Dedicated communication encryption processing system based on 2.4G frequency band
By monitoring link status in real time and dynamically adjusting key access strategies in a dedicated communication encryption processing system in the 2.4GHz band, the problems of unstable communication links and key negotiation failures are solved, achieving efficient and secure communication encryption processing, adapting to dynamic networking requirements and reducing communication overhead.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-07
- Publication Date
- 2026-04-03
AI Technical Summary
Existing dedicated communication systems in the 2.4GHz band suffer from unstable communication link quality, frequent key negotiation failures, and difficulties in adapting to dynamic networking and long-term security requirements when faced with problems such as channel congestion, multiple interference sources, and rapid signal attenuation. Furthermore, existing encryption schemes are unable to adapt to dynamic networking and long-term security needs and lack adaptive optimization capabilities.
A dedicated communication encryption processing system based on the 2.4G frequency band is adopted, including an impact assessment module, a baseline deformation generation module, a residual deformation learning module, and a fusion and closed-loop correction module. Random numbers are generated through a quantum key distribution device, and key screening and management are carried out in combination with a hardware security module. The key access strategy is dynamically adjusted, a multi-layer key management structure is established, the link status is monitored in real time, and a dynamic thread pool is used for multicast key distribution to achieve adaptive adjustment and protection.
It ensures a high success rate of key negotiation and communication continuity under fluctuating link conditions, achieves forward and backward security, improves key synchronization efficiency and system scalability in large-scale multicast scenarios, and reduces communication overhead.
Smart Images

Figure CN121463028B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication security cryptography technology, and more specifically, to a dedicated communication encryption processing system based on the 2.4G frequency band. Background Technology
[0002] The 2.4GHz band, as a globally universal unlicensed ISM band, is widely used in dedicated wireless communications in fields such as the Internet of Things, industrial control, and medical monitoring due to its advantages of easy deployment and low cost. However, this band also suffers from problems such as channel congestion caused by multiple devices sharing the band, including Wi-Fi and Bluetooth, multiple interference sources, and rapid signal attenuation, resulting in unstable and frequent fluctuations in communication link quality. This instability poses a severe challenge to traditional encrypted communication systems that rely on fixed negotiation protocols, often leading to key negotiation failures, communication interruptions, or performance degradation.
[0003] At the security level, dedicated communication systems typically transmit critical industrial data or sensitive medical information, requiring extremely high confidentiality and integrity. Existing encryption schemes are mostly based on traditional public key infrastructures (PKIs) or pre-shared key mechanisms; the former suffers from low negotiation efficiency in 2.4GHz fluctuating links and faces the risk of being cracked by future quantum computing; the latter suffers from rigid key management and a lack of forward security, making it difficult to adapt to dynamic networking and long-term security needs. Especially in multicast communication scenarios, how to efficiently and securely distribute and update keys in large-scale multicast groups with dynamically changing members, while controlling the resulting network overhead, remains a challenge that current technologies have not adequately addressed.
[0004] In addition, most existing systems use statically configured security parameters and policies, lacking the ability to dynamically adjust according to the actual operating environment such as link conditions, multicast status, and security threats. After deployment, the system cannot adaptively optimize and often responds slowly when the link deteriorates or is attacked, making it difficult to maintain the best balance between security and communication efficiency.
[0005] To address the above problems, this invention proposes a solution. Summary of the Invention
[0006] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a dedicated communication encryption processing system based on the 2.4G frequency band to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides the following technical solution:
[0008] A dedicated communication encryption processing system based on the 2.4G frequency band includes: an impact assessment module, a baseline deformation generation module, a residual deformation learning module, and a fusion and closed-loop correction module, with signal connections between the modules;
[0009] Key system construction module: Random numbers are generated through quantum key distribution equipment, and the error rate and randomness are judged by hardware security module to screen qualified keys and distinguish them into working key pool and encryption key pool. Based on the link stability index and packet error rate calculation results, time threshold and update criteria are set to form a multi-layer key management structure with forward security, providing secure input for the subsequent session layer.
[0010] Link adaptation session module: acquires communication data between the terminal and the peer, calculates the link stability index and packet error rate, obtains the smoothing index using the moving average, and divides the link status into three categories: stable, normal and poor according to the threshold. For each corresponding status, a session key is established using three methods: wireless channel characteristics, quantum-resistant encapsulation and pre-set key. The derivation and update are completed according to the criteria.
[0011] Multicast key management module: Monitors multicast member changes and time thresholds, establishes a dual-criteria update mechanism, generates and encapsulates a new multicast key when the member change count or time threshold meets the triggering conditions, uses a dynamic thread pool to achieve concurrent distribution of multiple members, and calculates scaling conditions through task load and thread utilization to ensure distribution synchronization and resource matching.
[0012] Adaptive adjustment protection module: During the monitoring period, it acquires four types of indicators: link quality, multicast status, thread performance, and security events. It calculates parameters such as fluctuation coefficient, member change rate, and abnormal growth rate, compares their respective thresholds and performs calibration. When the indicators are stable, it extends the key validity period. When the fluctuation increases, it shortens the threshold and adjusts the thread scale. At the same time, when the abnormal accumulation reaches the criterion, it triggers enhanced protection and identity authentication upgrade.
