Power distribution terminal remote upgrading method and device, storage medium and program product

By introducing a communication architecture separated from the business channel and the management channel in the power distribution terminal, the problems of high operation and maintenance costs and real-time service interference in the upgrade process in the existing technology are solved, and an efficient and reliable remote upgrade method is realized, which is suitable for large-scale power distribution automation systems.

CN120335842AActive Publication Date: 2025-07-18SHANGHAI HOLYSTAR INFORMATION TECH

Patent Information

Application Number
CN202510812463.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-18
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

The existing power distribution terminal upgrade method has the problem of high operation and maintenance costs, low efficiency, and the upgrade process is prone to interfere with real-time service communication.

Method used

Using a dual-channel communication architecture separated from the service channel and the management channel, the upgrade activation instructions are sent through the management channel and the program files are transmitted in segments. The power distribution terminal performs integrity verification after receiving it to ensure the correctness and transmission reliability of the upgrade files.

Benefits of technology

It realizes a high degree of automation and intelligence of the remote upgrade process of power distribution terminals, improves transmission efficiency, reduces manual operation and maintenance costs, and ensures the real-time and stability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120335842A_ABST
    Figure CN120335842A_ABST
Patent Text Reader

Abstract

The invention provides a power distribution terminal remote upgrading method and device, a storage medium and a program product, and the method comprises the steps that a power master station establishes communication connection of a service channel and a management channel with a power distribution terminal, the service channel is used for transmitting real-time service data, and the management channel is used for transmitting a control instruction and data content of an upgrading file; the two channels operate independently and communicate with each other without interfering with each other; the power master station sends an upgrade activation instruction to the power distribution terminal through the management channel, and remote upgrade is started; the power master station divides a to-be-upgraded program file into a plurality of data segments and sends the data segments to the power distribution terminal through the management channel in sequence; the power distribution terminal receives and caches the multiple data segments, integrity verification is carried out after all the data segments are received, and program updating operation of the power distribution terminal is started after verification is passed. According to the method, the situation that real-time communication resources are occupied in the upgrading process is effectively avoided, and interference on real-time services is prevented. The method is suitable for centralized upgrade management in a large-scale distribution automation system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of power equipment communication, and particularly to a method, device, storage medium, and program product for remote upgrade of distribution terminals. Background Art

[0002] In recent years, with the large-scale construction and continuous promotion of the distribution automation system, the feeder terminal unit (FTU), as a key intelligent device on the distribution network site, plays an increasingly important role in aspects such as power system operation monitoring, control execution, and data acquisition. To ensure the intelligent level, safety, and stability of system operation, the FTU device needs to be regularly updated with program versions and upgraded with functions.

[0003] At present, the upgrade methods of FTU devices mainly rely on manual on-site operations or remote program distribution, and there are many problems to be solved. On the one hand, in the context of a large scale of existing network devices, the method of manual upgrade one by one has high operation and maintenance costs and low efficiency, and it is difficult to meet the actual needs of large-scale centralized upgrades. On the other hand, in the existing distribution network communication architecture, four remote services such as telemetry, tele-signaling, and tele-control share the same communication channel with file transfer tasks. In a concurrent communication scenario, the four remote services have a higher transmission priority, and file transfer packets are easily interrupted, discarded, or retransmitted, affecting the terminal upgrade efficiency. Summary of the Invention

[0004] Aiming at the deficiencies of the existing technology, this application provides a method, device, storage medium, and program product for remote upgrade of distribution terminals, at least to solve the problems that the business channel needs to be occupied and real-time service communication is easily interfered during the upgrade process of distribution terminals in the existing technology.

[0005] To achieve the above objectives and other advantages, some embodiments of this application provide the following aspects: In a first aspect, some embodiments of this application provide a method for remote upgrade of distribution terminals, including: The power master station respectively establishes communication connections for a business channel and a management channel with the distribution terminal. Among them, the business channel is used to transmit real-time service data with high priority, and the management channel is used to transmit control instructions and data content of upgrade files. The business channel and the management channel operate independently of each other, and their communications do not interfere with each other; The power master station sends an upgrade activation instruction to the distribution terminal through the management channel to start the remote upgrade process; The power master station divides the program file to be upgraded into multiple data segments and sequentially sends them to the distribution terminal through the management channel; The distribution terminal receives the multiple data segments and caches them. After all the data segments are received, the integrity of the upgrade file is verified. If the verification passes, the program update operation of the distribution terminal is started.

[0006] In a second aspect, some embodiments of the present application further provide an electronic device, which includes: One or more processors; and a memory storing computer program instructions, which when executed cause the processors to execute the remote upgrade method of the distribution terminal as described in any one of the above.

[0007] In a third aspect, some embodiments of the present application further provide a computer-readable storage medium, on which computer programs and / or instructions are stored, and when the computer programs and / or instructions are executed by a processor, the remote upgrade method of the distribution terminal as described in any one of the above is implemented.

[0008] In a fourth aspect, some embodiments of the present application further provide a computer program product, including computer programs and / or instructions, and when the computer programs / instructions are executed by a processor, the remote upgrade method of the distribution terminal as described in any one of the above is implemented.

[0009] Compared with the related art, in the solution provided by the embodiments of the present application, a dual-channel communication architecture with separation of the service channel and the management channel is adopted, which can effectively avoid occupying real-time communication resources during the upgrade process, prevent interference with four-remote services such as telemetry and tele-signaling, and thus ensure the real-time performance and stability of the operation of the distribution terminal system. During the upgrade process, the power master station sends an upgrade activation instruction through the management channel, and divides the program file to be upgraded into multiple data segments frame by frame, and transmits them to the distribution terminal in sequence, realizing the remote distribution and segmented transmission of the upgrade file, improving the overall transmission efficiency, and reducing the manual operation and maintenance cost. The distribution terminal performs integrity verification after receiving all the data segments, and only executes the program update operation on the premise that the verification passes, ensuring the correctness and transmission reliability of the upgrade file. This upgrade method realizes a high degree of automation and intelligence in the remote upgrade process of the distribution terminal, and is applicable to centralized upgrade management in large-scale distribution automation systems. Description of the Drawings

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.

[0011] Figure 1 It is a schematic flowchart of a remote upgrade method for a distribution terminal provided by an embodiment of the present application; Figure 2 It is a processing flow chart for a power distribution terminal provided by an embodiment of the present application to respectively monitor a service channel and a management channel; Figure 3 It is a timing diagram of the normal file transmission and integrity verification process provided by an embodiment of the present application; Figure 4 It is a timing diagram for data recovery transmission through a breakpoint resumption mechanism after an interruption occurs during the transmission process provided by an embodiment of the present application; Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific Embodiment

[0012] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.

