Information security encryption transmission method of intelligent converged terminal
By improving the combination of PWC-Net network and time-reverse key chain, dynamic secure transmission of intelligent fusion terminals in complex network environments is realized, solving the problem of insufficient adaptive control in existing technologies and improving security and stability.
Patent Information
- Application Number
- CN202610817881.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-08
- Publication Date
- 2026-08-25
AI Technical Summary
Existing information security encryption transmission methods for intelligent converged terminals are difficult to adaptively adjust to dynamically changing transmission environments in complex network environments. They lack comprehensive analysis capabilities for terminal identity status, service flow element order, link fluctuations, and key consumption status, posing security risks. Furthermore, they lack effective data isolation mechanisms, allowing attackers to compromise the effective transmission structure through methods such as insertion and out-of-order replay.
An improved PWC-Net network is introduced for security status awareness and offset identification. Combined with a time-reverse key chain, dynamic key generation and reverse folding are realized. A self-collapsed secure pass domain is constructed, a secure transmission chain is generated and encryption is performed. The receiving end performs multi-dimensional verification to form a closed-loop control of the entire link.
It enables continuous perception and dynamic analysis of the security status of intelligent converged terminals in multi-service concurrent and complex link environments, improves the timeliness and accuracy of security perception, enhances anti-attack capabilities and transmission stability, and can quickly identify and isolate abnormal transmission segments to block attacks.
Smart Images

Figure CN122640116A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security communication technology, and in particular to an information security encrypted transmission method for intelligent converged terminals. Background Technology
[0002] With the rapid development of Industrial Internet, smart manufacturing, and IoT technologies, intelligent converged terminals are widely used in scenarios such as data acquisition, equipment control, and edge computing. These terminals typically need to continuously interact with the cloud or edge gateway in complex network environments, involving the transmission of large amounts of sensitive information, such as equipment control commands, operational status data, and alarm information. Therefore, ensuring the security of data transmission in multi-service concurrency and complex link environments has become an important research direction in the field of communication network security. Currently, related technologies mostly employ symmetric encryption algorithms, asymmetric key exchange mechanisms, and session-based key update strategies to encrypt and protect transmitted data.
[0003] In existing technologies, common methods for secure encrypted transmission mainly rely on fixed session keys or periodically updated keys to encrypt data, while combining integrity checks and authentication mechanisms to achieve basic security protection. In practice, the terminal typically updates the key according to a predetermined period and encrypts transmitted data in packets, while the receiving end verifies the data through key matching and verification rules. However, these methods are mostly based on static rules or single-dimensional state judgments, lacking the ability to comprehensively analyze terminal identity status, service flow element order, link fluctuations, and key consumption status, making it difficult to adaptively adjust to dynamically changing transmission environments.
[0004] In practical applications, when intelligent converged terminals are in weak network environments or experience link jitter, retransmissions, or gateway switching, existing technologies struggle to promptly identify continuous shifts in security status. This allows the current key to continue encrypting data even under abnormal links, posing a security risk. Furthermore, highly sensitive control data and ordinary collected data are typically processed in the same transmission environment, lacking effective isolation mechanisms. This allows attackers to gradually approach the valid transmission structure through methods such as fragment insertion, out-of-order replay, or link probing. Existing methods mostly perform post-hoc verification at the receiving end, lacking proactive security status awareness and dynamic key adjustment capabilities. They also cannot proactively terminate or isolate the transmission process under abnormal conditions, limiting the overall improvement in security protection effectiveness.
[0005] Therefore, how to provide a secure encrypted transmission method for intelligent converged terminals is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0006] One objective of this invention is to propose an information security encrypted transmission method for intelligent converged terminals. This invention achieves security status awareness and offset identification by introducing an improved PWC-Net network, realizes dynamic key generation and reverse folding by combining a time-reverse key chain, and realizes active isolation and failure control of abnormal transmission by utilizing a self-collapsed secure takeover domain. This constructs a dynamic secure transmission mechanism for multi-service concurrency and complex link environments, which has the advantages of strong security, high anti-attack capability, high status awareness accuracy, and good transmission stability.
[0007] The information security encryption transmission method for a smart fusion terminal according to an embodiment of the present invention includes:
[0008] Collect multi-source security status data from intelligent fusion terminals, align the multi-source security status data, and generate a security status sequence;
[0009] The security state sequence is input into the improved PWC-Net network for security state offset matching, generating a security state stream, identifying security state phase transition points, generating a security state evolution trajectory based on the security state phase transition points, and outputting security entropy value, key folding depth adjustment flag, security bearing domain adjustment flag, and self-collapse trigger flag.
[0010] The time-reverse key chain is generated by adjusting the marker based on the security entropy value and key folding depth. A future key seed set is generated based on the terminal root key, current security state data, timestamp, and gateway challenge random number. The future key seed set is folded and calculated in reverse order to generate the current transmission key.
[0011] Based on the safety state evolution trajectory and safety transition domain adjustment markers, a self-collapsed safety transition domain is constructed. The continuity of the transition is verified at the safety state phase transition point to generate a safety transition chain. A failure transition zone is generated based on the self-collapse trigger marker.
[0012] Based on the secure transmission chain, phase transition segmentation is performed on the data to be transmitted, generating multiple secure transmission segments and binding them with key nodes in the corresponding time reverse key chain. The secure transmission segments are then encrypted using the current transmission key, generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message.
[0013] The receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, feeds back the verification results to the intelligent fusion terminal, updates the security state sequence, and uses it as input for the next transmission cycle to improve the PWC-Net network.
[0014] Optionally, the multi-source security status data includes terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data.
[0015] Optionally, the step of aligning the multi-source security state data to generate a security state sequence includes:
[0016] Acquire the collection time stamps corresponding to terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data;
[0017] Based on the acquisition time stamp, various types of status data are sorted by time, and status data within the same transmission cycle are associated with the same cycle record;
[0018] Missing state items are filled in, and duplicate state items are merged to generate standardized periodic state records.
[0019] Construct a state feature vector in the order of terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data;
[0020] The feature vectors of each state are arranged according to the transmission cycle order to generate a safe state sequence.
[0021] Optionally, the output security entropy value, key folding depth adjustment flag, security inheritance field adjustment flag, and self-collapse trigger flag include:
[0022] Construct a security state training dataset by slicing terminal identity state data, service transmission state data, link risk state data, key chain state data, and receiver verification state data according to the transmission cycle and normalizing them to generate a security state vector sequence, and then dividing it into training set, verification set, and test set.
[0023] An improved PWC-Net network is constructed by retaining the feature pyramid module, twist alignment module, cost volume module and decoding module in the original PWC-Net network. A dynamic time offset correction module is connected in series between the feature pyramid module and the twist alignment module. A safe channel attention-entropy fusion module is connected in series after the cost volume module. A phase transition detection branch is added at the same level as the decoding module to form the improved PWC-Net network.
[0024] Multi-scale feature extraction is performed on the safety state vector sequence through the feature pyramid module. The feature pyramid module is composed of four levels of residual structure connected in sequence. The number of output feature channels at each level is 32, 64, 96 and 128 respectively, which are used to generate multi-scale safety state features.
[0025] The dynamic time offset correction module performs time offset correction on the multi-scale security state characteristics of adjacent transmission cycles. The dynamic time offset correction module is composed of a one-dimensional convolutional subnet and a gated cyclic unit connected in sequence. It is used to align the state offset caused by delay, retransmission and link fluctuation in weak network environment.
[0026] The offset relationship between the current security state features and the aligned security state features is calculated by the cost volume module. The offset relationship is then processed by feature weighting and entropy aggregation by the security channel attention-entropy fusion module to generate a security state stream and corresponding security entropy value.
