Network encryption machine concurrent communication method, system, electronic device and storage medium

By configuring a preset encryption library in the client that corresponds one-to-one with the terminal device, concurrent communication of the network encryption machine is realized, which solves the problem of low efficiency in the existing technology and ensures successful and efficient encrypted communication of multiple terminal devices.

CN115766124BActive Publication Date: 2025-12-09SHENZHEN CLOU ELECTRONICS +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211353909.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-01
Publication Date
2025-12-09
Estimated Expiration
2042-11-01

AI Technical Summary

Technical Problem

The encryption libraries provided by existing network encryption machine manufacturers can only retrieve data once at a time, resulting in low efficiency when the client communicates with multiple terminal devices, and data exchange errors during concurrent communication, leading to data loss on some terminal devices.

Method used

By configuring a preset encryption library in the client that corresponds one-to-one with multiple terminal devices, and using these encryption libraries to communicate concurrently with the network encryption machine, concurrent encryption parameters are generated and sent to the terminal devices through the corresponding preset encryption libraries, thus realizing synchronous or asynchronous encrypted communication between the client and multiple terminal devices.

Benefits of technology

It improves communication efficiency, avoids data errors when different terminal devices communicate in parallel, and ensures the successful completion of encryption operations independently by each terminal device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115766124B_ABST
    Figure CN115766124B_ABST
Patent Text Reader

Abstract

The application discloses a network encryption machine concurrent communication method and system, electronic equipment and a storage medium, and relates to the technical field of communication, wherein the network encryption machine concurrent communication method is configured with a preset encryption library corresponding to a plurality of terminal devices in a client, and communication data between the client and different terminal devices is transmitted to the network encryption machine for encryption through the corresponding preset encryption library, so that the client realizes the function of simultaneously operating a plurality of terminal devices for encrypted communication at a time, and saves the result information of each operation to enable different terminal devices to successfully complete respective configuration requirements and other target operations. The application solves the problem of communication failure caused by data loss during concurrent communication, realizes concurrent synchronization or asynchronous use of the network encryption machine by the client, effectively improves the efficiency in large-scale communication production or testing of the terminal device, and saves costs.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a network encryption machine concurrent communication method and system, an electronic device and a storage medium. BACKGROUND

[0002] Electricity meters are applied in various aspects of people's daily life, such as residential places, office areas, commercial entertainment areas, etc. Various data in the electricity meters are closely related to enterprises or individuals. If the status of the electricity meters, such as electricity quantity, demand quantity, metering accuracy, pull-in and pull-out state of the control meter, etc., is stolen or tampered with by network hackers or other illegal persons, serious consequences will be caused.

[0003] At present, the State Grid, the Southern Power Grid or the competent units of local power grids have designed network encryption machines for communication of electricity meter type terminal devices, which are used to prevent intrusion by illegal persons. When an authorized user uses a client to communicate with a terminal device, the user only needs to interact with the network encryption machine through an encryption library provided by the network encryption machine manufacturer to encrypt relevant communication data in the interaction process. However, the encryption library provided by each network encryption machine manufacturer can only obtain data once at the same time. When the client communicates with multiple terminal devices, the client can only sequentially and successively encrypt the communication with each terminal device, which is low in execution efficiency. If concurrent communication is performed with multiple terminal devices, different terminal devices will be interleaved in different execution steps in the communication process, data interaction will be wrong, data of some terminal devices will be lost, and thus communication encryption will fail.

[0004] SUMMARY

[0005] The present application aims to at least solve one of the technical problems existing in the prior art. To this end, the embodiments of the present application provide a network encryption machine concurrent communication method and system, an electronic device and a storage medium, which can enable a client to perform concurrent synchronous or asynchronous encryption communication with multiple terminal devices.

