5G and TSN communication device and system

By introducing a forwarding module, a security context extraction module, and an FPGA encryption/decryption module, the problem of the disconnect between security policies and data transmission in 5G and TSN networks is solved. This achieves a close association between security policies and service contexts, improves the security and flexibility of cross-domain communication, and meets the low latency requirements of TSN networks.

CN121751152APending Publication Date: 2026-03-27CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-19
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

There is a gap in the connection of security policies between 5G networks and TSN networks during data transmission, which makes it impossible to achieve fine-grained and end-to-end coherent security protection, resulting in a disconnect between security policies and business context.

Method used

By employing a forwarding module, a security context extraction module, and an FPGA-supported encryption/decryption module, the system acquires 5G security context in real time and dynamically generates security policies. Combined with a hardware acceleration module, encryption and decryption processing is performed to ensure the security and flexibility of data transmission.

Benefits of technology

It achieves a close association between security policies and business context, improves the overall security and policy flexibility of cross-domain communication, meets the deterministic low-latency requirements of TSN networks for data transmission, and ensures the reliable operation of the device in real-time demand scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121751152A_ABST
    Figure CN121751152A_ABST
Patent Text Reader

Abstract

The invention provides a 5G and TSN communication device and system, relates to the technical field of 5G and TSN communication, and is used for enhancing the security of data transmission between 5G network equipment and TSN network equipment through transfer equipment. The device comprises a forwarding module used for receiving 5G original data sent by a 5G network device; the security context extraction module is used for obtaining a 5G security context based on the 5G original data and obtaining a security policy based on the 5G security context; the encryption and decryption module is used for performing first decryption processing on the 5G original data and then performing first encryption processing on the decrypted 5G original data based on a security policy to obtain first to-be-transmitted data; and the forwarding module is also used for converting the first to-be-transmitted data into first target data conforming to the TSN transmission specification, and sending the first target data to the TSN network equipment.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of 5G and TSN communication, in particular to a 5G and TSN communication device and system. BACKGROUND

[0002] Fifth generation mobile communication network (5G) and time sensitive network (TSN) fusion is a key enabling technology to support the wireless and flexible upgrade of key fields such as industrial internet and vehicle networking. In this fusion architecture, the device side TSN converter (DS-TT) as a core network element undertakes the protocol conversion and forwarding work between 5G data and TSN data.

[0003] However, 5G network and TSN network adopt completely different and independent security systems. 5G relies on end-to-end security mechanism based on air interface encryption and core network authentication, while TSN usually relies on link layer security protocol such as MACsec. When data flows from 5G domain to TSN domain via DS-TT, DS-TT usually only adopts static and unified processing mode, which causes security policy to be disconnected, which leads to the disconnection of security policy and business context executed by DS-TT, and cannot realize fine and end-to-end coherent security protection.

[0004] Therefore, a scheme is needed to strengthen the security of data transmission between 5G network equipment and TSN network equipment through the relay equipment. SUMMARY

[0005] The application provides a 5G and TSN communication device and system for strengthening the security of data transmission between 5G network equipment and TSN network equipment through the relay equipment.

[0006] To achieve the above purpose, the application adopts the following technical scheme: In a first aspect, the application provides a 5G and TSN communication device, comprising: a forwarding module, a security context extraction module, and an encryption and decryption module supported by FPGA; The forwarding module is used for receiving 5G original data sent by a 5G network device, and forwarding the 5G original data to the security context extraction module; The security context extraction module is used for obtaining a 5G security context based on the 5G original data, obtaining a security policy based on the 5G security context, and forwarding the security policy to the encryption and decryption module; The encryption and decryption module is used for performing first decryption processing on the 5G original data, performing first encryption processing on the decrypted 5G original data based on the security policy, obtaining first to-be-transmitted data, and sending the first to-be-transmitted data to the forwarding module; The forwarding module is further configured to convert the first to-be-transmitted data into first target data conforming to a TSN transmission specification, and send the first target data to the TSN network device.

[0007] The technical scheme provided in the application brings at least the following beneficial effects: By introducing the security context extraction module, the 5G security context of the to-be-processed 5G original data can be obtained in real time, and a corresponding security policy can be dynamically generated based on the context. The current DS-TT node security policy static, uniform defect is overcome, so that the security processing from the 5G domain to the TSN domain can be dynamically adjusted according to the specific security attributes and business requirements of each communication session or data flow, the close association between the security policy and the business context is realized, and the overall security and policy flexibility of cross-domain communication are improved.

[0008] Moreover, in the application, the encryption and decryption module supported by the FPGA is used to perform the encryption and decryption core operation. The parallel processing capability and customizable hardware pipeline of the FPGA enable the first decryption processing and the first encryption processing to be performed at line speed in a hardware acceleration manner, with extremely low processing delay and high determination. This avoids the time delay jitter problem caused by software implementation of the encryption and decryption process, ensures that even when complex security algorithms are executed, the determinacy low latency requirement of the TSN network for data transmission can be met, thereby guaranteeing the reliable operation of the device provided in the application in real-time requirement scenarios.

[0009] In the 5G and TSN communication device provided in the application, the forwarding module is responsible for data reception and final sending, the security context extraction module is responsible for policy generation, and the encryption and decryption module focuses on hardware-accelerated security operation. Such modular design makes the entire process of data reception (5G side), security policy decision, hardware security processing, format conversion and sending (TSN side) clear and efficient. The forwarding module finally performs the operation of converting into the TSN transmission specification, ensuring the correctness of the protocol encapsulation, so that the 5G and TSN communication device provided in the application becomes a functional complete and highly cooperative communication hub, improving the maintainability and overall processing efficiency of the device.

