Internet of Things multi-protocol self-adaption method and system
Through protocol feature recognition and microservice architecture, the certificate management problem of IoT devices in a multi-protocol environment is solved, lightweight certificate automatic management and multi-protocol adaptation are achieved, and device resource utilization and system scalability are improved.
Patent Information
- Application Number
- CN202511134939.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-08-14
AI Technical Summary
IoT devices face problems of protocol fragmentation and resource constraints in a multi-protocol environment, resulting in complex, costly, and inefficient deployment of traditional PKI systems. Lightweight certificates also fail to address cross-protocol compatibility issues.
The protocol feature matrix and feature parsing rule matrix are used for protocol identification, lightweight certificate templates are generated, and automatic certificate management is achieved through a microservice architecture, including protocol adaptation microservices, CA/RA microservices and a dynamic certificate template engine. A unified PKI operation interface is provided to support multi-protocol self-adaptation.
It achieves seamless adaptation to multiple IoT protocols, reduces deployment complexity and cost, improves device resource utilization, has good compatibility and scalability, and supports the connection of massive devices.
Smart Images

Figure CN120639880A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to a method and system for multi-protocol self-adaptation of the Internet of Things. Background Art
[0002] The current IoT environment faces two key challenges:
[0003] 1) Protocol Fragmentation: IoT devices use numerous communication protocols (such as DLMS / MQTT / CoAP / LoRaWAN / Modbus), with vastly varying protocol stacks, data formats, and security mechanisms. Traditional PKI (Public Key Infrastructure) systems (primarily designed for HTTP / HTTPS) struggle to directly adapt to these protocols, requiring custom development for each protocol or reliance on protocol conversion gateways. This leads to complex, costly, and inefficient deployment. 2) Limited Device Resources: Many IoT devices have extremely low computing power, memory, and storage space. The certificate size of traditional PKI systems is prohibitively large for these devices, making them impractical.
[0004] Existing technologies typically use protocol gateways or customized PKI to address multi-protocol adaptation, but these have the following drawbacks: 1) Protocol-specific gateways: These introduce additional equipment, increasing single points of failure, latency, and cost, and the gateway itself can become a bottleneck. 2) Customized PKI: These simplify PKIs tailored to specific protocols / devices, sacrificing generality, making them difficult to scale and interoperate, and resulting in high maintenance costs. 3) Lightweight certificates: These only address the certificate size issue, but fail to address cross-protocol compatibility. Summary of the Invention
[0005] The technical problem to be solved by this application is to provide a method and system for realizing the automated and lightweight application and management of device certificates in an IoT environment with a mixture of multiple protocols such as DLMS / MQTT / CoAP / LoRaWAN / Modbus.
[0006] According to one aspect of the present application, a method for multi-protocol self-adaptation of the Internet of Things is provided, comprising the following steps: receiving a protocol message sent by an Internet of Things device; extracting features of the protocol message and performing protocol identification; parsing the protocol message based on the protocol identification result to obtain protocol message elements, wherein the protocol message elements include a certificate signing request, a signature algorithm type, and a security level; generating a certificate template; generating a certificate based on the certificate template; and encapsulating the certificate into a corresponding protocol message and sending it to the Internet of Things device.
[0007] According to some embodiments, the steps of extracting the features of the protocol message and performing protocol identification include: establishing a protocol feature matrix and a feature analysis rule matrix; assigning a weight value to each element in the row vector of the protocol feature matrix, and normalizing the row vector; extracting the features of the protocol message according to the feature analysis rule matrix to obtain a message feature matrix, and normalizing the row vectors in the message feature matrix; performing feature comparison between the row vectors of the message feature matrix and the row vectors in the protocol feature matrix, and calculating the similarity between them; if the maximum similarity is greater than a threshold, the match is successful, and the protocol identification is completed; otherwise, the protocol is an unknown protocol.
