An optimization method for secure communication of a Bluetooth chip device

By identifying the type and protocol version of Bluetooth devices and optimizing security policy configuration, the problem of unifying security policies for different Bluetooth devices is solved. This enables the generation and dynamic adjustment of device-specific security policies, thereby improving the security and stability of Bluetooth communication.

CN121078415BActive Publication Date: 2026-02-17深圳市乾海芯联科技有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511596645.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-04
Publication Date
2026-02-17
Estimated Expiration
2045-11-04

AI Technical Summary

Technical Problem

Bluetooth devices from different manufacturers have security vulnerabilities due to differences in hardware design and protocol versions, making it difficult to formulate a unified security strategy. Furthermore, older protocol versions are vulnerable to attacks and cannot meet the security needs of all devices.

Method used

By identifying device type identifiers and protocol version characteristics, hardware capability parameters are extracted to generate an initial set of security policies. Combined with channel quality data and interference intensity sequences, the security policy configuration is optimized, and the channel status is monitored in real time for dynamic adjustments.

Benefits of technology

Ensure that security strategies are compatible with device hardware capabilities, dynamically adapt to channel changes, improve the security and stability of Bluetooth communication, avoid resource waste, and ensure the accuracy and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121078415B_ABST
    Figure CN121078415B_ABST
Patent Text Reader

Abstract

The application relates to the field of Bluetooth communication technology and discloses an optimization method for safe communication of a Bluetooth chip device. The method identifies a device type identifier and a protocol version feature, extracts a hardware capability parameter and generates an initial safe strategy set; then, channel data is collected to calculate a stability index and a dynamic noise baseline; then, a safe strategy is screened and sorted to generate an execution queue, and an encryption strength threshold is adjusted according to the noise baseline to perform iterative optimization, and a final strategy configuration is output; when a target Bluetooth chip establishes a communication connection, the final safe strategy configuration is loaded and the channel state is monitored in real time, and when the channel state changes by more than a preset tolerance, a strategy dynamic switching mechanism is triggered to optimize the safe communication effect of the Bluetooth chip device. The method can accurately adapt the safe strategy to the device and the channel state, dynamically adjust the strategy, and effectively improve the safety and stability of the Bluetooth chip device communication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of Bluetooth communication technology, and particularly to an optimization method for secure communication of a Bluetooth chip device. BACKGROUND

[0002] As a short-range wireless communication technology, Bluetooth technology has been widely used in many fields due to its low power consumption, low cost, easy integration and other advantages. In the consumer electronics field, Bluetooth earphones, Bluetooth speakers, smartwatches and other devices have become an indispensable part of people's daily life. For example, people can freely listen to music and answer phone calls through Bluetooth earphones, freeing themselves from the constraints of wired earphones and enjoying a more convenient audio experience. Smartwatches can connect with mobile phones through Bluetooth and receive real-time notifications and monitor health data.

[0003] In the field of smart home, Bluetooth technology also plays an important role. Various smart home appliances, such as smart light bulbs, smart sockets, smart door locks, etc., can realize interconnection and intercommunication between devices and remote control of user's mobile phone through Bluetooth. Users can use the application on their mobile phones to turn on the smart light bulbs at home in advance through Bluetooth technology to welcome themselves home with warm light when they are on their way home from work, or remotely control the smart door lock to open the door for visiting guests. In the field of industrial control, Bluetooth technology is applied to production line data acquisition, wireless device control, smart warehouse management, etc. On the production line, various sensors, controllers and other devices can be wirelessly connected through Bluetooth to obtain real-time data such as temperature, pressure and humidity, avoiding the trouble of traditional wired connection and greatly improving production efficiency and data accuracy. In smart warehousing, Bluetooth tags and scanners are wirelessly connected with industrial computers through Bluetooth to track the location and status of goods in real time, improving the efficiency of warehouse management. As can be seen, Bluetooth technology has penetrated into every corner of people's life and industrial production, and has had a profound impact on the development of modern society.

[0004] Problems caused by device type and protocol differences: With the wide application of Bluetooth technology, various Bluetooth devices have appeared in the market, which come from different manufacturers and have different device type identifiers and protocol version characteristics. Bluetooth devices from different manufacturers differ in hardware design, software implementation, etc., which may lead to different security vulnerabilities. Some early Bluetooth devices, due to the limitations of the technology at that time, may have deficiencies in encryption algorithms, authentication mechanisms, etc., which are easy to be exploited by attackers. Moreover, different protocol versions differ in security, and low version Bluetooth protocols may lack some advanced security features and are more vulnerable to attacks. When Bluetooth devices of different types and protocol versions communicate, how to develop appropriate security strategies becomes a problem. Because a security strategy may only be applicable to devices of a specific type and protocol version, it cannot meet the security needs of all devices. SUMMARY

[0005] The purpose of the present application is to provide an optimization method for secure communication of Bluetooth chip devices to solve the problems raised in the background art.

[0006] To achieve the above-mentioned purpose, the present application provides an optimization method for secure communication of Bluetooth chip devices, which comprises:

[0007] Identify the device type identifier and protocol version characteristics in the current Bluetooth communication link, extract the hardware capability parameters of the target Bluetooth chip according to the device type identifier, and generate an initial security strategy set based on the protocol version characteristics;

[0008] Collect the channel quality data and interference intensity sequence of the target Bluetooth chip in the historical communication period, perform segmented fitting processing on the channel quality data to obtain the channel stability index, and calculate the dynamic noise baseline in combination with the interference intensity sequence;

[0009] Filter a candidate strategy subset according to the matching degree of the hardware capability parameters and the initial security strategy set, prioritize the candidate strategy subset using the channel stability index, and generate a strategy execution queue;

[0010] Adjust the encryption strength threshold of each security strategy in the strategy execution queue based on the dynamic noise baseline, iteratively optimize the strategy execution queue according to the adjusted encryption strength threshold, and output the final security strategy configuration;

[0011] When the target Bluetooth chip establishes a communication connection, load the final security strategy configuration and monitor the channel state changes in real time, and trigger the strategy dynamic switching mechanism when the channel state changes exceed the preset tolerance.

[0012] Preferably, the hardware capability parameters of the target Bluetooth chip are extracted according to the device type identifier, which comprises:

[0013] Parsing the manufacturer code and chip model field in the device type identification, indexing the corresponding processor frequency and memory capacity from a pre-built hardware capability database;

[0014] Detecting the encryption algorithm type and key length range currently supported by the target Bluetooth chip, and generating a hardware capability parameter matrix in combination with the processor frequency and memory capacity;

[0015] Normalizing the hardware capability parameter matrix to obtain a quantized score vector of the hardware capability parameters.

[0016] Preferably, the segment fitting processing of the channel quality data to obtain the channel stability indicator comprises:

[0017] Dividing the historical communication period into multiple time windows of equal length, and extracting the packet loss rate and signal strength fluctuation value of the channel quality data in each time window;

[0018] Fitting the packet loss rate change curve in each time window using a linear regression model, and calculating the slope difference degree of the fitting curves of adjacent time windows;

[0019] Generating a local stability coefficient for each time window according to the weighted sum of the signal strength fluctuation value and the slope difference degree;

[0020] Sliding average calculation of the local stability coefficients of all time windows to output the channel stability indicator.

[0021] Preferably, the calculation of the dynamic noise baseline comprises:

[0022] Performing frequency domain transformation on the interference intensity sequence to extract the energy distribution spectrum of the characteristic frequency band;

[0023] Identifying the burst interference pulses in the energy distribution spectrum that exceed a preset threshold, and counting the duration and interval period of the burst interference pulses;

[0024] According to the ratio relationship between the duration and interval period, an adaptive updating model of the dynamic noise baseline is established.

[0025] Preferably, the priority sorting of the candidate strategy subset using the channel stability indicator comprises:

[0026] Establishing a mapping relationship table between the channel stability indicator and the success rate of security strategy execution;

[0027] Removing the strategy items in the candidate strategy subset whose success rates in the mapping relationship table are lower than a threshold value to generate an effective strategy set;

[0028] According to the sensitivity of each strategy item in the effective strategy set to the channel stability indicator, calculating the priority weight of the strategy;

[0029] arranging the effective policy set in order of policy priority weight from high to low to generate a policy execution queue.