[0010] Optionally, the security context extraction module is specifically configured to: based on the identification information of the 5G original data, index the security context from a preset security context library.

[0011] Optionally, the security context includes: a K_gNB key, an encryption algorithm identifier and an integrity protection algorithm identifier used by the 5G network negotiation, and a QoS flow identifier and a 5G QoS indicator associated with a data flow of the 5G original data.

[0012] Optionally, the security policy comprises an encryption priority and an encryption algorithm corresponding to the decrypted 5G original data; and the security context extraction module is specifically configured to: determine the encryption priority corresponding to the decrypted 5G original data according to the priority indicated by the QoS flow identifier; and determine the encryption algorithm corresponding to the decrypted 5G original data according to the encryption algorithm identifier.

[0013] Optionally, the apparatus further comprises a key management module; and the security context extraction module is further configured to send the 5G security context to the key management module; and the key management module is configured to: obtain the K_gNB key from the 5G security context, and derive a session key based on the K_gNB key; generate an encryption key corresponding to the decrypted 5G original data based on the session key and an identifier of the decrypted 5G original data; and configure the encryption key to the encryption and decryption module.

[0014] Optionally, the encryption and decryption module is specifically configured to: allocate a corresponding encryption resource to the decrypted 5G original data according to the encryption priority, and perform first encryption processing on the decrypted 5G original data according to the encryption algorithm and the encryption key based on the encryption resource, to obtain first to-be-transmitted data.

[0015] Optionally, the key management module is further configured to: detect a usage time and / or an encryption data volume of the encryption key; and update the encryption key in a case where the usage time of the encryption key is greater than or equal to a preset time threshold or the encryption data volume is greater than or equal to a preset data volume threshold.

[0016] Optionally, the apparatus further comprises a centralized management platform configured to: send a security policy template to the security context extraction module, so that the security context extraction module determines the security policy based on the security policy template; and send a key management rule to the key management module, so that the key management module updates the encryption key based on the key management rule.

[0017] Optionally, the encryption and decryption module is specifically configured to: perform integrity verification on the 5G original data; and perform first decryption processing on the 5G original data in a case where the integrity verification on the 5G original data is passed.

[0018] Optionally, the forwarding module is further configured to: receive TSN original data sent by a TSN network device, and send the TSN original data to the encryption and decryption module; and the encryption and decryption module is further configured to: perform second decryption processing on the TSN original data, and send the decrypted TSN original data to the forwarding module; and the forwarding module is further configured to: convert the decrypted TSN original data into second target data conforming to a 5G transmission specification, and send the second target data to the 5G network device.

[0019] Optionally, the encryption and decryption module is specifically configured to: according to the security parameter index in the TSN original data packet, search for a decryption key corresponding to the encryption key; and perform a second decryption process on the TSN original data based on the decryption key.

[0020] Optionally, the encryption and decryption module is specifically configured to: perform security verification on the TSN original data; the security verification includes at least one of the following: verifying the security header format, verifying the validity of the security parameter index, and verifying whether the sequence number is within a preset range; and in a case where the security verification on the TSN original data is passed, performing a second decryption process on the TSN original data.

[0021] Optionally, the apparatus further includes a threat detection module and a security executor; the threat detection module is configured to: detect a traffic pattern and / or a sequence number of data flowing through the apparatus; identify, based on the traffic pattern and / or the sequence number of the data flowing through the apparatus, whether there is a security threat through machine learning; if there is, generate a security event and report it to the security executor; and the security executor is configured to: based on the security event, determine and control other modules in the apparatus to execute a protection strategy, the protection strategy being configured to avoid a security accident caused by the data with the security threat.

[0022] Optionally, the apparatus further includes a statistics module, configured to: in a process in which the encryption and decryption module performs encryption processing or decryption processing on the data, count encrypted traffic or decrypted traffic, and generate and report security statistics information.

[0023] In a second aspect, the present application provides a 5G and TSN communication system, including: a 5G network device, a TSN network device, and the 5G and TSN communication apparatus provided by the first aspect and any one of the possible implementation manners thereof.

[0024] In the specific implementation manners of the present application, the names of the components of the apparatus do not constitute a limitation on the apparatus itself, and in actual implementation, these components can appear with other names. As long as the functions of the components are similar to those in the specific implementation manners of the present application, they belong to the scope of the claims of the present application and equivalent technologies thereof.

[0025] In addition, the technical effects brought about by the second aspect can be referred to the technical effects brought about by the different design methods in the first aspect, which will not be described herein again. BRIEF DESCRIPTION OF DRAWINGS

[0026] Figure 1 FIG. 1 is a structural schematic diagram of a 5G and TSN communication system provided by an embodiment of the present application; Figure 2 FIG. 2 is a forward security data processing flow schematic diagram provided by an embodiment of the present application; Figure 3This is a schematic diagram of a reverse security data processing flow provided in an embodiment of this application. Detailed Implementation

[0027] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0028] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0029] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "connected" and "linked" should be interpreted broadly, for example, as a fixed connection, a detachable connection, or an integral connection. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances. Furthermore, when describing pipelines, the terms "connected" and "linked" as used in this application have the meaning of establishing electrical connection. The specific meaning needs to be understood in conjunction with the context.

[0030] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0031] As described in the background section, the current DS-TT uses a static and uniform security strategy when processing cross-domain data transmission between the 5G domain and the TSN domain. This results in the DS-TT executing security strategies being disconnected from the business context, making it impossible to achieve refined, end-to-end coherent security protection.