[0027] The security state stream is output through the decoding module. The security state stream is used to detect state changes through the phase transition detection branch, identify security state phase transition points, connect the security state phase transition points in chronological order to generate a security state evolution trajectory, and output key folding depth adjustment flag, security bearing domain adjustment flag and self-collapse trigger flag.
[0028] The improved PWC-Net network is trained using a joint loss function, which includes offset prediction loss, phase transition detection loss, and safety entropy constraint loss. After training, the improved PWC-Net network can output a safety state flow, a safety state evolution trajectory, and various adjustment markers based on the input safety state sequence.
[0029] Optionally, the step of folding the future key seed set in reverse order to generate the current transmission key includes:
[0030] Read the security entropy value, key folding depth adjustment flag, terminal root key, current security status data, timestamp, gateway challenge random number, terminal device number and link status digest; determine the number of future key seeds based on the preset security entropy range in which the security entropy value is located; and determine the key folding round based on the key folding depth adjustment flag.
[0031] Construct a key derivation input record in the order of the fields: terminal device number, current security status data, timestamp, gateway challenge random number, link status digest, and terminal root key. Input the key derivation input record into the cryptographic derivation function to generate the first future key seed. Use the first future key seed, seed number, and current security status digest as the next derivation input to generate a set of future key seeds corresponding to the number of future key seeds in sequence.
[0032] Write the seed number, binding transmission period, binding security state digest and binding link state digest to each future key seed in the future key seed set in the order of generation time, generate a future key seed chain arranged in forward time, and select the target key seed segment to participate in the generation of the current transmission key from the future key seed chain according to the key folding round.
[0033] The folding process is performed in reverse order of the target key seed segment. First, the last generated future key seed is read as the initial folding input. Then, the previous future key seed is read in sequence. The previous future key seed, the previous round folding result, the current security state digest and the gateway challenge random number are concatenated and derived. Folding results are generated round by round until all future key seeds in the target key seed segment are folded, and a time-reverse key chain is generated.
[0034] Read the final folded result of the time-reverse key chain, the current security state digest, the service transport segment identifier, and the link state digest, perform a key confirmation derivation, and generate the current transport key.
[0035] Optionally, the generation of the secure succession chain, based on the self-collapse trigger marker to generate a failure succession zone, includes:
[0036] Read the security state evolution trajectory, security acceptance domain adjustment flag, self-collapse trigger flag, security state phase transition point, current security state data, time-reverse key chain, service transmission state data, and link risk state data. Divide the identity acceptance domain, service acceptance domain, link acceptance domain, key acceptance domain, and reassembly acceptance domain according to the terminal identity state, service transmission state, link risk state, key chain state, and reception verification state, and generate a self-collapse security acceptance domain.
[0037] Based on the time sequence of each security state phase transition point in the security state evolution trajectory, the preceding state segment and the following state segment corresponding to each security state phase transition point are extracted. The identity state summary, service sequence marker, link state summary, key node identifier and reception verification marker in the preceding state segment and the following state segment are read respectively to generate the connection verification segment between adjacent phase transition points.
[0038] Perform continuity verification on each continuity verification segment, and connect adjacent phase transition points that pass the continuity verification in chronological order to generate a safe continuity chain;
[0039] Based on the security assumption domain adjustment flag, perform domain boundary shrinking processing on the security assumption chain:
[0040] Shrink the allowed range of identity status in the identity domain, shrink the allowed range of service order in the service domain, shrink the allowed range of link fluctuation in the link domain, shrink the allowed range of key nodes in the key domain, and shrink the allowed range of receiving order in the reassembly domain to generate a shrunken secure connection chain.
[0041] Based on the self-collapse trigger flag, the shrunk secure takeover chain is subjected to failure segmentation processing. State segments, service segments, link segments, key node segments, or receive reassembly segments in the secure takeover chain that do not meet the constraints of the shrunk takeover domain are marked as failure segments. Continuous failure segments are merged to generate a failure takeover area.
[0042] Optionally, the step of generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message includes:
[0043] Based on the order of adjacent receiving nodes in the secure receiving chain, phase-change segmentation is performed on the data to be transmitted, dividing the data to be transmitted into multiple secure transmission segments. For each secure transmission segment, a transmission segment identifier, a service type identifier, a corresponding receiving node identifier, and a generation time stamp are written.
[0044] Based on the failure acceptance zone, each secure transmission segment is subjected to failure filtering. Secure transmission segments located within the failure acceptance zone are marked as failed transmission segments and subsequent binding processes are stopped. Secure transmission segments located outside the failure acceptance zone are marked as valid transmission segments. A set of valid transmission segments is generated according to the acceptance order in the secure acceptance chain.
[0045] Based on the correspondence between the set of valid transmission segments and the key nodes in the time-reverse key chain, key node binding processing is performed on each valid transmission segment. The receiver node identifier, time stamp, link state digest and security state digest corresponding to each valid transmission segment are read. Key nodes in the time-reverse key chain that are consistent with the transmission period, correspond to the receiver position and have not expired are selected to establish a one-to-one binding relationship between valid transmission segments and key nodes.
[0046] Encrypt each valid transmission segment using the current transmission key, and connect the encrypted valid transmission segments, corresponding key node identifiers, link state digests, security state digests, and transmission sequence markers in the order of concatenation to generate a secure transmission chain.
[0047] Based on the secure transmission chain, each encrypted valid transmission segment is encrypted and encapsulated. In each encapsulation unit, the key node identifier, state digest, transmission chain sequence marker, time window marker, and integrity verification marker are written to generate a secure transmission message.
[0048] Optionally, the receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, including:
[0049] After receiving a secure transmission message, the receiving end parses the terminal device identifier, transmission segment identifier, key node identifier, status digest, link status digest, transmission chain sequence marker, time window marker, and integrity verification marker in the secure transmission message. Based on the terminal device identifier, it reads the corresponding terminal root key index, gateway challenge random number, and time-reverse key chain recorded by the receiving end.
[0050] Based on the key node identifier, locate the corresponding key node in the time-reverse key chain, verify whether the key node is consistent with the transport segment identifier, time window mark and link state digest, mark the consistent secure transport segment as the key node valid segment, and mark the inconsistent secure transport segment as the key node abnormal segment;
[0051] Based on the time-reverse key chain corresponding to the valid segment of the key node and the current transmission key, the secure transmission message is decrypted. The content of the decrypted secure transmission segment is read, and the state digest and integrity check flag are regenerated. They are then compared with the state digest and integrity check flag carried in the message to generate the state digest check result.
[0052] Perform sequence verification on all valid segments of key nodes according to the transmission chain sequence mark in the secure transmission chain, verify whether the successor node identifier, the preceding transmission segment identifier and the following transmission segment identifier between adjacent secure transmission segments are continuous, and verify whether each secure transmission segment is within the allowed reception time range according to the time window mark, and generate transmission chain sequence verification result and time window verification result.
[0053] The receiving end summarizes the key node verification results, state digest verification results, transmission chain sequence verification results, and time window verification results, generates a verification feedback record, sends the verification feedback record to the intelligent fusion terminal, writes the verification feedback record into the received verification state data, updates the security state sequence, and uses the updated security state sequence as the input for the next transmission cycle to improve the PWC-Net network.
[0054] The beneficial effects of this invention are:
[0055] This invention constructs a security state evolution model based on an improved PWC-Net network, enabling continuous perception and dynamic analysis of the security state of intelligent converged terminals in multi-service concurrent and complex link environments. Compared with existing technical solutions that rely on static rules or single-dimensional judgment, this invention comprehensively considers terminal identity status, service flow element order, link fluctuations, and key consumption status to identify subtle deviations in security status in advance, completing risk prediction before anomalies fully manifest, thus improving the timeliness and accuracy of security perception.
