A network data transmission encryption system and method for industrial computer communication
By collecting the spatiotemporal status of equipment in a smart factory, predicting movement paths, and constructing dual-path handover plans, the problem of connection delays and interruptions caused by frequent changes in network topology in smart factories is solved, achieving efficient and reliable network access and data transmission.
Patent Information
- Application Number
- CN202511121277.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-08-12
AI Technical Summary
Existing industrial network encryption technologies cannot effectively cope with the frequently changing network topology and dynamic trust status of devices in smart factories, leading to security risks and efficiency issues, especially when devices roam across regions, resulting in frequent connection delays and interruptions.
By periodically and synchronously collecting physical space coordinates, motion vectors, and network signal strength from mobile terminals, the spatiotemporal status of the device is generated, the movement path is predicted, potential wireless access points are screened, a dual-path handover plan is constructed, and a temporary communication tunnel is established using instantaneous connection tokens to realize dynamic encryption strategies and end-to-end data transmission.
It significantly improves network access efficiency and communication continuity, reduces security connection interruptions caused by path prediction failures, and ensures stable transmission of critical industrial data and continuity of production processes.
Smart Images

Figure CN120614660B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication technology, and in particular to a network data transmission encryption system and method for industrial computer communication. Background Technology
[0002] In smart factories and advanced production lines, devices such as Automated Guided Vehicles (AGVs), collaborative robots, mobile workstations, and various temporarily connected smart tools frequently join and leave the network, causing the network topology to be constantly changing. However, existing industrial network encryption technologies are primarily designed for relatively static network environments, with their security architecture based on pre-configured fixed network topologies and relatively stable communication relationships. These technologies perform one-time authentication and key distribution upon initial device access, and then use fixed encryption algorithms and security policies. In the dynamic environment of a smart factory, this static encryption model cannot effectively cope with frequently changing network node relationships, leading to various security vulnerabilities and efficiency issues. Secondly, traditional authentication mechanisms are usually based on static identities and preset trust relationships, lacking support for dynamic trust assessment. In a smart factory environment, the trust status of devices should be dynamically adjusted according to their location, behavior patterns, and network topology relationships, rather than relying solely on initial authentication. Existing technologies cannot assess changes in the security status of mobile devices in real time, leading to an increase in the potential risk of unauthorized access, especially when devices move between different security domains. Summary of the Invention
[0003] Based on this, the present invention provides a network data transmission encryption system and method in industrial computer communication to solve at least one of the above-mentioned technical problems.
[0004] To achieve the above objectives, a method for encrypting network data transmission in industrial computer communication includes the following steps:
[0005] Step S1: During the continuous movement of the mobile terminal, its physical space coordinates, motion vector and network signal strength are periodically and synchronously collected to generate the device spatiotemporal state; based on the device spatiotemporal state, its movement path is predicted, thereby filtering out at least two potential wireless access point sets.
[0006] Step S2: Correct the mobile path based on the network signal strength in the device's spatiotemporal state, and select the first candidate network target and the second candidate network target from the set of potential wireless access points to construct a dual-path handover plan; determine the instantaneous connection token containing dual-path authentication based on the dual-path handover plan;
[0007] Step S3: During the continuous monitoring of network signals by the mobile terminal, when the preset signal strength switching conditions are met, an instantaneous connection message is broadcast to the candidate network target in the dual-path handover plan to establish a temporary communication tunnel.
[0008] Step S4: Report the real-time location of the mobile terminal through the temporary communication tunnel to determine the dynamic encryption strategy; complete the authentication handshake with the first candidate network target or the second candidate network target using the instantaneous connection token, and establish an end-to-end data transmission encryption link according to the dynamic encryption strategy and the temporary communication tunnel.
[0009] The present invention also provides a network data transmission encryption system for industrial computer communication, which executes the network data transmission encryption method for industrial computer communication as described above. The network data transmission encryption system for industrial computer communication includes:
[0010] The trajectory sensing module is used to periodically and synchronously collect the physical space coordinates, motion vectors and network signal strength of the mobile terminal during continuous movement to generate the spatiotemporal status of the device; based on the spatiotemporal status of the device, its movement path is predicted, thereby filtering out at least two potential wireless access point sets.
[0011] The dual-path planning module is used to correct the mobile path based on the network signal strength in the device's spatiotemporal state, and select a first candidate network target and a second candidate network target from the set of potential wireless access points to construct a dual-path handover plan; and determine the instantaneous connection token containing dual-path authentication based on the dual-path handover plan.
[0012] The communication switching module is used to broadcast an instantaneous connection message to the candidate network target in the dual-path handover plan when the preset signal strength switching conditions are met during the continuous monitoring of network signals by the mobile terminal, so as to establish a temporary communication tunnel.
[0013] The secure link establishment module is used to report the real-time location of the mobile terminal through a temporary communication tunnel to determine the dynamic encryption strategy; to complete the authentication handshake with the first or second candidate network target using a momentary connection token; and to establish an end-to-end data transmission encryption link according to the dynamic encryption strategy and the temporary communication tunnel.
[0014] The beneficial effects of this invention are as follows:
[0015] On the one hand, by periodically and synchronously collecting the physical space coordinates, motion vectors, and network signal strength of mobile terminals to generate the spatiotemporal state of the devices, and based on this, predictively forecasting their movement paths, this invention can pre-select candidate network targets and construct a dual-path handover plan containing first and second candidate targets. Furthermore, by pre-generating instantaneous connection tokens containing dual-path authentication information, the passive authentication request is transformed into an active pre-authorization mode, fundamentally solving the connection delay and interruption problems caused by the complexity of key establishment processes and the inability to adapt to frequent changes in network topology in traditional encryption methods. This significantly improves the network access efficiency of mobile devices when roaming across regions, ensuring the continuity of production processes and the real-time nature of data transmission.
[0016] On the other hand, by selecting a first candidate network target and a second candidate network target from a set of potential wireless access points and constructing a dual-path handover contingency plan, this invention provides a reliable redundancy mechanism for network handover. When a mobile terminal fails to establish a connection with the first candidate network target due to path changes or signal interference, a handover procedure with the second candidate network target can be initiated immediately. This design can readily cope with the rapidly changing network topology and unpredictable signals in industrial environments, significantly improving the success rate of network handover and the continuity of communication, and effectively reducing the problem of secure connection interruptions (cumulative 5-15 minutes / shift) caused by single-path prediction failures.
[0017] On the other hand, by reporting the real-time location of mobile terminals through temporary communication tunnels and determining dynamic encryption strategies based on the risk level of the physical area where they are located, this invention deeply binds network security strategies to the physical space security domain of the factory. This invention can intelligently adjust the encryption strength based on whether the equipment is in a high-risk core assembly area (using AES-256-GCM) or a low-risk storage area (using ChaCha20-Poly1305). While ensuring the highest security in the core area, it can reduce the encryption overhead for equipment in non-critical areas, thereby avoiding data transmission interruptions and business stagnation caused by single-point switching failures in terms of security and communication efficiency. It greatly improves communication reliability under complex working conditions and rapid changes in network topology, and ensures the stable transmission of critical industrial data. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating the steps of the network data transmission encryption method in industrial computer communication according to the present invention.
[0019] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0020] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. It is obvious that the embodiments described are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.
[0021] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor and / or microcontroller approaches.
[0022] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.
[0023] To achieve the above objectives, please refer to Figure 1 This invention provides a method for encrypting network data transmission in industrial computer communication, comprising the following steps:
[0024] Step S1: During the continuous movement of the mobile terminal, its physical space coordinates, motion vector and network signal strength are periodically and synchronously collected to generate the device spatiotemporal state; based on the device spatiotemporal state, its movement path is predicted, thereby filtering out at least two potential wireless access point sets.
