Industrial internet covert communication system based on OPC UA protocol and encoding and decoding method

By transmitting classified data through redundant fields of the OPC UA protocol, the problems of easy detection and noise interference in existing covert communication technologies are solved, thus realizing secure transmission and improved resistance to detection of classified data in the Industrial Internet.

CN120956474APending Publication Date: 2025-11-14CHANGZHOU INST OF MECHATRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511122826.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing industrial internet covert communication technologies are insufficient in terms of security and effectiveness when transmitting classified data. Storage-based methods are easily detected, while time-based methods are susceptible to network noise interference.

Method used

The OPC UA protocol is used as a covert communication carrier. Confidential data is transmitted through the redundant fields of the Secure Conversation message. Data filtering, segmentation, encoding and decoding modules are used to embed the confidential data into the secure footer field of the OPC UA protocol. At the receiving end, authentication and data combination are performed to ensure the security and anti-detection of data transmission.

Benefits of technology

Without altering the normal communication mode of the protocol, it significantly improves the security and anti-detection capabilities of covert communication in the Industrial Internet, ensuring the secure transmission of classified data to the cloud via open wireless links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956474A_ABST
    Figure CN120956474A_ABST
Patent Text Reader

Abstract

The invention provides an industrial internet covert communication system based on an OPC UA protocol and a coding and decoding method, and relates to the technical field of network information security. The system comprises a covert communication sender located in an industrial gateway and a covert communication receiving end located in a cloud platform, the sender serves as a message publisher of an OPC UA server, and the receiving end serves as a message subscriber of an OPC UA client. During coding, after a sender blocks secret-related industrial data, the secret-related industrial data is embedded into a'secure foot 'field of a Secure Conversion message, and the secret-related industrial data is packaged and sent in combination with identity information and a block serial number; and during decoding, a receiving end screens a message containing security, extracts blocks after identity authentication, and combines the blocks into complete data. According to the method, on the basis of OPC UA protocol characteristics, hidden transmission of secret-related data is achieved on the premise that a normal communication mode and default attributes of fields are not changed, and detection resistance and safety are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network information security technology, specifically to an industrial internet covert communication system and encoding / decoding method based on the OPC UA protocol. Background Technology

[0002] The Industrial Internet is a ubiquitous network connecting people, data, and machines, enabling the collection, transmission, and application of industrial data. This optimizes production processes and management decisions, improving the efficiency of manufacturing resource allocation and management services. Applications such as product traceability and predictive maintenance of industrial equipment often involve critical and confidential industrial data, including core parameters throughout the production process and equipment operating status. However, this data, as vital trade secrets for manufacturing enterprises, is vulnerable to eavesdropping and theft by competitors during transmission from industrial gateways to cloud platforms via open wireless networks. Information leakage can cause significant economic losses, impact core market competitiveness, and even threaten a company's survival and development. Therefore, covert communication technologies can be employed to ensure the secure transmission of industrial data.

[0003] Covert network communication is a type of covert communication technology that uses legitimate network data streams as carriers to hide information, employing various methods to modulate secret information within them. It can be mainly divided into two categories: stored-mode and time-based. Stored-mode primarily utilizes the redundancy of network protocols to embed secret information into the protocol header or payload. This method is simple and easy to implement, but it is often easily detected due to altering the original default values ​​or patterns of the protocol, lacking security. Time-based methods modulate secret information into the temporal behavior of the network data stream; however, existing methods are prone to generating abnormal temporal characteristics or are susceptible to interference from network noise such as latency and packet loss, affecting the effectiveness of covert communication.

[0004] Therefore, in industrial internet application scenarios, improving the security and effectiveness of covert communication and finding a suitable covert communication carrier have become urgent problems that need to be solved. Among existing network covert communication technologies, storage-based methods utilize protocol redundancy to embed secret information, which are easily detected by changing protocol defaults; time-based methods modulate information into the temporal behavior of data streams, which are susceptible to network noise interference. The OPC UA (OPC Unified Architecture) protocol, as a core communication protocol of the industrial internet, has advantages such as platform independence, security, and standardized data modeling, making it an ideal covert communication carrier. Therefore, a covert communication solution based on the OPC UA protocol is urgently needed to improve the security and effectiveness of industrial confidential data transmission. Summary of the Invention

[0005] The purpose of this invention is to overcome at least one technical problem existing in the prior art and to provide an industrial internet covert communication system and encoding / decoding method based on the OPC UA protocol.

