Edge device management method, system, device and medium based on industrial internet
By introducing a security device with encryption, decryption, and location functions between edge devices and the industrial internet platform, dual authentication of device identity and location is achieved, solving the security issues of secure access and communication for edge devices and improving the security and flexibility of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-14
- Publication Date
- 2026-04-10
AI Technical Summary
Existing edge device security access solutions are vulnerable to identity theft, have high hardware integration costs and poor timeliness, and cannot effectively identify device locations, resulting in insufficient communication security.
Secure devices with encryption/decryption calculation and real-time positioning capabilities are bound to edge devices. Dual authentication ensures the legitimacy of device identity and location, and only successfully registered devices can communicate with the industrial internet platform.
It improves the security of edge device access and communication, reduces integration costs, and supports flexible management of device update scenarios.
Smart Images

Figure CN115643072B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of Internet of Things and industrial Internet, and in particular to an edge device management method and system based on industrial Internet, an edge device management device and a medium. BACKGROUND
[0002] Industrial Internet is a new type of infrastructure, application mode and industrial ecology formed by deep integration of new generation information communication technology and industrial economy, which promotes industrial reform, improves production efficiency and reduces production cost through sharing production data.
[0003] With the continuous development of industrial Internet, the financial industry industrial Internet platform has begun to rise, which puts forward new requirements for the secure access and two-way secure communication authentication of edge devices. The existing secure access scheme realizes the secure access of edge devices by applying for a certificate to the industrial Internet platform or integrating a security chip. This scheme can realize the theft of identity by copying information, and increases the additional hardware integration cost, which is time-consuming and cannot distinguish whether the edge device is used in the usual location. SUMMARY
[0004] In view of the above problems of the prior art, the present application provides an edge device management method and system based on industrial Internet, an edge device management device and a medium, which realizes dual authentication of device identity and real-time location, flexibly supports device update scenarios, and improves the security of device access and device communication.
[0005] The first aspect of the present application provides an edge device management method based on industrial Internet, which is used for an electronic device, and the method comprises:
[0006] Registering an edge device on an industrial Internet platform, so that the edge device is bound to a security device;
[0007] Accessing the edge device to the industrial Internet platform using the security device;
[0008] Using the security device to communicate between the edge device and the industrial Internet platform.
[0009] In a possible implementation, the registering an edge device on an industrial Internet platform, so that the edge device is bound to a security device comprises:
[0010] Issuing the security device to the edge device by the industrial Internet platform;
[0011] Sending, by the edge device, the encrypted edge device identity information associated with the edge device to the industrial Internet platform using the security device;
[0012] decrypt, by the industrial internet platform, the encrypted edge device identity information associated with the edge device to register the edge device so that the edge device is bound to the security device.
[0013] In a possible implementation, sending, by the edge device, encrypted edge device identity information and edge device location information associated with the edge device to the industrial internet platform using the security device;
[0014] decrypt, by the industrial internet platform, the encrypted edge device identity information and edge device location information associated with the edge device to register the edge device so that the edge device is bound to the security device and record the frequently used location of the edge device.
[0015] In a possible implementation, the using the security device to access the edge device to the industrial internet platform comprises:
[0016] sending, by the edge device, encrypted second edge device identity information and second edge device location information associated with the edge device to the industrial internet platform using the security device;
[0017] decrypt, by the industrial internet platform, the encrypted second edge device identity information and second edge device location information associated with the edge device to determine whether the edge device is registered and whether the edge device is located at the frequently used location of the edge device;
[0018] In a case where it is determined that the edge device is registered and the edge device is located at the frequently used location of the edge device, accessing the edge device to the industrial internet platform.
[0019] In a possible implementation, the method further comprises:
[0020] In response to the edge device being updated to a second edge device, deregistering the edge device on the industrial internet platform so that the edge device is unbound to the security device;
[0021] registering the second edge device on the industrial internet platform so that the second edge device is bound to the security device.
