data encryption transmission method according to an embodiment of the present application;

[0049] Figure 2 A schematic flow chart of encrypting data on a current device according to an embodiment of the present application;

[0050] Figure 3 A schematic flowchart of clock cycle synchronization of a current device according to an embodiment of the present application;

[0051] Figure 4 A schematic overall flow chart of implementing data encryption transmission on the current device according to an embodiment of the present application;

[0052] Figure 5 This is a schematic flow chart of a network relay filtering a current device according to an embodiment of the present application;

[0053] Figure 6 This is a schematic flowchart of each device accessing the network where the security device is located according to an embodiment of the present application;

[0054] Figure 7 This is a schematic structural diagram of a TSN-based data encryption transmission system according to an embodiment of the present application. DETAILED DESCRIPTION

[0055] To facilitate understanding of the present application, the present application will be described more fully below with reference to the accompanying drawings. The accompanying drawings provide embodiments of the present application. However, the present application may be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to make the disclosure of the present application more thorough and comprehensive.

[0056] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are for the purpose of describing specific embodiments only and are not intended to limit this application.

[0057] When used herein, the singular forms "a", "an", and "the" may also include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the terms "include / comprise" or "have" and the like specify the presence of stated features, integers, steps, operations, components, parts, or combinations thereof, but do not preclude the possibility of the presence or addition of one or more other features, integers, steps, operations, components, parts, or combinations thereof.

[0058] In the first aspect, the present invention provides a data encryption transmission method based on TSN (Time-Sensitive Networking, time-sensitive network), see Figure 1The method includes steps S101 to S102.

[0059] Step S101: A plurality of encryption time windows are divided on the clock cycle of the current device through a time-aware shaping protocol.

[0060] The current device and the security device can complete the sending and receiving of the same data within the same encryption time window. The security device is a device that has the same encryption time window as the current device divided into clock cycles.

[0061] It is understandable that the current device can function as both a data transmitter and a data receiver to transmit and receive data with at least one security device. The time-aware shaping protocol includes, but is not limited to, the IEEE 802.1qbv protocol, which is not specifically limited in this embodiment.

[0062] The IEEE 802.1qbv protocol defines a time-aware traffic scheduling mechanism. Its core principles include time period division, gated list control, and precise time scheduling. Gated list control involves controlling the flow of data traffic through a gated list. Only traffic permitted in the gated list is allowed to travel through specific network paths, while other traffic is blocked.

[0063] Gating list control is implemented by configuring the network router to specify which source MAC addresses or specific traffic types are allowed to pass through gating. This divides a clock cycle into multiple time windows, and flows of different priorities can choose which priority flows are allowed within each time window based on user configuration. These multiple time windows are divided into encrypted time windows and standard time windows. Encrypted time windows transmit data that meets the requirements for MAC addresses or traffic types, while other data that does not meet the requirements is transmitted through standard time windows.

[0064] Precise time scheduling means scheduling the sending and receiving of data traffic according to a precise time plan, ensuring that each data packet is transmitted and processed at a specific time to meet real-time requirements. This is achieved by precisely dividing time periods based on the IEEE 802.1AS time synchronization protocol and scheduling and controlling traffic within each time period. With precise time synchronization, network routers can accurately know when each data packet should be sent and received, thus achieving precise time scheduling. Gated time switching relies heavily on this time accuracy, as synchronized gate opening and closing is only possible when all devices are aligned.

[0065] Step S102: Configure a dynamic key for each encryption time window so that when the current device sends data through the encryption time window, it encrypts the data sent by the dynamic key, and when receiving data through the encryption time window, it uses the same dynamic key as the data sender to decrypt the data.

[0066] For example, sending a byte on a gigabit network takes approximately 8 nanoseconds. When sending a maximum 1500-byte data packet, the time from the data transmitter to the data receiver is generally less than 12 microseconds, and the window period can be set to 1 millisecond. The first 500 microseconds are when the encryption window opens and encrypted data is sent. The second 500 microseconds are when the encryption window closes and encrypted data transmission is prohibited. During this period, all data encryption and decryption keys are accurate to the millisecond, so they can all be considered to be synchronized. During this 500 microsecond period, encrypted data can generally be transmitted normally, allowing the data receiver to complete decryption within the same encryption window.

