Key transmission and acquisition method and apparatus
By sending the wireless network cell identifier and the location information of the controlled device to the server through the edge computing device, the security of key transmission is ensured, which solves the problem that edge computing devices are easily stolen or lost in the field and improves the security of sensitive data.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- LENOVO (BEIJING) LTD
- Filing Date
- 2022-11-21
- Publication Date
- 2026-04-10
AI Technical Summary
Edge computing devices are easily stolen or lost in the field, making it difficult to guarantee the security of encryption keys for sensitive data, thereby increasing the risk of sensitive data leakage.
The edge computing device sends device characteristic information to the server, including the identifier of the accessed wireless network cell and the location information of the controlled device. The server only sends key information when it confirms that this information matches the registered information, thus ensuring the security of the key.
It improves key security, reduces the risk of sensitive data leakage after edge computing devices are stolen or lost, and lowers the requirements for device deployment.
Smart Images

Figure CN115734220B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular to a key transmission and acquisition method and device. BACKGROUND
[0002] The edge computing device is generally connected with a sensor and a programmable logic controller and the like for data collection or control through a wired or wireless manner. The edge computing device stores important sensitive data. In addition to certificates, accounts and passwords for communication with a server, the sensitive data can also include data reported by a hanging device.
[0003] Once the sensitive information stored in the edge computing device is leaked, it will bring an immeasurable loss to the user. However, in the wind power, solar energy and oil extraction industries, the edge computing device is generally deployed in a wild production environment. Due to the harsh environment and no one to guard, the edge computing device is easy to be lost. In order to improve the security of the sensitive data in the edge computing device, the sensitive data is usually encrypted by using a key, and the sensitive data is decrypted by using the key when the sensitive data is needed. Therefore, how to ensure the security of the key for encrypting the sensitive data is the key to ensure the security of the sensitive data. SUMMARY
[0004] The present application provides a key transmission and acquisition method and device.
[0005] The key transmission method is applied to a server and includes the following steps.
[0006] Obtaining first device feature information sent by an edge computing device, wherein the first device feature information includes a first cell identifier of a wireless network accessed by the edge computing device and position information of at least one first controlled device connected by the edge computing device;
[0007] Determining second device feature information registered by the edge computing device, wherein the second device feature information includes a second cell identifier of a wireless network accessed by the edge computing device and position information of at least one second controlled device connected by the edge computing device;
[0008] If the first cell identifier matches the second cell identifier and the position information of the at least one first controlled device matches the position information of the at least one second controlled device, sending key information to the edge computing device.
[0009] In a possible implementation manner, before the step of obtaining the first device feature information sent by the edge computing device, the method further includes the following steps.
[0010] detecting that the edge computing device establishes a communication connection with a server, sending an information acquisition instruction to the edge computing device, the information acquisition instruction being used to indicate at least one target controlled device to be verified, the at least one target controlled device belonging to the at least one second controlled device;
[0011] The position information of the at least one first controlled device matches the position information of the at least one second controlled device, including:
[0012] The position information of the at least one first controlled device matches the position information of the at least one target controlled device.
[0013] In yet another possible implementation, the position information of the at least one first controlled device matches the position information of the at least one second controlled device, including:
[0014] The matching degree of the position information of the at least one first controlled device and the position information of the at least one second controlled device exceeds a set threshold;
[0015] Further comprising, before or at the same time of sending the key information to the edge computing device:
[0016] Updating the position information of at least one second controlled device in the registered second device feature information by using the position information of the at least one first controlled device.
[0017] In yet another possible implementation, the obtaining of the first device feature information sent by the edge computing device includes:
[0018] Obtaining a login request sent by the edge computing device, the login request carrying the first device feature information;
[0019] Further comprising, before sending the key information to the edge computing device:
[0020] Sending a login success instruction to the edge computing device;
[0021] The sending of the key information to the edge computing device includes:
[0022] After obtaining the key request sent by the edge computing device, sending the key information to the edge computing device.
[0023] In yet another possible implementation, before obtaining the device feature information sent by the edge computing device, further comprising:
[0024] Obtaining a registration request sent by the edge computing device, the registration request carrying second device feature information to be registered by the edge computing device;
[0025] If the edge computing device is a configured edge computing device with registration permissions, the second device feature information is stored as the second device feature information registered by the edge computing device.
[0026] Another possible implementation includes:
[0027] If the first cell identifier does not match the second cell identifier or the location information of the at least one first controlled device does not match the location information of the at least one second controlled device, a reminder message is sent to the terminal device of the designated administrator. The reminder message is used to indicate that the edge computing device does not have access rights.
[0028] If the administrator receives an approval access instruction from the administrator's terminal device in response to the reminder message, the administrator updates the second device feature information that the edge computing device has registered using the first device feature information, and sends the key information to the edge computing device.
[0029] One key acquisition method, applied to an edge computing device, includes:
[0030] Obtain the current first device feature information of the edge computing device, the first device feature information including: the first cell identifier of the wireless network accessed by the edge computing device and the location information of at least one first controlled device connected to the edge computing device;
[0031] Send the first device feature information to the server;
[0032] Obtain the key information returned by the server.
[0033] In one possible implementation, before obtaining the current first device characteristic information of the edge computing device, the method further includes:
[0034] Establish a communication connection between the edge computing device and the key server;
[0035] Obtain the information acquisition instruction sent by the key server, the information acquisition instruction being used to indicate the device identifier of at least one target controlled device to be verified;
[0036] The step of obtaining the current first device characteristic information of the edge computing device includes:
[0037] Based on the device identifier of the at least one target controlled device, the location information of each of the target controlled devices connected to the edge computing device is obtained;
[0038] Determine the first cell identifier of the wireless network accessed by the edge computing device;
[0039] The location information of the at least one target controlled device is determined as the location information of the at least one first controlled device to be sent, and first device feature information containing the first cell identifier and the location information of the at least one first controlled device is generated.
[0040] The key transmission device is applied to a server and includes:
[0041] The feature information obtaining unit is configured to obtain first device feature information sent by an edge computing device, the first device feature information including a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected to the edge computing device.
[0042] The registration information determining unit is configured to determine second device feature information registered by the edge computing device, the second device feature information including a second cell identifier of a wireless network accessed by the edge computing device and location information of at least one second controlled device connected to the edge computing device.
[0043] The key transmission unit is configured to send key information to the edge computing device if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device.
[0044] The key obtaining device is applied to an edge computing device and includes:
[0045] The feature obtaining unit is configured to obtain first device feature information of the edge computing device, the first device feature information including a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected to the edge computing device.
[0046] The feature sending unit is configured to send the first device feature information to a server.
[0047] The key obtaining unit is configured to obtain key information returned by the server.
[0048] From the above, in the embodiments of the present application, the edge computing device needs to obtain the key information from the server, and needs to send the cell identity of the wireless network accessed by the edge computing device and the location information of at least one controlled device connected by the edge computing device to the server. Since the cell identity of the wireless network accessed by the edge computing device and the location information of the controlled device connected by the edge computing device can represent the location and deployment environment state of the edge computing device, therefore, the server will only send the key information to the edge computing device in the case that the cell identity and the location information of the controlled device sent by the edge computing device respectively match the cell identity and the location information of the controlled device registered by the edge computing device, which can reduce the case that the key information is provided to the edge computing device after the edge computing device is stolen or for other reasons, improve the security of the key, and naturally reduce the risk of leakage of the encrypted sensitive data in the edge computing device. BRIEF DESCRIPTION OF DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are only embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of the provided drawings.