[0025] In this embodiment of the invention, while the mobile terminal (such as an AGV) is in continuous motion, its multi-dimensional physical and network parameters are periodically and synchronously collected at a frequency of not less than 20Hz. The collected data includes: three-dimensional physical space coordinates provided by UWB (Ultra-Wideband) positioning base stations deployed within the factory; three-axis acceleration and angular velocity provided by the IMU (Inertial Measurement Unit) integrated into the terminal, from which the instantaneous motion vector is calculated; and received signal strength indication (RSSI) values of all surrounding wireless access points (APs) scanned by the terminal's wireless communication module. These heterogeneous data are timestamped and then encapsulated into a structured device spatiotemporal status data packet.
[0026] In one implementation of this invention, assuming that at a certain moment t=T0, the physical space coordinates of the AGV are collected as (10.2m, 35.4m, 1.1m), its motion vector is 1.5m / s, its direction angle is 45°, and the received network signal strength is {AP-1: -55dBm, AP-2: -88dBm, AP-3: -90dBm, AP-4: -92dBm}. These data together constitute the spatiotemporal state of the device at this moment. Based on this state, the movement path for the next 3 seconds is predicted, which will extend from (10.2, 35.4) to (13.4, 38.6). Comparing this predicted path with the preset factory AP coverage map, it is found that the path will successively enter the effective signal range (within the -85dBm equipotential line) of AP-2 and AP-3. Therefore, {AP-2, AP-3} are selected as the potential wireless access point set.
[0027] Step S2: Correct the mobile path based on the network signal strength in the device's spatiotemporal state, and select the first candidate network target and the second candidate network target from the set of potential wireless access points to construct a dual-path handover plan; determine the instantaneous connection token containing dual-path authentication based on the dual-path handover plan;
[0028] In this embodiment of the invention, the continuous trend of RSSI value changes in the spatiotemporal state of the device is analyzed to correct the deviation of pure physical motion prediction. If the RSSI change trend is consistent with the direction of physical motion prediction, the reliability of the predicted path is enhanced; if not, the prediction weight is appropriately reduced. Subsequently, APs in the potential wireless access point set are evaluated. Based on the intersection depth of the predicted path trajectory in its core signal coverage area (e.g., the -65dBm area), the estimated signal gain gradient, and the AP's own load, the APs are comprehensively ranked, and the two best and second-best APs are selected as the first and second candidate network targets, forming a dual-path handover plan.
[0029] In one implementation of this invention, analysis of the continuous spatiotemporal state of the devices revealed that the RSSI value of AP-2 steadily increased from -88dBm to -80dBm, while the RSSI value of AP-3 fluctuated around -90dBm, confirming that the AGV was moving towards AP-2. Further calculations showed that the predicted path length within the -65dBm core coverage area of AP-2 was 2.5 meters, while in the corresponding area of AP-3 it was only 0.8 meters. Therefore, AP-2 was selected as the first candidate network target, and AP-3 as the second candidate network target. These two targets were combined with the AGV IDs to form a dual-path handover plan: {AGV-ID: 007, Target 1: AP-2, Target 2: AP-3, Estimated Time 1: 2.8s}. Based on this plan, the central authentication server generated authentication key materials for AP-2 and AP-3 respectively, and encrypted and encapsulated them into an instantaneous connection token containing dual-path authentication information, which was pre-issued to the AGV.
[0030] Step S3: During the continuous monitoring of network signals by the mobile terminal, when the preset signal strength switching conditions are met, an instantaneous connection message is broadcast to the candidate network target in the dual-path handover plan to establish a temporary communication tunnel.
[0031] In this embodiment of the invention, a mobile terminal carrying a transient connection token continuously monitors the signal strength of the currently connected AP (AP-1) and the first candidate network target (AP-2) in the dual-path handover plan at a high frequency (e.g., once every 50 milliseconds). When the signal strength of the current AP is detected to have attenuated to a certain preset lower threshold, while the signal strength of the target AP has increased to a certain preset upper threshold, the handover condition is triggered. At this time, the terminal immediately broadcasts its transient connection token to the common channel of the first candidate network target to request the establishment of a connection.
[0032] In one implementation of this invention, the preset switching condition is: the RSSI value of the current AP (AP-1) is less than -82dBm and the RSSI value of the first candidate target (AP-2) is greater than -78dBm. At t=T0+2.7s, the AGV detects that the signal strength of AP-1 is -83dBm and the signal strength of AP-2 is -77dBm, at which point the switching condition is met. The AGV immediately extracts the portion prepared for AP-2 from the instantaneous connection token and broadcasts it to AP-2. After AP-2 receives and verifies the token, it does not need to communicate with the central server again and directly establishes a basic, unadjusted temporary communication tunnel with the AGV.
[0033] Step S4: Report the real-time location of the mobile terminal through the temporary communication tunnel to determine the dynamic encryption strategy; complete the authentication handshake with the first candidate network target or the second candidate network target using the instantaneous connection token, and establish an end-to-end data transmission encryption link according to the dynamic encryption strategy and the temporary communication tunnel.
[0034] In this embodiment of the invention, the mobile terminal immediately reports its most accurate real-time UWB coordinates to the central server via the newly established link the instant the temporary communication tunnel is successfully established. Based on these coordinates, the server queries the risk level corresponding to the module at that location in a preset factory space security map, and selects the appropriate encryption protocol accordingly, forming a dynamic encryption strategy. Simultaneously, the terminal and the access point (AP) complete the final authentication handshake using the pre-installed key material in the instantaneous connection token, and apply the dynamic encryption strategy to the tunnel, thereby solidifying it into an end-to-end data transmission encryption link with an appropriate security level.
[0035] In one implementation of this invention, the AGV reports its real-time coordinates (14.5m, 39.0m) through a temporary communication tunnel established with AP-2. The central server queries the map and finds that these coordinates are located in the "core component quality inspection area," belonging to the "high communication risk" level. Therefore, it determines the dynamic encryption strategy to be AES-256-GCM. The server immediately distributes this strategy to both the AGV and AP-2. Simultaneously, the AGV and AP-2 complete an authentication handshake based on a momentary connection token. Subsequently, both parties jointly apply the AES-256-GCM strategy to upgrade the temporary tunnel into a high-strength data transmission encryption link. If AP-2 does not respond to the AGV's broadcast within a specified time (e.g., 500ms), the AGV will automatically activate the second part of the contingency plan, broadcasting the token to AP-3 and repeating this process to ensure connection reliability.
[0036] Preferably, in step S1, during the continuous movement of the mobile terminal, periodically and synchronously collecting its physical space coordinates, motion vector, and network signal strength to generate the device's spatiotemporal state includes:
[0037] By deploying ultra-wideband positioning base stations within the factory, the physical coordinates of the mobile terminal are collected at a frequency of 10Hz to obtain the instantaneous spatial coordinates.
[0038] The inertial measurement unit integrated in the mobile terminal is used to obtain its three-axis acceleration, and the instantaneous motion vector is calculated based on the instantaneous spatial coordinates;
[0039] Using the instantaneous motion vector as a reference, the instantaneous spatial coordinates within a continuous 0.5s are forward propagated for verification to correct the positioning error and obtain a highly reliable trajectory point.
[0040] The raw RSSI sequence is obtained by continuously collecting at least 10 Received Signal Strength Indication values received by the mobile terminal from the current wireless access point in the past 1 second.
