Data security transmission method and device
By dynamically adjusting access policies based on trust assessment results and employing elliptic curve cryptography and signature processing, the problem of data leakage and permission invalidation caused by static key authentication mechanisms in smart terminal IoT is solved, thereby improving security and flexibility.
Patent Information
- Application Number
- CN202511152149.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-18
- Publication Date
- 2025-11-14
AI Technical Summary
In the Internet of Things (IoT) for smart terminals, static key-based authentication mechanisms prevent control centers from ensuring data security and the effectiveness of system access permissions during subsequent data transmission. Key leakage or cracking can lead to continuous data leakage and failure of system access permission management.
The smart terminal obtains the trust assessment results from the control center, dynamically adjusts the access policy, and transmits data through elliptic curve encryption and signature processing. At the same time, it records policy execution error events and feeds them back to the control center to optimize the trust assessment mechanism.
It enables precise control over access permissions to smart terminals, improves data transmission security, enhances system privacy protection and efficiency, and ensures system stability and flexibility.
Smart Images

Figure CN120956487A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of information security and applied cryptography, and in particular to a method and apparatus for secure data transmission. Background Technology
[0002] With the rapid development of new power systems, integrated space-ground networks, and the Internet of Things (IoT), various smart terminals (such as smart meters, edge computing points, satellite terminals, and relay gateways) are widely deployed in distributed access networks. These smart terminals need to periodically upload various key business data (such as electricity consumption, load statistics, energy quality parameters, or link status information) to the control center or relay gateway to support core applications such as load scheduling, billing and settlement, resource optimization and allocation, and anomaly early warning.
[0003] Under relevant technologies, in the Internet of Things (IoT) where smart terminals are deployed on a large scale, smart terminals generally adopt authentication mechanisms based on static keys, such as symmetric encryption algorithms or traditional public-key cryptography algorithms. Under this mechanism, smart terminals use pre-configured fixed keys for data encryption and digital signatures. The control center must independently perform decryption and signature verification for each transmitted message to ensure data integrity and the authenticity of the smart terminal's identity. Based on the verification results, the control center adopts a binary authorization mode, granting full system access to verified smart terminals, while completely prohibiting access to smart terminals that fail verification.
[0004] The above scheme relies on a static key authentication mechanism, which means that the control center can only ensure the legitimacy of the smart terminal's identity and assign fixed access permissions when the smart terminal initially accesses the network. Therefore, if an identity authentication security vulnerability occurs during subsequent data transmission, it will affect the security of all subsequent data transmissions and the effectiveness of system access permissions.
[0005] For example, if a key is leaked or cracked during subsequent data transmission, an attacker with fixed privileges can not only continuously decrypt all transmitted data, but also maintain the original system access permissions for a long time. This would lead to the dual risks of continuous data leakage and failure of system access permission management.
[0006] In view of this, there is a need to provide a new method for secure data transmission to overcome the above-mentioned shortcomings. Summary of the Invention
[0007] This application provides a method and apparatus for secure data transmission to avoid continuous data leakage and system access control failure during information transmission.
[0008] In a first aspect, embodiments of this application provide a data secure transmission method, the method comprising:
[0009] After the last data transmission with the control center, the smart terminal obtains the previous trust assessment result issued by the control center; the previous trust assessment result is obtained by the control center based on the security detection data reported by the smart terminal during the previous data transmission; the previous trust assessment result is used to describe the security and trust level of the smart terminal in the previous data transmission.
[0010] The smart terminal obtains the access policy formulated by the control center based on the previous trust assessment result; the access policy describes the access control permissions used by the smart terminal in this data transmission.
[0011] The smart terminal uses the access strategy described above to perform this data transmission with the control center.
[0012] Using the above method, the trust assessment result of the previous data transmission can be obtained based on the security detection data reported by the smart terminal during the previous data transmission. Then, based on the assessment result, the access policy for the smart terminal to conduct the current data transmission can be formulated. This allows for precise control over the access permissions of the smart terminal and improves the security of data transmission.
[0013] In an optional embodiment, the method further includes:
[0014] During the data transmission process using the access policy and control center, the security detection data for this data transmission is reported to the control center in the following manner:
[0015] During the data transmission process using the access policy and control center, the smart terminal reports the security detection data of the data transmission to the control center in the following manner:
[0016] Based on the behavior auditing requirements included in the current access policy, the smart terminal records various policy execution error events generated by the data to be transmitted during this data transmission.
[0017] The smart terminal reports the failure events of each strategy execution as security detection data to the control center.
[0018] In one optional embodiment, the policy execution failure events include at least one of the following:
[0019] Signature verification failed; the signature verification failure indicates that the signature data carried by the smart terminal in the data to be transmitted has not passed the verification of the control center;
[0020] Policy offset; the policy offset indicates that there is a deviation between the data upload permission of the smart terminal and the access policy during the current data transmission process; the data upload permission is determined based on the access control permission and is used to describe at least one of the following: the data content, transmission method and reporting frequency of the data to be transmitted;
[0021] In an optional embodiment, the method further includes:
[0022] The smart terminal receives the trust assessment result of the current data transmission, obtained from the security detection data of the current data transmission, returned by the control center;
[0023] Based on the trust assessment results of the current data transmission, the smart terminal formulates the next access strategy to be used in the next data transmission.
[0024] In one optional embodiment, the smart terminal uses the current access strategy to transmit the data to be transmitted to the control center, including:
[0025] The smart terminal encrypts the original data to obtain encrypted original data, and uses the encrypted original data as data to be transmitted.
[0026] The smart terminal performs signature processing on the data to be transmitted to obtain signature data;
[0027] The smart terminal uses the access strategy to send the data to be transmitted and the signature data to the control center. When the control center determines that the signature data has passed the signature verification, it aggregates and decrypts the data to be transmitted and other transmitted data sent by the other smart terminal to obtain the original data.