[0032] To address the aforementioned issues, this application provides a 5G and TSN communication device, comprising: a forwarding module, a security context extraction module, and an encryption / decryption module supported by an FPGA; the forwarding module is used to receive 5G raw data sent by a 5G network device and forward the 5G raw data to the security context extraction module; the security context extraction module is used to obtain a 5G security context based on the 5G raw data, obtain a security policy based on the 5G security context, and forward the security policy to the encryption / decryption module; the encryption / decryption module is used to perform a first decryption process on the 5G raw data, and then perform a first encryption process on the decrypted 5G raw data based on the security policy to obtain a first data to be transmitted, and send the first data to be transmitted to the forwarding module; the forwarding module is further used to convert the first data to be transmitted into first target data conforming to the TSN transmission specification, and send the first target data to the TSN network device.

[0033] By introducing a security context extraction module, the 5G security context can be obtained in real time from the raw 5G data to be processed, and corresponding security policies can be dynamically generated based on this context. This overcomes the shortcomings of the current static and uniform security policies of DS-TT nodes, enabling security processing from the 5G domain to the TSN domain to be dynamically adjusted according to the specific security attributes and service requirements of each communication session or data stream. This achieves a close correlation between security policies and service context, improving the overall security and policy flexibility of cross-domain communication.

[0034] Furthermore, this application employs an FPGA-supported encryption / decryption module to perform the core encryption / decryption operations. The parallel processing capabilities and customizable hardware pipeline of the FPGA enable the first decryption and first encryption processes to be executed at line speed with hardware acceleration, resulting in extremely low processing latency and high determinism. This avoids the latency jitter issues caused by software-implemented encryption / decryption processes, ensuring that even when executing complex security algorithms, the deterministic low-latency requirements of the TSN network for data transmission are met, thereby guaranteeing the reliable operation of the device provided in real-time demand scenarios.

[0035] In the 5G and TSN communication device provided in this application, the forwarding module is responsible for data reception and final transmission, the security context extraction module is dedicated to policy generation, and the encryption / decryption module focuses on hardware-accelerated security computation. This modular design makes the entire process of data reception (5G side), security policy decision-making, hardware security processing, to format conversion and transmission (TSN side) clear and efficient. The forwarding module ultimately performs operations that conform to the TSN transmission specification, ensuring the correctness of protocol encapsulation. This makes the 5G and TSN communication device provided in this application a fully functional and highly efficient communication hub, improving the maintainability and overall processing efficiency of the device.

[0036] Figure 1This is a schematic diagram of the structure of a 5G and TSN communication system provided in an embodiment of this application. Figure 1 As shown, the 5G and TSN communication system 1 includes: 5G network equipment 10, TSN network equipment 20, and 5G and TSN communication device 30.

[0037] The 5G and TSN communication device 30 is communicatively connected to the 5G network device 10 and the TSN network device 20, respectively. The connection method can be direct or indirect.

[0038] The 5G network device 10 is used to send 5G raw data to the 5G and TSN communication device 30, so that the 5G raw data is processed by the 5G and TSN communication device 30 and then forwarded to the TSN network device 20.

[0039] TSN network device 20 is used to send raw TSN data to 5G and TSN communication device 30, so that the raw TSN data is processed by 5G and TSN communication device 30 and then forwarded to 5G network device 10.

[0040] In some embodiments, the 5G and TSN communication device 30 may include a forwarding module 301, a security context extraction module 302, and an encryption / decryption module 303 supported by an FPGA.

[0041] The forwarding module 301 is used to receive 5G raw data sent by the 5G network device 10 and forward the 5G raw data to the security context extraction module 302; the security context extraction module 302 is used to obtain the 5G security context based on the 5G raw data, obtain the security policy based on the 5G security context, and forward the security policy to the encryption / decryption module 303; the encryption / decryption module 303 is used to perform a first decryption process on the 5G raw data, and then perform a first encryption process on the decrypted 5G raw data based on the security policy to obtain the first data to be transmitted, and send the first data to be transmitted to the forwarding module 301; the forwarding module 301 is also used to convert the first data to be transmitted into first target data conforming to the TSN transmission specification, and send the first target data to the TSN network device 20.

[0042] The encryption / decryption module 303 can be called a unified encryption / decryption engine, which implements a complete encryption algorithm hardware accelerator in the FPGA.

[0043] The encryption / decryption module 303 supports hardware acceleration for various encryption algorithms, such as: 1. Symmetric encryption: AES-GCM, AES-CCM, ChaCha20-Poly1305; 2. Asymmetric encryption: ECDSA, RSA-2048; 3. Hash algorithms: SHA-256, SHA-3.

[0044] In symmetric encryption, AES-GCM and AES-CCM employ dedicated encryption cores, supporting key lengths of 128 / 192 / 256 bits, and achieving high throughput through optimized S-Box implementations. The ChaCha20-Poly1305 algorithm uses a pipelined quarter-round function architecture, making it particularly suitable for software-defined scenarios. In asymmetric encryption, ECDSA employs a hardware-optimized implementation based on the NIST P-256 curve, while RSA-2048 uses a Montgomery modular multiplier to accelerate large number operations. Among hash algorithms, SHA-256 employs a message scheduler optimization, and SHA-3 uses a Keccak-f

[1600] round function hardware implementation.

[0045] In particular, the encryption / decryption module 303 adopts a pipelined architecture, which enables line-speed encryption and decryption while ensuring deterministic latency.

[0046] The encryption / decryption module 303 employs a pipelined architecture, decomposing the encryption process into multiple independent processing stages. Each stage handles specific subtasks, such as key expansion, round operations, and pattern processing. This architecture allows for the simultaneous processing of different encryption stages of multiple data packets, completing the processing of one data block per clock cycle. Deterministic latency is guaranteed through a fixed number of pipeline stages, ensuring predictable encryption latency regardless of data packet size, typically less than 2 microseconds.