[0050] Figure 1 A flowchart of a key transmission method provided by an embodiment of the present application is shown;
[0051] Figure 2 A flowchart of a key acquisition method provided by an embodiment of the present application is shown;
[0052] Figure 3 A flowchart of a key acquisition and transmission method provided by an embodiment of the present application is shown;
[0053] Figure 4 A composition architecture diagram of a key acquisition and transmission system provided by an embodiment of the present application is shown;
[0054] Figure 5 A flowchart of an edge computing device registering with a server provided by an embodiment of the present application is shown;
[0055] Figure 6 Another flowchart of a key acquisition and transmission method provided by an embodiment of the present application is shown;
[0056] Figure 7 A composition structure diagram of a key transmission device provided by an embodiment of the present application is shown;
[0057] Figure 8This paper shows a schematic diagram of the composition structure of a key acquisition device provided in an embodiment of this application;
[0058] Figure 9 A schematic diagram of the composition structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0059] The solution in this application embodiment can be applied to improve the security of the key information required for decrypting data in edge computing devices, thereby enhancing the security of sensitive data in edge computing devices and reducing the risk of sensitive data being leaked due to theft or loss of edge computing devices in the field.
[0060] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0061] In this application, the key information required for decrypting data in the edge computing device is stored on the server side. In this application, the server can be a cloud server or other servers that the edge computing device can establish a communication connection with via a wireless network, without any limitation.
[0062] To make it easier to understand, we will start with the server side.
[0063] like Figure 1 The diagram illustrates a flowchart of a key transmission method provided in this embodiment, which is applied to a server. The method of this embodiment may include:
[0064] S101, Obtain the first device characteristic information sent by the edge computing device.
[0065] The first device feature information includes: the first cell identifier of the wireless network accessed by the edge computing device and the location information of at least one first controlled device connected to the edge computing device.
[0066] The cell identity of the wireless network accessed by the edge computing device, also referred to as a cell unique identity, is used to uniquely identify a base station cell in the wireless network. For example, the cell identity of the wireless network can also be referred to as a service identity (service ID). For another example, in a Long Term Evolution (LTE) network (i.e., commonly known as a 4G network), because of the evolution relationship, we refer to the access network part as an Evolved UMTS Terrestrial Radio Access Network (E-UTRAN), and the cell unique identity in the mobile communication wireless network in the LTE is also referred to as an E-UTRAN cell unique identity (ECI).
[0067] The cell identity of the wireless network accessed by the edge computing device can represent the location area where the edge computing device is located and the state of the wireless network.
[0068] The controlled device connected to the edge computing device can also be referred to as a hanging device of the edge computing device, which means that the device is connected to the edge computing device through a wired or wireless manner and performs data collection or other operations under the control of the edge computing device. For example, the controlled device connected to the edge computing device can include one or more of various types of sensors, monitoring devices, and control devices that perform operations based on the control of the edge computing device.
[0069] The location information of the controlled device connected to the edge computing device can be obtained by the edge computing device from the controlled device, such as the location information of the controlled device reported by the controlled device to the edge computing device, or the location information of the controlled device requested by the edge computing device to the controlled device, which is not limited.
[0070] In this application, in order to distinguish, the device feature information sent by the edge computing device to the server for obtaining the key information is referred to as first device feature information, and the cell identity included in the first device feature information is referred to as first cell identity. Similarly, the controlled device involved in the location information in the first device feature information is referred to as a first controlled device.
[0071] S102, determine the second device feature information registered by the edge computing device.
[0072] The second device feature information includes a second cell identity of the wireless network accessed by the edge computing device and location information of at least one second controlled device connected to the edge computing device.
[0073] The second device feature information is the device feature information sent by the edge computing device to the server and stored in the server when the edge computing device applies for registration to the server. In order to distinguish, the device feature information of the edge computing device that has been registered and stored in the server is referred to as second feature information, and the second cell identifier in the second device feature information is the cell identifier of the wireless network accessed by the edge computing device when the edge computing device applies for registration to the server. Similarly, the controlled device connected by the edge computing device when the edge computing device applies for registration to the server is referred to as the second controlled device.
[0074] It can be understood that in actual application, after the edge computing device is deployed, in order to obtain the key information required by the edge computing device to decrypt data from the server subsequently, the edge computing device needs to be registered to the server first. Based on this, before step S101, the server can obtain the registration request sent by the edge computing device, and the registration request carries the second device feature information to be registered by the edge computing device. On this basis, if the edge computing device belongs to the edge computing device with registration permission configured, the second device feature information is stored as the second device feature information registered by the edge computing device.
[0075] Among them, the edge computing device with registration permission in the server can be pre-configured by the user.
[0076] For example, the device identifier of the edge computing device with registration permission can be pre-stored in the server, and on this basis, the registration request sent by the edge computing device can carry the device identifier of the edge computing device and the second device feature information. If the server detects that the device identifier of the edge computing device belongs to the device identifier of the edge computing device with registration permission, the server will store the second device feature information of the edge computing device as the registered device feature information corresponding to the device identifier of the edge computing device.
[0077] S103, if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, send the key information to the edge computing device.
[0078] It can be understood that after the edge computing device is deployed, the location information of the edge computing device is basically unchanged under normal circumstances, and therefore the network information of the network accessed by the edge computing device is also fixed, and therefore the cell identifier of the wireless network accessed by the edge computing device is also relatively fixed. Based on this, in combination with whether the cell identifier of the wireless network accessed by the edge computing device changes after the edge computing device is registered, it can be judged whether the edge computing device is transferred, and it can also assist in judging whether the edge computing device is lost or the like.
[0079] Based on this, matching the first cell identifier with the second cell identifier can be achieved when the first cell identifier and the second cell identifier are the same.
[0080] In some cases, after the edge computing device is deployed, its location remains largely unchanged. However, due to special reasons such as wireless network instability, the wireless network the edge computing device connects to may change, or the cell it connects to may change. For example, if the edge computing device is located at the boundary of two wireless network cells, it may connect to different cells of the wireless network at different times.
[0081] Since the location of the cell represented by the cell identifier of the wireless network can be determined, the location of the edge computing device can be reflected by combining the cell identifier of the wireless network accessed by the edge computing device. Based on this, the matching of the first cell identifier and the second cell identifier can also be: the difference between the first location information corresponding to the first cell represented by the first cell identifier and the second location information corresponding to the second cell represented by the second cell identifier is less than a set threshold.
[0082] The location information corresponding to the cell represented by the cell identifier can be the range of cell locations represented by the cell identifier, retrieved based on the cell identifier. Correspondingly, the difference between the first location information and the second location information being less than a set threshold can be the difference in location ranges being less than a set range threshold.
[0083] The location information corresponding to the cell represented by the cell identifier can also be the center location of the cell. Based on this, the difference between the first location information and the second location information being less than a set threshold can be defined as the distance between the first location information and the second location information being less than a set distance threshold.
[0084] In this application, the matching of the location information of at least one first controlled device with the location information of at least one second controlled device can indicate that at least one first controlled device belongs to a controlled device registered by the edge computing device, and the location information of the at least one first controlled device matches the location information of the at least one first controlled device registered by the edge computing device.
[0085] Specifically, matching the location information of at least one first controlled device with the location information of at least one second controlled device can mean that the location information of at least one first controlled device is exactly the same as the location information of at least one controlled device. For example, at least one first controlled device is the same as at least one second controlled device, and the location information of at least one first controlled device is the same as the location information of at least one second controlled device.