[0030] Preferably, the adjusting the encryption strength threshold of each security policy in the policy execution queue comprises:

[0031] obtaining a current fluctuation amplitude of the dynamic noise baseline, and determining an encryption strength adjustment step according to the fluctuation amplitude;

[0032] selecting a first to-be-executed policy in the policy execution queue, and reading an initial encryption strength threshold and a maximum allowed strength value of the first to-be-executed policy;

[0033] incrementing or decrementing the initial encryption strength threshold by the encryption strength adjustment step, so that the modified threshold does not exceed the maximum allowed strength value;

[0034] repeating the modifying operation on the remaining policy items in the policy execution queue until all the policy items in the queue are adjusted.

[0035] Preferably, the triggering the dynamic switching mechanism of the policy comprises:

[0036] collecting real-time channel state parameters, including an instantaneous error rate and a signal attenuation slope;

[0037] comparing the instantaneous error rate with the dynamic noise baseline, and starting a primary policy switching when a difference between the two exceeds a first switching threshold;

[0038] detecting a change trend of the signal attenuation slope after the primary policy switching, and triggering a secondary policy switching when the change trend continuously deteriorates;

[0039] recording channel state parameters and executed policy identifiers in the policy switching process, and updating historical communication period data.

[0040] Preferably, the starting the primary policy switching comprises:

[0041] selecting candidate policy items with encryption strength thresholds lower than a current value from the policy execution queue;

[0042] calculating an average execution success rate and a switching time consumption of each candidate policy item in a historical communication period;

[0043] selecting a candidate policy item with the highest average execution success rate and the shortest switching time consumption as a primary switching target;

[0044] suspending a data encryption process of a current policy, loading a policy configuration of the primary switching target, and resetting an encryption session key.

[0045] Preferably, the triggering the secondary policy switching comprises:

[0046] Locating a next-in-line policy item of a current executing policy in a policy execution queue;

[0047] Verifying a matching degree of a hardware compatibility parameter of the next-in-line policy item with a current channel state parameter;

[0048] When the matching degree meets a preset condition, raising an encryption strength threshold of the next-in-line policy item to a preset security level;

[0049] Reinitializing the data encryption channel with the raised encryption strength threshold to complete a secondary policy switching.

[0050] Preferably, the loading of the final security policy configuration comprises:

[0051] Parsing a key derivation algorithm and an authentication protocol type in the final security policy configuration;

[0052] Generating a derivation parameter combination of a master key and a temporary session key according to the key derivation algorithm;

[0053] Establishing a two-way identity authentication process according to the authentication protocol type, and activating the data encryption channel after verification;

[0054] Continuously monitoring a key update period and an authentication validity period in the encryption channel, and initiating an automatic renewal request before expiration.

[0055] Compared with the prior art, the present application has the beneficial effects that:

[0056] The present application can deeply understand the characteristics and security requirements of the Bluetooth device by identifying the device type identifier and the protocol version feature in the current Bluetooth communication link. According to the device type identifier, the hardware capability parameters of the target Bluetooth chip are extracted, so that we can clearly know the specific situation of the device in terms of computing ability, storage ability, etc. Based on this, when facing numerous security policies, a candidate policy subset can be selected according to the matching degree of the hardware capability parameters and the initial security policy set. This way ensures that the selected security policy is compatible with the hardware capability of the device, avoiding the problems of device performance degradation or security vulnerabilities caused by overly complex or simple security policies. For example, for a Bluetooth chip with weak hardware computing ability, an encryption algorithm with too much complexity and calculation amount will not be selected, but a relatively simple and suitable security policy for its hardware capability will be selected, thereby improving the security of Bluetooth communication, ensuring efficient operation of the device, and reducing unnecessary consumption of resources.

[0057] In the process of Bluetooth communication, the application can fully grasp the dynamic changes of the channel by collecting the channel quality data and the interference intensity sequence of the target Bluetooth chip in the historical communication period. The channel quality data is processed by segment fitting to obtain the channel stability index, which enables us to quantitatively evaluate the stability of the channel. The dynamic noise baseline is calculated in combination with the interference intensity sequence, which provides a benchmark for measuring the noise level in a complex channel environment. According to these indexes and the baseline, we can adjust the security policy in real time according to the channel state. When the channel stability is poor and the interference intensity is large, the encryption strength is automatically increased to ensure the confidentiality and integrity of the data in the transmission process; when the channel stability is good and the interference intensity is small, the encryption strength is appropriately reduced to reduce the occupation of computing resources and improve the communication efficiency. This dynamic adaptation to channel changes effectively reduces the impact of interference on Bluetooth communication and ensures the accuracy and integrity of data transmission.

[0058] In the application, the strategy execution queue is generated by priority sorting of the candidate strategy subset, so that the execution of the security policy is more orderly and efficient. Moreover, the encryption strength threshold of each security policy in the strategy execution queue is adjusted according to the dynamic noise baseline, and the strategy execution queue is iteratively optimized, which fully considers the real-time state of the channel and the security requirements. Under different channel conditions, the optimal security policy can be selected for execution, avoiding the limitations of fixed security policies in complex channel environments. When the channel noise is large, the encryption strength threshold is adjusted in time to select a stronger encryption policy to ensure the safe transmission of data; when the channel noise is small, the encryption strength threshold is reduced to reduce the waste of computing resources and improve the efficiency of communication. Through such optimization, the security and stability of Bluetooth communication are improved, so that Bluetooth communication can reliably operate in various complex environments. BRIEF DESCRIPTION OF DRAWINGS

[0059] Figure 1 The working principle diagram of the optimization method for the security communication of the Bluetooth chip device described in the application;

[0060] Figure 2 The flowchart for extracting the hardware capability parameters of the Bluetooth chip;

[0061] Figure 3 The flowchart for segment fitting of the channel quality data and generation of the channel stability index;

[0062] Figure 4 The relationship diagram of signal intensity fluctuation and local stability coefficient. DETAILED DESCRIPTION

[0063] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work belong to the scope of protection of the present application.

[0064] Please refer to Figure 1 The present application provides an optimization method for secure communication of a Bluetooth chip device, which comprises identifying a device type identifier and a protocol version feature in a current Bluetooth communication link, the device type identifier being extracted from a Bluetooth broadcast data packet or a connection request frame, and the protocol version feature being obtained by analyzing a Bluetooth protocol data unit; extracting a hardware capability parameter of a target Bluetooth chip according to the device type identifier, the hardware capability parameter comprising a processor main frequency, a memory capacity, a supported encryption algorithm type and a key length range; generating an initial security policy set based on the protocol version feature, the initial security policy set covering all authentication mechanisms and encryption suites supported by the protocol version. Collecting channel quality data and an interference intensity sequence of the target Bluetooth chip in a historical communication period, the channel quality data comprising a signal strength indicator and a link quality index, and the interference intensity sequence being collected by a radio frequency front end; obtaining a channel stability index by segment fitting the channel quality data, the segment fitting dividing the historical period into equal length time segments and calculating statistical features of the quality parameters in each segment; calculating a dynamic noise baseline in combination with the interference intensity sequence, the dynamic noise baseline reflecting time-varying characteristics of channel background interference. Screening a candidate policy subset according to a matching degree of the hardware capability parameter and the initial security policy set, the matching degree evaluating a bearing capacity of hardware resources on strategy execution overhead; prioritizing the candidate policy subset by using the channel stability index to generate a strategy execution queue, the prioritizing principle being that a channel with high stability adopts a complex strategy in priority. Adjusting an encryption strength threshold of each security policy in the strategy execution queue based on the dynamic noise baseline, the adjustment direction of the encryption strength threshold being positively correlated with a noise level change; iteratively optimizing the strategy execution queue according to the adjusted encryption strength threshold to output a final security policy configuration, the iteration process eliminating conflicting configurations among the strategies. When the target Bluetooth chip establishes a communication connection, loading the final security policy configuration and monitoring channel state changes in real time, the monitoring parameters comprising a bit error rate and a signal attenuation slope; triggering a strategy dynamic switching mechanism when the channel state changes exceed a preset tolerance, the preset tolerance being dynamically set according to security requirements of an application scenario.