[0008] According to some embodiments, the protocol feature matrix, the feature parsing rule matrix, and the message feature matrix are all m×n matrices, where m is the number of protocols and n is the dimension of the protocol's feature vector; the protocol feature matrix contains m feature vectors of Internet of Things protocols; the feature parsing rule matrix contains m feature parsing rule vectors; and the message feature matrix contains m message feature vectors.
[0009] According to some embodiments, the feature parsing rule vector includes: the first N bytes, the protocol identifier, the length field position, the range of the first 4 bytes Shannon entropy, the check start position, the check length, the check algorithm and the transmission protocol; wherein N is an integer greater than 0.
[0010] According to some embodiments, the similarity is the cosine of the angle between the vectors.
[0011] According to some embodiments, the certificate template is a minimized certificate dynamically generated based on rules; the minimized certificate only contains mandatory fields, and other optional fields are dynamically added according to the security level; each protocol has a corresponding certificate template.
[0012] According to another aspect of the present application, a system for multi-protocol self-adaptation of the Internet of Things is also provided, for implementing the aforementioned method, characterized in that it includes: a protocol adaptation microservice, a CA / RA microservice, and a dynamic certificate template engine; the protocol adaptation microservice includes a protocol identification engine, a protocol adapter library, and a protocol abstraction layer; the protocol identification engine is used to extract message features and perform protocol identification; the protocol adapter library is used to parse the message to obtain protocol message elements; the protocol abstraction layer is used to provide a unified, protocol-independent core PKI operation interface; the CA / RA microservice is used to generate a certificate based on the certificate template, and send the certificate and protocol label to the protocol adaptation microservice through the protocol abstraction layer; the dynamic certificate template engine is used to generate a certificate template; the protocol adaptation microservice is used to receive protocol messages sent by the Internet of Things device, perform protocol identification and message parsing, send the certificate template to the CA / RA microservice through the protocol abstraction layer, find the protocol adapter according to the protocol label, encapsulate the certificate data into the corresponding protocol message, and send it to the Internet of Things device.
[0013] According to some embodiments, the PKI operation interface of the protocol abstraction layer includes the following API functions: requestCertificate(), downloadCertificate(), and queryCertificate(). The API functions are used to shield the details of the underlying specific communication protocol and implement the core logic of PKI to interact only with the protocol abstraction layer.
[0014] According to another aspect of the present application, a computer-readable storage medium is also provided, characterized in that the computer-readable storage medium includes a stored computer program, wherein when the computer program is executed by a processor, the device where the storage medium is located is controlled to execute the method for multi-protocol self-adaptation of the Internet of Things as described above.
[0015] The beneficial effects of this application are:
[0016] 1) It implements a PKI system that can seamlessly and automatically adapt to the vast majority of mainstream and non-mainstream IoT protocols. This eliminates the need to customize PKI components for each protocol or rely on external protocol conversion, solving the problem of protocol fragmentation and achieving "one-time deployment, multi-protocol support" with broad compatibility. At the same time, it replaces protocol-specific gateways with microservices, eliminating single points of failure and reducing latency and costs. 2) It provides a lightweight certificate design, enabling PKI functions to run efficiently on IoT devices with severely constrained resources. 3) PKI components are microserviced to meet the needs of connecting massive IoT devices, while providing good compatibility, scalability, and ease of deployment. 4) The microservice architecture and pluggable protocol adapter design facilitate horizontal system expansion and rapid support for emerging protocols. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 A system block diagram of multi-protocol self-adaptation for the Internet of Things according to an example embodiment is shown.
[0019] Figure 2 A protocol identification flow diagram is shown according to an example embodiment. DETAILED DESCRIPTION
[0020] The following describes the embodiments of the present application in detail with reference to the accompanying drawings. It should be understood that the embodiments described are only a portion of the embodiments of the present application, and not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0021] Those skilled in the art should be aware that the following specific embodiments or implementation methods are a series of optimized configuration methods listed in this application to further explain the specific application content, and these configuration methods can be combined or used in conjunction with each other, unless this application clearly states that some or a specific embodiment or implementation method cannot be associated with or used together with other embodiments or implementation methods. At the same time, the following specific embodiments or implementation methods are only intended to be optimized configuration methods and are not to be understood as limiting the scope of protection of this application.