[0067] The dynamic key is calculated based on the specific time point within the encryption time window and the device identification information of the data sending end.

[0068] In this embodiment, combined with Figure 2 The dynamic key is calculated using the encryption algorithm based on the start time of the encryption window, the MAC address of the current device, and the ID of the encryption window. The encryption algorithm includes but is not limited to the HMAC-SHA256 algorithm.

[0069] Combine Figure 2 ,The method also includes preparing encryption basic parameters, which includes generating a random initialization vector (IV, 16 bytes) as a non-repeating initial value for AES-GCM encryption;

[0070] Build the encryption environment, which includes initializing the AES-GCM cipher with a dynamic key and IV, and adding the current device ID (plaintext) as authentication data (AAD);

[0071] Encrypt data and verify integrity, which includes performing AES-GCM encryption on the data to be transmitted, generating ciphertext and authentication tags to verify data integrity and authenticity;

[0072] Integrate the encryption results, including packaging the ciphertext and authentication tag into a result set for the receiver to decrypt and verify.

[0073] In the encryption process, it can be expressed as C = E k (P, IV), T = MAC k (AAD||C).

[0074] Where C represents ciphertext, E_k represents the encryption function using key k, P represents plaintext, IV represents the initialization vector, T represents the authentication tag, MAC_k represents the message authentication code function, and AAD represents the additional authentication data.

[0075] It should be noted that the dynamic key is a temporary key dynamically generated based on the encryption time window, which enhances the timeliness security of encryption; IV (initialization vector) ensures that the same plaintext generates different ciphertext in different encryption cycles, thus preventing replay attacks; AAD (additional authentication data) provides plaintext association authentication, such as timestamps and protocol headers, to prevent encrypted data from being tampered with; authentication tags are used to verify the integrity and source legitimacy of data, such as SHA-256-HMAC or AES-GCM authentication tags.

[0076] The TSN-based data encryption transmission method and system provided in this embodiment divides the clock cycle of the current device into encryption time windows and configures a dynamic key for each encryption time window. In this way, when the data sent by the data sending end passes through the encryption time window, the device can encrypt the data using the corresponding dynamic key. At the same time, the data receiving end will use the same dynamic key to decrypt the corresponding data in the same encryption time window. The dynamic key will change continuously over time to realize encrypted data transmission, thereby ensuring the security of data transmission while improving the real-time performance of data transmission.

[0077] In a further optional embodiment of this embodiment, before the step of dividing the clock cycle of the current device into multiple encryption time windows using the time-aware shaping protocol, the method further includes:

[0078] According to the time synchronization protocol, the clock cycle of the current device is synchronized with the clock cycle of the security device.

[0079] Time synchronization protocols include, but are not limited to, IEEE 802.1AS. IEEE 802.1AS is a simplified version of PTP (Precision Time Protocol) designed specifically for Industrial Ethernet. Its core principle is to select an optimal clock source (Grandmaster Clock). Users can also specify a grandmaster clock, calculate propagation delay, and compensate for clock skew through a configuration file.

[0080] In a further optional embodiment of this embodiment, in combination with Figure 3 The steps of synchronizing the clock cycle of the current device with the clock cycle of the security device include:

[0081] Determine whether the current device is a Grandmaster device, which is one of all security devices.

[0082] If not, receive the synchronization operation message, i.e., the Sync message, sent by the master device, and record the time t2 when the synchronization operation message is received; receive the follow-up message, i.e., the Follow-Up message, sent by the master device, which carries the time t1 when the master device sent the synchronization operation message; send a delay request message, i.e., the Delay-Req message, and record the time t3 when the delay request message is sent; receive the delay response message, i.e., the Delay-Rsp message, sent by the master device, which carries the time t4 when the master device received the delay request message; calculate the clock offset of the current device relative to the master device based on time t1, time t2, time t3 and time t4; adjust the clock period of the current device based on the clock offset to synchronize the clock period of the current device with the clock period of the master device.