[0047] By introducing the security context extraction module 302, the 5G security context can be obtained in real time from the raw 5G data to be processed, and the corresponding security policy can be dynamically generated based on this context. This overcomes the shortcomings of the current static and uniform security policies of DS-TT nodes, enabling the security processing from the 5G domain to the TSN domain to be dynamically adjusted according to the specific security attributes and service requirements of each communication session or data stream. This achieves a close association between security policies and service context, improving the overall security and policy flexibility of cross-domain communication.

[0048] Furthermore, this application employs an FPGA-supported encryption / decryption module 303 to perform the core encryption / decryption operations. The parallel processing capabilities and customizable hardware pipeline of the FPGA enable the first decryption and first encryption processes to be executed at line speed with hardware acceleration, resulting in extremely low processing latency and high determinism. This avoids the latency jitter issues caused by software-implemented encryption / decryption processes, ensuring that even when executing complex security algorithms, the deterministic low-latency requirements of the TSN network for data transmission are met, thereby guaranteeing the reliable operation of the device provided in real-time demand scenarios.

[0049] In the 5G and TSN communication device provided in this application, the forwarding module 301 is responsible for receiving and ultimately sending data, the security context extraction module 302 is dedicated to policy generation, and the encryption / decryption module 303 focuses on hardware-accelerated security operations. This modular design makes the entire process of data reception (5G side), security policy decision-making, hardware security processing, to format conversion and transmission (TSN side) clear and efficient. The forwarding module ultimately performs operations that conform to the TSN transmission specification, ensuring the correctness of protocol encapsulation. This makes the 5G and TSN communication device 30 provided in this application a fully functional and highly efficient communication hub, improving the maintainability and overall processing efficiency of the device.

[0050] In some embodiments, the security context extraction module 302 is specifically used to: obtain the security context from a preset security context library based on the identification information of the 5G raw data.

[0051] The security context may include: the K_gNB key, the encryption algorithm identifier and integrity protection algorithm identifier used for 5G network negotiation, and the QoS flow identifier and 5G QoS metrics associated with the data stream of the raw 5G data.

[0052] The 5G and TSN communication device 30 integrates a 5G protocol stack that interfaces with the 5G network device 10. The security context extraction module 302 obtains security configuration information such as the K_{gNB} derived key, integrity protection algorithm identifier (such as 128-NIA), encryption algorithm identifier (such as 128-NEA), QoS flow identifier (QFI) and 5G QoS features (such as 5QI) from the RRC layer and NAS layer of the 5G protocol through the 5G protocol stack.

[0053] The security context extraction module 302 interacts with the 5G protocol stack through a dedicated security API interface to ensure real-time acquisition of security context.

[0054] In some embodiments, the security policy includes the encryption priority and encryption algorithm corresponding to the decrypted 5G raw data; the security context extraction module 302 is specifically used to: determine the encryption priority corresponding to the decrypted 5G raw data according to the priority indicated by the QoS flow identifier; and determine the encryption algorithm corresponding to the decrypted 5G raw data according to the encryption algorithm identifier.

[0055] The security context extraction module 302 maps 5G security parameters to TSN network security policies, establishing cross-network security associations. The security context extraction module 302 enables intelligent mapping from 5G security parameters to TSN security policies.

[0056] For example, the PDU session security policy in the raw 5G data is mapped to the MACsec security association of the TSN, and the 5G QoS flow priority is mapped to the encryption priority of the TSN flow (decrypted 5G encrypted data, referring to the data to be sent to the TSN network device). The mapping process is based on a preset policy rule base, considering multiple dimensions such as security level, latency requirements, and bandwidth requirements. The established cross-network security association table records the TSN security parameters corresponding to each 5G session, including the security protocol used, key index, lifespan, and other information.

[0057] The security context extraction module 302 extracts security parameters and key context from the 5G protocol stack, dynamically generates corresponding TSN network encryption policies and session keys, realizes seamless connection between 5G and TSN security, and constructs a cross-network domain security context conversion mechanism.

[0058] Secure communication between 5G and TSN is achieved through the security context extraction module 302, which maps and converts the 5G security context to the TSN security policy, providing end-to-end hardware-accelerated secure communication.

[0059] In some embodiments, the 5G and TSN communication device 30 further includes a key management module 304; the security context extraction module 302 is further configured to send the 5G security context to the key management module 304; the key management module 304 is configured to: obtain the K_gNB key from the 5G security context, and derive a session key based on the K_gNB key; generate an encryption key corresponding to the decrypted 5G original data based on the session key and the identifier of the decrypted 5G original data; and configure the encryption key to the encryption / decryption module 303.

[0060] The key management module 304 derives session keys based on 5G K_{gNB} and also generates independent encryption keys for each TSN stream, realizing a two-layer key management system.

[0061] The first layer of key management is based on the 5G K_{gNB} root key, using standard KDF functions (such as HKDF) to derive session-level intermediate keys. The derivation process considers session-specific parameters, such as PDU session ID and counter values, to ensure key uniqueness. The second layer generates independent encryption keys for each TSN stream, using stream identifiers (such as MAC address, VLAN ID, and IP 5-tuple) as derivation inputs.

[0062] This hierarchical structure maintains key coherence while achieving stream-level key isolation. The two-layer key management and derivation system derives session keys based on the 5G K_{gNB} root key and generates independent encryption keys for each TSN data stream, supporting automatic key rotation and forward security protection.

[0063] In some embodiments, the encryption / decryption module 303 is specifically used to: allocate corresponding encryption resources to the decrypted 5G raw data according to the encryption priority, and perform a first encryption process on the decrypted 5G raw data based on the encryption resources, according to the encryption algorithm and the encryption key, to obtain the first data to be transmitted.