[0041] The original RSSI sequence, high-confidence trajectory points, and instantaneous motion vectors are encapsulated into the device's spatiotemporal state.
[0042] In this embodiment of the invention, a UWB tag is installed on the top of a mobile terminal (such as an AGV), and UWB positioning base stations are uniformly deployed on the factory ceiling. The central positioning server sends positioning requests to all base stations at a fixed period of 100 milliseconds (10Hz). The base stations calculate the real-time three-dimensional physical coordinates of the AGV by measuring the time difference of arrival (TDOA) of the signals emitted by the UWB tags.
[0043] In one implementation of this invention, it is assumed that at t=1.0s, the central positioning server determines the physical coordinates of the AGV as (10.21m, 35.43m, 1.10m) through the collaborative calculation of four UWB base stations. This coordinate data is then marked as the instantaneous spatial coordinates at that moment.
[0044] In this embodiment of the invention, the IMU integrated inside the AGV continuously outputs its triaxial acceleration and angular velocity data at a higher frequency (e.g., 100Hz). The IMU data closest to the instantaneous spatial coordinate timestamp is extracted. Simultaneously, by performing a difference operation on two consecutive instantaneous spatial coordinates, the average velocity and direction of the AGV within 100 milliseconds can be calculated.
[0045] In one implementation of this invention, it is assumed that the instantaneous spatial coordinates (10.21, 35.43, 1.10) at t=1.0s and the coordinates (10.10, 35.32, 1.10) at t=0.9s are obtained. Calculations show that the displacement within this time interval is approximately 0.156 meters, the direction angle is approximately 45 degrees, and therefore the velocity is 1.56 m / s. Combining this with the acceleration data provided by the IMU (e.g., x-axis acceleration ax=0.1 m / s²), the instantaneous motion vector at that moment is formed as: {velocity: 1.56 m / s, direction: 45°, acceleration: (0.1, 0.05, 0.0) m / s²}.
[0046] In this embodiment of the invention, the instantaneous spatial coordinates of the past 0.5 seconds (i.e., 5 acquisition cycles) are cached. Starting from the coordinate point 0.4 seconds ago, forward propagation (i.e., position estimation) is performed using the subsequent 4 consecutive instantaneous motion vectors to obtain a theoretical current position. Then, this theoretical position is compared with the latest acquired instantaneous spatial coordinates. If the deviation between the two is less than a preset threshold (e.g., 10cm), the latest instantaneous spatial coordinates are considered reliable; if the deviation is too large, the theoretical position is used for weighted correction. The final verified and corrected coordinate point is recorded as a high-reliability trajectory point.
[0047] In another implementation of this invention, it is assumed that the instantaneous motion vector predicted at t=0.5s should have coordinates at t=0.6s as (10.36, 35.58, 1.10). The actual UWB-acquired instantaneous spatial coordinates at t=0.6s are (10.38, 35.60, 1.10). The Euclidean distance between the two is less than a preset threshold of 10cm, thus passing the verification. The system uses a weighted average (e.g., predicted value weight 0.3, actual value weight 0.7) to calculate the final corrected coordinates (10.374, 35.594, 1.10). This verified and corrected coordinate point is marked as a high-confidence trajectory point. If the distance exceeds the threshold, the system temporarily discards the UWB reading and uses the motion vector prediction value as the high-confidence trajectory point to ensure trajectory continuity.
[0048] In this embodiment of the invention, the AGV's wireless communication module continuously scans and records the RSSI value of its currently connected AP (e.g., AP-1) at intervals of approximately 100ms. The system maintains a sliding queue with a time window of 1 second to store the most recent RSSI readings.
[0049] It should be noted that collecting at least 10 samples is necessary to perform trend analysis (such as calculating the slope), thereby more accurately judging the trend of signal strength changes and avoiding misjudgments caused by single signal jitter.
[0050] In one implementation of this invention, at time t=1.0s, the high-confidence trajectory point (10.21, 35.43, 1.10), the instantaneous motion vector {velocity: 1.56m / s, ...}, and the original RSSI sequence containing 10 RSSI values {-55dBm, ...}, along with the device ID and timestamp, are combined into a complete data packet. This data packet represents the final generated spatiotemporal state of the device used for subsequent decision-making.
[0051] Preferably, step S1, which involves predicting the device's movement path based on its spatiotemporal state to filter out at least two potential wireless access point sets, includes:
[0052] Calculate the standard deviation of the instantaneous motion vector in the most recent 1 second in the spatiotemporal state of the equipment, and denote this standard deviation as the equipment motion stability.
[0053] Determine whether the equipment's motion stability is greater than a preset threshold of 0.1 m / s. If so, generate a motion status code.
[0054] Based on the maneuver status code and the high-reliability trajectory points and instantaneous motion vectors in the spatiotemporal state of the device, the mobile terminal's movement path within the next 2 seconds is identified as the predicted displacement path;
[0055] Based on the pre-set spatial topology map of the entire plant's AP signal strength, the predicted displacement path is spatially superimposed and compared to filter out wireless access points whose trajectories will enter the range of their -75dBm signal equipotential lines, thus forming a set of potential wireless access points; among them, the pre-set spatial topology map of the entire plant's AP signal strength is marked with the physical location of each wireless access point in the plant and the -75dBm signal equipotential coverage circle.
[0056] In this embodiment of the invention, velocity components of all instantaneous motion vectors within the past second (e.g., the most recent 10 sampling points) are extracted from a continuous device spatiotemporal state data stream. Then, statistical calculations are performed on this set of velocity data to determine its standard deviation. This standard deviation is used to quantitatively evaluate the motion stability of the mobile terminal in the recent past.
[0057] In one implementation of this invention, ten speed readings of the AGV over the past second were extracted, namely {1.50, 1.51, 1.49, 1.50, 1.52, 1.50, 1.51, 1.48, 1.50, 1.49} m / s. The standard deviation of this data set was calculated to be approximately 0.011 m / s. This value is recorded as the device's motion stability at the current moment. A smaller standard deviation indicates that the device is moving smoothly at a constant or near-constant speed.
[0058] In one implementation of this invention, it is assumed that the currently calculated device motion stability is 0.011 m / s, which is less than a preset threshold of 0.1 m / s. Therefore, the AGV is determined to be in a stable driving state, no motion status code is generated, and a linear model is used for path prediction. Here, the linear model is a simple geometric extrapolation method based on the assumption of uniform linear motion, the purpose of which is to quickly estimate the future position of the device in a short period of time with extremely low computational resource consumption.
[0059] The specific implementation of this linear model is as follows:
[0060] Parameter definition and retrieval: Current position : Obtained from the latest high-confidence trajectory points, denoted as coordinates Current speed : Obtain the velocity magnitude from the latest instantaneous motion vector; current direction : Obtain the direction angle from the latest instantaneous motion vector; this angle is the angle between the velocity vector and the positive X-axis direction of the factory coordinate system; prediction time window. This is a preset parameter used to define the predicted future duration. In this invention, this value is set to 2 seconds.
[0061] Predicted displacement calculation: The system first decomposes the velocity vector into components on the X and Y axes:
[0062] X-axis velocity component: Y-axis velocity component: ;
[0063] Then, calculate within the prediction time window. Displacement along the X and Y axes:
[0064] X-axis displacement Y-axis displacement ;
[0065] Future location calculation: Add the calculated displacement to the current location coordinates to obtain the predicted future location. :
[0066] Predicted position X coordinate Predicted position Y coordinate ;
[0067] Generate predicted displacement path: Finally, the current position point With the predicted future location Connect them to form a straight line segment. This straight line segment is the final output predicted displacement path.
