A multi-algorithm deeply fused wireless ad hoc network device encryption system
Patent Information
- Application Number
- CN202610938623.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-26
- Publication Date
- 2026-09-25
AI Technical Summary
[0005]本发明的目的在于提供一种多算法深度融合的无线自组网设备加密系统,有效解决现有方案单一算法易破解、密钥易被物理窃取、加密认证分离存在漏洞、密钥共用引发全域泄露、固件明文外泄总线等问题,实现安全强度乘法级提升、公钥暴力读取概率大幅降低、通信低时延、固件与业务数据安全隔离、存量设备无驱动改造适配的综合技术效果
[0016]本发明相对于现有技术而言,基于依托加密存储、安全加载、可信执行三级硬件防护体系,搭配SM4分组密码与ChaCha20流密码级联融合的双层加密流水线、混沌映射驱动的公钥离散存储机制、程序与业务数据相互隔离的双密钥派生链路、先认证后解密的一体化AEAD报文处理逻辑,完整解决前述背景技术中单一算法易被破解、密钥集中存储易被物理窃取、加密与认证分离带来额外开销与安全漏洞、程序与业务共用密钥体系引发单点泄露、固件解密明文暴露无保护总线、内核层加密改造兼容性差等一系列串联存在的技术问题。将SM4分组密码与ChaCha20流密码采用级联异或的方式深度融合,两套算法采用完全独立派生的密钥与随机数参与运算,密文生成同时依赖两类数学构造完全不同的密码算法,系统整体安全强度由原有两种算法防护能力简单相加升级为相乘关系,大幅提升攻击者同时破解两套算法的难度,有效增强整套系统抗量子计算、抗差分密码攻击的能力,弥补了传统两级密钥封装方案算法融合度不足、防护增益有限的缺陷;通过混沌映射生成随机偏移地址将32字节SM2公钥分片离散写入2KB内存空间,公钥字节与普通运行数据交错存放,不存在连续完整的密钥存储片段,经理论计算公钥被暴力读取成功的概率低至2.9e-71,从物理内存层面阻断DMA、物理探针、内存嗅探等针对密钥的窃取手段,解决背景技术中公钥连续存储极易被完整捕获的问题。采用一体化AEAD流水线实现一次运算同步完成双层加密与报文认证,将Poly1305完整性校验设置为解密前置步骤,报文篡改、伪造内容在校验阶段直接丢弃,不会触发后续解密运算,既规避分步加密认证带来的时序侧信道漏洞,又省去单独校验带来的额外运算开销,适配无线自组网节点低时延实时通信需求;系统划分两套完全独立的密钥派生链路,依托设备硬件唯一标识派生程序镜像专用密钥,依靠实时动态随机数生成业务会话密钥,两套链路采用互不相同的密钥派生函数,固件与业务数据安全域相互隔离,即便某一类密钥发生泄露,另一类数据仍可保持完整加密防护状态,彻底消除传统方案共用密钥体系带来的全盘解密风险。通过内置ROM固化安全启动加载器的PSOC异构芯片搭配独立LKT4200HS加密芯片构建硬件可信底座,程序镜像解密过程产生的密钥、明文固件仅暂存于芯片内部OCM与受保护DDR区域,全程不向外置无保护数据总线输出敏感数据,避免总线嗅探、故障注入攻击截获固件与密钥信息,降低外部存储镜像遭受差分故障攻击、暴力枚举破解的风险;将全部加解密运算逻辑部署于操作系统用户态,无需改动内核网络驱动原生接口,存量无线自组网设备可直接移植本加密方案,无需大规模底层硬件与驱动改版,有效降低设备升级、批量部署的改造与时间成本,在兼顾高强度全域安全防护的同时,同步提升方案工程落地的兼容性与实用性,取得现有传统加密方案无法同时实现的多重协同技术优势。
Smart Images

Figure CN122825104A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure communication encryption technology. Background Technology
[0002] MANETs, relying on the characteristics of having no fixed infrastructure and allowing nodes to move freely, are widely used in scenarios such as outdoor mobile communication and distributed radio transmission. In these scenarios, devices are in an open and unprotected physical environment for extended periods, making communication data, device firmware images, and key information highly vulnerable to various active and passive attacks. Therefore, the overall encryption and protection system for these devices has extremely high security requirements. Currently, mainstream MANET encryption solutions in the industry generally use a single SM4 or AES symmetric encryption algorithm to encrypt service data and program images. Key distribution relies solely on pre-shared configuration or simple asymmetric key encapsulation for overall protection. While the basic implementation logic is simple, the entire protection system has multiple security vulnerabilities.