[0028] In one optional embodiment, the smart terminal encrypts the original data to obtain encrypted original data, and uses the encrypted original data as data to be transmitted, including:
[0029] The smart terminal performs elliptic curve point encoding on the raw data to obtain corresponding encoded data; each elliptic curve point represents a portion of the encoded data.
[0030] The smart terminal randomly selects an integer from the finite field of the elliptic curve points as the temporary session private key for this data transmission;
[0031] The smart terminal uses the product of the temporary session private key and the public key of the control center as a shared elliptic curve point;
[0032] The smart terminal performs elliptic curve point addition on the encoded data and the shared elliptic curve points to obtain the encrypted original data.
[0033] In one optional embodiment, the smart terminal performs signature processing on the data to be transmitted to obtain signature data, including: the smart terminal obtains a temporary session public key based on the temporary session private key and the generator; the temporary session public key is an elliptic curve point; the generator is a base point on the elliptic curve.
[0034] The smart terminal obtains its role private key based on the master private key issued by the key management center and the smart terminal's identity identifier, and generates an authentication sub-private key based on the smart terminal's role public key, the smart terminal's public key, the master private key, and the master public key;
[0035] The smart terminal obtains a signature digest based on the temporary session public key, the data to be transmitted, the smart terminal's public key, the timestamp, and the relay gateway's public key;
[0036] The smart terminal obtains its signature data based on the signature digest, its private key, and the authentication sub-private key.
[0037] In one optional embodiment, when the control center determines that the signature data has passed signature verification, the process of aggregating and decrypting the data to be transmitted and other transmitted data sent by other smart terminals to obtain the original data includes:
[0038] To enable the control center to perform the following operations:
[0039] The signature digest is reproduced based on the temporary session public key of the smart terminal, the data to be transmitted, the public key of the smart terminal, the timestamp, and the public key of the relay gateway.
[0040] Based on the reproduced signature digest, reproduced signature data is obtained. When it is determined that the reproduced signature data is the same as the signature data of the smart terminal, the temporary session public key and the encoded data of the smart terminal are added to the temporary session public key and the encoded data of other smart terminals respectively to obtain the session aggregation point and the data aggregation point.
[0041] Based on the private key of the control center, a multiplication operation is performed on the session aggregation point to generate a new elliptic curve point to offset the session aggregation point;
[0042] The difference between the data aggregation point and the new elliptic curve point is used as the merged data of the data to be transmitted from the smart terminal and other transmitted data sent by other smart terminals.
[0043] The difference is decoded to recover the original data of the smart terminal and the aggregated data of the original data of other terminals.
[0044] In one optional embodiment, the smart terminal uses the current access strategy to send the data to be transmitted and the signature data to the control center, including:
[0045] The smart terminal obtains a mask digest based on its role public key, the timestamp, the relay gateway's public key, and the temporary session public key; obtains an identity mask based on the mask digest and the identity identifier; and obtains a public key mask based on the mask digest and the smart terminal's public key.
[0046] The smart terminal generates a corresponding anonymous message based on the data to be transmitted, the signature data, the identity mask, the public key mask, and the timestamp, and sends the anonymous message to the control center through the relay gateway.
[0047] Secondly, embodiments of this application provide a data security transmission device, including:
[0048] The receiving module is configured to, after the previous data transmission with the control center, obtain the previous trust assessment result issued by the control center, wherein the previous trust assessment result is obtained by the control center based on the secure transmission data reported during the previous data transmission; the previous trust assessment result is used to describe the security and trust level in the previous data transmission; and obtain the current access policy formulated by the control center based on the previous trust assessment result; the current access policy is used to describe the access control permissions used in the current data transmission.
[0049] The processing module is used to perform this data transmission with the control center using the current access strategy.
[0050] In this embodiment, a trust assessment result is dynamically generated based on the security detection data reported by the smart terminal in the previous data transmission. This result is then used to formulate the next access strategy for the smart terminal, achieving precise control over smart terminal access permissions and effectively improving data transmission security. Simultaneously, encryption and signature processing are employed to ensure the confidentiality and integrity of the data transmission, supporting anonymous transmission and aggregated decryption, thus enhancing the system's privacy protection and efficiency.
[0051] Furthermore, by recording and reporting policy execution failures, the trust assessment mechanism was further optimized, ensuring the system's stability and reliability. This mechanism of dynamically adjusting access policies and trust assessments not only improves data transmission security but also enhances the system's flexibility and adaptability, enabling it to better cope with complex and ever-changing network environments and potential security threats. Attached Figure Description
[0052] Figure 1 A flowchart illustrating a secure data transmission method provided in this application embodiment;
[0053] Figure 2 A schematic diagram of a system architecture provided in an embodiment of this application;
[0054] Figure 3 This is a schematic diagram illustrating the data transmission process in an embodiment of this application.
[0055] Figure 4 This is a schematic flowchart of a data encryption method provided in an embodiment of this application;
[0056] Figure 5 This is a schematic flowchart illustrating a data aggregation and decryption method provided in an embodiment of this application;
[0057] Figure 6 A schematic diagram illustrating a security detection data reporting process provided in an embodiment of this application;
[0058] Figure 7 This is a schematic diagram illustrating a process for anonymizing data, provided as an embodiment of this application.
[0059] Figure 8 This is a schematic flowchart of a method for constructing mask information provided in an embodiment of this application;
[0060] Figure 9 This is a schematic flowchart of a method for identity registration and key configuration provided in an embodiment of this application;
[0061] Figure 10 This is a schematic diagram of a data security transmission device provided in an embodiment of this application. Detailed Implementation
[0062] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.