[0086] It can be understood that, considering that the edge computing device connected controlled devices can be partially changed, based on this, the matching of the location information of the at least one first controlled device and the location information of the at least one second controlled device can also be that the matching degree of the location information of the at least one first controlled device and the location information of the at least one second controlled device exceeds a preset threshold.
[0087] For example, the similarity of the location information of the at least one first controlled device and the location information of the at least one second controlled device registered exceeds a set threshold. For example, eighty percent of the location information of the at least one first controlled device is the same as the location information of the at least one second controlled device registered.
[0088] In particular, considering that the number of edge computing device connected controlled devices can be large, if the edge computing device needs to collect and report the location information of all controlled devices every time the key information is obtained, it will inevitably lead to a large amount of data collected by the edge computing device, a long time consumption, and a waste of excessive bandwidth resources. Based on this, after the edge computing device and the server establish a communication connection, the server can also send an information acquisition instruction to the edge computing device, and the information acquisition instruction is used to indicate at least one target controlled device to be verified, and the at least one target controlled device belongs to the at least one second controlled device registered by the edge computing device.
[0089] Correspondingly, the edge computing device can only obtain the location information of the at least one target controlled device, and send the obtained location information of the at least one target controlled device and the first cell identifier of the wireless network accessed by the edge computing device as the first device feature information to the server. On this basis, if the server determines that the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one target controlled device, the server can send the key information to the edge computing device.
[0090] Wherein, the matching of the location information of the at least one first controlled device and the location information of the at least one target controlled device can also be complete matching, or the matching degree exceeds the set threshold, which is not limited.
[0091] In this application, the key information is used for the edge computing device to decrypt the encrypted data stored by the edge computing device.
[0092] In a possible implementation, the edge computing device itself has a key for implementing data encryption, and the edge computing device encrypts sensitive data and the like by using the key. In order to ensure the security of the key, the key needs to be encrypted by using the key information provided by the server, and the encrypted key is stored in the edge computing device. On this basis, the edge computing device needs to obtain the key information from the server before decrypting the encrypted data stored in the edge computing device each time, and decrypt the encrypted key.
[0093] Based on this, the key information sent by the server to the edge computing device in the application can include a first key, and the first key is used to decrypt a second key encrypted in the edge computing device, and the second key is a key used to encrypt data in the edge computing device.
[0094] In particular, if the first cell identifier does not match the second cell identifier or the location information of the at least one first controlled device does not match the location information of the at least one second controlled device, the server can also send a reminder message to the terminal device of the designated administrator, and the reminder message is used to prompt that the edge computing device does not have access permission, so that the administrator verifies whether the edge computing device is abnormal.
[0095] Correspondingly, after obtaining the reminder message, the administrator can verify whether the edge computing device is lost or the like. If the administrator confirms that the edge computing device is not abnormal, and considers that the edge computing device has the permission to access the server, the administrator can also send an approved access instruction to the reminder message by using the terminal device. On this basis, after receiving the approved access instruction sent by the terminal device of the administrator, the server can update the second device feature information registered by the edge computing device by using the first device feature information, so that the server can send the key information to the edge computing device.
[0096] As can be seen from the above, in the embodiment of the application, the edge computing device needs to obtain the key information from the server, and needs to send the cell identifier of the wireless network accessed by the edge computing device and the location information of the at least one controlled device connected by the edge computing device to the server. Since the cell identifier of the wireless network accessed by the edge computing device and the location information of the controlled device connected by the edge computing device can represent the location and deployment environment state of the edge computing device, the server will send the key information to the edge computing device only when the cell identifier sent by the edge computing device and the location information of the controlled device match the cell identifier and the location information of the controlled device registered by the edge computing device, which can reduce the situation that the key information is provided to the edge computing device after the edge computing device is stolen or for other reasons, improve the security of the key, and naturally reduce the risk of leakage of sensitive data encrypted in the edge computing device.
[0097] In the present application, the server and the edge computing device can be connected through a conventional wireless network, without the need to establish a dedicated network between the edge computing device and the server, and naturally, there is no need for the edge computing device to perform related deployment required for accessing the dedicated network, which naturally reduces the deployment requirements for the edge computing device, and avoids the situation that the edge computing device cannot obtain the key information due to the environment where the edge computing device is located not meeting the deployment conditions of the dedicated network.
[0098] It can be understood that if the matching degree of the location information of the at least one first controlled device and the location information of the second controlled device exceeds the set threshold, it is considered that the location information of the at least one second controlled device matches the location information of the at least one second controlled device, in order to keep the second device feature information of the edge computing device registered by the server as the latest device feature information, and ensure the integrity of the second device feature information, the location information of the at least one second controlled device in the registered second device feature information can also be updated by using the location information of the at least one first controlled device.
[0099] Next, the scheme of the present application is introduced from the edge computing device side. As shown in Figure 2 Fig. 1 shows a flowchart of a key acquisition method provided by the present application. The present embodiment is applied to an edge computing device. The method of the present embodiment can include:
[0100] S201, obtaining the first device feature information of the edge computing device at present.
[0101] The first device feature information includes the first cell identifier of the wireless network accessed by the edge computing device and the location information of the at least one first controlled device connected by the edge computing device.
[0102] S202, sending the first device feature information to the server.
[0103] The first device feature information includes the first cell identifier of the wireless network accessed by the edge computing device and the location information of the at least one first controlled device.
[0104] S203, obtaining the key information returned by the server.
[0105] It can be understood that the key information is sent by the server to the edge computing device after confirming that the first device feature information matches the second device feature information of the edge computing device registered by the server.
[0106] The second device feature information includes: a second cell identifier accessed by the edge computing device registered by the edge computing device and location information of at least one second controlled device. Correspondingly, the matching of the first device feature information and the second device feature information is that the first cell identifier is matched with the second cell identifier, and the location information of the at least one first controlled device is matched with the location information of the at least one second controlled device. For details, refer to the related description of other embodiments of the present application, which will not be repeated here.
[0107] As described above, the key information can be a key required by the edge computing device to decrypt the encrypted data encrypted by the edge computing device. For example, the key information can be a key used to decrypt the encrypted data of the edge computing device; or the key information is a first key used to decrypt a second key encrypted in the edge computing device, and the edge computing device stores the data encrypted by the second key.
[0108] Further, if the first cell identifier does not match the second cell identifier or the location information of the at least one first controlled device does not match the location information of the at least one second controlled device, the server can also send a reminder message to the terminal device of the designated administrator.
[0109] In this case, if the administrator confirms that the edge computing device is lost after learning the reminder message, the administrator can also send an encrypted data processing instruction to the edge computing device through the terminal device, which can instruct the edge computing device to transmit the stored encrypted data to the server or delete the stored encrypted data. Correspondingly, the edge computing device can transmit the stored encrypted data to the server or delete the stored encrypted data in response to the data processing instruction.
[0110] It can be understood that, in order to ensure the security of the key information required by the edge computing device, the edge computing device does not store the key information, and therefore the edge computing device can obtain the key information from the server after each boot. In one possible case, the edge computing device can send a login request to the server after each boot, and the server can allow the edge computing device to log in only after confirming that the edge computing device has login permission by using the implementation manner of the scheme of the present application. The edge computing device can request the key information from the server only after logging in the server.
