A remote terminal equipment secure networking communication system

By fragmenting, compressing, and concealing data transmission from remote terminal devices, combined with redundant link transmission, the security and reliability issues of data transmission between remote terminal devices and the control center are resolved, thereby improving network transmission security and reliability without replacing the equipment.

CN122137571APending Publication Date: 2026-06-02SUPCON TECH CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUPCON TECH CO LTD
Filing Date
2026-01-14
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In existing technologies, data transmission between remote terminal devices and control centers suffers from low security and reliability issues, and replacing secure RTU devices leads to resource waste.

Method used

The system employs remote terminal protection devices to segment and compress real-time data, which is then transmitted covertly within the audio and video streams. Data transmission is achieved using n+1 redundant links, and the data is stored offline. Data parsing and transmission strategy adjustments are performed through a central protection device.

Benefits of technology

It improves the confidentiality, integrity, and reliability of data transmission, avoids waste of resources, and does not require replacement of existing equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137571A_ABST
    Figure CN122137571A_ABST
Patent Text Reader

Abstract

This invention discloses a secure networking communication system for remote terminal devices, solving the problems of low security and reliability of data transmission between RTUs and control centers in existing technologies, and the resource waste caused by secure RTUs. The system includes: a remote terminal protection device that collects, fragments, and compresses real-time data from the RTU, concealing the compressed data within audio and video streams, using n+1 redundant links for data transmission, storing offline data, and transmitting and storing the collected real-time data without application layer protocols; and a central protection device that parses the real-time tag data sent by the remote terminal protection device, determines the presence of network intrusion based on changes in the tag data, and dynamically adjusts the transmission strategy based on communication traffic. This system improves the confidentiality, integrity, and reliability of remote data transmission, enhancing network transmission security while preserving fixed investments and reducing resource waste.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission security protection technology, and in particular to a secure networking communication system for remote terminal devices. Background Technology

[0002] During the transmission of oil, gas, or electricity, there are a considerable number of remote stations or unattended RTUs (Remote Terminal Units). These devices collect real-time monitoring and control data or video data from nearby equipment and upload them to the control center via dedicated or public networks, while also receiving signaling and other information from the control center.

[0003] For example, patent CN117439267A describes an intelligent monitoring system and method for power systems. A data acquisition module acquires analog signals from sensor modules in real time and converts them into digital signals. A remote communication module transmits the digital signals to a central processing module. The central processing module summarizes and analyzes the received digital signals to obtain equipment status parameters and operating parameters, thus enabling power system monitoring. Based on the monitoring data, the central processing module uses intelligent analysis algorithms to optimize the power system's control strategy. When monitoring data is abnormal, the central processing module issues control commands or alarms. Remote stations are far from the control center, and in some environments, data needs to be transmitted through networks lacking security and reliability. This poses risks such as data leakage, network intrusion at the station or control center, and link disruption, leading to a loss of confidentiality, integrity, and reliability in bidirectional data transmission, causing production losses. While existing designs and developments of secure RTUs can improve the security of remote data transmission, using secure RTUs requires replacing the RTUs on the station side and the transceiver terminals on the control center side, resulting in a waste of initial investment and implementation difficulties. Summary of the Invention

[0004] The purpose of this invention is to solve the problems of low security and reliability of data transmission between RTU and control center in the prior art, and the easy waste of resources caused by secure RTU. It provides a secure networking communication system for remote terminal equipment, which improves the confidentiality, integrity and reliability of remote data transmission, and can improve the security of network transmission and reduce resource waste while preserving fixed investment.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: A secure networking communication system for remote terminal devices, comprising: The remote terminal protection device collects, segments, and compresses the real-time data of the RTU, hides the compressed data in the audio and video stream, uses n+1 redundant links for data transmission, stores the data offline during offline periods, and transmits and stores the collected real-time data without application layer protocol. The central protection device parses the real-time tag data sent by the remote terminal protection device, determines whether there is a network intrusion based on the changes in the tag data, and dynamically adjusts the transmission strategy according to the communication traffic.

[0006] The secure networking communication system for remote terminal devices provided by this invention does not require replacing the data transmission devices on the remote site or central side. By segmenting and compressing the collected real-time data and concealing the compressed data within the audio and video streams, data security can be improved. Simultaneously, n+1 redundant links are employed to enhance data transmission reliability.

[0007] As a preferred method, concealing the compressed data within the audio and video stream includes: automatically detecting whether an audio and video stream exists on-site; if it does, encoding the real-time tag data into the pixel redundancy bits or audio frequency gaps of the audio and video stream; if no audio and video stream exists, generating a simulated environmental noise stream and embedding the tag data into the noise; high-priority tag data is encoded into the earlier segments of the audio and video stream, and the encoding depth is configured according to security requirements, with higher security scenarios occupying more pixel bits.

[0008] As a preferred option, when transmitting data, if the remote terminal protection device uses multi-link load balancing, it will further split the encrypted data and distribute the split data across multiple communication links according to bandwidth and latency; if the data transmission network is a mesh layout, it will transmit the split data fragments as units and destroy them after successful data transmission; when used in a network, it will store the data fragments transmitted by the upstream nodes.

[0009] Preferably, the method of using n+1 redundant links for data transmission includes: if there is only one available communication path from the RTU to the control center, the data is split into segments before transmission and transmitted directly; if there are multiple communication paths from the RTU to the control center, the bandwidth and latency of each communication path are tested, and the currently transmitting n+1 communication paths are selected. Continuous data segments are transmitted on n of these communication links, and the parity check values ​​of the first n data segments are transmitted on another link; the channel for transmitting the parity check values ​​is selected by sequential rotation.

[0010] Preferably, the remote protection device includes an offline storage module. When all communication links are interrupted, the offline storage module temporarily stores the data to be sent in segments, prioritizing the storage of highly sensitive data. When the storage capacity threshold is reached, the earliest ordinary data is deleted first. After communication is restored, the temporarily stored data is used as historical data transmission. After the historical data is successfully transmitted, the cached data is destroyed.

[0011] As a preferred method, the data to be destroyed in the cache includes: determining whether the data is sensitive; if it is not sensitive, and the control center sends a historical data reception confirmation, a three-stage overwrite mechanism is used to destroy the locally stored data, successively overwriting 0x00, 0xFF, and a random value; after destruction, a destruction verification code is generated and sent to the control center, which compares the verification code to confirm successful destruction; if destruction fails, the storage partition is locked. If it is sensitive data, and one of the following is received: a historical data reception confirmation signal, a device offline signal, a policy update signal, or an authentication failure signal, a seven-stage overwrite and storage partition formatting method is used to strengthen the destruction of sensitive data.

[0012] Preferably, the central protection device includes a data review module, which identifies and detects intrusion information and audio / video data collected by the RTU, and detects the risks of remote terminals or sites according to pre-configured strategies: for real-time tag number data and historical tag number data, it monitors the tag number value change, tag number value change frequency, tag number value, and tag number change rate over time according to pre-configured strategies, and blocks current communication or sends an alarm when an anomaly is detected in the tag number; for audio / video information, it uses machine learning algorithms to identify the on-site environment, and alarms or blocks communication when on-site anomalies are detected.