[0006] On one hand, this invention provides an industrial internet covert communication system based on the OPC UA protocol. The communication system includes a covert communication transmitter and a covert communication receiver. The covert communication transmitter integrates a data filtering module, a data processing module, an encoder, and an OPC UA message transmission module. The data filtering module is used to filter out classified industrial data S and non-classified industrial data N from all data collected from the production site. The data processing module is used to divide the classified industrial data S into blocks to obtain classified data blocks S0. i The encoder is used to divide the classified data into blocks S according to an agreed-upon covert communication format. i The secure foot field of the Secure Conversation message in the OPC UA protocol is modulated and encapsulated into a confidential Secure Conversation message P_s for the covert communication monitoring node. i [node^i], where node^i (i = 1, 2, ..., m) is the name of the covert communication monitoring node; the data filtering module is also used to directly encapsulate the non-classified industrial data N into a normal SecureConversation message P_n of a normal communication monitoring node in the OPCUA protocol. j [nodej], where nodej (j = 1, 2, ..., k) is the name of the normal communication monitoring node; the OPC UA message transmission module is used to transmit message P_s i [node^i] and message P_n j [nodej] is pushed to the covert communication receiver that has subscribed to the corresponding monitoring node; the covert communication receiver integrates an OPC UA message receiving module, a decoder, and a data combination module; the OPC UA message receiving module is used to filter out the Secure Conversation message (P_s) containing encryption based on the covert communication monitoring node. i [node^i])′;The decoder is used to process the encrypted SecureConversation message (P_s) i [node^i])' is parsed and the classified industrial data blocks (S) are obtained. i The data combination module is used to divide the classified industrial data into blocks (S). i By combining the data, we obtain complete classified industrial data S′={(s) i )′|i=1,2,…,m}.

[0007] Furthermore, the covert communication sender is deployed on an industrial gateway, and the covert communication receiver is deployed on an industrial cloud platform. The covert communication sender and the covert communication receiver share the normal communication monitoring node name [nodej] and the covert communication monitoring node name [node^i] through a clear channel. The covert communication receiver registers monitoring items in its subscription and adds the normal communication monitoring node and the covert communication monitoring node.

[0008] Furthermore, the data filtering module integrates a filter that filters all data collected on-site through keyword matching, filtering out classified industrial data S and unclassified industrial data N.

[0009] Furthermore, the data processing module is used to perform binary block processing on the classified industrial data S, including: converting the classified industrial data S into a binary stream; and splitting it into classified data blocks S in 8-bit units. i Each block of classified data is an 8-bit binary number, represented as:

[0010]

[0011] Furthermore, the encoder is used to: construct a covert communication field using the security foot of the Secure Conversation message, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i Write the name of the covert communication monitoring node into the node name part of the Secure Conversation message payload; write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB; divide the classified data into blocks S. i Write the low byte LB to obtain the secure Conversation message P_s. i [node^i].

[0012] Furthermore, the OPC UA message transmission module is used to transmit the encapsulated, encrypted Secure Conversation message P_s through the publishing interface of the OPC UA server. i [node^i] and normal Secure Conversation message P_n j [nodej] pushes the data to the covert communication receiver until all classified data blocks S are reached. i Send all.

[0013] Furthermore, the OPC UA message receiving module is used to continuously receive message data containing normal messages and classified messages sent by the OPC UA message transmission module through the OPC UA subscription mechanism; it iterates through the message data, parses the node name in the payload field, and filters out messages named "covert communication monitoring node" as classified SecureConversation messages (P_s). i [node^i])′, ignores the messages corresponding to the normal communication monitoring nodes.

[0014] Furthermore, the decoder is used to: parse the high byte HB of the secure footer field of the Secure Conversation message containing confidential information, and perform authentication based on the high four bits; in response to successful authentication, parse the low four bits of the high byte HB to obtain the block sequence number Index = i; parse the low byte LB of the secure footer field of the Secure Conversation message containing confidential information to obtain the confidential data block (S i )′; until all classified data blocks (S i Decoding complete, output classified data block (S) i )′.

[0015] Furthermore, the data combination module is used to combine data blocks to obtain complete industrial classified data S′={(s i )′|i=1,2,…,m}.