[0003] The most readily available and mature implementation is the SM2-encapsulated SM4 key encryption architecture used in some dedicated radio stations. This solution encapsulates the SM4 session key with the SM2 public key, and then uses SM4 to encrypt the program image and transmitted data respectively. Although it introduces both asymmetric and symmetric cryptographic algorithms, the two algorithms are only associated by simple key encapsulation. The program encryption process and the business data encryption process are independent of each other. It does not fully leverage the complementary protective characteristics of block ciphers and stream ciphers in mathematical structure, and its overall resistance to quantum computing attacks and fault injection attacks still has significant shortcomings. At the algorithm protection level, the overall system security strength is merely the sum of the protection capabilities of two algorithms. Attackers can target either the SM2 public key or the SM4 symmetric algorithm with side-channel attacks or quantum cracking. Once either algorithm is compromised, the entire communication system will be completely disabled. At the key storage level, during device operation, public keys and symmetric keys are mostly stored in memory in a complete and continuous form. Attackers can completely capture all key data through physical probes, DMA bus sniffing, and brute-force memory reading. Furthermore, the existing key management logic is poorly designed and lacks protection mechanisms against key fragmentation and discrete hiding, resulting in a persistently high risk of key leakage.
[0004] Meanwhile, existing encryption architectures separate data encryption operations and message integrity authentication operations into two independent execution phases. Verification logic is executed separately after encryption, adding extra computational overhead to wireless message transmission. This step-by-step workflow also introduces timing vulnerabilities, making it highly susceptible to timing attacks and fault injection attacks to deduce key information. At the key derivation management level, existing devices share the same key derivation system for local program images and wireless service data. If a key is leaked in a single communication session, all historical transmission messages and stored firmware images can be completely decrypted, creating a fatal flaw of single-point leakage leading to total vulnerability. Furthermore, the program image stored on the device's external storage medium relies solely on a single encryption algorithm for protection, making it vulnerable to brute-force key enumeration and differential fault attacks that could tamper with the image. Plaintext firmware and intermediate keys generated by traditional secure boot processes are directly exposed on unprotected external data buses, further expanding the leakage paths for keys and firmware data. Conventional encryption logic is mostly deployed at the operating system kernel level; modifying existing wireless driver interfaces requires significant modifications to the underlying code, resulting in high costs for mass production adaptation and upgrades, and making it difficult to adapt to and be compatible with multiple models of existing wireless self-organizing network terminals. Summary of the Invention
[0005] The purpose of this invention is to provide a wireless self-organizing network device encryption system that deeply integrates multiple algorithms, effectively solving the problems of existing solutions such as easy cracking of single algorithms, easy physical theft of keys, vulnerabilities in encryption and authentication separation, global leakage caused by key sharing, and plaintext leakage of firmware to the bus. It achieves a multiplicative improvement in security strength, a significant reduction in the probability of brute-force reading of public keys, low communication latency, secure isolation between firmware and business data, and driverless adaptation for existing devices.
[0006] To address the aforementioned technical problems, this invention provides a wireless ad hoc network device encryption system with deep fusion of multiple algorithms, including a hardware security protection unit, a program image encryption processing unit, and a service data transmission encryption unit. The hardware security protection unit includes a heterogeneous main control chip, an external encryption chip, and a secure boot loader; The program image encryption processing unit is equipped with a block cipher algorithm execution link and a key discrete storage link; The business data transmission encryption unit is equipped with a block-stream cipher concatenated encryption link and a message integrity authentication link.