[0056] This invention introduces a time-reverse key chain mechanism, combining the future key seed set with the current security state data. Key folding calculations are performed in reverse order to generate the current transmission key. This makes the key generation process no longer dependent on derivation logic in a single time direction, but forms a dynamic association structure. This effectively avoids the risk of key inference or reuse. The key folding depth and seed number are adaptively adjusted according to changes in security entropy, enabling the key system to be dynamically optimized as the transmission environment changes, thereby enhancing the anti-attack capability and key security of encrypted transmission.
[0057] This invention achieves dynamic constraints and anomaly isolation of the transmission structure by constructing a self-collapsed secure transmission domain and introducing a secure transmission chain mechanism. When a security state phase transition or continuity disruption is detected, it can quickly locate abnormal transmission segments and generate a failed transmission zone, blocking abnormal data from entering the effective transmission link. This prevents attackers from gradually approaching the effective structure through segment insertion, out-of-order replay, or link probing. Combined with the secure transmission chain and multi-dimensional verification mechanism, it achieves closed-loop control of the entire link from transmission to reception verification, improving the stability and security protection capabilities of the overall system in complex network environments. Attached Figure Description
[0058] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0059] Figure 1 This is a flowchart of the information security encryption transmission method for intelligent fusion terminals proposed in this invention;
[0060] Figure 2 This is a schematic diagram of the overall structure of the improved PWC-Net network for the information security encryption transmission method of the intelligent fusion terminal proposed in this invention. Detailed Implementation
[0061] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.
[0062] refer to Figure 1 and Figure 2 The information security encryption transmission method for intelligent converged terminals includes:
[0063] Collect multi-source security status data from intelligent fusion terminals, align the multi-source security status data, and generate a security status sequence;
[0064] The security state sequence is input into the improved PWC-Net network for security state offset matching, generating a security state stream, identifying security state phase transition points, generating a security state evolution trajectory based on the security state phase transition points, and outputting security entropy value, key folding depth adjustment flag, security bearing domain adjustment flag, and self-collapse trigger flag.
[0065] The time-reverse key chain is generated by adjusting the marker based on the security entropy value and key folding depth. A future key seed set is generated based on the terminal root key, current security state data, timestamp, and gateway challenge random number. The future key seed set is folded and calculated in reverse order to generate the current transmission key.
[0066] Based on the safety state evolution trajectory and safety transition domain adjustment markers, a self-collapsed safety transition domain is constructed. The continuity of the transition is verified at the safety state phase transition point to generate a safety transition chain. A failure transition zone is generated based on the self-collapse trigger marker.
[0067] Based on the secure transmission chain, phase transition segmentation is performed on the data to be transmitted, generating multiple secure transmission segments and binding them with key nodes in the corresponding time reverse key chain. The secure transmission segments are then encrypted using the current transmission key, generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message.
[0068] The receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, feeds back the verification results to the intelligent fusion terminal, updates the security state sequence, and uses it as input for the next transmission cycle to improve the PWC-Net network.
[0069] In this embodiment, the multi-source security status data includes terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data.
[0070] In this embodiment, the step of aligning multi-source security state data to generate a security state sequence includes:
[0071] Acquire the collection time stamps corresponding to terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data;
[0072] Based on the acquisition time stamp, various types of status data are sorted by time, and status data within the same transmission cycle are associated with the same cycle record;
[0073] Missing state items are filled in, and duplicate state items are merged to generate standardized periodic state records.
[0074] Construct a state feature vector in the order of terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data;
[0075] The feature vectors of each state are arranged according to the transmission cycle order to generate a safe state sequence.
[0076] In this embodiment, the output security entropy value, key folding depth adjustment flag, security carryover domain adjustment flag, and self-collapse trigger flag include:
[0077] Construct a security state training dataset by slicing terminal identity state data, service transmission state data, link risk state data, key chain state data, and receiver verification state data according to the transmission cycle and normalizing them to generate a security state vector sequence, and then dividing it into training set, verification set, and test set.
[0078] An improved PWC-Net network is constructed by retaining the feature pyramid module, twist alignment module, cost volume module and decoding module in the original PWC-Net network. A dynamic time offset correction module is connected in series between the feature pyramid module and the twist alignment module. A safe channel attention-entropy fusion module is connected in series after the cost volume module. A phase transition detection branch is added at the same level as the decoding module to form the improved PWC-Net network.
[0079] Multi-scale feature extraction is performed on the safety state vector sequence using a feature pyramid module. This feature pyramid module consists of a four-level residual structure connected sequentially, with each level having 32, 64, 96, and 128 output feature channels respectively. This module is used to generate multi-scale safety state features, specifically:
[0080] First, the input security state vector sequence is fed into the first-level residual structure. A one-dimensional convolution with a stride of 1 is performed on the original sequence, and the result is added with the identity mapping to output 32-channel features. Then, a one-dimensional convolution with a stride of 2 is performed on the first-level features for downsampling, and the result is fed into the second-level residual structure. After the same residual operation, 64-channel features are obtained. Subsequently, the second-level features are downsampled again and fed into the third-level residual structure to generate 96-channel features. Finally, the third-level features are downsampled and input into the fourth-level residual structure to output 128-channel features. The four-level features are retained according to their respective levels and used in the subsequent dynamic time offset correction module and decoding module for multi-scale security state information fusion.
[0081] A dynamic time offset correction module performs time offset correction on the multi-scale security state characteristics of adjacent transmission cycles. This module, composed of a one-dimensional convolutional subnet and gated recurrent units connected sequentially, is used to align state offsets caused by delays, retransmissions, and link fluctuations in weak network environments. Specifically, the time offset correction for multi-scale security state characteristics of adjacent transmission cycles is performed as follows:
[0082] First, the security state features of the current transmission cycle and the previous transmission cycle at the same scale are concatenated along the time dimension to form a two-cycle combined feature sequence. Then, the combined feature sequence is input into a one-dimensional convolutional subnet, which continuously stacks two convolutional layers with a stride of 1 and a batch normalization layer to extract the cross-cycle time offset pattern and output the time offset vector. Next, the time offset vector and the security state features of the previous cycle are input into a gated recurrent unit. The gated recurrent unit performs dynamic displacement and weight redistribution on the features of the previous cycle according to the time offset vector to generate aligned security state features of the previous cycle. Finally, the aligned features of the previous cycle replace the original features of the previous cycle and are retained together with the features of the current cycle.
[0083] The offset relationship between the current security state features and the aligned security state features is calculated using the cost volume module. The security channel attention-entropy fusion module then performs feature weighting and entropy aggregation on the offset relationship to generate a security state stream and corresponding security entropy values, where:
[0084] The cost volume module consists of three layers connected sequentially: a sliding correlation layer, a bidirectional difference stacking layer, and a three-dimensional convolutional compression layer. The sliding correlation layer performs displacement-by-displacement correlation operations on the current safety state features and the aligned safety state features with a preset displacement window to obtain the displacement correlation tensor. The bidirectional difference stacking layer calculates the element-wise difference between the forward correlation tensor and the backward correlation tensor, and stacks them according to the displacement index to form the initial cost volume. The three-dimensional convolutional compression layer uses a 3×3×3 convolution kernel to deeply compress the initial cost volume and outputs a simplified cost value tensor to represent the offset relationship between the two sets of safety state features under each displacement.
[0085] The secure channel attention-entropy fusion module consists of a channel attention subnet, an entropy weight estimation unit, and a weighted fusion layer connected sequentially. The channel attention subnet contains a 1×1 convolution layer, a global average pooling layer, and a sigmoid activation layer, used to calculate the attention weights for five types of channels: identity, service, link, key, and verification. The entropy weight estimation unit calculates the information entropy based on the probability distribution of the above five types of channels, and obtains the corresponding entropy weight coefficients. The weighted fusion layer multiplies the cost tensor element by element with the channel, attention weight, and entropy weight coefficient, and sums them to output the fusion feature. The fusion feature is projected into the flow direction to generate a secure state flow. At the same time, the current secure entropy value is obtained by averaging all channel entropy weight coefficients according to their weights.