[0083] Specifically, the clock offset Offset = t2 - t1 - D path ,

[0084] The clock offset is added to the current device's clock, resulting in the adjusted clock period. At this point, the current device's clock period is synchronized with the master device's clock period. Furthermore, based on the core principles of the IEEE 802.1AS protocol described above, the master device can be selected by the user or based on the accuracy of each device's clock source.

[0085] It is understandable that among many safety devices, except for the master device, the rest of the safety devices are slave clock devices. The clock corresponding to the master device is the master clock, and the clock of the slave clock device before synchronization is the slave clock.

[0086] In a further optional embodiment of this embodiment, the method also includes: when it is determined that the current device is the master device, sending a synchronization operation message and recording the time t1 of sending the synchronization operation message; sending a follow message; receiving a delay request message and recording the time t4 of receiving the delay request message; sending a delay response message.

[0087] In a further optional embodiment of this embodiment, in combination with Figure 4 Before synchronizing the clock cycle of the current device with the clock cycle of the security device, the method further includes:

[0088] A MAC address registration request is sent to register the current device, and when the current device is successfully registered, the current device is added to the flow whitelist. The MAC address registration request includes the MAC address of the current device.

[0089] It's important to note that the MAC address registration request sent by the current device is sent to the network router that connects various interactive devices. This means that the current device communicates with at least one security device through the network router. Upon receiving the MAC address registration request, the network router verifies the MAC address and, upon successful verification, adds the current device to the whitelist, thus completing the device's registration confirmation.

[0090] The network relay is a switch or a router, etc. In this embodiment, the network relay is a switch.

[0091] The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow table whitelist.

[0092] It is understandable that for devices that fail to register successfully, although they can interact with other security devices through the switch, since the device is not in the flow whitelist, the device cannot be configured with an encryption time window and a dynamic key to encrypt the sent data or decrypt the received encrypted data.

[0093] The flow whitelist mechanism allows the switch to only allow data flows from specific source MAC addresses. Specifically, the switch configures the MAC addresses of devices that allow time synchronization, specifically security devices, and prevents clock synchronization for devices not on the whitelist. This ensures that even if a non-encrypting device intercepts data, it will not obtain the same key, making it impossible to parse the encrypted data. Furthermore, the flow whitelist mechanism does not affect non-encrypted data packets, allowing other data packets to pass normally, allowing other non-encrypted services to continue as normal.

[0094] On the switch, you can enter the following command to filter out untrusted MAC devices: gptp domain 1clock-selectionmac-address 00:22:46:xx:xx:xx.

[0095] In a time synchronization network with gPTP (IEEE 802.1AS, Generalized Precision Time Protocol) domain number 1, only devices with MAC addresses starting with 00:22:46 can be selected as a grandmaster clock or participate in time synchronization.

[0096] In this command, gptp domain 1 indicates that the configuration is applied to the time synchronization network with gPTP domain number 1. gPTP uses domain numbers to distinguish different time synchronization domains. Each domain number represents an independent time synchronization network, ranging from 0 to 31. clock-selection indicates that the configuration is related to the master clock selection. In the gPTP protocol, slave clock devices select the best master clock as the time reference source based on the received Announce message. Clock-selection allows administrators to limit which devices can be selected as the master clock by specific conditions. mac-address00:22:46:xx:xx:xx is a MAC address filtering rule, indicating that only devices with MAC addresses starting with 00:22:46 can participate in time synchronization in this domain. xx:xx:xx is a wildcard, indicating that MAC addresses with any suffix are matched. For example, 00:22:46:01:02:03 matches, 00:22:46:AB:CD:EF matches, and 00:11:22:01:02:03 does not match.

[0097] It should be noted that in the gPTP protocol, the selection of the best master clock as the time reference source by the slave clock device is usually based on the following aspects.

[0098] First, the slave clock device evaluates the timestamp accuracy in the received Announce message. The higher the timestamp accuracy, the better the time synchronization performance of the master clock, and the more likely it is to be selected as the best master clock.

[0099] Secondly, the priority setting of the master clock is considered. If a higher priority is set for some master clocks in the network configuration, the master clock with a higher priority is more likely to be selected in the competition.