[0065] Embodiment 1: refer to Figure 2, the manufacturer code in the device type identifier is parsed, and the chip model field is extracted from a device broadcast data packet. A corresponding processor frequency and memory capacity are indexed from a pre-constructed hardware capability database, and the hardware capability database continuously updates hardware specification parameters of mainstream Bluetooth chips. The current supported encryption algorithm type and key length range of the target Bluetooth chip are detected, and the detection process calls a chip bottom layer security management interface to query an algorithm support list. A hardware capability parameter matrix is generated in combination with the processor frequency and the memory capacity, and the rows of the matrix represent different algorithm types, and the columns represent the corresponding relationship between the key length and the processing speed. The hardware capability parameter matrix is normalized, and the normalization uses a minimum-maximum scaling method to map the values of each dimension to a unified dimension. A quantized score vector of the hardware capability parameter is obtained, and the quantized score vector is used for numerical comparison of subsequent strategy matching degrees.

[0066] The parsing of the manufacturer code relies on a manufacturer identifier allocation list maintained by the Bluetooth Special Interest Group, and the chip model field is extracted from a device information exchange frame in the Bluetooth connection establishment process. The pre-constructed stage of the hardware capability database integrates public chip specification documents and laboratory test reports, and the index value of the processor frequency is converted to a unified unit of megahertz after being read from the database. The detection of the encryption algorithm type is realized by sending a Bluetooth security manager command, and the detection of the key length range uses a gradual trial method. The generation algorithm of the hardware capability parameter matrix dynamically adjusts the size of the matrix, and the number of rows is determined according to the detected number of algorithms. The processor frequency parameter affects the columns related to processing speed in the matrix, and the memory capacity parameter determines the dimension of the number of storable keys in the matrix. The minimum and maximum values of the normalization processing are obtained from the statistical records in the database, and the weighting coefficients of the quantized score vector are set according to the security requirements of the application scenario. The accuracy of the manufacturer code parsing is verified by checksum, and the resolution of the chip model field considers the version variation. The index operation of the hardware capability database supports fuzzy matching, and the parameter value of the processor frequency considers the dynamic frequency adjustment characteristics of the chip. The detection list of the encryption algorithm type covers all algorithms defined in the Bluetooth standard, and the detection of the key length range records the specific length values supported by the chip. The structure design of the hardware capability parameter matrix is a sparse matrix, and the mapping of the processor frequency and the encryption algorithm execution speed is based on benchmark test data. The association between the memory capacity and the key storage size is calculated through the security context size, and the parameter range of the normalization processing is updated regularly.

[0067] The resolution of the device type identifier is performed in the Bluetooth connection initialization phase, and the resolution rule of the vendor code processes the multi-byte identifier. The resolution of the chip model field processes the variable length field, and the pre-construction process of the hardware capability database includes data cleaning and verification. The index value of the processor frequency is converted to a floating point number, and the index value of the memory capacity is aligned to the standard unit. The detection command of the encryption algorithm type uses the operation code specified by the Bluetooth security management protocol, and the detection process of the key length range records the key length of the failure point. The generation algorithm of the hardware capability parameter matrix optimizes the matrix filling order, and the processor frequency parameter in the matrix is represented by a relative value. The memory capacity parameter is mapped to the storage dimension in the matrix, and the scaling parameter of the normalization processing is dynamically adjusted. The flow of resolving the device type identifier integrates the error handling mechanism, and the resolution of the vendor code supports the extended vendor code defined by the Bluetooth Technology Alliance. The resolution of the chip model field processes the mapping of the abbreviation model and the full name model, and the index operation of the hardware capability database records the query log. The index value of the processor frequency is verified for reasonableness, and the index of the memory capacity considers the chip memory partitioning situation. The detection result of the encryption algorithm type is cached for a period of time, and the detection of the key length range adapts to the dynamic capability adjustment of the chip. The generation of the hardware capability parameter matrix supports real-time updating, and the influence factor of the processor frequency parameter is weighted in the matrix. The relationship between the memory capacity parameter and the algorithm complexity is defined by a lookup table, and the output value of the normalization processing is rounded to a specified number of decimal places.

[0068] The resolution performance optimization of the device type identification adopts a parallel resolution technique, and the index of the hardware capability database uses a multi-level index structure. The index values of the processor frequency and the memory capacity are attached with time stamps, and the detection of the encryption algorithm type adopts a batch detection mode. The detection of the key length range uses a binary search method, and the storage format of the hardware capability parameter matrix is optimized as row-column storage. The calculation of the normalization processing uses an incremental update algorithm, and the generation of the quantized score vector supports vectorization operation. The module for resolving the device type identification is loosely coupled with other modules of the Bluetooth protocol stack, and the resolution rules of the vendor code are configurable. The resolution processing of the chip model field resolves model aliases, and the distributed deployment of the hardware capability database is in multiple nodes. The index values of the processor frequency are attached with confidence scores, and the index values of the memory capacity contain measurement error ranges. The detection command of the encryption algorithm type is encrypted for transmission, and the detection results of the key length range are verified for integrity. The generation log of the hardware capability parameter matrix records detailed steps, and the parameter range alarm mechanism of the normalization processing. The resolution of the device type identification is completed in the Bluetooth pairing stage, and the resolution of the vendor code is compatible with both Bluetooth Low Energy and classic Bluetooth modes. The resolution of the chip model field supports future Bluetooth version extension, and the index API of the hardware capability database provides both synchronous and asynchronous interfaces. The index values of the processor frequency are unified as hertz, and the index values of the memory capacity are standardized as integer byte numbers. The detection of the encryption algorithm type covers national standard algorithms, and the detection of the key length range records historical detection results. The serialization storage of the hardware capability parameter matrix supports the saving and restoring of matrix states, and the parameter persistent storage of the normalization processing.

[0069] The input data for parsing the device type identifier comes from the Bluetooth host controller interface, and the parsing of the vendor code supports multi-vendor cooperation devices. The parsing of the chip model field verifies the validity of the field, and the index operation of the hardware capability database audits the log. The index value of the processor frequency can be adjusted by the cache strategy, and the index value of the memory capacity is marked by the source. The detection result of the encryption algorithm type is bound to the digital certificate, and the detection environment of the key length range is isolated. The access control of the hardware capability parameter matrix restricts the access of the authorization module, and the calculation resources of the normalization processing are monitored. The parsing output structure of the device type identifier is standardized, and the parsing of the vendor code supports offline mode. The parsing of the chip model field is internationalized, and the index result of the hardware capability database returns detailed information. The index value of the processor frequency is controlled in precision, and the index value of the memory capacity is aligned with the memory page boundary. The detection result of the encryption algorithm type is formatted for output, and the detection result of the key length range is statistically distributed. The visualization tool of the hardware capability parameter matrix is used for debugging, and the historical data of the normalization processing are compared to show the parameter change trend. The module unit test of the device type identifier covers various boundary conditions, and the parsing error code of the vendor code is defined in detail. The performance benchmark test of the parsing of the chip model field, and the index query optimization of the hardware capability database. The index value of the processor frequency is verified, and the index value of the memory capacity is consistent. The security test of the encryption algorithm type detection, and the stress test of the key length range detection. The concurrent access control of the hardware capability parameter matrix, and the numerical stability analysis of the normalization processing. The generation accuracy of the quantitative score vector is verified using the standard test vector.