[0007] The heterogeneous main control chip adopts the FMQL45T900 PSOC chip, which includes a PS-side ARM processor and a PL-side FPGA logic; the external encryption chip adopts the LKT4200HS security encryption chip, which outputs the SM2 standard public key.
[0008] The execution steps of the key discrete storage link are as follows: S1 and PL terminals read the original bytes of the SM2 public key output by the LKT4200HS security encryption chip from the FPGA logic. S2. Preprocess the original public key bytes using the ChaCha20 stream cipher. S3. Generate multiple sets of random memory offset addresses based on chaotic mapping functions; S4. Distribute the 32-byte SM2 public key bytes into different random offset addresses within a 2KB memory space.
[0009] The program image encryption processing unit executes the following steps in sequence: S1. The program images of the wireless self-organizing network's supporting WEB network management software, main control software, routing software, and MAC software are encrypted using SM4 block cipher CBC mode. S2. Use the SM2 public key to encrypt the SM4 session key of the corresponding program image; S3, the secure boot loader reads the encrypted program image stored internally on the external eMMC storage medium; S4. Decrypt the encrypted program image and write the plaintext image generated by decryption into the chip's built-in OCM storage area or DDR protected memory area.
[0010] The secure boot loader is embedded in the internal ROM storage area of the FMQL45T900 PSOC chip; the key data and plaintext data generated during the entire process of program image decryption are only stored in the protected storage area inside the chip and are not output to the unprotected data bus.
[0011] The sending end of the block-stream cipher concatenated encryption link performs the following steps in sequence: S1. Use SM4 block cipher CBC mode to encrypt the plaintext business data and generate intermediate ciphertext C1; S2. Retrieve the independent derived key and randomly generate a 12-byte nonce, encrypt the intermediate ciphertext C1 using the ChaCha20 stream cipher, and generate the final ciphertext C2. S3. Input the fixed-format security header and the final ciphertext C2 into the Poly1305 authentication module to generate a 16-byte authentication tag. S4. Assemble and transmit messages in a fixed order. The structure of the transmitted message consists of a security header, final ciphertext C2, and authentication tag.
[0012] The receiving end of the block-stream cipher concatenated encryption link performs the following steps in sequence: S1, the Poly1305 authentication module retrieves the security header and the final ciphertext C2 to complete the authentication tag verification; S2. After the authentication tag verification is passed, the final ciphertext C2 is decrypted using the ChaCha20 stream cipher to restore the intermediate ciphertext C1. S3. Decrypt the intermediate ciphertext C1 using the SM4 block cipher in CBC mode to restore the original plaintext business data.
[0013] The security header is a 20-byte fixed-length structure. Inside the security header, there are sequentially set a 4-byte identifier field, a 1-byte version field, a sender node number field, a receiver node number field, a reserved field, a 32-bit start identifier field, and a 64-bit globally incrementing sequence number field. The complete security header data is input as additional authentication data into the Poly1305 authentication module to participate in the verification calculation.
[0014] Two isolated key derivation links are configured. The first key derivation link reads the unique hardware device identifier and generates a dedicated key for encrypting the program image. The second key derivation link reads a real-time dynamic random number and generates a session key for business data transmission. The two key derivation links are configured with different key derivation functions.
[0015] All encryption and decryption operations of the business data transmission encryption unit are deployed in the user space of the operating system; the operating system kernel network driver maintains the native interface structure.
