Security protection method and device of smart home gateway, electronic equipment and medium
By employing multi-protocol and multi-layered security mechanisms, the system addresses the weak security protection of smart home gateways, achieving in-depth defense across the entire chain, enhancing system security and stability, and meeting domestic compliance requirements.
Patent Information
- Application Number
- CN202511441650.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-10-10
AI Technical Summary
Existing smart home gateways have weak security protection capabilities and are vulnerable to network threats such as unauthorized device access, man-in-the-middle attacks, data eavesdropping, and malicious code injection. Furthermore, they are difficult to meet the security compliance requirements for domestic production.
It adopts a multi-protocol, multi-layer security mechanism, including identity authentication, encryption algorithms, and network traffic anomaly detection. Data security protection is carried out through Zigbee communication module, main control module and Ethernet communication module. Combined with national cryptographic algorithms and local priority processing strategy, a full-link defense-in-depth system is built.
It significantly improves the security and stability of smart home systems, preventing risks such as unauthorized access, data leakage, and malicious firmware injection, and meets the security compliance requirements for domestic production.
Smart Images

Figure CN120915609A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of smart home devices, and relates to a security protection method and device for a smart home gateway, an electronic device and a medium. BACKGROUND
[0002] With the rapid development of Internet of Things technology and the wide application of smart home systems, the number of smart terminal devices connected to the home network environment continues to grow, covering smart lighting, security monitoring, environmental sensing, home appliance control and other types. As the core hub of the home network, the smart home gateway undertakes key functions such as device access management, heterogeneous network communication, protocol conversion, data aggregation and forwarding, and is an important node for realizing the interconnection and centralized control of smart home systems.
[0003] However, since the smart home gateway is usually exposed to the public network environment and interacts with a large number of smart terminal devices, it faces increasing security risks. The existing smart home gateway generally has weak security protection capabilities and is vulnerable to network threats such as illegal device access, man-in-the-middle attacks, data eavesdropping, replay attacks and malicious code injection. In addition, sensitive private content such as user behavior data, identity information and control instructions lacks effective protection during transmission and storage, and there is a risk of being stolen, tampered with or misused, which seriously threatens user privacy and home security.
[0004] Currently, the security protection scheme of the smart home gateway relies on internationally common encryption algorithms. However, with the continuous improvement of the security controllability requirements for key information infrastructure, such technical solutions are difficult to meet the standard requirements of domestic security compliance. SUMMARY
[0005] The application provides a security protection method and device for a smart home gateway, an electronic device and a medium, which are used to improve the security of smart home systems and the ability to protect user privacy, while meeting the requirements of domestic security compliance.
[0006] In a first aspect, the application provides a security protection method of a smart home gateway, the smart home gateway comprising a Zigbee communication module, a master control module and an Ethernet communication module; the Zigbee communication module is in communication connection with a smart home terminal based on a Zigbee protocol; the master control module is in serial communication connection with the Zigbee communication module and the Ethernet communication module respectively; the Ethernet communication module is in communication connection with a remote control platform based on an HTTPS protocol and an MQTT protocol; the method comprises: performing access security protection on the smart home terminal and the remote control platform through identity authentication; performing data security protection on communication data between the smart home terminal, the smart home gateway and the remote control platform based on an encryption algorithm; performing privacy security protection on user sensitive data generated by the smart home gateway through data interaction based on a local priority processing strategy; performing security protection on a firmware remote upgrade process based on a security channel constructed by the HTTPS protocol, in combination with a digital signature and an integrity verification mechanism; performing security protection on communication traffic generated by the smart home gateway based on the Zigbee protocol, the HTTPS protocol and the MQTT protocol based on a network traffic anomaly detection algorithm.
[0007] In an implementation form of the first aspect, performing access security protection on the smart home terminal and the remote control platform through identity authentication comprises: identifying and rejecting access requests of illegal terminals through a preset device white list and a dynamic key negotiation mechanism, so as to complete identity legality verification of the smart home terminal; in response to an access request of the remote control platform, performing identity authentication on the remote control platform based on a digital certificate or an identity token, and authorizing a request party passing the identity authentication to access corresponding gateway resources.
[0008] In an implementation form of the first aspect, the remote control platform comprises a client and a cloud server, and the client and the cloud server are in communication connection; authorizing a request party passing the identity authentication to access corresponding gateway resources comprises: generating an identity token having time effectiveness, uniqueness and permission binding characteristics after the client or the cloud server passes the identity authentication; signing the identity token based on an encryption algorithm to obtain a signed identity token; performing validity verification on the signed identity token; and authorizing the client or the cloud server to access corresponding gateway resources when the signed identity token passes the validity verification.
[0009] In an implementation form of the first aspect, the smart home gateway further comprises a security module, which is in communication connection with the master module; the data security protection of the communication data between the smart home terminal, the smart home gateway and the remote control platform based on the encryption algorithm comprises: encrypting the data transmitted between the smart home terminal and the Zigbee communication module based on the advanced encryption standard algorithm; encrypting the data transmitted between the Zigbee communication module and the master module, and between the master module and the Ethernet communication module based on the symmetric encryption algorithm, wherein the key used by the symmetric encryption algorithm is generated and managed by the security module when the Zigbee communication module and the master module are first paired based on a security key agreement mechanism; and the data transmitted between the Ethernet communication module and the remote control platform is encrypted based on the national encryption algorithm.