[0013] First Embodiment The first embodiment of the present application relates to a method for remote upgrade of a power distribution terminal. Referring to Figure 1 as shown, the method may include the following steps: Step S1: The power master station respectively establishes communication connections for a service channel and a management channel with the power distribution terminal. Among them, the service channel is used to transmit high-priority real-time service data, and the management channel is used to transmit control instructions and data content of the upgrade file. The service channel and the management channel operate independently of each other, and their communications do not interfere with each other.

[0014] Regarding step S1, specifically, the power master station respectively establishes two independent communication connections with the power distribution terminal during the system initialization phase, namely the service channel and the management channel. The service channel is established based on the IEC 60870-5-104 communication protocol (standard 104 protocol), usually listens on port 2404, and is used to carry high-priority real-time service data such as telemetry, telecontrol, telecommand, and telesignalization, ensuring the continuity and timeliness of the main station's online monitoring, control, and operation status acquisition of the power distribution terminal. The management channel listens on port 2402 and communicates using the extended 104 communication protocol. It is mainly used for file transmission control in the remote upgrade process, including sending upgrade activation instructions, downloading program file data segments, performing version information interaction, and upgrade status confirmation.

[0015] The service channel and the management channel are physically and logically independent of each other, and their communication processes do not interfere with each other, enabling parallel processing of the upgrade operation while ensuring the uninterrupted real-time service communication.

[0016] Step S2: The power master station sends an upgrade activation instruction to the distribution terminal through the management channel to initiate the remote upgrade process.

[0017] Regarding Step S2, specifically, after successfully establishing the management channel connection, the power master station sends an upgrade activation instruction to the distribution terminal. This instruction belongs to the data frame of a specific function type defined in the 104 communication protocol. For example, a data frame with the function type of writing file activation is constructed, and this frame carries the necessary information for initializing the upgrade task (such as the function code TI = 210: representing function upgrade; the transmission reason code COT = 6: representing the master station activation upgrade request), establishing an upgrade task between the master station and the terminal, and triggering the distribution terminal to enter the remote upgrade preparation state.

[0018] After receiving this activation instruction, the distribution terminal will perform the following preprocessing operations: initialize the internal storage space for caching the upgrade file, reset the previous file reception status, and suspend non-critical service processing tasks unrelated to the upgrade to release the necessary processing resources and communication resources for the upgrade process. Subsequently, the distribution terminal returns an upgrade activation confirmation frame to the power master station, indicating that it has successfully entered the upgrade standby state. Only after receiving the confirmation can the master station initiate the subsequent file data segment transmission process.

[0019] Step S3: The power master station divides the program file to be upgraded into multiple data segments and sequentially sends them to the distribution terminal through the management channel.

[0020] Regarding Step S3, specifically, after receiving the upgrade activation confirmation from the distribution terminal, the power master station initiates the process of sending the program file. To meet the requirements of the communication protocol for the encrypted frame length limit and improve the transmission efficiency at the same time, the power master station divides the complete program file to be upgraded into several ordered data segments according to a preset single-frame message length threshold (such as 1.5 KB).

[0021] Each data segment generates a data segment transmission message, which can contain the following key fields: data segment content: representing the valid data part of this segment of the file; data offset field: used to identify the starting byte position of this segment of data in the complete program file, facilitating subsequent data recombination and breakpoint resumption by the terminal; simple check code: such as CRC value (cyclic redundancy check value), used to quickly check whether this segment of data is damaged during transmission.

[0022] The power master station sends the above data segments frame by frame to the distribution terminal through the management channel in the order of the data segments. After receiving each frame of data segment, the distribution terminal immediately performs field parsing and data verification, and returns a write file confirmation frame to the master station to feedback the reception status of the data segment and confirm whether the reception is successful. If the reception of a certain frame fails or the verification fails, the power master station can initiate a retransmission according to the content of the write file confirmation frame until the data segment is successfully written into the cache of the distribution terminal, ensuring the reliability and consistency of data transmission.

[0023] Step S4: The distribution terminal receives multiple data segments and caches them. After all the data segments are received, the integrity of the upgrade file is verified. If the verification passes, the program update operation of the distribution terminal is started.

[0024] Regarding step S4, specifically, after the distribution terminal successfully receives and caches all the upgrade data segments, it enters the integrity verification stage of the upgrade file. The power master station has sent the digest information of the target upgrade file to the distribution terminal during the upgrade initialization stage. This digest value can be calculated using the MD5 (Message Digest Algorithm) or SHA algorithm (Secure Hash Algorithm) and is used to uniquely identify the content integrity of the target file.

[0025] The distribution terminal will re-perform the hash calculation on the locally cached complete upgrade file and compare the locally calculated hash value with the digest information of the target upgrade file sent by the power master station.

[0026] If the comparison result is consistent, it indicates that the upgrade file has not been damaged or tampered with during the transmission process. The distribution terminal will immediately execute the program update process. The update process includes: writing the new version of the firmware into the running storage area, automatically restarting the terminal after the writing is completed, and loading the new program version to put it into operation.

[0027] If the comparison fails, it indicates that the file content does not match the master station's expectation, and there may be abnormal situations such as data loss, content tampering, or link interference. At this time, the distribution terminal will refuse to execute the upgrade operation and trigger any of the following error handling processes according to the preset policy: actively roll back to the stable program image of the previous version to ensure the continuity and security of the terminal operation; or return the verification failure status to the master station, and the master station decides whether to re-send the upgrade file or abort the upgrade task.

[0028] It is not difficult to find that, compared with the related technologies, in the solution provided by the embodiments of the present application, a dual-channel communication architecture with separate service channels and management channels is adopted, which can effectively avoid occupying real-time communication resources during the upgrade process, prevent interference with four-remote services such as telemetry and tele-signaling, and thus ensure the real-time performance and stability of the operation of the distribution terminal system. During the upgrade process, the power master station sends an upgrade activation command through the management channel, and divides the program file to be upgraded into multiple data segments frame by frame, and transmits them to the distribution terminal in sequence, realizing the remote distribution and segmented transmission of the upgrade file, improving the overall transmission efficiency, and reducing the manual operation and maintenance cost. After receiving all the data segments, the distribution terminal performs an integrity check, and only executes the program update operation on the premise that the check passes, ensuring the correctness and transmission reliability of the upgrade file. This upgrade method realizes a high degree of automation and intelligence in the remote upgrade process of the distribution terminal, and is applicable to centralized upgrade management in large-scale distribution automation systems.