[0100] In addition, the slave clock device monitors the stability and reliability of the master clock. For example, it determines the master clock's stability by monitoring metrics such as the delay variation and packet loss rate of messages sent by the master clock. A master clock with good stability, low packet loss rate, and minimal delay variation is more likely to be considered the optimal master clock. This embodiment does not impose any specific restrictions on the selection of the master clock.

[0101] In a further optional embodiment of this embodiment, in combination with Figure 5 and Figure 6 The steps that the network mediator needs to perform include:

[0102] Obtain the domain number of the current device accessing the network router; determine whether the current device and the security device are devices in the same network based on the domain number, that is, determine whether the domain number of the current device is consistent with the domain number of the security device. If not, ignore the current device, so that the current device cannot interact with other devices connected to the network router for data. If so, obtain the MAC address of the current device; determine whether the MAC address of the current device matches the MAC address of the security device stored in the flow table whitelist. If so, allow the current device to perform clock cycle synchronization operations, that is, execute steps S101 to S102. If not, deny the current device from performing clock cycle synchronization operations, that is, the current device is an ordinary device.

[0103] In a further optional embodiment of this embodiment, the method also includes: sending a heartbeat packet once every preset time period, the heartbeat packet containing microsecond timestamp information; receiving heartbeat packets sent by other devices, and calculating the delay time of receiving the heartbeat packets sent by other devices based on the timestamp information in the heartbeat packets sent by other devices; judging whether the delay time exceeds a preset delay threshold, and if so, triggering an alarm operation.

[0104] Among them, the method for calculating the delay time is to subtract the time when the heartbeat packet is received from the timestamp information in the heartbeat packet to obtain the delay time; the preset duration and delay threshold can be set according to actual conditions. In this embodiment, the preset duration is 100μs and the delay threshold is 1μs.

[0105] In the method provided in this embodiment, in terms of time correlation, each encryption time window uses a different dynamic key. The size of the encryption time window can be configured within the range of 100μs-1ms, and the update frequency of the dynamic key is synchronized with the encryption time window. In terms of key strength, the AES-256-bit dynamic key algorithm is used to generate dynamic keys based on time and device information, and the HMAC (Hash-based Message Authentication Code) algorithm is used to ensure the security of key generation. In terms of protection mechanisms, authenticated encryption (AE) is used to protect data integrity, and the encryption time window can limit replay.

[0106] This method for implementing encrypted data transmission closely integrates time synchronization, window division, and encryption, ensuring both data security and real-time transmission reliability. Precise time synchronization and window division enable microsecond-level encryption key updates, significantly improving system security.

[0107] In the second aspect, an embodiment of the present invention provides a data encryption transmission system based on TSN, based on the method provided in the first aspect, combined with Figure 7The system includes security devices and network routers. Each security device includes:

[0108] a partitioning module configured to partition a clock cycle of a current device into multiple encryption time windows using a time-aware shaping protocol, so that the current device and a security device can complete transmission and reception of the same data within the same encryption time window, where the security device is a device having the same encryption time window partitioned on the clock cycle as the current device;

[0109] a configuration module configured to configure a dynamic key for each encryption time window, so that when the current device sends data through the encryption time window, the current device encrypts the data sent by using the dynamic key, and when the current device receives data through the encryption time window, the current device decrypts the data by using the same dynamic key as the data sender;

[0110] The dynamic key is calculated based on the specific time point within the encryption time window and the device identification information of the data sending end.

[0111] In a further optional embodiment of this embodiment, the security device further includes:

[0112] The clock synchronization module is configured to synchronize the clock cycle of the current device with the clock cycle of the security device before executing the partitioning module.