[0013] In a preferred embodiment, the key system construction module includes the following steps:
[0014] The dual threshold determination of bit error rate and randomness for qualified keys includes:
[0015] The key sequence is filtered by bit error rate; if the bit error rate is greater than the bit error rate threshold, it is deemed unqualified.
[0016] Randomness verification is performed, and if the entropy value is lower than the randomness threshold, it is deemed unqualified.
[0017] A hash function is used to calculate a digest for integrity verification; if the digest is inconsistent, the integrity is deemed invalid.
[0018] Based on the link conditions, three methods are selected to obtain shared random materials, including:
[0019] Key exchange based on the physical characteristics of wireless channels: when the link stability index is higher than the high threshold and the packet error rate is less than or equal to the maximum allowable value, both parties synchronously collect the received signal strength of the link, normalize and adaptively quantize the sampled sequence to obtain the bit string, exchange hash digests to verify consistency, and obtain shared random material through privacy amplification.
[0020] Based on quantum-resistant cryptography key encapsulation, when the link stability index is between high and low thresholds, the terminal generates a quantum-resistant public-private key pair, the peer uses the public key to encapsulate the shared random material, and after transmission, the terminal decapsulates to obtain the shared material.
[0021] Pre-set key access: When the link stability index is below the low threshold or the packet error rate exceeds the maximum allowable value, the pre-set key is used as shared random material.
[0022] In a preferred embodiment, the link adaptation session module includes the following steps:
[0023] The link status is determined based on the high and low thresholds of the link stability index and the maximum allowable packet error rate, and the link status is divided into three categories: stable status, normal status and poor status.
[0024] Based on shared random materials, session keys, working keys, and key encryption keys are derived separately through key derivation functions. The uses of the three keys are isolated, and their activation time and effective time threshold are marked respectively.
[0025] In a preferred embodiment, the multicast key management module includes the following steps:
[0026] The dual-criteria update mechanism includes:
[0027] Time threshold update criterion: Triggered when the current time is greater than the sum of the key activation time and the time threshold;
[0028] Member change threshold update criterion: Triggered if the cumulative number of member changes is greater than or equal to the member change threshold when the time threshold is not met;
[0029] The threshold for member changes is calculated based on the multicast group size and adjustment factor.
[0030] A dynamic thread pool is used for key distribution, and its scaling conditions are calculated based on task load and thread utilization, including:
[0031] When the thread utilization rate is higher than the high utilization threshold, the task load is higher than the high load threshold, and the current total number of threads is less than the maximum number of threads, the number of threads will be increased according to the preset rules.
[0032] When the thread utilization rate is lower than the low utilization rate threshold and the current total number of threads is greater than the initial number of threads, the number of threads is reduced according to the preset rules.
[0033] In a preferred embodiment, the adaptive adjustment protection module includes the following steps:
[0034] The four types of indicators obtained include:
[0035] Link quality metrics include smoothed link stability index, packet error rate, and link fluctuation coefficient;
[0036] Multicast status metrics include member change count, member change rate, and multicast key update frequency;
[0037] Thread pool performance metrics include task load, thread utilization, and average task processing time.
[0038] Security incident indicators, including anomaly count and anomaly rate;
[0039] The calibration process, based on the comparison between the indicators and thresholds, includes:
[0040] When the link quality indicators are stable, extend the effective time threshold of the working key and the key encryption key.
[0041] When the link fluctuation coefficient exceeds the fluctuation threshold and the abnormal event growth rate exceeds the growth rate threshold, shorten the effective time threshold of the session layer key and the key pool key, and lower the adjustment factor of the multicast member change threshold.
[0042] When the anomaly count exceeds the abnormal high threshold for multiple consecutive monitoring periods, the enhanced protection mode is triggered, and the linkage handling process includes:
[0043] Immediately trigger the key update process to replace the currently used keys;
[0044] Shorten the key validity period threshold;
[0045] Switch the identity authentication process to an enhanced authentication strategy and enable a stricter blacklist handling strategy;
[0046] Report abnormal alerts to core infrastructure.
[0047] The technical effects and advantages of the dedicated communication encryption processing system based on the 2.4G frequency band of this invention are as follows:
[0048] By monitoring the link stability index and packet error rate in real time, the system dynamically selects the optimal key access strategy among three methods: physical feature exchange, quantum-resistant cryptographic encapsulation, and pre-set keys. This ensures a high success rate for key negotiation and communication continuity under fluctuating link conditions. A root key system based on quantum key distribution is constructed, and session keys, working keys, and key encryption keys with strictly isolated uses are derived through HKDF functions. Combined with timed update and emergency destruction mechanisms, forward and backward security are achieved, effectively resisting quantum computing threats. A multicast key update strategy triggered by dual thresholds of time and member changes is adopted, combined with dynamic thread pool concurrent distribution technology based on task load, which improves key synchronization efficiency and system scalability in large-scale multicast scenarios, while reducing communication overhead. Attached Figure Description
[0049] Figure 1 This is a schematic diagram of the dedicated communication encryption processing system based on the 2.4G frequency band of the present invention. Detailed Implementation
[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0051] Example
[0052] Please see Figure 1 As shown, this invention discloses a dedicated communication encryption processing system based on the 2.4G frequency band, including: a key system construction module, a link adaptation session module, a multicast key management module, and an adaptive adjustment protection module, with signal connections between each module;
[0053] Key system construction module: Random numbers are generated through quantum key distribution equipment, and the error rate and randomness are judged by hardware security module to screen qualified keys and distinguish them into working key pool and encryption key pool. Based on the link stability index and packet error rate calculation results, time threshold and update criteria are set to form a multi-layer key management structure with forward security, providing secure input for the subsequent session layer.