[0013] Preferably, the central protection device includes a data flow control module. Based on the monitoring of historical bandwidth and site data, the data flow control module establishes a communication traffic model for each site, allocates historical data uploading strategies for each RTU in real time according to the communication traffic model, and dynamically adjusts the uploading of real-time data and historical data.

[0014] Preferably, both the central protection device and the remote terminal protection device include a transmission strategy module. The transmission strategy module includes a signaling protection strategy. The signaling protection strategy encrypts the control signaling between the control center and the RTU using SM4+ timestamp encryption. If the timestamp error exceeds the time threshold, the control signaling is discarded. At the same time, a CRC32 checksum is added to each signaling message. The control center or RTU verifies the message upon receipt. If the verification fails, execution is rejected and an alarm is triggered.

[0015] Preferably, the remote terminal includes: The data classification module categorizes the data collected from the RTU according to the region of the data source, priority, and real-time performance. The data compression / decompression module efficiently compresses the real-time tag data to be sent into fragments and decompresses the received data. The physical environment monitoring module collects environmental fingerprints; The communication authentication module authenticates and monitors the entire connection and communication process. Authentication is based on software information credentials, hardware credentials, and remote site fingerprint credentials. Data to be sent is cleared when authentication fails.

[0016] Preferably, the central protective device includes: The data distribution module converts and restores the data sent by the remote terminal protection device. The hidden data extraction module extracts the real-time tag number data stream from the audio and video stream that encodes the real-time tag number data, and erases the real-time tag number data stream from the audio and video stream; The data fragmentation and combination module merges, restores, and verifies data fragments that have been transmitted through multiple paths, forming the original data stream. The physical environment monitoring module collects environmental fingerprints for communication authentication; The communication authentication module authenticates and monitors the communication process. Authentication criteria include software information credentials, hardware credentials, and remote site fingerprint credentials. Data to be sent is cleared when authentication fails.

[0017] Therefore, the present invention has the following beneficial effects: 1. By fragmenting, compressing, and encrypting the real-time data collected by the RTU, data can be prevented from being eavesdropped on or destroyed. At the same time, it can also reduce the consumption of network bandwidth resources and reduce the network processing burden. The use of n+1 redundant links ensures that data can still be delivered correctly even if some data is lost, making it difficult for intruders to intercept all traffic for analysis and attack.

[0018] 2. The remote terminal supports offline storage of data during offline periods, ensuring that data is not permanently lost during disconnection; the collected real-time data is transmitted and stored without application layer protocols, overcoming the obstacles inherent in application layer protocols themselves. Attached Figure Description

[0019] Figure 1 This is a structural block diagram of the secure networking communication system for remote terminal devices in this invention.

[0020] Figure 2 This is a flowchart of the connection establishment strategy in Embodiment 2.

[0021] Figure 3 This is a flowchart of the data concealment strategy in Embodiment 2. Detailed Implementation

[0022] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments: Example 1: This embodiment provides a secure networking communication system for remote terminal devices, such as... Figure 1As shown, it includes: a remote terminal protection device and a central protection device. The remote terminal protection device and the central protection device are interconnected. In each set of secure network communication systems, there is only one central protection device, which is deployed at the control center. There can be multiple remote terminal protection devices, that is, each remote terminal or station is deployed as a gateway to handle all incoming and outgoing traffic of the remote terminal or station.

[0023] The remote terminal protection device is used to collect, fragment, and compress real-time data from the RTU, conceal the compressed data in the audio and video stream, use n+1 redundant links for data transmission, store data offline during offline periods, and transmit and store the collected real-time data without application layer protocols.

[0024] The central protection device is used to parse the real-time tag data sent by the remote terminal protection device, determine whether there is a network intrusion based on the changes in the tag data, and dynamically adjust the transmission strategy according to the communication traffic.

[0025] RTU stands for Remote Terminal Unit; a station is an intermediate node in an oil and gas transportation or power grid environment that manages the pipeline or power grid. Stations have PLC controllers, cameras, or other data acquisition systems, and the collected data is transmitted to the control center for unified monitoring, storage, and management.

[0026] The control center is used to manage the controllers, cameras, and other hardware located at multiple stations, receiving tag data or monitoring data from the stations. It performs unified monitoring, storage, and management of the received data.

[0027] The data transmitted from remote terminals to the control center mainly includes real-time tag numbers, equipment diagnostic information, field environmental monitoring information, and audio / video data. The control center transmits control signaling and configuration data to remote terminals, with relatively low data volume. Due to the large number of monitoring sites and the large number of devices at each site, the total data volume is enormous, resulting in high data volume, and there are also high requirements for real-time data transmission.

[0028] In this embodiment, the deployment of the secure networking communication system for remote terminal devices does not require changes to the existing network structure on site, nor does it require replacement of the existing remote terminals or control center hardware and software. This can increase network transmission security while avoiding existing investment losses.

[0029] The following examples and specific application scenarios further illustrate the technical solution and effects of the present invention. The following examples are explanations of the present invention, but the present invention is not limited to the following examples.

[0030] In summary, to address the shortcomings of existing technologies, this embodiment provides a secure networking communication system for remote terminal devices, including a remote terminal protection device and a central protection device. Both the remote terminal protection device and the central protection device include multiple modules, each used to implement different functions. The remote terminal protection device and the central protection device will be further described below.

[0031] I. Remote terminal protection device.

[0032] The remote terminal protection device is installed on the remote terminal side of the link between the remote terminal and the control center. The remote terminal protection device includes: a local communication transmission module, a data acquisition module, a data classification module, a data compression / decompression module, a data concealment module, an offline storage module, a data encryption / decryption module, a data splitting and multi-path transmission module, a physical environment monitoring module, a communication authentication module, a remote communication transmission module, and a transmission strategy management module.

[0033] The function of each module is explained in detail below.

[0034] 1. Local communication transmission module.

[0035] The local communication transmission module is used to connect to the data terminal at the remote site, enabling communication with the data terminal. The local communication transmission module includes physical hardware (such as network interface cards, serial communication cards, and necessary peripherals) and the necessary software for communication (drivers, protocol stacks, etc.). The data terminal is existing equipment in the field, which can be terminal devices such as RTUs, controllers, and data acquisition computers, or independent smart sensors, as well as field status acquisition devices such as cameras or hard disk recorders that collect monitoring video. These devices are used to collect and summarize real-time data from the field and receive control signals from the control center.

[0036] The local communication transmission module is a standalone hardware module, containing firmware or operating system-compatible software (drivers, etc.) running on it. It can be plugged into remote terminal protection devices as an independent component via common physical interfaces (such as PCIe, USB, etc.) for rapid deployment and replacement. The local communication transmission module provides a physical interface to connect to field physical networks (such as IEEE 802.3 Ethernet, RS-485 (EIA / TIA-485), CAN bus, HART, Foundation Fieldbus, other twisted-pair-based physical layers, and even DDZ-III analog signals), enabling data acquisition, transmission, and processing capabilities from field communication networks.