[0111] The case will be introduced below in combination with a specific implementation. As shown in FIG. 8, it shows an interactive flowchart of a key acquisition and transmission method provided by an embodiment of the present application. The method of the present embodiment can include the following steps. Figure 3
[0112] S301, the edge computing device obtains a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected to the edge computing device.
[0113] For example, after the edge computing device is started, in order to obtain the key information, the edge computing device needs to perform the step S301 first.
[0114] In particular, in order to distinguish the first controlled devices connected to the edge computing device, the edge computing device further obtains device identifiers of the first controlled devices.
[0115] S302, the edge computing device sends a login request to the server, and the login request carries first device feature information.
[0116] The first device feature information includes the first cell identifier corresponding to the edge computing device and the location information of the at least one first controlled device.
[0117] In particular, in order to enable the server to distinguish the edge computing device and the first controlled devices connected to the edge computing device, the first device feature information further carries a device identifier of the edge computing device and device identifiers of the first controlled devices.
[0118] For example, the first device feature information can include the device identifier of the edge computing device, the first cell identifier corresponding to the edge computing device, and the location information of the first controlled devices connected to the edge computing device.
[0119] Similar to the foregoing embodiments, in order to reduce the amount of data of the first device feature information that needs to be collected and reported by the edge computing device, after the edge computing device establishes a communication connection with the server, the server can further send an information acquisition instruction to the edge computing device, and the information acquisition instruction is used to indicate at least one target controlled device to be verified. For example, the information acquisition instruction can indicate the device identifiers of the at least one target controlled device to be verified.
[0120] The target controlled device belongs to at least one second controlled device registered by the edge computing device.
[0121] Correspondingly, the edge computing device can obtain the location information of the target controlled devices connected to the edge computing device based on the device identifiers of the at least one target controlled device. In this case, the edge computing device can determine the location information of the at least one target controlled device as the location information of the at least one first controlled device to be sent, and generate the first device feature information including the first cell identifier and the location information of the at least one first controlled device.
[0122] To distinguish from other second controlled devices registered by the edge computing device, the information acquisition instruction can also indicate the to-be-verified controlled device as a target controlled device.
[0123] The information acquisition instruction can have various specific forms, for example, the information acquisition instruction can be a login instruction, which is used to instruct the edge computing device to log in to the server.
[0124] S303, the server determines the second device feature information registered by the edge computing device in response to the login request sent by the edge computing device.
[0125] The registered second device feature information includes the second cell identifier of the wireless network accessed by the edge computing device and the location information of the at least one second controlled device connected by the edge computing device.
[0126] In particular, considering that the server can maintain multiple second device feature information registered by the edge computing device, the server can store the device identifier of the edge computing device in association with the second device feature information registered by the edge computing device.
[0127] Further, to distinguish the location information of the second controlled devices registered by the edge computing device, the edge computing device sends the device identifier of the second controlled device and the location information of the second controlled device to the server when registering. Correspondingly, the registered second device feature information stored by the server includes the location information of the second controlled device corresponding to the device identifier of the second controlled device registered by the edge computing device.
[0128] S304, if the server confirms that the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, the server sends a login success instruction to the edge computing device.
[0129] The matching process can refer to the related description in the foregoing embodiments, which will not be repeated here.
[0130] In particular, before the edge computing device sends the login request, if the server indicates the to-be-verified second controlled device to the edge computing device through the information acquisition instruction, when the server compares the location information of the controlled device, it only needs to compare whether the location information of the at least one first controlled device matches the location information of the at least one to-be-verified second controlled device.
[0131] For example, it is detected whether the location information corresponding to the device identifier of the at least one first controlled device completely matches the location information corresponding to the device identifier of the at least one to-be-verified second controlled device or the matching degree exceeds a set threshold.
[0132] It can be understood that if the server confirms that the first cell identity matches the second cell identity and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, it indicates that the edge computing device is in a normal state and no state abnormality due to theft or loss has occurred. Based on this, it can be confirmed that the edge computing device has login permission, and accordingly, the server sends a login success indication to the edge computing device. As can be seen, the login success indication indicates that the edge computing device has the permission to log in to the server.
[0133] S305, after the edge computing device receives the login success indication, the edge computing device sends a key request to the server.
[0134] After the edge computing device receives the login success indication, it can be confirmed that the edge computing device is not in an abnormal state and has the permission to access the server, and naturally has the right to obtain key information from the server, so that the edge computing device can send a key request to the server.
[0135] The key request is used to request key information of the edge computing device.
[0136] S306, the server sends key information to the edge computing device in response to the key request.
[0137] After the edge computing device obtains the key information, the edge computing device can perform related operations for data decryption based on the key information.
[0138] For example, the key information is a key for decrypting encrypted data stored in the edge computing device, and the edge computing device uses the key information to decrypt the encrypted data.
[0139] For another example, the key information is a first key in the edge computing device for decrypting a second key, and the first key can be used to decrypt the encrypted second key to obtain the decrypted second key, and the second key is used to decrypt encrypted data in the edge computing device.
[0140] It can be understood that in any one of the above embodiments of the present application, the edge computing device can also detect whether its state is a registered state after starting. If the edge computing device has not completed registration, it needs to perform a registration operation to the server first.
[0141] For example, after the edge computing device is started, it is determined that the registration status of the edge computing device is the unregistered state, the edge computing device obtains the cell identifier of the wireless network accessed, that is, the second cell identifier; and the location information of each second controlled device accessed by the edge computing device is also obtained. On this basis, the edge computing device sends a registration request to the server, and the registration request carries the second device feature information to be registered by the edge computing device, and the second device feature information includes the second cell identifier corresponding to the edge computing device and the location information of each second controlled device.
[0142] After the server confirms that the edge computing device belongs to the edge computing device with registration permission configured, the second device feature information is stored as the second device feature information registered by the edge computing device. In addition, the server also sends a registration success indication to the edge computing device. After the edge computing device receives the registration success indication, it records the registration status as the registered state.
[0143] If the edge computing device starts and finds that it is in the registered state, the first device feature information can be obtained according to the foregoing operation and sent to the server to request the key information.
[0144] It can be understood that the edge computing device can be deployed with a disk partition for storing encrypted data before leaving the factory. At the same time, in order to enable the edge computing device to obtain the key information from the server after starting, the edge computing device can also be deployed with the required programs and software required in the present case before leaving the factory.
[0145] The edge computing device can be configured with a disk encryption standard, an encryption and decryption mechanism, and an encryption and decryption framework tool. The present application does not limit the disk encryption standard, the encryption and decryption mechanism, and the related encryption and decryption framework tool configured in the edge computing device.
[0146] For example, the edge computing device can be configured with Linux Unified Key Setup (LUKS), which is a general standard for Linux disk encryption. In this standard, the encryption-related setting information is stored in the partition header, so that data migration becomes simple. To configure an encrypted disk or partition using LUKS, the cryptsetup tool can be used in the edge computing device. Under this encryption standard, the specific of the encrypted disk is that the key information for decrypting the encrypted encryption key of the partition header needs to be obtained every time the edge computing device is restarted or the disk is remounted.
[0147] In order to enable the edge computing device to automatically obtain the key information for decrypting the encryption key without user intervention, the network bound disk encryption (NBDE) technology can also be adopted on the edge computing device. Based on this, the Clevis automatic decryption framework tool can also be adopted on the edge computing device to realize automatic decryption of the logical volume of the disk partition.