[0054] Link adaptation session module: acquires communication data between the terminal and the peer, calculates the link stability index and packet error rate, obtains the smoothing index using the moving average, and divides the link status into three categories: stable, normal and poor according to the threshold. For each corresponding status, a session key is established using three methods: wireless channel characteristics, quantum-resistant encapsulation and pre-set key. The derivation and update are completed according to the criteria.
[0055] Multicast key management module: Monitors multicast member changes and time thresholds, establishes a dual-criteria update mechanism, generates and encapsulates a new multicast key when the member change count or time threshold meets the triggering conditions, uses a dynamic thread pool to achieve concurrent distribution of multiple members, and calculates scaling conditions through task load and thread utilization to ensure distribution synchronization and resource matching.
[0056] Adaptive adjustment protection module: During the monitoring period, it acquires four types of indicators: link quality, multicast status, thread performance, and security events. It calculates parameters such as fluctuation coefficient, member change rate, and abnormal growth rate, compares their respective thresholds and performs calibration. When the indicators are stable, it extends the key validity period. When the fluctuation increases, it shortens the threshold and adjusts the thread scale. At the same time, when the abnormal accumulation reaches the criterion, it triggers enhanced protection and identity authentication upgrade.
[0057] In the key system construction module, random numbers are generated through a quantum key distribution device. Combined with a hardware security module, a dual threshold judgment of bit error rate and randomness is performed to screen qualified keys and classify them into a working key pool and an encryption key pool. Based on the link stability index and packet error rate calculation results, time thresholds and update criteria are set to form a multi-layered key management structure with forward security, providing secure input for the subsequent session layer. Specific content includes:
[0058] This step constructs a key system that meets quantum security requirements. Initial random numbers are generated using a quantum key distribution (QKD) device, and then classified, stored, and managed for lifecycle using a hardware security module (HSM). The specific steps are as follows:
[0059] To combat quantum attacks in 2.4 GHz band communication, QKD devices in fiber optics or free space are used to generate keys. QKD uses the quantum uncertainty principle to ensure the security of key distribution, but the original sequence still needs to be quality checked.
[0060] Perform bit error rate filtering on the key sequence: if the bit error rate is greater than the bit error rate threshold If the key fails, it is invalid and destroyed; otherwise, it passes.
[0061] Perform a randomness verification; if the entropy value is lower than the randomness threshold... If so, it is deemed unqualified;
[0062] Integrity verification is performed by calculating a digest using a hash function; if the digest is inconsistent, the verification is also deemed invalid. Only when both conditions are met—a bit error rate less than or equal to a bit error rate threshold—can the integrity be verified. And the entropy value is greater than or equal to the randomness threshold. Only if the key is valid is it included in the subsequent process, then the key is considered valid.
[0063] Qualified keys are entered into two independent key pools: the working key pool (WKPool) and the key encryption key pool (KEKPool). The working key pool (WKPool) is used to derive working keys for encrypting business data, while the key encryption key pool (KEKPool) is used to derive keys for encrypting other keys.
[0064] To reduce the risk of leakage, each pool has a time threshold: the effective time threshold for the working key is denoted as... The effective time threshold of the encryption key is denoted as . ,and It can be set to 3× When a key is used for a period of time exceeding a threshold, an update will be triggered;
[0065] Three methods are selected to obtain shared random materials based on link conditions. Link conditions are measured by the Link Stability Index (LSI), and a high threshold for the LSI is set. and low threshold Other parameters used to determine different levels include the packet error rate (PER), whose maximum allowable value is denoted as […]. ;
[0066] Key exchange based on the physical characteristics of the wireless channel, when LSI ≥ And PER≤ At that time, the link is stable, and both parties are within the detection window. The received signal strength (RSSI) of the 2.4GHz link is collected synchronously, and 500 sampling points can be obtained at 10-millisecond intervals.
[0067] The sampled sequence is normalized and adaptively quantized. The continuous values are converted into binary bit strings using the mean as the quantization threshold. Then, the two parties exchange hash digests to verify consistency. If the digests are consistent, privacy amplification is performed, such as obtaining a 256-bit shared random material through the Poly1305 hash function. Identity authentication is performed based on the device identifiers of both parties and the temporary authentication key.
[0068] Key encapsulation based on quantum-resistant cryptography (PQC): When ≤LSI< At that time, the link had some bit errors but was generally stable. The terminal used quantum-resistant algorithms such as public key generation. and private key Used by the other end Encapsulating shared random material generates ciphertext. After transmission, the terminal decapsulates the same encapsulated shared material. Both parties use hash verification to check consistency. If decapsulation fails, the access method is reselected according to the link status. The shared random material obtained through PQC encapsulation is also used as the input of the derived key.
[0069] Pre-set key access: When LSI < Or PER> Poor link quality makes interactive negotiation unsuitable. The core infrastructure pre-defines a fixed-length key from the QKD key and writes it into the terminal's HSM. Upon initial device startup and successful authentication, the pre-defined key is used directly as shared random material. Once the link recovers and continuously satisfies LSI ≥ 1, the connection is restored. After a certain period K, it will automatically switch to the above physical characteristic exchange or PQC packaging method to update the shared random material;
[0070] Regardless of how the shared random material is obtained, both parties generate a session key Sk, a working key WK, and a key encryption key KEK through the key derivation function HKDF. The three are used in isolation to reduce the impact of a single key being leaked.