[0016] Compared with existing technologies, this invention is based on a three-level hardware protection system of encrypted storage, secure loading, and trusted execution, combined with a two-layer encryption pipeline that integrates SM4 block cipher and ChaCha20 stream cipher, a public key discrete storage mechanism driven by chaotic mapping, a dual-key derivation link that isolates program and business data, and an integrated AEAD message processing logic that authenticates before decryption. This invention completely solves a series of interconnected technical problems in the aforementioned background technologies, such as the ease with which a single algorithm can be cracked, the vulnerability of centralized key storage to physical theft, the additional overhead and security vulnerabilities caused by the separation of encryption and authentication, the single point of leakage caused by the shared key system between programs and business, the exposure of plaintext during firmware decryption without a protected bus, and the poor compatibility of kernel-level encryption modifications. This invention deeply integrates the SM4 block cipher and the ChaCha20 stream cipher using a concatenated XOR method. Both algorithms employ completely independently derived keys and random numbers in their computations. Ciphertext generation relies on two entirely different mathematically constructed cryptographic algorithms. The overall system security is upgraded from a simple addition of the two algorithms' protective capabilities to a multiplicative relationship, significantly increasing the difficulty for attackers to simultaneously crack both algorithms. This effectively enhances the system's resistance to quantum computing and differential cryptography attacks, compensating for the shortcomings of traditional two-level key encapsulation schemes, such as insufficient algorithm integration and limited protection gains. By generating random offset addresses through chaotic mapping, the 32-byte SM2 public key is fragmented and discretely written into a 2KB memory space. The public key bytes are interleaved with ordinary operational data, eliminating the possibility of continuous, complete key storage fragments. Theoretically, the probability of a successful brute-force read of the public key is as low as 2.9e-71. This blocks key theft methods such as DMA, physical probes, and memory sniffing at the physical memory level, solving the problem in the background technology where continuous public key storage is easily captured. The system employs an integrated AEAD pipeline to simultaneously complete dual-layer encryption and message authentication in a single operation. Poly1305 integrity verification is set as a pre-decryption step, and message tampering or forgery is directly discarded during the verification stage without triggering subsequent decryption operations. This avoids the timing-side channel vulnerability caused by step-by-step encryption and authentication, and saves the additional computational overhead of separate verification, adapting to the low-latency real-time communication requirements of wireless ad hoc network nodes. The system divides two completely independent key derivation links, relying on the device hardware's unique identifier to derive the program image dedicated key, and relying on real-time dynamic random numbers to generate the service session key. The two links use different key derivation functions, and the firmware and service data security domains are isolated from each other. Even if one type of key is leaked, the other type of data can still maintain a complete encrypted protection state, completely eliminating the risk of full decryption caused by the shared key system of traditional solutions.A trusted hardware foundation is built by combining a PSOC heterogeneous chip with a built-in ROM-embedded secure boot loader and an independent LKT4200HS encryption chip. The keys and plaintext firmware generated during the program image decryption process are only temporarily stored in the chip's internal OCM and protected DDR areas. Sensitive data is never output to the external unprotected data bus, avoiding bus sniffing and fault injection attacks that could intercept firmware and key information. This reduces the risk of external storage images being attacked by differential fault attacks or brute-force enumeration. All encryption and decryption logic is deployed in the operating system's user space, without requiring modifications to the kernel network driver's native interface. Existing wireless self-organizing network devices can directly port this encryption scheme without large-scale modifications to the underlying hardware and drivers, effectively reducing the transformation and time costs of device upgrades and batch deployments. While ensuring high-strength, all-domain security protection, the scheme simultaneously improves the compatibility and practicality of engineering implementation, achieving multiple collaborative technical advantages that existing traditional encryption schemes cannot achieve at the same time.
[0017] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0018] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0019] Figure 1 This is a schematic diagram of the system architecture of at least one embodiment of the present invention; Figure 2 This is a schematic diagram of the complete encryption and decryption process of the device program image in one embodiment of the present invention; Figure 3 This is a schematic diagram of the discrete distribution of the SM2 public key in memory in one embodiment of the present invention; Figure 4 This is a schematic diagram of the complete internal processing flow of mixed encryption of business data in one embodiment of the present invention. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the embodiments of this invention will be described in detail below with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details are presented in the embodiments of this invention to facilitate a better understanding of this application. However, the technical solutions claimed in this application can be implemented even without these technical details and various variations and modifications based on the following embodiments. The division of the following embodiments is for ease of description and should not constitute any limitation on the specific implementation of this invention. The embodiments can be combined with and referenced by each other without contradiction.