[0070] Embodiment 2: see Figure 3The historical communication period is divided into multiple time windows with equal length, and the length of the time window is adaptively adjusted according to the communication data volume. In each time window, the packet loss rate of channel quality data and the signal strength fluctuation value are extracted, the packet loss rate is counted from the transmission layer confirmation mechanism, and the signal strength fluctuation value is calculated by taking the standard deviation of the received signal strength indication. A linear regression model is used to fit the packet loss rate curve in each time window, and the least square method is used to estimate the curve parameters. The slope difference degree of adjacent time windows fitting curves is calculated, and the slope difference degree is measured by the Euclidean distance of the change amplitude of adjacent slopes. According to the weighted sum of the signal strength fluctuation value and the slope difference degree, the local stability coefficient of each time window is generated, and the weight coefficient is obtained by training the historical data. The local stability coefficients of all time windows are calculated by moving average, and the channel stability index is output. The frequency domain transformation is performed on the interference intensity sequence, and the fast Fourier transform algorithm is used to convert the time domain signal into frequency domain representation. The energy distribution spectrum of the characteristic frequency band is extracted, and the characteristic frequency band corresponds to the 2.4GHz frequency band and its harmonic frequency of the Bluetooth channel. The burst interference pulse exceeding the preset threshold in the energy distribution spectrum is identified, and the preset threshold is dynamically calibrated according to the environmental noise base. The duration and interval period of the burst interference pulse are counted, and the duration records the time span of the pulse exceeding the threshold. According to the ratio relationship between the duration and the interval period, an adaptive updating model of the dynamic noise baseline is established.

[0071] The time window partitioning algorithm considers the periodic variation of the communication load, and the window length is an integer multiple of the load period. The packet loss rate extraction includes both transmission errors and timeout losses, and the signal strength fluctuation calculation excludes power adjustments caused by device power saving. The goodness-of-fit test of the linear regression model determines whether to use a higher-order polynomial fit, with a goodness threshold of 0.8. The slope difference calculation introduces a time decay factor, giving higher weights to recent windows. The weighted coefficient of the local stability coefficient is dynamically adjusted, with the signal strength weight increasing in high interference environments. The window size of the moving average calculation is configurable, with a negative correlation between size and stability update frequency. The sampling rate of the frequency domain transformation meets the Nyquist criterion, avoiding spectral aliasing. The energy distribution map is generated using the Welch average periodogram method to reduce variance. The identification of burst interference pulses sets a minimum duration threshold to filter transient noise. The duration statistics are accurate to the microsecond level, and the interval period calculation uses a ring buffer to store pulse events. The adaptive update model uses an exponentially weighted moving average algorithm, with new observations having higher weights than historical values. The division of the historical communication period receives input data from the communication quality monitoring module, and the data packet timestamps are aligned with the global clock. The packet loss rate statistics use a sliding counter, which is reset at window switching. The input data preprocessing for linear regression fitting removes obvious outliers, and the outlier determination is based on the boxplot rule. The slope difference calculation considers curve sign changes, and sign reversal indicates trend reversal. The local stability coefficient generation module integrates a weight learning function, and the weight is adjusted according to historical accuracy feedback. The moving average calculation uses a double buffer mechanism, with one buffer for calculating the current average and the other receiving new data updates.

[0072] The collection of interference intensity sequence is obtained by a radio frequency front-end analog-to-digital converter, and the sampling value is quantized into a digital signal. The pre-processing of frequency domain transformation includes windowing function to reduce spectral leakage, and the window function type is Hanning window. The feature band division of energy distribution map refers to Bluetooth channel planning, and the energy value is calculated for 40 channels respectively. The identification algorithm of burst interference pulse includes front edge detection and back edge detection, and the pulse width measurement is accurate to the sampling period. The statistics of duration and interval period use high-precision timer, and the timer resolution is nanosecond level. The division of time window supports dynamic re-division mechanism, and when the channel condition changes dramatically, the window length is automatically adjusted. The packet loss rate statistics distinguish controllable packet loss and uncontrollable packet loss, and the controllable packet loss includes active packet loss caused by power consumption management. When the linear regression model fails, the backup fitting algorithm is enabled, and the backup algorithm uses moving average smoothing and difference calculation to calculate the slope. The calculation of slope difference degree increases the confidence interval estimation, and the confidence interval is calculated based on the historical difference degree distribution. The weighted sum calculation of local stability coefficient introduces nonlinear transformation, and the transformation function is Sigmoid function. The window boundary processing of moving average calculation uses mirror expansion to avoid boundary effect. The parallel calculation of frequency domain transformation uses multi-core processor, and the transformation task is divided into multiple sub-tasks for parallel execution. The storage of energy distribution map uses sparse matrix format, and the zero value area is stored in compressed form. The identification of burst interference pulse increases the pattern matching function, and common interference sources such as Wi-Fi signal have specific patterns. The grouping aggregation of duration statistics results is based on the time interval, and the interval size is logarithmically distributed. The parameters of adaptive update model are learned online, and the learning rate decays over time.

[0073] The division of the time window is synchronized with the upper layer application, and the application data burst period shortens the window length. The packet loss rate statistics are associated with the application layer retransmission information, and the retransmission causes the packet loss to be counted separately. The real-time optimization of linear regression fitting uses recursive least squares to avoid matrix inversion. The slope difference degree calculation introduces multi-window sliding comparison, and the comparison window size is variable from 3 to 7. The generation of the local stability coefficient increases the time correlation constraint, and the coefficient difference of adjacent windows is limited within a certain range. The weight distribution of the moving average calculation is adjustable, and the weight distribution supports two modes of uniform distribution and Gaussian distribution. The input data buffer of the frequency domain transformation uses a ring buffer, and the selection of the buffer length trades off delay and computational overhead. The analysis of the energy distribution map increases the calculation of the spectral kurtosis value, which characterizes the energy distribution shape. The classification storage of the identification results of the burst interference pulse is classified according to the pulse shape and frequency position. The ratio calculation of the duration and interval period increases the smoothing of the moving average, and the smoothing window size is proportional to the pulse frequency. The initial value setting of the adaptive update model depends on the historical data, and the conservative default value is used when the initial value is insufficient. The division of the time window is synchronized in a distributed system, and the window boundaries of multiple nodes are aligned. The packet loss rate statistics fuse multiple data source information, including link layer statistics and service layer feedback. The confidence interval calculation of linear regression fitting uses Student's t distribution, and the interval width is related to the data volume and variance. The long-term trend analysis of the slope difference degree uses time series analysis, and the trend component is used to predict future difference. The generation of the local stability coefficient introduces spatial correlation, and the coefficients of adjacent channels refer to each other. The anomaly value robustness improvement of the moving average calculation is based on the median absolute deviation.

[0074] The collection of the interference intensity sequence calibrates the front-end gain, and the gain value is recorded for data restoration. The output precision control of the frequency domain transformation is related to the calculation word length. The compressed transmission of the energy distribution map uses differential encoding, and the encoding efficiency is related to the map change rate. The identification of the burst interference pulse increases multi-threshold detection, and different thresholds correspond to different sensitivities. The distributed aggregation of the duration statistics, the statistics of multiple collection points are aggregated and fused. The parameter secure storage of the adaptive update model is a secure element. The division metadata of the time window records, including the division time point and the window identifier. The sampling interval of the packet loss rate statistics is configurable, and the interval matches the data rate. The residual analysis of linear regression fitting, the residual distribution is used for model verification. The calculation buffer mechanism of the slope difference degree, the recent calculation results are cached. The pipeline optimization of the local stability coefficient generation, multiple windows are calculated in parallel. The numerical stability improvement of the moving average calculation uses the Kahan summation algorithm to reduce the accumulation error.

[0075] Hardware acceleration of frequency domain transformation utilizes dedicated digital signal processors with transformation kernels hardened in hardware. Visual debugging interface for energy distribution profile visualizes spectrum over time. Machine learning enhancement for burst interference pulse identification uses support vector machine classification. Real-time report generation for duration statistics standardizes report formats. Version compatibility handling for adaptive update model is compatible with old parameter formats. Elastic scaling for time window partitioning merges windows under high system load. Quality assessment indicators for packet loss rate statistics include integrity and accuracy scores. Distributed computation for linear regression fitting distributes fitting tasks to multiple compute nodes. Forecasting model integration for slope difference uses autoregressive integrated moving average models. On-line learning support for local stability coefficient generation uses stochastic gradient descent learning algorithms. Window size adaptive adjustment for moving average computation adjusts based on data variability. Preprocessing optimization for frequency domain transformation includes direct current component removal and trend elimination. Anomaly detection for energy distribution profile is based on outlier analysis. Rule engine for burst interference pulse identification dynamically loads rule scripts. Data compression for duration statistics is based on dictionary encoding. Redundant backup for adaptive update model runs in parallel.