[0086] The decoding module outputs a secure state stream. A phase transition detection branch detects state changes in the secure state stream, identifies secure state phase transition points, and connects these points in chronological order to generate a secure state evolution trajectory. The output includes a key folding depth adjustment flag, a secure transition domain adjustment flag, and a self-collapse trigger flag.
[0087] The decoding module consists of three decoding units connected sequentially from top to bottom. Each decoding unit includes a nearest neighbor upsampling layer, a 1×1 convolutional channel integration layer, a feature concatenation layer, and a 3×3 convolutional thinning layer. The nearest neighbor upsampling layer expands the size of the input feature map to the scale of the next pyramid. The 1×1 convolutional channel integration layer unifies the number of channels of the upsampled features to half. The feature concatenation layer concatenates the integrated features with the corresponding horizontally connected features of the pyramid by channels. The 3×3 convolutional thinning layer refines the concatenated features and outputs them. The three decoding units restore the spatial resolution step by step and finally output the full-size safe state stream.
[0088] The phase transition detection branch consists of a temporal differential extraction layer, a dual-threshold decision layer, and a marker generation unit connected sequentially. The temporal differential extraction layer performs cross-cycle differential calculations on the secure state flow to highlight the state transition region. The dual-threshold decision layer determines whether the differential amplitude exceeds the preset phase transition threshold based on the high threshold and the low threshold, respectively. The high threshold is determined as a significant phase transition point, and the area between the low threshold and the high threshold is determined as a potential phase transition point. The marker generation unit connects the significant phase transition points in chronological order to generate the secure state evolution trajectory, and automatically outputs key folding depth adjustment markers, secure transition domain adjustment markers, and self-collapse trigger markers based on the phase transition point density, duration, and differential amplitude.
[0089] The improved PWC-Net network is trained using a joint loss function, which includes offset prediction loss, phase transition detection loss, and safety entropy constraint loss. After training, the improved PWC-Net network can output a safety state flow, a safety state evolution trajectory, and various adjustment markers based on the input safety state sequence.
[0090] The improved PWC-Net network is trained using a joint loss function, specifically as follows:
[0091] Randomly sample the safety state sequences from the training set and input them into the network in batches. Record the safety state stream, phase transition point label probability, and safety entropy prediction value of the network output.
[0092] Calculate the offset prediction loss, compare the output safe state stream with the labeled safe state offset, and use smoothed absolute error to measure the prediction error;
[0093] Calculate the phase transition detection loss, compare the output phase transition point probability with the manually labeled phase transition, and use binary cross-entropy to measure the classification error.
[0094] Calculate the safety entropy constraint loss, compare the output safety entropy value with the center value of the sample's true safety entropy interval, and use the mean square error to measure the magnitude of the deviation.
[0095] The offset prediction loss, phase transition detection loss, and safety entropy constraint loss are weighted and summed with weights of 0.6:0.3:0.1 to form a joint loss, which is then backpropagated to update the network parameters. The batch size is 32, the initial learning rate is 0.001, and the learning rate is reduced by 0.9 times after every 8 rounds of training. The iteration continues for 80 rounds until the validation set error converges.
[0096] In this embodiment, the step of folding the future key seed set in reverse order to generate the current transmission key includes:
[0097] Read the security entropy value, key folding depth adjustment flag, terminal root key, current security state data, timestamp, gateway challenge random number, terminal device number, and link state digest. Determine the future key seed quantity based on the preset security entropy range in which the security entropy value falls, and determine the key folding round based on the key folding depth adjustment flag. Where:
[0098] The number of future key seeds is determined based on the preset security entropy range in which the security entropy value falls, specifically as follows:
[0099] First, compare the security entropy value with four preset threshold intervals. If the security entropy value is in interval I, which is higher than the first threshold and not lower than the highest threshold, then set the number of future key seeds to 8. If the security entropy value is in interval II, which is between the first and second thresholds, then set the number of future key seeds to 12. If the security entropy value is in interval III, which is between the second and third thresholds, then set the number of future key seeds to 16. If the security entropy value is in interval IV, which is lower than the third threshold, then set the number of future key seeds to 20.
[0100] A key derivation input record is constructed according to the following field order: terminal device number, current security status data, timestamp, gateway challenge random number, link state digest, and terminal root key. This key derivation input record is then input into a cryptographic derivation function to generate the first future key seed. Using the first future key seed, seed number, and current security status digest as the next derivation input, a set of future key seeds corresponding to the number of future key seeds is generated sequentially. Specifically, the generation of the first future key seed is as follows:
[0101] The terminal device number, current security status summary, timestamp, gateway challenge random number, link status summary and terminal root key are concatenated into a fixed-length byte string in an agreed order. The key derivation function is called to perform a single round of iterative operation on the byte string, and the derivation result directly output is used as the first future key seed.
[0102] In accordance with the generation time order, each future key seed in the future key seed set is written with a seed number, bound transmission period, bound security state digest, and bound link state digest, generating a future key seed chain arranged in forward chronological order. Based on the key folding round, a target key seed segment is selected from the future key seed chain to participate in the generation of the current transmission key. Specifically, the future key seed chain arranged in forward chronological order is as follows:
[0103] The generation timestamp, seed bytecode, transmission period index, security state digest at generation time, and link state digest at generation time are read sequentially for each future key seed in the future key seed set. The 64-bit generation timestamp, 32-byte seed bytecode, 16-bit transmission period index, 32-byte security state digest, and 32-byte link state digest are concatenated in the order of timestamp, seed bytecode, transmission period index, security state digest, and link state digest to form a fixed-length 115-byte seed record. All seed records are written sequentially to the linked storage area in ascending order of generation timestamp. After each record is written, the address of the next record is written to its linked pointer bit until the last record. A null pointer is written to the linked pointer bit to mark NULL, forming a forward-ordered future key seed chain with the earliest head node time and the latest tail node time.
[0104] The folding process is performed in reverse order of the target key seed segment. First, the last generated future key seed is read as the initial folding input. Then, the previous future key seed is read sequentially. The previous future key seed, the previous round's folding result, the current security state digest, and the gateway challenge random number are concatenated to derive the folding result round by round until all future key seeds within the target key seed segment are folded, generating a time-reverse key chain. Specifically, generating the time-reverse key chain involves:
[0105] First, read the latest future key seed from the target key seed segment and write the 32-byte seed bytecode into the folding buffer as the first round of folding input. Then, read the previous future key seeds one by one in reverse chronological order. Concatenate the 32-byte seed bytecode, the 32-byte hash of the previous folding result, the 32-byte bytecode of the current security state digest, and the 16-byte gateway challenge random number in the order of seed bytecode, folding hash, state digest, and random number to form a 112-byte folding input block. Finally, call the preset cryptographic hash function to perform a single-round hash operation on the folding input block to obtain the new... The 32-byte folded hash is output and written to the end of the folded buffer. The above reverse reading, concatenation, hashing and result writing operations are repeated until the last future key seed in the target key seed segment is folded. After folding, a chain record is generated according to the writing order of the folded buffer. Each record contains 32 bytes of the current folded hash, 32 bytes of the corresponding source seed bytecode and 8 bytes of chain pointer address. Adjacent records are pointed to each other in the writing order to form a time-reverse key chain with the first node being the last time folded hash and the last node being the earliest time folded hash.