[0022] In a possible implementation, the registering the second edge device on the industrial internet platform so that the second edge device is bound to the security device comprises:
[0023] sending, by the second edge device, encrypted edge device identity information and edge device location information associated with the second edge device to the industrial internet platform using the security device;
[0024] decrypting, by the industrial internet platform, the encrypted edge device identity information and edge device location information associated with the second edge device to determine whether the second edge device is located at a usual location of the edge device;
[0025] in a case where it is determined that the second edge device is located at the usual location of the edge device, registering the second edge device such that the second edge device is bound to the security device.
[0026] In a possible implementation, the method further includes:
[0027] in response to the security device being updated to a second security device, re-joining the edge device to the industrial internet platform using the second security device.
[0028] In a possible implementation, the re-joining the edge device to the industrial internet platform using the second security device includes:
[0029] sending, by the edge device, encrypted third edge device identity information and third edge device location information associated with the edge device to the industrial internet platform using the second security device;
[0030] decrypting, by the industrial internet platform, the encrypted third edge device identity information and third edge device location information associated with the edge device to determine whether the edge device is registered and whether the edge device is located at a usual location of the edge device;
[0031] in a case where it is determined that the edge device is registered and the edge device is located at the usual location of the edge device, re-joining the edge device to the industrial internet platform.
[0032] In a possible implementation, the using the security device to communicate between the edge device and the industrial internet platform includes:
[0033] sending, by the edge device, encrypted communication data to the industrial internet platform using the security device;
[0034] decrypting, by the industrial internet platform, the encrypted communication data.
[0035] The second aspect of the present application provides an edge device management system based on an industrial internet, the system comprising an industrial internet platform, an edge device and a security device; the edge device is registered on the industrial internet platform, so that the edge device is bound with the security device; the edge device is accessed to the industrial internet platform using the security device; and communication is performed between the edge device and the industrial internet platform using the security device.
[0036] The third aspect of the present application provides an electronic device, comprising a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the edge device management method based on the industrial internet according to the first aspect of the present application.
[0037] The fourth aspect of the present application provides a computer readable storage medium, the computer readable storage medium storing at least one instruction or at least one program, the at least one instruction or at least one program being loaded and executed by a processor to implement the edge device management method based on the industrial internet according to the first aspect of the present application.
[0038] The fifth aspect of the present application provides a computer program product, the computer program product comprising computer instructions, the computer instructions being executed to implement the edge device management method based on the industrial internet according to the first aspect of the present application.
[0039] Due to the above technical solutions, the present application has the following beneficial effects:
[0040] The edge device is bound with the security device which has both encryption and decryption calculation and real-time positioning functions, one security device can only bind one edge device at a time, and only the registered edge device can communicate with the industrial internet platform, so that the security of edge device access and the security of communication between the device platform can be effectively guaranteed, the integrated cost is low, and the access is more efficient.
[0041] The embodiment of the present application can realize dual authentication of the identity and real-time position of the edge device when the edge device accesses, and provide a double insurance security service.
[0042] The embodiment of the present application can flexibly support the scenarios of edge device update and security device update. BRIEF DESCRIPTION OF DRAWINGS
[0043] In order to make the technical scheme of the present application clearer, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0044] Figure 1 is a flowchart of an industrial internet-based edge device management method according to an embodiment of the present application;
[0045] Figure 2 is a flowchart of a registration function according to an embodiment of the present application;
[0046] Figure 3 is a flowchart of a registration function according to another embodiment of the present application;
[0047] Figure 4 is a flowchart of an access function according to an embodiment of the present application;
[0048] Figure 5 is a structural diagram of an industrial internet-based edge device management system according to an embodiment of the present application;
[0049] Figure 6 is a structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0050] In order to make the technical scheme of the present application clearer, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0051] It should be noted that the terms "first", "second", and the like in the description, claims, and drawings of the present application are intended to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product, or apparatus that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products, or apparatuses.
[0052] The acquisition, storage, use, processing, etc. of data in the technical solutions disclosed in the embodiments of the present application comply with relevant provisions of national laws and regulations.