[0016] Secondly, embodiments of the present invention provide an industrial internet covert communication encoding and decoding method based on the OPC UA protocol. The method is applied to the aforementioned industrial internet covert communication system based on the OPC UA protocol. The industrial internet covert communication encoding method based on the OPC UA protocol includes:

[0017] Step S1: Set keywords containing core process parameters and equipment status information in the filter, and filter out classified industrial data S and non-classified industrial data N based on the keywords; Step S2: For non-classified data N = {n j |j=1,2,…,k}, are directly encapsulated into a normal Secure Conversation message P_n according to the Secure Conversation message format. j [nodej] and send; Step S3: Divide the industrial classified data S into blocks to obtain classified data blocks S i denoted as S = {s} i|i=1,2,…,m};Step S4: Construct a covert communication field using the security footer of the Secure Conversation message, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i Step S5: Write the name of the covert communication monitoring node into the node name part of the Secure Conversation message payload field; Step S6: Write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB; Step S7: Divide the classified data into blocks S i Write the low byte LB to obtain the secure Conversation message P_s. i [node^i]; Step S8: Send the message P_s i [node^i] and message P_n j [nodej] pushes to the covert communication receiver that has subscribed to the corresponding monitoring node; Step S9: Repeat steps S5 to S8 until all industrial classified data blocks S i Transmission complete;

[0018] The industrial internet covert communication decoding method based on the OPC UA protocol includes:

[0019] Step S10: The covert communication receiver registers monitoring items within the subscription, adding the normal communication monitoring node nodej and the covert communication monitoring node node^i; Step S11: Receives the message P_s pushed by the covert communication sender. i [node^i] and message P_n j [nodej]; Step S12: Based on the name of the covert communication monitoring node, node^i, filter for secret SecureConversation messages (P_s). i [node^i])′; Step S13: Parse the high byte HB of the Secure Conversation message's security footer field and perform authentication based on the high four bits; Step S14: In response to successful authentication, parse the low four bits of the high byte HB to obtain the block sequence number Index = i; Step S15: Parse the low byte LB of the Secure Conversation message's security footer field to obtain the confidential data block (s i Step S16: Repeat steps S12 to S15 until all classified data blocks are decoded; Step S17: Combine the parsed classified data blocks to obtain the complete industrial classified data S′={(s i )′|i=1,2,…,m}.

[0020] In another aspect, the present invention also provides a computer-readable storage medium storing one or more instructions, the computer instructions being used to cause the computer to execute the above-described industrial internet covert communication encoding and decoding method based on the OPCUA protocol.

[0021] In another aspect, the present invention provides an electronic device, comprising: a memory and a processor; the memory stores at least one program instruction; the processor loads and executes the at least one program instruction to implement the above-mentioned industrial internet covert communication encoding and decoding method based on the OPC UA protocol.

[0022] Compared with existing related technologies, this invention has the following advantages: Using the OPC UA protocol as a carrier, and leveraging its secure communication mechanism and standardized data modeling characteristics, this invention transmits confidential data through redundant fields in the "security footer" of the Secure Conversation message without altering the protocol's normal communication mode and default field attributes. This ensures the normal transmission of industrial data to the cloud while effectively resisting steganography detection because the original characteristics of the protocol remain unchanged, significantly improving the security and anti-detection capabilities of covert communication in the Industrial Internet. Attached Figure Description

[0023] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0024] Figure 1 This is a schematic diagram of an industrial internet covert communication system based on the OPC UA protocol provided in Embodiment 1 of the present invention.

[0025] Figure 2 This is a schematic diagram of a covert communication monitoring node based on the OPC UA protocol provided in Embodiment 1 of the present invention.

[0026] Figure 3 This is a schematic diagram of a covert communication process based on Secure Conversation messages provided in Embodiment 1 of the present invention.

[0027] Figure 4 This is a schematic diagram of a covert communication field format based on Secure Conversation messages provided in Embodiment 1 of the present invention.

[0028] Figure 5 This is a flowchart of an industrial internet covert communication coding method based on the OPC UA protocol provided in Embodiment 2 of the present invention.

[0029] Figure 6 This is a flowchart of an industrial internet covert communication decoding method based on the OPC UA protocol provided in Embodiment 2 of the present invention.

[0030] Figure 7 This is a partial block diagram of the electronic device provided in Embodiment 4 of the present invention. Detailed Implementation

[0031] Before discussing the exemplary embodiments in more detail, it should be noted that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations as sequential processes, many of these operations can be performed in parallel, concurrently, or simultaneously. Furthermore, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but may also have additional steps not included in the figures. The process can correspond to a method, function, procedure, subroutine, subroutine, etc.