[0063] With the rapid development of new power systems, integrated space-ground networks, and the Internet of Things (IoT) for smart terminals, various smart terminals (such as smart meters, edge computing points, satellite terminals, and relay gateways) are widely deployed in distributed access networks. These smart terminals need to periodically upload various key business data (such as electricity consumption, load statistics, energy quality parameters, or link status information) to the control center or relay gateway to support core applications such as load scheduling, billing and settlement, resource optimization and allocation, and anomaly early warning.
[0064] Under relevant technologies, in the Internet of Things (IoT) where smart terminals are deployed on a large scale, smart terminals generally adopt authentication mechanisms based on static keys, such as symmetric encryption algorithms or traditional public-key cryptography algorithms. Under this mechanism, smart terminals use pre-configured fixed keys for data encryption and digital signatures. The control center must independently perform decryption and signature verification for each transmitted message to ensure data integrity and the authenticity of the smart terminal's identity. Based on the verification results, the control center adopts a binary authorization mode, granting full system access to verified smart terminals, while completely prohibiting access to smart terminals that fail verification.
[0065] The above scheme relies on a static key authentication mechanism, which means that the control center can only ensure the legitimacy of the smart terminal's identity and assign fixed access permissions when the smart terminal initially accesses the network. Therefore, if an identity authentication security vulnerability occurs during subsequent data transmission, it will affect the security of all subsequent data transmissions and the effectiveness of system access permissions.
[0066] For example, if a key is leaked or cracked during subsequent data transmission, an attacker with fixed privileges can not only continuously decrypt all transmitted data, but also maintain the original system access permissions for a long time. This would lead to the dual risks of continuous data leakage and failure of system access permission management.
[0067] To address the aforementioned technical problems, this application provides a method for secure data transmission. In this embodiment, after the previous data transmission with the control center, the smart terminal obtains the previous trust assessment result issued by the control center. The smart terminal then obtains the current access policy formulated by the control center based on the previous trust assessment result, and uses this access policy to conduct the current data transmission with the control center. This method allows for dynamic adjustment of the smart terminal's access control permissions based on the trust assessment result of the previous data transmission, avoiding the risks of continuous data leakage and system access permission management failure during data transmission.
[0068] The following is a brief introduction to the system architecture diagram applicable to the technical solutions of the embodiments of this application. It should be noted that the system architecture diagram described below is only used to illustrate the embodiments of this application and is not intended to limit the scope of the application.
[0069] For example, see Figure 2 As shown, it is a system architecture diagram applicable to the embodiments of this application. The system architecture includes at least a smart terminal 20, a relay gateway 21, and a control center 22.
[0070] The smart terminal 20 is used to collect raw data, encrypt the raw data to generate data to be transmitted, sign the data to be transmitted to obtain signed data, and upload the data to be transmitted and the signed data to the relay gateway 21.
[0071] The relay gateway 21 is used to verify the signature data uploaded by the smart terminal. After successful verification, it forwards the data to be transmitted to the control center.
[0072] Control center 22 is used to verify the signature of the data to be transmitted by the smart terminal forwarded by relay gateway S202, and then decrypt the verified data to be transmitted.
[0073] In addition, based on the security detection data recorded during the current data transmission of the smart terminal 20, the control center 22 calculates the trust assessment result of the current data transmission of the smart terminal 21, formulates the next access policy, and sends the trust assessment result and the next access policy to the smart terminal 20. The smart terminal 20 then uses the next access policy to perform the next data transmission.
[0074] The technical solution of this application will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0075] For example, see Figure 1 The diagram shown is a flowchart of a data security transmission method provided in an embodiment of this application. The method includes:
[0076] S10. After the last data transmission with the control center, the smart terminal obtains the last trust assessment result issued by the control center.
[0077] Specifically, after the last data transmission with the control center, the smart terminal obtains the trust assessment result issued by the control center. The last trust assessment result is obtained by the smart center based on the security detection data reported by the smart terminal during the last data transmission. The last trust assessment result is used to describe the security and trust level of the smart terminal in the last data transmission.
[0078] For example, in the embodiments of this application, Γ is used k As an identifier for the trust assessment result. Γ in the previous data transmission k The larger the value, the higher the security and reliability of the smart terminal. When Γ... k When the value is ≥0.75, the smart terminal is considered to have high security and trustworthiness; when 0.5≤Γ kWhen ≤0.75, the smart terminal is considered to have medium security trustworthiness; when 0.2≤Γ k When the value is ≤0.5, the smart terminal is considered to have low security trustworthiness. k When the value is ≤0.2, the smart terminal is considered to have extremely low security and trustworthiness. (The last data transmission value is Γ.) k The relationship between security and trustworthiness of smart terminals is shown in Table 1:
[0079] Table 1
[0080] <![CDATA[Γ k ]]> Security and trustworthiness <![CDATA[Γ k ≥0.75]]> high <![CDATA[0.5≤Γ k ≤0.75]]> medium <![CDATA[0.2≤Γ k ≤0.5]]> Low <![CDATA[Γ k ≤0.2]]> Extremely low
[0081] Based on the trust assessment results of the previous data transmission of the smart terminal by the control center, the security and trustworthiness of the smart terminal can be assessed, and then the data upload permissions of the smart terminal for this data transmission can be restricted according to the security and trustworthiness.
[0082] S11. The smart terminal obtains the access policy formulated by the control center based on the results of the previous trust assessment.
[0083] Specifically, the smart terminal obtains the access policy formulated by the control center based on the previous trust assessment results. This access policy is used to set the access control permissions used by the smart terminal in this data transmission.
