A network energy equipment security vulnerability isolation monitoring device

By introducing a security vulnerability isolation and monitoring device into the network energy equipment, the problem of information transmission vulnerabilities in the equipment's backend was solved, and encrypted data transmission and authentication between the equipment and the monitoring center were realized, ensuring the security and stability of the network energy equipment.

CN114967564BActive Publication Date: 2026-04-24YUNZHENG TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
YUNZHENG TECH CO LTD
Filing Date
2022-05-07
Publication Date
2026-04-24

Smart Images

  • Figure CN114967564B_ABST
    Figure CN114967564B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of energy equipment security vulnerability isolation monitoring, and discloses a network energy equipment security vulnerability isolation monitoring device, wherein the network energy equipment is used for power supply of important load and is also a monitored device; the RS232 communication interface is a communication interface of the monitored device and is connected with the RS232 communication line; the RS232 communication line is used for connecting the monitored device and the security vulnerability isolation monitoring device, so that mutual data transmission is realized between the two; the security vulnerability isolation monitoring device is a data interaction management and control device of the monitored network energy equipment and the customer's management center device, any action instruction issued by the monitoring management center is confirmed by the device and the administrator and then is issued to the monitored device; the management center is a data monitoring management of the client and is responsible for receiving data of the monitored device and issuing relevant operation instructions, and the present application solves the problem of malicious attack on the network energy equipment by intruders through the external network, causing a safety accident.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of energy equipment security vulnerability isolation and monitoring technology, and particularly relates to a network energy equipment security vulnerability isolation and monitoring device. Background Technology

[0002] Currently, with the rapid development of communication technology, various network energy equipment products are equipped with data communication interfaces, enabling them to upload device data to the user's monitoring and management center, and also receive some operation commands issued by the monitoring and management center. Traditional network energy product monitoring methods on the market generally use RS485 and RS232 communication interfaces to directly upload internal parameter information to the user's monitoring center, or add an SNMP network interface monitoring card or a network SMS alarm to achieve remote network management and monitoring.

[0003] Due to advancements in communication technology and the Internet of Things (IoT), as well as the need for monitoring and managing product security, most network energy equipment products now upload their operational information to the customer's monitoring platform via communication interfaces. This allows customers to quickly and easily understand the equipment's status anytime, anywhere. However, many energy equipment products, including those from leading international brands, currently suffer from vulnerabilities in their backend data transmission. These software vulnerabilities allow malicious actors to attack energy equipment, potentially leading to data loss and economic damage, or even power outages and loss of life. Therefore, the security and stability of the equipment's backend transmission are crucial for customers; exploiting vulnerabilities can result in incalculable losses.

[0004] Based on the above analysis, the problems and shortcomings of the existing technology are as follows:

[0005] The software vulnerability in the backend information transmission of existing methods allows some criminals to attack energy equipment, which may result in data loss and economic losses, or even power outages and endanger personnel's lives. Summary of the Invention

[0006] To address the problems existing in the prior art, this invention provides a network energy equipment security vulnerability isolation and monitoring device.

[0007] This invention is implemented as follows: a network energy device security vulnerability isolation and monitoring device, the network energy device security vulnerability isolation and monitoring device comprising:

[0008] Network power equipment is used to supply power to important loads and is also a monitored device, connected to an RS232 communication interface;

[0009] The RS232 communication interface is the communication interface of the monitored device and is connected to the RS232 communication line;

[0010] The RS232 communication line is used to connect the monitored device and the security vulnerability isolation monitoring device, enabling data transmission between the two.

[0011] The security vulnerability isolation and monitoring device is a data interaction control device between the monitored network energy equipment and the customer's management center equipment. Any action instructions issued by the monitoring management center are confirmed with the administrator through this device before being sent to the monitored equipment.

[0012] The management center is used for data monitoring and management of the client, and is responsible for receiving data from the monitored devices and issuing relevant operation instructions.

[0013] Furthermore, the left end of the security vulnerability isolation and monitoring device is connected to an RS232 communication line, and the right end is connected to the management center.