[0006] In a first aspect, the embodiments of the present application provide a network encryption machine concurrent communication method, comprising:

[0007] Obtaining device information of one or more terminal devices, the terminal devices being one-to-one corresponding to a preset encryption library, the preset encryption library being in communication connection with the network encryption machine;

[0008] Obtaining operation information of each terminal device, the operation information including a device number and a current counter value;

[0009] Sending the device information and the operation information of each terminal device to the corresponding preset encryption library;

[0010] receiving first configuration parameters of each of the terminal devices generated by the preset encryption library according to the device information and the current counter value;

[0011] if the connection with the terminal device is successful, sending the first configuration parameters to the terminal device based on the device number;

[0012] receiving an analysis packet generated by the terminal device according to the first configuration parameters;

[0013] based on the analysis packet, obtaining configuration parameters according to configuration requirements, and sending the configuration parameters to the terminal device, so that the terminal device implements the configuration requirements by using the configuration parameters.

[0014] In some embodiments of the present application, before the device information of one or more terminal devices is obtained, the method comprises:

[0015] obtaining the number of terminal devices;

[0016] generating a corresponding number of preset encryption libraries according to the number of devices.

[0017] In some embodiments of the present application, the device information of one or more terminal devices is obtained, comprising:

[0018] obtaining the ESAM serial number of the terminal device, and storing the ESAM serial number in a first array;

[0019] obtaining the key version information of the terminal device, and storing the key version information in a second array.

[0020] In some embodiments of the present application, the preset encryption library comprises a master station session interface; and the sending of the device information and the operation information of each of the terminal devices to the corresponding preset encryption library comprises:

[0021] sending the device information and the operation information of each of the terminal devices to the master station session interface of the corresponding preset encryption library, so that the preset encryption library communicates with the network encryption machine through the master station session interface.

[0022] In some embodiments of the present application, the receiving of the first configuration parameters of each of the terminal devices generated by the preset encryption library according to the device information and the current counter value comprises:

[0023] receiving the first configuration parameters of each of the terminal devices returned by the preset encryption library by using the master station session interface, the first configuration parameters comprising one or more of a master station random number, application connection cipher text, or signature information.

[0024] In some embodiments of the present application, the configuration requirement comprises a configuration number and a configuration operation; and the obtaining of the configuration parameter according to the configuration requirement and the sending of the configuration parameter to the terminal device to enable the terminal device to implement the configuration requirement by using the configuration parameter based on the parsed message comprise:

[0025] obtaining a device number of the terminal device that needs to be configured, wherein the device number is the configuration number;

[0026] obtaining the configuration parameter returned by the network encryption machine by using the preset encryption library based on the configuration operation;

[0027] sending the configuration parameter to the terminal device based on the configuration number to enable the terminal device to implement the configuration requirement by using the configuration parameter for the configuration operation.

[0028] In some embodiments of the present application, the parsed message comprises one or more of vendor information, merchant preset information, authentication result information, and authentication additional information;

[0029] the vendor information comprises one or more of a vendor code, a software version number, a software version date, a hardware version number, a hardware version date, or vendor extension information;

[0030] the merchant preset information comprises one or more of a preset application layer protocol version number, a preset protocol consistency block, a preset function consistency block, a server sending frame maximum size, a server receiving frame maximum size, a server receiving frame maximum window size, a server maximum processable APDU size, or a preset application connection timeout;

[0031] the authentication result information comprises one or more of allowing establishment of an application connection or not allowing establishment of an application connection;

[0032] the authentication additional information comprises one or more of application session negotiation data returned by the terminal device, session negotiation MAC returned by the terminal device, or session key negotiation verification.