[0106] Read the final folded result of the reverse key chain, the current security state digest, the service transport segment identifier, and the link state digest; perform a key confirmation derivation to generate the current transport key. Specifically, generating the current transport key involves:
[0107] First, obtain the 32-byte final folded hash from the tail node of the time-reverse key chain. Then, concatenate the folded hash with the 32-byte current security state digest, the 4-byte service transmission segment identifier, and the 32-byte link state digest in the order of folded hash, state digest, segment identifier, and link digest to form a 100-byte confirmation input block. Using a preset root salt value as the initialization vector, call the key confirmation derivation function to perform a single-round diffusion operation on the confirmation input block and output a 32-byte confirmation hash. Write the confirmation hash into the transmission session key register area, and at the same time generate a 4-byte checksum and write it into the checksum register area. The confirmation hash is the current transmission key, and the checksum is used by the receiving end to verify the validity of the current transmission key.
[0108] In this embodiment, the generation of a secure succession chain, which generates a failure succession zone based on a self-collapse trigger marker, includes:
[0109] Read the security state evolution trajectory, security acceptance domain adjustment flag, self-collapse trigger flag, security state phase transition point, current security state data, time-reverse key chain, service transmission state data, and link risk state data. Divide the domain into identity acceptance domain, service acceptance domain, link acceptance domain, key acceptance domain, and reassembly acceptance domain according to terminal identity state, service transmission state, link risk state, key chain state, and reception verification state. Generate a self-collapse security acceptance domain. Specifically, the generation of the self-collapse security acceptance domain involves:
[0110] Based on the current security status data, the terminal identity status field, service transmission status field, link risk status field, key chain status field, and receive verification status field are read. These are then compared with the corresponding fields at each security state transition point within the security state evolution trajectory to calculate the identity differential amplitude, service differential amplitude, link differential amplitude, key differential amplitude, and verification differential amplitude. Following the shrinkage coefficient given in the security acceptance domain adjustment marker, the five differential amplitudes are multiplied by their respective shrinkage coefficients to obtain the identity acceptance threshold, service acceptance threshold, link acceptance threshold, key acceptance threshold, and reassembly acceptance threshold. Finally, the time is reversed... Cross-mapping is performed on the key chain and service transmission status data, and link risk status data. The allowable range of identity status, service order, link fluctuation, key node usage, and reception reassembly order are limited by various acceptance thresholds to generate an initial security acceptance domain containing five subdomains. Finally, the self-collapse trigger flag determines whether the security acceptance domain should be reduced immediately: if the self-collapse trigger flag is 1, the range corresponding to the five subdomains is tightened synchronously by a shrinkage ratio of 20%; if the self-collapse trigger flag is 0, the initial range remains unchanged. Thus, the self-collapse security acceptance domain corresponding to the current transmission cycle is obtained.
[0111] Based on the time sequence of each security state phase transition point in the security state evolution trajectory, the preceding state segment and the following state segment corresponding to each security state phase transition point are extracted. The identity state summary, service sequence marker, link state summary, key node identifier and reception verification marker in the preceding state segment and the following state segment are read respectively to generate the connection verification segment between adjacent phase transition points.
[0112] Perform continuity verification on each continuity verification segment, and connect adjacent phase transition points that pass the continuity verification in chronological order to generate a safe continuity chain, wherein:
[0113] Perform continuity verification on each connection verification segment, specifically as follows:
[0114] The identity status difference, service sequence difference, link status difference, key node difference, and reception verification difference in each acceptance verification segment are read sequentially. Each difference is compared item by item in the corresponding order of identity acceptance threshold, service acceptance threshold, link acceptance threshold, key acceptance threshold, and reassembly acceptance threshold. When all five differences are less than or equal to their respective thresholds, the acceptance verification segment is marked as continuous. When any difference exceeds its corresponding threshold, the acceptance verification segment is marked as broken, and the breakage reason label is recorded.
[0115] The secure connection chain is generated as follows:
[0116] The system iterates through adjacent safe state phase transition points in the safe state evolution trajectory in chronological order. When a continuous succession verification segment is encountered, the two phase transition points are connected to each other by a one-way chain pointer. When a broken succession verification segment is encountered, the connection is skipped and the traversal continues. After the traversal is completed, a chain structure is obtained, which is composed of continuous phase transition points connected in sequence. The first node is the phase transition point that passes the continuity verification earliest in time, and the last node is the phase transition point that passes the continuity verification latest in time. The chain structure is the safe succession chain.
[0117] Based on the security assumption domain adjustment flag, perform domain boundary shrinkage processing on the security assumption chain:
[0118] Shrink the allowed range of identity status in the identity domain, shrink the allowed range of service order in the service domain, shrink the allowed range of link fluctuation in the link domain, shrink the allowed range of key nodes in the key domain, and shrink the allowed range of receiving order in the reassembly domain to generate a shrunken secure connection chain.
[0119] Based on the self-collapse trigger flag, failure segmentation processing is performed on the shrunk secure takeover chain. State segments, service segments, link segments, key node segments, or receive reassembly segments in the secure takeover chain that do not meet the constraints of the shrunk takeover domain are marked as failed segments. Consecutive failed segments are merged to generate a failed takeover region. The specific process for generating a failed takeover region is as follows:
[0120] Starting from the head node of the shrunk secure takeover chain, the system sequentially traverses the state segments, service segments, link segments, key node segments, and reassembled segments associated with each node within the chain. Each segment is compared against the constraints of the shrunk identity takeover domain, service takeover domain, link takeover domain, key takeover domain, and reassembled takeover domain. If any segment parameter exceeds the corresponding constraint range, the segment is marked as a failed segment. During the traversal, the first and last segment indices of consecutive failed segments are recorded. When the next segment is restored to a valid segment, the previously recorded first and last indices are used as boundaries to output a failed segment. After the traversal, all failed segment segments are merged according to the time order within the chain. If the interval between adjacent failed segments is less than three segments, they are considered the same consecutive failed segment and merged to obtain a failed takeover area composed of several consecutive failed segments.
[0121] In this embodiment, the step of generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message includes:
[0122] Phase-change segmentation is performed on the data to be transmitted according to the order of adjacent receiving nodes in the secure receiving chain. This divides the data into multiple secure transmission segments. Each secure transmission segment is then assigned a transmission segment identifier, its associated service type identifier, the corresponding receiving node identifier, and a generation time stamp. Specifically, the phase-change segmentation based on the order of adjacent receiving nodes in the secure receiving chain is as follows:
[0123] Based on the timestamps recorded by each receiving node in the secure relay chain, the start and end times of adjacent node pairs are extracted in ascending order of time. The data stream to be transmitted is sorted by acquisition time, and data whose timestamps fall between the start and end times of adjacent node pairs are aggregated into a raw segment. Then, starting from 1, the raw segments are assigned transmission segment identifiers in the order of aggregation, and the service type label of the first data packet in the segment is read and written into the corresponding service type identifier field. At the same time, the identifier of the previous receiving node corresponding to the segment is written into the corresponding receiving node identifier field, and the timestamp of the last data packet of the segment is written into the generation time stamp field. This process is repeated for all adjacent receiving node pairs until the end node of the chain, and finally the data to be transmitted is divided into multiple secure transmission segments with complete identifier information.
[0124] Based on the failure acceptance zone, each secure transmission segment is subjected to failure filtering. Secure transmission segments located within the failure acceptance zone are marked as failed transmission segments and subsequent binding processes are stopped. Secure transmission segments located outside the failure acceptance zone are marked as valid transmission segments. A set of valid transmission segments is generated according to the acceptance order in the secure acceptance chain.
[0125] Based on the correspondence between the set of valid transmission segments and the key nodes in the time-reverse key chain, key node binding processing is performed on each valid transmission segment. The receiver node identifier, time stamp, link state digest and security state digest corresponding to each valid transmission segment are read. Key nodes in the time-reverse key chain that are consistent with the transmission period, correspond to the receiver position and have not expired are selected to establish a one-to-one binding relationship between valid transmission segments and key nodes.