[0148] In order to facilitate understanding of the scheme of the present application, the scene to which the key acquisition and transmission method of the present application is applied is introduced. As shown in Figure 4 The scheme of the present application is shown in the composition architecture diagram of the key acquisition and transmission system to which the scheme of the present application is applied.
[0149] As shown in Figure 4 It can be seen that the system can include at least one edge computing device 401, and the edge computing device 401 can be connected to at least one controlled device 402 through wired or wireless means.
[0150] For example, the edge computing device 401 can be connected to the controlled device through a wired means such as RS-485 bus, or connected to the controlled device through a wireless network such as Zigbee, etc., without limitation.
[0151] The edge computing device 401 can be connected to the server 403 through a public wireless network. The server can be a cloud server, etc., without limitation.
[0152] For ease of understanding, an application scenario is described.
[0153] Taking the application scenario of the edge computing unit (NCU) in a photovoltaic power station controlling the inclination angle of the photovoltaic panel array as an example.
[0154] The current advanced photovoltaic power station will deploy edge computing devices that can adjust the inclination angle of the photovoltaic panel array according to the direction of maximum light intensity, combined with wind direction, wind speed and rain and snow conditions, to improve power generation efficiency and protect the photovoltaic panel from wind, rain and snow damage. The edge computing system of a photovoltaic power station is composed of multiple NCUs and their hanging sensors and tracking control units (TCUs). Based on this, in this scenario, Figure 4 The edge computing device in the middle is the NCU, and the controlled device connected by the edge computing device can be the sensor and TCU connected by the NCU.
[0155] The NCU (Neural Control Unit) is installed in a cabinet near a group of photovoltaic (PV) panel arrays and connects to a cloud-based maintenance and control backend via a public wireless network (e.g., 3G / 4G / 5G). Each NCU connects to several sensors and 100-200 TCUs (Transport Control Units) via wired (e.g., RS485 bus) or wireless (e.g., Zigbee network) connections. Each TCU is mounted on a PV panel array and reports its geographical location to the NCU. Simultaneously, based on NCU commands, the TCU can control motors to change the tilt angle of its PV panel array and collect the tilt status of the array, reporting it back to the NCU. The NCU calculates the optimal tilt angle for each TCU's connected PV panel array based on the geographical location reported by each TCU, the tilt angle of the PV panel array, the precise time obtained by the NCU from the network, wind direction and speed data collected from attached anemometers and other sensors, and sky photos captured by attached cameras. This calculation is then converted into control commands and sent to the TCU.
[0156] As the edge control hub, the NCU stores critical algorithm programs and data collected over several days by numerous connected TCUs, as well as certificates, accounts, and passwords used for interaction with servers such as the cloud management backend. Upon requests from applications on user terminals, the cloud management backend and other servers retrieve relevant historical data from the NCU, process it, and present it graphically to the user terminal applications.
[0157] Based on this, the key algorithm programs, historical data, certificates, accounts, passwords, etc. on the NCU are sensitive data for equipment manufacturers and users. They need to be encrypted and stored on the NCU, and it must be ensured that they cannot be decrypted and extracted even if the NCU is lost.
[0158] exist Figure 4 Based on this, the following section will illustrate the solution of this application by taking one case of key information required in an edge computing device as an example.
[0159] This example illustrates how an edge computing device encrypts a disk partition containing sensitive data using a pre-defined disk encryption standard and encryption / decryption mechanism (e.g., the Luks disk encryption standard and DM-Crypto encryption / decryption mechanism). In this case, the edge computing device's disk partition is used to store locally encrypted data, such as encrypted sensitive data. The key for encrypting the sensitive data (i.e., the second key) is encrypted and stored in the header of the disk partition. The key used to encrypt the key for encrypting the sensitive data (i.e., the second key) (i.e., the first key) needs to be obtained from the server. Therefore, each time the edge computing device boots up, it needs to obtain key information from the server to decrypt the encrypted key (encrypted second key) stored in the header of the edge computing device's disk partition using the obtained key information (i.e., the first key).
[0160] In this scenario, the edge computing device can be pre-configured with the above-mentioned disk encryption standard and encryption / decryption mechanism and related software programs such as encryption / decryption tools before leaving the factory. At the same time, the edge computing device needs to be hung on the disk partition, the file system needs to be established, and the initial sensitive files need to be encrypted and stored in the disk partition.
[0161] Before the edge computing device leaves the factory, the edge computing device needs to be started, and the edge computing device needs to request key information from the key server deployed in the factory, wherein the key information of the edge computing device configured in the key server deployed in the factory is consistent with the key information of the edge computing device stored in the server in the cloud.
[0162] On this basis, the edge computing device generates a new encrypted key by using the obtained key information and the initial key password configured in the edge computing device, and stores the new encrypted key in the header of the disk partition of the edge computing device, and deletes the initial key password. The encrypted key stored in the header of the disk partition is the key used to encrypt sensitive data and other data in the edge computing device, and in order to decrypt the encrypted key in the header of the disk partition, the key information obtained from the server needs to be used to decrypt the encrypted key.
[0163] In order to enable the edge computing device to actively register with the server, the registration status of the edge computing device needs to be set to unregistered before leaving the factory.
[0164] On this basis, the process of the edge computing device applying for registration with the server in the present application will be introduced below.
[0165] As shown in Figure 5 , a flow interaction schematic diagram of the edge computing device registering device feature information with the server according to an embodiment of the present application is shown.
[0166] The flow can include:
[0167] S501, after the edge computing device is started, if it is detected that the registration status is unregistered, the cell identifier of the wireless network currently accessed by the edge computing device and the device identifier and location information of each controlled device currently connected by the edge computing device are obtained.
[0168] In the registration stage, the edge computing device needs to collect and report the device identifier and location information of each controlled device connected by the edge computing device to the server, so that the server can analyze whether the controlled device is in an abnormal state based on the network state of the wireless network accessed by the edge computing device and the location of the connected controlled device.
[0169] S502, the edge computing device sends a registration request to the server.
[0170] The registration request carries the device identifier of the edge computing device, the cell identifier of the wireless network accessed by the edge computing device, the device identifiers of the controlled devices connected by the edge computing device, and the location information of the controlled devices.
[0171] S503, the server detects whether the device identifier of the edge computing device belongs to at least one edge device identifier configured with registration authority.
[0172] The edge device identifier configured with registration authority in the server is the device identifier of the edge computing device configured with registration authority in the server.
[0173] S504, if the device identifier of the edge computing device belongs to the edge device identifier configured with registration authority, the server stores the cell identifier corresponding to the device identifier of the edge computing device, the device identifiers of the controlled devices, and the location information of the controlled devices as the registered device feature information of the edge computing device.
[0174] It can be understood that the registered device feature information here is the second device feature information mentioned in other embodiments of the application.
[0175] For example, if the device identifier of the edge computing device belongs to the edge device identifier configured, it means that the edge computing device has registration authority. In this case, the server can determine the cell identifier, the device identifiers of the controlled devices, and the location information reported by the edge computing device as the registered device feature information of the edge computing device, and store it in association with the device identifier of the edge computing device.
[0176] S505, the server sends a registration success indication to the edge computing device.
[0177] The execution order of the operation of storing the registered device feature information of the edge computing device in step S504 is not limited to Figure 5 The operations of the two steps can be interchanged or executed synchronously.
[0178] In a possible implementation, in order to avoid repeated registration of the same edge computing device, the server can also store edge device identifiers with registration authority and not yet registered. On this basis, the server can delete the device identifier of the edge computing device from the edge device identifiers not yet registered at the same time or after sending the registration success indication to the edge computing device.