[0010] In an implementation form of the first aspect, the smart home gateway further comprises a storage module, which is in communication connection with the master module and the security module respectively; the privacy security protection of the user sensitive data generated by the smart home gateway through data interaction based on the local priority processing strategy comprises: desensitizing and minimizing the user sensitive data locally in priority, and writing the processed sensitive data into the storage module; when a specific business requirement is met, uploading the user sensitive data to a cloud server through a secure channel constructed based on the HTTPS protocol or the MQTT protocol; dynamically configuring the collection, storage and sharing range of the user sensitive data based on the privacy policy set by the user on the client; and encrypting the sensitive data using the national encryption algorithm or the international standard algorithm before writing the processed sensitive data into the storage module and when uploading the user sensitive data, wherein the key used for encryption is generated and managed by the security module.
[0011] In an implementation form of the first aspect, the security protection of the communication traffic generated by the smart home gateway based on the Zigbee protocol, the HTTPS protocol and the MQTT protocol based on the network traffic anomaly detection algorithm comprises: monitoring the communication traffic generated by the smart home gateway based on the Zigbee protocol, the HTTPS protocol and the MQTT protocol in real time; processing the monitored communication traffic based on the network traffic anomaly detection algorithm to identify the security threats existing when the smart home gateway communicates with the smart home terminal and the remote control platform respectively; the security threats include illegal access, data leakage and protocol attack; triggering corresponding security protection measures based on the security threats; the security protection measures include log recording, security alarm, communication blocking and device isolation.
[0012] In an implementation form of the first aspect, further comprising: performing multi-security management on the cloud server based on a user management security mechanism; wherein the user management security mechanism comprises multi-factor identity authentication, role-based permission hierarchical control, sensitive operation auditing and alarming, session security management, data encryption and privacy protection, and security policy customization.
[0013] In a second aspect, the present application provides a security protection device of an intelligent home gateway, the intelligent home gateway comprising a Zigbee communication module, a master control module and an Ethernet communication module; the Zigbee communication module is in communication connection with an intelligent home terminal based on a Zigbee protocol; the master control module is in serial communication connection with the Zigbee communication module and the Ethernet communication module respectively; the Ethernet communication module is in communication connection with a remote control platform based on an HTTPS protocol and an MQTT protocol; the device comprises: an access protection module, configured to perform access security protection on the intelligent home terminal and the remote control platform through identity authentication; a communication protection module, configured to perform data security protection on communication data between the intelligent home terminal, the intelligent home gateway and the remote control platform based on an encryption algorithm; a privacy protection module, configured to perform privacy security protection on user sensitive data generated by the intelligent home gateway through data interaction based on a local priority processing strategy; an update protection module, configured to perform security protection on a firmware remote upgrade process based on a security channel constructed by the HTTPS protocol, in combination with a digital signature and an integrity checking mechanism; and a traffic protection module, configured to perform security protection on communication traffic generated by the intelligent home gateway based on Zigbee protocol, HTTPS protocol and MQTT protocol based on a network traffic anomaly detection algorithm.
[0014] In a third aspect, the present application provides an electronic device, comprising: a memory, configured to store a computer program; and a processor, configured to execute the computer program stored in the memory, so that the electronic device executes the method of any one of the above aspects.
[0015] In a fourth aspect, the present application provides a computer readable storage medium, having a computer program stored thereon, the computer program being executed by a processor to implement the method of any one of the above aspects.
[0016] As described above, the security protection method, device, electronic device and medium of the intelligent home gateway provided by the present application effectively prevent security risks such as illegal access, data leakage, privacy abuse, malicious firmware injection and protocol layer attack by adopting multi-protocol and multi-level security mechanisms and privacy protection strategies, significantly improve the overall security, stability and attack resistance of the intelligent home system, and meet the requirements of domestic security compliance. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 Fig. 1 shows a structural schematic diagram of an intelligent home system according to an embodiment of the present application.
[0018] Figure 2 Fig. 2 shows a structural schematic diagram of an intelligent home gateway according to an embodiment of the present application.
[0019] Figure 3 Fig. 3 shows a flowchart of a security protection method of the intelligent home gateway according to an embodiment of the present application.
[0020] Figure 4 Fig. 4 shows a structural schematic diagram of an intelligent home gateway according to another embodiment of the present application.
[0021] Figure 5 Fig. 5 shows a flowchart of the privacy security protection according to an embodiment of the present application.
[0022] Figure 6 Fig. 6 shows a flowchart of the communication flow security protection according to an embodiment of the present application.
[0023] Figure 7 Fig. 7 shows an interaction timing diagram between the modules of the intelligent home gateway and the intelligent home terminal and the remote control platform according to an embodiment of the present application.
[0024] Figure 8 Fig. 8 shows a structural schematic diagram of a security protection device of the intelligent home gateway according to an embodiment of the present application.
[0025] Figure 9 Fig. 9 shows a data flow diagram of the intelligent home gateway system and the security protection device of the intelligent home gateway according to an embodiment of the present application.