[0064] The encryption / decryption module 303 allocates independent encryption resources for TSN streams of different priorities, ensuring low latency for high-priority streams.

[0065] The encryption / decryption module 303 also establishes independent encryption channels for TSN streams of different priorities. Each channel has a dedicated key store, state machine, and data buffer. High-priority streams (such as the Credit-Based Shaper queue for TSN) are assigned to encryption cores with faster clock frequencies and enjoy priority scheduling. This resource allocation is implemented through a hardware queue management system, ensuring that critical control flows receive low-latency encryption services even during network congestion.

[0066] In some embodiments, the key management module 304 is further configured to: detect the usage time of the encryption key and / or the amount of encrypted data; and update the encryption key if the usage time of the encryption key is greater than or equal to a preset duration threshold or the amount of encrypted data is greater than or equal to a preset data amount threshold.

[0067] The key rotation mechanism of the key management module 304 is based on dual trigger conditions: time and usage. Time-triggered rotation is performed automatically according to a predefined key lifespan (e.g., 24 hours), while usage-triggered rotation begins when the amount of encrypted data reaches a threshold (e.g., 1GB). Forward security is achieved through ECDH key negotiation. Each rotation generates a new temporary key pair (the encryption key used to encrypt data during the 5G→TSN process, and the decryption key used to decrypt data during the TSN→5G process), ensuring that even long-term key leakage will not affect the security of historical communications. The rotation process employs seamless switching technology to avoid communication interruptions, thus supporting automatic key rotation and forward security.

[0068] In some embodiments, the key management module 304 also provides a secure key storage and destruction mechanism. Key storage utilizes tamper-proof memory within the FPGA and employs Physically Unclonable Function (PUF) technology to protect the root key. All keys are encrypted during storage, with the encryption key derived from the PUF. The key destruction mechanism includes immediate erasure and overwrite, automatically executed upon detection of a physical attack or the end of a session. Furthermore, key backup and recovery functions are provided, using a threshold secret sharing scheme to fragment keys and store them in multiple secure areas.

[0069] In some embodiments, the 5G and TSN communication device 30 further includes a centralized management platform 305, which is configured to: send a security policy template to the security context extraction module 302 so that the security context extraction module 302 determines a security policy based on the security policy template; and send key management rules to the key management module 304 so that the key management module 304 updates the encryption key based on the key management rules.

[0070] A unified security policy is issued to the distributed DS-TT through a centralized security management platform, building a unified security policy management architecture that supports real-time security status detection and dynamic policy adjustment.

[0071] In some embodiments, the encryption / decryption module 303 is specifically used for: verifying the integrity of the 5G raw data; and performing a first decryption process on the 5G raw data if the integrity verification of the 5G raw data passes.

[0072] In some embodiments, the forwarding module 301 is further configured to receive TSN raw data sent by the TSN network device 20 and send the TSN raw data to the encryption / decryption module 303; the encryption / decryption module 303 is further configured to perform a second decryption process on the TSN raw data and send the decrypted TSN raw data to the forwarding module 301; the forwarding module 301 is further configured to convert the decrypted TSN raw data into second target data conforming to the 5G transmission standard and send the second target data to the 5G network device 10.

[0073] In some embodiments, the encryption / decryption module 303 is specifically used to: retrieve a decryption key based on the security parameter index in the original TSN data packet, wherein the decryption key corresponds to the encryption key; and perform a second decryption process on the original TSN data based on the decryption key.

[0074] In some embodiments, the encryption / decryption module 303 is specifically used to: perform security verification on the TSN raw data; the security verification includes at least one of the following: verifying the security header format, verifying the validity of the security parameter index, and verifying whether the serial number is within a preset range; and if the security verification of the TSN raw data passes, perform a second decryption process on the TSN raw data.

[0075] In some embodiments, the 5G and TSN communication device 30 further includes a threat detection module 306 and a security actuator 307; the threat detection module 306 is used to: detect the traffic pattern and / or sequence number of the data flowing through the 5G and TSN communication device 30; identify whether a security threat exists based on the traffic pattern and / or sequence number of the data flowing through the 5G and TSN communication device 30 through machine learning; if a security threat exists, generate a security event and report it to the security actuator 307; the security actuator 307 is used to: determine and control other modules in the 5G and TSN communication device 30 to execute protection strategies based on the security event, the protection strategies being used to prevent data with security threats from causing security incidents.

[0076] The threat detection module 306 detects abnormal traffic patterns in real time, including DDoS attacks and replay attacks. It identifies security threats through multiple detection dimensions. Traffic pattern analysis includes features such as packet rate statistics, flow size distribution, and protocol type ratios. DDoS detection uses an entropy-based anomaly detection algorithm to identify traffic spikes and abnormal source address distributions. Replay attack detection maintains a sequence number window, discarding packets outside a reasonable range. All detection metrics are calculated in real time, with a detection latency of less than 100 microseconds.

[0077] The threat detection module 306 identifies potential security threats based on machine learning algorithms. The machine learning model employs a lightweight neural network architecture, suitable for hardware acceleration in FPGAs. Feature engineering extracts temporal features including packet interval time, payload size distribution, and flow duration. Model training uses labeled data of normal traffic and known attacks, and anomaly scores are evaluated in real-time during the online inference phase. The model supports online updates, adapting to new attack patterns. Detection results include a confidence score for subsequent decision-making.

[0078] Protection strategies may include temporarily blocking suspicious flows, adjusting encryption strength, and triggering key updates.

[0079] The threat detection module 306 works in conjunction with the safety actuator 307 to achieve dynamic protection.