[0053] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer and more apparent, the embodiments of the present application are further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the embodiments of the present application and are not used to limit the embodiments of the present application.
[0054] Figure 1 is a flowchart of an industrial internet-based edge device management method according to an embodiment of the present application. As shown in Figure 1 , the method comprises:
[0055] In S101, an edge device is registered on an industrial internet platform, so that the edge device is bound to a security device.
[0056] Specifically, the edge device is a very important link in the industrial internet system, and plays a crucial role in the transmission of information, data and instructions between the terminal node and the industrial internet platform. The edge device is responsible for collecting data information of the terminal node for data storage and data processing, and sending raw data / processed data to the cloud storage. At the same time, it receives processing instructions, data processing results, or device application updates / system updates and other data and information issued by the cloud.
[0057] The industrial internet platform can be a financial industry industrial internet platform with high security requirements, etc.
[0058] The security device is built-in with a certificate, integrates encryption and decryption algorithms and a positioning chip (such as a Beidou positioning chip), and has independent encryption and decryption calculation function. The certificate information and encryption and decryption algorithms of the security device are stored on the industrial internet platform.
[0059] The embodiments of the present application bind the security device with the edge device, which has encryption and decryption calculation and real-time positioning functions. One security device can only bind one edge device at a time, and only the edge device that has successfully registered can communicate with the industrial internet platform, so that the security of the edge device access can be effectively guaranteed.
[0060] Figure 2 is a flowchart of a registration function according to an embodiment of the present application. As shown in Figure 2 , the registration of the edge device on the industrial internet platform in step S101, so that the edge device is bound to the security device, comprises:
[0061] In S201, the security device is issued to the edge device by the industrial internet platform.
[0062] Specifically, in response to the request for applying the security device by the edge device to the industrial internet platform, the security device is issued by the industrial internet platform to the edge device, and after the security device is acquired, the security device is connected to the edge device.
[0063] In S202, the edge device sends the encrypted edge device identity information associated with the edge device to the industrial internet platform using the security device.
[0064] Specifically, the edge device sends the edge device identity information associated with the edge device to the security device to initiate an encryption request, which can uniquely indicate the edge device. In response to the encryption request, the security device encrypts the edge device identity information associated with the edge device and sends the encrypted edge device identity information associated with the edge device back to the edge device. Finally, the edge device sends the encrypted edge device identity information associated with the edge device to the industrial internet platform.
[0065] In S203, the industrial internet platform decrypts the encrypted edge device identity information associated with the edge device to register the edge device, so that the edge device is bound with the security device.
[0066] Specifically, the industrial internet platform decrypts the encrypted edge device identity information associated with the edge device based on the public key in the stored encryption and decryption algorithm to confirm the identity information of the edge device, and registers and stores the identity information of the edge device in association with the certificate information of the security device, so that one security device can only bind one edge device at a time.
[0067] Figure 3 is a flowchart of the registration function according to another embodiment of the present application. As shown in Figure 3 The registration of the edge device on the industrial internet platform in step S101 so that the edge device is bound with the security device includes:
[0068] In S301, the industrial internet platform issues the security device to the edge device.
[0069] In S302, the edge device sends the encrypted edge device identity information associated with the edge device and the edge device location information to the industrial internet platform using the security device.
[0070] Specifically, since the security device integrates the positioning chip, after connecting the security device to the edge device, the security device can obtain the real-time position of the edge device, i.e., the edge device position information associated with the edge device. In response to the encryption request, the edge device identity information and the edge device position information associated with the edge device are encrypted by the security device, and the encrypted edge device identity information and the edge device position information associated with the edge device are sent back to the edge device. Finally, the edge device sends the encrypted edge device identity information and the edge device position information associated with the edge device to the industrial internet platform.
[0071] In S303, the encrypted edge device identity information and the edge device position information associated with the edge device are decrypted by the industrial internet platform to register the edge device, so that the edge device is bound with the security device, and the common position of the edge device is recorded.