[0032] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0033] The present invention will now be described in detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0034] Example 1

[0035] For ease of understanding, the inventive concept is described in its entirety before detailing the embodiments of the present invention: This invention uses the OPC UA protocol as a covert communication carrier in the Industrial Internet. Based on in-depth analysis of its system structure, communication mode, and message format, an industrial internet covert communication system and encoding / decoding method based on the OPC UA protocol are designed. Utilizing the subscription / publish mode of the OPC UA protocol, a covert communication method is designed: the publisher constructs a covert communication data format in the redundant optional fields of the Secure Conversation message; under the agreed monitoring node, classified industrial data is embedded in blocks within the "security footer" field; the subscriber parses and combines the data according to the covert communication data format to obtain the complete classified data. Since this invention does not change the normal subscription / publish mode of OPC UA and the default attributes of the protocol fields, it does not affect the transmission of industrial data to the cloud, and therefore can effectively resist detection by various steganography analysis methods. Therefore, this invention aims to provide a covert communication technology for the Industrial Internet with strong anti-detection capabilities to improve the security of transmitting classified industrial data to the cloud via open wireless links.

[0036] The specific implementation method is as follows:

[0037] like Figure 1 The diagram shown is a schematic of an industrial internet covert communication system based on the OPC UA protocol provided by the present invention.

[0038] As an example, the communication system includes: a covert communication transmitter 1 and a covert communication receiver 2; the covert communication transmitter 1 integrates a data filtering module 10, a data processing module 11, an encoder 12, and an OPC UA message transmission module 13; the data filtering module 10 is used to filter out classified industrial data S and unclassified industrial data N from all data collected from the production site; the data processing module 11 is used to divide the classified industrial data S into blocks to obtain classified data blocks S. i The encoder 12 is used to divide the classified data into blocks S according to an agreed-upon covert communication format. i The secure foot field of the Secure Conversation message in the OPC UA protocol is modulated and encapsulated into a confidential Secure Conversation message P_s for the covert communication monitoring node. i [node^i], where node^i (i = 1, 2, ..., m) is the name of the covert communication monitoring node; the data filtering module 10 is also used to directly encapsulate the non-classified industrial data N into a normal Secure Conversation message P_n of a normal communication monitoring node in the OPC UA protocol. j [nodej], where nodej (j = 1, 2, ..., k) is the name of the normal communication monitoring node; the OPC UA message transmission module 13 is used to transmit message P_s i [node^i] and message P_n j [nodej] is pushed to the covert communication receiver 2 that has subscribed to the corresponding monitoring node; the covert communication receiver 2 integrates an OPC UA message receiving module 20, a decoder 21, and a data combination module 22; the OPC UA message receiving module 20 is used to filter out the Secure Conversation message (P_s) containing encryption according to the covert communication monitoring node. i [node^i])′;The decoder 21 is used to process the encrypted Secure Conversation message (P_s i [node^i])′ is parsed and the classified industrial data block (S) is obtained. i The data combination module 22 is used to divide the classified industrial data into blocks (S). iBy combining the data, we obtain complete classified industrial data S′={(s) i )′|i=1,2,…,m}.

[0039] In some feasible implementations, system deployment and preliminary preparations during practical application include: Deployment of roles and locations of communicating parties: The covert communication sender is deployed in the industrial gateway as a message publisher for the OPC UA server. The industrial gateway is an intermediate node connecting industrial field devices and the cloud platform. The sender can be implemented through a software module embedded in the gateway (such as an OPC UA server SDK based on C++ / Python), responsible for collecting device data and performing encoding operations. The covert communication receiver is deployed on a private / public cloud platform as a message subscriber for the OPC UA client. It is implemented through an OPC UA client module on the cloud server (such as an OPC UA client SDK based on Node-RED or Java), responsible for subscribing to and receiving messages and performing decoding operations. Sharing monitoring node information: Both parties share two types of node names through a clear channel (such as a pre-configured encrypted channel or offline synchronization): Normal communication monitoring node nodej (j = 1, 2, ..., k): used to transmit non-confidential data, and the name can be set to a publicly available device routine parameter node (such as "Temperature Sensor 1" or "Motor Speed"). Covert communication monitoring node node^i (i = 1, 2, ..., m): Used for transmitting classified data. Its name can be set to an inconspicuous, redundant node (e.g., "Device Log Backup" or "Reserved Parameter Item"), known only to the communicating parties. See attached... Figure 2 As shown, the covert communication recipient registers monitored items within the subscription and adds all of the above monitoring nodes.

[0040] In some feasible implementations, as shown in the appendix Figure 3 As shown, for non-classified data N = {n j |j=1,2,…,k}, are directly encapsulated into a normal Secure Conversation message P_n according to the Secure Conversation message format. j [nodej] and send, where node j (j = 1, 2, ..., k) is the name of the normal communication monitoring node.