[0084] For example, in this embodiment of the application, the control center, based on the previous data transmission, Γ k Define the access policy for this data transmission by the smart terminal. This access policy determines the upload permissions of the smart terminal during this data transmission, and includes the upload permissions from the previous data transmission. k The larger the value, the greater the number of operations and access permissions that the smart terminal is allowed to perform during this data transmission. k When ≥0.75, the intelligent terminal can be granted full-function authorization during this data transmission, allowing normal access and data reporting. When 0.5≤Γ k When 0.2 ≤ Γ, the smart terminal's access is restricted during this data transmission, and the data transmission channel is limited. k When the value is ≤0.5, the smart terminal is set to read-only mode during this data transmission, blocking data reporting and only allowing query responses. When Γ k When the value is ≤0.2, the smart terminal is isolated during this data transmission and is prohibited from participating in data transmission.
[0085] Create the Γ of the last data transfer k The relationship between the security and trustworthiness of the smart terminal and the access permissions of the smart terminal for this data transmission is shown in Table 2:
[0086] Table 2
[0087]
[0088] The access policy for this data transmission by the smart terminal consists of the initial security assessment result, key lifecycle, data upload permissions, behavior auditing requirements, and service binding. The initial security assessment result is the result obtained from the previous data transmission. k The data upload permissions for this access policy are shown in Table 2, and the permissions for the last data transmission are as follows: k The corresponding smart terminal's upload permission for this data transmission. The policy dimensions and their relationship to each are shown in Table 3:
[0089] Table 3
[0090] Strategy Dimension Content Description Initial security assessment results Set an initial trust value for each type of smart terminal. Key lifecycle Set the key validity period, rotation cycle, and revocation trigger conditions. Data upload permissions Limit maximum upload frequency, data type, or path channel. Behavioral audit requirements Record the operation logs and signature behavior of the smart terminal. Service binding Security functions of specified smart terminals
[0091] Based on the trust assessment results of the previous data transmission of the smart terminal, the access policy for the current data transmission of the smart terminal can be formulated, thereby realizing dynamic control of the data upload permissions of the smart terminal.
[0092] S12. The smart terminal uses the access policy and control center to perform this data transmission.
[0093] For example, see Figure 3 As shown, when the smart terminal uses the access strategy for this data transmission, firstly, the original data is encrypted to obtain encrypted original data, and this encrypted original data is used as the data to be transmitted. Next, the smart terminal signs the data to be transmitted to obtain signed data. Finally, the smart terminal uses the access strategy to send the data to be transmitted and the signed data to the control center. When the control center determines that the signed data has passed the signature verification, it aggregates and decrypts the data to be transmitted and other transmitted data sent by other smart terminals to obtain the original data.
[0094] Based on the above S12 data transmission process, the specific steps for the intelligent terminal and control center to perform this data transmission are as follows:
[0095] S120: The smart terminal encrypts the original data to obtain the data to be transmitted.
[0096] Specifically, in this embodiment of the application, the smart terminal uses elliptic curve cryptography to process the original data, and then calculates the shared elliptic curve points based on the temporary session private key to generate encrypted original data as data to be transmitted.
[0097] For example, see Figure 4As shown, firstly, the smart terminal uses the elliptic curve point generator P and elliptic curve point encoding to process the original data m. i Encode the curve points to obtain encoded data m i ′ =m i ·P; Then, randomly select an integer from the finite field of elliptic curve points as the temporary session private key r for this data transmission. i The smart terminal will use the temporary session private key r i PK with the public key of the control center cc The product of the ... i Finally, based on the encoded data m i ′ and shared elliptic curve point T i Generate encrypted original data C i =T i +m i ′ The encrypted original data C i This refers to the data to be transmitted by the smart terminal.
[0098] S121. The smart terminal performs signature processing on the data to be transmitted.
[0099] Specifically, for the data to be transmitted, the smart terminal implements the signature of the data to be transmitted based on a dual private key structure of the authentication sub-private key and the smart terminal's private key.
[0100] For example, in this embodiment of the application, firstly, the smart terminal uses the temporary session private key r i The product of the generator P and the generator P yields the temporary session public key R. i =r i P; then, the smart terminal uses the master private key sk issued by the key management center. kgc and the identity ID of the smart terminal i Obtain the role private key sk of the smart terminal sm Based on the role's private key sk sm , smart terminal public key sk i,1 P, master private key sk kgc and the master key sk kgc P generates an authentication sub-private key sk i,2 =sk sm +H(sk i,1 P,sk kgc P)sk kgc Next, the smart terminal uses the temporary session public key R i The data to be transmitted and the public key sk of the smart terminal i,1 P, timestamp t i And the public key of the relay gateway is hashed to obtain the signature digest d.i Finally, the smart terminal uses the signature digest d i The private key sk of the smart terminal i,1 and authentication sub-private key sk i,2 Obtain the signature data a from the smart terminal i .
[0101] S122. The control center aggregates and decrypts the data that has passed signature verification.
[0102] Specifically, after the control center verifies the signature, it aggregates and decrypts data from multiple terminals, verifies signature consistency through hash operations, aggregates temporary session public keys and encoded data, uses private keys to offset session aggregation points, and finally decodes and restores the original data summary.