[0029] Second Embodiment The second embodiment of the present application relates to a method for remotely upgrading a distribution terminal. The second embodiment is an improvement based on the first embodiment. The specific improvement lies in that: in the second embodiment of the present application, the management channel communicates based on the extended IEC 60870-5-104 communication protocol to improve the carrying capacity of a single-frame data during the transmission of large files and meet the requirements for high-efficiency transmission performance in remote upgrades. The extended IEC 60870-5-104 communication protocol includes: expanding the length field used to indicate the total length of the application protocol data unit in the standard IEC60870-5-104 communication protocol from 1 byte to 2 bytes to support the transmission of data content not exceeding 65,535 bytes per frame of message.

[0030] Specifically, on the basis of following the original protocol framework, the extended 104 communication protocol performs a field-level expansion on the length field in the structure of the application protocol data unit (APDU). In the standard 104 communication protocol, the length field of the APDU is 1 byte (8 bits), which can only indicate a maximum message length of 255 bytes, restricting the upper limit of the data that can be transmitted in a single frame. To break through this limitation, in the extended protocol, this length field is expanded from 1 byte to 2 bytes (16 bits), so that the theoretical maximum length of a single-frame message is increased to 65,535 bytes.

[0031] In the specific implementation process, the power master station can dynamically negotiate and set the transmission length of each data segment according to the encryption chip capability of the distribution terminal and the current network link stability. The recommended range is from 1024 bytes to 10,000 bytes. This length range can significantly reduce the number of communication frames while ensuring the encryption integrity of the message and the link reliability, shorten the file transmission time, and improve the transmission efficiency of the file during remote distribution.

[0032] It should be noted that the extended communication protocol is only used in the management channel to carry control instructions and file data transmission during the upgrade process; the service channel continues to follow the standard IEC 60870-5-104 communication protocol to handle data communication tasks such as real-time telemetry, telecontrol, and teleindication. The two do not affect each other, thus realizing the logical separation and protocol compatibility between the management channel and the real-time service channel.

[0033] Third Embodiment The third embodiment of the present application relates to a method for remotely upgrading a distribution terminal. The third embodiment is an improvement based on the first embodiment. The specific improvement lies in that in the third embodiment of the present application, a specific implementation manner of a dual-channel listening and encryption authentication mechanism is provided, that is, step S1 may further include the following steps: Step S101: After the distribution terminal is started, it acts as a server and listens to two physical ports simultaneously: port 2404 and port 2402. Port 2404 corresponds to the service channel based on the standard IEC 60870-5-104 communication protocol, and port 2402 corresponds to the management channel based on the extended IEC 60870-5-104 communication protocol; Step S102: When a connection request sent by the power master station is listened to on any one of the two physical ports, the distribution terminal determines whether the corresponding channel enables the encrypted communication mode; Step S103: If the channel enables the encrypted communication mode, first perform gateway encryption authentication, and complete the gateway-level identity verification and initial key exchange between the distribution terminal and the power master station; Step S104: After the gateway encryption authentication is successful, continue with the master station encryption authentication, establish a secure session between the distribution terminal and the power master station, and negotiate to generate the master station encryption random number and the terminal encryption random number; Step S105: After the master station encryption authentication is successful, the distribution terminal stores and binds the master station encryption random number and the terminal encryption random number to the communication sessions of the corresponding ports respectively; Step S106: If the channel does not enable the encrypted communication mode, the distribution terminal skips the encryption authentication process after establishing the connection and directly enters the service interaction stage defined by the corresponding communication protocol.

[0034] Specifically, referring to Figure 2As shown in the figure, after the power distribution terminal is powered on or restarted, it acts as a server and listens to two physical ports simultaneously: port 2404 and port 2402. Among them: port 2404 corresponds to the service channel, and uses the standard IEC 60870-5-104 communication protocol, which is mainly used for the transmission of real-time services with high priority, such as the transmission of four remote data including telemetry, tele-signaling, tele-control, and tele-adjustment; port 2402 corresponds to the management channel, and uses the extended IEC 60870-5-104 communication protocol, which is used for the transmission of non-real-time control data such as terminal upgrade packages and configuration files.

[0035] When the power distribution terminal monitors that a connection request from the power main station is received on either port (port 2404 or port 2402), the power distribution terminal first determines whether the channel is configured to enable the encrypted communication mode according to the pre-set communication parameters. If it is determined that the channel enables the encrypted communication mode, the power distribution terminal first initiates the gateway encryption authentication process. Gateway encryption authentication is the first line of defense for secure communication in the power distribution system, which is used to verify whether the communication parties are trusted devices. This process can be completed based on the pre-deployed symmetric or asymmetric key mechanism. Specifically, the power distribution terminal performs an identity handshake with the encryption device gateway of the power main station, and both parties exchange authentication request and response messages, and complete the negotiation or verification of the initial key, such as the SM1 (symmetric encryption algorithm) / SM2 (asymmetric encryption algorithm) mechanism or EB-level authentication (EB-level authentication is the power B-level authentication, which is one of the security authentication levels for communication between power system devices formulated by the State Grid Corporation of China, usually indicating higher-level two-way identity authentication and encrypted transmission requirements). If the authentication is successful, the terminal enters the next stage of the master station-level encryption negotiation process; if the authentication fails, the connection is refused and the current port communication session is terminated.

[0036] After the gateway encryption authentication is completed, the power distribution terminal continues to execute the master station encryption authentication process to establish the data encryption session key for this communication session. The power main station and the power distribution terminal negotiate and generate two groups of random numbers during the encryption handshake process, which are respectively: the master station encryption random number (used for the power main station to send encrypted data to the power distribution terminal); the terminal encryption random number (used for the power distribution terminal to send encrypted data to the power main station); after the authentication is completed, both parties establish a symmetric encryption communication session based on this random number for the encryption and decryption of subsequent data segment messages.

[0037] When the master station encryption authentication fails, the power distribution terminal will refuse to enter the encrypted session state, disconnect the current communication connection, will not continue the subsequent data encryption transmission, and will not save the master station random number and its related key parameters. For the convenience of subsequent problem troubleshooting or security auditing, the terminal can record the relevant information of the encryption authentication failure in the log and mark the failure reason, such as: authentication handshake timeout, key digest inconsistency, illegal random number format, unregistered master station identity, etc. It can also send this failure event to the dispatching system or remote platform through the platform reporting mechanism.