[0037] For example, when remote station data transmission uses only Ethernet, the remote terminal protection device only needs to provide an Ethernet module. When applied to specific industries such as oil and gas transportation, power, and water utilities, the local communication transmission module can provide corresponding physical interfaces based on the actual bus type used on-site, such as RS-232, RS-485, customized coaxial cables, optical fibers, APL, and even analog signals (e.g., DDZ-Ⅲ). The local communication transmission module also has the necessary hardware for communication processing, enabling efficient communication with specific protocols.

[0038] 2. Data acquisition module.

[0039] The data acquisition module is used to collect data from remote stations or transmit signaling from the control center to remote stations using a specified data transmission protocol. The collected data includes real-time tag number information and video surveillance information. The signaling from the control center contains control data from the center to the stations. The transmission protocol used depends on the support of the field equipment. The collected real-time tag number data will be separated from the application layer protocol and managed uniformly according to the configuration set by the control center.

[0040] The data acquisition module is a software module that is independent of other software (modules) and can be replaced or called according to the actual network protocol used on site.

[0041] 3. Data classification module.

[0042] The data classification module classifies the collected data according to strategies or intelligent learning-assigned strategies, categorizing the data by the region where the data source is located, priority strategies, and real-time performance.

[0043] 4. Data compression / decompression module.

[0044] The data compression / decompression module is used to slice the real-time data to be sent and then compress it efficiently before sending it. It is also used to decompress the received data and hand it over to the upper level for processing.

[0045] Since the audio and video stream data has already been compressed during encapsulation, this layer (data compression / decompression module) only compresses the real-time tag data, and does not process the audio and video stream data.

[0046] 5. Data concealment module.

[0047] Real-time location data transmitted from remote terminals to the control center is usually more important than audio and video monitoring data, and it is easier to analyze and use if intercepted. At the same time, the data volume of real-time location data transmitted from remote terminals is much smaller than the data volume of audio and video data transmitted on-site.

[0048] To reduce the risk of being analyzed and exploited, this embodiment uses a data concealment module and a specific algorithm to encode the real-time tag number data into the audio and video data stream, completely hiding the real-time tag number data stream at the scene.

[0049] Specifically: When there is no audio or video data stream at the remote terminal or the audio or video data stream is not transmitted along with the network used for communication by the remote terminal, the real-time tag number data is encoded into a random audio or video noise stream to obfuscate the real-time tag number data and reduce the risk of the real-time tag number data being discovered and used.

[0050] When real-time tag data is embedded in audio and video streams, the amount of data that can be hidden can vary within a certain range. Therefore, in conjunction with transmission strategies, the encoding order can be dynamically adjusted according to the priority of data fragments to ensure that high-priority data is transmitted along with the data stream fragments with earlier numbers in the audio and video stream.

[0051] 6. Offline storage module.

[0052] Due to the long transmission path and the inherent unreliability of the transmission link, communication anomalies may occur during real-time data transmission due to network interruptions leading to offline status, reduced network bandwidth, link switching, or damage to physical network connections. When using multi-path communication, communication between the remote terminal and the central control center will fail if all communication paths fail to transmit data normally.

[0053] To ensure that the real-time tag data and audio / video stream data generated by the remote station are not permanently lost during communication failures, the remote terminal protection device includes an offline storage module for providing temporary data storage during communication failures. This allows for the storage of data fragments to be sent during communication failures, which can then be used as historical data transmissions after communication is restored.

[0054] After the historical data is successfully transmitted to the control center, the original data node uses a secure erasure method to destroy the cached data, ensuring that the historical data cannot be easily recovered.

[0055] 7. Data encryption / decryption module.

[0056] The data encryption / decryption module is used to efficiently encrypt fragmented real-time or offline data before sending it when the network is good; received data from the control center is decrypted and then handed over to the upper layer for processing.

[0057] 8. Data splitting and multi-path transmission module.

[0058] (1) To ensure high availability of network links, remote sites typically use multiple transmission media or multiple transmission paths to transmit data. During data transmission, multi-link load balancing can be selected. In this case, the data needs to be split again and distributed across multiple communication links according to bandwidth, latency, and other factors. While reducing network load, this also further ensures that transmitted data is not easily leaked (it is difficult to intercept data on multiple links) or affected by a single link network outage (the load is automatically switched to other normal links), thus improving the confidentiality and reliability of transmission.

[0059] (2) When the data transmission network adopts a mesh layout, there are multiple reasonable communication paths from remote stations (terminals) to the control center. At this time, the secure transmission system can form a communication network, and the communication data with the control center is transmitted in multiple ways on the communication network using the above-mentioned data segments as units. The intermediate nodes of the multiple transmission realize the caching and reliability guarantee of the original station data, ensuring that it is destroyed only after successful transmission to the next station or control center.

[0060] (3) When the network is in use, each secure transmission system can store data fragments transmitted by upstream nodes (usually nodes that are far from the control center) to achieve reliable relay of data fragments.

[0061] (4) The data splitting and multi-path transmission module adopts the following data splitting strategy: (a) Remote stations communicate with the control center via a single link.

[0062] When there is only one available communication path between the remote station and the control center (direct communication via a single link), the data is split into appropriately sized segments (designed according to network traffic, bandwidth, latency requirements, etc.) before transmission begins.

[0063] (b) Remote stations communicate with the control center via multiple links.

[0064] When communication between a remote field station and the control center involves multiple paths (including a grid consisting of multiple redundant lines or multiple secure transmission systems), multiple transmission paths are planned before transmission is established, and parameters such as bandwidth and delay of each transmission path are tested to select multiple reliable paths suitable for transmission.

[0065] Multipath transmission enables load balancing (increasing effective bandwidth and making data capture and exploitation more difficult) and also achieves n+1 redundancy. This involves transmitting consecutive data fragments on n communication links, while the parity check value of the first n fragments is transmitted on another link. The channel for transmitting the parity check value is not fixed; it is selected sequentially in a round-robin fashion. In this transmission mode, even if one fragment fails to transmit, the complete data can still be obtained from the other n fragments.

[0066] 9. Physical environment monitoring module.

[0067] The physical environment monitoring module is used to collect fingerprints for communication authentication. It includes hardware, drivers, and corresponding algorithms for monitoring the physical environment.

[0068] The hardware includes sensors that collect environmental information, including: (1) Chassis intrusion detection (physical switch for detecting intrusion into the chassis of the remote transmission system and intrusion into remote terminal equipment or critical equipment, or cabinet intrusion detection as an alternative).

[0069] (2) Sensors of the surrounding environment of the data security transmission system and remote terminal (temperature and humidity, light, wind speed, electromagnetic radiation level, and concentration of key gas components in the environment).