[0041] In some feasible implementations, the data filtering module 10 integrates a filter that filters all data collected on-site through keyword matching, separating classified industrial data (S) from non-classified industrial data (N). For example, a preset keyword library includes classified identifiers such as "core process parameters," "equipment operating status," and "production formula number." Data classification: When raw data collected by the industrial gateway (such as PLC register data and sensor data streams) flows through the filtering module, data containing keywords is marked as classified industrial data (S), and the rest are marked as non-classified industrial data (N).

[0042] In some feasible implementations, the data processing module 11 is used to perform binary block processing on the classified industrial data S, including: converting the classified industrial data S into a binary stream; and splitting it into classified data blocks S in 8-bit units. i Each block of classified data is an 8-bit binary number, represented as:

[0043]

[0044] Specifically, first convert S (such as text or numerical values) into a binary stream (e.g., convert "core pressure = 1.2 MPa" into its ASCII binary equivalent). Then, split it into 8-bit (1-byte) units to obtain blocks of S. i (i = 1, 2, ..., m), each block is an 8-bit binary number (e.g., S1 = 10110011), ensuring that the block size matches the capacity of the low byte of the subsequent "safety foot".

[0045] In some feasible implementations, the encoder 12 is used to: construct a covert communication field using the security foot of the Secure Conversation message, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i Write the name of the covert communication monitoring node into the node name part of the SecureConversation message payload field; write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB; divide the classified data into blocks S. i Write the low byte LB to obtain the secure Conversation message P_s. i [node^i].

[0046] Preferred, combined Figure 4As shown, the construction of the "security foot" field structure includes: utilizing the redundancy feature of the "security foot" in Secure Conversation messages (the protocol does not specify the specific content and length), the field format is divided as follows: High byte (HB): 8 bits in total. The first 4 bits are allocated to the identity information ID (used to verify the sender's legitimacy), and the last 4 bits are allocated to the block sequence number Index (identifying the position of the current block in the complete data, ranging from 0 to 15, supporting a maximum of 16 blocks; if there are more than 16 blocks, it can be expanded through multiple rounds of transmission). Low byte (LB): 8 bits in total, directly corresponding to the classified data block S. i (8-bit binary) is used to store actual classified information.

[0047] Preferred, combined Figure 4 As shown, encapsulating a classified message includes: Writing the covert node name: In the "Node Name" section of the "Payload" field of the SecureConversation message, fill in the preset covert communication node node^i (e.g., "Device Reserved Parameter_i"), which is used by the receiver to identify the classified message. Writing the identity and block sequence number: Write the sender's identity identifier (id, such as the pre-agreed 4-bit binary code "0011") into the first 4 bits of the high byte, and write the block sequence number i (e.g., the 3rd block corresponds to "0011") into the last 4 bits of the high byte. Writing the classified data block: Write the classified data block S... i (8-bit binary) is directly filled into the low byte (LB).

[0048] In some feasible implementations, combined with Figure 3 As shown, the OPC UA message transmission module 13 is used to transmit the encapsulated, encrypted Secure Conversation message P_s through the publishing interface of the OPC UA server. i [node^i] and normal Secure Conversation message P_n j [nodej] pushes the data to the covert communication receiver until all classified data blocks S are reached. i Send all.

[0049] In some feasible implementations, the OPC UA message receiving module 20 is used to continuously receive message data containing normal messages and classified messages sent by the OPC UA message transmission module 13 through the OPC UA subscription mechanism; traverse the message data, parse the node name in the payload field, and filter out messages named "covert communication monitoring node" as classified Secure Conversation messages (P_s). i [node^i])′, ignores the messages corresponding to the normal communication monitoring nodes.

[0050] Preferably, the receiving end calls the "Subscribe to Monitoring Items" interface through the OPC UA client SDK to add all normal communication nodes (nodej) and covert communication nodes (node^i) to the subscription list, ensuring that it can receive all Secure Conversation messages from both types of nodes. The client continuously receives messages pushed by the server (including normal messages and encrypted messages) through the OPC UA subscription mechanism and temporarily stores them in a local cache (such as a memory queue). It iterates through the received messages, parses the "Node Name" in the "Payload" field, and filters out messages named node^i (i.e., encrypted messages (P_s)). i [node^i])′), ignores the message corresponding to the normal node nodej.