[0033] In a second aspect, the embodiments of the present application further provide a network encryption machine concurrent communication system, comprising a network encryption machine, a preset encryption library, a client, and a terminal device, wherein the preset encryption library is configured in the client, the client is in communication connection with one or more terminal devices, the preset encryption library corresponds to the terminal device one by one, and the preset encryption library is in communication connection with the network encryption machine;

[0034] the client obtains device information and operation information of the terminal device and sends the device information and the operation information to the network encryption machine by using the preset encryption library;

[0035] The client receives first configuration parameters generated by the network encryption machine according to the device information and the operation information, and sends the first configuration parameters to the terminal device;

[0036] The client receives a parsing packet generated by the terminal device according to the first configuration parameters;

[0037] The client sends the parsing packet and configuration requirements to the network encryption machine through the preset encryption library;

[0038] The client receives configuration parameters generated by the network encryption machine according to the parsing packet and the configuration requirements;

[0039] The client sends the configuration parameters to the terminal device, so that the terminal device implements the configuration requirements by using the configuration parameters.

[0040] In a third aspect, an electronic device is provided, which includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the network encryption machine concurrent communication method according to the first aspect of the present application is implemented.

[0041] In a fourth aspect, a computer readable storage medium is provided, which stores a program. When the program is executed by a processor, the network encryption machine concurrent communication method according to the first aspect of the present application is implemented.

[0042] The embodiments of the present application at least have the following beneficial effects: the embodiments of the present application provide a network encryption machine concurrent communication method, system, electronic device and storage medium, wherein the client simultaneously obtains device information and operation information of more than one terminal device, the operation information includes a device number and a current counter value of the terminal device, the client sends the obtained device information and operation information to a preset encryption library corresponding to the terminal device, the network encryption machine is connected with the preset encryption library, the network encryption machine concurrently encrypts the device information and operation information of different terminal devices to generate first configuration parameters of different terminal devices, and then sends the first configuration parameters to the client through the corresponding preset encryption library, after the client and the different terminal devices establish an application connection, the client sends the first configuration parameters to the corresponding terminal device according to the device number, the terminal device generates an analysis message according to the first configuration parameters and sends the analysis message to the client, the client analyzes the analysis message and obtains configuration parameters according to configuration requirements and sends the configuration parameters to the corresponding terminal device, and the terminal device completes the configuration requirements according to the configuration parameters. By establishing the preset encryption library corresponding to the different terminal devices, the client can synchronously or asynchronously concurrently communicate with multiple terminal devices, each terminal device independently performs communication encryption, the problem of data error in parallel communication of different terminal devices is avoided, and the communication encryption efficiency of the terminal device is effectively improved.

[0043] Additional aspects and advantages of the application will be set forth in part in the description which follows, and in part will become apparent to those skilled in the art upon examination of the following and / or by practice of the application. BRIEF DESCRIPTION OF DRAWINGS

[0044] The above and / or additional aspects and advantages of the present application will become apparent and be readily appreciated from the following description, including the accompanying drawings, in which:

[0045] Figure 1 is a flowchart of a network encryption machine concurrent communication method provided by an embodiment of the present application;

[0046] Figure 2 is a schematic diagram of a network encryption machine concurrent communication system provided by an embodiment of the present application;

[0047] Figure 3 is a flowchart before step S101 of Figure 1

[0048] Figure 4 is a flowchart of step S101 of Figure 1

[0049] Figure 5 is a flowchart of step S103 of Figure 1

[0050] Figure 6 is a flowchart of step S103 of Figure 1 ​​​the flowchart of step S107 of the network encryption machine;

[0051] Figure 7 is a schematic diagram of a network encryption machine concurrent communication system provided by another embodiment of the present application;

[0052] Figure 8 is a schematic diagram of a network encryption machine concurrent communication system provided by another embodiment of the present application;

[0053] Figure 9 is a schematic diagram of a network encryption machine concurrent communication system provided by another embodiment of the present application;

[0054] Figure 10 is a schematic diagram of an electronic device provided by an embodiment of the present application.

[0055] Reference signs: network encryption machine 1, preset encryption library 2, client 3, terminal device 4, electronic device 1000, processor 1001, memory 1002. DETAILED DESCRIPTION

[0056] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and cannot be used to limit the present application.