[0070] (3) In addition to the data directly collected by the hardware sensors mentioned above, the collected data also includes key location data information of remote stations.

[0071] The physical environment monitoring module establishes a baseline or model based on the three or more types of information collected above, and verifies historical data from the most recent period during communication authentication to ensure the reliability of the physical environment.

[0072] 10. Communication authentication module.

[0073] The communication authentication module on the remote terminal side is used to authenticate and monitor the entire connection and communication process. During connection establishment, it presents its authentication and environment information to the central protection device to prove its authenticity. During communication after connection establishment, the communication authentication module monitors the communication and system status in real time. If an anomaly is detected (communication environment does not match the preset parameters), the central protection device will interrupt the data communication of the remote terminal protection device. The authentication policy is configured by the transmission policy management module.

[0074] In this embodiment, the secure networking communication system for remote terminal devices provides three types of authentication criteria, which can be used individually or in combination. Specifically, these include: (1) Software information certificate.

[0075] In addition to the passwords, certificates, and signatures built into the remote terminal protection device, the authentication information should also include verification of the remote terminal, including its inherent state (hardware and software configuration), current state, configuration, and connected peripheral devices. These credentials are either built into the remote protection terminal's file system or obtained by collecting local area network information. While simple to implement and easy to use, this method carries significant risks.

[0076] (2) Hardware credentials.

[0077] The remote and central protection devices incorporate a hardware root of trust (such as a TPM 2.0 chip or a Trusted Execution Environment (TEE)) to store device identity certificates, encryption keys, and policy configurations, ensuring that this core information is not maliciously read or tampered with. During authentication, the root of trust first verifies the integrity of the protection device's firmware (e.g., by checking the firmware hash value), and then performs two-way identity authentication, forming a progressive authentication chain of "system trust → identity trust".

[0078] (3) Remote site fingerprint certificate.

[0079] A new "Dynamic Device Fingerprint Module" has been added to collect runtime data from remote terminals / protection devices in real time. ① Hardware fingerprints (CPU utilization, memory read / write frequency, interface voltage fluctuations, and electrical characteristics of core circuits); ② Software fingerprint (process list, protocol stack version, log generation frequency); ③ Environmental fingerprint (station temperature and humidity, vibration value, power stability, collected by the above "physical environment monitoring module").

[0080] These dynamic fingerprints are compared with the "baseline fingerprints" stored in the root of trust. If a discrepancy is found (such as a sudden increase in vibration value indicating physical disassembly, or an unknown process appearing in the process list), authentication failure is immediately triggered and communication is blocked, rather than relying solely on static configuration verification.

[0081] The communication authentication module provides two-way authentication. Besides proving its own authenticity to the control center, it also needs to verify the authenticity and reliability of the control center. The verification method is the same as the three types mentioned above. When verification fails, the data to be sent in the communication module will be securely cleared.

[0082] 11. Remote communication transmission module.

[0083] The remote communication transmission module comprises hardware and software. The hardware includes physical layer hardware such as Ethernet cards and modems for enabling remote data transmission; the software includes necessary communication protocol stacks, as well as address masquerading modules and firewall modules.

[0084] (1) Address masquerading module.

[0085] The address masquerading module is used to mask the communication addresses and other information between remote terminals and the control center, preventing intruders from actively probing the network configuration on either the remote terminal or the control center side by eavesdropping on network communication data streams or infiltrating the link. Each remote terminal uses a separate network segment when communicating with the control center.

[0086] (2) Firewall module.

[0087] The firewall module is used to defend against common network attacks and to allow or block corresponding MAC addresses, IP addresses, ports, etc., according to the actual communication configuration.

[0088] 12. Transmission strategy management module.

[0089] The transmission strategy management module is used to receive transmission strategies from the control center and apply them to the entire transmission process. It is mainly used to execute and monitor the above processes.

[0090] II. Central protective device.

[0091] The central protection device is located on the control center side, between the remote terminals and the control center. The central protection device and the remote terminal protection devices have a one-to-many relationship; that is, one central protection device connects to multiple remote terminal protection devices. Each remote terminal protection device can communicate directly with the control center, or they can form a network based on geographical distribution, communicating through multiple intermediate remote terminal protection devices.

[0092] The central protection device includes a local communication transmission module, a data distribution module, a data auditing module, a real-time data processing module / historical data processing module, a data compression / decompression module, a covert data extraction module, a data encryption / decryption module, a data fragmentation and combination module, a data flow control module, a physical environment monitoring module, an authentication center module, a remote communication transmission module, and a transmission strategy management module.

[0093] The central protection device and the remote terminal protection device have modules with relatively equivalent functions. The following description focuses only on the functions that are different from those of the remote terminal protection device.

[0094] 1. Local communication transmission module.

[0095] The local communication transmission module is used to connect to the data acquisition server, master station, video recorder, configuration server, and other data transceiver systems in the control center, enabling communication with data terminals. It includes physical hardware (such as network cards, serial communication cards, and necessary peripherals; hardware can be replaced according to actual connection requirements) and the necessary software for communication (drivers, protocol stacks, etc.).

[0096] 2. Data distribution module.

[0097] The data distribution module converts real-time tag number data and video surveillance data from remote terminal protection devices into a data format that the control center can receive, simulating communication between remote terminals and the control center's server via a local communication transmission module. It can also restore real-time data from remote terminal protection devices that deviates from application-layer protocols to application-layer data formats supported by the control center, based on configuration settings. For audio and video data streams, it can perform protocol conversion according to configuration to match the control center's video data interface.

[0098] 3. Data auditing module.

[0099] The data auditing module monitors real-time and historical data trends and identifies and detects intrusion information and audio / video data collected from remote terminals, detecting risks to remote terminals or sites according to pre-defined strategies. For real-time and historical tag number data, it monitors for anomalies in key tags according to pre-configured strategies, including tag number value changes exceeding range, tag number value change frequency exceeding range, tag number value exceeding range, tag number stopping changing, tag number change rate (slope) exceeding range, missing tag number value, and replay within the time range. When an anomaly is detected in a tag, a handling method can be selected (e.g., blocking communication or sending an alarm) to prevent further damage from potential threats. For on-site intrusion detection information, communication can be blocked or an alarm can be issued according to set strategies after detecting suspected intrusion behavior (abnormal vibration, enclosure opening). For audio / video information, machine learning algorithms are used to identify the on-site environment and issue alarms or block communication for on-site anomalies.

[0100] 4. Real-time data processing module / historical data processing module.

[0101] This module is used for organizing and processing the decompressed real-time data. It reassembles the data fragments from the remote terminal protection device's data fragmentation / combination module and submits them to the data review module for processing. Real-time data processing takes precedence over historical data processing.

[0102] 5. Data compression / decompression module.

[0103] The data compression / decompression module compresses and packages data sent to the remote terminal; it also decompresses real-time data received from the remote terminal.

[0104] 6. Hidden data extraction module.