[0038] After the encryption authentication at the main station is completed, the power main station establishes connections with the distribution terminal through ports 2404 and 2402 respectively, forming two logically independent secure communication session environments. The distribution terminal persistently stores the random number information generated during the authentication process and binds it to the corresponding port to ensure that the encryption state corresponds to the physical channel and operates independently of each other. For example, the distribution terminal saves the encryption random number of power main station A and its own random number under port 2404 for the encryption of four remote services; it saves the encryption random number information of circuit main station B under port 2402 for the encryption of the file transfer channel. This can prevent the confusion of encryption states and support multiple channels to maintain different encryption states simultaneously.

[0039] For the large file transfer scenario, such as when the length of a single-frame message is relatively long (e.g., more than 1KB), the power main station uses the EB90 encryption header structure compliant with the "Definition of Secure Messages for State Grid Distribution Terminals" for data encryption. This structure reserves dedicated fields in the message header to identify the encryption algorithm flag bit, check identifier, key number, etc., and can be compatible with the security authentication mechanism while maximizing the data payload, achieving efficient encrypted transmission. For the short message communication scenario (such as control messages like write file confirmation frames, upgrade activation frames, etc.), the power main station enables the full-message encryption mechanism, that is, the entire application protocol data unit (APDU) is completely encapsulated and encrypted to ensure that critical control commands and task identification information are not intercepted or tampered with.

[0040] When it is determined in step S102 that the communication channel does not enable the encryption mode, the distribution terminal will skip the above encryption authentication process and directly enter the service interaction stage defined by the corresponding communication protocol after establishing a TCP connection with the power main station. For the connection of port 2404, the distribution terminal directly enters the standard four-remote service interaction process based on the IEC 60870-5-104 communication protocol to process commands such as telemetry, tele-signaling, remote control, and remote adjustment sent by the power main station; for the connection of port 2402, the terminal enters the file management and upgrade data interaction process based on the extended 104 communication protocol for processes such as file upgrade activation instructions, data segmented transmission, verification, and program update.

[0041] Furthermore, both the service channel and the management channel adopt the TCP long connection mechanism actively initiated by the power master station. After the connection is established, the service channel and the management channel respectively maintain continuous and stable connections with the distribution terminal, that is, both channels are long connection sessions, supporting the heartbeat mechanism and the abnormal reconnection mechanism to ensure that the communication link is not interrupted throughout the life cycle. Specifically, when the power master station successfully establishes a communication connection with the distribution terminal through the management channel and completes the encryption authentication process, if the software upgrade task is not triggered currently, the management channel will enter the idle maintenance state. To maintain the continuity of the connection and the activity of the channel, the power master station will send heartbeat frames to the distribution terminal at a preset frequency, and the terminal will return a response after receiving the heartbeat frame, so as to achieve periodic confirmation of the link. Among them, the sending frequency of the heartbeat frame is a configurable parameter, which can be flexibly set according to the system deployment environment, link bandwidth situation or master station policy, and is not specifically limited in this embodiment.

[0042] It is not difficult to find that in the embodiment of the present application, by introducing the dual-channel listening mechanism and the separate encryption authentication process in the distribution terminal, after each channel establishes a connection, it can respectively judge whether to enable encrypted communication according to the preset policy, and sequentially execute the gateway encryption authentication and the master station encryption authentication processes, and finally bind the encrypted random number and session information generated by the authentication to the corresponding ports respectively. The distribution terminal can perform independent security control on the service data communication based on the IEC 60870-5-104 communication protocol and the upgrade file transmission based on the extended 104 communication protocol respectively, realizing the complete decoupling of the service channel and the management channel in terms of communication path and security policy. This design not only improves the security and controllability of communication, but also enhances the adaptability of the system to the multi-channel and multi-task parallel scenarios, supports flexible execution of remote upgrade tasks on the premise of ensuring service real-time performance, thereby improving the overall operation efficiency, security level and deployment flexibility of the distribution terminal system.

[0043] It should be noted that the third embodiment of the present application can also be an improvement based on any one or more of the first embodiment to the second embodiment.

[0044] Fourth Embodiment The fourth embodiment of the present application relates to a method for remotely upgrading a distribution terminal. The fourth embodiment is an improvement based on the first embodiment. The specific improvement lies in: in the fourth embodiment of the present application, a specific implementation manner of segmented transmission and segment-by-segment confirmation is provided, that is, step S3 can further include the following steps: Step S301: The power master station segments the program file according to a preset threshold of the length of each frame message, forming multiple data segment messages. Each data segment message contains at least fields identifying the data segment number and the check code. Among them, the data segment content is used to carry the actual data fragment of the program file at the corresponding position, and the check code is used to verify the integrity of the data segment message; Step S302: The power master station sequentially sends each data segment message through the management channel. After receiving the data segment message, the distribution terminal immediately performs verification and returns a write file confirmation frame for each data segment message. The write file confirmation frame includes the corresponding data segment number and the reception status indicating success or failure; Step S303: If the distribution terminal feedbacks that the data segment message is received successfully, the power master station continues to send the next data segment message. If the distribution terminal feedbacks reception failure or there is no confirmation due to timeout, the power master station retransmits the current data segment message until it is successful or the retry count exceeds the limit.

[0045] Specifically, referring to Figure 3 As shown, it schematically shows the standard process for the power master station to send an upgrade file to the distribution terminal through the management channel, including four stages: write file activation, data segment transmission, transmission confirmation, and MD5 integrity verification. The specific process is as follows: Write file activation stage: The power master station sends a write file activation request message to the distribution terminal. The "type identifier TI = 210 (indicating a write file command), transmission reason code COT = 6 (indicating an activation request), and task number with operation identifier = 7" carried in the message. The operation identifier is an identifier in the protocol used to identify a certain interaction process or command category, such as the serial numbers of operation steps such as write file activation, data transmission request, and response frame confirmation. After receiving the instruction, the distribution terminal performs preprocessing, such as initializing the buffer area, and returns a write file activation confirmation message. The "TI = 210, COT = 7 (indicating agreement to the activation request), operation identifier = 8" carried in the message.