[0126] Encrypt each valid transmission segment using the current transmission key. Then, concatenate the encrypted valid transmission segments, their corresponding key node identifiers, link state digests, security state digests, and transmission sequence markers in sequential order to generate a secure transmission chain. Specifically, generating the secure transmission chain involves:
[0127] The symmetric encryption algorithm is invoked, using the current transmission key as the key parameter, to encrypt the data payload and service identifier field of each valid transmission segment one by one, and output the encrypted payload. A chain record is generated for each encrypted payload. The chain record contains the encrypted payload, the corresponding time-reverse key chain key node identifier, a 32-byte link state digest, a 32-byte security state digest, and a 4-byte transmission order marker. A chain pointer is reserved at the end of the chain record for writing the address of the next chain record. The chain records are written to the chain storage area in chronological order of the nodes in the secure takeover chain. After writing a record, the storage address of the next record is immediately written to its chain pointer, until the last record, whose chain pointer is marked as NULL. After writing, the first address of the chain storage area is the address of the secure transmission chain head node, and the chain tail node points to a NULL pointer. This completes the generation of the secure transmission chain.
[0128] Encryption encapsulation is performed on each encrypted valid transmission segment according to the secure transmission chain. In each encapsulation unit, a key node identifier, state digest, transmission chain sequence marker, time window marker, and integrity check marker are written to generate a secure transmission message. Specifically, generating a secure transmission message involves:
[0129] Traverse the chained records in the secure transmission chain in sequence, reading the encrypted payload, key node identifier, link state digest, security state digest, and transmission order marker from each record. Allocate a fixed-size encapsulation unit for the current record and write the following information sequentially: key node identifier, link state digest, security state digest, transmission order marker, sending timestamp, and receiving timeout duration according to a preset time window format. Calculate the message verification code using the current transmission key on the aforementioned fields and the encrypted payload and write the integrity verification marker. Finally, write the encrypted payload. After encapsulation, append the encapsulation unit to the message buffer. Repeat the traversal of all chained records in the chain and perform the same encapsulation operation, appending encapsulation units sequentially according to the chain order. After traversal, write a message header at the beginning of the message buffer. The message header includes the total message length, encryption algorithm identifier, key chain number, and number of encapsulation units, resulting in a complete secure transmission message.
[0130] In this embodiment, the receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, including:
[0131] After receiving a secure transmission message, the receiving end parses the terminal device identifier, transmission segment identifier, key node identifier, status digest, link status digest, transmission chain sequence marker, time window marker, and integrity verification marker in the secure transmission message. Based on the terminal device identifier, it reads the corresponding terminal root key index, gateway challenge random number, and time-reverse key chain recorded by the receiving end.
[0132] Based on the key node identifier, locate the corresponding key node in the time-reverse key chain, verify whether the key node is consistent with the transport segment identifier, time window mark and link state digest, mark the consistent secure transport segment as the key node valid segment, and mark the inconsistent secure transport segment as the key node abnormal segment;
[0133] Based on the time-reverse key chain corresponding to the valid segment of the key node and the current transmission key, the secure transmission message is decrypted. The content of the decrypted secure transmission segment is read, and the state digest and integrity check flag are regenerated. They are then compared with the state digest and integrity check flag carried in the message to generate the state digest check result.
[0134] Perform sequence verification on all valid segments of key nodes according to the transmission chain sequence mark in the secure transmission chain, verify whether the successor node identifier, the preceding transmission segment identifier and the following transmission segment identifier between adjacent secure transmission segments are continuous, and verify whether each secure transmission segment is within the allowed reception time range according to the time window mark, and generate transmission chain sequence verification result and time window verification result.
[0135] The receiving end summarizes the key node verification results, state digest verification results, transmission chain sequence verification results, and time window verification results, generates a verification feedback record, sends the verification feedback record to the intelligent fusion terminal, writes the verification feedback record into the received verification state data, updates the security state sequence, and uses the updated security state sequence as the input for the next transmission cycle to improve the PWC-Net network.
[0136] Example 1: In a continuous secure transmission test cycle for a smart converged terminal, the system connected 18 smart converged terminals, 2 edge gateways, and 1 receiver verification node. Each terminal simultaneously uploaded collected data, device status data, alarm data, and control receipt data. A total of 8640 original transmission records were generated during the test cycle, including 5340 collection records, 1840 status records, 838 alarm records, and 622 control receipt records. The average round-trip time of the original link was 118 milliseconds, the maximum latency was 426 milliseconds, the average packet loss rate was 4.6%, the maximum number of retransmissions in a single cycle was 7, and a total of 31 gateway switching events occurred.
[0137] The system first extracts the terminal identity status, service transmission status, link risk status, key chain status, and receive verification status from each transmission record. Taking the 128th transmission cycle as an example, there are 26 service flow elements, including 16 acquisition flow elements, 5 status flow elements, 3 alarm flow elements, and 2 control receipt flow elements; the link latency is 142 milliseconds, there are 2 packet loss events, 4 retransmission events, 1 transmission sequence number jump, 8 future key seeds, 19 key usage events, and 0 receiver integrity verification failures. The system converts the above fields into a 96-dimensional security state vector and arranges them in the order of the transmission cycle, forming a security state sequence of length 720.
[0138] The training data was obtained using a replayable simulation method, totaling 12,000 samples, including 7,200 normal samples, 2,100 samples of weak network disturbances, 1,000 samples of out-of-order services, 750 samples of fragment insertion, 650 samples of key consumption anomalies, and 300 samples of identity digest anomalies. Each anomaly sample was generated by an injection script, which wrote the anomaly type, injection period, injection field, and injection magnitude into the original normal communication stream; therefore, the training labels were not subjectively labeled manually. The security state offset was obtained by normalizing the difference between the baseline period vector of the same terminal before injection and the period vector after injection, field by field. The identity field, service field, link field, key field, and verification field formed five types of offset labels. The phase transition label was determined by the offset change within three consecutive periods before and after the injection period. When any type of offset continuously exceeded twice the standard deviation of the corresponding baseline mean, the first period exceeding this threshold was marked as the phase transition point. The center value of the true security entropy interval is obtained by weighting five types of normalized risk quantities: identity risk weight is 0.25, business risk weight is 0.20, link risk weight is 0.20, key risk weight is 0.25, and verification risk weight is 0.10. These are then mapped to the interval between 0 and 1, with the center value of the stable zone being 0.85, the center value of the light risk zone being 0.65, the center value of the medium risk zone being 0.45, and the center value of the collapsed zone being 0.25.
[0139] When training the improved PWC-Net network, the training, validation, and test sets are divided in an 8:1:1 ratio. The feature pyramid module outputs four levels of features with 32, 64, 96, and 128 channels. The dynamic temporal offset correction module aligns the features from the previous cycle, the cost volume module calculates the offset relationship between the current feature and the aligned feature, and the safe channel attention-entropy fusion module outputs the safe state flow and the safe entropy value. After 80 training epochs, the validation set phase transition point identification accuracy is 93.5%, the false positive rate for weak network disturbances is 5.8%, and the mean absolute error of the safe entropy is 0.036.
[0140] The security entropy threshold was determined through grid testing on the validation set. The system tested 0.70, 0.75, and 0.80 as stable thresholds, 0.50, 0.55, and 0.60 as low-risk thresholds, and 0.30, 0.35, and 0.40 as collapse thresholds. After comparing the phase transition false negative rate and the frequent key update rate, 0.75, 0.55, and 0.35 were selected. The number of future key seeds is 8 when the security entropy is not lower than 0.75, 12 when it is lower than 0.75 but not lower than 0.55, 16 when it is lower than 0.55 but not lower than 0.35, and 20 when it is lower than 0.35. The number of folding rounds is determined by adjusting the marker according to the key folding depth: 3 rounds for normal marking, 5 rounds for enhanced marking, and 7 rounds for strong enhanced marking.