[0113] In a further optional embodiment of this embodiment, the clock synchronization module includes:

[0114] A determination submodule is configured to determine whether the current device is a master device, where the master device is one of all the security devices;

[0115] A first receiving submodule is configured to receive a synchronization operation message sent by the master device when the judging submodule determines that the current device is not the master device, and record a time t2 at which the synchronization operation message is received;

[0116] The second receiving submodule is configured to receive a follow message sent by the master device, wherein the follow message carries the time t1 at which the master device sends the synchronization operation message;

[0117] A first sending submodule is configured to send a delay request message and record a time t3 at which the delay request message is sent;

[0118] A third receiving submodule is configured to receive a delay response message sent by the master device, where the delay response message carries a time t4 at which the master device receives the delay request message;

[0119] The calculation submodule is configured to calculate a clock offset of the current device relative to the master device based on time t1, time t2, time t3, and time t4;

[0120] an adjustment submodule, configured to adjust a clock period of the current device according to the clock offset so as to synchronize the clock period of the current device with the clock period of the master device;

[0121] The second sending submodule is configured to send a synchronization operation message when the judging submodule determines that the current device is the master device, and record the time t1 of sending the synchronization operation message;

[0122] a third sending submodule, configured to send a follow message;

[0123] a fourth receiving submodule, configured to receive the delay request message and record a time t4 at which the delay request message is received;

[0124] The fourth sending submodule is configured to send a delay response message.

[0125] In a further optional embodiment of this embodiment, the system further includes:

[0126] The registration request module is configured to send a MAC address registration request to register the current device before executing the clock synchronization module, and when the current device is successfully registered, the current device is added to the flow whitelist, and the MAC address registration request includes the MAC address of the current device;

[0127] The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow table whitelist.

[0128] In a further optional embodiment of this embodiment, the security device further includes:

[0129] The sending module is configured to send a heartbeat packet every preset time, and the heartbeat packet contains timestamp information;

[0130] A receiving module is configured to receive heartbeat packets sent by other devices;

[0131] a calculation module configured to calculate a delay time of receiving a heartbeat packet sent by another device based on timestamp information in the heartbeat packet received from the other device;

[0132] A first determining module is configured to determine whether the delay time exceeds a preset delay threshold;

[0133] The trigger module is configured to trigger an alarm operation when the judgment module determines that the delay time exceeds a preset delay threshold.

[0134] In a further optional embodiment of this embodiment, the network relay includes:

[0135] A first acquisition module is configured to acquire a domain number of a current device accessing the network relay;

[0136] The second judgment module is configured to judge whether the current device and the security device are devices in the same network according to the domain number, that is, to judge whether the domain number of the current device is consistent with the domain number of the security device. If not, ignore the current device;

[0137] A second acquisition module is configured to acquire the MAC address of the current device when the second judgment module determines that the domain number of the current device is consistent with the domain number of the security device;

[0138] The third judgment module is configured to judge whether the MAC address of the current device matches the MAC address of the security device stored in the flow table whitelist. If so, the current device is allowed to perform the clock cycle synchronization operation; if not, the current device is denied the clock cycle synchronization operation.

[0139] The system provided in this embodiment is simple to use, easy to configure and manage, and reduces the maintenance cost and difficulty of use of the system.

[0140] Throughout this specification, references to terms such as "some embodiments," "other embodiments," and "desired embodiments" indicate that a particular feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present application. The schematic descriptions of these terms throughout this specification do not necessarily refer to the same embodiment or example.

[0141] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0142] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be determined by the appended claims.

Claims

1. A data encryption transmission method based on TSN, characterized in that: The method comprises: Using a time-aware shaping protocol, multiple encryption time windows are divided on the clock cycle of the current device. The current device and the security device can complete the transmission and reception of the same data within the same encryption time window. The security device is a device with the same encryption time window divided on the clock cycle as the current device. Configuring a dynamic key for each encryption time window, so that when the current device sends data through the encryption time window, the data to be sent is encrypted using the dynamic key, and when the current device receives data through the encryption time window, the data is decrypted using the same dynamic key as the data sender; The dynamic key is calculated based on a specific time point within the encryption time window and the device identification information of the data sending end.

2. The method according to claim 1, characterized in that Before the step of dividing a clock cycle of the current device into a plurality of encryption time windows using a time-aware shaping protocol, the method further includes: The clock cycle of the current device is synchronized with the clock cycle of the security device.