[0179] S506, the edge computing device receives the registration success indication, and updates the registration status of the edge computing device to a registered state.
[0180] S507, if the device identifier of the edge computing device does not belong to the configured device identifiers with registration authority, the edge computing device sends a registration exception prompt to the terminal device of the designated administrator.
[0181] The registration exception prompt can carry the device identifier of the edge computing device, and the registration exception prompt is used to prompt that the edge computing device does not have registration authority.
[0182] On this basis, the administrator can perform relevant processing based on the registration exception prompt in combination with the implementation situation.
[0183] For example, if the administrator confirms that the edge computing device has registration authority or hopes that the edge computing device registers to the server, the administrator can send a confirmation registration indication for the registration exception prompt to the server through the terminal device, and the confirmation registration indication is used to indicate that the edge computing device is allowed to register to the server. Correspondingly, after the server receives the confirmation registration indication, the cell identifier and the location information of the controlled device reported by the edge computing device can be stored as the registered device feature information of the edge computing device, and the server also sends a registration success indication to the edge computing device.
[0184] If the administrator confirms that the edge computing device does not have registration authority, the administrator can also send a rejection indication for the registration exception prompt to the server through the terminal device, and the rejection indication is used to indicate that the edge computing device is not allowed to register to the server. Correspondingly, the server rejects the registration of the edge computing device in response to the rejection indication.
[0185] Of course, the server can also send a disapproval registration indication to the edge computing device. After the edge computing device receives the disapproval registration indication, the registration status of the edge computing device is still maintained as an unregistered state.
[0186] Generally, after the edge computing device is registered successfully, the edge computing device can also be restarted to obtain key information from the server.
[0187] On the basis of Figure 4 and Figure 5 , the key acquisition and transmission method of the present application will be introduced in combination with an implementation manner.
[0188] As shown in Figure 6 , another flow interaction schematic diagram of the key acquisition and transmission method provided by the embodiment of the present application is shown, and the method of the embodiment can include:
[0189] S601, after the edge computing device is started, it is detected that the edge computing device is in a registered state, and the edge computing device establishes a communication connection with the server.
[0190] The process of establishing a communication connection here can be to establish a communication connection channel to provide necessary support for the edge computing device to send a login request and transmit data to the server subsequently.
[0191] S602, the server confirms that the edge computing device is a registered edge computing device, and sends an information acquisition instruction to the edge computing device.
[0192] For example, the edge computing device carries the device identifier of the edge computing device when initiating the connection request, and the server queries whether the device identifier of the edge computing device is a registered device identifier or whether there is registered device feature information corresponding to the device of the edge computing device based on the device identifier of the edge computing device. If so, it is confirmed that the edge computing device is a registered edge computing device.
[0193] The information acquisition instruction is used to indicate the device identifier of at least one target controlled device to be verified. The device identifier of the at least one target controlled device belongs to the device identifier of at least one controlled device (i.e. the second controlled device) in the registered device feature information of the edge computing device.
[0194] The device identifier of the target controlled device indicated in the information acquisition instruction can be the port number of the target controlled device, or the device serial number of the target controlled device, etc., which is not limited.
[0195] It can be understood that the number of controlled devices connected by the edge computing device will be large, and therefore the data of the device identifiers of the registered controlled devices in the edge computing device will also be large. In order to reduce the number of data information of the controlled devices reported by the edge computing device in the login introduction, the at least one target controlled device can be part of the at least one controlled device registered by the edge computing device.
[0196] For example, the server can select a certain proportion or a certain number of controlled devices from the at least one controlled device registered by the edge computing device as target controlled devices. The certain proportion can be set as needed, for example, the certain proportion can be 10%. Similarly, the certain number can also be set as needed, and the certain number is generally much smaller than the total number of controlled devices actually connected by the edge computing device when registering.
[0197] For example, the server can select 10 device identifiers of controlled devices from the device identifiers of the controlled devices registered by the edge computing device as the device identifiers of the target controlled devices to be verified each time.
[0198] S603, the edge computing device obtains the location information of each target controlled device connected to the edge computing device based on the device identifier of each target controlled device.
[0199] In this embodiment, the edge computing device only needs to obtain the location information of the target controlled device to be verified as indicated by the server, and does not need to obtain the location information of other controlled devices connected to the edge computing device that are not the target controlled device to be verified.
[0200] S604, the edge computing device obtains the cell identifier of the wireless network currently accessed by the edge computing device.
[0201] The cell identifier obtained in this step is the same as the first cell identifier mentioned in the previous embodiments of this application.
[0202] S605, the edge computing device sends a login request to the server.
[0203] The login request carries the device identifier of the edge computing device, the cell identifier of the currently accessed wireless network, and the device identifiers and location information of each target controlled device connected to the edge computing device.
[0204] S606, the server obtains the registered device characteristic information of the edge computing device based on the device identifier of the edge computing device.
[0205] The server can store the registered device feature information corresponding to the device identifier of each registered edge computing device. Therefore, based on the identifier information of the edge computing device, the registered device feature information of the edge computing device can be determined.
[0206] As mentioned above, the registered device characteristic information of the edge computing device includes: the cell identifier of the wireless network accessed by the edge computing device when it is registered, and the device identifiers and location information of all controlled devices connected to the edge computing device.
[0207] S607, the server determines the degree of information matching between the cell identifier reported by the edge computing device and the device identifier and location information of each target controlled device and the cell identifier and device identifier and location information of each target controlled device in the registered device feature information.
[0208] In one possible implementation, the server can query the geographical location corresponding to the cell identifier reported by the edge computing device, and at the same time determine the geographical location corresponding to the cell identifier registered by the edge computing device. If the location difference between the geographical location corresponding to the cell identifier reported by the edge computing device and the geographical location information corresponding to the registered cell identifier is less than a preset distance threshold, then it is determined that the reported cell identifier matches the registered cell identifier.
[0209] For the device identifier and the location information of each target controlled device reported by the edge computing device, whether the reported location information of the target controlled device matches the registered location information of the target controlled device can be determined for the device identifier of each target controlled device, and then a matching proportion of the target controlled device with the matched location information is determined. Based on the matching proportion of the current reported target controlled device and the registered target controlled device, a matching degree of the location information of each target controlled device and the location information of the registered target controlled device is determined.
[0210] The information matching degree can be determined by the matching degree of the current reported cell identifier and the registered cell identifier, and the matching degree of the location information of the current reported target controlled device and the registered target controlled device. For example, the matching degree of the cell identifier and the matching degree of the location information can each correspond to a weight, and the information matching degree can be determined by combining the matching degrees of the two dimensions.
[0211] S608, if the information matching degree exceeds the set threshold, the server sends a login success indication to the edge computing device.
[0212] In an optional manner, if the information matching procedure exceeds the set threshold, the server can also update the location information of each target controlled device in the device feature information registered by the edge computing device based on the location information of each target controlled device reported by the edge computing device.
[0213] S609, the edge computing device sends a key request to the server.
[0214] In a possible implementation manner, the edge computing device can run a login client of a login application and a decryption and encryption application. For example, the decryption and encryption application can be a Clevis program. The operations performed by the edge computing device in the above steps S601 to S608 can be performed by the login client. After the login client obtains the login success indication, the login client can call the decryption and encryption application, such as the Clevis program. On this basis, the Clevis program or other decryption and encryption application can send a key request for obtaining key information to the login client, and the key request can be a post message based on HTTP. The login client of the edge computing device can encapsulate the key request and send it to the server through a public wireless network.
