Method, device and storage medium for accessing an Internet of Things power distribution terminal without configuration

By realizing configuration-free access to power distribution terminals in the Internet of Things platform, and using the comparison of digital certificate feature information, the problems of large operation and maintenance workload and low access efficiency in the existing technology are solved, and fast identification and multi-node expansion are achieved.

CN115484283BActive Publication Date: 2025-08-05ZHUHAI XUJIZHI ELECTRIFIED WIRE NETING AUTOMATIONCO +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211026691.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-25
Publication Date
2025-08-05
Estimated Expiration
2042-08-25

AI Technical Summary

Technical Problem

In the prior art, configuration information is added separately for each smart terminal, resulting in large operation and maintenance workload and low efficiency, which is not conducive to the rapid access of smart terminals and the multi-node expansion of secure access services.

Method used

The distribution terminal sends a feature information request through the secure access service, and the distribution terminal returns the feature information. The secure access service retrieves digital certificates from the database and extracts feature information, and compares the feature information. If it matches, completes identity authentication and connects to the Internet of Things platform, eliminating the terminal ledger configuration steps.

Benefits of technology

It realizes rapid identification of terminals, simplifies the access process, supports multiple terminals to access simultaneously, and facilitates node expansion of secure access services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115484283B_ABST
    Figure CN115484283B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device and storage medium for configuration-free access of an Internet of Things distribution terminal, comprising the following steps: a secure access service sends a feature information request to the distribution terminal; the distribution terminal returns the first feature information; the secure access service retrieves the digital certificate of the distribution terminal from the database and extracts the second feature information in the digital certificate; compares the first feature information with the second feature information; when the first feature information does not match the second feature information, terminates access to the distribution terminal; when the first feature information matches the second feature information, calls an encryption device and the distribution terminal to complete identity authentication, and connects the distribution terminal to the Internet of Things platform. Compared to the prior art, the present invention omits the terminal ledger configuration step in the terminal access phase, and can quickly identify the terminal; by verifying the feature information in the digital certificate, multiple terminals can be quickly accessed at the same time, facilitating node expansion of the secure access service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power distribution equipment management, and in particular to a method, device and storage medium for configuration-free access of an Internet of Things power distribution terminal. Background Art

[0002] With the advent of the IoT era for power distribution, a large number of IoT power distribution terminals are connected to the IoT platform (IoT platform), making IoT security protection particularly important. The security solution, which combines secure access services, secure access gateways, and terminal security agents, provides effective protection for identity authentication and data transmission between applications and smart terminals.

[0003] Traditional secure access services are a functional module of power distribution front-end services. They typically employ the following approach: Access channel and terminal configurations are manually added to the power distribution front-end service for each smart terminal. This configuration includes not only basic information but also characteristic information used to identify the terminal, and specifies a digital certificate for identity authentication. This involves establishing terminal ledger information based on a database and local configuration files. During the identity authentication phase, the power distribution front-end service matches the characteristic information sent by the smart terminal with the ledger information. In this case, adding individual configuration information for each smart terminal not only increases the O&M workload but also hinders rapid smart terminal access, resulting in low efficiency and inconvenience in scaling the secure access service to multiple nodes. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a method, device, and storage medium for configuration-free access of an Internet of Things power distribution terminal.

[0005] A first aspect of the present invention provides a method for configuration-free access of an Internet of Things power distribution terminal, characterized by comprising the following steps:

[0006] The secure access service sends a feature information request to the power distribution terminal;

[0007] The power distribution terminal returns the first characteristic information;

[0008] The secure access service retrieves the digital certificate of the power distribution terminal from the database and extracts the second characteristic information in the digital certificate;

[0009] comparing the first feature information with the second feature information;

[0010] When the first characteristic information does not match the second characteristic information, terminating access to the power distribution terminal;

[0011] When the first characteristic information matches the second characteristic information, the encryption device and the power distribution terminal are called to complete identity authentication, and the power distribution terminal is connected to the Internet of Things platform.