[0026] Figure 10 Fig. 10 shows a structural schematic diagram of an electronic device according to an embodiment of the present application.
[0027] Element number explanation 10 intelligent home terminal 20 intelligent home gateway 21 Zigbee communication module 22 master control module 23 Ethernet communication module 24 security module 25 storage module 30 remote control platform 31 client 32 cloud server 41 access protection module 42 communication protection module 43 privacy protection module 44 update protection module 45 traffic guard module 51 memory 52 processor 53 display DETAILED DESCRIPTION
[0028] The present application can also be embodied in a different specific form, without departing from the spirit or central characteristics of the present application. Embodiments disclosed in this specification are to be considered in all respects as illustrative and not restrictive. It should also be understood that the following embodiments and features thereof can be combined with each other, without conflict.
[0029] It should be noted that the drawings provided in the following embodiments only schematically illustrate the basic concept of the present application, and only the components related to the present application are shown in the drawings, rather than the number, shape and size of the components when actually implemented. The actual implementation of each component can be arbitrarily changed in terms of shape, number and ratio, and the layout pattern of the components can also be more complex.
[0030] The following embodiments of the present application provide a security protection method and device for a smart home gateway, an electronic device and a medium. Through the synergistic effect of multiple security protection mechanisms such as device access protection, data transmission protection, user privacy protection, firmware remote upgrade protection and communication traffic protection, an integrated and multi-level security protection architecture is formed, and a depth defense system covering the whole link of "terminal-network-cloud" is constructed. This system can realize legal identity authentication of the device on the terminal side, realize local data security processing through encrypted transmission, protocol security reinforcement and traffic anomaly detection mechanism on the communication side, and realize user permission control, operation audit and dynamic policy management on the cloud side, so as to comprehensively guarantee the security and controllability of the smart home system in the key links of device access, data transmission, storage processing, remote control, etc.
[0031] Before the technical solutions of the present application are described in detail, the hardware architecture of the smart home system and the smart home gateway involved in the following embodiments of the present application is first described, so as to provide a clear basic framework for the subsequent technical content.
[0032] Please refer to Figure 1 , which shows a structural schematic diagram of a smart home system in an embodiment of the present application.
[0033] As Figure 1As shown, the smart home system includes a smart home terminal 10, a smart home gateway 20 and a remote control platform 30. The smart home gateway 20 is communicatively connected with the smart home terminal 10 and the remote control platform 30 respectively.
[0034] Please refer to Figure 2 , which shows a structural schematic diagram of the smart home gateway in an embodiment of the present application.
[0035] As Figure 2 shown, the smart home gateway 20 includes a Zigbee communication module 21, a master control module 22 and an Ethernet communication module 23; the Zigbee communication module 21 is communicatively connected with the smart home terminal 10 based on Zigbee protocol; the master control module 22 is communicatively connected with the Zigbee communication module 21 and the Ethernet communication module 23 through serial communication respectively; the Ethernet communication module 23 is communicatively connected with the remote control platform 30 based on HTTPS (HyperText Transfer Protocol Secure) protocol and MQTT (Message Queuing Telemetry Transport) protocol.
[0036] Specifically, the Zigbee communication module 21 complies with IEEE 802.15.4 standard and Zigbee protocol stack specification, has characteristics such as low power consumption, self-organizing network and multi-hop transmission, and is suitable for device interconnection scenarios in home environment which have high requirements on reliability and energy efficiency.
[0037] The master control module 22 is the core processing unit of the smart home gateway 20, and can usually adopt an embedded microprocessor or a system-level chip. For example, a processor based on ARM architecture, running a real-time operating system or a lightweight Linux system. The master control module 22 has functions such as protocol conversion, data processing, task scheduling and security management. The master control module 22 establishes a bidirectional communication connection with the Zigbee communication module 21 and the Ethernet communication module 23 through UART or USART serial port, realizes data interaction of command issuing and state feedback.
[0038] The Ethernet communication module 23 is used to realize the wide area network connection between the smart home gateway 20 and the remote control platform 30. The module accesses the home broadband network through a wired Ethernet interface, and then accesses the Internet. At the communication protocol level, the Ethernet communication module 23 adopts the HTTPS protocol and the MQTT protocol to interact with the remote control platform 30. The HTTPS protocol is used to protect the confidentiality and integrity of sensitive data such as user configuration information and authentication credentials during transmission, to prevent eavesdropping and tampering. The MQTT protocol is a lightweight publish / subscribe mode message transmission protocol, which is suitable for remote monitoring and control of devices in low-bandwidth and unstable network environments, and has the advantages of low delay and high efficiency.
[0039] The remote control platform 30 includes a client 31 and a cloud server 32, and the client 31 and the cloud server 32 are in communication connection. The cloud server 32 is deployed in a data center or a cloud environment, and is responsible for core functions such as device management, user authentication, data storage, business logic processing, and message routing. The client 31 can be an application (App) or a Web interface running on a smartphone, tablet computer, or personal computer. Users can remotely access, view the status of, and control the smart home terminal through the client 31. The client 31 and the cloud server 32 communicate through a secure encrypted channel (such as TLS / SSL) to ensure the security of end-to-end data transmission.