[0072] Specifically, the encrypted edge device identity information and the edge device position information associated with the edge device are decrypted by the industrial internet platform based on the public key in the stored encryption and decryption algorithm to confirm the identity information and the real-time position of the edge device, register and store the identity information of the edge device in association with the certificate information of the security device, so that one security device can only bind one edge device at a time, and record the real-time position of the edge device at the time of registration as the common position of the edge device, so that the double authentication of identity and real-time position described below can be realized.
[0073] It can be understood that, Figure 3 Other contents not mentioned in the method shown can be the same or similar to Figure 2 , and therefore will not be described one by one.
[0074] Returning to Figure 1 , the method comprises:
[0075] In S102, the edge device is accessed to the industrial internet platform using the security device.
[0076] The embodiment of the application requires the edge device to access the industrial internet platform via the security device, so that a communication connection is established between the edge device and the industrial internet platform, and communication can only begin thereafter, which is low in integration cost and efficient in access.
[0077] Figure 4 is a flowchart of an access function according to an embodiment of the application. As Figure 4 shown, the use of the security device to access the edge device to the industrial internet platform described in step S102 comprises:
[0078] At S401, the second edge device identity information and the second edge device location information associated with the edge device are sent by the edge device to the industrial internet platform using the security device.
[0079] Specifically, the second edge device identity information and the second edge device location information associated with the edge device are sent by the edge device to the security device to initiate an encryption request. It is worth noting that the term “second” is used here to distinguish the edge device identity information and the edge device location information associated with the edge device in the access process and the registration process, which may be the same or similar in information structure and information content. In response to the encryption request, the second edge device identity information and the second edge device location information associated with the edge device are encrypted by the security device, and the encrypted second edge device identity information and the second edge device location information associated with the edge device are sent back to the edge device. Finally, the encrypted second edge device identity information and the second edge device location information associated with the edge device are sent by the edge device to the industrial internet platform.
[0080] At S402, the encrypted second edge device identity information and the second edge device location information associated with the edge device are decrypted by the industrial internet platform to determine whether the edge device has been registered and whether the edge device is located at the usual location of the edge device.
[0081] Specifically, the encrypted second edge device identity information and the second edge device location information associated with the edge device are decrypted by the industrial internet platform based on the public key in the stored encryption and decryption algorithm to confirm the identity information and the real-time location of the edge device, determine whether the identity information of the edge device has been registered and stored, and determine whether the real-time location of the edge device is the same as the real-time location of the edge device at the time of registration (i.e., the usual location of the edge device).
[0082] At S403, in the case where it is determined that the edge device has been registered and the edge device is located at the usual location of the edge device, the edge device is accessed to the industrial internet platform.
[0083] Specifically, if it is determined that the identity information of the edge device has been registered and stored (i.e., the edge device has been bound with the security device), and it is determined that the real-time location of the edge device at the time of access is the same as the real-time location of the edge device at the time of registration (i.e., the usual location of the edge device), the edge device is accessed to the industrial internet platform. In contrast, if it is determined that the identity information of the edge device has not been registered and stored (i.e., the edge device has not been bound with the security device), or it is determined that the real-time location of the edge device at the time of access is different from the real-time location of the edge device at the time of registration (i.e., the usual location of the edge device), the edge device is refused to be accessed to the industrial internet platform.
[0084] It can be understood that, in the case of determining that the edge device is not located at the normal position of the edge device, a short message verification code or a secondary password can be sent by the edge device to the industrial internet platform for secondary confirmation, and after the secondary confirmation, it can be determined that the edge device is located at the safe position, so that in the case of determining that the edge device has been registered, the edge device can also be accessed to the industrial internet platform.
[0085] The embodiment of the application can realize dual authentication of the identity and real-time position of the edge device when the edge device accesses, and provide a double-insured security service.
[0086] Returning to Figure 1 , the method comprises:
[0087] In S103, the secure device is used to communicate between the edge device and the industrial internet platform.