[0076] See Figure 4In the optimization method for secure communication of Bluetooth chip devices, the integration process of channel stability evaluation and dynamic noise baseline calculation relies on multi-dimensional data fusion technology. In the specific operation, the historical communication period is divided into adaptive time windows, and the window length is dynamically adjusted according to the communication data volume to match the periodic changes in load. In each time window, the packet loss rate is obtained from the transmission layer confirmation mechanism, and the controllable and uncontrollable packet loss is distinguished; the signal strength fluctuation value is obtained by calculating the standard deviation of the received signal strength indication, and the influence of power adjustment caused by device power saving is excluded. A linear regression model is used to fit the packet loss rate change curve in each window, the model uses the least squares method to estimate the parameters, and the goodness of fit threshold is set to 0.8, and when it is insufficient, a high-order polynomial backup algorithm is enabled. Calculate the slope difference of adjacent window fitting curves, introduce the Euclidean distance metric and time decay factor, and give higher weight to recent windows. Combine the weighted sum of signal strength fluctuation value and slope difference to generate local stability coefficient, and the weight coefficient is dynamically adjusted through historical data training, and the signal strength weight increases in high interference environment. The local stability coefficients of all windows are calculated by sliding average, the window size can be configured, the double buffer mechanism is used to avoid boundary effects, and the channel stability index is output. At the same time, the dynamic noise baseline calculation is realized by frequency domain transformation of the interference intensity sequence, and Hanning window is applied before transformation to reduce spectrum leakage, and the sampling rate meets the Nyquist criterion. Extract the energy distribution map of the characteristic frequency band, and the characteristic frequency band corresponds to the Bluetooth 2.4GHz channel and its harmonics, and use the Welch average periodogram method to generate the map. Identify the burst interference pulses in the map that exceed the dynamic threshold, set the minimum duration threshold to filter transient noise, and the pulse identification includes front edge detection and back edge detection. Calculate the duration and interval period of the pulses, and use a high-precision timer to measure, with a precision of microseconds. According to the ratio relationship between the duration and the interval period, an adaptive updating model of the dynamic noise baseline is established, and the model uses the exponential weighted moving average algorithm, and the weight of new observation value is higher than that of historical value.

[0077] In the candidate policy subset, remove the policy items with a success rate lower than the threshold value in the mapping relationship table, and dynamically set the threshold value according to the security requirements of the application scenario. The removal operation iterates through each policy item in the candidate policy subset, and queries the mapping relationship table to obtain the historical success rate thereof. Generate an effective policy set, which contains all the policy items that pass the threshold screening. The generation of the set is completed at one time by using list comprehension, avoiding multiple iterations. According to the sensitivity of each policy item in the effective policy set to the channel stability index, calculate the policy priority weight. The sensitivity is measured by the success rate change rate of the policy under different stability conditions, and the change rate is calculated by using the derivative method. Arrange the effective policy set in the order from high to low according to the policy priority weight, generate a policy execution queue, and arrange the algorithm by using quicksort. The head of the queue stores the high-weight policy.

[0078] Obtain the current fluctuation amplitude of the dynamic noise baseline. The fluctuation amplitude is obtained by calculating the variance of the dynamic noise baseline in the last several sampling periods. The variance calculation uses an unbiased estimation formula. Determine the encryption strength adjustment step size according to the fluctuation amplitude. The determination process uses a piecewise linear function to map the fluctuation amplitude value to the step size value. Select the first to-be-executed policy in the policy execution queue. The selection operation is achieved by reading the queue head pointer. The pointer locates the policy configuration storage address. Read the initial encryption strength threshold and the maximum allowed strength value of the first to-be-executed policy. The read operation accesses the policy configuration database. The database uses a relational model to store the strength parameters. Increment or decrement the initial encryption strength threshold by using the encryption strength adjustment step size. The modification direction is determined according to the change trend of the dynamic noise baseline. The trend analysis uses linear regression. Make the modified threshold not exceed the maximum allowed strength value. The boundary check is performed after each modification operation. When it exceeds the limit, it is truncated to the boundary value. Repeat the above modification operation for the remaining policy items in the policy execution queue. The repetition process uses a loop structure to traverse the queue. The loop termination condition is that the queue is empty.

[0079] The mapping relationship table is constructed by using a machine learning algorithm. The training features are the discrete level labels of the channel stability index. The training target is the statistical value of the policy execution success rate. The success rate threshold is set considering the communication interruption risk caused by policy execution failure. A higher threshold is set for high-risk applications. The threshold setting formula is:

[0080]

[0081] wherein: represents the final adopted dynamic threshold value, represents the basic threshold value, Indicates the risk coefficient. This represents the variance of historical success rates. During the generation of the effective strategy set, deduplication is performed to avoid the same strategy appearing multiple times; deduplication is based on the hash value of the strategy identifier. A time decay factor is introduced into the calculation of strategy priority weights, with more recent success rate data having higher weights; the decay factor uses an exponential function. The strategy execution queue is arranged considering the dependencies between strategies; dependent strategies are kept consecutively, and dependencies are resolved from the strategy configuration file.

[0082] The calculation window for fluctuation amplitude is synchronized with the dynamic noise baseline update cycle, and the window boundaries are aligned with the baseline update time point to ensure the timeliness of data acquisition. The piecewise linear function parameters for adjusting the encryption strength step size are determined experimentally, and the function inflection point is dynamically adjusted according to the device type to achieve personalized configuration. The selection of the first policy to be executed adds validity verification, confirming policy compatibility by querying the hardware capability database to avoid resource conflicts. The initial encryption strength threshold read operation is protected by a mutex lock to prevent multi-threaded concurrent access issues and ensure data consistency. The encryption strength threshold correction operation is executed atomically to ensure that the correction process is uninterrupted and the results take effect immediately. The maximum allowable strength value is set with both soft and hard boundaries. The soft boundary allows temporary over-limit and triggers alarms, while the hard boundary strictly limits to prevent system overload. The mapping relationship table triggers incremental updates after policy execution, and new data is smoothly integrated into the historical records. The success rate threshold is dynamically adjusted according to the network security status, and the status assessment uses a multi-indicator weighted score. The effective policy set is maintained through an LRU caching mechanism, and a fixed-size cache automatically evicts idle policies. The calculation of policy priority weights introduces a complexity factor, and the weight of complex policies is increased accordingly. The strategy execution queue supports priority preemption, allowing high-priority strategies to be inserted in the middle of the queue. Fluctuation amplitude calculations utilize spectral analysis to filter periodic interference, and the encryption strength adjustment step size is optimized based on historical performance. The first executed strategy is equipped with a failover mechanism. The initial encryption strength threshold is optimized through caching and version management, and operation logs are corrected. The maximum allowable strength value is set differently according to device specifications to ensure stable system operation.