[0014] Furthermore, the network energy equipment security vulnerability isolation and monitoring device is installed on the communication trunk line between the monitored device and the monitoring center, and all information uploaded and received by the monitored network energy equipment is filtered by the security vulnerability isolation and monitoring device.

[0015] Furthermore, the device can select the information to upload when uploading information.

[0016] Furthermore, all action commands issued by the monitoring center to the monitored devices are intercepted, and the security vulnerability isolation monitoring device will issue passwords and verification codes to administrators with relevant permissions.

[0017] Furthermore, only when the security vulnerability isolation and monitoring device receives the correct password and verification code can the instructions issued by the monitoring center be effectively transmitted to the communication backend of the monitored network energy equipment to execute the relevant instructions.

[0018] Furthermore, the communication between the network energy equipment and the host computer software is encrypted, eliminating plaintext transmission.

[0019] Furthermore, the monitoring device was designed and developed with the addition of an encryption chip and encryption algorithm.

[0020] Furthermore, the operation of external control using host computer software also requires security verification.

[0021] Furthermore, only after the security verification is passed will the host computer issue control commands to the network energy device to avoid illegal operation or human error.

[0022] Combining all the above technical solutions, the advantages and positive effects of this invention are as follows: This invention acts on the communication between network energy products and the external network monitoring and management center, and is an added monitoring and communication protection device to improve network security and make up for security vulnerabilities. The network equipment is not damaged by malicious attacks from the outside world, thereby effectively protecting the power and information security of user equipment, enhancing the security of data transmission and protecting the security of data transmitted by the equipment, and avoiding the problem of intruders maliciously attacking network energy equipment through the external network and causing security accidents.

[0023] The security of network information is of paramount importance today. This invention can effectively prevent criminals from exploiting vulnerabilities in the monitoring software of devices to compromise the security of network energy equipment. By adding a network communication control box to the communication trunk loop, reliable information upload and download instructions are screened and verified. The original plaintext transmission of information is eliminated, and any operation instructions sent to the monitored device require the corresponding administrator's identity verification. Only after verification will the instruction be sent to the monitored device. This adds an extra verification facility to the monitored network trunk, making the information more secure and reliable. Attached Figure Description

[0024] Figure 1 This is a schematic diagram of the network energy equipment security vulnerability isolation and monitoring device provided in an embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram of the network energy equipment security vulnerability isolation and monitoring device provided in an embodiment of the present invention;

[0026] Figure 3 This is a schematic diagram of the workflow of the network energy equipment security vulnerability isolation and monitoring device provided in this embodiment of the invention;

[0027] Figure 4 This is a schematic diagram of the encryption implementation provided in an embodiment of the present invention;

[0028] Figure 5 The principle of AES-CCM provided in this embodiment of the invention is shown in the figure;

[0029] Figure 6 This is a schematic diagram of the encryption chip parameter protection scheme provided in an embodiment of the present invention. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0031] To address the problems existing in the prior art, the present invention provides a network energy equipment security vulnerability isolation and monitoring device. The present invention will be described in detail below with reference to the accompanying drawings.

[0032] Main plan and effect description section:

[0033] like Figure 1 As shown, a network energy device security vulnerability isolation and monitoring device includes:

[0034] Network power equipment is used to supply power to important loads and is also a monitored device, connected to an RS232 communication interface;

[0035] The RS232 communication interface is the communication interface of the monitored device and is connected to the RS232 communication line;

[0036] The RS232 communication line is used to connect the monitored device and the security vulnerability isolation monitoring device, enabling data transmission between the two.

[0037] The security vulnerability isolation and monitoring device is a data interaction control device between the monitored network energy equipment and the customer's management center equipment. Any action instructions issued by the monitoring management center are confirmed with the administrator through this device before being sent to the monitored equipment.

[0038] The management center is used for data monitoring and management of the client, and is responsible for receiving data from the monitored devices and issuing relevant operation instructions.

[0039] The security vulnerability isolation and monitoring device is connected to the RS232 communication line on the left and to the management center on the right.