[0012] Furthermore, the digital certificate of the distribution terminal is issued by the Internet of Things platform after the distribution terminal is registered on the Internet of Things platform; after obtaining the digital certificate of the distribution terminal, the security access service will collect the generated digital certificate of the distribution terminal from the Internet of Things platform and store it in the database.

[0013] Furthermore, the characteristic information specifically includes: a first characteristic code, a second characteristic code and a third characteristic code;

[0014] The first feature code is obtained by generating a first random character segment via the IoT platform, encrypting it using the IoT platform's digital certificate, and signing it with the power distribution terminal's digital certificate.

[0015] The second feature code is obtained by generating a second random character segment by the power distribution terminal, encrypting it using the digital certificate of the power distribution terminal, and signing it with the digital certificate of the Internet of Things platform;

[0016] The third feature code is obtained by performing an agreed logical operation on the first feature code and the second feature code;

[0017] After obtaining the first feature code, the second feature code and the third feature code, the first feature code, the second feature code and the third feature code are recorded in the digital certificate of the power distribution terminal as the second feature information.

[0018] Furthermore, the power distribution terminal includes an encryption module, and the generation process of the first feature code, the second feature code and the third feature code is completed by the encryption module; the generated first feature code, the second feature code and the third feature code will be stored in the power distribution terminal as the first feature information.

[0019] Furthermore, the extracting of the second characteristic information in the digital certificate specifically includes the following steps:

[0020] Finding the first characteristic code through the digital certificate signature of the power distribution terminal;

[0021] Communicate with the IoT platform to obtain the digital certificate of the IoT platform;

[0022] Find the second feature code through the digital certificate signature of the IoT platform;

[0023] Perform a logical inverse operation on all contents in the digital certificate, and compare the operation result with the first feature code and the second feature code. If they are the same, the third feature code is obtained.

[0024] Extract the first feature code, the second feature code, and the third feature code.

[0025] Furthermore, the comparing of the first feature information and the second feature information specifically involves comparing the first feature code, the second feature code and the third feature code in the first feature information with the first feature code, the second feature code and the third feature code in the second feature information; when the first feature code, the second feature code and the third feature code are exactly the same, it is determined that the first feature information is consistent with the second feature information.

[0026] Furthermore, when at least one of the first feature code, the second feature code and the third feature code is the same and at least one feature code is different, the distribution terminal is notified to resend the first feature information and compare again; if the first feature code, the second feature code and the third feature code in the comparison result are still not exactly the same, the access of the distribution terminal is terminated.

[0027] Furthermore, the characteristic information will be updated regularly by generating new random character segments and adopting new logical operations.

[0028] A second aspect of the present invention discloses an electronic device, comprising a processor and a memory;

[0029] The memory is used to store programs;

[0030] The processor executes the program to implement a method for configuration-free access of an Internet of Things power distribution terminal.

[0031] A third aspect of the present invention discloses a computer-readable storage medium, which stores a program. The program is executed by a processor to implement a method for configuration-free access to an Internet of Things power distribution terminal.

[0032] The present invention has the following beneficial effects: compared with the existing technology, the present invention omits the terminal ledger configuration step in the terminal access stage, and can quickly identify the terminal; by verifying the characteristic information in the digital certificate, it can quickly access multiple terminals at the same time, facilitating the node expansion of secure access services.

[0033] Additional aspects and advantages of the present invention will be set forth in part in the description which follows and, in part, will be obvious from the description which follows, or may be learned by practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0035] Figure 1This is a data interaction flow chart of a method, device, and storage medium for configuration-free access to an Internet of Things power distribution terminal of the present invention;

[0036] Figure 2 This is a connection diagram of a method, device and storage medium for configuration-free access to an Internet of Things power distribution terminal according to the present invention. DETAILED DESCRIPTION

[0037] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0038] The secure access service is a service component on the master side of the power distribution authentication system. It connects to the encryption authentication device and performs identity authentication, data encryption and decryption, and data forwarding with the smart terminal. Its counterpart on the smart terminal side is the terminal security agent.