[0083] The query of the mapping relationship table is optimized by B+ tree index, the index field is channel stability level, the success rate threshold is seasonally adjusted according to network load, and the adjustment period is pre-configured. The effective strategy set is stored by using bitmap encoding compression, and the compression algorithm uses run-length encoding. The strategy priority weight is dynamically updated according to real-time channel conditions, and the update period is fixed. The strategy execution queue realizes multi-core load balancing through a polling algorithm. The fluctuation amplitude calculation adopts pipeline processing, including data sampling, variance calculation and result output three stages. The encryption strength adjustment step is realized by fuzzy control, and the fuzzy rule supports dynamic configuration. The first to be executed strategy uses a preloading mechanism to reduce delay. The initial encryption strength threshold is stored by using the AES algorithm. The threshold is modified and verified by analog operation. The maximum allowed strength value is gradually improved with the performance of the device. The mapping relationship table is stored in a distributed manner by using range sharding strategy. The success rate threshold is set by referring to similar devices through collaborative filtering algorithm. The effective strategy set is quickly retrieved by using hash table. The strategy priority weight provides a visual debugging interface. The strategy execution queue sets a regular recovery point to realize fault tolerance processing. The fluctuation amplitude anomaly detection uses the Isolation Forest algorithm to mark abnormal values. The encryption strength adjustment step is optimized for long-term benefits through dynamic programming. The first execution strategy monitors the load according to the CPU usage. The initial encryption strength threshold is optimized by using a genetic algorithm. The encryption strength threshold realizes distributed consensus through the Paxos algorithm. The maximum allowed strength value is limited by the physical hardware limit. The mapping relationship table realizes a differential backup mechanism. The success rate threshold is adaptively learned by using the gradient descent algorithm. The effective strategy set is version-controlled by using the Git model. The strategy priority weight is trained by multiple devices through federated learning. The strategy execution queue uses the priority inheritance protocol to avoid priority inversion.

[0084] The fluctuation amplitude analysis realizes multi-resolution analysis by using wavelet transform, and the encryption strength adjustment step is learned by using Q-learning algorithm. The first execution strategy is selected by using LSTM model prediction. The initial encryption strength threshold is protected by using Shamir secret sharing scheme. The encryption strength threshold is updated by using Paillier homomorphic encryption. The maximum allowed strength value is verified by using a trusted execution environment. The mapping relationship table stores the relationship structure by using a graph database. The success rate threshold realizes multi-party equilibrium by using game theory. The effective strategy set handles the partial order relationship by using topological sorting. The strategy priority weight dynamically adjusts the feature attention degree by using attention mechanism. The strategy execution queue is analyzed by using M / M / 1 model. The fluctuation amplitude modeling uses Caputo fractional differential. The encryption strength adjustment step is optimized by using stochastic gradient descent. The first execution strategy is optimized by using quantum computing. The initial encryption strength threshold is protected by using differential privacy technology. The encryption strength threshold is stored in a distributed manner by using blockchain. The maximum allowed strength value is bound to the device fingerprint by using PUF function.

[0085] Embodiment 4: Real-time acquisition of current channel state parameters, including instantaneous bit error rate and signal attenuation slope, is achieved through the physical layer monitoring module of the Bluetooth baseband chip. The sampling frequency is synchronized with the data packet transmission period. The instantaneous bit error rate is compared with the dynamic noise baseline. The comparison algorithm calculates the absolute difference and the percentage deviation of the dynamic noise baseline. The percentage deviation value is stored in the ring buffer to record the historical comparison results. When the difference exceeds the first switching threshold, the primary strategy switching is started. The first switching threshold is set according to the communication reliability requirements. The threshold parameters are stored in the strategy configuration database. After the primary strategy switching, the change trend of the signal attenuation slope is detected. The change trend analysis uses a sliding window linear fitting. The fitting window size matches the channel coherence time. When the change trend continues to deteriorate, the secondary strategy switching is triggered. The continuous deterioration condition requires that the negative change rate of the signal attenuation slope exceeds the threshold value for three consecutive sampling periods. Record the channel state parameters and the executed strategy identifier during the strategy switching process. The recorded data is stored in a structured format, including a timestamp, a parameter vector, and a strategy identifier.

[0086] The candidate strategy items with encryption strength thresholds lower than the current value are selected from the strategy execution queue. The selection conditions include strategy compatibility check and resource availability verification. The selection results generate a candidate strategy list. The average execution success rate and switching time of each candidate strategy item in the historical communication period are calculated. The average execution success rate is calculated using a weighted moving average. The switching time is calculated from the strategy activation to the encryption readiness. The candidate strategy with the highest average execution success rate and the shortest switching time is selected as the primary switching target. The selection algorithm uses multi-objective optimization Pareto frontier solution. In case of conflict, the success rate is prioritized. The data encryption process of the current strategy is suspended. The encryption context state is saved to the secure storage area. The suspension signal is delivered through the interrupt mechanism. The strategy configuration of the primary switching target is loaded and the encryption session key is reset. The strategy configuration is loaded from the strategy library to the memory. The session key is generated using an enhanced key derivation function.

[0087] Referring to Table 1, the next order strategy item of the current execution strategy in the strategy execution queue is located. The positioning algorithm traverses the queue linked list structure. The order is determined based on the priority weight ordering result. The matching degree of the hardware compatibility parameters of the next order strategy item and the current channel state parameters is verified. The matching degree is calculated using a multi-dimensional feature cosine similarity algorithm. The similarity threshold is dynamically adjusted. When the matching degree meets the preset condition, the encryption strength threshold of the next order strategy item is raised to the preset security level. The preset security level corresponds to the security requirements of high reliability application scenarios. The data encryption channel is reinitialized using the raised encryption strength threshold. The reinitialization process includes password algorithm reset and key material injection. The initialization completion signal is notified through the callback function.

[0088] Table 1: Policy switching threshold parameter comparison table

[0089]

[0090] The collection of instantaneous bit error rate uses the statistical counter of the forward error correction module, the counter value is sampled every millisecond, and the sampling value is processed by digital filtering. The calculation of signal attenuation slope uses the least square method to fit the latest ten signal strength sampling points, and the fitted slope value is converted into percentage change rate for storage. The comparison operation of dynamic noise baseline sets the hysteresis interval to avoid frequent switching caused by parameter jitter near the threshold, and the width of the hysteresis interval is configurable. The hierarchical management of the first switching threshold corresponds to the quality of service requirements of different service types, the service level is read from the configuration file, and the level division standard is based on delay sensitivity. The detection algorithm of change trend adds confidence evaluation, low confidence trend needs additional verification period, confidence calculation is based on fitting residual. The judgment condition of continuous deterioration considers the device motion state, the motion state is judged by the inertial measurement unit data, and the motion compensation algorithm eliminates false deterioration. The data structure of policy switching record adds a checksum field, which is used to detect the integrity of the record, and the damaged record is automatically repaired. The screening process of the alternative policy item performs policy dependency relationship check, the dependent policy must meet the screening condition at the same time, and the dependency relationship graph is stored in a directed acyclic graph. The calculation of average execution success rate distinguishes different channel condition scenarios, and the scenario classification is based on the clustering results of historical channel state, and the scenario label is attached with a success rate weight. The statistics of switching time consumption includes policy configuration loading time and key negotiation time, and the time measurement uses a high-precision performance counter. The selection algorithm of primary switching target realizes multi-target optimization, the target function weighted sum generates a comprehensive score, and the weight coefficient is adjusted according to the business demand. The suspension of data encryption process uses atomic operation to ensure state consistency, the atomic operation is realized by hardware memory barrier, and the suspension point is selected at the data packet boundary. The loading process of policy configuration verifies the digital signature to prevent tampering, the signature algorithm uses elliptic curve digital signature, and the certificate chain verification is complete. The reset of session key follows the principle of forward security, the new key has no mathematical correlation with the old key, and the key derivation uses temporary exchange parameters.

[0091] The positioning of the next order policy item realizes a fast jump mechanism, the queue node stores front and back pointers, and the positioning operation time complexity is constant level. The verification of the hardware compatibility parameter includes processor architecture checking instruction set support, and the instruction set test passes through the feature identification register reading. The multi-dimensional features of the matching degree calculation include channel bandwidth utilization and antenna configuration parameters, and the feature vector normalization processing eliminates the dimension influence. The mapping relationship of the preset security level is stored in the security policy database, the level definition refers to the industry security standard, and the standard version is updated regularly. The promotion operation of the encryption strength threshold adopts a ladder adjustment, one security level is adjusted each time, and the level interval is fixed as a security strength unit. The re-initialization of the data encryption channel executes a two-way handshake protocol, a handshake timeout mechanism prevents initialization suspension, and the timeout value is dynamically calculated. The collection data of the instantaneous bit error rate calibrate the receiver sensitivity, the sensitivity parameter is from the device calibration table, and the calibration table is updated regularly. The calculation of the signal attenuation slope excludes the influence of adaptive adjustment of the antenna gain, and the gain control signal is used as a reference input. The setting of the hysteresis interval adopts adaptive width adjustment, the interval width is negatively related to the channel change rate, and the rate measurement uses derivative calculation. The classified management of the service level supports dynamic reclassification, the reclassification event is triggered by the application layer service type change, and the event notification uses the observer mode. The threshold learning of the confidence assessment is trained by historical data, and the training features include the joint distribution of signal strength and bit error rate. The algorithm of motion state compensation fuses multi-sensor data, including accelerometers and gyroscopes, and the fusion algorithm uses Kalman filtering. The design of the record data structure supports fast query, the query index is established on the timestamp field, and the index type is B+ tree.