[0105] The real-time tag number data stream is extracted from audio / video streams or noise data streams that have been encoded with real-time tag number data, and any hidden real-time tag number data streams transmitted in the audio / video streams are erased. This prevents audio / video data containing hidden data from being leaked and used when stored as audio / video.

[0106] 7. Data encryption / decryption module.

[0107] The data encryption / decryption module decrypts the fragmented data from the remote protection device and hands it over to the upper layer for processing; the data from the control center is encrypted and prepared for transmission.

[0108] 8. Data sharding and combination module.

[0109] The data fragmentation and combination module merges, restores, and verifies data fragments that have been transmitted through multiple paths, forming the original data stream.

[0110] 9. Data flow control module.

[0111] When a large number of remote terminals go offline for a period of time and then come back online, there will be a significant amount of offline historical data upload traffic. Without restrictions, this historical data upload may cause network congestion at the control center, affecting real-time data transmission. Therefore, the collected offline historical data should be subject to traffic control, and the system should support configuring historical data upload policies. This allows different remote terminal protection devices to upload historical data in batches or reduce upload traffic based on the network bandwidth resources at the remote terminals. The policy is controlled by the central protection device, and is jointly executed by the remote communication transmission modules of the remote protection devices and the remote communication module of the central protection device.

[0112] The data flow control module includes artificial intelligence algorithms. Based on the monitoring of historical bandwidth and site data, it establishes a communication traffic model for each site. According to the communication traffic model, it allocates the historical data uploading strategy for each site in real time, dynamically adjusts the uploading of real-time data and historical data, and ensures that newly generated high-priority real-time data is transmitted first, and that historical data is not missed or misread (for example, when the network fails and the terminal starts to send back historical data, the uploading rate and time should be automatically adjusted to prevent congestion or excessive central load).

[0113] 10. Physical environment monitoring module.

[0114] The physical environment monitoring module is used to collect environmental fingerprints for communication authentication. The physical environment monitoring module includes hardware, drivers, and corresponding algorithms for monitoring the physical environment.

[0115] The hardware includes sensors that collect environmental information, including: (1) Chassis intrusion detection (physical switch for detecting intrusion into the chassis of the remote transmission system and intrusion into remote terminal equipment or critical equipment, or cabinet intrusion detection as an alternative).

[0116] (2) Sensors in the surrounding environment of the data security transmission system and remote terminal (temperature, humidity, light, wind speed, electromagnetic radiation level, and concentration of key gas components). The software algorithm is used to establish a baseline or model for the two or more types of data collected above, and to verify historical data from the most recent period during communication authentication to ensure the reliability of the physical environment.

[0117] 11. Certification Center Module.

[0118] The central protection device on the control center side authenticates and monitors the entire communication process of all remote protection devices that require communication with the authentication center. The authentication center interacts with the communication authentication module of the remote protection devices, verifying the authenticity of the control center and the remote protection devices themselves. During communication, the status of the remote terminals submitted by the remote terminal protection devices is verified. If a remote terminal is found to be inconsistent with the configured policy, communication will be blocked or an alarm will be issued according to the policy.

[0119] This enables the verification and execution of authentication information submitted by remote site protection devices.

[0120] Similar to remote terminal protection devices, central protection devices also offer three authentication methods, which can be selected according to actual needs, including software information credentials, hardware credentials, and control center fingerprint credentials.

[0121] The fingerprint credentials used by the control center will collect various information from the main terminal devices of the control center: ① Hardware fingerprints (CPU utilization, memory read / write frequency, interface voltage fluctuations, and electrical characteristics of core circuits); ② Software fingerprint (process list, protocol stack version, log generation frequency); ③ Environmental fingerprint (center temperature and humidity, vibration value, power stability, collected by the above "physical environment monitoring module").

[0122] These dynamic fingerprints are compared with the "baseline fingerprints" stored in the root of trust. If a discrepancy is found (such as a sudden increase in vibration value indicating physical disassembly, or an unknown process appearing in the process list), authentication failure is immediately triggered and communication is blocked, rather than relying solely on static configuration verification.

[0123] Provides functionality to securely destroy data in case of authentication failure.

[0124] 12. Remote communication transmission module.

[0125] The remote communication transmission module includes: (1) Traffic monitoring module: Real-time analysis and monitoring of the real-time data traffic mode sent by each remote terminal, supports automatic collection of traffic baseline, analyzes the real-time traffic value according to the configured strategy or baseline, and issues an alarm or blocks communication when the traffic exceeds the threshold.

[0126] (2) Address masquerading module: used to mask the communication addresses and other information between remote terminals and the control center, preventing intruders from actively probing the network configuration on the remote terminal side or the control center side by listening to network communication data streams or intruding into the link. Each remote terminal uses a separate network segment when communicating with the control center.

[0127] (3) Firewall module: used to defend against common network attacks and to allow or block corresponding MAC, IP, ports, etc. according to the actual communication configuration.

[0128] 13. Transmission strategy management module.

[0129] The transmission policy management module is used to manage and execute the policies in the transmission policy management module of the remote terminal protection device, and provides a configuration interface for administrators and auditors to configure and audit.

[0130] The secure networking communication system for remote terminal devices provided in this embodiment has the following beneficial effects: 1. Real-time data is collected, fragmented, compressed, and encrypted to prevent data from being eavesdropped on or destroyed, while also reducing the consumption of network bandwidth resources and reducing the network processing burden; n+1 redundant links are used to ensure that data can still be delivered correctly even if some data is lost, making it difficult for intruders to intercept all traffic for analysis and attack.

[0131] 2. The remote terminal supports offline storage of data during offline periods, ensuring that data is not permanently lost during disconnection; the collected real-time data is transmitted and stored without application layer protocols, which can overcome the obstacles of the application layer protocols themselves (such as real-time transmission protocols not supporting offline caching) and support more functions.

[0132] 3. Authentication and monitoring of communication establishment and the entire communication process to prevent attackers from intervening during the communication establishment phase or communication process (TOC / TOU attack); application address spoofing to prevent intruders from analyzing network addresses.

[0133] 4. Real-time data and historical data are transmitted and processed separately to avoid offline data uploading occupying real-time data bandwidth, causing real-time data delays or loss.

[0134] 5. It can parse the tag data and review changes in key tags according to the strategy. By monitoring the changes in tag numbers, it can detect potential intrusion behaviors.

[0135] 6. The central protection device incorporates artificial intelligence algorithms to dynamically adjust the transmission strategy.

[0136] 7. In addition to traditional authentication methods based on certificates and key storage modules, it provides authentication of device hardware fingerprints and environmental fingerprints, which are extremely difficult to forge; it also provides identification and monitoring of abnormal data transmission.

[0137] 8. The data acquisition module can be replaced according to the application industry, thus expanding the scope of use.

[0138] 9. It adopts a covert transmission mode to prevent the discovery and exploitation of high-security real-time tag data; it transmits data in multiple channels, and can be fault-tolerant to transmitted data like RAID5; it can automatically destroy secure data when authentication fails.