[0068] In another implementation of this invention, assuming the AGV is turning, its speed reading becomes {1.5, 1.4, 1.2, 1.0, 0.8, ...} m / s, and the calculated device motion stability is 0.25 m / s, which is greater than the threshold of 0.1 m / s. At this time, a motion status code (e.g., 0x01) will be generated. This status code will notify subsequent steps that a nonlinear prediction model considering acceleration should be used, which can be referred to the linear model implementation described above.
[0069] In this embodiment of the invention, a pre-drawn digital map of the factory is loaded. This map precisely marks the physical coordinates of each wireless access point (AP) and draws a theoretical -75dBm signal strength equipotential line (usually simplified to a circle or ellipse) around each AP, which is called the "AP weak signal coverage circle". The predicted displacement path generated in the previous step is used as a geometric line segment, and intersection calculation is performed with all the "AP weak signal coverage circles" on this map.
[0070] In one implementation of this invention, for example, the predicted displacement path segment [(10.21, 35.43), (12.42, 37.64)] is overlaid on the overall AP coverage map. The calculation results show that this path segment intersects with both the -75dBm coverage circles of AP-2 and AP-3. Therefore, AP-2 and AP-3 are selected as the two wireless access points.
[0071] It should be noted that -75dBm is generally considered the edge signal strength for a reliable Wi-Fi connection. Choosing this value as the filtering boundary ensures that the selected access points are potential targets that can provide effective service. Finally, the identifiers of the two selected access points, {AP-2, AP-3}, constitute the potential wireless access point set.
[0072] Preferably, identifying the mobile terminal's movement path within the next 2 seconds based on the maneuver status code and high-reliability trajectory points and instantaneous motion vectors in the device's spatiotemporal state includes:
[0073] The slope of the change in RSSI within the most recent 500ms time window is calculated based on the original RSSI sequence in the spatiotemporal state of the device to obtain the slope of the signal strength trend.
[0074] The sign of the slope of the signal strength trend is analyzed to identify whether the mobile terminal is approaching or moving away from the wireless access point, thereby obtaining the relative movement trend of the device;
[0075] Cross-verification of Doppler frequency shift in communication signals is performed based on the relative movement trend of the equipment. If the two directions are consistent, a verified direction vector is constructed based on the maneuver status code.
[0076] Based on the verified direction vector and the instantaneous motion vector in the device's spatiotemporal state, the predicted landing point coordinates of the mobile terminal are extrapolated 2 seconds ahead of the predicted time window.
[0077] The predicted displacement path is calculated by linear interpolation of the predicted landing point coordinates and high-confidence trajectory points in the spatiotemporal state of the equipment.
[0078] In this embodiment of the invention, the latest raw RSSI sequence is extracted from the device's spatiotemporal state, focusing only on data points within the most recent 500ms time window. Linear regression analysis is applied to these data points to calculate the slope of an optimally fitted line, which quantitatively reflects the recent trend in signal strength.
[0079] Specifically, the slope The calculation uses the least squares method, and its mathematical expression is:
[0080] ;
[0081] in: This refers to the number of samples within a 500ms time window; It is the first The collection timestamp of each sample (relative to the start of the window); It is the first RSSI values for each sample (unit: dBm).
[0082] In this embodiment of the invention, it is only necessary to determine the slope of the signal strength trend calculated in the previous step. The symbol is . A positive slope indicates that the signal strength is increasing, meaning that the mobile terminal is approaching the signal source (wireless access point); a negative slope indicates that the signal is weakening, meaning that it is moving away.
[0083] In one implementation of this invention, for example, since the calculated signal strength trend slope is +19.0 dBm / s, which is a positive number, it is determined that the mobile terminal is approaching AP-2. This determination result is recorded as the device's relative movement direction, and the data format can be {direction: approaching, target AP: AP-2}.
[0084] In this embodiment of the invention, to improve the reliability of direction determination, a physical layer Doppler frequency shift is introduced as a cross-verification method. The mobile terminal's wireless communication module measures the carrier frequency offset of the received signal, i.e., the Doppler frequency shift. Theoretically, when a terminal approaches a signal source, a positive frequency shift (frequency increases); when it moves away, a negative frequency shift occurs. The symbol is compared with the relative movement tendency of the device obtained in the previous step.
[0085] Specifically, the following judgment is made: if the relative movement of the equipment tends to be "closer" and >0, or tending towards "far away" and If the value is less than 0, the direction indication is considered consistent, and the verification passes. After successful verification, the current instantaneous motion vector is considered highly reliable and is directly adopted as the verified direction vector.
[0086] In one implementation of this invention, it is assumed that the relative movement of the devices tends to be "closer," and the Doppler frequency shift measured by the wireless communication module... The value is +50Hz. Since the physical effect of "approaching" is a positive frequency shift, the two directions indicate the same direction, and the cross-validation passes. Therefore, the instantaneous motion vector in the current spatiotemporal state of the device is confirmed as the verified direction vector. If the relative movement tendency of the device indicates "approaching," but the estimated Doppler frequency shift is -40Hz (indicating "moving away"), a contradiction occurs. In this case, the direction verification will be determined to have failed, the verified direction vector will not be generated, and an alarm will be triggered or a more conservative prediction strategy will be implemented, such as shortening the prediction time window.
[0087] It should be noted that the Doppler frequency shift measurement can be provided by the baseband processor of the communication chip, without the need for additional hardware.
[0088] In this embodiment of the invention, since a maneuver status code has been generated previously, indicating that the device is in a non-uniform motion state, a quadratic kinematic model that considers acceleration is used for prediction.
[0089] Specifically, predicting the landing point coordinates The calculation formula is:
[0090] ;
[0091] in: It is the predicted future location vector ; It is the current position vector, taken from a high-confidence trajectory point in the device's spatiotemporal state. ; It is the current velocity vector, taken from The corresponding verified direction vector; It is the current acceleration vector, taken from the value calculated by the IMU in the device's spatiotemporal state. ; It is the predicted time window, preset to 2.0 seconds.
[0092] It should be noted that the preset 2-second time window is derived from a comprehensive consideration of the typical speed of AGVs in the factory (0-2m / s) and the preparation time required for network switching (about 1-3 seconds). It can provide sufficient lead time without causing excessive amplification of errors due to excessively long prediction time.
[0093] In this embodiment of the invention, linear interpolation refers to directly connecting the predicted starting point and ending point to form a straight path representing the net displacement. The high-confidence trajectory point in the device's spatiotemporal state is used as the starting point of the path, and the predicted landing point coordinates calculated in the previous step are used as the ending point of the path.
[0094] In one implementation of this invention, the starting point (15.0, 40.0) m and the ending point (17.0, 41.8) m are connected to form a straight line segment. This line segment, which represents the net displacement direction and distance within the next 2 seconds, is ultimately determined as the predicted displacement path.
[0095] Preferably, step S2, which involves correcting the mobile path based on the network signal strength in the device's spatiotemporal state and selecting a first candidate network target and a second candidate network target from the set of potential wireless access points to construct a dual-path handover plan, includes:
[0096] For each wireless access point in the potential wireless access point set, the spatial intersection length between its core signal coverage area and the predicted displacement path is calculated to obtain the trajectory intersection depth; where the core signal coverage area is the area in the wireless access point with a signal strength better than -55dBm;
[0097] Based on the trajectory intersection depth, all wireless access points in the potential wireless access point set are sorted in descending order to form the preferred AP ranking;
[0098] Search the pre-set spatial topology map of AP signal strength throughout the plant and mark the best wireless access point in the preferred AP ranking as the first candidate network target.