[0080] The threat detection module 306 and the security executor 307 communicate in real time via an event bus. When a threat is detected, the threat detection module 306 immediately generates a security event, including information such as the threat type, severity, and affected flows. The security executor 307 takes action according to predefined response strategies, such as temporarily blocking suspicious flows, adjusting encryption strength, or triggering key updates. The linkage mechanism supports multi-level responses, from warnings to proactive defense, achieving adaptive security protection.

[0081] In some embodiments, the 5G and TSN communication device 30 further includes a statistics module 308, which is used to: count the encrypted traffic or decrypted traffic during the encryption or decryption process of the encryption module 303, and generate and report security statistics information.

[0082] The statistics module 308 collects security-related statistics, including encrypted traffic statistics, authentication success rate, and threat detection results. The statistics collection covers multiple dimensions, including encryption operations, authentication events, and threat detection. Encryption statistics include the amount of encrypted data, algorithm usage, and error count for each security-related event. Authentication statistics record the number of successful / failed authentications, authentication latency, and certificate verification results. Threat detection statistics collect metrics such as the number of alarms, type distribution, and false alarm rate. All statistics are stored with timestamps, supporting time-series analysis.

[0083] The statistics module 308 reports security status to the management platform via a security interface. This interface uses a standardized data model and supports both RESTful API and NETCONF protocols. Security status reports include real-time metrics and aggregated statistics, supporting both on-demand querying and scheduled push notifications. Report content uses digital signatures to ensure integrity, and sensitive information is transmitted encrypted. The interface supports filtering and aggregation functions, allowing the management platform to obtain specific dimensions of security information as needed.

[0084] The statistics module 308 also supports security auditing and compliance checks. The auditing function logs all security-related events, including key operations, policy changes, and threat detection results. Audit logs use a tamper-proof storage structure, containing consecutive sequence numbers and hash chains. Compliance checks are based on predefined security policy templates, such as NIST CSF and ISO 27001 standards. Compliance reports are automatically generated, highlighting non-compliance items and improvement recommendations. Audit log retention time is configurable to meet different regulatory requirements.

[0085] In some embodiments, the security context extraction module 302 detects changes in the 5G security status in real time and dynamically adjusts the security policy. The security context extraction module 302 continuously monitors 5G security status indicators, including key update events, security algorithm switching, and authentication status changes. When a security status change is detected, a dynamic policy adjustment mechanism is triggered. For example, when the 5G network performs a key update, the security context extraction module 302 automatically triggers the corresponding security-associated key update on the TSN side; when a security threat is detected, the encryption strength is dynamically increased or the security algorithm is switched. This real-time detection is implemented through an event-driven architecture, ensuring the timeliness and accuracy of the security policy.

[0086] In some embodiments, the 5G and TSN communication device 30 may further include a security authentication module 309.

[0087] The security authentication module 309 enables bridging of 5G AKA and TSN MACsec authentication. It achieves interoperability between 5G AKA and TSN MACsec through protocol conversion. After the 5G UE completes AKA authentication, the security authentication module 309 extracts the authentication vector and session key, converting them into the SAK (Security Association Key) used by MACsec. The bridging process maintains the consistency of the authentication state, ensuring that only devices that have passed 5G authentication can establish a TSN security association. It also supports real-time synchronization of authentication parameters, including key validity period and authentication algorithm preferences.

[0088] The security authentication module 309 supports two-way device authentication and certificate management. Two-way authentication is based on the X.509 digital certificate system and uses the ECC-256 algorithm for certificate verification. Device certificates include extended fields such as manufacturer information, device type, and security capabilities. Certificate management functions include certificate issuance, verification, and revocation list (CRL) checks. The authentication process employs a challenge-response mechanism, combined with timestamps to prevent replay attacks. The security authentication module 309 also supports automatic certificate updates and online status verification to ensure the real-time validity of authentication.

[0089] The security authentication module 309 also provides secure boot and firmware integrity verification. Secure boot employs a multi-stage verification mechanism, starting from the Boot ROM and verifying the integrity and authenticity of the bootloader, operating system kernel, and application software level by level. Verification uses RSA-2048-based digital signatures, with the signature key stored in the hardware security module. Firmware integrity verification uses secure hash comparisons to periodically check critical firmware components for tampering during operation. Upon detecting integrity corruption, it automatically enters secure recovery mode.

[0090] In some embodiments, the forwarding module 301, security context extraction module 302, encryption / decryption module 303, key management module 304, threat detection module 306, security executor 307, statistics module 308, and security authentication module 309 may actually be functional modules deployed in the DS-TT device, while the centralized management platform 305 is deployed outside the DS-TT device.

[0091] The aforementioned technical solution addresses the core cybersecurity needs of the Industrial Internet and intelligent manufacturing sectors. It solves the security challenges in 5G and TSN converged networks through an innovative hardware security architecture, complements the timing capabilities of China Unicom's PNT (Programmable Node.js) system, upgrades traditional Ethernet to a deterministic network, and reshapes the industrial communication architecture. It achieves high-precision synchronization and deterministic latency in a standardized manner, meeting the needs of deterministic real-time communication in scenarios such as industrial automation, autonomous driving, and smart grids. Its feasibility for implementation is mainly reflected in the following aspects: 1. Performance Advantages: Hardware encryption latency <10μs, meeting TSN deterministic requirements. Supports flexible selection of multiple encryption algorithms, balancing security and performance. Power consumption is lower than software encryption schemes, suitable for deployment on terminal devices.

[0092] 2. Wide range of applications: (1) Industrial control: Protect the communication security of key equipment such as robots and PLCs.

[0093] (2) Smart grid: Ensure the confidentiality and integrity of power control commands.

[0094] (3) Internet of Vehicles: Protecting secure communication between vehicles and infrastructure.