[0040] The principles and implementation manners of the security protection method, device, and electronic equipment of the smart home gateway according to the embodiment will be described in detail below, so that those skilled in the art can understand the security protection method, device, and electronic equipment of the smart home gateway according to the embodiment without any creative work.
[0041] Please refer to Figure 3 , which shows a flowchart of the security protection method of the smart home gateway according to an embodiment of the present application.
[0042] As Figure 3 shown, the present embodiment provides a security protection method of a smart home gateway, which includes the following steps S100 to S500.
[0043] In step S100, the smart home terminal 10 and the remote control platform 30 are protected by identity authentication.
[0044] Specifically, the smart home terminal 10 is a device supporting the Zigbee communication protocol. For example, the smart home terminal 10 can be a smart lamp, a smart switch, a smart curtain, etc.
[0045] It should be noted that the number of smart home terminals 10 can be flexibly configured according to actual application scenarios, and can be one or more, and the present application does not limit this.
[0046] In an embodiment of the present application, the access security protection of the smart home terminal 10 and the remote control platform 30 through identity authentication includes the following steps S110 to S120.
[0047] In step S110, the access request of an illegal terminal is identified and rejected through a preset device white list and a dynamic key negotiation mechanism, so as to complete the identity legality verification of the smart home terminal 10.
[0048] In the present embodiment, the device white list includes a set of authorized legal device identification information. For example, the IEEE 802.15.4 MAC address of the device, the product serial number or the preset unique device ID. When a smart home terminal 10 initiates a network access request, the Zigbee communication module 21 receives the request and forwards it to the host module 22. The host module 22 parses the device identity information in the request message and compares it with the records in the white list database. If the device identity is not within the white list range, its access request is immediately rejected, and relevant event logs can be recorded for subsequent audit.
[0049] To enhance security and prevent known legal device identities from being imitated, the present application also introduces a dynamic key negotiation mechanism. Specifically, after the device passes the white list check, the host module 22 triggers the key negotiation process, requiring the requesting device to participate in the challenge-response authentication process, and only when the verification is passed will the device be allowed to formally access the smart home gateway 20.
[0050] In the present implementation, through the dual verification mechanism of white list and dynamic key negotiation, the pseudo-access behavior of illegal devices can be effectively identified and blocked, and the security protection capability of the local network boundary is significantly improved.
[0051] In step S120, in response to the access request of the remote control platform 30, the identity of the remote control platform 30 is authenticated based on a digital certificate or an identity token (Token), and the request party that passes the identity authentication is authorized to access the corresponding gateway resources.
[0052] In the present embodiment, the Token can be generated based on user / service identity, device information and timestamp, and is digitally signed using an encryption algorithm to ensure that it cannot be tampered with.
[0053] In addition, the application supports a token life cycle management mechanism, including active invalidation, remote logout, forced offline, permission binding, and other session management functions, to prevent unauthorized access and session hijacking. For example, when a user logs out or a device is unbound, the system will blacklist the token or automatically invalidate it through a short validity period design, thereby preventing credential abuse.
[0054] In an embodiment of the present application, the requestor is authorized to access the corresponding gateway resource after identity authentication, including: generating an identity token with time effectiveness, uniqueness, and permission binding characteristics; signing the identity token based on an encryption algorithm to obtain a signed identity token; verifying the validity of the signed identity token; and authorizing the client 31 or the cloud server 32 to access the corresponding gateway resource when the signed identity token passes the validity verification.
[0055] In the present implementation, by adopting an identity token access control mechanism based on encryption signature, illegal access and permission abuse can be effectively prevented, providing a reliable guarantee for the safe operation of the smart home system in an open network environment.
[0056] In step S200, data security protection is performed on the communication data between the smart home terminal 10, the smart home gateway 20, and the remote control platform 30 based on an encryption algorithm.
[0057] Referring to Figure 4 , a structural schematic diagram of the smart home gateway 20 in another embodiment of the present application is shown.
[0058] As shown in Figure 4 , the smart home gateway 20 further includes a security module 24, which is in communication connection with the main control module 22.
[0059] The security module 24 is configured to generate and manage a local data encryption key. The local data encryption key includes a Zigbee network key, a session key, a device master key, etc. The security module 24 also supports a hierarchical encryption mechanism, i.e., different encryption levels and access policies are set according to different data types (such as control instructions, user privacy data, log information) and access subjects (such as users, administrators, third-party services), and fine-grained data permission management is realized in combination with an access control list.
[0060] In an embodiment of the present application, data security protection is performed on the communication data between the smart home terminal 10, the smart home gateway 20, and the remote control platform 30 based on an encryption algorithm, including the following steps S210 to S230.
[0061] At step S210, the data transmitted between the smart home terminal 10 and the Zigbee communication module 21 is encrypted based on an Advanced Encryption Standard (AES) algorithm.
[0062] Specifically, during the network access phase of the smart home terminal 10, the AES encryption algorithm is used for key negotiation and network security protection, ensuring good interoperability and protocol compatibility between the smart home terminal 10 and the smart home gateway 20.
[0063] At step S220, the data transmitted between the Zigbee communication module 21 and the master module 22, and between the master module 22 and the Ethernet communication module 23 is encrypted based on a symmetric encryption algorithm.