[0071] Based on the shared random material and the context identifiers Context for different purposes, a pseudo-random key PRK is calculated, and then three keys are derived respectively. The specific formula can be expressed as follows: , , The output length of the HKDF-Expand function is set to 32 bytes to meet the key length requirements of symmetric encryption algorithms such as AES-256.
[0072] The session key SK is used only to encrypt control fields, such as sequence numbers and timestamps, and to calculate message authentication codes; the working key WK is used only to encrypt business data payloads; and the key encryption key KEK is used only to encapsulate or decapsulate other keys. The three keys respectively mark the activation time T0 and the effective time threshold. , ,as well as And stored in a separate area of the HSM;
[0073] To maintain forward and backward security, a timer is set to monitor the activation time T0 of each key and the current time T. An update is triggered when any expiration condition is met: when... or or At that time, the corresponding key expired;
[0074] In the update process, the core infrastructure intercepts the new key from the key pool, encapsulates it in a KEK, and sends it to the terminal. The terminal decapsulates the key and re-derives the SK, WK, and KEK using HKDF, replacing the old key and destroying the old value. The destruction operation is physically overwritten by HSM and recorded in the destruction log. Emergency destruction is also possible if a leakage risk is detected. Through regular updates and usage isolation, even if a key is leaked, it cannot decrypt past data or affect future communications. The judgment criterion for this stage can be stated as: when... And PER≤ If the current working key expires, it is determined that it needs to be updated; similarly, the updates of KEK and SK are also based on their respective time thresholds and link conditions.
[0075] By constructing a quantum-secure key system, the security and reliability of key sources in subsequent communications are ensured, and diverse key access methods and comprehensive lifecycle management are provided for different applications, laying the foundation for link adaptation and session establishment in step S2.
[0076] In the link adaptation session module, communication data between the terminal and the peer is acquired, the link stability index and packet error rate are calculated, a smoothing index is obtained using a moving average, and the link status is divided into three categories—stable, average, and poor—based on a threshold. For each corresponding status, a session key is established using three methods: wireless channel characteristics, quantum-resistant encapsulation, and a pre-set key. Derivation and updating are performed based on criteria. Specific content includes:
[0077] The 4GHz unlicensed frequency band has a large number of interference sources, which causes frequent fluctuations in link quality, directly affecting the success rate of key negotiation and communication stability. By monitoring the link status in real time, dynamically selecting the appropriate key access method, establishing an end-to-end encrypted channel, and dealing with link fluctuations through a session maintenance mechanism, the security and continuity of communication can be ensured.
[0078] In each detection window This section summarizes the control and test packets transmitted between the terminal and the peer. Assuming the total number of packets sent within a window is PktTotal, and the number of packets received and acknowledged (ACK) is PktSucc, the following parameters can be obtained from these two statistics:
[0079] According to the calculation formula, the link stability index : This reflects the reliability of the link; packet error rate. : To avoid misjudgments caused by instantaneous fluctuations, a moving average was also performed on LSI and PER, denoted as... and Its calculation formula can be expressed as: ; Where α is the smoothing coefficient, ranging from 0.4 to 0.8, adjusted according to the degree of link fluctuation. The smoothed exponent and error rate can be obtained through the above calculation, and the link status is divided into three levels, corresponding to different key access methods. The specific judgment rules are as follows:
[0080] steady state: With low link error rate and reliable communication, key exchange methods based on the physical characteristics of wireless channels are preferred.
[0081] Normal state: The link has some bit errors, but it can meet the requirements for interactive key negotiation; PQC key encapsulation method is preferred. Poor state: The link has a high error rate and interactive negotiation is prone to failure, so a pre-set key access method is adopted.
[0082] , and The initial value of the threshold parameter is based on test data from typical application scenarios, such as industrial plants and medical computer rooms, but it can be calibrated according to the actual deployment environment to ensure compatibility. The calibration process is as follows: In the target deployment environment, continuously monitor the link status and record the LSI value, key negotiation success rate and data transmission error rate at different time periods. Select the minimum LSI value with a key negotiation success rate ≥ 95% as... For example, if the negotiation success rate is 96% when LSI ≥ 0.89 is measured in an industrial plant, then the following setting is made: ; Select the maximum LSI value with a key negotiation success rate ≤50% as... For example, if the negotiation success rate is 48% when LSI ≤ 0.64, then set... ; Set to 1- The default value is 0.35. At that time, the session key update is triggered;
[0083] After threshold calibration is completed, it can be stored as an environment configuration file, which will be automatically loaded at startup and supports recalibration according to environmental changes.
[0084] Different key access methods are selected based on the link status level to complete session key establishment:
[0085] Normal state: Session key establishment based on PQC, when the link state is in the normal state. Generate public key The public key is sent to the other end, which verifies the public key and generates shared material to encapsulate the shared material. During transmission, CRC32 checksum and MAC value are used for integrity and authentication. If decapsulation fails, the parties will re-negotiate according to the number of retries. If the maximum number of retries is exceeded, the parties will switch to the preset key method. After successful decapsulation, both parties will derive SK, WK and KEK through HKDF and synchronize the key effective time T0.