[0103] For example, see Figure 5 As shown in this embodiment, after the signature data passes the signature verification by the control center, the control center needs to aggregate and decrypt the data to be transmitted from the smart terminal and other transmitted data sent by other smart terminals to obtain the original data. First, the control center uses the temporary session public key R of the smart terminal... i The data to be transmitted and the public key sk of the smart terminal i,1 P, timestamp t i The public key of the relay gateway is hashed to obtain the reproducible signature digest d. j ′ Then, based on the reproduced signature digest d j ′ Obtain the reproduced signature data a j ′ And in determining the reproducible signature data a j ′ Signature data a from the smart terminal i When they are the same, the temporary session public key R of the smart terminal is used respectively. i and encoded data m i ′ The temporary session public key and encoded data from other smart terminals are added together to obtain the session aggregation point. and data aggregation points Next, the smart terminal uses the control center's private key sk cc,1 For session aggregation point R agg Perform a multiplication operation to generate a new elliptic curve point sk used to offset the session aggregation point. cc,1 R agg Data aggregation point C agg With the new elliptic curve point sk cc,1 R agg The difference ∑m i ′This is the combined data of the data to be transmitted from the smart terminal and other transmitted data sent by other smart terminals; finally, the control center calculates the difference ∑m. i ′ Decoding is performed to recover the original data from the smart terminal and the aggregated original data from other terminals, ∑m. i .in, This indicates the public key R of the relay gateway for the temporary session with the smart terminal. i The aggregated value of the temporary session public key of other smart terminals, This represents the adjacent encoded data m of the relay gateway for the smart terminal. i ′ The aggregated value of encoded data from other smart terminals.
[0104] By employing the elliptic curve cryptography method described above, along with a dual-key signature mechanism based on the smart terminal's private key and an authentication sub-key, secure data transmission and aggregation from smart terminals can be achieved. The control center then uses aggregation decryption to decode the encrypted data from multiple gateways into aggregated data, improving both data processing efficiency and overall system security.
[0105] Furthermore, in this embodiment of the application, during the process of the smart terminal using the current access policy to transmit data with the control center, it is also necessary to report the security detection data of the current data transmission to the control center. The control center then needs to return the trust assessment result of the current data transmission obtained based on the security detection data of the current data transmission to the smart terminal. Accordingly, the smart terminal then formulates the next access policy to be used in the next data transmission based on the trust assessment result of the current data transmission.
[0106] For details, please refer to Figure 6 As shown in this embodiment, the smart terminal can report the security detection data of this data transmission to the control center in the following ways:
[0107] S60 and smart terminals record various policy execution error events that occur during the data transmission of the data to be transmitted, based on the behavior auditing requirements included in the access policy.
[0108] Specifically, in this embodiment of the application, the strategy execution error events recorded by the smart terminal include at least one of the following:
[0109] Signature verification failed; Signature verification failure indicates that the signature data carried by the smart terminal in the data to be transmitted has not passed the verification of the control center.
[0110] Policy offset; Policy offset indicates that there is a discrepancy between the data upload permissions of the smart terminal during this data transmission process and the current access policy. Data upload permissions are determined based on access control permissions and are used to describe at least one of the following: the data content, transmission method, and reporting frequency of the data to be transmitted.
[0111] S61. The intelligent terminal will report the various policy execution error events it obtains as security detection data to the control center.
[0112] For example, in this embodiment, firstly, signature verification failure of the smart terminal, as well as policy deviations including exceeding data reporting frequency limits, sudden changes in trust assessment results, and isolation and recovery operations of the smart terminal, will trigger the behavior auditing requirements of the aforementioned access policy to be logged, thereby obtaining the policy execution error event of the smart terminal in this data transmission; then, the security detection data obtained from the policy execution error event includes the signature verification success rate V of the smart terminal. k Frequency of abnormal records A k , Resume attempt behavior R k Compliance with strategy k Finally, the control center based its decisions on the weighting factor α. j (∑α j =1) and the trust evaluation function f(α1V) k +α2VA k +α3VR k +α4P k The trust assessment result of the current data transmission by the smart terminal is calculated, and the next access strategy to be used in the next data transmission is formulated based on the trust assessment result.
[0113] By recording and reporting policy execution errors during data transmission via smart terminals, the control center can calculate trust assessment results based on this security detection data and formulate access policies for the next data transmission accordingly. This approach enables dynamic monitoring and evaluation of smart terminal behavior, allowing for flexible adjustment of access permissions based on the actual performance of the smart terminals.
[0114] On the other hand, see Figure 7 As shown in the embodiment of this application, when the data to be transmitted and the signature data of the smart terminal are obtained and uploaded to the control center, the identity mask and public key mask of the smart terminal can be constructed, an anonymous message can be constructed and sent to the control center through the relay gateway.
[0115] Specifically, the smart terminal obtains a mask digest based on its role public key, timestamp, relay gateway public key, and temporary session public key; it then obtains an identity mask based on the mask digest and identity identifier; and finally, it obtains a public key mask based on the mask digest and the smart terminal's public key. The smart terminal generates a corresponding anonymous message based on the data to be transmitted, signature data, identity mask, public key mask, and timestamp, and sends the anonymous message to the control center through the relay gateway.
[0116] For example, see Figure 8 As shown in the embodiment of this application, firstly, the role public key sk of the smart terminal is... sm P, timestamp t i The public key of the relay gateway and the public key of the ephemeral session R i Perform a hash operation to obtain a mask digest, and then use the mask digest and the identity ID as the basis for the hash operation. i Perform an XOR operation to obtain the identity mask (DID). i And, based on the mask digest and the public key sk of the smart terminal i,1 P is XORed to obtain the public key mask DPK i Then, the smart terminal, based on the data to be transmitted and the signature data a i Identity Mask (DID) i Public key mask (DPK) i and timestamp t i The corresponding anonymous message is generated; finally, the anonymous message is sent to the control center through the relay gateway.
[0117] By constructing identity masks and public key masks to generate anonymous messages, the identity and public key information of smart terminals are effectively protected, and the privacy and security of data transmission are improved.
[0118] In one alternative embodiment, before the smart terminal uses the current access policy to transmit data, the key management center needs to initialize the system parameters and authorize and issue role keys for various smart terminals.