[0051] In some feasible implementations, the decoder 21 is used to: parse the high byte HB of the secure footer field of the Secure Conversation message, and perform authentication based on the high four bits; in response to successful authentication, parse the low four bits of the high byte HB to obtain the block sequence number Index = i; parse the low byte LB of the secure footer field of the Secure Conversation message to obtain the classified data block (S i )'; until all classified data blocks (S i Decoding complete, output classified data block (S) i )'.

[0052] Preferably, the high byte HB of the "Security Footer" field of the encrypted message is parsed to extract the first 4 bits of the ID, which is then compared with a pre-set valid ID (e.g., "0011") at the receiving end. If they do not match (authentication failed), the message is discarded, and the filtering continues. If they match (authentication passed), the next step is executed. The last 4 bits of the high byte HB are parsed to obtain the block sequence number Index (e.g., "0011" corresponds to sequence number 3), which is used to determine the block position during subsequent data reassembly. The low byte LB of the "Security Footer" field is parsed to directly obtain 8 bits of binary data, which is used as the current block (S). i )'(with the sender's S i correspond).

[0053] In some feasible implementations, the data combination module 22 is used to combine data blocks to obtain complete industrial classified data S' = {(s i )'|i=1,2,…,m}.

[0054] The above implementation uses the OPC UA protocol as a carrier, leveraging its secure communication mechanism and standardized data modeling characteristics to transmit confidential data through redundant fields in the "security footer" of the Secure Conversation message without altering the protocol's normal communication mode and default field attributes. This ensures the normal transmission of industrial data to the cloud while effectively resisting steganography detection because the original characteristics of the protocol remain unchanged, significantly improving the security and anti-detection capabilities of covert communication in the Industrial Internet.

[0055] It is worth mentioning that all modules involved in this embodiment are logical units. In practical applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. Furthermore, to highlight the innovative aspects of this invention, this embodiment does not introduce units that are not closely related to solving the technical problem proposed by this invention; however, this does not mean that other units are absent from this embodiment.

[0056] Example 2

[0057] Please see Figure 5-6 This embodiment provides a flowchart of an industrial internet covert communication encoding and decoding method based on the OPC UA protocol.

[0058] As an example, such as Figure 5 As shown, the method is applied to the industrial internet covert communication system based on the OPC UA protocol described in Example 1. The industrial internet covert communication encoding method based on the OPC UA protocol includes:

[0059] Step S1: Set keywords in the filter that contain the core process parameters of the product and equipment status information, and filter out classified industrial data S and non-classified industrial data N based on the keywords.

[0060] Step S2: For non-classified data N = {n j |j=1,2,…,k}, are directly encapsulated into a normal Secure Conversation message P_n according to the Secure Conversation message format. j [nodej and send.]

[0061] Step S3: Divide the industrial classified data S into blocks to obtain classified data blocks S. i denoted as S = {s} i |i=1,2,··},m}.

[0062] Step S4: Using the secure footer of the Secure Conversation message, construct the covert communication field, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i .

[0063] Step S5: Write the name of the covert communication monitoring node into the node name part of the Secure Conversation message payload field.

[0064] Step S6: Write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB.

[0065] Step S7: Divide the classified data into blocks S i Write the low byte LB to obtain the encrypted Secure Conversation message Ps.

[0066] Step S8: Send the message P_s i [node^i] and message P_n j [nodej] pushes to the covert communication receiver that has subscribed to the corresponding monitoring node.

[0067] Step S9: Repeat steps S5 to S8 until all industrial classified data blocks S i Transmission complete.

[0068] Combination Figure 6 As shown, the industrial internet covert communication decoding method based on the OPC UA protocol includes:

[0069] Step S10: The covert communication receiver registers monitoring items within the subscription, adding the normal communication monitoring node nodej and the covert communication monitoring node node^i.

[0070] Step S11: Receive the message P_s pushed by the covert communication sender. i [node^i] and message P_n j [nodej]

[0071] Step S12: Based on the name of the covert communication monitoring node, node^i, filter for Secure Conversation messages (P_s). i [node^i])′.

[0072] Step S13: Parse the high byte HB of the Secure Conversation message's security footer field and perform authentication based on the high four bits.

[0073] Step S14: In response to successful authentication, parse the lower four bits of the high byte HB to obtain the block sequence number Index = i.

[0074] Step S15: Parse the low byte (LB) of the Secure Conversation message's security footer field to obtain the classified data block (s i )′.

[0075] Step S16: Repeat steps S12 to S15 until all classified data blocks have been decoded.

[0076] Step S17: Combine the parsed classified data into blocks to obtain complete industrial classified data S′={(s i )'|i=1,2,···,m}.