[0139] Example 2: Based on Embodiment 1, this embodiment provides a secure networking communication system for remote terminal devices, and provides a detailed description of the process by which the transmission policy management module executes and monitors the other modules.

[0140] Specifically, the policies in the transmission policy management module include: (1) Connection establishment strategy.

[0141] Responsible for initializing the secure connection between the remote protection device and the central protection device. For example... Figure 2 As shown, the core functions of the connection establishment strategy include: (a) Triggering conditions: Connection requests are only allowed after the remote terminal protection device has completed dual pre-authentication of "hardware trusted root verification + site dynamic fingerprint verification" to avoid unauthorized connection attempts.

[0142] (b) Link adaptation: Automatically detect the bandwidth and delay parameters of available communication links (such as fiber optic, 4G, leased lines), and prioritize the establishment of main connections for links that meet real-time requirements (such as data transmission delay of tag number ≤ 100ms).

[0143] (c) Connection timeout control: Configure the connection timeout threshold (default 30 seconds, configurable). If the connection is not established within the timeout period, the local cache of data to be sent will be automatically cleared to avoid data retention and leakage.

[0144] Allows users to configure link selection strategies, connection timeout mechanisms, and behaviors.

[0145] (2) Transmission channel closure strategy.

[0146] Manage the secure termination process of the connection to ensure that no data remains when the channel is closed. Core functions include: (a) Active shutdown: When the control center issues a "channel shutdown command" or the remote station equipment goes offline, the current segment data transmission is completed synchronously first, and then a "shutdown confirmation signal" is sent. After the control center responds, the channel is shut down.

[0147] (b) Abnormal shutdown: If “authentication failure, link interruption, device intrusion” is detected (e.g., the chassis is opened), an emergency shutdown is triggered immediately. At the same time, sensitive data that has not been sent in the remote protection device (e.g., tag fragments) is erased, and the reason for shutdown is reported to the control center if possible (if the link is interrupted, try to report through other links or temporarily store the data).

[0148] (c) Channel release: After closing, the link resources are automatically released and the channel is marked as "idle" for subsequent connection reuse to avoid resource occupation.

[0149] Allows users to configure the conditions and behaviors for triggering abnormal shutdown, as well as the conditions and behaviors for automatically releasing channels.

[0150] (3) Historical data storage and transmission strategy.

[0151] In conjunction with the "offline storage module," it enables secure temporary storage and recovery of disconnected data. Its core functions include: (a) Temporary Storage Trigger: When all communication links are interrupted (or the bandwidth is lower than the data generation rate), the temporary storage function is automatically activated, prioritizing the temporary storage of highly sensitive data (such as oil and gas pressure tags, power grid load data), while ordinary environmental data (such as temperature and humidity) can be configured to be "temporarily stored with low priority" or "discarded". Users can configure which data to temporarily store.

[0152] (b) Storage limits: Set a temporary storage capacity threshold (e.g., 80% of local storage). Once the threshold is reached, delete the oldest ordinary data in a "first-in, first-out" manner to ensure that highly sensitive data is not overwritten. Allow users to configure the space available for storing historical data or the temporary storage time, as well as the behavior after the storage limit is exceeded.

[0153] (c) Resumption of Transmission: After the link is restored, historical data is transmitted in batches and time periods according to the station transmission strategy issued by the control center. While ensuring the correct transmission of real-time data, the remaining bandwidth is used to transmit temporarily stored data. Users are allowed to configure the maximum bandwidth value or percentage that can be used for historical data transmission.

[0154] (4) Communication authentication measurement.

[0155] Configure the authentication rules for the "Communication Authentication Module" to cover the usage logic of the three types of authentication credentials in the original document. Core functions include: (a) Authentication mode selection: Configure authentication combination according to the security level of the site - core sites (such as oil and gas pressurization stations) adopt dual authentication of "hardware root of trust + site dynamic fingerprint", while ordinary sites can adopt authentication of "software credential + hardware root of trust".

[0156] (b) Baseline update: Regularly (e.g., weekly) synchronize the “site benchmark fingerprint database” (e.g., normal vibration value of equipment, electromagnetic radiation range) issued by the control center to ensure that the certification benchmark matches the status of the on-site equipment.

[0157] (c) Abnormal retry: Allows configuration of the number of retries and intervals when authentication fails. If authentication still fails after exceeding the number of retries, the administrator of the control center's protection device needs to manually unlock it to prevent brute-force attacks.

[0158] (5) Data sharding strategy.

[0159] Configure the fragmentation rules of the "Data Fragmentation / Assembly Module" to balance transmission efficiency and data security. Core functions include: Fragment size adaptation: Allows users to set the size of transmission fragments. Larger fragments result in higher transmission efficiency but higher latency, while smaller fragments result in lower bandwidth utilization but lower latency. It can be automatically configured based on bandwidth and network latency.

[0160] (6) Fragmented multiplex transmission strategy.

[0161] In conjunction with the "data splitting and multi-path transmission module," it achieves multi-link load balancing and redundancy. Its core functions include: (a) Multipath strategy switching: Allows users to set which multipath strategy to use during transmission and which transmission channels to use.

[0162] (b) Path selection: Before transmission, test the "bandwidth stability" of all available links (e.g., bandwidth fluctuation ≤10% within 5 seconds is considered stable), and select ≥2 stable links as transmission channels.

[0163] (c) Load balancing: Distribute fragments according to the link bandwidth ratio (e.g., if link A has a bandwidth of 4Mbps and link B has a bandwidth of 2Mbps, then A will bear 2 / 3 of the fragments and B will bear 1 / 3), to avoid single link congestion.

[0164] (d) Redundancy configuration: When n+1 redundancy is enabled, one link is automatically designated to transmit the "parity check fragment". The check link is switched according to the rule of "rotating once every 5 minutes" (i.e., automatically selecting a specific check fragment transmission channel) or "automatically switching one by one in sequence" (i.e., each group of transmitted fragments uses a different channel to transmit check data) to prevent the check channel from being targeted by attacks.

[0165] (8) Data encryption and decryption strategies.

[0166] Configure the algorithm and key management of the "Data Encryption / Decryption Module". Core functions include: (a) Algorithm selection: The encryption algorithm is matched according to the data sensitivity level—the national cryptographic SM4 algorithm (high strength) is used for tag data and control signaling, and the lightweight algorithm (reducing computing power consumption) is used for audio and video data.

[0167] (b) Key Management: The key is negotiated and issued by the control center, and the key is not stored in the local file system, but only temporarily stored in the hardware root of trust. A new key is used each time a transmission channel is established.

[0168] (c) Decryption fault tolerance: If decryption fails (e.g., key mismatch, data tampering), the fragment is immediately discarded and a "decryption anomaly alarm" is sent to the control center without triggering a retry (to avoid malicious data injection).

[0169] (8) Data concealment strategy.