[0046] Data Segment Transmission Phase: After receiving the upgrade activation confirmation from the distribution terminal, the power master station first divides the program file to be upgraded into equal-length or on-demand segments according to the preset length of each frame message, generating several data segments. Each data segment is encapsulated into a frame of write file data segment message transmitted through the management channel. Each frame message contains at least the following key fields: data segment content and data check code. The data segment content field stores the actual data payload content of this segment, which is a byte sequence intercepted at the current offset position of the program file, usually with a fixed length or a variable length for the last segment. The data segment content can use segment numbers (such as segment 1, segment 2, segment 3...), indicating the relative position of this segment of data in the complete upgrade file, which is used for the distribution terminal to correctly cache and reconstruct the upgrade file structure, and can also be used as a basis for breakpoint resumption or retransmission positioning. The data check code field is used to verify the integrity of the current data segment content, and can be CRC16 (16-bit cyclic redundancy check), CRC32 (32-bit cyclic redundancy check) or simple checksum. After receiving the data, the terminal will perform a check on the data segment based on this field to determine whether to request a retransmission. It can also include a frame control field, containing control bits such as whether it is the last frame, whether an acknowledgment is required, and the retransmission flag. The message carries "TI = 210, COT = 5 (indicating writing of file data segment), operation identifier = 9".

[0047] Write File Acknowledgment Phase: The distribution terminal can use a single-frame acknowledgment mechanism to receive and acknowledge the data segments of the upgrade file sent by the power master station. Specifically, after the power master station sends a frame of data segment message to the distribution terminal, after the distribution terminal successfully receives and completes the structure parsing and integrity check of this data segment, it immediately returns a frame of write file acknowledgment message as an acknowledgment of the successful reception of this data segment. The message carries "TI = 210, COT = 5, operation identifier = 10".

[0048] The distribution terminal can also use a multi-frame acknowledgment mechanism to batch respond to the data segments sent by the power master station. That is, the master station can continuously send multiple data segment messages (such as n segments) without waiting for the acknowledgment feedback for each segment; after receiving n frames of data segments, the distribution terminal uniformly returns a frame of write file acknowledgment message to confirm the reception result of this batch of data. The message carries "TI = 210, COT = 5, operation identifier = 10". This mechanism has higher transmission efficiency compared to per-frame acknowledgment, can significantly reduce the number of message interactions, reduce the link load, and improve the continuous transmission ability of the master station, especially suitable for communication environments with relatively stable links or limited bandwidth. Preferably, n is a configurable parameter and can be dynamically set according to the master station's sending strategy, terminal load capacity or task type. For example, the terminal can preset the acknowledgment period to every 4 frames or every 8 frames in the configuration, flexibly balancing real-time performance and transmission efficiency.

[0049] If the write file confirmation frame returned by the distribution terminal indicates that the reception of this data segment fails (such as checksum failure, format error, etc.), or the power master station does not receive any confirmation response within the set confirmation waiting time (such as 10 seconds) (regarded as timeout without confirmation), then the power master station regards the transmission of this data segment as failed and immediately triggers the retransmission mechanism for the current data segment. Under the retransmission mechanism, the master station will reconstruct and send the failed data segment message again and wait for the distribution terminal to confirm again. The power master station can set the maximum retransmission times threshold (such as setting the timeout retransmission retry times from 1 to 3 times). If the retry times exceed this threshold and no successful confirmation is obtained yet, then the power master station can execute one of the following processing strategies: abort the current upgrade task and report the failure status; or roll back the transmitted data, notify the terminal to release the cache, or initiate an upgrade retry after renegotiating the transmission parameters.

[0050] Integrity verification phase: After the master station confirms that all data segments are sent, it sends an MD5 verification request message to the terminal. The "TI = 212, COT = 6" carried in this message requires the distribution terminal to perform a hash verification on the upgrade. The distribution terminal locally calculates the MD5 value of the upgrade file and compares it with the preset value of the power master station. If the verification is successful, the distribution terminal returns an integrity verification confirmation message, and the "TI = 212, COT = 7" carried in the message indicates that the data is complete and the upgrade can continue. If the verification fails, the power master station can retransmit some data segments or the entire upgrade file, or the terminal triggers a rollback mechanism.

[0051] It is not difficult to find that in the embodiments of the present application, by introducing a frame-by-frame transmission mechanism based on data segments, segment-by-segment confirmation, and retransmission control strategy during the remote upgrade process, the reliability of the upgrade file distribution and the fault tolerance of the system are effectively improved. At the same time, by setting up the reception confirmation and retransmission mechanism, the master station can initiate retransmission in time when the terminal fails to receive a certain data segment successfully, avoiding the interruption of the overall upgrade caused by a single point of failure. In addition, this mechanism also supports on-demand configuration as single-frame or multi-frame confirmation, taking into account both transmission efficiency and link stability, and is applicable to complex and changeable distribution communication network environments.

[0052] It should be noted that the fourth embodiment of the present application can also be an improvement based on any one or more of the first to third embodiments.

[0053] The fifth embodiment The fifth embodiment of the present application relates to a method for remote upgrade of a distribution terminal. The fifth embodiment is an improvement based on the first embodiment. The specific improvement lies in: In the fifth embodiment of the present application, a specific implementation manner of a breakpoint continuation mechanism based on data offset is provided, that is, step S3 can further include the following steps: During the data transmission process, after successfully receiving each data segment message, the distribution terminal extracts and records the corresponding data offset from the data segment message; When the file transfer is interrupted, the distribution terminal retains the data offset of the last successfully received data; After re - establishing the communication link, the distribution terminal sends the recorded data offset to the power master station through a write - file confirmation frame; After the power master station receives the write - file confirmation frame and confirms that it is consistent with the current task to be continued, it determines the breakpoint position according to the data offset, and continues to transmit the remaining untransmitted data - segment messages from the breakpoint position to achieve breakpoint - resumed transmission of the program file.

[0054] Specifically, referring to Figure 4 As shown, this figure schematically shows the complete process of how the power master station and the distribution terminal perform breakpoint - resumed transmission based on the data offset after a communication interruption occurs during the file transfer. The broken line in the figure indicates a link interruption during data transmission, and the power master station fails to receive subsequent confirmation frames. At this time, the distribution terminal does not empty the current buffer, but retains the data offset corresponding to the last received data segment as the breakpoint position of the current upgrade task. After re - establishing the communication link between the power master station and the distribution terminal, the master station resends a breakpoint - resumed - transmission activation message, which carries "TI = 210, COT = 6, operation identifier = 9". The distribution terminal responds to the breakpoint - resumed - transmission activation and sends a breakpoint - resumed - transmission activation confirmation message to the power master station, which carries "TI = 210, COT = 7, operation identifier = 10", and carries the previously retained data offset and the current upgrade task identifier in the confirmation frame to notify the power master station of the breakpoint position and resume transmission.