[0064] In this embodiment, the key used by the symmetric encryption algorithm is generated and managed by the security module 24 based on a secure key negotiation mechanism when the Zigbee communication module 21 and the master module 22 are first paired.
[0065] Specifically, the SM4 symmetric encryption algorithm can be used to encrypt all data packets transmitted. At the same time, a data digest is generated using the SM3 cryptographic hash algorithm for integrity verification of the data packet, to effectively prevent data eavesdropping, tampering, and replay attacks. The data packet contains a digest verification field generated by the SM3 algorithm, which is used to verify the integrity and authenticity of the data during transmission on the serial communication interface at the receiving end.
[0066] The key used by the symmetric encryption algorithm supports a periodic rotation mechanism, which periodically updates the key to enhance the long-term security of the system and reduce the security risks caused by key leakage.
[0067] At step S230, the data transmitted between the Ethernet communication module 23 and the remote control platform 30 is encrypted based on a national cryptographic algorithm using TLS / SSL.
[0068] In this embodiment, the national cryptographic algorithm used includes the SM2 public key cryptographic algorithm, the SM3 hash cryptographic algorithm, and the SM4 block cipher algorithm.
[0069] In some embodiments, a cryptographic algorithm that meets international standards can also be used to encrypt the communication data between the Ethernet communication module 23 and the remote control platform 30 to achieve corresponding security protection.
[0070] In this implementation, by encrypting the data for transmission, the confidentiality and integrity of the communication data during transmission over a public network can be effectively guaranteed.
[0071] At step S300, the user sensitive data generated by the smart home gateway 20 through data interaction is protected based on a local priority processing strategy.
[0072] In this embodiment, the user sensitive data can be derived from data reported by the smart home terminal 10, control data issued by the user through the client 31, operation logs of the user, system configuration data, etc. Taking a smart home application scenario as an example, the user sensitive data includes user identity information (such as user account, name, mobile phone number, email), user authentication credentials (such as password, Token, key), home network topology and spatial layout information, device running state and control instructions, and other information closely related to user privacy.
[0073] In an embodiment of the present application, the smart home gateway 20 further includes a storage module 25, which is in communication connection with the main control module 22 and the security module 24 respectively.
[0074] Please refer to Figure 5 , which shows a flowchart of the privacy security protection according to an embodiment of the present application.
[0075] As Figure 5 shown, the privacy security protection of the user sensitive data generated by the smart home gateway 20 through data interaction based on a local priority processing strategy includes the following steps S301 to S304.
[0076] At step S301, the user sensitive data is desensitized and minimized locally in priority, and the processed sensitive data is written into the storage module 25.
[0077] Specifically, the desensitization processing includes masking, hashing, replacing or generalizing sensitive fields through technical means, so that it cannot directly identify specific individuals or leak key privacy information; the minimization processing is used to retain data items necessary to meet specific functional or business purposes, and to eliminate irrelevant or redundant information, thereby reducing the risk of privacy leakage.
[0078] At step S302, when a specific business requirement is met, the user sensitive data is uploaded to the cloud server 32 through a secure channel based on the HTTPS protocol or the MQTT protocol.
[0079] Specifically, the specific business requirement includes remote device state monitoring, cross-region device linkage control, fault diagnosis and log analysis, firmware upgrade service, user-authorized data synchronization, abnormal behavior detection, and system performance optimization, and other functional scenarios that need to rely on cloud computing resources or remote service support.
[0080] At step S303, the collection, storage and sharing range of the user sensitive data are dynamically configured based on the privacy policy set by the user at the client 31.
[0081] Specifically, the privacy policy supports the user to set data processing rules in different data types, different devices or application scenarios on demand, realizing fine-grained privacy control.
[0082] At step S304, before writing the processed sensitive data into the storage module 25 and when uploading the user sensitive data, the sensitive data is encrypted by using a national cryptographic algorithm or an international standard algorithm.
[0083] Specifically, the key used for encryption is generated and managed by the security module 24, preventing data leakage caused by physical theft and illegal reading and the like.
[0084] In the present implementation, by using the local first processing strategy, it can be ensured that the user sensitive data is kept within the local network range in the collection, processing and storage and the like, reducing unnecessary uploading of sensitive information to the cloud or external network, thereby improving the data privacy and security, meeting the data minimization principle and the technical requirements for personal information protection.
[0085] At step S400, the secure channel constructed based on the HTTPS protocol is used in combination with the digital signature and integrity check mechanism to perform security protection on the firmware remote upgrade process.
[0086] Specifically, the remote firmware upgrade package is signed by using the digital signature technology at the publishing end, and the integrity check information is generated before transmission. At the receiving end, the signature verification and integrity check are performed on the upgrade package before writing the firmware.
[0087] In the present implementation, the injection of malicious firmware and illegal flashing can be effectively prevented, and it is ensured that only the authenticated legal firmware can complete the update operation, thereby realizing secure and trusted remote firmware upgrade, and guaranteeing the stability of device operation and system security.
[0088] At step S500, the network traffic anomaly detection algorithm is used to perform security protection on the communication traffic generated by the smart home gateway 20 based on the Zigbee protocol, the HTTPS protocol and the MQTT protocol.
[0089] Please refer to Figure 6 , which shows a communication traffic security protection flowchart according to an embodiment of the present application.