[0057] The embodiments of the present application will be described in detail below, and examples of the embodiments are shown in the drawings, in which the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are only used to explain the present application and cannot be understood as limiting the present application.

[0058] In the description of the present application, it should be understood that the orientation description, such as the orientation or position relationship indicated by up, down, front, back, left, right, etc. is based on the orientation or position relationship shown in the drawings, and is only for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the device or element indicated must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.

[0059] In the description of the present application, the meaning of several is one or more, and the meaning of multiple is more than two, greater than, less than, more than, etc. are understood as not including the number, and above, below, etc. are understood as including the number. If it is described as first, second, etc., it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features or the order of indicated technical features.

[0060] In the description of the present application, the words such as setting, installation, connection and the like should be understood in a broad sense, and the specific meanings of the words in the present application can be determined by the skilled in the art in combination with the specific content of the technical solutions.

[0061] In order to better understand the technical solutions provided in the present application, the terms appearing in the text are explained as follows:

[0062] Network encryption machine: In order to meet the relevant requirements of the state power department for the data transmission security protection of power metering equipment, the data encryption of national secret algorithm is adopted to realize the confidentiality and integrity of the regional data transmission between terminal equipment and client application software.

[0063] ESAM: Embedded Secure Access Module, the fee control intelligent electric energy meter should embed ESAM module for information exchange security authentication. When performing parameter setting, pre-storing electricity fee, information rewriting and issuing remote control command operation on the fee control intelligent electric energy meter through solid-state medium or virtual medium, security authentication through ESAM module is required, and data encryption and decryption processing is required to ensure the security and integrity of data transmission.

[0064] State Grid Corporation of China and Southern Power Grid Corporation require that the information communicated needs to be dynamically encrypted by the network encryption machine provided by them, and then sent to the electric meter. After a number of operations, the electric meter can be configured or the target data of the electric meter can be read, which effectively reduces the risk of stealing and illegal modification of electric meter data. The network encryption machine is a high-performance service computer device, which generally only allows encryption and decryption of power metering communication data, so it has its own operating system and application software. In order to prevent network hacker intrusion and also reduce the difficulty of use for authorized users, each network encryption machine manufacturer provides a network encryption software dynamic library for external operation, i.e. encryption library.

[0065] As a high-performance computer, the network encryption machine device itself supports client concurrent communication, but since the encryption library provided by each manufacturer does not open a memory data storage space, it can only obtain data once at the same time, and each target operation needs multiple communication operations between the client and the network encryption machine to complete. Specifically, when the client communicates with the meter, the data is provided to the encryption library, the encryption library transmits the data to the network encryption machine for encryption, returns the ciphertext data to the client, and the client sends the ciphertext data to the meter. The meter correctly parses and returns the first step completion information, and retains the return information. The client transends the return information and other meter information to the network encryption machine through the encryption library for encryption, returns the second step ciphertext data information to the client, and the client software again gives the ciphertext data to the meter, and so on until the target operation is completed. Therefore, the target operation of each meter must wait for the target operation of the previous meter to be completed step by step.

[0066] In this case, if the client performs concurrent communication with multiple meters, when the client completes the first step communication data operation with the second meter and saves the data returned by the encryption library, and then gives the network encryption machine the data saved by the client and the encryption library returned by the first meter, since the encryption library does not open a memory data storage space, the network encryption machine will lose the previous data, and instead encrypts the data of the second meter of the previous operation and transmits it to the encryption library of the client. The result is that the first meter receives the ciphertext data, decrypts it and finds that the stored key information does not match, resulting in communication failure, so the so-called concurrent communication of each meter can only be serially encrypted and communicated, which is low in efficiency.

[0067] Based on this, the embodiment of the application provides a network encryption machine concurrent communication method, system, electronic device and storage medium, which can enable the client to perform concurrent synchronous or asynchronous encryption communication operation with multiple terminal devices, and effectively improves the communication efficiency. The following embodiment takes the terminal device as a meter for description.