[0119] Specifically, the key management center uniformly initializes system parameters, generating encryption parameters and role-level keys suitable for smart terminals. Simultaneously, the key management center employs blockchain technology to construct a public key registration mechanism. Furthermore, the key management center generates fine-grained zero-trust access policies for different roles.
[0120] For example, in this embodiment of the application, the key management center first selects curve E, which is suitable for efficient encryption and homomorphic operations. p (a,b), of order q, take P∈E p This serves as the system's base point; then, the key management center generates the master private key sk. kgc ∈Z qAnd calculate the corresponding master public key PK. kgc =sk kgc ·P; Finally, this master private key will be deployed in the hardware security module for subsequent signature authorization and policy binding operations.
[0121] The key management center generates role-level key pairs uniformly according to the role categories of smart terminals. First, the key management center generates a unified role private key sk for the smart terminal. sm ∈Z q Its corresponding public key is PK. sm =sk sm • P; Then, the key management center generates a unified role private key sk for the relay gateway. gw ∈Z q The corresponding character's public key is PK. gw =sk gw ·P; Finally, the key management center generates a unified role private key sk for the control center. cc ∈Z q The corresponding character's public key is PK. cc =sk cc • All role-level public keys are uniformly registered in the system's public key registry, allowing for querying and verification by various modules such as smart terminals, relay gateways, and control centers.
[0122] In addition, the key management center uses permissioned blockchain technology to build a public key registration and verification platform. The registration content structure is RegInfo = {PK kgc PK sm PK gw E p The blockchain uses consensus algorithms such as PBFT to ensure that the registered content cannot be modified without authorization. Then, the key management center restricts access to entities such as the policy engine, relay gateway, and control center through an encrypted interface, supports multi-level permission queries and anti-tampering audits, and uses a compact Merkle tree structure for data organization and hash chain compression to improve the verification efficiency and scalability of registration information.
[0123] Furthermore, the key management center defines fine-grained access policies for each type of smart terminal, covering multi-dimensional access control and behavioral constraint requirements. Specific policy dimensions are shown in Table 3 of S11 above. First, the key management center signs the access policy content to generate σ. policy =H(policy,PK) role )·(sk sm +sk gw )+sk kgc Then, bind the data structure as {PK}. role Policy, σ policyThe access policy is registered to the system public key registry. During operation, the control center and gateway call the access policy from the system public key registry as needed. Finally, the smart terminal only receives the access policy during registration. The relay gateway interprets the access policy on behalf of the smart terminal, reducing the computing burden on the smart terminal and controlling the granularity of access.
[0124] By initializing system parameters and authorizing the release of role keys through the key management center, encrypted communication and access control support are provided for smart terminals. At the same time, the key management center uses blockchain technology to build a public key registration mechanism to ensure information transparency and security. In addition, the key management center defines fine-grained zero-trust access policies for smart terminals and implements policy management through signature binding and registration processes, thereby reducing the computing burden on smart terminals.
[0125] In one optional embodiment, before the smart terminal performs this data transmission using the current access policy, the smart terminal must first register its identity and configure the controlled key.
[0126] Specifically, see Figure 9 As shown, the smart terminal generates a local key fragment and sends a registration request to the key management center. After verification, the key management center generates an authorized subkey and assigns a policy index. After verification, the smart terminal completes the registration, and the registration information is recorded in the blockchain-based key registration library.
[0127] For example, in the embodiments of this application, firstly, the smart terminal SM i Randomly select sk i,1 ∈Z q And calculate the corresponding public key PK. i =sk i,1 •P; Then, the smart terminal registration request is constructed as RegReq i ={PK i ID i ,TYPE i META i}, where TYPE i Indicates device type, META i It includes unique identification information such as device model, installation location code, and hardware serial number; finally, the registration request of the smart terminal is sent to the key management center through a secure link.
[0128] After receiving the registration request, the key management center first verifies the validity of the request information (ID). i Unique, PK i In elliptic curve E p (a,b) are valid); then, call the registered role public key PK. sm PK of the master key kgc Then, based on the unified private key sksm and master key sk kgc Calculate the authentication sub-private key sk i,2 =sk sm +H(PK i PK sm PK kgc )·sk kgc Finally, the key management center assigns a policy index to the smart terminal pointing to the access policy, and issues the policy index and authentication sub-private key to the smart terminal.
[0129] After receiving the response, the smart terminal first verifies the validity of the authentication key (sk). i,2 ·P = PK sm +H(PK i PK sm PK kgc )·PK kgc If the verification passes, the final private key structure of the smart terminal will be: sk i ={sk i,1 ,sk i,2},PK i =sk i,1 • P; Then, the policy index is recorded for smart terminal access and access control; Finally, after the smart terminal completes local verification and registration, the key management center writes the registration information into the key registration library, including the device public key PK. i Character mapping PK i →PK sm Registration status, initial trust level Policy binding, timestamp, and registration number.
[0130] A local key fragment is generated by a smart terminal and a registration request is sent to the key management center. After verification, the key management center generates an authorized subkey and assigns a policy index. After verification by the smart terminal, the registration is completed, and the registration information is recorded in a blockchain-based key registration library. This method ensures the traceability of the terminal's identity and the controllability of its behavior.
[0131] In one optional embodiment, during the data transmission process using the current access strategy by the smart terminal, the relay gateway needs to perform signature aggregation and verification on the multiple smart terminals after receiving data uploaded by multiple smart terminals.
[0132] Specifically, the relay gateway performs signature verification, batch aggregation verification, and zero-trust dynamic filtering on the data reported by the smart terminal. At the same time, it performs ciphertext aggregation of encrypted data and completes secure summation of data without decryption.