[0088] Specifically, the communication between the edge device and the industrial internet platform using the secure device described in step S103 comprises:
[0089] The encrypted communication data is sent by the edge device to the industrial internet platform using the secure device;
[0090] The encrypted communication data is decrypted by the industrial internet platform.
[0091] More specifically, the communication data to be communicated with the industrial internet platform is sent by the edge device to the secure device to initiate an encryption request. In response to the encryption request, the communication data is encrypted by the secure device, and the encrypted communication data is sent back to the edge device. Then, the encrypted communication data is sent by the edge device to the industrial internet platform. Finally, the encrypted communication data is decrypted by the industrial internet platform based on the public key in the stored encryption and decryption algorithm to obtain the communication data.
[0092] It can be understood that, in the communication process, if the edge device is disconnected with the industrial internet platform, it is necessary to return to step S102 to re-use the secure device to access the edge device to the industrial internet platform.
[0093] It can be understood that, in the communication process, the edge device can also be required to send the encrypted edge device position information associated with the edge device to the industrial internet platform at regular intervals or irregular intervals, so that in the case of a large position offset of the edge device, it is necessary to return to step S102 to re-use the secure device to access the edge device to the industrial internet platform.
[0094] The embodiment of the application realizes the communication between the edge device and the industrial internet platform through the secure device, and improves the communication security.
[0095] Preferably, as Figure 1 The method shown further comprises:
[0096] In response to the edge device being updated to the second edge device, unregister the edge device on the industrial internet platform, so that the edge device is unbound from the security device;
[0097] Register the second edge device on the industrial internet platform, so that the second edge device is bound to the security device.
[0098] Specifically, when the edge device is updated or replaced by another edge device due to damage, the edge device can be understood as being updated to the second edge device. Since one security device can only bind one edge device at a time, the original edge device needs to be unregistered, and the identity information of the original edge device is no longer registered and stored in association with the certificate information of the security device, so that the original edge device is unbound from the security device, and the security device is connected to the new edge device, and the new edge device is registered according to the registration process described in step S101, and the new edge device is bound to the security device.
[0099] Specifically, registering the second edge device on the industrial internet platform, so that the second edge device is bound to the security device comprises:
[0100] Sending, by the second edge device, the encrypted edge device identity information associated with the second edge device and the edge device location information to the industrial internet platform using the security device;
[0101] Decrypting, by the industrial internet platform, the encrypted edge device identity information associated with the second edge device and the edge device location information to determine whether the second edge device is located at the usual location of the edge device;
[0102] In the case where it is determined that the second edge device is located at the usual location of the edge device, register the second edge device, so that the second edge device is bound to the security device.
[0103] It can be understood that when registering the new edge device, special attention is paid to whether the real-time location of the new edge device is the same as the usual location of the original edge device. Because in the case where the edge device is updated or replaced by another edge device due to damage, the real-time location of the new edge device should be the same as the usual location of the original edge device. If the real-time location of the new edge device is different from the usual location of the original edge device, there is a possibility of device impersonation, at which time the industrial internet platform should send a registration failure or update failure message to the second edge device.
[0104] Similarly, in a case where it is determined that the second edge device is not located at the usual location of the edge device, a second confirmation can be sent by the second edge device to the industrial internet platform, such as an SMS verification code or a secondary password, and after the second confirmation, it can be determined that the second edge device is located at the safe location, so that the second edge device can also be registered, so that the second edge device is bound with the safe device.
[0105] It can be understood that other contents not mentioned in the above method can be the same or similar to Figure 2 and Figure 3 , and therefore will not be described one by one.
[0106] Preferably, as Figure 1 indicated, the method further comprises:
[0107] In response to the safe device being updated to the second safe device, re-accessing the edge device to the industrial internet platform using the second safe device.