3. The method according to claim 2, characterized in that The step of adjusting the clock cycle of the current device to be synchronized with the clock cycle of the security device comprises: Determine whether the current device is a master device, the master device being one of all the security devices; If not, receive the synchronization operation message sent by the master device and record the time t2 when the synchronization operation message is received; receive the follow message sent by the master device, the follow message carrying the time t1 when the master device sent the synchronization operation message; send a delay request message and record the time t3 when the delay request message is sent; receive the delay response message sent by the master device, the delay response message carrying the time t4 when the master device received the delay request message; Calculating a clock offset of the current device relative to the master device based on the time t1, the time t2, the time t3, and the time t4; The clock cycle of the current device is adjusted according to the clock offset so that the clock cycle of the current device is synchronized with the clock cycle of the master device.

4. The method according to claim 3, characterized in that The method further comprises: When it is determined that the current device is the master device, the synchronization operation message is sent and the time t1 of sending the synchronization operation message is recorded; the follow message is sent; the delay request message is received and the time t4 of receiving the delay request message is recorded; and the delay response message is sent.

5. The method according to claim 2, characterized in that Before synchronizing the clock cycle of the current device with the clock cycle of the security device, the method further includes: Sending a MAC address registration request to register the current device, and when the current device is successfully registered, adding the current device to a flow whitelist, wherein the MAC address registration request includes the MAC address of the current device; The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow whitelist.

6. The method according to claim 1, characterized in that The method further comprises: Send a heartbeat packet every preset time, and the heartbeat packet contains timestamp information; Receive a heartbeat packet sent by another device, and calculate a delay time for receiving the heartbeat packet sent by the other device based on the timestamp information in the received heartbeat packet sent by the other device; Determine whether the delay time exceeds a preset delay threshold, and if so, trigger an alarm operation.

7. A data encryption transmission system based on TSN, characterized in that: The system comprises: a partitioning module configured to partition a clock cycle of a current device into a plurality of encryption time windows using a time-aware shaping protocol, wherein the current device and a security device can complete transmission and reception of the same data within the same encryption time window, wherein the security device is a device having the same encryption time window as the current device in its clock cycle; a configuration module configured to configure a dynamic key for each encryption time window, so that when the current device sends data through the encryption time window, the current device encrypts the sent data using the dynamic key, and when receiving data through the encryption time window, the current device decrypts the data using the same dynamic key as the data sender; The dynamic key is calculated based on a specific time point within the encryption time window and the device identification information of the data sending end.

8. The system according to claim 7, characterized in that The system further comprises: The clock synchronization module is configured to synchronize the clock cycle of the current device with the clock cycle of the security device before executing the division module.

9. The system according to claim 8, characterized in that The clock synchronization module includes: A determination submodule is configured to determine whether the current device is a master device, wherein the master device is one of all the security devices; a first receiving submodule configured to receive a synchronization operation message sent by the master device when the judging submodule determines that the current device is not the master device, and record a time t2 at which the synchronization operation message is received; A second receiving submodule is configured to receive a follow message sent by the master device, wherein the follow message carries the time t1 at which the master device sends the synchronization operation message; A first sending submodule is configured to send a delay request message and record a time t3 at which the delay request message is sent; a third receiving submodule, configured to receive a delay response message sent by the master device, wherein the delay response message carries a time t4 at which the master device receives the delay request message; a calculation submodule, configured to calculate a clock offset of the current device relative to the master device based on the time t1, the time t2, the time t3, and the time t4; an adjusting submodule, configured to adjust a clock period of the current device according to the clock offset so as to synchronize the clock period of the current device with the clock period of the master device; A second sending submodule is configured to send a synchronization operation message when the judging submodule judges that the current device is the master device, and record the time t1 of sending the synchronization operation message; a third sending submodule, configured to send the follow message; a fourth receiving submodule, configured to receive the delay request message and record a time t4 at which the delay request message is received; The fourth sending submodule is configured to send the delay response message.

10. The system according to claim 7, wherein: The system further comprises: a registration request module configured to, before executing the clock synchronization module, send a MAC address registration request to register the current device, and when the current device is successfully registered, add the current device to the flow whitelist, wherein the MAC address registration request includes the MAC address of the current device; The step of synchronizing the clock cycle of the current device with the clock cycle of the security device includes: synchronizing the clock cycle of the current device with the clock cycle of the security device when the MAC address of the current device is in the flow whitelist.