[0055] The power master station first performs a consistency check on the task identifier included in the confirmation frame to ensure that the current resumed - transmission operation belongs to the same previous upgrade task; if the task identifier is inconsistent with the current task context of the master station, the power master station can choose to abort the resumed transmission, re - activate the task, or request the terminal to realign the status. On the premise that the task identifiers are consistent, the power master station locates the starting position of the upgrade file that has not been completed for transmission according to the feedback data offset, and starts from this offset to reorganize and send the remaining data - segment messages. The organizational structure of each data segment is the same as that in the initial transmission stage, and is still sent frame by frame through the management channel, and the distribution terminal continues to execute the reception and confirmation process.

[0056] The above - mentioned resumed - transmission process will continue until the entire program file is transmitted, and it is confirmed that the upgrade file is successfully transmitted through the final integrity - check step, and then it enters the program - writing and version - upgrade stage.

[0057] It is not difficult to find that in the embodiments of the present application, a breakpoint resumption mechanism is introduced to handle the situation of file transmission interruption caused by communication interruption, link anomaly, system restart, etc. during the actual remote upgrade process. By recording the data offset at the distribution terminal side and transmitting this information back to the power main station after the link is restored, the power main station can locate the unfinished part according to the breakpoint information and continue to transmit the remaining file data from the interruption position, avoiding repeated transmission and upgrade interruption, and significantly improving the robustness and upgrade success rate of the system in an unstable network environment.

[0058] Furthermore, the power main station segments the program file according to a preset threshold of the length of each frame of message, forming multiple data segment messages. The following steps may also be included: In the initialization stage of the upgrade task, obtain the maximum encrypted message lengths supported by the encryption machine configured by the power main station and the encryption chip integrated with the distribution terminal respectively, and take the smaller value of the two as the threshold of the length of a single frame of message; Taking the threshold of the length of a single frame of message as the basis for data segmentation, divide the program file into multiple data segment messages in sequence from the starting byte according to the threshold of the length of a single frame of message. The length of each data segment message does not exceed the threshold of the length of a single frame of message, and a data offset field indicating the data offset compared to the starting position in the complete upgrade file is recorded in each data segment message.

[0059] Specifically, the power main station first obtains the maximum encrypted message length supported by its own configured encryption device (such as a national secret encryption machine), for example, 1.5 KB; at the same time, the main station also obtains the maximum decrypted message length supported by the encryption chip integrated with the target distribution terminal through the device registry, terminal capability query or negotiation method, for example, 2.0 KB. Determine the smaller value of the above two values as the threshold of the length of a single frame of message for this upgrade task (for example, take 1.5 KB), which serves as the upper limit of the length for subsequent upgrade file segmentation and message construction. The setting of this threshold ensures that during the transmission of each frame of data segment message through the secure link, transmission failure, data loss or decryption error will not occur due to exceeding the encryption capacity.

[0060] Based on this message length threshold, the main station starts from the starting byte of the upgrade program file and sequentially divides the file content into multiple data segment messages. The actual length of each data segment does not exceed this threshold, forming several independent upgrade data frames, which are convenient for being sent to the terminal frame by frame through the management channel. In each data segment message, the main station also embeds a data offset field (such as an offset value in bytes), which is used to indicate the starting position of the current data segment in the complete upgrade file and is used to identify the resumption starting point during breakpoint resumption after a communication anomaly occurs. It can also be used to guide data segment sorting and integrity verification during file caching and reconstruction on the terminal side.

[0061] It should be noted that the fifth embodiment of this application can also be an improvement based on any one or more of the first to fourth embodiments.

[0062] Sixth Embodiment The sixth embodiment of this application relates to a method for remote upgrade of a distribution terminal. The sixth embodiment is an improvement based on the first embodiment. The specific improvement lies in: in the sixth embodiment of this application, a specific implementation manner of an upgrade file integrity verification and security rollback strategy is provided, that is, in step S4, the integrity verification of the upgrade file can further include the following steps: After all data segments of the upgrade file are transmitted, the power master station sends a verification instruction containing the digest information of the target upgrade file to the distribution terminal. The digest information is the hash verification value generated on the power master station side for the upgrade file; After receiving the complete upgrade file, the distribution terminal performs local hash calculation and compares the calculation result with the hash verification value sent by the power master station. If the comparison is consistent, it is regarded that the file integrity verification is passed. The distribution terminal then performs program writing and version replacement operations and completes an automatic restart to load the new version program; If the comparison fails, it is regarded that there is an error in the file transmission. The distribution terminal refuses to execute the program update operation and triggers at least one of the following processing flows: actively roll back to the stable version program before the upgrade to resume operation; or feedback the verification failure status to the power master station, and the power master station re-initiates the upgrade file transmission process.

[0063] Specifically, when the distribution terminal completes the reception operation of all upgrade data segments, the power master station actively sends a verification request instruction to the terminal. This instruction contains the digest information of the corresponding upgrade file, such as the file hash value generated by using MD5, SHA-256 or other hash algorithms, which is used to represent the original integrity characteristics of the file recorded on the master station side. After the distribution terminal reorganizes the upgrade file in the buffer area, it immediately performs local hash calculation to generate the hash value of the actually received complete file.

[0064] Subsequently, the terminal compares this locally calculated value bit by bit with the target hash value sent by the master station. If the hash values are the same, it means that no tampering or data loss occurred during the file transmission process, and the file integrity verification is passed, and the next program update process can be entered; if the hash values are different, it indicates that there may be anomalies such as packet loss, tampering, and incorrect overwriting during the data reception process, resulting in unreliable file content. This integrity verification fails, and the upgrade process is automatically aborted and transferred to the failure response process.

[0065] When the verification passes, the distribution terminal executes the program writing process, burns the new version program file to the running storage area, and automatically completes the restart operation to load the new version firmware and enter the normal working state; when the verification fails, the distribution terminal refuses to execute the program update operation and triggers at least one of the following processing methods: Active rollback mechanism: The terminal loads the stable version program before the upgrade from the internal backup area or the reserved area, and resets the boot flag to ensure that the terminal can still recover to a runnable state without completing the security upgrade, ensuring that the power distribution function is not affected. Failure reporting mechanism: The distribution terminal sends an upgrade failure status frame or a feedback message with an error code to the power main station through the management channel, informing the power main station of the reason and status of the upgrade failure. The power main station can judge whether to restart the complete upgrade process based on this, or locate the error data segment based on the breakpoint information and re-transmit it.