[0108] Specifically, when the safe device is updated or replaced by another safe device due to damage, the safe device can be understood as being updated to the second safe device. At this time, it is not necessary to unbind the edge device, but only to re-access the edge device to the industrial internet platform using the new safe device according to the access process described in step S102. It can be understood that since the safe device is issued by the industrial internet platform, the industrial internet platform can obtain the certificate information and encryption and decryption algorithm of the new safe device to replace the certificate information and encryption and decryption algorithm of the original safe device.
[0109] Specifically, re-accessing the edge device to the industrial internet platform using the second safe device comprises:
[0110] sending, by the edge device, the encrypted third edge device identity information and third edge device location information associated with the edge device to the industrial internet platform using the second safe device;
[0111] decrypting, by the industrial internet platform, the encrypted third edge device identity information and third edge device location information associated with the edge device to determine whether the edge device has been registered and whether the edge device is located at the usual location of the edge device;
[0112] In a case where it is determined that the edge device has been registered and the edge device is located at the usual location of the edge device, re-accessing the edge device to the industrial internet platform.
[0113] It is worth noting that the term "third" is used here to distinguish the edge device identity information and edge device location information associated with the edge device in the re-access process, the access process and the registration process, which may be the same or similar in information structure and information content.
[0114] It can be understood that when the edge device is reconnected to the industrial internet platform using a new security device, special attention is paid to whether the real-time location of the edge device during the reconnection is the same as the real-time location of the edge device during the registration (i.e., the usual location of the edge device). Because in the case of security device replacement due to update or damage, the real-time location of the edge device should always be the same. If the real-time location of the edge device changes, there is a possibility of device impersonation, at which time the industrial internet platform should send a message of reconnection failure or update failure to the edge device.
[0115] Similarly, in the case of determining that the edge device is not located at the usual location of the edge device, a short message verification code or a secondary password can be sent by the edge device to the industrial internet platform for secondary confirmation, and after the secondary confirmation, it can be determined that the edge device is located at a secure location, so that in the case of determining that the edge device has been registered, the edge device can also be reconnected to the industrial internet platform.
[0116] The embodiment of the present application can flexibly support the scenarios of edge device update and security device update.
[0117] It can be understood that other contents not mentioned in the above method can be the same or similar to Figure 4 , and therefore will not be described one by one.
[0118] Figure 5 is a structural schematic diagram of an edge device management system based on industrial internet according to an embodiment of the present application. As Figure 5 shown, the system 500 includes an industrial internet platform 501, an edge device 502, and a security device 503. The edge device 502 is registered on the industrial internet platform 501, so that the edge device 502 is bound with the security device 503. The edge device 502 is connected to the industrial internet platform 501 using the security device 503. The security device 503 is used for communication between the edge device 502 and the industrial internet platform 501.
[0119] The different modules described above are used to perform different steps of the edge device management method based on industrial internet according to the present application. Here, it will not be described again.
[0120] It should be noted that the system provided by the above embodiment, in realizing its function, only takes the above-mentioned division of each functional module as an example, and in actual application, the above-mentioned functions can be completed by different functional modules according to the needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the system provided by the above embodiment and the corresponding method embodiment belong to the same concept, and the specific implementation process is shown in the corresponding method embodiment, which will not be described here.
[0121] One embodiment of the present invention also provides an electronic device including a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the industrial internet-based edge device management method provided in the above method embodiments.
[0122] Memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. Memory can primarily include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for the functions, etc.; the data storage area can store data created based on the use of the device, etc. Furthermore, memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.