[0068] Referring to the network encryption machine concurrent communication method flowchart shown in Figure 1 The embodiment of the application provides a network encryption machine concurrent communication method, which is applied to an encryption system composed of a client, a network encryption machine and multiple terminal devices. Referring to the network encryption machine concurrent communication method flowchart shown in Figure 2The network encryption machine concurrent communication system schematic diagram is shown. In an embodiment, the network encryption machine concurrent communication encryption system includes a network encryption machine 1, a preset encryption library 2, a client 3, and a terminal device 4. The preset encryption library 2 is configured in the client 3. The client 3 is in communication connection with more than one terminal device 4. The preset encryption library 2 and the terminal device 4 are in one-to-one correspondence. The preset encryption library 2 is in communication connection with the network encryption machine 1. Specifically, when the client 3 communicates with five terminal devices 4 concurrently, the client 3 is configured to generate five corresponding preset encryption libraries 2. The network encryption machine 1 can concurrently receive and transmit and encrypt communication data through different preset encryption libraries 2 that work independently of each other, so as to realize concurrent communication of the network encryption machine. Therefore, the quantity relationship between the encryption systems can be represented as client 3: network encryption machine 1: terminal device 4 = 1:1:N. The network encryption machine concurrent communication method includes but is not limited to the following steps S101 to S107.

[0069] In step S101, the device information of more than one terminal device 4 is acquired. The terminal device 4 is in one-to-one correspondence with the preset encryption library 2. The preset encryption library 2 is in communication connection with the network encryption machine 1.

[0070] In an embodiment, the client 3 acquires the device information of the terminal device 4 that needs to be configured or other target operation. In the actual testing or production process of the terminal device 4, there are a large number of communication operations that need to be encrypted, such as configuration of the device number of the terminal device 4 by the client 3, configuration of the negotiation time limit, configuration of the asset management number, configuration of the turning current, configuration of the minimum current, and the like. Therefore, the number of terminal devices 4 is determined according to actual needs. Each terminal device 4 is in one-to-one correspondence with the preset encryption library 2. It can be understood that when the client 3 needs to concurrently communicate with three terminal devices 4, three preset encryption libraries 2 are generated in one-to-one correspondence with each terminal device 4. When the client 3 needs to concurrently communicate with five terminal devices 4, five preset encryption libraries 2 are generated in one-to-one correspondence with each terminal device 4. The preset encryption library 2 is in communication connection with the network encryption machine 1. The client 3 transmits the communication data that needs to be encrypted to the network encryption machine 1 through the preset encryption library 2 for encryption.

[0071] In step S102, the operation information of each terminal device 4 is acquired. The operation information includes the device number and the current counter value.

[0072] In an embodiment, the client 3 obtains the operation information of each terminal device 4, and the operation information includes the device number of the terminal device 4 with configuration requirements or other target operations. According to the device number, the client 3 can configure or perform other target operations on the corresponding terminal device 4. The operation information also includes the current counter value, according to which the client 3 can obtain the current state of the corresponding terminal device 4, and prepare for the next operation of the client 3 on the corresponding terminal device 4. It can be understood that the corresponding current counter value will also increase by one with each communication step of the client 3 and the terminal device 4.

[0073] In step S103, the device information and the current counter value of the corresponding terminal device 4 are sent to the network encryption machine 1 for encryption through different preset encryption libraries 2.

[0074] In an embodiment, after the client 3 and the network encryption machine 1 establish an application connection successfully, the preset encryption library 2 corresponding to each different terminal device 4 sends the corresponding device information and the current counter value to the network encryption machine 1 for encryption. The network encryption machine 1 encrypts and analyzes the device information and generates the corresponding operation result information according to the current counter value. The encrypted data and the operation result information are returned to the client 3. The client 3 stores each operation result information as a basis for the network encryption machine 1 to analyze and encrypt the communication data next time.

[0075] In step S104, the first configuration parameters of the corresponding terminal device 4 generated by the network encryption machine 1 are received through different preset encryption libraries 2.