[0215] S610, the server sends a first key to the edge computing device.
[0216] S611, the edge computing device decrypts the second key encrypted by the disk partition header based on the first key, and obtains the decrypted second key.
[0217] For example, the server can send the first key to the login client of the edge computing device after encapsulation, and the login client can send the first key to the Clevis program or other encryption and decryption application after extracting the first key. The Clevis program or other encryption and decryption application can use the first key to decrypt the encrypted second key in the disk partition header of the edge computing device to obtain the second key.
[0218] It can be understood that after obtaining the second key, the edge computing device can use the second key to decrypt the encrypted sensitive data in the disk partition. Details are not described herein again.
[0219] It can be understood that similar to the previous embodiment, if the server confirms that the matching degree of the cell identifier reported by the edge computing device and the location information of the target controlled device with the registered cell identifier and the location information of the target controlled device is lower than the set threshold, the server can also send a reminder message to the terminal device of the designated administrator, and the reminder message is used to prompt that the edge computing device does not have access permission. In this case, the administrator can also process the reminder message. Details are described above and are not described herein again.
[0220] In another possible implementation, the edge computing device can generate a check value (such as an MD5 value) based on the device identifiers and location information of the registered controlled devices when registering with the server. In a specific implementation, the edge computing device can also divide the controlled devices connected thereto into a plurality of controlled device groups, and each controlled device group includes at least one controlled device. On this basis, for each controlled device group, the edge computing device can calculate a first check value based on the reported location information of each controlled device in the controlled device group.
[0221] Further, after obtaining the login success indication, the edge computing device can further obtain the device identifiers and location information of other first controlled devices connected to the edge computing device and not belonging to the target controlled device. After the edge computing device obtains the device identifiers and location information of all the first controlled devices connected thereto, for each controlled device group, the edge computing device calculates a second check value corresponding to the controlled device group based on the current location information of each controlled device in the controlled device group.
[0222] If the edge computing device detects that the second check value of the controlled device group is different from the first check value, the edge computing device can send a registration information update request to the server, and the registration information update request is used to request to update the location information of the registered controlled devices. Meanwhile, the registration update request can carry the location information of each controlled device in the controlled device group in which the check value changes.
[0223] Correspondingly, if the server detects that the matching degree between the position information of each controlled device in the controlled device group and the position information of each controlled device in the registered device feature information exceeds a set threshold, the server can update the position information of each controlled device in the registered controlled device group by using the position information of each controlled device in the controlled device group reported by the edge computing device.
[0224] Further, after the server updates the position information of each controlled device in the registered controlled device group, the server can also send an update success indication to the edge computing device. Correspondingly, in response to the update success indication, the edge computing device can update the first check value of the controlled device group to the second check value of the controlled device group.
[0225] Corresponding to the key transmission method provided in the present application, the present application also provides a key transmission device. As shown in the figure, it shows a component structure schematic diagram of the key transmission device provided by the embodiment of the present application. The device is applied to a server, and the device can include: Figure 7
[0226] The feature information obtaining unit 701 is configured to obtain the first device feature information sent by the edge computing device, and the first device feature information includes: a first cell identifier of a wireless network accessed by the edge computing device and position information of at least one first controlled device connected by the edge computing device;
[0227] The registration information determining unit 702 is configured to determine the second device feature information registered by the edge computing device, and the second device feature information includes: a second cell identifier of a wireless network accessed by the edge computing device and position information of at least one second controlled device connected by the edge computing device;
[0228] The key transmission unit 703 is configured to send key information to the edge computing device if the first cell identifier matches the second cell identifier and the position information of the at least one first controlled device matches the position information of the at least one second controlled device.
[0229] In a possible implementation, the device further includes:
[0230] The indication sending unit is configured to, before the feature information obtaining unit obtains the first device feature information sent by the edge computing device, detect that the edge computing device establishes a communication connection with the server, and send an information acquisition indication to the edge computing device, the information acquisition indication being used to indicate at least one target controlled device to be verified, the at least one target controlled device belonging to the at least one second controlled device.
[0231] The key transmission unit determines that the location information of the at least one first controlled device matches the location information of the at least one second controlled device, specifically, determines that the location information of the at least one first controlled device matches the location information of the at least one target controlled device.
[0232] In yet another possible implementation, the key transmission unit determines that the location information of the at least one first controlled device matches the location information of the at least one second controlled device, specifically, determines that the matching degree of the location information of the at least one first controlled device and the location information of the at least one second controlled device exceeds a set threshold value.
[0233] The apparatus further comprises an information updating unit configured to update the location information of the at least one second controlled device in the registered second device feature information by using the location information of the at least one first controlled device at the same time or before the key transmission unit sends the key information to the edge computing device.
[0234] In yet another possible implementation, the information obtaining unit comprises:
[0235] The login request obtaining unit is configured to obtain a login request sent by the edge computing device, wherein the login request carries the first device feature information.
[0236] The apparatus further comprises:
[0237] The success indication unit is configured to send a login success indication to the edge computing device before the key transmission unit sends the key information to the edge computing device, if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device.
[0238] The key transmission unit comprises:
[0239] The key transmission sub-unit is configured to send key information to the edge computing device after obtaining the key request sent by the edge computing device.
[0240] In yet another possible implementation, the apparatus further comprises:
[0241] The registration request obtaining unit is configured to obtain a registration request sent by the edge computing device before the feature information obtaining unit obtains the device feature information sent by the edge computing device, wherein the registration request carries the second device feature information to be registered by the edge computing device.
[0242] The registration information storage unit is configured to store the second device feature information as second device feature information registered by the edge computing device if the edge computing device belongs to the configured edge computing device with registration authority.
[0243] In yet another possible implementation, the apparatus further includes:
[0244] The reminding unit is configured to send a reminding message to a terminal device of a designated manager if the first cell identifier does not match the second cell identifier or the location information of the at least one first controlled device does not match the location information of the at least one second controlled device, the reminding message being used to prompt that the edge computing device does not have access authority.
[0245] The approval processing unit is configured to update the second device feature information registered by the edge computing device by using the first device feature information if an approval access indication sent by the terminal device of the manager in response to the reminding message is received, and send the key information to the edge computing device.
[0246] According to the key acquisition method provided in the embodiments of the present application, the present application further provides a key acquisition apparatus.
[0247] As shown in Figure 8 , which shows a component structure diagram of the key acquisition apparatus provided in the embodiments of the present application. The apparatus is applied to an edge computing device, and the apparatus can include:
[0248] The feature acquisition unit 801 is configured to obtain the first device feature information of the edge computing device, the first device feature information including a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected by the edge computing device.
[0249] The feature sending unit 802 is configured to send the first device feature information to a server.
[0250] The key obtaining unit 803 is configured to obtain the key information returned by the server.
[0251] In a possible implementation, the apparatus further includes:
[0252] The connection establishing unit is configured to establish a communication connection between the edge computing device and the key server before the feature acquisition unit obtains the first device feature information of the edge computing device.
[0253] The indication obtaining unit is configured to obtain an information acquisition indication sent by the key server, the information acquisition indication being used to indicate a device identifier of at least one target controlled device to be verified.
[0254] The feature acquisition unit comprises:
[0255] The position acquisition sub-unit is configured to obtain position information of each target controlled device connected to the edge computing device based on the device identifier of the at least one target controlled device.