[0123] The method embodiments provided in this invention can be executed in a terminal, server, or similar computing device; that is, the aforementioned electronic device may include a terminal, server, or similar computing device. Taking running on a server as an example, such as... Figure 6 The diagram illustrates the structure of a server implementing an edge device management method based on the Industrial Internet, as provided in this embodiment of the invention. The server 600 can vary significantly depending on its configuration or performance, and may include one or more Central Processing Units (CPUs) 610 (e.g., one or more processors) and memory 630, and one or more storage media 620 (e.g., one or more mass storage devices) for storing application programs 623 or data 622. The memory 630 and storage media 620 can be temporary or persistent storage. The program stored in the storage media 620 may include one or more modules, each module including a series of instruction operations on the server. Furthermore, the CPU 610 may be configured to communicate with the storage media 620 and execute the series of instruction operations in the storage media 620 on the server 600. Server 600 may also include one or more power supplies 660, one or more wired or wireless network interfaces 650, one or more input / output interfaces 640, and / or one or more operating systems 621, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0124] The input / output interface 640 can be configured to receive or transmit data via a network. The network can include a wireless network provided by a communication provider of the server 600. In one example, the input / output interface 640 includes a network interface controller (NIC) that can be connected to other network devices through a base station to communicate with the Internet. In one example, the input / output interface 640 can be a radio frequency (RF) module configured to communicate with the Internet through wireless communication, which can use any communication standard or protocol, including but not limited to global system for mobile communication (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.
[0125] Those skilled in the art can understand that, Figure 6 The structure shown is only schematic, and the server 600 can further include more or fewer components than those shown, or have a different configuration of components than those shown. Figure 6 The structure shown is only schematic, and the server 600 can further include more or fewer components than those shown, or have a different configuration of components than those shown. Figure 6 The structure shown is only schematic, and the server 600 can further include more or fewer components than those shown, or have a different configuration of components than those shown.
[0126] An embodiment of the present application also provides a computer readable storage medium, which can be arranged in an electronic device to store at least one instruction or at least one program for implementing an edge device management method based on industrial internet. The at least one instruction or the at least one program is loaded and executed by the processor to implement the edge device management method based on industrial internet provided by the above method embodiment.
[0127] Optionally, in the embodiment of the present application, the storage medium can include but is not limited to: a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0128] One embodiment of the present application also provides a computer program product or computer program, which comprises computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the edge device management method based on industrial internet provided in the various optional implementations.
[0129] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description, not representing the advantages and disadvantages of the embodiments. And the above-mentioned describes the specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be executed in different order from the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are possible or can be advantageous.
[0130] Each of the embodiments in the present application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. Especially, the device embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the part of the method embodiments.
[0131] A person of ordinary skill in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program instructing relevant hardware to complete, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be read-only memory, magnetic disk or optical disk, etc.
[0132] The above-mentioned is only the preferred embodiment of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. An edge device management method based on an industrial internet, characterized by, The method is used for an electronic device, and the method comprises: registering an edge device on an industrial internet platform, so that the edge device is bound with a security device, wherein the security device is independent of each edge device, built-in with a certificate, and integrated with an encryption and decryption algorithm and a positioning chip, certificate information of the security device and the encryption and decryption algorithm are stored on the industrial internet platform; accessing the edge device to the industrial internet platform using the security device; communicating between the edge device and the industrial internet platform using the security device; in response to the edge device being updated to a second edge device, deregistering the edge device on the industrial internet platform, so that the edge device is unbound with the security device; registering the second edge device on the industrial internet platform, so that the second edge device is bound with the security device; wherein the registering the edge device on the industrial internet platform, so that the edge device is bound with the security device comprises: issuing the security device to the edge device by the industrial internet platform; sending encrypted edge device identity information and edge device location information associated with the edge device to the industrial internet platform using the security device by the edge device; decrypting the encrypted edge device identity information and edge device location information associated with the edge device by the industrial internet platform to confirm identity information and real-time location of the edge device, and registering the identity information of the edge device in association with the certificate information of the security device, so that the edge device is bound with the security device, and recording the real-time location of the edge device at the time of registration as a usual location of the edge device; wherein the registering the second edge device on the industrial internet platform, so that the second edge device is bound with the security device comprises: sending encrypted edge device identity information and edge device location information associated with the second edge device to the industrial internet platform using the security device by the second edge device; decrypting the encrypted edge device identity information and edge device location information associated with the second edge device by the industrial internet platform to determine whether the second edge device is located at the usual location of the edge device; in a case where it is determined that the second edge device is located at the usual location of the edge device, registering the second edge device, so that the second edge device is bound with the security device.