[0092] The generation of the alternative strategy list optimizes query performance, query conditions are pushed to the database engine for execution, and the database uses indexes to optimize query plans. The clustering algorithm for scenario classification uses K-means clustering, the number of cluster centers is determined according to the elbow rule, and feature standardization is performed. The use of performance counters calibrates clock drift, and clock synchronization between multi-core processors is achieved through timestamp counters. The generation of the Pareto solution set for multi-objective optimization uses the non-dominated sorting algorithm, and the size of the solution set is limited to the top ten optimal solutions. The implementation of the hardware memory barrier relies on processor-specific instructions, and the instruction sequence ensures memory access order consistency. The construction of the certificate chain for digital signature verification starts from the root certificate, the root certificate is preloaded in the secure storage area, and the certificate revocation list is checked regularly. The generation of temporary exchange parameters uses a true random number generator, the random number entropy source comes from a hardware noise source, and the entropy quality test is performed continuously. The pointer maintenance of the queue jump mechanism uses atomic update, the pointer update uses the compare-and-swap instruction to avoid concurrent modification problems. The coverage of the instruction set test includes encryption extension instructions, and the extension instruction detection is implemented through feature bit scanning. The normalization method of the feature vector selects the min-max scaling, and the scaling parameters are obtained from the training data statistics. The update of the security standard version supports smooth transition, and the old standard policy is compatible during the transition period, and the transition period length is configurable. The definition of the security strength unit is based on the key length of the encryption algorithm, and the unit conversion table stores the equivalent strength of different algorithms. The implementation of the handshake protocol uses a three-way handshake process, the handshake message is encrypted for transmission, and the message integrity check uses a message authentication code.

[0093] The calibration of the instantaneous bit error rate acquisition system uses a standard signal source, and the calibration process is completed in the factory test stage, and the calibration data is written into the read-only memory. The timing alignment of the signal strength sampling point uses an interpolation algorithm, the interpolation method selects linear interpolation, and the sampling clock is synchronized with the global clock. The adaptive adjustment algorithm of the hysteresis interval uses fuzzy control, the input variable is the channel parameter change rate, and the output variable is the interval width. The detection of service type change is through deep packet detection technology, and the detection features include protocol header information, and the feature library is updated regularly. The training data acquisition of joint distribution covers typical application scenarios, including indoor, outdoor and mobile states, and the data labeling is completed manually. The parameter adjustment of Kalman filter is based on sensor accuracy index, the index comes from sensor data manual, and the filter initial value is self-calibrated. The optimization of record query is implemented by cache mechanism, the hot query results are cached to memory, and the cache invalidation strategy is based on time driving. The optimization of database query plan uses statistical information, the statistical information includes data distribution histogram, and the histogram is reconstructed regularly. The execution of elbow rule automatically determines the optimal cluster number, the rule index calculates the within-cluster sum of squares, and the inflection point detection uses second-order difference. The synchronization of timestamp counter uses network time protocol, the protocol corrects clock drift, and the correction period is adaptively adjusted. The algorithm optimization of non-dominated sorting uses fast non-dominated sorting, and the sorting time complexity is reduced to O(NlogN). The access control of secure storage area is based on hardware security domain, the security domain isolates different application data, and domain switching requires privileged instructions.

[0094] In the key derivation algorithm and authentication protocol type in the final security policy configuration, the key derivation algorithm field identifier is KDF_AES_256, and the authentication protocol type field value is SC_3_0. According to the key derivation algorithm, the derivation parameter combination of the master key and the temporary session key is generated, and the master key derivation uses the device unique identifier as the input seed. According to the authentication protocol type, a two-way identity authentication process is established, and the two-way identity authentication process adopts the elliptic curve digital signature algorithm. After verification, the data encryption channel is activated, and the data encryption channel adopts the AES-GCM mode. The key update period and the authentication validity period in the encryption channel are continuously monitored, and the key update period is set to 3600 seconds. An automatic renewal request is initiated before expiration, and the automatic renewal request is triggered 300 seconds before expiration. The analysis of the key derivation algorithm verifies the digital signature, and the signature of the configuration file uses the RSA-2048 algorithm. The analysis of the authentication protocol type checks the version compatibility, and the backward compatible mode is enabled when the protocol version is lower than 4.0. The master key derivation parameter combination includes the key usage identifier, and different keys for different purposes use different derivation paths. The derivation parameters of the temporary session key add context information, and the context information includes the device type and the session identifier. The implementation of the two-way identity authentication process complies with the FIPS196 standard, and the randomness of the challenge code is tested by entropy. The activation of the data encryption channel tests the encryption function, and the test sends known plaintext to verify the correctness of encryption and decryption.

[0095] The monitoring of the key update period employs multiple redundant timers, the master timer being a hardware counter. The checking of the authentication validity period combines the device system clock and the network time protocol. The encryption of the automatic renewal request uses the current session key, the request message containing new key agreement parameters. The failure handling of the renewal procedure attempts multiple retransmissions with exponential backoff of the retransmission interval. The key switch after a successful renewal employs a smooth transition, the old key being discarded after 10 seconds of parallel use with the new key. The parameter verification of the key derivation algorithm includes a check of the algorithm strength, algorithms with insufficient strength being marked. The parsing of the authentication protocol type processes the protocol extension field, the extension field indicating optional security enhancements. The hierarchical structure of the master key derivation path supports multiple levels of key derivation. The derivation of the temporary session key incorporates a forward security mechanism, a new random number being used for each derivation. The timeout handling mechanism of the two-way authentication procedure, the connection being terminated in case of an authentication not completed within the timeout. The activation sequence of the data encryption channel first negotiating the parameters and then initializing the engine. The strength testing of the key derivation algorithm performs cryptographic test vector validation. The version checking of the authentication protocol type ensures that interconnected devices use the same protocol version. The protection of the master key derivation parameters uses secure hardware storage. The derivation of the temporary session key records an audit log, the log containing the key usage and the derivation timestamp. The certificate verification of the two-way authentication follows the X.509 standard. The performance monitoring of the data encryption channel measures the throughput and the latency.

[0096] The selection of the key derivation algorithm considers the device computing power. The configuration of the authentication protocol type supports multiple protocols coexistence. The storage of the master key adopts decentralized storage, and part of the key components is memorized by the user. The derivation of the temporary session key uses a deterministic random number generator. The auxiliary channel of the two-way identity verification uses a visual or audio channel. The key update of the data encryption channel adopts a proactive push method. The implementation of the key derivation algorithm is certified by the payment industry security. The parameter configuration of the authentication protocol type is protected by the security policy. The generation of the master key is completed within the secure element. The derivation of the temporary session key uses a hardware cryptographic engine. The biometric integration of the two-way identity verification uses fingerprint or facial recognition as an auxiliary authentication factor. The key update of the data encryption channel is bound with the transaction. The real-time testing of the key derivation algorithm measures the algorithm execution time. The optimization of the authentication protocol type reduces the handshake round. The update of the master key is synchronized with the device maintenance cycle. The derivation of the temporary session key considers the deterministic needs of the control system. The certificate design of the two-way identity verification contains device lifecycle information. The error code tolerance mechanism of the data encryption channel ensures system reliability. In the specific implementation process, the key derivation algorithm in the final security policy configuration is parsed as PBKDF2 when the Bluetooth smart lock is paired with the phone. The master key is generated by the smart lock in combination with the MAC address and the manufacturer's certificate hash value. The temporary session key derivation uses elliptic curve point multiplication to calculate the shared key. The two-way identity verification adopts a timestamp challenge mechanism, and the AES-CCM encryption channel is activated after verification. The key update period is set to 3580 seconds, and the automatic renewal request is initiated before expiration. The master key is generated by the HMAC-Based KDF algorithm in the heart rate monitor scene of the medical device. The temporary session key derivation performs 1000 iterations to enhance security. The two-way identity verification adopts a certificate chain verification mechanism. The encryption channel uses the AES-128-GCM algorithm to protect patient data. The key validity period monitoring uses a hardware timer to ensure continuous secure transmission of medical data.