[0095] (4) Medical equipment: Ensure the reliable and safe operation of telemedicine equipment.

[0096] 3. Industrialization: We can cooperate with equipment manufacturers and system integrators to promote industrialization.

[0097] In summary, the data processing flow in the 5G and 5SN communication device 30 is as follows: 1. Forward secure data processing (5G→TSN), such as Figure 2 As shown: 5G data arrives: The 5G and TSN communication device 30 receives 5G data.

[0098] The centralized management platform updates its policy rules.

[0099] Integrity verification is performed. If the verification passes, the subsequent steps of obtaining the 5G security context are carried out. If the verification fails, the incomplete 5G data is discarded.

[0100] Obtaining the 5G security context: When 5G data arrives, the module first identifies the PDU session identifier and retrieves the complete security context from the active session table. This includes the currently used encryption key, integrity protection key, security algorithm identifier, and QoS flow characteristics. The extraction process is completed via direct memory access, ensuring low latency and high efficiency.

[0101] Generate TSN security policy: Based on the extracted security context, the policy mapping engine queries the policy rule base to determine the corresponding TSN security parameters. The mapping considers multiple factors: 5G security level is mapped to TSN encryption strength, 5QI parameters are mapped to TSN stream priority, and session characteristics determine the security protocol selection. Output a complete TSN security policy descriptor.

[0102] A centralized management platform is used for key distribution management.

[0103] Encryption Algorithm and Key Selection: Choose the optimal encryption scheme (including encryption algorithm and key) based on traffic characteristics and security requirements. For critical control flows, prioritize the low-latency AES-GCM algorithm; for large data flows, use the high-throughput ChaCha20 algorithm; and for management traffic, employ AES-CCM, balancing performance and security. The selection process considers hardware resource availability and performance requirements.

[0104] Hardware-accelerated processing: Data enters the FPGA encryption pipeline, undergoing preprocessing, key loading, round-robin computation, and post-processing stages. The encryption process uses a dedicated secure DMA channel to avoid memory copy overhead. Integrity protection and encryption are executed in parallel, generating authentication tags. The entire process guarantees deterministic latency.

[0105] Add a security header: A security header is added to the encrypted data, containing information such as the Security Parameter Index (SPI), serial number, and initialization vector. The header format is optimized for 32-byte alignment for easier hardware processing. The serial number employs an anti-wrap design to support long-cycle communication.

[0106] The centralized management platform performs security status checks.

[0107] Security statistics updates: Multiple statistical counters are updated, including encrypted byte count, message count, and algorithm usage statistics. Statistical information is stored in a dual-port memory, supporting real-time querying and periodic reporting. Important statistical events trigger threshold alarms.

[0108] Reverse secure data processing (TSN→5G), such as Figure 3 As shown: TSN data arrival: The 5G and TSN communication device 30 receives TSN data.

[0109] Security Verification: The received TSN data undergoes security verification, checking the security header format, SPI validity, sequence number range, etc. If the security verification passes, the process proceeds to the subsequent decryption steps; if the security verification fails, the TSN data is considered invalid, and the TSN data is immediately discarded and a security event is recorded. The verification process uses a hardware-accelerated state machine.

[0110] Decryption Processing: The corresponding decryption key and security parameters are retrieved based on the SPI, and the data packet enters the decryption pipeline. The decryption process is symmetrical to encryption but uses a different key scheduling. Authentication tag verification and decryption are performed in parallel; processing terminates immediately upon failure.

[0111] Replay protection: Maintains a receive window and checks if the sequence number is within the valid range. A sliding window mechanism is used to detect duplicate packets; the window size is configurable to suit different application scenarios. Replay packets are discarded and a security alarm is generated.

[0112] Security context recovery: Based on the security association mapping table, the decrypted data is restored to the format expected by the 5G protocol. The 5G security context is reconstructed, including adding necessary protocol headers and restoring QoS flags.

[0113] Forward to 5G network: Transmit data that has been restored with a security context to the 5G network.

[0114] The following describes the process of data forwarding and transmission by the hardware-encrypted 5G and TSN communication device provided in the embodiments of this application from the perspective of method and flow: 1. Initialization phase: 1.1 The DS-TT on the robot has completed 5G AKA certification with the 5G core network; 1.2 The centralized management platform issues a unified security policy to DS-TT; 1.3 Establish a mapping relationship between 5G security context and TSN security policy.

[0115] 2. Control command transmission: 2.1 The central controller sends encrypted control commands to DS-TT via the 5G network; 2.2 The security context extraction module identifies this as a critical control flow, requiring high security safeguards; 2.3 The unified encryption and decryption engine uses the AES-GCM algorithm for encryption, with a latency of <10μs; 2.4 Add a security header containing a timestamp and serial number to prevent replay attacks; 2.5 The encrypted data is sent to the robot controller via the TSN network.

[0116] 3. Data collection and feedback: 3.1 Robot sensor data reaches DS-TT via the TSN network; 3.2 The threat detection module detects data streams and anomaly patterns; 3.3 The encryption / decryption module verifies data integrity and decrypts it; 3.4 Restore the 5G security context and send data to the central controller via the 5G network.

[0117] 4. Dynamic security management: 4.1 The centralized management platform monitors the security status of each DS-TT in real time; 4.2. Dynamically adjust security strategies based on security incidents; 4.3. Rotate encryption keys regularly to ensure forward security.

[0118] This application also provides an electronic device, including a processor and a memory. The memory stores computer execution instructions. The processor is connected to the memory. When the electronic device is running, the processor executes the computer execution instructions stored in the memory, so that the electronic device can realize the process of forwarding and transmitting data by the 5G and TSN communication device provided in the above embodiments.