[0066] It is not difficult to find that in the embodiments of the present application, by introducing an integrity verification mechanism based on hash digest in the remote upgrade process and combining the automatic processing strategies for upgrade success and failure, the data security and system stability of the distribution terminal during the program version update process are significantly improved. On the one hand, by means of the master station sending the hash verification value and the terminal recalculating and comparing locally, the integrity of the file is guaranteed from the source; on the other hand, when the verification fails, the terminal can automatically trigger the version rollback mechanism, restore to the stable program before the upgrade, or send the failure status back to the master station to support subsequent differential retransmission, ensuring that the system has good self-recovery ability and remote diagnosis ability.

[0067] The step division of the above various methods is only for clear description. When implementing, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, they are all within the protection scope of the present application; adding insignificant modifications or introducing insignificant designs to the algorithm or process, but not changing the core design of its algorithm and process are all within the protection scope of this application.

[0068] In addition, some embodiments of the present application also provide an electronic device. The electronic device can be various forms of digital computers, such as, laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and so on. The electronic device can also be various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices and other similar computing devices.

[0069] The electronic device includes: one or more processors; and a memory storing computer program instructions, which when executed cause the processors to execute a method for remote upgrade of a distribution terminal provided by any one or more of the above embodiments. Figure 5An exemplary structural diagram of the electronic device is disclosed. The electronic device includes: one or more processors 1101, a memory 1102, and interfaces for connecting the components, including a high-speed interface and a low-speed interface. Each component is interconnected using different buses and can be mounted on a common motherboard or otherwise installed as required. The processor can process instructions executed within the electronic device, including instructions stored in the memory or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some other embodiments, multiple processors and / or multiple buses can be used in conjunction with multiple memories if needed. Similarly, multiple electronic devices can be connected, with each device providing part of the necessary operations. Herein, the components shown, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described herein and / or claimed.

[0070] The electronic device may further include: an input device 1103 and an output device 1104. The processor 1101, the memory 1102, the input device 1103, and the output device 1104 can be connected via a bus or other means. Figure 5 Taking connection via a bus as an example.

[0071] The input device 1103 can receive input digital or character information and generate key signal inputs related to the user settings and function controls of the electronic device, such as input devices like a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 1104 can include a display device, an auxiliary lighting device (such as an LED), and a haptic feedback device (such as a vibration motor), etc. The display device can include, but is not limited to, a liquid crystal display, a light-emitting diode display, and a plasma display. In some embodiments, the display device can be a touch screen.

[0072] To provide interaction with the user, the electronic device can be a computer. The computer has: a display device for displaying information to the user (such as a cathode ray tube or an LCD monitor); and a keyboard and a pointing device (such as a mouse), through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (such as visual feedback, auditory feedback); and input from the user can be received in any form (such as voice input or tactile input).

[0073] In the embodiments of the present application, a computer program / instructions is stored on a computer-readable medium. When the computer program / instructions is executed by a processor, it implements a remote upgrade method for a power distribution terminal provided in any one or more of the above embodiments. The computer-readable medium may be included in the electronic device described in the above embodiments; or it may exist separately without being assembled into the device. The above computer-readable medium carries one or more computer-readable instructions.

[0074] The memory 1102 can be used as a non-transitory computer-readable storage medium, and can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules. By running the non-transitory software programs, instructions, and modules stored in the memory 1102, the processor 1101 executes various functional applications and data processing of the server, so as to implement the program instructions / modules corresponding to the methods provided in any one or more of the above embodiments of the present application.

[0075] The memory 1102 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 1102 may include a high-speed random access memory, and may also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory 1102 may optionally include a memory remotely provided with respect to the processor 1101, and these remote memories may be connected to the electronic device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0076] It should be noted that the computer-readable medium described in the present application may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable medium may be, for example, but not limited to: an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.

[0077] A computer-readable medium includes both permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory, static random access memory, dynamic random access memory, other types of random access memory, read-only memory, electrically erasable programmable read-only memory, flash memory or other memory technologies, compact disc read-only memory, digital versatile disc or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0078] Computer program code for performing the operations of the present application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as C or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network or a wide area network, or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0079] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. For example, a dedicated integrated circuit, a general-purpose computer, or any other similar hardware device can be used. In some embodiments, the software program of the present application can be executed by a processor to implement the above steps or functions. Similarly, the software program of the present application (including related data structures) can be stored in a computer-readable recording medium, such as a RAM memory, a magnetic or optical drive, or a floppy disk and similar devices. Additionally, some steps or functions of the present application can be implemented by hardware, for example, as a circuit that cooperates with a processor to execute each step or function.

[0080] The computer program product provided by the embodiments of the present application includes one or more computer programs / instructions. When the computer programs / instructions are executed by a processor, they wholly or partly generate the processes or functions described in the embodiments of the present application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, a computer, a server, or a data center to another website, a computer, a server, or a data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive), etc.

[0081] The flowcharts or block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0082] The scope of the present application is defined by the appended claims rather than the above description. Therefore, all changes that fall within the meaning and scope of the equivalent elements of the claims are intended to be included in the present application. Any reference signs in the claims should not be construed as limiting the claims concerned. In addition, it is obvious that the word "including" does not exclude other units or steps, and the singular does not exclude the plural. The multiple units or devices stated in the apparatus claims may also be implemented by one unit or device through software or hardware. The words "first", "second", etc. are only used for descriptive distinction and do not represent any specific order, nor can they be understood as indicating or implying relative importance.

[0083] As described above, these are only specific embodiments of the present application. However, the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily make changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims, and the above embodiments should be regarded as exemplary and non-limiting.

Claims

1. A method for remote upgrade of a distribution terminal, characterized in that, Including: The power master station respectively establishes communication connections for a service channel and a management channel with the distribution terminal. Among them, the service channel is used to transmit high-priority real-time service data, and the management channel is used to transmit control instructions and data content of the upgrade file. The service channel and the management channel operate independently of each other, and their communications do not interfere with each other. The power master station sends an upgrade activation instruction to the distribution terminal through the management channel to initiate the remote upgrade process. The power master station divides the program file to be upgraded into multiple data segments and sequentially sends them to the distribution terminal through the management channel. The distribution terminal receives the multiple data segments and caches them. After all the data segments are received, it performs an integrity check on the upgrade file. If the check passes, it initiates the program update operation of the distribution terminal.