[0086] Steady state: Session key establishment based on wireless physical characteristics, when the link meets the steady state requirement. RSSI is used as the random source: both parties collect RSSI values within the detection window and filter outliers. Then, the average value of the sampled sequence is used as the quantization threshold to map the sampled values into bit strings. After both parties exchange hash digests to verify consistency, shared random material is obtained through privacy amplification, and then SK, WK, and KEK are derived through HKDF.
[0087] Poor state: Session key establishment based on a preset key. When the link state is poor... If the terminal cannot negotiate stably, it activates a pre-set key as shared random material and derives a key through HKDF. This process continues until the link is restored and the desired connection is met. After K windows, it automatically switches to a more secure physical signature or PQC method to update the session key;
[0088] The conditions that trigger a session key update include: key expiration, change in link state level, or... > Multicast key updates can cause the SK or KEK to expire before one-third of its validity remains, or an abnormal event can be detected a certain number of times. The update process is the same as the initial setup: new shared random materials are obtained through the adapted access method, and a new key is derived.
[0089] After establishing SK, WK, and KEK, data transmission employs a layered encryption strategy: the frame header uses SK and is encrypted with AES-256-GCM; the service data payload uses WK and employs the same authentication encryption algorithm; if a new WK or multicast key needs to be sent, it is encapsulated in KEK and placed in the payload. The sending end calculates the MAC value and Frame Check Sequence (FCS), and the receiving end decrypts and verifies them in reverse order. To prevent replay attacks, the receiving end maintains a replay protection window; if the SN of a newly received frame is within the window and already exists, it is considered a duplicate and discarded.
[0090] The session maintenance mechanism includes: periodically sending link keep-alive packets to confirm the connection; automatically retrying when negotiation fails, and switching the access method after multiple consecutive failures; recording abnormal events and reporting them when the number of abnormal events exceeds the limit; and when communication is restored after a link interruption, if the old key has not expired and meets the requirements... ≤ The session will be restored quickly; otherwise, the session key will be re-established.
[0091] By monitoring link status in real time, selecting appropriate key access methods, establishing and updating session keys, and maintaining secure data transmission channels, the problem of ensuring communication reliability and confidentiality under 2.4GHz link fluctuation conditions is solved, providing a stable basic session layer for multicast key management.
[0092] In the multicast key management module, multicast member changes and time thresholds are monitored, and a dual-criteria update mechanism is established. When the member change count or time threshold meets the trigger condition, a new multicast key is generated and encapsulated. A dynamic thread pool is used to achieve concurrent distribution of multiple members. The scaling conditions are calculated based on task load and thread utilization to ensure distribution synchronization and resource matching. Specific content includes:
[0093] Multicast communication is very common in industrial monitoring and medical sensing scenarios. It uses a multicast key update strategy based on member changes and time thresholds, and efficiently distributes keys to member stations through a dynamic thread pool, while also including exception handling.
[0094] The multicast master maintains the multicast member change counter Membchg and the key activation time T0. Two thresholds determine when to update the multicast key:
[0095] Time threshold : Indicates the maximum usage time of the multicast key, which is 600 seconds by default. It can be set to 300 seconds in high-security scenarios and 900 seconds in scenarios with high real-time requirements.
[0096] Member change threshold This represents the cumulative number of member changes allowed before the key expires. It is calculated based on the multicast group size N and the adjustment factor c, and can be expressed by the following formula: Where c is an adjustment factor, which can be set between 0.5 and 1.0, to balance security and communication overhead. This is the floor function; max(1,·) ensures that when the group size N≤2, Membermax=1, meaning the key is updated whenever there is a member change, reducing the management complexity of small groups; when N is between 3 and 4, ... The value is still 1; N is 2 between 5 and 8; N is 3 between 9 and 16; N is 4 between 17 and 32; N is still 4 between 33 and 64; N is 5 between 65 and 128. These values ensure that the key is updated in time when small groups change, while large-scale multicast can tolerate more member changes to reduce overhead.
[0097] The multicast master station determines whether to update based on two parameters: when the current time meets the following conditions: Time update is triggered at any time; Under the condition that the cumulative number of changes in members is greater than or equal to 1, then... This triggers a member change update. When either the time threshold or the member change threshold is met, it is considered that the multicast key needs to be updated.
[0098] Once an update is triggered, the multicast master station generates a new 256-bit multicast key GK' using quantum random numbers or hardware random numbers, and performs a randomness check on it. If the randomness fails, it is regenerated. Then, GK' is encapsulated using KEK from the current session key to obtain the ciphertext EncGK'.
[0099] The multicast master station sends the data packet via the 2.4GHz multicast link. Upon receiving it, member stations verify the CRC, confirm their membership in the group, calculate the MAC value using the session key SK, and compare it. If verification is successful, they use their local KEK to decapsulate the GK', store it in the HSM (Host Smart Message) marking its version and validity period, and immediately decrypt the multicast data using the new key. The member station then sends an acknowledgment message to the master station; the timeout period for the master station to wait for acknowledgment is recorded as [description of timeout]. Members whose updates expire after this time limit will be added to the incomplete update list. For incomplete update members, the main site will retry a maximum of [number missing] times using unicast. If it still fails, mark it as an error and temporarily remove it from the multicast group;
[0100] like If no confirmation is received after the unicast retry, the multicast master station marks the member station as abnormal, temporarily removes it from the multicast member list, and reports the abnormality alarm to the core infrastructure. The operation and maintenance personnel can investigate the cause of the abnormality through the management platform, and rejoin the multicast group and obtain a new key after recovery.