[0170] Configure the "data hiding module" to achieve hidden transmission of tag data, such as Figure 3 As shown, the core functions of the data concealment strategy include: (a) Covert triggering: Automatically detect whether there is an audio or video stream on site. If it exists (e.g., the site camera is working normally), the tag number data is encoded into the “pixel redundancy bit” or “audio frequency gap” of the audio or video stream. If it does not exist, a “simulated environmental noise stream” (e.g., electromagnetic noise from equipment operation) is generated, and the tag number data is embedded in the noise.

[0171] (b) Encoding priority: High-priority tag data (such as power grid fault tag) is encoded first into the "early segments" (such as the first 10% segments) of the audio and video stream to ensure priority transmission.

[0172] (c) Concealment strength: Configure the encoding depth according to security requirements (e.g., high-security scenarios are encoded to "3 pixels per frame of video", and ordinary scenarios are encoded to "1 pixel") to avoid over-encoding affecting the normal playback of audio and video.

[0173] (9) Data compression strategy.

[0174] Configure compression rules for the "Data Compression / Decompression Module," focusing on real-time tag data optimization. Core functions include: (a) Compression target limitation: Only real-time tag data (such as numerical pressure and flow data) is compressed. Audio and video data are not compressed again because they are already encapsulated in a compression format (such as H.265). (b) Algorithm selection: The user selects the specific compression algorithm to use.

[0175] (c) Compression ratio control: The compression ratio is configured by the user or dynamically adjusted according to the link bandwidth to ensure data transmission bandwidth utilization and real-time performance.

[0176] (10) Data acquisition strategy.

[0177] This module guides the data acquisition logic of the "Data Acquisition Module," adapting to multiple devices and protocols. It configures which data to acquire from remote sites and which terminal devices to communicate with. Core functions include: (a) Data acquisition frequency configuration: Set the frequency according to the data type. For example, real-time tag data (such as oil and gas pipeline pressure) is acquired once every 1 second, equipment diagnostic data is acquired once every 5 seconds, and environmental monitoring data (such as temperature and humidity) is acquired once every 30 seconds.

[0178] (b) Protocol adaptation: Based on the industrial protocols supported by the field equipment (such as Modbus-RTU, IEC 61850, HART), the corresponding protocol parsing plugin is called, without the need for manual configuration.

[0179] (c) Handling of data acquisition anomalies: If “data out of range” (e.g., pressure value exceeds equipment range) or “no response” (sensor failure) is acquired, the data is immediately marked as “invalid” and a “data acquisition anomaly alarm” is sent to the control center. At the same time, the historical data acquired 30 seconds before the failure is retained for troubleshooting.

[0180] (11) Signaling protection strategy.

[0181] Special protection is provided for control signaling between the control center and remote terminals (such as starting / stopping RTUs and adjusting valve openings). Core functions include: (a) Signaling encryption: Control signaling is protected by "SM4 + timestamp" dual protection. Signaling with a timestamp error of more than 5 seconds is directly discarded to prevent replay attacks.

[0182] (b) Integrity verification: Add a CRC32 checksum to each signaling message. The control center / remote terminal verifies the message upon receipt. If the verification fails, execution is rejected and an alarm is triggered.

[0183] (c) Signaling priority: Control signaling (such as emergency stop signaling) has a higher priority than ordinary signaling (such as configuration update signaling) and occupies link resources first during transmission; (d) Access control: Configure a “signaling execution whitelist” to allow only the execution of signaling issued by the control center’s designated IP (or hardware root of trust identifier) ​​and reject signaling from other sources.

[0184] (12) Firewall security policy.

[0185] Configure firewall protection rules in the "Remote Communication Transmission Module" to adapt to attack characteristics in industrial scenarios. Core functions include: (a) Access control: Configure a whitelist for the dedicated network segment of “site-control center” to allow traffic from the communication addresses of both parties (such as the IP disguised by the remote protection device and the IP authenticated by the control center) to pass through, and block access from unknown IPs.

[0186] (b) Port control: Only open necessary industrial ports (such as Modbus port 502, IEC 61850 port 102), and close other ports by default; configure "port scan detection" for open ports, and temporarily block them (30 minutes) if more than 10 invalid connections are detected within 1 minute.

[0187] (c) Attack defense: Configure a signature database for common industrial network attacks (such as Modbus protocol flood attacks and PLC instruction injection) to detect and block abnormal traffic in real time; support log recording (including attack source IP, attack type, and interception time), and retain logs for 90 days for auditing.

[0188] (d) Rule synchronization: Automatically synchronize "firewall rule update packages" (such as adding attack features and adjusting port policies) from the control center every week to ensure the timeliness of protection rules.

[0189] (13) Data security destruction strategy.

[0190] Manage the destruction logic of temporary data in the "offline storage module" to ensure that data cannot be recovered after successful data transfer. Core functions include: (a) Destruction Trigger: Local temporary data destruction is triggered only when the control center sends a "historical data reception confirmation" (containing a list of data identifiers).

[0191] (b) Destruction algorithm: The "3-time overwrite" mechanism is adopted (overwriting 0x00, 0xFF and random value in sequence), which complies with the industrial data security destruction standard (such as GB / T 29827); the key stored in the hardware root of trust is destroyed by the "physical circuit breaking" method (it cannot be recovered after the circuit breaking).

[0192] (c) Destruction verification: After destruction is completed, a "destruction verification code" is generated and sent to the control center. The control center compares the verification code to confirm that the destruction was successful. If destruction fails (e.g., due to storage medium error), the storage partition is immediately locked to prevent data leakage.

[0193] (d) Destruction Log: Records the "destruction time, data identifier, and destruction result" of each data entry. The log is immutable and is used for subsequent security audits.

[0194] (14) Transmission scheduling and flow control.

[0195] In conjunction with the "data flow control module" and the "multi-path transmission module," it enables dynamic management and control of traffic across the entire link. Its core functions include: (a) Priority scheduling: Clearly define the priority order of data transmission—emergency control signaling > real-time tag data > historical tag data > audio and video data > normal environment data; when bandwidth is insufficient, transmission is downgraded according to priority (first suspend normal environment data, then suspend audio and video data). (b) Bandwidth allocation: Configure bandwidth quotas according to the importance of the site - the maximum upload bandwidth of core sites (such as the main oil and gas transmission stations) is 5Mbps, and that of ordinary sites is 2Mbps, so as to avoid a single site occupying too many resources.

[0196] (c) Congestion handling: When the network load on the control center side exceeds 80%, an "speed reduction command" is automatically sent to the remote protection device. The remote protection device reduces the historical data transmission rate by 50% to prioritize the protection of real-time data.

[0197] (d) Dynamic adjustment: The link bandwidth changes are detected every 10 seconds. If the bandwidth increases from 2Mbps to 10Mbps, the historical data transmission rate is automatically increased (from 500KB / s to 2MB / s) to make full use of the link resources.

[0198] (15) Sensitive data destruction strategy.