[0099] After determining the first candidate target, the second-best wireless access point in the preferred AP ranking is retrieved and identified, and is denoted as the second candidate network target.
[0100] The identifiers of the first and second candidate network targets are combined with the ID of the mobile terminal, and a timestamp is added to form a dual-path handover plan.
[0101] In this embodiment of the invention, the core signal coverage area is extracted for each AP in the potential wireless access point set from a preset spatial topology map of the entire factory's AP signal strength. This core area is defined as a circular region where the signal strength can theoretically be stably maintained above -55dBm. Then, the predicted displacement path (a straight line segment) generated in the previous step is geometrically intersected with these circular regions to calculate the length of the path segment within each circle. It should be noted that -55dBm is a typical signal strength value that can provide high-quality, high-throughput Wi-Fi service. Specifically, the intersection length... The calculation involves the problem of the intersection of a line and a circle in analytic geometry. For a given... A circle with center r and radius r, and a line from point r... and The calculation process for the defined line segment includes determining whether the line segment intersects with the circle, solving for the intersection point, and finally calculating the length of the line segment inside the circle. This length is quantified into a new parameter, denoted as the trajectory intersection depth.
[0102] In one implementation of this invention, it is assumed that the potential wireless access point set is {AP-2, AP-3}. The core signal coverage area of AP-2 is a circle with a center at (18.0, 42.0) and a radius of 10 meters. The core area of AP-3 is a circle with a center at (22.0, 45.0) and a radius of 8 meters. The predicted displacement path is a line segment connecting points (17.0, 41.8) and (19.5, 43.0). Through geometric calculation: the intersection length of this path segment with the core area of AP-2 is 2.8 meters; the intersection length of this path segment with the core area of AP-3 is 1.1 meters; these two calculated length values are the intersection depths of the trajectories of AP-2 and AP-3, respectively.
[0103] In one implementation of this invention, according to the calculation results, the intersection depth of the trajectories of AP-2 (2.8 meters) is greater than the intersection depth of the trajectories of AP-3 (1.1 meters). Therefore, including but not limited to sorting the set {AP-2, AP-3...} in descending order, the result is an ordered list: [AP-2, AP-3...], which is the preferred AP sort.
[0104] In this embodiment of the invention, an element is directly taken from the top of the preferred AP sorting list, that is, the AP ranked first, which is considered to be the best switching choice under the current predicted path.
[0105] In one implementation of this invention, the system extracts the first element AP-2 from the preferred AP sort [AP-2, AP-3...], and then internally identifies AP-2 as the first candidate network target.
[0106] In one implementation of this invention, the second element AP-3 is taken from the preferred AP sort [AP-2, AP-3], and then the system officially identifies AP-3 as the second candidate network target.
[0107] In one implementation of this invention, the mobile terminal ID (e.g., AGV-007), the first candidate network target (AP-2), the second candidate network target (AP-3), and the current system timestamp (e.g., 1678886405.123) are combined. The final generated data structure is as follows: {Plan ID: PRE-001, Timestamp: 1678886405.123, Terminal ID: AGV-007, Target 1: AP-2, Target 2: AP-3}, resulting in a dual-path handover plan.
[0108] Preferably, in step S2, the instantaneous connection token containing dual-path authentication is determined according to the dual-path handover plan, including:
[0109] Based on the first and second candidate network targets in the dual-path handover plan, immediately initiate a collaborative authentication request to the central server to obtain the first collaborative session ID and the second collaborative session ID.
[0110] A first temporary key pair is generated based on the first collaborative session ID, and one public key of the first temporary key pair is sent to the first candidate network target, and the other is sent to the mobile terminal, which is recorded as the first session seed;
[0111] A second temporary key pair is generated based on the second collaborative session ID. One public key of the second temporary key pair is sent to the second candidate network target, and the other is sent to the mobile terminal. This is recorded as the second session seed.
[0112] The mobile terminal performs a SHA-256 hash digest calculation once with its own device certificate and the received first session seed and second session seed respectively to obtain the first pre-trust and the second pre-trust respectively;
[0113] Based on the estimated time to enter the wireless access point in the dual-path handover plan plus a 2-second safety window, calculate the absolute failure timestamp to form a token expiration tag.
[0114] The first pre-establishment token, the second pre-establishment token, and the token expiration tag are combined to form a temporary connection token specific to this mobile terminal.
[0115] In one implementation of this invention, after receiving the proposal, the central authentication server generates an identifier, SessionID_A='A7B3-C9D1-E4F2-10AB', for the potential connection between AGV-007 and AP-2. This is the first collaborative session ID. Simultaneously, it generates a SessionID_B='F6A9-8B2E-5C1D-77FF' for the potential connection between AGV-007 and AP-3. This is the second collaborative session ID.
[0116] In this embodiment of the invention, the central authentication server uses its built-in cryptography library to generate a temporary, short-lived public-private key pair for the first collaborative session ID based on elliptic curve cryptography (ECC). Subsequently, the server pushes the public key portion of this key pair to both communicating parties through an internal secure channel (e.g., an established IPsec tunnel).
[0117] Specifically, the server generates a key pair (PrivKey_A, PubKey_A) for SessionID_A. Then, it sends the public key PubKey_A directly to AP-2 via the internal wired network. It also distributes the same public key PubKey_A to the AGV via AP-1, which is currently connected to AGV-007. This public key PubKey_A distributed to the AGV is recorded as the first session seed.
[0118] It should be noted that the public key is issued here, so even if it is eavesdropped on during transmission, no critical information will be leaked. The private key PrivKey_A is securely stored by a central authentication server, or in some architectures it can be directly issued to the AP, but it will never be issued to mobile terminals.
[0119] In one implementation of this invention, the server sends the public key PubKey_B to AP-3 via the internal network, and also distributes the same public key PubKey_B to AGV-007 via AP-1. This public key PubKey_B distributed to the AGV is recorded as the second session seed. Thus, the AGV simultaneously holds two different session seeds (public keys) for communicating with AP-2 and AP-3.
[0120] In this embodiment of the invention, after receiving the session seed, the mobile terminal performs a local hash calculation in order to generate a credential that can prove its identity and be bound to the current session. It concatenates its own device certificate (an X.509 certificate issued by the root CA containing its identity and public key) with the session seed, and then calculates its hash value.
[0121] Specifically, the calculation process is as follows:
[0122] ; ;
[0123] in, and These are the calculated hash digest values; It is the standard SHA-256 hash function; It is the binary content of the device certificate for AGV-007; and These are the first and second session seeds received, respectively; || represents binary concatenation operation.
[0124] In one implementation of this invention, the AGV performs the above calculation, and the resulting 256-bit hash value H_A is recorded as the first prior token, while the hash value H_B is recorded as the second prior token.
[0125] In one implementation of this invention, it is assumed that the estimated handover time (estimated time to enter the first candidate target) in the dual-path handover plan is 2.8 seconds. The current system time is... The security window is preset to 2.0 seconds. Therefore, the expiration timestamp... The calculation is as follows:
[0126] ;
[0127] This calculated future absolute timestamp +4.8s is recorded as the expiration date of the token.
[0128] In one implementation of this invention, the AGV encapsulates a first pre-existing token (a 256-bit hash value), a second pre-existing token (another 256-bit hash value), and a token expiration tag (a 64-bit Unix timestamp) in a predetermined format.
[0129] In another implementation of this invention, the generation and structure of the instantaneous connection token further includes:
[0130] Based on the first and second pre-concepts, a monotonically increasing sequence number is generated by the central server, which together constitutes the core session data.