[0077] It is not difficult to see that this embodiment is a method embodiment corresponding to the first embodiment, and this embodiment can be implemented in conjunction with the first embodiment. The relevant technical details mentioned in the first embodiment are still valid in this embodiment, and will not be repeated here to reduce repetition. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the first embodiment.

[0078] Example 3

[0079] This invention also proposes a storage medium storing an industrial internet covert communication encoding and decoding method based on the OPC UA protocol. When executed by a processor, the OPC UA-based industrial internet covert communication encoding and decoding program implements the steps of the OPC UA-based industrial internet covert communication encoding and decoding method described above. Since this storage medium employs all the technical solutions of the above embodiments, it possesses at least all the beneficial effects brought about by the technical solutions of the above embodiments, which will not be elaborated upon further here.

[0080] Example 4

[0081] Please see Figure 7 The present invention also provides an electronic device, including: a memory and a processor; the memory stores at least one program instruction; the processor loads and executes the at least one program instruction to implement the industrial Internet covert communication encoding and decoding method based on the OPC UA protocol provided in Embodiment 2.

[0082] The memory 702 and processor 701 are connected via a bus, which may include any number of interconnecting buses and bridges, connecting various circuits of one or more processors 701 and memory 702 together. The bus may also connect various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface between the bus and the transceiver. The transceiver may be a single element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. Data processed by processor 701 is transmitted over a wireless medium via an antenna, which further receives data and transmits it to processor 701.

[0083] Processor 701 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory 702 can be used to store data used by processor 701 during operation.

[0084] The above descriptions are merely embodiments of the present invention. Commonly known structures and characteristics are not described in detail here. Those skilled in the art are aware of all common technical knowledge in the field prior to the application date or priority date, are aware of all existing technologies in that field, and have the ability to apply conventional experimental methods prior to that date. Those skilled in the art can, based on the guidance provided in this application, improve and implement this solution in combination with their own capabilities. Some typical known structures or methods should not be obstacles for those skilled in the art to implement this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the structure of the present invention. These should also be considered within the scope of protection of the present invention, and will not affect the effectiveness of the implementation of the present invention or the practicality of the patent. The scope of protection claimed in this application should be determined by the content of its claims, and the specific embodiments described in the specification can be used to interpret the content of the claims.

Claims

1. An industrial internet covert communication system based on the OPC UA protocol, characterized in that, The communication system includes: a covert communication transmitter and a covert communication receiver; The covert communication transmitter integrates a data filtering module, a data processing module, an encoder, and an OPC UA message transmission module. The data filtering module is used to filter out classified industrial data S and unclassified industrial data N from all data collected from the production site. The data processing module is used to divide the classified industrial data S into blocks to obtain classified data blocks S. i ; The encoder is used to divide the classified data into blocks S according to an agreed-upon covert communication format. i The secure foot field of the Secure Conversation message in the OPC UA protocol is modulated and encapsulated into a confidential Secure Conversation message P_s for the covert communication monitoring node. i [node^i], where node^i (i = 1, 2, ..., m) is the name of the covert communication monitoring node; The data filtering module is also used to directly encapsulate the non-classified industrial data N into a normal Secure Conversation message P_n of a normal communication monitoring node in the OPC UA protocol. j [nodej], where nodej (j = 1, 2, ..., k) is the name of the normal communication monitoring node; The OPC UA message transmission module is used to transmit message P_s i [node^i] and message P_n j [nodej] pushes to the covert communication receiver that has subscribed to the corresponding monitoring node; The covert communication receiver integrates an OPC UA message receiving module, a decoder, and a data combination module. The OPC UA message receiving module is used to filter out encrypted SecureConversation messages (P_s) based on the covert communication monitoring node. i [node^i])'; The decoder is used to process the encrypted Secure Conversation message (P_s). i [node^i])' is parsed and the classified industrial data blocks (S) are obtained. i )'; The data combination module is used to divide the classified industrial data into blocks (S i By combining the data, we obtain complete classified industrial data S' = {(s)} i )'|i=1,2,…,m}.

2. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The covert communication sender is deployed on an industrial gateway, and the covert communication receiver is deployed on an industrial cloud platform. The covert communication sender and the covert communication receiver share the normal communication monitoring node name [nodej] and the covert communication monitoring node name [node^i] through a clear channel. The covert communication receiver registers monitoring items in the subscription and adds the normal communication monitoring node and the covert communication monitoring node.

3. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The data filtering module integrates a filter that filters all data collected on-site by keyword matching, separating classified industrial data S from unclassified industrial data N.

4. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The data processing module is used to perform binary block processing on the classified industrial data S, including: Convert the classified industrial data S into a binary stream; The classified data is divided into blocks S by splitting it into 8-bit units. i Each block of classified data is an 8-bit binary number, represented as:

5. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The encoder is used for: Using the secure footer of the Secure Conversation message, a covert communication field is constructed, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i ; Write the name of the covert communication monitoring node into the node name part of the Secure Conversation message payload field; Write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB; Divide the classified data into blocks S i Write the low byte LB to obtain the secure Conversation message P_s. i [node^i].

6. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The OPC UA message transmission module is used to transmit the encapsulated, encrypted SecureConversation message P_s through the OPC UA server's publishing interface. i [node^i] and normal Secure Conversation message P_n j [nodej] pushes the data to the covert communication receiver until all classified data blocks S are reached. i Send all.

7. The industrial internet covert communication system based on the OPC UA protocol according to claim 1, characterized in that, The OPC UA message receiving module is used to continuously receive message data containing normal messages and classified messages sent by the OPC UA message transmission module through the OPC UA subscription mechanism; Traverse the message data, parse the node name in the payload field, and filter out messages named "covert communication monitoring node" as encrypted Secure Conversation messages (P_s). i [node^i[)', ignores the messages corresponding to the normal communication monitoring nodes.

8. The industrial internet covert communication system based on the OPC UA protocol according to claim 7, characterized in that, The decoder is used for: Parse the high byte (HB) of the security footer field in the encrypted Secure Conversation message, and perform authentication based on the high four bits. In response to successful authentication, the lower four bits of the high byte HB are parsed to obtain the block sequence number Index = i; Parse the low-byte block (LB) of the security footer field in the Secure Conversation message containing classified information to obtain the classified data block (S). i )'; Until all classified data blocks (S i Decoding complete, output classified data block (S) i )'.

9. The industrial internet covert communication system based on the OPC UA protocol according to claim 8, characterized in that, The data combination module is used to combine data blocks to obtain complete industrial classified data S'={(s i )'|i=1,2,…,m}.

10. A method for encoding and decoding covert communication in the industrial internet based on the OPC UA protocol, the method being applied to the covert communication system of the industrial internet based on the OPC UA protocol as described in any one of claims 1-9, characterized in that, The industrial internet covert communication coding method based on the OPC UA protocol includes: Step S1: Set keywords containing core process parameters of the product and equipment status information in the filter, and filter out classified industrial data S and non-classified industrial data N based on the keywords; Step S2: For non-classified data N = {n j |j=1,2,…,k}, are directly encapsulated into a normal Secure Conversation message P_n according to the Secure Conversation message format. j [nodej] and send; Step S3: Divide the industrial classified data S into blocks to obtain classified data blocks S. i denoted as S = {s} i |i=1,2,…,m}; Step S4: Using the secure footer of the Secure Conversation message, construct the covert communication field, including: dividing the high byte HB of the field into identity information ID and block sequence number Index, and the low byte LB corresponding to the classified data block S. i ; Step S5: Write the name of the covert communication monitoring node into the node name part of the Secure Conversation message payload field; Step S6: Write the identity information ID and block sequence number Index of the covert communication sender into the high byte HB; Step S7: Divide the classified data into blocks S i Write the low byte LB to obtain the secure Conversation message P_s. i [node^i]; Step S8: Send the message P_s i [node^i] and message P_n j [nodej] pushes to the covert communication receiver that has subscribed to the corresponding monitoring node; Step S9: Repeat steps S5 to S8 until all industrial classified data blocks S i Transmission complete; The industrial internet covert communication decoding method based on the OPC UA protocol includes: Step S10: The covert communication receiver registers monitoring items within the subscription, adding the normal communication monitoring node nodej and the covert communication monitoring node node^i; Step S11: Receive the message P_s pushed by the covert communication sender. i [node^i] and message P_n j [nodej]; Step S12: Based on the name of the covert communication monitoring node, node^i, filter for Secure Conversation messages (P_s). i [node^i])′; Step S13: Parse the high byte HB of the Secure Conversation message's security footer field and perform authentication based on the high four bits; Step S14: In response to successful authentication, parse the lower four bits of the high byte HB to obtain the block sequence number Index = i; Step S15: Parse the low byte (LB) of the Secure Conversation message's security footer field to obtain the classified data block (s i )′; Step S16: Repeat steps S12 to S15 until all classified data blocks have been decoded. Step S17: Combine the parsed classified data into blocks to obtain complete industrial classified data S′={(s i )′|i=1,2,…,m}.