[0022] Example 1
[0023] Figure 1 A system block diagram of multi-protocol self-adaptation for the Internet of Things according to an example embodiment is shown.
[0024] like Figure 1 As shown, a multi-protocol self-adaptive system for the Internet of Things (i.e. Figure 1The PKI microservice cluster in the protocol is composed of: a protocol adaptation microservice module, a CA / RA (certificate authority / registration authority) and other microservice modules, and a dynamic certificate template engine; the protocol adaptation microservice module includes a protocol identification engine for extracting message features and performing protocol identification; a protocol adapter library for parsing messages to obtain protocol message elements; a protocol abstraction layer for providing a unified, protocol-independent core PKI operation interface; the dynamic certificate template engine is used to generate a certificate template; the CA / RA and other microservice modules are used to generate a certificate according to the certificate template, and send the certificate and protocol label to the protocol adaptation microservice module through the protocol abstraction layer; the protocol adaptation microservice module is used to receive the protocol message sent by the IoT device, perform protocol identification and message parsing, and send the certificate template to the CA / RA microservice through the protocol abstraction layer, find the protocol adapter according to the protocol label, encapsulate the certificate data into the corresponding protocol message and send it to the IoT device.
[0025] like Figure 1 As shown, the overall process for IoT devices to apply for certificates using the above IoT multi-protocol self-adaptive system is as follows:
[0026] ①The IoT device sends the protocol message to the PKI protocol adaptation microservice.
[0027] ② After receiving the message, the protocol adapter microservice performs the following steps: S1, calls the protocol identification engine to extract message features and perform identification; S2, after identification, calls the corresponding protocol adapter to parse the message to obtain the certificate signing request CSR, signature algorithm type, security level, etc.; S3, calls the dynamic certificate template engine to generate a certificate template.
[0028] ③The protocol adaptation microservice sends the certificate template to the CA / RA microservice through the unified API provided by the protocol abstraction layer.
[0029] ④The CA / RA microservice generates a certificate based on the certificate template and sends the certificate and protocol tag to the protocol adaptation microservice through a unified API.
[0030] ⑤ The protocol adaptation microservice finds the protocol adapter based on the protocol tag, encapsulates the certificate and other data into the corresponding protocol message and sends it to the IoT device.
[0031] The protocol message includes the CSR, signature algorithm type (optional), and security level (optional). If the protocol message does not include the signature algorithm type or security level, the default configuration is in the certificate template.
[0032] Figure 2 A protocol identification flow diagram is shown according to an example embodiment.
[0033] like Figure 2As shown in the figure, the protocol identification process is as follows:
[0034] Step S21: Establish a protocol feature matrix and a feature analysis rule matrix.
[0035] Use A m×n represents the protocol feature matrix, X m×n Represents the feature parsing rule matrix, m represents the number of protocols, and n represents the dimension of the protocol's feature vector.
[0036] Taking n=5 (expandable), the feature parsing rule vector x is expressed as follows: [(first N bytes, protocol identifier), (length field position 1, length field position 2...), range of the first 4 bytes Shannon entropy (the first 4 bytes usually contain key information such as protocol identifier, version number, type field, etc., which is expandable), (check start position, length, check algorithm) or (0: indicates no check), (transport protocol 1, transport protocol 2...) (e.g.: 0=UDP / DTLS, 1=TCP / TLS, 2=HTTP / HTTPS)].
[0037] Shannon entropy is calculated as follows: H(X) = -Σp(x_i) × log2 (p(x_i)), where X is a random variable (here, a byte sequence) and p(x_i) is the probability of the byte value x_i occurring. For example, if X = [0x00, 0x01, 0x00, 0x01], then p(0x00) = 0.5, p(0x01) = 0.5, and H(X) = -(0.5 × log20.5 + 0.5 × log20.5) = 1.
[0038] For the protocol feature matrix A m×n Each element in the row vector is assigned a weight value (for example, the protocol identifier and length field positions have larger weights), and the row vector is normalized so that the modulus of the vector after processing is 1. The modulus processing can be ignored in feature comparison, reducing the amount of calculation.