[0141] The phase transition detection branch outputs three types of control flags. The system counts the number of phase transition points in the last five transmission cycles as the phase transition point density, counts the number of cycles continuously exceeding a low threshold as the duration, and reads the maximum difference value in the secure state stream as the difference amplitude. When the phase transition point density is 1 and the duration does not exceed 2 cycles, it outputs a normal key folding depth flag and a domain preservation flag; when the phase transition point density is 2 or the duration reaches 3 cycles, it outputs a key folding depth enhancement flag and a domain shrinkage of 10% flag; when the phase transition point density is not less than 3, the duration is not less than 3 cycles, and the difference amplitude is not less than 0.65, it outputs a self-collapse trigger flag. If the identity offset, key offset, and verification offset all exceed the threshold simultaneously, the system no longer waits for density statistics and directly outputs the self-collapse trigger flag.
[0142] In the 55th transmission cycle, the link latency increased from 96 milliseconds to 237 milliseconds, the number of retransmissions increased from 1 to 5, and the security entropy decreased from 0.86 to 0.64. Based on these thresholds, the number of future key seeds was adjusted from 8 to 12, and the number of folding rounds was adjusted from 3 to 5. The system first generates 12 future key seeds in a forward direction, and then folds backwards starting from the last generated seed. Each folding round introduces the current security state digest and a gateway challenge random number, ultimately generating the current transmission key. This process takes 9.4 milliseconds on the edge gateway side, with seed generation taking 4.1 milliseconds and reverse folding taking 5.3 milliseconds.
[0143] In the 63rd transmission cycle, the terminal uploaded 3 control receipt streams and 2 alarm streams, and there were 2 transmission sequence number jumps and 1 sequence check anomaly. The system identified the composite phase transition point of the service link and constructed a self-collapsed secure succession domain. There were a total of 46 secure transmission segments in this cycle. Succession continuity verification found that the preceding identifier of the 18th secure transmission segment was 17 but the following identifier jumped to 21. The link state digest of the 19th secure transmission segment was inconsistent with the receiver record. The key node corresponding to the 20th secure transmission segment exceeded the usage window. The system marked the 18th to 20th secure transmission segments as failed segments. The failed area merging interval was set to 3 segments. This value was obtained from the validation set scan: when the interval was 1, the failure merging rate of the abnormal area was 11.6%; when the interval was 2, it was 6.9%; when the interval was 3, it was 2.8% and the false merging rate was 3.1%; when the interval was 4, the false merging rate increased to 8.7%. Therefore, 3 segments were used as the merging interval.
[0144] During encryption and encapsulation, the three transmission segments within the failed continuation zone are no longer included in the secure transmission chain. The remaining 43 valid transmission segments are bound to valid key nodes in the reverse time key chain. Taking the 22nd transmission segment as an example, the original payload length is 384 bytes. After binding to the 7th reverse key node, a 32-byte link state digest and a 32-byte security state digest are written, and then encrypted using the current transmission key, outputting 416 bytes of ciphertext. The 43 valid transmission segments are encapsulated to form an 18.7 kilobyte secure transmission message. The receiving end performs key node verification, state digest verification, transmission chain order verification, and time window verification. 42 transmission segments pass on the first attempt, while one segment is partially retransmitted due to time window exceeding the limit, with a retransmitted data volume of 0.48 kilobytes.
[0145] In 3000 test transmission tasks, the average anomaly isolation time of the traditional fixed session key plus integrity verification method was 1680 milliseconds, while that of this invention was 312 milliseconds. The 312 milliseconds were obtained by accumulating the measured steps: security state vector construction 18 milliseconds, improved PWC-Net inference 46 milliseconds, time-reverse key chain generation 9 milliseconds, continuity verification 41 milliseconds, transmission segment encryption and encapsulation 88 milliseconds, receiver verification 72 milliseconds, and feedback writing 38 milliseconds. The time consumption of the traditional method mainly comes from whole packet retransmission, with an average of 3.8 retransmissions per anomaly, and an average waiting time of 392 milliseconds per retransmission. Comparative results show that the anomaly early detection rate of the traditional method is 43.6%, while that of this invention is 92.8%; the fragment insertion detection rate of the traditional method is 56.9%, while that of this invention is 96.1%; the number of times the key continues to be used after an anomaly is 38, while that of this invention is 2; the average retransmission data volume of the traditional method is 136.5 kilobytes, while that of this invention is 29.8 kilobytes; and the effective transmission completion rate of the traditional method is 90.7%, while that of this invention is 98.1%.
[0146] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A method for secure encrypted transmission of information in an intelligent converged terminal, characterized in that, include: Collect multi-source security status data from intelligent fusion terminals, align the multi-source security status data, and generate a security status sequence; The security state sequence is input into the improved PWC-Net network for security state offset matching, generating a security state stream, identifying security state phase transition points, generating a security state evolution trajectory based on the security state phase transition points, and outputting security entropy value, key folding depth adjustment flag, security bearing domain adjustment flag, and self-collapse trigger flag. The time-reverse key chain is generated by adjusting the marker based on the security entropy value and key folding depth. A future key seed set is generated based on the terminal root key, current security state data, timestamp, and gateway challenge random number. The future key seed set is folded and calculated in reverse order to generate the current transmission key. Based on the safety state evolution trajectory and safety transition domain adjustment markers, a self-collapsed safety transition domain is constructed. The continuity of the transition is verified at the safety state phase transition point to generate a safety transition chain. A failure transition zone is generated based on the self-collapse trigger marker. Based on the secure transmission chain, phase transition segmentation is performed on the data to be transmitted, generating multiple secure transmission segments and binding them with key nodes in the corresponding time reverse key chain. The secure transmission segments are then encrypted using the current transmission key, generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message. The receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, feeds back the verification results to the intelligent fusion terminal, updates the security state sequence, and uses it as input for the next transmission cycle to improve the PWC-Net network.
2. The information security encryption transmission method for intelligent fusion terminals according to claim 1, characterized in that, The multi-source security status data includes terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data.
3. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The step of aligning multi-source security state data to generate a security state sequence includes: Acquire the collection time stamps corresponding to terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data; Based on the acquisition time stamp, various types of status data are sorted by time, and status data within the same transmission cycle are associated with the same cycle record; Missing state items are filled in, and duplicate state items are merged to generate standardized periodic state records. Construct a state feature vector in the order of terminal identity status data, service transmission status data, link risk status data, key chain status data, and reception verification status data; The feature vectors of each state are arranged according to the transmission cycle order to generate a safe state sequence.
4. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The output security entropy value, key folding depth adjustment flag, security carryover field adjustment flag, and self-collapse trigger flag include: Construct a security state training dataset by slicing terminal identity state data, service transmission state data, link risk state data, key chain state data, and receiver verification state data according to the transmission cycle and normalizing them to generate a security state vector sequence, and then dividing it into training set, verification set, and test set. An improved PWC-Net network is constructed by retaining the feature pyramid module, twist alignment module, cost volume module and decoding module in the original PWC-Net network. A dynamic time offset correction module is connected in series between the feature pyramid module and the twist alignment module. A safe channel attention-entropy fusion module is connected in series after the cost volume module. A phase transition detection branch is added at the same level as the decoding module to form the improved PWC-Net network. Multi-scale feature extraction is performed on the safety state vector sequence through the feature pyramid module. The feature pyramid module is composed of four levels of residual structure connected in sequence. The number of output feature channels at each level is 32, 64, 96 and 128 respectively, which are used to generate multi-scale safety state features. The dynamic time offset correction module performs time offset correction on the multi-scale security state characteristics of adjacent transmission cycles. The dynamic time offset correction module is composed of a one-dimensional convolutional subnet and a gated cyclic unit connected in sequence. It is used to align the state offset caused by delay, retransmission and link fluctuation in weak network environment. The offset relationship between the current security state features and the aligned security state features is calculated by the cost volume module. The offset relationship is then processed by feature weighting and entropy aggregation by the security channel attention-entropy fusion module to generate a security state stream and corresponding security entropy value. The security state stream is output through the decoding module. The security state stream is used to detect state changes through the phase transition detection branch, identify security state phase transition points, connect the security state phase transition points in chronological order to generate a security state evolution trajectory, and output key folding depth adjustment flag, security bearing domain adjustment flag and self-collapse trigger flag. The improved PWC-Net network is trained using a joint loss function, which includes offset prediction loss, phase transition detection loss, and safety entropy constraint loss. After training, the improved PWC-Net network can output a safety state flow, a safety state evolution trajectory, and various adjustment markers based on the input safety state sequence.
5. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The step of folding the future key seed set in reverse order to generate the current transmission key includes: Read the security entropy value, key folding depth adjustment flag, terminal root key, current security status data, timestamp, gateway challenge random number, terminal device number and link status digest; determine the number of future key seeds based on the preset security entropy range in which the security entropy value is located; and determine the key folding round based on the key folding depth adjustment flag. Construct a key derivation input record in the order of the fields: terminal device number, current security status data, timestamp, gateway challenge random number, link status digest, and terminal root key. Input the key derivation input record into the cryptographic derivation function to generate the first future key seed. Use the first future key seed, seed number, and current security status digest as the next derivation input to generate a set of future key seeds corresponding to the number of future key seeds in sequence. Write the seed number, binding transmission period, binding security state digest and binding link state digest to each future key seed in the future key seed set in the order of generation time, generate a future key seed chain arranged in forward time, and select the target key seed segment to participate in the generation of the current transmission key from the future key seed chain according to the key folding round. The folding process is performed in reverse order of the target key seed segment. First, the last generated future key seed is read as the initial folding input. Then, the previous future key seed is read in sequence. The previous future key seed, the previous round folding result, the current security state digest and the gateway challenge random number are concatenated and derived. Folding results are generated round by round until all future key seeds in the target key seed segment are folded, and a time-reverse key chain is generated. Read the final folded result of the time-reverse key chain, the current security state digest, the service transport segment identifier, and the link state digest, perform a key confirmation derivation, and generate the current transport key.
6. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The generation of the secure succession chain, based on the self-collapse trigger marker, generates a failure succession zone, including: Read the security state evolution trajectory, security acceptance domain adjustment flag, self-collapse trigger flag, security state phase transition point, current security state data, time-reverse key chain, service transmission state data, and link risk state data. Divide the identity acceptance domain, service acceptance domain, link acceptance domain, key acceptance domain, and reassembly acceptance domain according to the terminal identity state, service transmission state, link risk state, key chain state, and reception verification state, and generate a self-collapse security acceptance domain. Based on the time sequence of each security state phase transition point in the security state evolution trajectory, the preceding state segment and the following state segment corresponding to each security state phase transition point are extracted. The identity state summary, service sequence marker, link state summary, key node identifier and reception verification marker in the preceding state segment and the following state segment are read respectively to generate the connection verification segment between adjacent phase transition points. Perform continuity verification on each continuity verification segment, and connect adjacent phase transition points that pass the continuity verification in chronological order to generate a safe continuity chain; Based on the security assumption domain adjustment flag, perform domain boundary shrinkage processing on the security assumption chain: Shrink the allowed range of identity status in the identity domain, shrink the allowed range of service order in the service domain, shrink the allowed range of link fluctuation in the link domain, shrink the allowed range of key nodes in the key domain, and shrink the allowed range of receiving order in the reassembly domain to generate a shrunken secure connection chain. Based on the self-collapse trigger flag, the shrunk secure takeover chain is subjected to failure segmentation processing. State segments, service segments, link segments, key node segments, or receive reassembly segments in the secure takeover chain that do not meet the constraints of the shrunk takeover domain are marked as failure segments. Continuous failure segments are merged to generate a failure takeover area.
7. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The process of generating a secure transmission chain and performing encrypted encapsulation to generate a secure transmission message includes: Based on the order of adjacent receiving nodes in the secure receiving chain, phase-change segmentation is performed on the data to be transmitted, dividing the data to be transmitted into multiple secure transmission segments. For each secure transmission segment, a transmission segment identifier, a service type identifier, a corresponding receiving node identifier, and a generation time stamp are written. Based on the failure acceptance zone, each secure transmission segment is subjected to failure filtering. Secure transmission segments located within the failure acceptance zone are marked as failed transmission segments and subsequent binding processes are stopped. Secure transmission segments located outside the failure acceptance zone are marked as valid transmission segments. A set of valid transmission segments is generated according to the acceptance order in the secure acceptance chain. Based on the correspondence between the set of valid transmission segments and the key nodes in the time-reverse key chain, key node binding processing is performed on each valid transmission segment. The receiver node identifier, time stamp, link state digest and security state digest corresponding to each valid transmission segment are read. Key nodes in the time-reverse key chain that are consistent with the transmission period, correspond to the receiver position and have not expired are selected to establish a one-to-one binding relationship between valid transmission segments and key nodes. Encrypt each valid transmission segment using the current transmission key, and connect the encrypted valid transmission segments, corresponding key node identifiers, link state digests, security state digests, and transmission sequence markers in the order of concatenation to generate a secure transmission chain. Based on the secure transmission chain, each encrypted valid transmission segment is encrypted and encapsulated. In each encapsulation unit, the key node identifier, state digest, transmission chain sequence marker, time window marker, and integrity verification marker are written to generate a secure transmission message.
8. The information security encrypted transmission method for intelligent fusion terminals according to claim 1, characterized in that, The receiving end performs key node verification, state digest verification, transmission chain sequence verification, and time window verification on the secure transmission message, including: After receiving a secure transmission message, the receiving end parses the terminal device identifier, transmission segment identifier, key node identifier, status digest, link status digest, transmission chain sequence marker, time window marker, and integrity verification marker in the secure transmission message. Based on the terminal device identifier, it reads the corresponding terminal root key index, gateway challenge random number, and time-reverse key chain recorded by the receiving end. Based on the key node identifier, locate the corresponding key node in the time-reverse key chain, verify whether the key node is consistent with the transport segment identifier, time window mark and link state digest, mark the consistent secure transport segment as the key node valid segment, and mark the inconsistent secure transport segment as the key node abnormal segment; Based on the time-reverse key chain corresponding to the valid segment of the key node and the current transmission key, the secure transmission message is decrypted. The content of the decrypted secure transmission segment is read, and the state digest and integrity check flag are regenerated. They are then compared with the state digest and integrity check flag carried in the message to generate the state digest check result. Perform sequence verification on all valid segments of key nodes according to the transmission chain sequence mark in the secure transmission chain, verify whether the successor node identifier, the preceding transmission segment identifier and the following transmission segment identifier between adjacent secure transmission segments are continuous, and verify whether each secure transmission segment is within the allowed reception time range according to the time window mark, and generate transmission chain sequence verification result and time window verification result. The receiving end summarizes the key node verification results, state digest verification results, transmission chain sequence verification results, and time window verification results, generates a verification feedback record, sends the verification feedback record to the intelligent fusion terminal, writes the verification feedback record into the received verification state data, updates the security state sequence, and uses the updated security state sequence as the input for the next transmission cycle to improve the PWC-Net network.