[0090] As Figure 6As shown, the security protection of the smart home gateway 20 based on Zigbee protocol, HTTPS protocol and MQTT protocol communication traffic based on the network traffic anomaly detection algorithm includes the following steps S501 to S503.
[0091] In step S501, the communication traffic generated by the smart home gateway 20 based on Zigbee protocol, HTTPS protocol and MQTT protocol is monitored in real time.
[0092] Specifically, the monitoring range covers uplink and downlink data streams, and multi-dimensional traffic feature information including packet length, communication frequency, session length, target address distribution, protocol field characteristics and data transmission rate is collected to provide a data basis for subsequent anomaly detection.
[0093] In step S502, the network traffic anomaly detection algorithm is used to process the monitored communication traffic to identify security threats existing when the smart home gateway 20 communicates with the smart home terminal 10 and the remote control platform 30 respectively.
[0094] In this embodiment, the security threats include illegal access, data leakage and protocol attacks.
[0095] Specifically, the network traffic anomaly detection algorithm can use a detection mechanism based on rule matching, statistical analysis, machine learning model or their combination, which can dynamically learn normal communication behavior patterns and judge abnormal traffic deviating from normal behavior accordingly.
[0096] In step S503, based on the security threats, the corresponding security protection measures are triggered; the security protection measures include log recording, security alarm, communication blocking and device isolation.
[0097] In this implementation, real-time monitoring and intelligent analysis of multi-protocol communication traffic are achieved, which can autonomously identify and respond to typical security threats such as illegal access, data leakage and protocol layer attacks without relying on external security devices, significantly enhancing the security capability and overall protection level of the system.
[0098] In an embodiment of the present application, the security protection method of the smart home gateway in the embodiment of the present application further includes step S600.
[0099] In step S600, the cloud server 32 is subjected to multiple security management based on a user management security mechanism; wherein the user management security mechanism includes multi-factor identity authentication, role-based permission hierarchical control, sensitive operation audit and alarm, session security management, data encryption and privacy protection, and security policy customization.
[0100] Through the synergistic effect of the multiple security management mechanisms, the comprehensive security protection level of the cloud server in user identity authentication, permission control, operation audit and data protection and the like can be effectively improved, the compliance requirements in a high security level application scenario can be met, and a reliable remote service environment is provided for users.
[0101] Referring to Figure 7 , a timing sequence diagram of interaction between modules of the smart home gateway and the smart home terminal and the remote control platform is shown.
[0102] As Figure 7 shown, in this embodiment, the data interaction between the modules of the smart home gateway 20 and the smart home terminal 10 and the remote control platform 30 follows a specific execution sequence.
[0103] It should be noted that the protection scope of the security protection method of the smart home gateway described in the embodiments of the present application is not limited to the execution sequence of the steps listed in the embodiments, and any scheme realized by adding, replacing or deleting steps of the prior art according to the principle of the present application is included in the protection scope of the present application.
[0104] Referring to Figure 8 , a structural schematic diagram of the security protection device of the smart home gateway according to an embodiment of the present application is shown.
[0105] As Figure 8 shown, the present application provides a security protection device of a smart home gateway, which comprises an access protection module 41, a communication protection module 42, a privacy protection module 43, an update protection module 44 and a traffic protection module 45.
[0106] The access protection module 41 is configured to perform access security protection on the smart home terminal 10 and the remote control platform 30 through identity authentication.
[0107] The communication protection module 42 is configured to perform data security protection on the communication data between the smart home terminal 10, the smart home gateway 20 and the remote control platform 30 based on an encryption algorithm.
[0108] The privacy protection module 43 is configured to perform privacy security protection on user sensitive data generated by the smart home gateway 20 through data interaction based on a local priority processing strategy.
[0109] The update protection module 44 is configured to perform security protection on a firmware remote upgrade process based on a security channel constructed by an HTTPS protocol, in combination with a digital signature and an integrity verification mechanism.
[0110] The traffic protection module 45 is configured to perform security protection on the communication traffic generated by the smart home gateway 20 based on Zigbee protocol, HTTPS protocol and MQTT protocol based on a network traffic anomaly detection algorithm.
[0111] It should be noted that the structures and principles of the access protection module 41, the communication protection module 42, the privacy protection module 43, the update protection module 44 and the traffic protection module 45 in this embodiment correspond one by one to the steps in the security protection method of the smart home gateway, and therefore will not be described here.
[0112] Please refer to Figure 9 , which shows the data flow conversion schematic diagram of the smart home gateway system and the security protection device of the smart home gateway according to an embodiment of the present application. From Figure 9 , the data interaction process between the security protection device of the smart home gateway and the smart home gateway, and between the smart home gateway and the smart home terminal and the remote control platform can be seen in detail.
[0113] It should be noted that only part of the data interaction examples are shown in the figure, and in the actual running scene, there may be other implicit data interaction links that have not been embodied in the figure.
[0114] The security protection device of the smart home gateway provided in the embodiments of the present application can implement the security protection method of the smart home gateway described in the present application, but the implementation device of the security protection method of the smart home gateway described in the present application includes but is not limited to the structure of the security protection device of the smart home gateway listed in the embodiments, and any structural deformation and replacement of the prior art according to the principles of the present application are included in the protection scope of the present application.