[0039] The normalization formula for vector ai is as follows: aij' = aij / ∥ai∥, where 1≤i≤m, 1≤j≤n, ∥ai∥ is the modulus of vector ai before processing, aij is the element of vector ai before processing, aij' is the element of vector ai after processing, and the modulus of vector ai after processing is 1.
[0040] For example, in the DLMS protocol, the feature parsing rule vector x=[(2,0x0001), (7,8), (1,2), (0), (1)], the feature vector a=[4, 4, 1, 0, 1], and after normalization a'=[4 / √34, 4 / √34, 1 / √34, 0, 1 / √34].
[0041] Step S22: extracting message features.
[0042] With matrix B m×n Indicates the extracted message features. m×n , extract one feature from the message according to the feature parsing rules of each protocol, such as if the message meets the parsing rule x ij , then b ij = a ij , otherwise b ij = 0, and finally vector b i Perform unit processing (where: 1≤ i ≤m, 1≤ j≤ n). The processing of each protocol does not affect each other and can be processed in parallel. Parallel technologies such as multithreading can be used for efficient extraction.
[0043] Step S23: feature comparison.
[0044] To B m×n With A m×n The corresponding row vectors in the feature comparison can be used as the similarity by the cosine of the angle θ between the two vectors. The formula is cosθ i = b i .a i / (∥b i ∥∥a i ∥) = b i .a i = ij a ij , where 1≤ i ≤m, bi.ai is the vector dot product, ∥bi∥, ∥ai∥ is the vector modulus (due to normalization, the modulus is 1). The larger the cosine, the more similar it is. Select cosθ with the largest cosine. max As the final similarity, if cosθ max If the protocol is greater than or equal to the threshold (e.g., the threshold is 0.9, which is adjustable), it is a match; otherwise, it is an unknown protocol.
[0045] The protocol adapter library parses protocol messages and encapsulates data such as certificates into the protocol format. The protocol adapter library is pluggable. To add a new protocol, simply add a protocol adapter, register it with the library, and then add the corresponding row vectors to the matrices A and X.
[0046] The protocol abstraction layer defines a unified, protocol-independent set of core PKI operation interfaces (such as requestCertificate(), downloadCertificate(), queryCertificate(), etc.). This layer shields the details of the underlying communication protocols. The core logic of PKI (CA, RA) only interacts with the protocol abstraction layer.
[0047] The dynamic certificate template engine is used to dynamically generate minimal certificates based on rules. Each protocol has a certificate template that, by default, contains only required fields. Optional fields are added dynamically based on the security level. Table 1 provides examples of required and optional fields for the DLMS and CoAP protocols.
[0048] Table 1 Examples of mandatory and optional fields for two protocols
[0049]
[0050] Example 2
[0051] A specific embodiment of the present application further provides a computer-readable storage medium having a program stored thereon. When the program is executed by a processor, the program implements a multi-protocol self-adaptation method for the Internet of Things in the above embodiment.
[0052] The computer-readable storage medium may be an internal storage unit of any device with data processing capabilities described in any of the aforementioned embodiments, such as a hard disk or memory. The computer-readable storage medium may also be an external storage device of any device with data processing capabilities, such as a plug-in hard disk, a smart media card (SMC), an SD card, a flash card, etc. equipped on the device. Furthermore, the computer-readable storage medium may also include both an internal storage unit and an external storage device of any device with data processing capabilities. The computer-readable storage medium is used to store the computer program and other programs and data required by any device with data processing capabilities, and may also be used to temporarily store data that has been output or is to be output.
[0053] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A method for multi-protocol self-adaptation of the Internet of Things, characterized in that: The following steps are involved: Receive protocol messages sent by IoT devices; Extracting features of the protocol message and performing protocol identification; Parsing the protocol message according to the protocol identification result to obtain protocol message elements, wherein the protocol message elements include a certificate signing request, a signature algorithm type, and a security level; Generate certificate template; generating a certificate according to the certificate template; The certificate is encapsulated into a corresponding protocol message and sent to the IoT device.