[0101] In large-scale multicast, single-threaded round-robin key distribution can lead to excessively long distribution delays, causing some member stations to fail to update keys in a timely manner and resulting in data decryption failures. This embodiment employs dynamic thread pool technology, dynamically adjusting the number of threads based on task load (TL) and thread utilization (TU) to achieve concurrent distribution of multicast keys, improving distribution efficiency and synchronization. Therefore, a dynamic thread pool is used to concurrently execute the key distribution task.
[0102] The thread pool has an initial number of threads (InitThreads), a maximum number of threads (MT), a task queue length (TL), and a thread utilization rate (TU). The specific definitions are as follows:
[0103] Initial Threads: The initial number of threads when the thread pool starts. The default value is 4, which can be adjusted according to the initial size of the multicast group. For example, set it to 2 for small groups and 8 for large groups.
[0104] Maximum number of threads MT: The maximum number of threads allowed in the thread pool. The default value is 16. The value is determined based on the concurrent transmission capacity of the 2.4GHz link and the hardware resources of the multicast master station, such as the number of CPU cores, to avoid resource contention caused by too many threads.
[0105] Task queue length TL: The maximum length of the queue storing key distribution tasks. The default value is 100. Tasks exceeding the capacity will be blocked until there is free space in the queue.
[0106] Thread idle timeout: If an idle thread in the thread pool does not process any tasks for more than 60 seconds, the thread will be automatically destroyed and resources will be released.
[0107] Thread utilization (TU): ;in, This represents the number of threads currently processing tasks. This represents the total number of threads in the current thread pool.
[0108] When both conditions are met , as well as When conditions are met, the thread pool is expanded, and the number of new threads added during the expansion is [number missing]. The calculation formula is: Where BlockSize=5, it represents the number of tasks that can be processed by each additional thread. For the round-up function, the number of new threads must not exceed [a certain limit]. To avoid exceeding the maximum number of threads;
[0109] Scaling down conditions and thread reduction: When both conditions are met as well as When conditions are met, the thread pool is scaled down. The number of threads reduced during scaling down is 50% of the current number of idle threads. This ensures that enough threads are retained to handle sudden tasks and avoids excessive scaling down that could cause congestion in subsequent tasks.
[0110] The thread pool status monitoring and adjustment period is 5 seconds, consistent with the link status detection window, to ensure the timeliness and stability of the adjustment;
[0111] After a thread in the thread pool starts, it retrieves a task from the task queue for distribution. If the queue is empty, it enters an idle state and waits for a new task.
[0112] The thread extracts the member station device identifier and key update data packet from the task, sends the key update packet, and waits for confirmation from the member station. If no confirmation is received within a timeout period, the task is re-added to the queue and the retry count is increased. If the retry count exceeds... The thread marks the task as failed and reports it. When multiple threads access the state of the same member, resource locks are used to prevent concurrent competition. By dynamically adjusting the thread pool, the distribution efficiency can be improved while ensuring link bandwidth and hardware resource constraints.
[0113] Member station voluntarily leaving or going offline abnormally can affect key security. Upon leaving, a member station sends a leave request to the master station, which removes it from the member list and increments the member change count (Membchg). Then, it determines whether a key update is needed: if Membchg ≥ 1... If the threshold for member changes is reached, an update will be triggered immediately; otherwise, the master station will only send a key destruction instruction to the departing member and require the other party to destroy the current multicast key. For abnormal offline members, such as those whose link keep-alive packets have no response for three consecutive times or those who engage in malicious behavior, such as those who frequently join or leave or forge confirmation messages, the master station will blacklist them and refuse their subsequent join requests.
[0114] By introducing dual thresholds for time and member changes to control multicast key updates, adopting a secure key generation and encapsulation process, utilizing a dynamic thread pool for concurrent distribution, and implementing robust member management and exception handling, we ensure efficient and secure key synchronization in large-scale multicast scenarios, while significantly reducing communication overhead.
[0115] In the adaptive protection module, four types of indicators are acquired during the monitoring period: link quality, multicast status, thread performance, and security events. Parameters such as fluctuation coefficient, member change rate, and anomaly growth rate are calculated, their respective thresholds are compared, and calibration is performed. When the indicators are stable, the key validity period is extended; when fluctuations increase, the threshold is shortened and the thread size is adjusted. Simultaneously, when the accumulated anomalies reach the criteria, enhanced protection and identity authentication upgrades are triggered. Specific details include:
[0116] Long-term operation requires continuous adaptation to environmental changes, introducing an iterative monitoring system and adaptive adjustment mechanism to optimize various parameters based on real-time data, such as key access method, multicast update threshold and thread pool size, while establishing hierarchical security protection;
[0117] The monitoring system covers four categories of indicators: link quality, multicast status, thread pool performance, and security events. The monitoring period is denoted as Tmon.