[0039] The specific implementation technologies for configuration-free access are as follows:

[0040] 0. The secure access service establishes a TCP connection with the security gateway;

[0041] 1. The power distribution terminal establishes a TCP connection with the security gateway;

[0042] In the TCP connection established in steps 0 and 1, the power distribution terminal and the secure access service act as clients, and the security gateway acts as the server.

[0043] 4. The secure access service sends a feature information request to the power distribution terminal;

[0044] 5. The power distribution terminal returns the first characteristic information;

[0045] 6. The secure access service retrieves the digital certificate of the power distribution terminal from the database, extracts the second characteristic information in the digital certificate, and compares the first characteristic information with the second characteristic information;

[0046] The characteristic information used in steps 4, 5, and 6 is mainly obtained through negotiation and calculation between the power distribution terminal and the Internet of Things platform. In this embodiment, the characteristic information can be generated in the following ways:

[0047] After the distribution terminal is registered on the IoT platform, the IoT platform issues a digital certificate Certn to the distribution terminal. At the same time, the digital certificate provided by the IoT platform is represented by Certp. The format of the digital certificate can be X.509 standard or other format standards.

[0048] The IoT platform generates a first random character segment R1 for the power distribution terminal, encrypts R1 using Certp, and completes the signature using Certn to obtain a first feature code.

[0049] The power distribution terminal independently generates a second random character segment R2, encrypts R2 through Certn, and completes the signature with Certp to obtain a second feature code;

[0050] The algorithm used in the above encryption process can be a symmetric encryption and decryption algorithm, an asymmetric encryption and decryption algorithm, a digest algorithm, or a signature verification algorithm.

[0051] After generating the first and second feature codes, the power distribution terminal and the IoT platform agree on a logical operator to perform the agreed logical operation on the first and second feature codes to obtain the third feature code. The logical operation can be common operators such as AND, OR, XOR, NOT, and any combination thereof.

[0052] After obtaining the first feature code, the second feature code and the third feature code, the power distribution terminal will record the first feature code, the second feature code and the third feature code as the authentication identifier of the terminal, that is, the first feature information.

[0053] At the same time, the power distribution terminal records the first, second, and third characteristic codes in its digital certificate Certn and sends it to the IoT platform. The IoT platform then sends it to the secure access service's database for storage. The database can store a large number of power distribution terminal digital certificates (Cert1, 2, 3, ... n). When multiple terminals establish connections simultaneously, access confirmation for multiple power distribution terminals can be easily completed by searching the database for digital certificates Cert1, 2, 3, ... n.

[0054] In this embodiment, extracting the second characteristic information in the digital certificate specifically includes the following steps:

[0055] Finding the first characteristic code through the digital certificate signature of the power distribution terminal;

[0056] Communicate with the IoT platform to obtain the IoT platform's digital certificate Certn;

[0057] Find the second feature code through the digital certificate signature of the IoT platform;

[0058] Perform a logical inverse operation on all contents in the digital certificate and compare the result with the first and second signature codes. If they match, the third signature code is obtained. The secure access service can communicate with the IoT platform to obtain the originally agreed upon logical operation method and establish a corresponding inverse operation process. After traversing the contents of the digital certificate Certn, perform the inverse operation on each of them. If the result of the inverse operation matches the first and second signature codes, the third signature code can be accurately located.

[0059] In this embodiment, the first feature information is compared with the second feature information, specifically, the first feature code, the second feature code, and the third feature code in the first feature information are compared with the first feature code, the second feature code, and the third feature code in the second feature information; when the first feature code, the second feature code, and the third feature code are exactly the same, it is determined that the first feature information is consistent with the second feature information.

[0060] 7-a. When the first characteristic information does not match the second characteristic information, terminating access to the power distribution terminal;

[0061] 7-b. When the first characteristic information matches the second characteristic information, the encryption device is called to complete identity authentication with the power distribution terminal, and the power distribution terminal is connected to the Internet of Things platform;

[0062] 7-c. When at least one of the first feature code, the second feature code and the third feature code is the same and at least one feature code is different, notify the distribution terminal to resend the first feature information and compare again; if the first feature code, the second feature code and the third feature code are still not exactly the same in the comparison result, terminate the access of the distribution terminal.