2. The method for multi-protocol self-adaptation of the Internet of Things according to claim 1, characterized in that: The step of extracting the features of the protocol message and performing protocol identification comprises: Establish a protocol feature matrix and a feature parsing rule matrix; Assigning a weight value to each element in the row vector of the protocol feature matrix and normalizing the row vector; Extracting features of the protocol message according to the feature parsing rule matrix to obtain a message feature matrix, and normalizing row vectors in the message feature matrix; Perform feature comparison on the row vectors of the message feature matrix and the row vectors in the protocol feature matrix, and calculate the similarity between them; If the maximum similarity is greater than the threshold, the match is successful and the protocol identification is completed; otherwise, the protocol is an unknown protocol.
3. The method for multi-protocol self-adaptation of the Internet of Things according to claim 2, characterized in that: The protocol feature matrix, the feature parsing rule matrix, and the message feature matrix are all m×n matrices, where m is the number of protocols and n is the dimension of the protocol's feature vector; The protocol feature matrix includes m feature vectors of IoT protocols; The feature parsing rule matrix includes m feature parsing rule vectors; The message feature matrix includes m message feature vectors.
4. The method for multi-protocol self-adaptation of the Internet of Things according to claim 3, characterized in that: The feature parsing rule vector includes: The first N bytes, protocol identifier, length field position, range of the first 4 bytes of Shannon entropy, check start position, check length, check algorithm and transmission protocol; where N is an integer greater than 0.
5. The method for multi-protocol self-adaptation of the Internet of Things according to claim 2, characterized in that: The similarity is the cosine of the angle between the vectors.
6. The method for multi-protocol self-adaptation of the Internet of Things according to claim 1, characterized in that: The certificate template is a minimized certificate dynamically generated based on rules; The minimized certificate only contains mandatory fields, and other optional fields are dynamically added according to the security level; Each protocol has a corresponding certificate template.
7. A multi-protocol self-adaptive system for the Internet of Things, used to implement the method according to any one of claims 1 to 6, characterized in that: include: Protocol adaptation microservice, CA / RA microservice and dynamic certificate template engine; The protocol adaptation microservice includes a protocol identification engine, a protocol adapter library and a protocol abstraction layer; The protocol identification engine is used to extract message features and perform protocol identification; The protocol adapter library is used to parse the message to obtain the protocol message elements; The protocol abstraction layer is used to provide a unified, protocol-independent core PKI operation interface; The CA / RA microservice is used to generate a certificate based on the certificate template, and send the certificate and protocol tag to the protocol adaptation microservice through the protocol abstraction layer; The dynamic certificate template engine is used to generate a certificate template; The protocol adapter microservice is used to receive protocol messages sent by IoT devices, perform protocol identification and message parsing, send the certificate template to the CA / RA microservice through the protocol abstraction layer, find the protocol adapter according to the protocol tag, encapsulate the certificate data into the corresponding protocol message and send it to the IoT device.
8. The multi-protocol self-adaptive system for the Internet of Things according to claim 7, characterized in that: The PKI operation interface of the protocol abstraction layer includes the following API functions: requestCertificate(), downloadCertificate() and queryCertificate(), The API function is used to shield the details of the underlying specific communication protocol, so that the core logic of the PKI only interacts with the protocol abstraction layer.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed by a processor, the device where the storage medium is located is controlled to execute the method for multi-protocol self-adaptation of the Internet of Things according to any one of claims 1 to 6.
Citation Information
Patent Citations
Integrated digital home control system based on hybrid cloud and heterogeneous Internet of Things
CN108696565A
Method and system for unifying different CA system interface protocols
CN115801910A
Internet of Things platform data processing method and device based on protocol and signature
CN116155905A
Method and system for dynamically expanding non-HTTP (Hyper Text Transport Protocol) based on micro-service gateway
CN116192933A
Dynamic expansion and hot plug method of equipment communication protocol
CN116233283A