[0115] Please refer to Figure 10 , which shows the structure schematic diagram of the electronic device according to an embodiment of the present application.
[0116] As shown in Figure 10 , the present embodiment provides an electronic device, which includes a memory 51 and a processor 52.
[0117] Specifically, the memory 51 is configured to store a computer program, which can include various media that can store program codes, such as ROM, RAM, disk, U disk, memory card or optical disk.
[0118] In the embodiments of the present application, the memory 51 can include a computer system readable medium in the form of volatile memory, such as RAM and / or cache memory. The electronic device can further include other removable / non-removable, volatile / non-volatile computer system storage media. The memory 51 can include at least one program product having a set (for example, at least one) of program modules configured to perform the functions of the embodiments of the present application.
[0119] The processor 52 is connected to the memory 51, and is configured to execute the computer program stored in the memory 51, so that the electronic device performs the method described in any one of the above.
[0120] Exemplarily, the processor 52 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. In other embodiments, the processor 52 can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0121] In some implementations, the electronic device provided by the embodiments of the present application can further include a display 53. The display 53 is connected in communication with the memory 51 and the processor 52, and is configured to display a graphical user interface (GUI) related to the electrical drawing design method based on the DeepSeek model.
[0122] In the embodiments of the present application, the display 53 can include a display screen (display panel). In some implementations, the display panel can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. In addition, the display 53 can also be a touch panel (touch screen, touch screen), which can include a display screen and a touch-sensitive surface. When the touch-sensitive surface detects a touch operation on or near it, it is transmitted to the processor 52 to determine the type of touch event, and then the processor 52 provides corresponding visual output on the display device according to the type of touch event.
[0123] In several embodiments provided in the present application, it should be understood that the disclosed system, device or method can be implemented in other manners. For example, the division of the above-described device embodiment is only a logical function division, and there can be another division manner for the actual implementation, for example, multiple devices or multiple units can be combined or integrated into another system, or some characteristics can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different parts can be indirect couplings or communication connections through some interfaces, devices or units, and can be electric, mechanical or in other forms.
[0124] The modules / units described as separated parts can or can not be physically separated, and the parts displayed as modules / units can or can not be physical modules, i.e., can be located in one place, or can be distributed on multiple network units. Some or all of the modules / units can be selected according to actual needs to achieve the purpose of the embodiments of the present application. For example, the functional modules / units in the embodiments of the present application can be integrated in one processing module, or can be physically separated, or two or more modules / units can be integrated in one module / unit.
[0125] Those of ordinary skill in the art should further appreciate that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the above description. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0126] The embodiments of the present application further provide a computer readable storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the method described in any of the above embodiments. Those skilled in the art can understand that all or part of the steps of the method for implementing the above embodiments can be instructed by a program to complete the processor, and the program can be stored in a computer readable storage medium, and the storage medium is a non-transitory medium, such as a random access memory, a read-only memory, a flash memory, a hard disk, a solid state disk, a magnetic tape, a floppy disk, an optical disc and any combination thereof. The storage medium can be any available medium that can be accessed by a computer or a data storage device such as a cloud server, a data center and the like, which includes one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a digital video disc (DVD)), or a semiconductor medium (for example, a solid state disk (SSD)) and the like.
[0127] In summary, the security protection method and device of the smart home gateway, the electronic device and the medium provided by the present application effectively prevent security risks such as illegal access, data leakage, privacy abuse, malicious firmware injection and protocol layer attack by adopting multi-protocol and multi-level security mechanisms and privacy protection strategies, significantly improve the overall security, stability and attack resistance of the smart home system, and meet the requirements of domestic security compliance.
[0128] The description of the flow or structure corresponding to each of the above figures has its own emphasis, and the parts not described in detail in a certain flow or structure can be referred to the related description of other flows or structures.
[0129] The above embodiments are only illustrative of the principles and effects of the present application, and are not used to limit the present application. Any person skilled in the art can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes completed by those skilled in the art without departing from the spirit and technical thought of the present application should be covered by the claims of the present application.
Claims
1. A security protection method of a smart home gateway, characterized in that, The smart home gateway comprises a Zigbee communication module, a master control module and an Ethernet communication module; the Zigbee communication module is in communication connection with a smart home terminal based on a Zigbee protocol; the master control module is in serial communication connection with the Zigbee communication module and the Ethernet communication module respectively; The Ethernet communication module is in communication connection with a remote control platform based on an HTTPS protocol and an MQTT protocol; the method comprises: Performing access security protection on the smart home terminal and the remote control platform through identity authentication; Performing data security protection on communication data between the smart home terminal, the smart home gateway and the remote control platform based on an encryption algorithm; Performing privacy security protection on user sensitive data generated by the smart home gateway through data interaction based on a local priority processing strategy; Performing security protection on a firmware remote upgrade process based on a security channel constructed based on the HTTPS protocol, in combination with a digital signature and an integrity check mechanism; Performing security protection on communication traffic generated by the smart home gateway based on the Zigbee protocol, the HTTPS protocol and the MQTT protocol based on a network traffic anomaly detection algorithm.