[0131] The public key of the target access point is used to perform asymmetric encryption on the core session data to form an asymmetric encryption block.
[0132] Add a fixed delay window of 2 seconds to the estimated entry time of the first and second candidate network targets in the dual-path handover plan to obtain the absolute failure time.
[0133] The final encapsulation structure of the instantaneous connection token consists of a plaintext header of the target access point ID, an asymmetric encryption block, and an absolute expiration time, forming a three-part token structure.
[0134] Preferably, step S3 includes the following steps:
[0135] Step S31: While carrying the instantaneous connection token, the mobile terminal continuously monitors the signal strength of the currently connected wireless access point and the signal strength of the target wireless access point in the dual-path handover plan at 50ms intervals to obtain real-time signal strength pairs.
[0136] Step S32: Identify the target wireless access point in the associated instantaneous connection object based on the real-time signal strength to obtain a connection group to be decided, which includes the handover source, target, and credentials;
[0137] Step S33: Determine whether the signal strength of the currently connected wireless access point in the connection group to be decided is less than -82dBm, and whether the signal strength of the target wireless access point in the dual-path handover plan is greater than -78dBm; if yes, the handover condition is determined to be met, and a handover execution command is generated; if no, the network status of the mobile terminal is continuously monitored.
[0138] Step S34: According to the handover execution instruction, the mobile terminal immediately broadcasts a momentary connection signal to the public channel of the wireless access point in the dual-path handover plan to form a temporary communication tunnel.
[0139] In this embodiment of the invention, upon receiving a momentary connection signal, the wireless communication module of the mobile terminal (such as an AGV) enters a high-frequency monitoring state. It not only continues to monitor the signal strength of the currently connected AP (source AP), but also, based on information in the dual-path handover plan, specifically listens to the beacon frames of the first and second candidate network target APs to obtain their real-time signal strength. The execution interval for this monitoring action is set to 50 milliseconds.
[0140] It should be noted that 50ms is a trade-off interval. It is short enough that when the AGV moves at a high speed of 2m / s, a signal evaluation can be performed every 10cm, thus ensuring the timeliness of switching decisions;
[0141] In one implementation of this invention, the AGV is currently connected to AP-1. The dual-path handover plan specifies AP-2 (first candidate) and AP-3 (second candidate) as the targets. At a certain monitoring moment, the signal strength readings obtained by the AGV are: AP-1: -81dBm, AP-2: -79dBm, AP-3: -88dBm.
[0142] In one implementation of this invention, the real-time signal strength pair (-81dBm, -79dBm) is logically bound to the instantaneous connection token of AGV-007. This token includes a first pre-connection token prepared for AP-2 and a second pre-connection token prepared for AP-3. The resulting connection group to be decided can then be described as: {Source AP: AP-1, Target AP: AP-2, Source signal: -81dBm, Target signal: -79dBm, Credential: [First pre-connection token]}.
[0143] In one implementation of this invention, during the next 50ms monitoring cycle, the signal strength in the connection group to be decided becomes {source signal: -83dBm, target signal: -77dBm}. The system then determines: S_source(-83dBm)<T_lower(-82dBm)--> The condition is true; S_target(-77dBm)>T_upper(-78dBm) --> The condition is true.
[0144] Since both conditions are met simultaneously, the system determines that the switching conditions have been met and immediately generates an internal switching execution instruction, where S_source is the signal strength of the currently connected AP; S_target is the signal strength of the first candidate target AP; T_lower is the lower limit threshold of the source AP signal strength, which is preset to -82dBm; and T_upper is the upper limit threshold of the target AP signal strength, which is preset to -78dBm.
[0145] In another implementation of this invention, if the signal strength is {source signal: -81dBm, target signal: -79dBm}, then neither of the two conditions is met, and the system will continue to monitor without generating any instructions.
[0146] In one implementation of this invention, upon receiving a switching command, the AGV's wireless communication protocol stack immediately executes a switching operation. It temporarily stops sending data to the source AP and switches its wireless network card to the working channel of the first candidate network target (AP-C). Then, the terminal constructs a specific management frame (e.g., a modified authentication request frame or a custom Action frame) and uses the transient connection token as the payload. This frame is broadcast on the AP-C's public channel. Upon receiving this frame, AP-2 parses the token content and locally verifies its validity (timeliness, integrity, etc.). Since the token is pre-signed by the central server, AP-2 trusts its content and does not need to communicate with the server again. It directly uses the implicit key material in the token to complete a handshake with the AGV, quickly establishing a basic, encrypted communication link within 100-300 milliseconds.
[0147] Preferably, step S4, which involves reporting the real-time location of the mobile terminal through a temporary communication tunnel to determine the dynamic encryption strategy, includes:
[0148] After the temporary safety tunnel is established, the mobile terminal immediately reports its real-time location coordinates through the tunnel;
[0149] The central server receives real-time location coordinates and determines the risk level of the real-time location coordinates by comparing them with the preset factory risk communication area; the risk level includes high communication risk and low communication risk.
[0150] If the communication risk is high, the AES-256-GCM encryption standard is selected; if the communication risk is low, the ChaCha20-Poly1305 encryption standard is selected. Then, the central server sends instructions to both communicating parties to obtain the dynamic encryption strategy.
[0151] In one implementation of this invention, within the first 50 milliseconds after the temporary safe tunnel is established, AGV-007 reads the output of its UWB module to obtain the coordinates (17.02m, 41.85m, 1.10m).
[0152] Specifically, the pre-defined factory risk communication zones are pre-defined by safety engineers. This divides the entire factory's two-dimensional or three-dimensional space into multiple polygonal areas, assigning a risk level to each area. For example, warehouses storing core materials, precision assembly workstations, and quality inspection areas are defined as "high communication risk," while public passageways and general material buffer areas are defined as "low communication risk." This map is stored digitally in a server database, with each area consisting of its vertex coordinate sequence and a risk level label.
[0153] In one implementation of this invention, the server receives the real-time location coordinates (17.02, 41.85) reported by AGV-007. The server executes a geometric judgment algorithm that determines if a point is inside a polygon, matching the coordinates with all areas on the risk map. The calculation result shows that the point falls within a polygon marked as the "core component quality inspection area," and the preset risk level for this area is "high communication risk." Therefore, the server determines the risk level for this query to be "high."
[0154] In another implementation of this invention, if the coordinates reported by the AGV are located in a public corridor, the risk level of the matched area is "low communication risk".
[0155] In this embodiment of the invention, a security policy mapping table exists within the central server. This table hard-associates different risk levels with specific encryption standards, a choice based on a trade-off between security strength and computational overhead. AES-256-GCM is an industry-recognized symmetric encryption algorithm with extremely high security strength, suitable for high-risk scenarios. ChaCha20-Poly1305, on the other hand, is an encryption algorithm that, while ensuring sufficient security, offers higher computational efficiency, especially performing better on CPUs without hardware acceleration, making it suitable for low-risk scenarios where energy consumption and latency are more critical.
[0156] Preferably, step S4, which involves using a transient connection token to complete the authentication handshake with the first or second candidate network target and establishing an end-to-end encrypted data transmission link based on a dynamic encryption strategy and a temporary communication tunnel, includes:
[0157] The first handover request is triggered within the 2-second validity period of the first prior token in the instantaneous connection token;
[0158] After the first candidate network target in the dual-path handover plan receives the first pre-qualification object through the temporary communication tunnel, it immediately performs local verification of the first pre-qualification object. If it passes the verification, it returns the first authentication confirmation.