[0256] The identifier acquisition sub-unit is configured to determine a first cell identifier of a wireless network accessed by the edge computing device.
[0257] The feature generation sub-unit is configured to determine the position information of the at least one target controlled device as position information of at least one first controlled device to be sent, and generate first device feature information comprising the first cell identifier and the position information of the at least one first controlled device.
[0258] In another aspect, the present application also provides an electronic device, as shown in the accompanying drawings, which shows a schematic diagram of a constituent structure of the electronic device. The electronic device can be any type of electronic device, and the electronic device at least comprises a processor 901 and a memory 902. Figure 9 The processor 901 is configured to execute the key acquisition method, the key transmission method, or the key acquisition and transmission method in any one of the above embodiments.
[0259] The memory 902 is configured to store programs required by the processor for executing operations.
[0260] The memory 902 is configured to store programs required by the processor for executing operations.
[0261] It can be understood that the electronic device can further comprise a display unit 903 and an input unit 904.
[0262] Of course, the electronic device can also have more or fewer components, and is not limited in this regard. Figure 9
[0263] In another aspect, the present application also provides a computer readable storage medium, wherein at least one instruction, at least one program, a code set or an instruction set is stored in the computer readable storage medium. The at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the key acquisition method, the key transmission method, or the key acquisition and transmission method in any one of the above embodiments.
[0264] The present application also proposes a computer program, which comprises computer instructions stored in a computer readable storage medium. The computer program is used to execute the key acquisition method, the key transmission method, or the key acquisition and transmission method in any one of the above embodiments when the computer program is run on an electronic device.
[0265] It should be noted that each of the above -mentioned embodiments of the present specification adopts a progressive manner for description, and each embodiment focuses on the difference from other embodiments. The same and similar parts among the embodiments can be mutually referred to. Meanwhile, the features recorded in each embodiment of the present specification can be replaced or combined with each other, so as to enable or use the present application. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiments.
[0266] Finally, it should also be noted that in this paper, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or equipment. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or equipment including the element.
[0267] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
[0268] The above is only the preferred embodiment of the present application, and it should be noted that for ordinary skilled in the art, several improvements and refinements can be made without departing from the principles of the present application, and these improvements and refinements should be regarded as the protection scope of the present application.
Claims
1. A key transmission method applied to a server, comprising: obtaining first device feature information sent by an edge computing device, the first device feature information comprising: a first cell identity of a wireless network accessed by the edge computing device, and location information of at least one first controlled device connected by the edge computing device; determining second device feature information registered by the edge computing device, the second device feature information comprising: a second cell identity of a wireless network accessed by the edge computing device, and location information of at least one second controlled device connected by the edge computing device; wherein the second device feature information is stored in association with a device identity of the edge computing device; and if the first cell identity matches the second cell identity and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, sending key information to the edge computing device. 2.The method of claim 1, before the obtaining first device feature information sent by an edge computing device, further comprising: detecting that the edge computing device establishes a communication connection with the server, and sending an information acquisition instruction to the edge computing device, the information acquisition instruction being used to indicate at least one target controlled device to be verified, the at least one target controlled device belonging to the at least one second controlled device; the location information of the at least one first controlled device matching the location information of the at least one second controlled device comprises: the location information of the at least one first controlled device matching the location information of the at least one target controlled device. 3.The method of claim 1, the location information of the at least one first controlled device matching the location information of the at least one second controlled device comprises: a matching degree of the location information of the at least one first controlled device and the location information of the at least one second controlled device exceeding a set threshold; before or simultaneously with the sending of the key information to the edge computing device, further comprising: updating the location information of the at least one second controlled device in the registered second device feature information by using the location information of the at least one first controlled device. 4.The method of claim 1, the obtaining first device feature information sent by an edge computing device comprises: obtaining a login request sent by the edge computing device, the login request carrying the first device feature information; before the sending of the key information to the edge computing device, further comprising: sending a login success instruction to the edge computing device; the sending of the key information to the edge computing device comprises: after obtaining a key request sent by the edge computing device, sending the key information to the edge computing device. 5.The method of claim 1, before the obtaining of the device feature information sent by an edge computing device, further comprising: obtaining a registration request sent by the edge computing device, the registration request carrying second device feature information to be registered by the edge computing device. If the edge computing device belongs to the configured edge computing device with registration authority, the second device feature information is stored as the second device feature information registered by the edge computing device.
6. The method of claim 1, further comprising: If the first cell identifier does not match the second cell identifier or the location information of the at least one first controlled device does not match the location information of the at least one second controlled device, sending a reminder message to a terminal device of a designated supervisor, the reminder message prompting that the edge computing device does not have access authority; If an approval access indication sent by the terminal device of the supervisor in response to the reminder message is received, updating the second device feature information registered by the edge computing device with the first device feature information, and sending the key information to the edge computing device.
7. A key acquisition method applied to an edge computing device, comprising: obtaining first device feature information of the edge computing device at present, the first device feature information comprising a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected by the edge computing device; sending the first device feature information to a server to make the server determine second device feature information registered by the edge computing device, the second device feature information comprising a second cell identifier of a wireless network accessed by the edge computing device and location information of at least one second controlled device connected by the edge computing device; wherein the second device feature information is stored in association with a device identifier of the edge computing device; if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, sending key information to the edge computing device; obtaining the key information returned by the server.
8. The method of claim 7, before obtaining the first device feature information of the edge computing device at present, further comprising: establishing a communication connection between the edge computing device and the server; obtaining an information acquisition indication sent by the server, the information acquisition indication indicating a device identifier of at least one target controlled device to be verified; the obtaining of the first device feature information of the edge computing device at present comprises: based on the device identifier of the at least one target controlled device, obtaining location information of each of the target controlled devices connected by the edge computing device; determining a first cell identifier of a wireless network accessed by the edge computing device; determining the location information of the at least one target controlled device as location information of at least one first controlled device to be sent, and generating first device feature information comprising the first cell identifier and the location information of the at least one first controlled device.
9. A key transmission device applied to a server, comprising: The feature information obtaining unit is configured to obtain first device feature information sent by an edge computing device, the first device feature information comprising: a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected by the edge computing device; The registration information determining unit is configured to determine second device feature information registered by the edge computing device, the second device feature information comprising: a second cell identifier of a wireless network accessed by the edge computing device and location information of at least one second controlled device connected by the edge computing device; wherein the second device feature information is stored in association with a device identifier of the edge computing device; The key transmission unit is configured to send key information to the edge computing device if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device.
10. A key acquisition apparatus applied to an edge computing device, comprising: The feature obtaining unit is configured to obtain first device feature information of the edge computing device, the first device feature information comprising: a first cell identifier of a wireless network accessed by the edge computing device and location information of at least one first controlled device connected by the edge computing device; The feature sending unit is configured to send the first device feature information to a server, so that the server determines second device feature information registered by the edge computing device, the second device feature information comprising: a second cell identifier of a wireless network accessed by the edge computing device and location information of at least one second controlled device connected by the edge computing device; wherein the second device feature information is stored in association with a device identifier of the edge computing device; if the first cell identifier matches the second cell identifier and the location information of the at least one first controlled device matches the location information of the at least one second controlled device, key information is sent to the edge computing device; The key obtaining unit is configured to obtain the key information returned by the server.
Citation Information
Patent Citations
Lightweight Internet of Things security key negotiation method based on edge computing
CN112073379A
Location-based detection of unauthorized use of interactive computing environment functions
US20210282018A1