[0021] Example 1 like Figure 1 The illustrated encryption system for wireless ad hoc networks, featuring deep integration of multiple algorithms, includes a hardware security protection unit, a program image encryption processing unit, and a service data transmission encryption unit. The hardware security protection unit comprises a heterogeneous main control chip, an external encryption chip, and a secure bootloader. The program image encryption processing unit includes a block cipher algorithm execution link and a discrete key storage link. The service data transmission encryption unit includes a block-stream cipher concatenated encryption link and a message integrity authentication link. Employing a three-tiered unit architecture (hardware, program image, and service data), the system logically isolates local firmware protection from wireless transmission data protection. The two types of encryption links are independently scheduled within different units, preventing timing-side channel leakage caused by shared computing resources between program encryption and message encryption. Furthermore, the layered architecture allows for the individual replacement of any unit's hardware or algorithm, adapting to wireless ad hoc network terminals with different computing power and security levels, providing underlying architectural support for multi-algorithm integration and hierarchical key protection.
[0022] This approach, through the parallel deployment of three layers of protection units—the hardware layer, local firmware, and wireless transmission—forms a layered protection logic of "hardware trusted base - local program static encryption - dynamic message transmission encryption." All subsequent innovative mechanisms, such as discrete key storage, dual-algorithm concatenated encryption, secure boot isolation, and dual-key derivation, can be implemented based on this layered architecture. From the top-level architecture level, it avoids the inherent shortcomings of existing technologies, such as single encryption dimensions and lack of protection boundaries, and provides a complete architectural foundation for multi-level and multi-dimensional collaborative security protection.
[0023] Example 2 Based on Example 1, the hardware selection is limited as follows: the heterogeneous main control chip adopts the FMQL45T900 PSOC chip, which includes a PS-side ARM processor and a PL-side FPGA logic; the external encryption chip adopts the LKT4200HS security encryption chip, which outputs the SM2 standard public key. The PSOC chip distinguishes between the PS software domain and the PL hardware logic domain, placing the key shuffling and preprocessing operations in the FPGA hardware logic for execution, without occupying ARM software computing resources and avoiding plaintext traces in memory generated by software key processing; the independent external encryption chip is dedicated to generating and outputting the SM2 public key, and the public key generation logic is enclosed inside the security processor, so that the external ARM cannot tamper with or hijack the public key generation process, ensuring the original credibility of the public key from the source.
[0024] The execution steps of the key discrete storage link are as follows: S1 and PL terminals read the original bytes of the SM2 public key output by the LKT4200HS security encryption chip from the FPGA logic. S2. The ChaCha20 stream cipher is used to preprocess the original public key bytes, thereby disrupting the fixed arrangement of the original public key bytes. Even if a memory segment is partially truncated, the attacker cannot identify it as a public key segment by byte features, further increasing the difficulty of key identification. S3. Based on the chaotic mapping function, multiple sets of random memory offset addresses are generated. The output of the chaotic mapping is a non-periodic random offset and there is no fixed address pattern. Unlike the ordinary random number generation method, attackers cannot reverse the public key fragment position through the address distribution pattern, which greatly reduces the success rate of brute-force matching. S4. The 32-byte SM2 public key bytes are scattered and written to different random offset addresses within a 2KB memory space. The 32-byte fragments are stored in a 2KB whole memory space. The public key bytes are interleaved with ordinary running data. After the attacker reads the whole memory space completely, he cannot distinguish the valid public key fragments. This blocks the attack path of DMA and probe to steal the public key completely from the physical memory level.
[0025] The above-mentioned discrete distribution of SM2 public keys in memory is arranged as follows: Figure 3 As shown.
