| While industrial wireless technology optimizes the communication performance of the industrial network environment,security has also become a key issue that restricts the popularization of industrial wireless network communication applications.As a selfdeveloped industrial wireless network protocol in my country,the WIA-PA standard urgently needs to establish a set of independent industrial wireless network protocols.The controllable security mechanism fundamentally guarantees the safety,reliability and controllability of the industrial communication process.This thesis aims to ensure the safe data transmission of WIA-PA wireless network and establish an autonomous and controllable security mechanism.Based on the national secret algorithms SM3 and SM4,a set of autonomous and controllable secure data transmission schemes suitable for WIA-PA network is proposed.It has carried out safety function verification and performance test analysis.The main research contents of the thesis are as follows:1.Designed a node identity authentication and key agreement scheme suitable for WIA-PA network.By combining the HMAC-SM3 hash algorithm with the SM4 symmetric encryption algorithm,the WIA-PA node and the WIA-PA gateway complete the two-way identity authentication,and generate the session key and security parameters required by the communication parties.The analysis results show that this scheme guarantees the legality and confidentiality of the WIA-PA node’s network access identity,and at the same time,the attacker cannot forge any useful information in the messages exchanged between the WIA-PA node and the WIA-PA gateway,effectively ensuring the message interaction Security.2.Based on the WIA-PA network node identity authentication and key agreement scheme proposed in this article,a WIA-PA network end-to-end data stream secure transmission scheme based on SM4-CCM* algorithm is designed.Using the unique CCM*working mode of the block cipher algorithm,in the authentication and encryption process of the WIA-PA network application layer data load,the random number factor generated by the WIA-PA node and the WIA-PA gateway is introduced,and the WIA-PA network key update mechanism.The analysis results show that it is difficult for an attacker to steal the effective data payload in the interactive message,nor can they forge legal data verification information,which ensures the confidentiality and integrity of the end-to-end data stream transmission of the WIA-PA network.3.Based on the TF2400 wireless communication module independently developed by the laboratory,a WIA-PA network security test and verification platform was built,and the security scheme proposed in this article was transplanted to the WIA-PA network protocol stack independently developed by the laboratory for security function verification and test analysis.The test results show that while meeting the security goals of the WIA-PA network,this solution achieves safe,autonomous and controllable industrial wireless standards and industrial communications,and the communication overhead caused by this solution is less than 200 μJ,which only occupies WIA-PA 5.2% of the storage space of the WIA-PA node meets the lightweight communication requirements of the WIA-PA network. |