2. The method of claim 1, wherein, the accessing the edge device to the industrial internet platform using the security device comprises: sending encrypted second edge device identity information and second edge device location information associated with the edge device to the industrial internet platform using the security device by the edge device; decrypting the encrypted second edge device identity information and second edge device location information associated with the edge device by the industrial internet platform to determine whether the edge device has been registered and whether the edge device is located at the usual location of the edge device; In a case where it is determined that the edge device is registered and the edge device is located at a common location of the edge device, the edge device is accessed to the industrial internet platform.
3. The method of claim 1, wherein, The method further comprises: In response to the security device being updated to a second security device, the edge device is re-accessed to the industrial internet platform using the second security device, wherein the second security device is built-in with a certificate and integrated with a cipher algorithm and a positioning chip, and certificate information of the second security device and the cipher algorithm are stored on the industrial internet platform.
4. The method of claim 3, wherein, The re-accessing of the edge device to the industrial internet platform using the second security device comprises: sending, by the edge device, encrypted third edge device identity information and third edge device location information associated with the edge device to the industrial internet platform using the second security device; decrypting, by the industrial internet platform, the encrypted third edge device identity information and third edge device location information associated with the edge device to determine whether the edge device is registered and whether the edge device is located at a common location of the edge device; In a case where it is determined that the edge device is registered and the edge device is located at a common location of the edge device, the edge device is re-accessed to the industrial internet platform.
5. The method of claim 1, wherein, The communicating between the edge device and the industrial internet platform using the security device comprises: sending, by the edge device, encrypted communication data to the industrial internet platform using the security device; decrypting, by the industrial internet platform, the encrypted communication data.
6. An edge device management system based on an industrial internet, characterized by, The system comprises an industrial internet platform, an edge device and a security device; the edge device is registered on the industrial internet platform, so that the edge device is bound with the security device, wherein the security device is independent of each edge device, built-in with a certificate and integrated with a cipher algorithm and a positioning chip, and certificate information of the security device and the cipher algorithm are stored on the industrial internet platform; the edge device is accessed to the industrial internet platform using the security device; communication is performed between the edge device and the industrial internet platform using the security device; in response to the edge device being updated to a second edge device, the edge device is deregistered on the industrial internet platform, so that the edge device is unbound with the security device; the second edge device is registered on the industrial internet platform, so that the second edge device is bound with the security device. The registration of the edge device on the industrial internet platform so that the edge device is bound to the security device comprises: issuing the security device to the edge device by the industrial internet platform; sending, by the edge device, encrypted edge device identity information and edge device location information associated with the edge device to the industrial internet platform using the security device; decrypting, by the industrial internet platform, the encrypted edge device identity information and edge device location information associated with the edge device to confirm the identity information and real-time location of the edge device, and registering the identity information of the edge device in association with the certificate information of the security device so that the edge device is bound to the security device, and recording the real-time location of the edge device at the time of registration as the usual location of the edge device; The registration of the second edge device on the industrial internet platform so that the second edge device is bound to the security device comprises: sending, by the second edge device, encrypted edge device identity information and edge device location information associated with the second edge device to the industrial internet platform using the security device; decrypting, by the industrial internet platform, the encrypted edge device identity information and edge device location information associated with the second edge device to determine whether the second edge device is located at the usual location of the edge device; and in the case where it is determined that the second edge device is located at the usual location of the edge device, registering the second edge device so that the second edge device is bound to the security device.
7. An electronic device, comprising: The electronic device comprises a processor and a memory, and the memory stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the industrial internet-based edge device management method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores at least one instruction or at least one program, which is loaded and executed by the processor to implement the industrial internet-based edge device management method according to any one of claims 1 to 5.
9. A computer program product, characterised in that, The computer program product comprises computer instructions, which, when executed, implement the industrial internet-based edge device management method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Method and system for terminal equipment to access power Internet of Things and Internet of Things management platform
CN112583796A