[0133] For example, in this embodiment of the application, firstly, the data packets uploaded by multiple smart terminals received by the relay gateway are Msg.i ={Enc i DID i ,σ i DPK i ,t i}, i = 1, ..., n1, for each smart terminal t i Perform freshness verification; if it times out, mark the path as abnormal. Then, the relay gateway... Demask all public keys of smart terminals and perform data processing on each data packet based on d. i ′ =H(R) i C i PK i ′ ,t i ,R j ,a j The process involves batch reconstruction of signature digests; finally, aggregated verification of signatures from all smart terminals is performed. If signature verification fails, the process proceeds to a grouped recursive localization procedure. For signature verification failures and policy execution errors such as abnormal paths (policy offsets) that occur during the process, access policy behavior auditing requirements will be triggered and recorded.
[0134] If signature verification is successful, the relay gateway aggregates the data to be transmitted from multiple smart terminals and aggregates the temporary sessions of the multiple smart terminals to obtain... Aggregating encoded data from multiple terminals yields For R j and C j The system performs a validity check. If the verification is valid, the relay gateway uploads the data to be transmitted from the multiple smart terminals that have passed the verification to the control center. If the verification is invalid, the system locates and isolates the smart terminals with abnormal data and re-aggregates the data from the multiple smart terminals.
[0135] The relay gateway performs signature verification, batch aggregation verification, and zero-trust dynamic filtering on the data reported by the smart terminal. At the same time, it performs ciphertext aggregation operations on encrypted data, supports secure summation of data without decryption, ensures the legality of aggregated data, protects privacy, and has anomaly prevention capabilities, and records and traces abnormal nodes.
[0136] In one optional embodiment, during the data transmission process using the current access strategy by the smart terminal, when the control center receives data to be transmitted from multiple smart terminals, it needs to identify, locate, and isolate the smart terminals that fail signature verification.
[0137] Specifically, the control center and relay gateway process the signatures and data to be transmitted reported by the smart terminals, identify and record issues such as signature verification failures, generate anomaly logs, and perform categorized analysis. The relay gateway and control center dynamically adjust trust assessment values by accurately locating abnormal smart terminals and relay gateways, and trigger anomaly isolation based on regional trust values. Simultaneously, they support isolation recovery and closed-loop feedback for abnormal smart terminals to ensure system security and stability.
[0138] For example, in this embodiment of the application, the control center first generates an exception log structure Log when the aggregated signature verification fails. j ={t j ID j ID region ,h j ,H(Enc j ),∑m i ,n1,L j The log structure, ,status,reason}, includes the gateway aggregation time t. j Gateway and Area Identifier ID region Aggregated encrypted digest h j Anonymous meter list hash L j The control center then collects anomaly logs, categorizes the log sources, and assigns different risk levels and trust impact weights based on the anomaly type (e.g., signature forgery, private key abuse, data format errors, communication delays, etc.). The severity of the anomaly is determined by combining historical log behavior data. Next, if the relay gateway forwards incorrect signature data for multiple consecutive cycles or the trust assessment value falls below the threshold T... j <T min If it is detected, it is marked as an abnormal relay gateway and the process is transferred to isolation; finally, in an anonymous environment, the control center uses the anonymous set in the logs to extract the information. j To retrieve the plaintext masked data set, request the cached smart terminal information {DID}. i DPK i Abnormal smart terminals can be located by binary signature re-verification and aggregate split verification.
[0139] Furthermore, the control center assigns weights w based on the severity of the anomaly type and updates the trust assessment value T accordingly. i ←T i -w·ΔT. Simultaneously, calculate the overall regional trust level T. region =avg(T j ,T i ∈region), if below the threshold This triggers a regional isolation alert. The regional distributed isolation mechanism includes single-node isolation strategies and regional isolation with alternative takeover measures. It isolates smart terminals or relay gateways and, when necessary, allows adjacent gateways to take over some data reporting permissions. Isolated smart terminals undergo periodic signature verification. If verification passes consecutively and the trust assessment value recovers (T... i >T recover If the isolation is lifted automatically, the recovery action will be recorded in the log.
[0140] By using the control center and relay gateway to accurately identify, locate, and isolate smart terminals that fail signature verification, the system not only dynamically adjusts the trust assessment value but also triggers isolation measures based on the regional trust score. This supports the isolation, recovery, and closed-loop feedback of abnormal smart terminals, ensuring the reliability and efficiency of data transmission.
[0141] Based on the same inventive concept, this application also provides a data security transmission device (e.g., a smart terminal), for example, see [link to relevant documentation]. Figure 10 As shown, the data security transmission device 100 includes:
[0142] The receiving module 1000 is used to obtain the previous trust assessment result issued by the control center after the previous data transmission. The previous trust assessment result is obtained by the control center based on the secure transmission data reported during the previous data transmission. The previous trust assessment result is used to describe the security and trust level in the previous data transmission. It is also used to obtain the access policy formulated by the control center based on the previous trust assessment result. The current access policy is used to describe the access control permissions used in the current data transmission.
[0143] Processing module 1001 is used to perform this data transmission in accordance with the access policy and control center.
[0144] In an optional embodiment, the receiving module 1000 is further configured to calculate the corresponding trust assessment result based on the security detection data recorded during the current data transmission, and formulate the next access strategy for the next data transmission.
[0145] The receiving module obtains the trust assessment result and current access policy calculated by the control center based on the security detection data of the previous data transmission. The processing module then uses this policy to perform the current data transmission and can formulate the next access policy based on the current data transmission. This achieves closed-loop management of dynamic access control and trust assessment, improving the security and flexibility of data transmission.