[0199] For sensitive data such as "key tag data, control signaling, and device authentication information," a more robust data destruction mechanism than that for ordinary data is provided. Core functions include: (a) Sensitive data definition: A list of sensitive data types is preset, such as oil and gas pipeline pressure / flow tag numbers, power grid load data, control signaling from the control center, and hardware trusted root certificates. The list can be dynamically updated by the control center.

[0200] (b) Destruction trigger scenarios: In addition to "destruction after successful transmission", three new trigger scenarios have been added: "device offline, policy update, and authentication failure 3 times" to ensure that sensitive data is not retained for a long time.

[0201] (c) Enhanced destruction method: Sensitive data adopts a combination of "7 overwrites + storage partition formatting", which is more thorough than ordinary data (3 overwrites); if the device suffers physical damage (such as storage chip failure), it supports issuing "physical destruction instructions" (such as short-circuiting storage chips) through the control center.

[0202] (d) Destruction audit: Generate a “Sensitive Data Destruction Report”, which includes the data type, destruction time, destruction method, and executor (automatic / manual triggering by the system). The report is encrypted and uploaded to the control center for archiving and is kept for more than 1 year.

[0203] The secure networking communication system for remote terminal devices provided in this embodiment has the following beneficial effects: 1. It can be connected to the existing network system as an independent accessory without changing the on-site network environment.

[0204] 2. It can prevent malicious intruders from probing the network and prevent unauthorized devices from accessing it.

[0205] 3. It can monitor the entire communication process and realize the parsing and monitoring of tag data.

[0206] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any way. Other variations and modifications are possible without departing from the technical solutions described in the claims.

Claims

1. A secure networking communication system for remote terminal devices, characterized in that, include: The remote terminal protection device collects, segments, and compresses the real-time data of the RTU, hides the compressed data in the audio and video stream, uses n+1 redundant links for data transmission, stores the data offline during offline periods, and transmits and stores the collected real-time data without application layer protocol. The central protection device parses the real-time tag data sent by the remote terminal protection device, determines whether there is a network intrusion based on the changes in the tag data, and dynamically adjusts the transmission strategy according to the communication traffic.

2. The secure networking communication system for remote terminal devices according to claim 1, characterized in that, Concealing compressed data within audio and video streams includes: automatically detecting whether an audio or video stream exists on-site; if it does, encoding real-time tag data into the pixel redundancy bits or audio frequency gaps of the audio or video stream; if no audio or video stream exists, generating a simulated environmental noise stream and embedding the tag data into the noise; high-priority tag data is encoded into the earlier segments of the audio or video stream, and the encoding depth is configured according to security requirements, with higher security scenarios occupying more pixel bits.

3. The secure networking communication system for remote terminal devices according to claim 1, characterized in that, The method of using n+1 redundant links for data transmission includes: if there is only one available communication path from the RTU to the control center, the data is split into fragments before transmission and transmitted directly; if there are multiple communication paths from the RTU to the control center, the bandwidth and latency of each communication path are tested, and the current n+1 communication paths are selected. Continuous data fragments are transmitted on n of these communication links, and the parity check values ​​of the first n data fragments are transmitted on another link; the channel for transmitting the parity check values ​​is selected by sequential rotation.

4. A secure networking communication system for remote terminal equipment according to claim 1, 2, or 3, characterized in that, The remote protection device includes an offline storage module. When all communication links are interrupted, the offline storage module will temporarily store the data to be sent in segments, prioritizing the storage of highly sensitive data, and prioritizing the deletion of the earliest ordinary data when the temporary storage capacity threshold is reached. After communication is restored, the temporarily stored data will be used as historical data transmission. Once the historical data is successfully transmitted, the cached data will be destroyed.

5. A secure networking communication system for remote terminal devices according to claim 4, characterized in that, The data destruction process includes: determining whether the data is sensitive; if it is not sensitive, and the control center sends a historical data reception confirmation, a three-stage overwrite mechanism is used to destroy the locally stored data, sequentially overwriting 0x00, 0xFF, and a random value. After destruction, a destruction verification code is generated and sent to the control center, which compares the verification code to confirm successful destruction. If destruction fails, the storage partition is locked. If the data is sensitive, and one of the following is received: a historical data reception confirmation signal, a device offline signal, a policy update signal, or an authentication failure signal, a seven-stage overwrite and storage partition formatting method is used to strengthen the destruction of sensitive data.

6. A secure networking communication system for remote terminal devices according to claim 1, characterized in that, The central protection device includes a data auditing module, which identifies and detects intrusion information and audio / video data collected by the RTU, and detects risks to remote terminals or sites according to pre-configured strategies: for real-time tag number data and historical tag number data, it monitors the tag number value change, tag number value change frequency, tag number value, and tag number change rate over time according to pre-configured strategies, and blocks current communication or sends an alarm when an anomaly is detected in the tag number; for audio / video information, it uses machine learning algorithms to identify the on-site environment, and alarms or blocks communication when on-site anomalies are detected.

7. A secure networking communication system for remote terminal devices according to claim 6, characterized in that, The central protection device includes a data flow control module. Based on the monitoring of historical bandwidth and site data, the data flow control module establishes a communication traffic model for each site and allocates the historical data uploading strategy for each RTU in real time according to the communication traffic model, dynamically adjusting the uploading of real-time data and historical data.

8. A secure networking communication system for remote terminal equipment according to claim 1, 2, 3, 6, or 7, characterized in that, Both the central protection device and the remote terminal protection device include a transmission strategy module. The transmission strategy module includes a signaling protection strategy. The signaling protection strategy encrypts the control signaling between the control center and the RTU using SM4 + timestamp. If the timestamp error exceeds the time threshold, the control signaling is discarded. At the same time, a CRC32 checksum is added to each signaling. The control center or RTU verifies the signaling upon receipt. If the verification fails, execution is rejected and an alarm is triggered.

9. A secure networking communication system for remote terminal equipment according to claim 1, 2, or 3, characterized in that, The remote terminal includes: The data classification module categorizes the data collected from the RTU according to the region of the data source, priority, and real-time performance. The data compression / decompression module efficiently compresses the real-time tag data to be sent into fragments and decompresses the received data. The physical environment monitoring module collects environmental fingerprints; The communication authentication module authenticates and monitors the entire connection and communication process. Authentication is based on software information credentials, hardware credentials, and remote site fingerprint credentials. Data to be sent is cleared when authentication fails.

10. A secure networking communication system for remote terminal equipment according to claim 6 or 7, characterized in that, The central protective device includes: The data distribution module converts and restores the data sent by the remote terminal protection device. The hidden data extraction module extracts the real-time tag number data stream from the audio and video stream that encodes the real-time tag number data, and erases the real-time tag number data stream from the audio and video stream; The data fragmentation and combination module merges, restores, and verifies data fragments that have been transmitted through multiple paths, forming the original data stream. The physical environment monitoring module collects environmental fingerprints for communication authentication; The communication authentication module authenticates and monitors the communication process. Authentication criteria include software information credentials, hardware credentials, and remote site fingerprint credentials. Data to be sent is cleared when authentication fails.