2. The method of claim 1, wherein, Performing access security protection on the smart home terminal and the remote control platform through identity authentication comprises: Identifying and rejecting an access request of an illegal terminal through a preset device white list and a dynamic key negotiation mechanism, so as to complete identity legality verification of the smart home terminal; In response to an access request of the remote control platform, performing identity authentication on the remote control platform based on a digital certificate or an identity token, and authorizing a request party passing the identity authentication to access corresponding gateway resources.
3. The method of claim 2, wherein, The remote control platform comprises a client and a cloud server, and the client and the cloud server are in communication connection; Authorizing a request party passing the identity authentication to access corresponding gateway resources comprises: After the client or the cloud server passes the identity authentication, generating an identity token with time effectiveness, uniqueness and permission binding characteristics; Signing the identity token based on an encryption algorithm to obtain a signed identity token; Performing validity verification on the signed identity token; When the signed identity token passes the validity verification, authorizing the client or the cloud server to access corresponding gateway resources.
4. The method of claim 1, wherein, The smart home gateway further comprises a security module in communication connection with the master control module; performing data security protection on communication data between the smart home terminal, the smart home gateway and the remote control platform based on an encryption algorithm comprises: Encrypting data transmitted between the smart home terminal and the Zigbee communication module based on an advanced encryption standard algorithm; The data transmitted between the Zigbee communication module and the master module, and between the master module and the Ethernet communication module are encrypted based on a symmetric encryption algorithm, wherein the key used by the symmetric encryption algorithm is generated and managed by the security module based on a security key negotiation mechanism when the Zigbee communication module and the master module are paired for the first time; The data transmitted between the Ethernet communication module and the remote control platform is encrypted based on a TLS / SSL encryption algorithm.
5. The method of claim 4, wherein, The smart home gateway further comprises a storage module in communication connection with the master module and the security module; The user sensitive data generated by the smart home gateway through data interaction are protected based on a local priority processing strategy, including: The user sensitive data are desensitized and minimized locally in priority, and the processed sensitive data are written into the storage module; When specific business requirements are met, the user sensitive data are uploaded to a cloud server through a secure channel based on an HTTPS protocol or an MQTT protocol; the specific business requirements include remote device state monitoring, cross-region device linkage control, fault diagnosis and log analysis, firmware upgrade service, user authorized data synchronization, abnormal behavior detection, and system performance optimization; The collection, storage, and sharing range of the user sensitive data are dynamically configured based on the privacy policy set by the user on the client; Before the processed sensitive data are written into the storage module, and when the user sensitive data are uploaded, the sensitive data are encrypted using a national standard encryption algorithm or an international standard encryption algorithm, wherein the key used for encryption is generated and managed by the security module.
6. The method of claim 1, wherein, The communication traffic generated by the smart home gateway based on Zigbee protocol, HTTPS protocol, and MQTT protocol is protected based on a network traffic anomaly detection algorithm, including: The communication traffic generated by the smart home gateway based on Zigbee protocol, HTTPS protocol, and MQTT protocol is monitored in real time; The monitored communication traffic is processed based on a network traffic anomaly detection algorithm to identify security threats existing when the smart home gateway communicates with the smart home terminal and the remote control platform respectively; the security threats include illegal access, data leakage, and protocol attack; Based on the security threats, corresponding security protection measures are triggered; the security protection measures include log recording, security alarm, communication blocking, and device isolation.
7. The method of claim 3, wherein, Further comprising: The cloud server is managed based on a user management security mechanism; the user management security mechanism includes multi-factor identity authentication, role-based permission hierarchical control, sensitive operation audit and alarm, session security management, data encryption and privacy protection, and security policy customization.
8. A security protection device of a smart home gateway, characterized in that, The smart home gateway comprises a Zigbee communication module, a master control module and an Ethernet communication module; the Zigbee communication module is in communication connection with a smart home terminal based on a Zigbee protocol; the master control module is in serial communication connection with the Zigbee communication module and the Ethernet communication module respectively; The Ethernet communication module is in communication connection with a remote control platform based on an HTTPS protocol and an MQTT protocol; the device comprises: An access protection module for performing access security protection on the smart home terminal and the remote control platform through identity authentication; A communication protection module for performing data security protection on communication data between the smart home terminal, the smart home gateway and the remote control platform based on an encryption algorithm; A privacy protection module for performing privacy security protection on user sensitive data generated by the smart home gateway through data interaction based on a local priority processing strategy; An update protection module for performing security protection on a firmware remote upgrade process based on a security channel constructed by the HTTPS protocol, in combination with a digital signature and an integrity checking mechanism; A traffic protection module for performing security protection on communication traffic generated by the smart home gateway based on Zigbee protocol, HTTPS protocol and MQTT protocol based on a network traffic anomaly detection algorithm.
9. An electronic device, comprising: Comprise: A memory for storing a computer program; A processor for executing the computer program stored by the memory to enable the electronic device to execute the method in any one of claims 1 to 7.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method in any one of claims 1 to 7.
Citation Information
Patent Citations
Intelligent home system
CN102546330A
Intelligent home system for protecting privacy and information safety of user
CN104426726A
Internet of Things smart home security gateway system
CN104580233A
Security communication module, security communication system and method and readable storage medium
CN111683367A
Multi-system fusion gateway and implementation method thereof
CN115277310A