[0097] Industrial Internet of Things gateway uses SM2 algorithm for key derivation. Sensor nodes use identity-based authentication protocol. Dynamic token authentication mechanism ensures real-time security of industrial control systems. Encryption channel uses lightweight algorithm to meet resource-constrained environment requirements. In vehicle-to-everything communication, the on-board unit generates a master key combined with GPS location information. Temporary session keys are bound to traffic event data to ensure key uniqueness. Digital certificate verification mechanism ensures V2X communication security. Key update strategy is dynamically adjusted according to message criticality. Smart home system uses lightweight key derivation algorithm. PIN code authentication mechanism transmits verification information through auxiliary channel. Device pairing code is combined with network identifier to generate master key. Encryption instructions use efficient algorithms to ensure smart device response speed. Mobile payment terminal follows PCI standard for key management. Three-level certificate system ensures payment transaction security. Transaction serial number is combined with random number to generate session key. Biometric authentication enhances payment system security. Industrial control system uses dedicated encryption algorithm to meet real-time requirements. Control parameters are associated with key material to ensure system determinism. Two-way digital certificate contains device function permission information. Lightweight encryption algorithm ensures security while meeting control timeliness requirements.

[0098] It should be noted that the relational terms herein, such as first and second, and the like, are used solely to distinguish one from another entity or action without necessarily requiring or implying any actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus.

[0099] While embodiments of the present application have been shown and described herein, it is understood that various modifications, alternatives, permutations, and variations of these embodiments can be made and employed by those skilled in the art without departing from the principles and spirit of the application, which is defined by the following claims and their equivalents.

Claims

1. An optimized method for secure communication in Bluetooth chip devices, characterized in that, Includes the following steps: Identify the device type identifier and protocol version characteristics in the current Bluetooth communication link, extract the hardware capability parameters of the target Bluetooth chip based on the device type identifier, and generate an initial security policy set based on the protocol version characteristics; The channel quality data and interference intensity sequence of the target Bluetooth chip during historical communication cycles are collected. The channel quality data is segmented and fitted to obtain the channel stability index. The dynamic noise baseline is calculated by combining the interference intensity sequence. A subset of candidate policies is selected based on the matching degree between hardware capability parameters and the initial security policy set. The candidate policy subsets are then prioritized using channel stability indicators to generate a policy execution queue. The encryption strength threshold of each security policy in the policy execution queue is adjusted based on the dynamic noise baseline. The policy execution queue is iteratively optimized based on the adjusted encryption strength threshold, and the final security policy configuration is output. When establishing a communication connection with the target Bluetooth chip, the final security policy configuration is loaded and channel status changes are monitored in real time. When the channel status changes exceed the preset tolerance, a dynamic policy switching mechanism is triggered.

2. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The step of extracting the hardware capability parameters of the target Bluetooth chip based on the device type identifier includes: Parse the manufacturer code and chip model fields in the device type identifier, and index the corresponding processor frequency and memory capacity from the pre-built hardware capability database; The target Bluetooth chip's currently supported encryption algorithm types and key length range are detected, and a hardware capability parameter matrix is ​​generated by combining the processor's clock speed and memory capacity. The hardware capability parameter matrix is ​​normalized to obtain a quantitative scoring vector for the hardware capability parameters.

3. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The process of segmenting and fitting the channel quality data to obtain the channel stability index includes: The historical communication period is divided into multiple time windows of equal length, and the packet loss rate and signal strength fluctuation value of the channel quality data are extracted in each time window. Linear regression models were used to fit the packet loss rate change curves within each time window, and the slope difference of the fitted curves between adjacent time windows was calculated. The local stability coefficient for each time window is generated by weighting the signal strength fluctuation value and the slope difference. The local stability coefficients for all time windows are calculated using a moving average, and the channel stability index is output.

4. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The calculated dynamic noise baseline includes: Perform frequency domain transformation on the interference intensity sequence to extract the energy distribution spectrum of the characteristic frequency bands; Identify sudden interference pulses exceeding a preset threshold in the energy distribution spectrum, and statistically analyze the duration and interval of the sudden interference pulses. An adaptive update model for the dynamic noise baseline is established based on the ratio of duration to interval period.

5. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The step of prioritizing the candidate strategy subset using channel stability indicators includes: Establish a mapping table between channel stability indicators and the success rate of security policy execution; Remove strategy items with a success rate below the threshold from the mapping table in the candidate strategy subset to generate a valid strategy set; Calculate the policy priority weights based on the sensitivity of each policy item in the effective policy set to channel stability indicators; The effective policy set is arranged in descending order of policy priority weight, and a policy execution queue is generated.

6. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The encryption strength thresholds for each security policy in the adjustment policy execution queue include: Obtain the current fluctuation amplitude of the dynamic noise baseline, and determine the step size for adjusting the encryption strength based on the fluctuation amplitude; Select the first policy to be executed from the policy execution queue and read its initial encryption strength threshold and maximum allowed strength value; The initial encryption strength threshold is adjusted by increasing or decreasing the encryption strength adjustment step size so that the adjusted threshold does not exceed the maximum allowable strength value. Repeat the above correction operation on the remaining policy items in the policy execution queue until all policy items in the queue have been adjusted.

7. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The dynamic switching mechanism for the triggering strategy includes: Real-time acquisition of current channel state parameters, including instantaneous bit error rate and signal attenuation slope; The instantaneous bit error rate is compared with the dynamic noise baseline, and the primary strategy handover is initiated when the difference exceeds the first handover threshold. After the primary strategy switch, the changing trend of the signal attenuation slope is detected, and the secondary strategy switch is triggered when the changing trend continues to deteriorate. Record channel state parameters and execution policy identifiers during the policy switching process, and update historical communication cycle data.

8. The optimization method for secure communication of Bluetooth chip devices according to claim 7, characterized in that, The initial strategy switching includes: Select alternative policy items whose encryption strength threshold is lower than the current value from the policy execution queue; Calculate the average success rate and switching time of each alternative strategy item within the historical communication cycle; Select the alternative strategy with the highest average success rate and the shortest switching time as the primary switching target; Pause the current policy's data encryption process, load the policy configuration of the primary switching target, and reset the encryption session key.

9. The optimization method for secure communication of Bluetooth chip devices according to claim 7, characterized in that, The triggering of the secondary policy switch includes: Locate the next policy item in the policy execution queue that is currently executing the policy; Verify the matching degree between the hardware compatibility parameters of the next priority policy item and the current channel state parameters; When the matching degree meets the preset conditions, the encryption strength threshold of the next priority policy item will be increased to the preset security level; The data encryption channel is reinitialized using the increased encryption strength threshold to complete the secondary strategy switch.

10. The optimization method for secure communication of Bluetooth chip devices according to claim 1, characterized in that, The loading of the final security policy configuration includes: Analyze the key derivation algorithm and authentication protocol type in the final security policy configuration; The derivation parameter combination of the master key and the temporary session key is generated according to the key derivation algorithm; Establish a two-way authentication process according to the authentication protocol type, and activate the data encryption channel after successful authentication; Continuously monitor the key update cycle and authentication validity period in the encrypted channel, and initiate an automatic renewal request before expiration.

Citation Information

Patent Citations

  • Control method based on intelligent voice mouse and intelligent voice mouse

    CN117292688A

  • Bluetooth connection method and system

    CN120201398A