[0026] In the above process, the probability of successfully guessing the 32-byte public key in 2K memory in a single brute-force attempt is: ≈32* - ≈2.9 Therefore, the technical solution of this application provides extremely high resistance to brute-force reads. The 32 bytes of the SM2 public key are distributed and written into memory according to the offset addresses generated by the chaotic mapping. Even if an attacker reads the entire memory, they will not be able to distinguish which bytes belong to the public key. The steps executed by the sender in a block-stream cipher concatenated encryption link are as follows: S1. The plaintext business data is encrypted using the SM4 block cipher in CBC mode to generate intermediate ciphertext C1. The SM4 block cipher achieves confusion diffusion on fixed-length message blocks, eliminates plaintext statistical features, and blocks differential attacks based on message format, serving as the first layer of basic encryption barrier. S2. Retrieve the independent derived key and randomly generate a 12-byte nonce. Encrypt the intermediate ciphertext C1 using the ChaCha20 stream cipher to generate the final ciphertext C2. The ChaCha20 stream cipher and SM4 use two independent keys and random numbers. The mathematical constructions of the two algorithms are completely unrelated. An attacker must crack both algorithms simultaneously to recover the plaintext. The security strength is the product of the protection strengths of the two algorithms. The 12-byte standard nonce satisfies the uniqueness requirement of the stream cipher and avoids the replay key stream vulnerability. S3. Input the fixed-format security header and the final ciphertext C2 into the Poly1305 authentication module to generate a 16-byte authentication tag. The header and ciphertext are used together in the tag calculation to fully cover all valid information in the message. There is no unauthenticated raw data, which avoids the risk of message header being tampered with and node identity being forged. S4. Assemble and transmit messages in a fixed order. The message structure consists of a security header, final ciphertext C2, and authentication tag. The fixed message order allows the receiver to quickly separate the security header, ciphertext, and tag at a fixed offset without additional parsing and judgment, reducing wireless message verification latency and adapting to the low-latency communication requirements of mobile ad hoc networks.
[0027] The receiving end of a block-stream cipher concatenated encryption link performs the following steps in sequence: S1 and Poly1305 authentication modules retrieve the security header and final ciphertext C2 to complete the authentication tag verification. The authentication verification is set as a pre-decryption step. Illegally tampered or forged messages are directly discarded during the verification stage and will not trigger subsequent decryption operations. This avoids the leakage of timing characteristics during the decryption process and resists fault injection and timing side-channel attacks. S2. After the authentication tag verification is passed, the final ciphertext C2 is decrypted using the ChaCha20 stream cipher to restore the intermediate ciphertext C1. S3. The intermediate ciphertext C1 is decrypted using the SM4 block cipher in CBC mode to restore the original plaintext business data. The decryption order corresponds to the reverse of the encryption order. This two-layer decryption and step-by-step restoration ensures that if any layer fails, the plaintext cannot be obtained, forming an irreversible double-layer protection. The complete internal processing flow for mixed encryption of business data is as follows: Figure 4 As shown.
[0028] Security header constraints: The security header is a fixed-length 20-byte structure. Internally, it contains a 4-byte identifier field, a 1-byte version field, a sender node number field, a receiver node number field, a reserved field, a 32-bit startup identifier field, and a 64-bit globally incrementing sequence number field. The complete security header data is input as additional authentication data to the Poly1305 authentication module for verification. The fixed-length structure has no memory-aligned padding bytes, allowing for precise prediction of the message length. The globally monotonically incrementing sequence number and the startup identifier bound to a single device power-on cycle provide a dual mechanism to block message replay attacks. Node numbers are included in the authentication scope to prevent cross-node forged message forwarding.
[0029] This approach uses chaotic mapping to fragment the public key storage, reducing the probability of brute-force reading of the public key to an extremely low theoretical value. At the same time, it employs two cryptographic serial concatenations with completely different mathematical mechanisms, SM4 and ChaCha20, achieving a multiplicative improvement in security strength. Combined with a verification sequence of authentication before decryption, it simultaneously strengthens communication security from three dimensions: hardware key storage, message encryption algorithm, and message integrity verification. The entire process has controllable computational overhead, adding only 36 bytes of message payload, and will not have a significant negative impact on the transmission bandwidth or real-time performance of the wireless ad hoc network.
[0030] At the hardware level, the FPGA independently completes key preprocessing and discrete writing without consuming software computing power. At the cryptographic level, the dual-layer encryption and integrated authentication pipeline are executed synchronously. The message format is lightweight and fully compatible with the original network transmission interface. It achieves comprehensive technical effects that cannot be achieved by existing technologies in many aspects, such as resistance to quantum computing cracking, resistance to physical hardware attacks, resistance to message tampering and replay, and reduction of communication verification overhead. This is the core innovative implementation branch of this invention that distinguishes it from existing encryption schemes, and it can fully support the inventive argument at the patent examination response stage.