[0040] like Figure 2 As shown, the network power device is the power supply for this device. It also receives data and instructions from the security vulnerability isolation and monitoring device and the management center through the RS232 communication interface. The security vulnerability isolation and monitoring device requires verification of password and verification code. Data transmission between devices is only allowed when the verification is correct.

[0041] like Figure 3 As shown, when uploading information, the device can choose to upload necessary information. All action commands issued by the monitoring center to the monitored device are intercepted. The security vulnerability isolation monitoring device will issue a password and verification code to the administrator with the relevant permissions. When the security vulnerability isolation monitoring device receives the correct password and verification code, the commands issued by the monitoring center can be effectively transmitted to the communication backend of the monitored network energy equipment to execute the relevant commands.

[0042] Working principle: The network power device is the power supply for this device. It also receives data and instructions from the security vulnerability isolation and monitoring device and the management center through the RS232 communication interface. The security vulnerability isolation and monitoring device requires password and verification code verification. Data transmission between devices is only allowed when the verification is correct.

[0043] 1. This monitoring module adopts the following architecture to implement its functions.

[0044] (1) Connect using a standard Internet of Things architecture.

[0045] (2) Encrypt at end A and decrypt at end B. Establish a key on the terminal and then encrypt the data.

[0046] (3) The platform software uses a dongle and encryption algorithm for encryption.

[0047] (4) The hardware uses chip-level encryption and communication method.

[0048] (5) After encryption, important operations and instructions must be confirmed manually.

[0049] 2. Encryption Implementation

[0050] Data encryption refers to converting plaintext into ciphertext using encryption algorithms and encryption keys, while decryption uses decryption algorithms and decryption keys to restore ciphertext to plaintext. Encryption remains one of the most reliable methods for protecting information in computer systems. It uses cryptographic techniques to encrypt information, achieving information concealment and thus protecting information security.

[0051] This invention employs an AES-CCM-based encryption algorithm and an embedded system device encryption technology solution. The AES-CCM encryption process consists of four different processing stages: byte substitution, row shifting, column obfuscation, and round key addition. After 10 rounds of the above processing on the input data array `state`, the encrypted ciphertext is obtained.

[0052] The principle of AES-CCM is as follows: Figure 5 .

[0053] The AES-CCM algorithm architecture is as follows: The algorithm module is developed based on a domestically produced embedded chip development board and the Lingke platform, using general-purpose C library functions, which can be easily ported to various embedded products requiring secure encryption processing. The program provides two interfaces: the AES algorithm interface and the AES-CCM algorithm interface. The former can be used for encrypting the transmitted encryption key TEK, and the latter can be used for encrypting the transmitted data, implemented by calling encryption functions, as shown in the figure below. PDU stands for Protocol Data Unit.

[0054] The implementation process of the AES-CCM algorithm is as follows:

[0055] The CCM encryption module flowchart is shown below. The module takes a key K and plaintext P as input. When calculating MAC T and the counting block S, it calls the AES encryption program.

[0056] Design and implementation of encryption application methods:

[0057] The application method of the algorithm module is mainly designed based on the correspondence between TEK (Transmission Encryption Key) and CID (Connection Identifier). In the 802.16 protocol, each CID corresponds to a unique key resource, so the corresponding key can be found based on the CID. Two tables are created in the system: a TEK table to store encryption keys and a CID table to store CID values ​​and corresponding key indices. The record structure in the CID table is as follows: The Type field indicates the encryption method used, 0 for DES-CBC (Data Encryption Standard, Block Encryption Algorithm), and 1 for AES-CCM; the Key index field value indicates the key information corresponding to the CID identifier and its index position in the TEK table; the CID field represents the CID identifier value.

[0058] Sending end algorithm module call process: Before sending data, the system checks the value of the encryption control bit in the header. If it is 1, it means that the PDU needs to be encrypted. Then, according to the key index number and encryption mode selection bit in the header, a specific encryption algorithm and key are selected to encrypt the data. For example, if the encryption method is AES-CCM, the CCM encryption module is called to encrypt the data.