[0146] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0147] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0148] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0149] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0150] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for secure data transmission, characterized in that, The method includes: After the last data transmission with the control center, the smart terminal obtains the previous trust assessment result issued by the control center; the previous trust assessment result is obtained by the control center based on the security detection data reported by the smart terminal during the previous data transmission; the previous trust assessment result is used to describe the security and trust level of the smart terminal in the previous data transmission. The smart terminal obtains the access policy formulated by the control center based on the previous trust assessment result; the access policy describes the access control permissions used by the smart terminal in this data transmission. The smart terminal uses the access strategy described above to perform this data transmission with the control center.
2. The method as described in claim 1, characterized in that, The method further includes: During the data transmission process using the access policy and control center, the smart terminal reports the security detection data of the data transmission to the control center in the following manner: Based on the behavior auditing requirements included in the current access policy, the smart terminal records various policy execution error events generated by the data to be transmitted during this data transmission. The smart terminal reports the failure events of each strategy execution as security detection data to the control center.
3. The method as described in claim 2, characterized in that, The execution failure events of each strategy include at least one of the following: Signature verification failed; the signature verification failure indicates that the signature data carried by the smart terminal in the data to be transmitted has not passed the verification of the control center; Strategy offset; The policy offset indicates that there is a deviation between the data upload permission of the smart terminal and the access policy during this data transmission process; the data upload permission is determined based on the access control permission and is used to describe at least one of the following: the data content, transmission method and reporting frequency of the data to be transmitted.
4. The method as described in claim 2, characterized in that, The method further includes: The smart terminal receives the trust assessment result of the current data transmission, obtained from the security detection data of the current data transmission, returned by the control center; Based on the trust assessment results of the current data transmission, the smart terminal formulates the next access strategy to be used in the next data transmission.
5. The method according to any one of claims 1-4, characterized in that, The smart terminal uses the current access strategy to transmit the data to be transmitted to the control center, including: The smart terminal encrypts the original data to obtain encrypted original data, and uses the encrypted original data as data to be transmitted. The smart terminal performs signature processing on the data to be transmitted to obtain signature data; The smart terminal uses the access strategy to send the data to be transmitted and the signature data to the control center. When the control center determines that the signature data has passed the signature verification, it aggregates and decrypts the data to be transmitted and other transmitted data sent by the other smart terminal to obtain the original data.
6. The method as described in claim 5, characterized in that, The smart terminal encrypts the original data to obtain encrypted original data, and uses the encrypted original data as data to be transmitted, including: The smart terminal performs elliptic curve point encoding on the raw data to obtain corresponding encoded data; each elliptic curve point represents a portion of the encoded data. The smart terminal randomly selects an integer from the finite field of the elliptic curve points as the temporary session private key for this data transmission; The smart terminal uses the product of the temporary session private key and the public key of the control center as a shared elliptic curve point; The smart terminal performs elliptic curve point addition on the encoded data and the shared elliptic curve points to obtain the encrypted original data.
7. The method as described in claim 6, characterized in that, The smart terminal performs signature processing on the data to be transmitted to obtain signature data, including: The smart terminal obtains a temporary session public key based on the temporary session private key and the generator; the temporary session public key is an elliptic curve point; the generator is a base point on the elliptic curve. The smart terminal obtains its role private key based on the master private key issued by the key management center and the smart terminal's identity identifier, and generates an authentication sub-private key based on the smart terminal's role public key, the smart terminal's public key, the master private key, and the master public key; The smart terminal obtains a signature digest based on the temporary session public key, the data to be transmitted, the smart terminal's public key, the timestamp, and the relay gateway's public key; The smart terminal obtains its signature data based on the signature digest, its private key, and the authentication sub-private key.
8. The method as described in claim 7, characterized in that, The smart terminal uses the access strategy described above to send the data to be transmitted and the signature data to the control center, including: The smart terminal obtains a mask digest based on its role public key, the timestamp, the relay gateway's public key, and the temporary session public key; obtains an identity mask based on the mask digest and the identity identifier; and obtains a public key mask based on the mask digest and the smart terminal's public key. The smart terminal generates a corresponding anonymous message based on the data to be transmitted, the signature data, the identity mask, the public key mask, and the timestamp, and sends the anonymous message to the control center through the relay gateway.
9. The method as described in claim 7, characterized in that, When the control center determines that the signature data has passed signature verification, the process of aggregating and decrypting the data to be transmitted and other transmitted data sent by other smart terminals to obtain the original data includes: To enable the control center to perform the following operations: The signature digest is reproduced based on the temporary session public key of the smart terminal, the data to be transmitted, the public key of the smart terminal, the timestamp, and the public key of the relay gateway. Based on the reproduced signature digest, reproduced signature data is obtained. When it is determined that the reproduced signature data is the same as the signature data of the smart terminal, the temporary session public key and the encoded data of the smart terminal are added to the temporary session public key and the encoded data of other smart terminals respectively to obtain the session aggregation point and the data aggregation point. Based on the private key of the control center, a multiplication operation is performed on the session aggregation point to generate a new elliptic curve point to offset the session aggregation point; The difference between the data aggregation point and the new elliptic curve point is used as the merged data of the data to be transmitted from the smart terminal and other transmitted data sent by other smart terminals. The difference is decoded to recover the original data of the smart terminal and the aggregated data of the original data of other terminals.
10. A data security transmission device, characterized in that, The device includes: The receiving module is configured to, after the previous data transmission with the control center, obtain the previous trust assessment result issued by the control center, wherein the previous trust assessment result is obtained by the control center based on the secure transmission data reported during the previous data transmission; the previous trust assessment result is used to describe the security and trust level in the previous data transmission; and obtain the current access policy formulated by the control center based on the previous trust assessment result; the current access policy is used to describe the access control permissions used in the current data transmission. The processing module is used to perform this data transmission with the control center using the current access strategy.