[0031] Example 3 Based on Example 1, the program image encryption processing unit performs the following steps in sequence: S1. The program images of the wireless self-organizing network's supporting WEB network management software, main control software, routing software, and MAC software are encrypted using SM4 block cipher CBC mode. All core control programs of the network are uniformly encrypted, and there are no unprotected bare program images. This prevents the routing and network management modules from being tampered with or hijacked individually, and ensures the reliability of the network routing logic. S2. The SM4 session key of the corresponding program image is encrypted using the SM2 public key. The firmware session key is encapsulated using the national cryptographic asymmetric algorithm. Only devices holding the corresponding private key can decrypt the image. External devices cannot directly enumerate the firmware encryption key by force. S3, the secure boot loader reads the encrypted program image stored internally on the external eMMC storage medium; S4. Decrypt the encrypted program image. The decrypted image plaintext is written to the chip's built-in OCM storage area or DDR protected memory area. The decrypted output plaintext is directly written to the chip's internal closed storage area. The image plaintext is not cached in the external general memory, thus blocking the external bus and DMA from reading the complete firmware code.
[0032] Complete encryption and decryption process of device program image as follows Figure 2 As shown.
[0033] Secure Boot Hardware Constraints: The secure boot loader is embedded in the internal ROM storage area of the FMQL45T900 PSOC chip; the key data and plaintext data generated during the entire program image decryption process are only stored in the protected storage area inside the chip and are not output to the unprotected data bus. The ROM is a one-time fixed read-only area, and the loader program cannot be tampered with externally; the key and plaintext are completely isolated and stored inside the chip, and data transmission does not pass through the open bus, preventing bus sniffing attacks from obtaining firmware and key information.
[0034] Key Derivation Link Configuration: The system is configured with two isolated key derivation links. The first key derivation link reads the unique hardware device identifier to generate a dedicated encryption key for the program image. The second key derivation link reads a real-time dynamic random number to generate a session key for business data transmission. Each key derivation link is configured with a different key derivation function. The firmware key is bound to the unique hardware ID of the device, ensuring one firmware key per device and preventing cross-platform encryption. The business session key is dynamically generated for each communication, achieving one key per message. The input sources and derivation functions of the two links are completely independent, ensuring that a single-path key leak will not simultaneously leak firmware and business data, eliminating the risk of a single point of failure leading to total system failure.
[0035] Encryption Deployment Location Restrictions: All encryption and decryption logic for business data transmission is deployed in the operating system's user space; the operating system kernel network driver maintains its native interface structure without modification. The encryption logic does not intrude into the kernel driver, requiring no modification to the underlying communication hardware driver code. Existing wireless self-organizing network terminals can directly port this encryption scheme, significantly reducing hardware modification costs and adaptation cycles; simultaneously, user-space program crashes will not cause kernel network link interruptions, improving device operational stability.
[0036] This leads to a complete implementation solution encompassing trusted offline firmware booting, dual-domain isolated key management, and non-intrusive software encryption deployment. Based on a chip ROM-embedded secure boot loader, it achieves full-process hardware isolation for image decryption, ensuring that plaintext and keys circulate only within the chip's closed storage area, completely blocking external bus interception channels. Two completely independent key derivation links physically isolate the firmware security domain from the business communication security domain, enabling one firmware key per device and one business session key per call, cutting off the risk of single-point leakage and cascading failures at the key source. All encryption logic is placed in the operating system's user space, fully compatible with existing underlying drivers, requiring no modification to the underlying hardware communication layer, significantly reducing equipment modification and batch deployment costs.
[0037] This embodiment balances offline static security protection for devices with engineering adaptability, complementing the wireless dynamic message encryption scheme of Embodiment 2. It covers the entire lifecycle security protection of device power-on startup, local firmware storage, and node wireless communication. The whole solution balances security performance and engineering practicality, resolving the contradiction between the difficulty of balancing security design and mass production implementation in existing technologies, and forming a technical solution with significant progress.
[0038] Those skilled in the art will understand that the above embodiments can be modified in form and detail in practical applications without departing from the spirit and scope of the invention.