2. The remote upgrade method for a power distribution terminal according to claim 1, wherein The management channel communicates based on the extended IEC 60870-5-104 communication protocol. The extended IEC 60870-5-104 communication protocol includes: expanding the length field used to indicate the total length of the application protocol data unit in the standard IEC 60870-5-104 communication protocol from 1 byte to 2 bytes to support transmitting data content of no more than 65,535 bytes per frame of message.

3. The remote upgrade method for a power distribution terminal according to claim 1 or 2, characterized in that The steps for the power master station to respectively establish communication connections for the service channel and the management channel with the distribution terminal include: After starting up, the distribution terminal acts as a server and listens to two physical ports simultaneously: port 2404 and port 2402. Port 2404 corresponds to the service channel based on the standard IEC 60870-5-104 communication protocol, and port 2402 corresponds to the management channel based on the extended IEC 60870-5-104 communication protocol. When a connection request sent by the power master station is detected by either of the two physical ports, the distribution terminal determines whether the corresponding channel enables the encrypted communication mode. If the channel enables the encrypted communication mode, first, gateway encryption authentication is performed, and the gateway-level identity verification and initial key exchange are completed between the distribution terminal and the power master station. After the gateway encryption authentication is successful, the master station encryption authentication continues. The distribution terminal and the power master station establish a secure session and negotiate to generate the master station encryption random number and the terminal encryption random number. After the master station encryption authentication is successful, the distribution terminal stores and binds the master station encryption random number and the terminal encryption random number to the communication sessions of the corresponding ports respectively. If the channel does not enable the encrypted communication mode, the distribution terminal skips the encryption authentication process after establishing the connection and directly enters the service interaction stage defined by the corresponding communication protocol.

4. The remote upgrade method for a power distribution terminal according to claim 1, wherein The steps for the power master station to divide the program file to be upgraded into multiple data segments and sequentially send them to the distribution terminal through the management channel include: The power master station segments the program file according to a preset threshold of the length of each frame of message to form multiple data segment messages. Each data segment message contains at least fields for the data segment content and the check code. Among them, the data segment content is used to carry the actual data segment of the program file at the corresponding position, and the check code is used to verify the integrity of the data segment message. The power master station sequentially sends each data segment message through the management channel. After receiving the data segment message, the distribution terminal immediately performs verification and returns a write file confirmation frame for each data segment message. The write file confirmation frame includes the corresponding data segment number and a reception status indicating success or failure of reception. If the distribution terminal feeds back that the data segment message is received successfully, the power master station continues to send the next data segment message. If the distribution terminal feeds back reception failure or there is no confirmation due to timeout, the power master station retransmits the current data segment message until it is successful or the retry count exceeds the limit.

5. The remote upgrade method for a power distribution terminal according to claim 4, wherein Each data segment message also contains a field identifying the data offset. The step of the power master station dividing the program file to be upgraded into multiple data segments and sequentially sending them to the distribution terminal through the management channel further includes: During the data transmission process, after successfully receiving each data segment message, the distribution terminal extracts and records the corresponding data offset from the data segment message. When the file transmission is interrupted, the distribution terminal retains the data offset of the last successfully received data. After re - establishing the communication link, the distribution terminal sends the recorded data offset to the power master station through the write file confirmation frame. After receiving the write file confirmation frame and confirming that it is consistent with the current task to be continued, the power master station determines the breakpoint position according to the data offset and continues to transmit the remaining untransmitted data segment messages from the breakpoint position to achieve breakpoint - continued transmission of the program file.

6. The remote upgrade method for a power distribution terminal according to claim 4, characterized in that, The step of the power master station segmenting the program file according to a preset per - frame message length threshold to form multiple data segment messages includes: In the initialization stage of the upgrade task, obtain the maximum encrypted message lengths supported by the encryption machine configured by the power master station and the encryption chip integrated in the distribution terminal respectively, and take the minimum of the two as the per - frame message length threshold. Taking the per - frame message length threshold as the basis for data segmentation, divide the program file into multiple data segment messages in sequence from the starting byte according to the per - frame message length threshold. The length of each data segment message does not exceed the per - frame message length threshold, and a data offset field indicating the position in the complete upgrade file relative to the starting position is recorded in each data segment message.

7. The remote upgrade method for a power distribution terminal according to claim 1, characterized in that, The step of performing integrity verification on the upgrade file includes: After all data segments of the upgrade file are transmitted, the power master station sends a verification instruction containing the digest information of the target upgrade file to the distribution terminal. The digest information is the hash check value generated on the power master station side for the upgrade file. After receiving the complete upgrade file, the distribution terminal performs local hash calculation and compares the calculation result with the hash check value sent by the power master station. If the comparison is consistent, it is considered that the file integrity verification passes. The distribution terminal then performs the program writing and version replacement operations and completes an automatic restart to load the new version program. If the comparison fails, it is considered that there is an error in the file transmission. The distribution terminal refuses to execute the program update operation and triggers at least one of the following processing flows: actively roll back to the stable version program before the upgrade to resume operation; or feedback the verification failure status to the power master station, and the power master station re - initiates the upgrade file transmission process.

8. An electronic device, characterized in that, The electronic device includes: One or more processors; and a memory storing computer program instructions that, when executed, cause the processors to perform the remote upgrade method for a power distribution terminal according to any one of claims 1-7.

9. A computer-readable storage medium having a computer program and / or instructions stored thereon, characterized in that, When the computer program and / or instructions are executed by a processor, the remote upgrade method for a power distribution terminal according to any one of claims 1-7 is implemented.

10. A computer program product, comprising a computer program and / or instructions, characterized in that, When the computer program and / or instructions are executed by a processor, the remote upgrade method for a power distribution terminal according to any one of claims 1-7 is implemented.

Citation Information

Patent Citations

  • Method and system for remotely upgrading optical network unit

    CN102064955A

  • Upgrading method of digital television system

    CN111176693A

  • Method for remotely upgrading ba by using unvarnished transmission channel

    CN118151966A

  • Remote OTA upgrading method and system

    CN119814557A

Cited By

  • OTA upgrading method, system and equipment integrating terminal and electric energy meter and medium

    CN121013073A

  • Electric energy meter firmware security upgrading method and system

    CN122132064A