[0119] This application also provides a computer-readable storage medium, including computer-executable instructions that, when run on a computer, cause the computer to perform the process of forwarding and transmitting data using the 5G and TSN communication devices provided in the above embodiments.

[0120] This application also provides a computer program product containing computer execution instructions, which, when run on a computer, enables the computer to perform the process of forwarding and transmitting data using the 5G and TSN communication devices provided in the above embodiments.

[0121] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer-executable instructions. When these computer-executable instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer-executable instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer-executable instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).

[0122] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, disclosure, and appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.

[0123] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.

[0124] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A 5G and TSN communication device, characterized in that, include: The system includes a forwarding module, a security context extraction module, and an FPGA-supported encryption / decryption module. The forwarding module is used to receive 5G raw data sent by 5G network devices and forward the 5G raw data to the security context extraction module. The security context extraction module is used to obtain the 5G security context based on the 5G raw data, obtain the security policy based on the 5G security context, and forward the security policy to the encryption / decryption module. The encryption / decryption module is used to perform a first decryption process on the 5G raw data, and then perform a first encryption process on the decrypted 5G raw data based on the security policy to obtain a first data to be transmitted, and send the first data to be transmitted to the forwarding module. The forwarding module is further configured to convert the first data to be transmitted into first target data conforming to the TSN transmission specification, and send the first target data to the TSN network device.

2. The apparatus according to claim 1, characterized in that, The security context extraction module is specifically used for: The security context is obtained by indexing from a preset security context library based on the identification information of the raw 5G data.

3. The apparatus according to claim 1, characterized in that, The security context includes: The K_gNB key, the encryption algorithm identifier and integrity protection algorithm identifier used for 5G network negotiation, and the QoS flow identifier and 5G QoS indicators associated with the data stream of the raw 5G data.

4. The apparatus according to claim 3, characterized in that, The security strategy includes the encryption priority and encryption algorithm corresponding to the decrypted 5G raw data; The security context extraction module is specifically used for: The encryption priority corresponding to the decrypted 5G raw data is determined based on the priority indicated by the QoS flow identifier. Based on the encryption algorithm identifier, the encryption algorithm corresponding to the decrypted 5G raw data is determined.

5. The apparatus according to claim 4, characterized in that, The device also includes a key management module; The security context extraction module is also used to send the 5G security context to the key management module; The key management module is used to: obtain the K_gNB key from the 5G security context, and derive the session key based on the K_gNB key; Based on the session key and the identifier of the decrypted 5G raw data, an encryption key corresponding to the decrypted 5G raw data is generated. Configure the encryption key to the encryption / decryption module.

6. The apparatus according to claim 5, characterized in that, The encryption / decryption module is specifically used for: According to the encryption priority, corresponding encryption resources are allocated to the decrypted 5G raw data. Based on the encryption resources, the decrypted 5G raw data is subjected to a first encryption process according to the encryption algorithm and the encryption key to obtain the first data to be transmitted.

7. The apparatus according to claim 6, characterized in that, The key management module is also used for: Detect the usage time of the encryption key and / or the amount of encrypted data; If the duration of use of the encryption key is greater than or equal to a preset duration threshold or the amount of encrypted data is greater than or equal to a preset data amount threshold, the encryption key shall be updated.

8. The apparatus according to claim 5, characterized in that, The device also includes a centralized management platform, which is used for: A security policy template is sent to the security context extraction module so that the security context extraction module determines the security policy based on the security policy template; Send key management rules to the key management module so that the key management module updates the encryption key based on the key management rules.

9. The apparatus according to claim 1, characterized in that, The encryption / decryption module is specifically used for: The integrity of the raw 5G data is verified. If the integrity verification of the 5G raw data passes, the 5G raw data undergoes a first decryption process.

10. The apparatus according to claim 5, characterized in that, The forwarding module is also used to receive raw TSN data sent by the TSN network device and send the raw TSN data to the encryption / decryption module; The encryption / decryption module is further configured to perform a second decryption process on the TSN raw data and send the decrypted TSN raw data to the forwarding module; The forwarding module is also used to convert the decrypted TSN raw data into second target data that conforms to the 5G transmission standard, and send the second target data to the 5G network device.

11. The apparatus according to claim 10, characterized in that, The encryption / decryption module is specifically used for: Based on the security parameter index in the original TSN data packet, a decryption key is retrieved, and the decryption key corresponds to the encryption key. The original TSN data is subjected to a second decryption process based on the decryption key.

12. The apparatus according to claim 10, characterized in that, The encryption / decryption module is specifically used for: The raw TSN data is subjected to security verification; the security verification includes at least one of the following: verifying the security header format, verifying the validity of the security parameter index, and verifying whether the serial number is within a preset range; If the security verification of the original TSN data passes, a second decryption process is performed on the original TSN data.

13. The apparatus according to any one of claims 1-12, characterized in that, The device also includes a threat detection module and a safety actuator; The threat detection module is used for: Detect the flow pattern and / or serial number of the data flowing through the device; Based on the traffic patterns and / or serial numbers of the data flowing through the device, machine learning is used to identify whether a security threat exists. If present, a security event is generated and reported to the security actuator; The safety actuator is used for: Based on the security incident, other modules in the device are identified and controlled to execute protection strategies, which are used to prevent data with security threats from causing security incidents.

14. The apparatus according to any one of claims 1-12, characterized in that, The device further includes a statistics module, which is used for: During the encryption or decryption process of the encryption module, the encryption or decryption traffic is counted, and security statistics are generated and reported.

15. A 5G and TSN communication system, characterized in that, Includes: 5G network equipment, TSN network equipment, and a 5G and TSN communication device as described in any one of claims 1-14.