Claims
1. A wireless ad hoc network device encryption system with deep fusion of multiple algorithms, characterized in that, It includes a hardware security protection unit, a program image encryption processing unit, and a business data transmission encryption unit; The hardware security protection unit includes a heterogeneous main control chip, an external encryption chip, and a secure boot loader; The program image encryption processing unit is equipped with a block cipher algorithm execution link and a key discrete storage link; The business data transmission encryption unit is equipped with a block-stream cipher concatenated encryption link and a message integrity authentication link.
2. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 1, characterized in that, The heterogeneous main control chip adopts the FMQL45T900 PSOC chip, which includes a PS-side ARM processor and a PL-side FPGA logic; the external encryption chip adopts the LKT4200HS security encryption chip, which outputs the SM2 standard public key.
3. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 2, characterized in that, The execution steps of the key discrete storage link are as follows: S1, PL terminal FPGA logic reads the original bytes of the SM2 public key output by the LKT4200HS security encryption chip; S2. Preprocess the original public key bytes using the ChaCha20 stream cipher. S3. Generate multiple sets of random memory offset addresses based on chaotic mapping functions; S4. Distribute the 32-byte SM2 public key bytes into different random offset addresses within a 2KB memory space.
4. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 1, characterized in that, The program image encryption processing unit executes the following steps in sequence: S1. The program images of the wireless self-organizing network's supporting WEB network management software, main control software, routing software, and MAC software are encrypted using SM4 block cipher CBC mode. S2. Use the SM2 public key to encrypt the SM4 session key of the corresponding program image; S3, the secure boot loader reads the encrypted program image stored internally on the external eMMC storage medium; S4. Decrypt the encrypted program image and write the plaintext image generated by decryption into the chip's built-in OCM storage area or DDR protected memory area.
5. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 4, characterized in that, The secure boot loader is embedded in the internal ROM storage area of the FMQL45T900 PSOC chip; The key data and mirror plaintext data generated during the entire process of program image decryption are stored only in the protected storage area inside the chip and are not output to the unprotected data bus.
6. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 1, characterized in that, The sending end of the block-stream cipher concatenated encryption link performs the following steps in sequence: S1. Use SM4 block cipher CBC mode to encrypt the plaintext business data and generate intermediate ciphertext C1; S2. Retrieve the independent derived key and randomly generate a 12-byte nonce, encrypt the intermediate ciphertext C1 using the ChaCha20 stream cipher, and generate the final ciphertext C2. S3. Input the fixed-format security header and the final ciphertext C2 into the Poly1305 authentication module to generate a 16-byte authentication tag. S4. Assemble and transmit messages in a fixed order. The structure of the transmitted message consists of a security header, final ciphertext C2, and authentication tag.
7. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 6, characterized in that, The receiving end of the block-stream cipher concatenated encryption link performs the following steps in sequence: S1, the Poly1305 authentication module retrieves the security header and the final ciphertext C2 to complete the authentication tag verification; S2. After the authentication tag verification is passed, the final ciphertext C2 is decrypted using the ChaCha20 stream cipher to restore the intermediate ciphertext C1. S3. Decrypt the intermediate ciphertext C1 using the SM4 block cipher in CBC mode to restore the original plaintext business data.
8. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 7, characterized in that, The security header is a 20-byte fixed-length structure. Inside the security header, there are sequentially set a 4-byte identifier field, a 1-byte version field, a sender node number field, a receiver node number field, a reserved field, a 32-bit start identifier field, and a 64-bit globally incrementing sequence number field. The complete security header data is input as additional authentication data into the Poly1305 authentication module to participate in the verification calculation.
9. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 1, characterized in that, Two isolated key derivation links are configured. The first key derivation link reads the unique hardware device identifier and generates a dedicated key for encrypting the program image. The second key derivation link reads a real-time dynamic random number and generates a session key for business data transmission. The two key derivation links are configured with different key derivation functions.
10. The encryption system for wireless ad hoc network devices with deep fusion of multiple algorithms as described in claim 1, characterized in that, All encryption and decryption operations of the business data transmission encryption unit are deployed in the user space of the operating system; the operating system kernel network driver maintains the native interface structure.