[0118] Link quality metric: Smoothed link stability index Packet error rate Link fluctuation coefficient LF and average RSSI, where LF can be calculated as follows: the fluctuation coefficient is obtained from the square root of the variance of the LSI sampled values within the detection window, and the formula is: Where n is the number of LSI samples within the detection window, This is the sampled average. LF≥ , A value of 0.1 can be used to determine severe link fluctuations; when the average RSSI is less than the signal threshold... The signal is determined to be too weak;
[0119] Multicast status metrics: Monitor member change count (Membchg), member change rate (R), and multicast key update frequency per unit time. ;
[0120] It should be noted that the rate of change of members, R, is the number of members changing per unit time, and the calculation formula is: Multicast key update frequency The number of multicast key updates per unit time is calculated using the following formula: Where UpdateCount represents the number of updates within the statistical period. The statistical period reflects the frequency of key updates; key update success rate. The proportion of member stations that successfully receive and update the multicast key is calculated using the following formula: Where SuccessCount represents the number of members who successfully updated, and TotalMemberCount represents the total number of members in the multicast group. This can be identified as an update anomaly;
[0121] Thread pool performance metrics include: Task Load (TL), Thread Utilization (TU), and Average Task Processing Time. And the number of expansions within the statistical period, ExpandCount;
[0122] It should be noted that the task load TL represents the number of key distribution tasks in the current task queue; the average task processing time... The average execution time for a single key distribution task is calculated using the following formula: Where m is the number of tasks completed within the statistical period; Let be the processing time for the i-th task; when > , can be set If the processing time is 5 seconds, it is considered to be inefficient, and the thread pool needs to be increased or the algorithm optimized.
[0123] Security incident metrics include the anomaly count (EC) and the anomaly rate. If the anomaly count exceeds the anomaly threshold within one hour... This will improve security strategies, such as shortening the key validity period or lowering the multicast update threshold;
[0124] At the end of each monitoring cycle (Tmon), the multicast master station summarizes four categories of indicators—link quality, multicast status, thread pool performance, and security events—based on the iterative monitoring system. It then compares each indicator with its corresponding threshold and performs adaptive calibration on key lifecycle parameters, multicast update parameters, and thread pool size. Among these, the link quality indicators include at least the smoothed link stability index. Packet error rate Link fluctuation coefficient (LF) and average RSSI; multicast status metrics include at least member change count (Membchg), member change rate (R), and multicast key update frequency per unit time; thread pool performance metrics include at least task load (TL), thread utilization (TU), and average task processing time. The security incident indicators include at least the anomaly count (EC) and the anomaly rate, and the monitoring period is Tmon.
[0125] When the multicast master station meets the stable link condition for a preset number of M monitoring cycles, it performs a calibration to extend the key validity time threshold. ≥ and ≤ Then the effective time threshold of the working key will be set. and the valid time threshold of the encryption key Adjust the step size according to the preset settings. , The threshold is adjusted upwards, and an upper limit constraint is applied to the adjusted threshold to prevent it from growing indefinitely; whereby... and For key pool lifecycle management parameters, , It is given by the policy configuration of the core infrastructure and has the same dimensions as Tmon;
[0126] When the link experiences increased volatility and a rise in security incidents, the multicast master station performs calibration by shortening the key validity period threshold and tightening the multicast update threshold: if both conditions are met... If the growth rate of abnormal events exceeds its growth rate threshold, the effective time threshold of the session layer key and the key pool key will be adjusted by a preset step size. The multicast key is lowered, and the adjustment factor c corresponding to the multicast member change threshold Membmax is lowered by a preset step size Δc, so that the Membmax calculated by the group size N and the adjustment factor c decreases accordingly, thereby triggering multicast key updates more frequently when member changes are active or the risk increases; the Membmax is calculated by the group size N and the adjustment factor c.
[0127] To adaptively adjust the thread pool size, the multicast master station reads the task load TL and thread utilization TU obtained from the thread pool monitoring at the end of each monitoring period Tmon, and combines them with the average task processing time. The thread pool status is determined. When the expansion criterion is met, the number of new threads is calculated and expansion is performed according to the dynamic thread pool expansion algorithm disclosed in step three. When the shrinkage criterion is met, the number of threads is reduced and shrinkage is performed according to the dynamic thread pool shrinkage algorithm disclosed in step three, so that the thread pool size matches the real-time load of the key distribution task.
[0128] Regarding security incident handling, when the anomaly count EC meets the requirements for J consecutive monitoring cycles... When this occurs, the multicast master station enters enhanced protection mode and executes a linkage handling process, which includes at least: immediately triggering a key update process to replace the currently used session key SK, working key WK, and key encryption key KEK;
[0129] The validity period thresholds of session keys and keys in the key pool are shortened by a preset downward step size; the identity authentication process is switched to an enhanced authentication policy and a stricter blacklist handling policy is enabled. Member stations that frequently join or leave, forge confirmation messages, or have abnormal keep-alive behavior are refused entry or temporarily removed. At the same time, abnormal alarms are reported to the core infrastructure for operation and maintenance auditing.
[0130] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0131] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.