[0159] After receiving the first authentication confirmation, the mobile terminal applies a dynamic encryption strategy to establish an encrypted data transmission link for the temporary communication tunnel and determines that the connection status is normal.
[0160] If the first authentication confirmation is not received when the 2-second validity period of the first prior token in the instantaneous connection token expires, the first path switching is determined to have failed, and a switching failure flag is generated.
[0161] After the handover failure flag is generated, a handover procedure is triggered to the second candidate network target in the dual-path handover plan, and a second handover request containing the second pre-confirmation in the transient connection token is issued;
[0162] Upon receiving the second handover request, the second candidate network target performs local verification of the second pre-authentication object. If the verification passes, it returns the second authentication confirmation.
[0163] After receiving the second authentication confirmation, the mobile terminal applies a dynamic encryption strategy to establish an encrypted data transmission link for the temporary communication tunnel and determines the connection status as normal standby.
[0164] In one implementation of this invention, the AGV meets the switching conditions and generates a switching execution command. It immediately starts a 2-second countdown and broadcasts a switching request containing a first pre-establishment to AP-2, the first candidate network target in the dual-path handover plan. This action is the first switching request.
[0165] In one implementation of this invention, AP-2 receives the first pre-connection token broadcast by the AGV. It performs a verification process and simultaneously checks the token's expiration tag in the instantaneous connection token to ensure the current time has not exceeded the expiration timestamp. After all checks pass, AP-2 determines the verification is successful and immediately returns a confirmation message to the AGV. This message is the first authentication confirmation.
[0166] In one implementation of this invention, the AGV receives a first authentication confirmation from AP-2 80ms after issuing the request. Almost simultaneously, it also receives a dynamic encryption policy from the central server specifying the use of AES-256-GCM. The AGV immediately enables the AES-256-GCM encryption suite in its protocol stack, negotiates a session key with AP-2 (which also received the same policy instruction), and applies it to the temporary communication tunnel.
[0167] In one implementation of this invention, it is assumed that the AGV fails to receive the first authentication confirmation due to a momentary high load on AP-2 or severe channel interference. At this time, the 2-second timer inside the AGV times out, triggering an interrupt. The program immediately determines that the handover with AP-2 has failed and generates an internal handover failure flag.
[0168] In one implementation of this invention, after the handover failure flag is generated, the AGV immediately starts a new 2-second timer and extracts the second pre-connection token H_B prepared for AP-3 from the instantaneous connection token. It encapsulates H_B in a new handover request and broadcasts it to the common channel of AP-3. This action is the second handover request.
[0169] In one implementation of this invention, the AGV receives a second authentication confirmation 120ms after issuing the second switching request. It also applies the dynamic encryption strategy issued by the central server (typically, the server issues the encryption to the backup path simultaneously with the primary path, or immediately after the primary path fails), negotiating with AP-3 and establishing a link encrypted using AES-256-GCM. Subsequently, the AGV updates its internal state, determining the connection with AP-3 as a normal backup connection. Even if the primary path switching fails, data transmission can be quickly restored through the backup path, ensuring business continuity.
[0170] Therefore, the embodiments should be considered as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of the equivalents of the application are intended to be included within the invention.
[0171] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.
Claims
1. A method for encrypting network data transmission in industrial computer communication, characterized in that, Includes the following steps: Step S1: During the continuous movement of the mobile terminal, its physical space coordinates, motion vector and network signal strength are periodically and synchronously collected to generate the spatiotemporal state of the device; Based on the spatiotemporal state of the device, its movement path is predicted, thereby filtering out at least two sets of potential wireless access points, including: Calculate the standard deviation of the instantaneous motion vector in the most recent 1 second in the spatiotemporal state of the equipment, and denote this standard deviation as the equipment motion stability. Determine whether the equipment's motion stability is greater than a preset threshold of 0.1 m / s. If so, generate a motion status code. Based on the maneuver status code and the high-reliability trajectory points and instantaneous motion vectors in the spatiotemporal state of the device, the mobile terminal's movement path within the next 2 seconds is identified as the predicted displacement path; Based on the pre-set spatial topology map of the entire plant's AP signal strength, the predicted displacement path is spatially superimposed and compared to filter out wireless access points whose trajectories will enter the range of their -75dBm signal equipotential lines, thus forming a set of potential wireless access points; among them, the pre-set spatial topology map of the entire plant's AP signal strength is marked with the physical location of each wireless access point in the plant and the -75dBm signal equipotential coverage circle. Step S2: Correct the mobile path based on the network signal strength in the device's spatiotemporal state, and select a first candidate network target and a second candidate network target from the set of potential wireless access points to construct a dual-path handover plan, which includes: For each wireless access point in the potential wireless access point set, the spatial intersection length between its core signal coverage area and the predicted displacement path is calculated to obtain the trajectory intersection depth; where the core signal coverage area is the area in the wireless access point with a signal strength better than -55dBm; Based on the trajectory intersection depth, all wireless access points in the potential wireless access point set are sorted in descending order to form the preferred AP ranking; Search the pre-set spatial topology map of AP signal strength throughout the plant and mark the best wireless access point in the preferred AP ranking as the first candidate network target. After determining the first candidate target, the second-best wireless access point in the preferred AP ranking is retrieved and identified, and is denoted as the second candidate network target. The identifiers of the first and second candidate network targets are combined with the ID of the mobile terminal and a timestamp is added to form a dual-path handover plan; based on the dual-path handover plan, an instantaneous connection token containing dual-path authentication is determined. Step S3: During the continuous monitoring of network signals by the mobile terminal, when the preset signal strength switching conditions are met, an instantaneous connection message is broadcast to the candidate network target in the dual-path handover plan to establish a temporary communication tunnel. Step S4: Report the real-time location of the mobile terminal through the temporary communication tunnel to determine the dynamic encryption strategy; complete the authentication handshake with the first candidate network target or the second candidate network target using the instantaneous connection token, and establish an end-to-end data transmission encryption link according to the dynamic encryption strategy and the temporary communication tunnel.
2. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, In step S1, during the continuous movement of the mobile terminal, its physical space coordinates, motion vector, and network signal strength are periodically and synchronously collected to generate the device's spatiotemporal state, including: By deploying ultra-wideband positioning base stations within the factory, the physical coordinates of the mobile terminal are collected at a frequency of 10Hz to obtain the instantaneous spatial coordinates. The inertial measurement unit integrated in the mobile terminal is used to obtain its three-axis acceleration, and the instantaneous motion vector is calculated based on the instantaneous spatial coordinates; Using the instantaneous motion vector as a reference, the instantaneous spatial coordinates within a continuous 0.5s are forward propagated for verification to correct the positioning error and obtain a highly reliable trajectory point. The raw RSSI sequence is obtained by continuously collecting at least 10 Received Signal Strength Indication values received by the mobile terminal from the current wireless access point in the past 1 second. The original RSSI sequence, high-confidence trajectory points, and instantaneous motion vectors are encapsulated into the device's spatiotemporal state.
3. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, Based on the mobile status code and high-reliability trajectory points and instantaneous motion vectors in the device's spatiotemporal state, the following mobile terminal movement paths within the next 2 seconds are identified: The slope of the change in RSSI within the most recent 500ms time window is calculated based on the original RSSI sequence in the spatiotemporal state of the device to obtain the slope of the signal strength trend. The sign of the slope of the signal strength trend is analyzed to identify whether the mobile terminal is approaching or moving away from the wireless access point, thereby obtaining the relative movement trend of the device; Cross-verification of Doppler frequency shift in communication signals is performed based on the relative movement trend of the equipment. If the two directions are consistent, a verified direction vector is constructed based on the maneuver status code. Based on the verified direction vector and the instantaneous motion vector in the device's spatiotemporal state, the predicted landing point coordinates of the mobile terminal are deduced 2 seconds ahead of the predicted time window. The predicted displacement path is calculated by linear interpolation of the predicted landing point coordinates and high-confidence trajectory points in the spatiotemporal state of the equipment.
4. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, In step S2, the instantaneous connection tokens containing dual-path authentication are determined according to the dual-path handover plan, including: Based on the first and second candidate network targets in the dual-path handover plan, immediately initiate a collaborative authentication request to the central server to obtain the first collaborative session ID and the second collaborative session ID. A first temporary key pair is generated based on the first collaborative session ID, and one public key of the first temporary key pair is sent to the first candidate network target, and the other is sent to the mobile terminal, which is recorded as the first session seed; A second temporary key pair is generated based on the second collaborative session ID. One public key of the second temporary key pair is sent to the second candidate network target, and the other is sent to the mobile terminal. This is recorded as the second session seed. The mobile terminal performs a SHA-256 hash digest calculation once with its own device certificate and the received first session seed and second session seed respectively to obtain the first pre-trust and the second pre-trust respectively; Based on the estimated time to enter the wireless access point in the dual-path handover plan plus a 2-second safety window, calculate the absolute failure timestamp to form a token expiration tag. The first pre-establishment token, the second pre-establishment token, and the token expiration tag are combined to form a temporary connection token specific to this mobile terminal.
5. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, Step S3 includes the following steps: Step S31: While carrying the instantaneous connection token, the mobile terminal continuously monitors the signal strength of the currently connected wireless access point and the signal strength of the target wireless access point in the dual-path handover plan at 50ms intervals to obtain real-time signal strength pairs. Step S32: Identify the target wireless access point in the associated instantaneous connection object based on the real-time signal strength to obtain a connection group to be decided, which includes the handover source, target, and credentials; Step S33: Determine whether the signal strength of the currently connected wireless access point in the connection group to be decided is less than -82dBm, and whether the signal strength of the target wireless access point in the dual-path handover plan is greater than -78dBm; if yes, the handover condition is determined to be met, and a handover execution command is generated; if no, the network status of the mobile terminal is continuously monitored. Step S34: According to the handover execution instruction, the mobile terminal immediately broadcasts a momentary connection signal to the public channel of the wireless access point in the dual-path handover plan to form a temporary communication tunnel.
6. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, Step S4, which involves reporting the real-time location of the mobile terminal through a temporary communication tunnel to determine the dynamic encryption strategy, includes: After the temporary safety tunnel is established, the mobile terminal immediately reports its real-time location coordinates through the tunnel; The central server receives real-time location coordinates and determines the risk level of the real-time location coordinates by comparing them with the preset factory risk communication area; the risk level includes high communication risk and low communication risk. If the communication risk is high, the AES-256-GCM encryption standard is selected; if the communication risk is low, the ChaCha20-Poly1305 encryption standard is selected. Then, the central server sends instructions to both communicating parties to obtain the dynamic encryption strategy.
7. The network data transmission encryption method in industrial computer communication according to claim 1, characterized in that, Step S4 involves using a transient connection token to complete an authentication handshake with the first or second candidate network target, and establishing an end-to-end encrypted data transmission link based on a dynamic encryption strategy and a temporary communication tunnel, including: The first handover request is triggered within the 2-second validity period of the first prior token in the instantaneous connection token; After the first candidate network target in the dual-path handover plan receives the first pre-qualification object through the temporary communication tunnel, it immediately performs local verification of the first pre-qualification object. If it passes the verification, it returns the first authentication confirmation. After receiving the first authentication confirmation, the mobile terminal applies a dynamic encryption strategy to establish an encrypted data transmission link for the temporary communication tunnel and determines that the connection status is normal. If the first authentication confirmation is not received when the 2-second validity period of the first prior token in the instantaneous connection token expires, the first path switching is determined to have failed, and a switching failure flag is generated. After the handover failure flag is generated, a handover procedure is triggered to the second candidate network target in the dual-path handover plan, and a second handover request containing the second pre-confirmation in the transient connection token is issued; Upon receiving the second handover request, the second candidate network target performs local verification of the second pre-authentication object. If the verification passes, it returns the second authentication confirmation. After receiving the second authentication confirmation, the mobile terminal applies a dynamic encryption strategy to establish an encrypted data transmission link for the temporary communication tunnel and determines the connection status as normal standby.
8. A network data transmission encryption system for industrial computer communication, characterized in that, For executing the network data transmission encryption method in industrial computer communication as described in claim 1, the network data transmission encryption system for industrial computer communication includes: The trajectory sensing module is used to periodically and synchronously collect the physical space coordinates, motion vector, and network signal strength of the mobile terminal during continuous movement to generate the device's spatiotemporal state; based on the device's spatiotemporal state, it predicts the device's movement path, thereby filtering out at least two potential wireless access point sets, including: Calculate the standard deviation of the instantaneous motion vector in the most recent 1 second in the spatiotemporal state of the equipment, and denote this standard deviation as the equipment motion stability. Determine whether the equipment's motion stability is greater than a preset threshold of 0.1 m / s. If so, generate a motion status code. Based on the maneuver status code and the high-reliability trajectory points and instantaneous motion vectors in the spatiotemporal state of the device, the mobile terminal's movement path within the next 2 seconds is identified as the predicted displacement path; Based on the pre-set spatial topology map of the entire plant's AP signal strength, the predicted displacement path is spatially superimposed and compared to filter out wireless access points whose trajectories will enter the range of their -75dBm signal equipotential lines, thus forming a set of potential wireless access points; among them, the pre-set spatial topology map of the entire plant's AP signal strength is marked with the physical location of each wireless access point in the plant and the -75dBm signal equipotential coverage circle. A dual-path planning module is used to correct the mobile path based on the network signal strength in the device's spatiotemporal state, and to select a first candidate network target and a second candidate network target from a set of potential wireless access points to construct a dual-path handover plan, which includes: For each wireless access point in the potential wireless access point set, the spatial intersection length between its core signal coverage area and the predicted displacement path is calculated to obtain the trajectory intersection depth; where the core signal coverage area is the area in the wireless access point with a signal strength better than -55dBm; Based on the trajectory intersection depth, all wireless access points in the potential wireless access point set are sorted in descending order to form the preferred AP ranking; Search the pre-set spatial topology map of AP signal strength throughout the plant and mark the best wireless access point in the preferred AP ranking as the first candidate network target. After determining the first candidate target, the second-best wireless access point in the preferred AP ranking is retrieved and identified, and is denoted as the second candidate network target. The identifiers of the first and second candidate network targets are combined with the ID of the mobile terminal and a timestamp is added to form a dual-path handover plan; based on the dual-path handover plan, an instantaneous connection token containing dual-path authentication is determined. The communication switching module is used to broadcast an instantaneous connection message to the candidate network target in the dual-path handover plan when the preset signal strength switching conditions are met during the continuous monitoring of network signals by the mobile terminal, so as to establish a temporary communication tunnel. The secure link establishment module is used to report the real-time location of the mobile terminal through a temporary communication tunnel to determine the dynamic encryption strategy; to complete the authentication handshake with the first or second candidate network target using a momentary connection token; and to establish an end-to-end data transmission encryption link according to the dynamic encryption strategy and the temporary communication tunnel.
Citation Information
Patent Citations
Method, device and system for realizing pre-certification
CN101616463A