[0063] The embodiment of the present invention also discloses a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs Figure 1 The method shown.

[0064] In some optional embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operation and logic flow presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.

[0065] Furthermore, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise indicated, one or more of the functions and / or features described may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It will also be understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present invention. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the ordinary skill of an engineer. Therefore, a person skilled in the art using ordinary skill will be able to implement the present invention set forth in the claims without undue experimentation. It will also be understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.

[0066] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0067] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0068] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0069] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0070] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the claims and their equivalents.

[0071] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the embodiments. Those skilled in the art can make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of this application.

Claims

1. A method for configuration-free access of an Internet of Things power distribution terminal, characterized in that: The following steps are involved: The secure access service sends a feature information request to the power distribution terminal; The power distribution terminal returns the first characteristic information; The secure access service retrieves the digital certificate of the power distribution terminal from the database and extracts the second characteristic information in the digital certificate; comparing the first feature information with the second feature information; When the first characteristic information does not match the second characteristic information, terminating access to the power distribution terminal; When the first characteristic information matches the second characteristic information, the encryption device is called to complete identity authentication with the power distribution terminal, and the power distribution terminal is connected to the Internet of Things platform; The characteristic information specifically includes: a first characteristic code, a second characteristic code, and a third characteristic code; The first feature code is obtained by generating a first random character segment via the IoT platform, encrypting it using the IoT platform's digital certificate, and signing it with the power distribution terminal's digital certificate. The second feature code is obtained by generating a second random character segment by the power distribution terminal, encrypting it using the digital certificate of the power distribution terminal, and signing it with the digital certificate of the Internet of Things platform; The third feature code is obtained by performing an agreed logical operation on the first feature code and the second feature code; After obtaining the first feature code, the second feature code and the third feature code, the first feature code, the second feature code and the third feature code are recorded in the digital certificate of the power distribution terminal as the second feature information.

2. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 1, characterized in that: The digital certificate of the distribution terminal is issued by the Internet of Things platform after the distribution terminal is registered on the Internet of Things platform; after obtaining the digital certificate of the distribution terminal, the security access service will collect the generated digital certificate of the distribution terminal from the Internet of Things platform and store it in the database.

3. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 1, characterized in that: The power distribution terminal includes an encryption module, and the generation process of the first feature code, the second feature code and the third feature code is completed by the encryption module; the generated first feature code, the second feature code and the third feature code will be stored in the power distribution terminal as the first feature information.

4. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 1, characterized in that: The step of extracting the second characteristic information from the digital certificate specifically includes the following steps: Finding the first characteristic code through the digital certificate signature of the power distribution terminal; Communicate with the IoT platform to obtain the digital certificate of the IoT platform; Find the second feature code through the digital certificate signature of the IoT platform; Perform a logical inverse operation on all contents in the digital certificate, and compare the operation result with the first feature code and the second feature code. If they are the same, the third feature code is obtained. Extract the first feature code, the second feature code, and the third feature code.

5. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 1, characterized in that: The comparing of the first feature information and the second feature information specifically involves comparing the first feature code, the second feature code, and the third feature code in the first feature information with the first feature code, the second feature code, and the third feature code in the second feature information; when the first feature code, the second feature code, and the third feature code are exactly the same, it is determined that the first feature information is consistent with the second feature information.

6. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 5, characterized in that: When at least one of the first feature code, the second feature code and the third feature code is the same and at least one feature code is different, the distribution terminal is notified to resend the first feature information and compare again; if the first feature code, the second feature code and the third feature code in the comparison result are still not exactly the same, the access of the distribution terminal is terminated.

7. The method for configuration-free access of an Internet of Things power distribution terminal according to claim 1, characterized in that: The characteristic information will be updated regularly by generating new random character segments and adopting new logical operations.

8. An electronic device, characterized in that: including a processor and a memory; The memory is used to store programs; The processor executes the program to implement the method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that The storage medium stores a program, and the program is executed by a processor to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Verification method and device, activation method and device, equipment and storage medium

    CN109600223A