[0059] The receiving end algorithm module call flow is as follows: When a PDU data is received, the system first checks whether the CID flag value in the header exists in the local CID table. If it does not exist, the PDU is discarded; if it exists, the corresponding CID record is found, the values ​​of Type and Keyindex are read from it, the decryption key is read from the TEK table according to the Key index value, and then the CCM decryption module is called to decrypt the PDU.

[0060] like Figure 6 As shown in the diagram, the implementation logic of the parameter protection scheme is as follows. Users can migrate some key parameters from the MCU to the encryption chip for storage. In actual operation, the MCU sends a parameter readback command and a random number to the encryption chip, which also generates a set of random numbers. Using these two sets of random numbers as input data, and combining them with a preset key, the pre-stored key parameters are encrypted to generate ciphertext. The ciphertext parameters and the random numbers generated by the encryption chip are then sent back to the MCU. At this point, the MCU uses a preset decryption key to decrypt the ciphertext parameters, restoring the key parameter M, and uses M as input data for further program execution.

[0061] Because the encryption chip stores critical data from the MCU, it becomes part of the product. Attacking the MCU alone cannot obtain complete parameters, but the missing critical parameters are stored in the encryption chip, which can effectively prevent cracking and thus provide effective protection.

[0062] In the description of this invention, unless otherwise stated, "a plurality of" means two or more; the terms "upper," "lower," "left," "right," "inner," "outer," "front end," "rear end," "head," "tail," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0063] It should be noted that embodiments of the present invention can be implemented in hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the above-described devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuitry such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., or by software executed by various types of processors, or by a combination of the above-described hardware circuitry and software, such as firmware.

[0064] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions, and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention, and within the spirit and principles of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A network energy equipment security vulnerability isolation and monitoring device, characterized in that, The network energy equipment security vulnerability isolation and monitoring device includes: Network power equipment is used to supply power to important loads and is also a monitored device, connected to an RS232 communication interface; The RS232 communication interface is the communication interface of the monitored device and is connected to the RS232 communication line; The RS232 communication line is used to connect the monitored device and the security vulnerability isolation monitoring device, enabling data transmission between the two. The security vulnerability isolation and monitoring device is a data interaction control device between the monitored network energy equipment and the customer's management center equipment. Any action instructions issued by the monitoring management center are confirmed with the administrator through this device before being sent to the monitored equipment. The management center is used for data monitoring and management of the client, and is responsible for receiving data from the monitored devices and issuing relevant operation instructions. The security vulnerability isolation and monitoring device is connected to the RS232 communication line on the left and to the management center on the right. The network energy equipment security vulnerability isolation and monitoring device is installed on the communication trunk line between the monitored equipment and the management center. All information uploaded and received by the monitored network energy equipment is filtered by the security vulnerability isolation and monitoring device. The monitored device can select the information to upload when uploading information; Action commands issued by the management center to the monitored devices are all intercepted. The security vulnerability isolation monitoring device will issue passwords and verification codes to administrators with relevant permissions.

2. The network energy equipment security vulnerability isolation and monitoring device as described in claim 1, characterized in that, Only when the security vulnerability isolation and monitoring device receives the correct password and verification code can the instructions issued by the management center be effectively transmitted to the communication backend of the monitored network energy equipment to execute the relevant instructions.

3. The network energy equipment security vulnerability isolation and monitoring device as described in claim 1, characterized in that, Encrypt the communication between the network energy equipment and the host computer software, and eliminate plaintext transmission.

4. The network energy equipment security vulnerability isolation and monitoring device as described in claim 1, characterized in that, The monitoring device incorporates an encryption chip and encryption algorithm during its development and design.

5. The network energy equipment security vulnerability isolation and monitoring device as described in claim 1, characterized in that, Operations controlled externally using host computer software also require security verification.

6. The network energy equipment security vulnerability isolation and monitoring device as described in claim 5, characterized in that, Only after the security verification is passed can the host computer issue control commands to the network energy device to avoid illegal operation or human error.

Citation Information

Patent Citations

  • Intelligent power distribution network and power-consumption real-time monitoring and managing system

    CN101826755A