[0132] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and inventive constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0133] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0134] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0135] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A dedicated communication encryption processing system based on the 2.4G frequency band, characterized in that, Signal connections between modules; Key system construction module: Random numbers are generated through quantum key distribution equipment, and the error rate and randomness are judged by hardware security module to screen qualified keys and distinguish them into working key pool and encryption key pool. Based on the link stability index and packet error rate calculation results, time threshold and update criteria are set to form a multi-layer key management structure with forward security, providing secure input for the subsequent session layer. Link adaptation session module: acquires communication data between the terminal and the peer, calculates the link stability index and packet error rate, obtains the smoothing index using the moving average, and divides the link status into three categories: stable, normal and poor according to the threshold. For each corresponding status, a session key is established using three methods: wireless channel characteristics, quantum-resistant encapsulation and pre-set key. The derivation and update are completed according to the criteria. Multicast key management module: Monitors multicast member changes and time thresholds, establishes a dual-criteria update mechanism, generates and encapsulates a new multicast key when the member change count or time threshold meets the triggering conditions, uses a dynamic thread pool to achieve concurrent distribution of multiple members, and calculates scaling conditions through task load and thread utilization to ensure distribution synchronization and resource matching. The adaptive adjustment protection module acquires four types of indicators during the monitoring period: link quality, multicast status, thread performance, and security events. It calculates the fluctuation coefficient, member change rate, and abnormal growth rate, compares their respective thresholds, and performs calibration. When the indicators are stable, it extends the key validity period; when the fluctuation increases, it shortens the threshold and adjusts the thread scale. At the same time, when the accumulated abnormalities reach the criteria, it triggers enhanced protection and identity authentication upgrades, realizing full-cycle self-adjustment and protection linkage of the system.
2. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 1, characterized in that, The key system construction module includes the following steps for determining the error rate and randomness of a qualified key using a dual threshold method: The key sequence is filtered by bit error rate; if the bit error rate is greater than the bit error rate threshold, it is deemed unqualified. Randomness verification is performed, and if the entropy value is lower than the randomness threshold, it is deemed unqualified. Integrity verification is performed by calculating a digest using a hash function; if the digest is inconsistent, the integrity is deemed invalid.
3. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 2, characterized in that, Based on the link conditions, three methods are selected to obtain shared random materials, including: Key exchange based on the physical characteristics of wireless channels: when the link stability index is higher than the high threshold and the packet error rate is less than or equal to the maximum allowable value, both parties synchronously collect the received signal strength of the link, normalize and adaptively quantize the sampled sequence to obtain the bit string, exchange hash digests to verify consistency, and obtain shared random material through privacy amplification. Based on quantum-resistant cryptography key encapsulation, when the link stability index is between high and low thresholds, the terminal generates a quantum-resistant public-private key pair, the peer uses the public key to encapsulate the shared random material, and after transmission, the terminal decapsulates to obtain the shared material. Pre-set key access: When the link stability index is below the low threshold or the packet error rate exceeds the maximum allowable value, the pre-set key is used as shared random material.
4. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 1, characterized in that, In the link adaptation session module, the link status is determined based on the high threshold and low threshold of the link stability index and the maximum allowable value of the packet error rate, and the link status is divided into three categories: stable status, normal status and poor status.
5. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 4, characterized in that, Based on shared random materials, session keys, working keys, and key encryption keys are derived separately through key derivation functions. The uses of the three keys are isolated, and their activation time and effective time threshold are marked respectively.
6. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 1, characterized in that, In the multicast key management module, the dual-criteria update mechanism includes: Time threshold update criterion: Triggered when the current time is greater than the sum of the key activation time and the time threshold; Member change threshold update criterion: Triggered if the cumulative number of member changes is greater than or equal to the member change threshold when the time threshold is not met; The threshold for member changes is calculated based on the multicast group size and adjustment factor.
7. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 6, characterized in that, A dynamic thread pool is used for key distribution, and its scaling conditions are calculated based on task load and thread utilization, including: When the thread utilization rate is higher than the high utilization threshold, the task load is higher than the high load threshold, and the current total number of threads is less than the maximum number of threads, the number of threads will be increased according to the preset rules. When the thread utilization rate is lower than the low utilization rate threshold and the current total number of threads is greater than the initial number of threads, the number of threads is reduced according to the preset rules.
8. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 1, characterized in that, The adaptive adjustment protection module acquires four types of indicators, including: Link quality metrics include smoothed link stability index, packet error rate, and link fluctuation coefficient; Multicast status metrics include member change count, member change rate, and multicast key update frequency; Thread pool performance metrics include task load, thread utilization, and average task processing time. Security incident indicators, including anomaly count and anomaly rate.
9. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 8, characterized in that, The calibration process, based on the comparison between the indicators and thresholds, includes: When the link quality indicators are stable, extend the effective time threshold of the working key and the key encryption key. When the link fluctuation coefficient exceeds the fluctuation threshold and the abnormal event growth rate exceeds the growth rate threshold, shorten the effective time threshold of the session layer key and the key pool key, and lower the adjustment factor of the multicast member change threshold.
10. The dedicated communication encryption processing system based on the 2.4G frequency band according to claim 8, characterized in that, When the anomaly count exceeds the abnormal high threshold for multiple consecutive monitoring periods, the enhanced protection mode is triggered, and the linkage handling process includes: Immediately trigger the key update process to replace the currently used keys; Shorten the key validity period threshold; Switch the identity authentication process to an enhanced authentication strategy and enable a stricter blacklist handling strategy; Report abnormal alerts to core infrastructure.
Citation Information
Patent Citations
Audio information encryption method based on le-audio Bluetooth
CN118301602A
Power grid frequency balance intelligent control system based on distributed architecture
CN120896190A