[0076] In an embodiment, the ciphertext data formed after the network encryption machine 1 encrypts the communication data between the client 3 and the terminal device 4 for the first time is the first configuration parameter. It can be understood that the communication data between different terminal devices 4 and the client 3 will form different first configuration parameters after being encrypted by the network encryption machine 1. Therefore, the client 3 needs to receive the corresponding first configuration parameters through the preset encryption library 2 corresponding to each different terminal device 4.

[0077] In step S105, different first configuration parameters are sent to the corresponding terminal device 4 based on the device number.

[0078] In an embodiment, after the client 3 receives different first configuration parameters, it needs to send different first configuration parameters to the corresponding terminal device 4 according to the device number of the terminal device 4 obtained previously. Specifically, the client 3 generates a message by organizing the first configuration parameter and other terminal device 4 information related to actual needs, such as table address information, and sends it to the terminal device 4. It can be understood that each terminal device 4 has a unique device number, which ensures that different terminal devices 4 receive correct communication data through the device number.

[0079] Step S106, the terminal device 4 generates a parsing message according to the first configuration parameter.

[0080] In an embodiment, after the terminal device 4 receives the message containing the first configuration parameter, the message is parsed by the stored key information, and the communication request of the client 3 is determined according to the parsed first configuration parameter, and the parsed message is generated and sent to the client 3.

[0081] Step S107, based on the parsed message, the configuration parameter is obtained according to the configuration requirement and sent to the terminal device 4, so that the terminal device 4 realizes the configuration requirement by using the configuration parameter.

[0082] In this embodiment, after the client 3 receives the parsed message, it is parsed, the parsed data and the actual configuration requirement are formed into communication data, and are transmitted to the network encryption machine 1 through the corresponding preset encryption library 2, the network encryption machine 1 encrypts the received communication data to generate configuration parameters to the client 3, the client 3 generates a message after receiving the configuration parameter and sends it to the corresponding terminal device 4, and the terminal device 4 parses the received message according to the configuration parameter to realize the configuration requirement of the client 3.

[0083] It can be understood that the communication data is not limited to the parsed data and the configuration requirement, but also includes other related data, such as the operation result information of the last step or the address of the terminal device 4 and other related information. Further, the communication data of different terminal devices 4 and the client 3 will form different configuration parameters after being encrypted by the network encryption machine 1, so the client 3 receives the corresponding configuration parameters through the preset encryption library 2 corresponding to different terminal devices 4.

[0084] It can be understood that the communication steps between the client 3, the network encryption machine 1 and the different terminal devices 4 are determined according to the actual requirement, and the related communication data and the target operation are also determined according to the actual requirement. By setting the one-to-one correspondence between the different terminal devices 4 and the preset encryption library 2, the client 3, the network encryption machine 1 and the different terminal devices 4 can communicate concurrently, fully developing the running ability of the network encryption machine 1 as a high-performance computer, and effectively improving the communication efficiency.

[0085] Referring to Figure 3 In an embodiment, the above step S101 can further include but not limited to the following steps S201 to S202.

[0086] Step S201, obtaining the number of terminal devices 4.

[0087] In an embodiment, the client 3 needs to determine the number of terminal devices 4 for concurrent communication before communicating with different terminal devices 4. For example, the terminal devices 4 for communication can be determined according to actual configuration requirements or other target operations.

[0088] In step S202, a preset encryption library 2 corresponding to the number of devices is generated according to the number of devices.

[0089] In an embodiment, the client 3 generates a preset encryption library 2 corresponding to the number of devices according to the number of devices. It can be understood that when the client 3 needs to communicate with three terminal devices 4 concurrently, three preset encryption libraries 2 are configured to be generated; when the client 3 needs to communicate with five terminal devices 4 concurrently, five preset encryption libraries 2 are configured to be generated. Different preset encryption libraries 2 are placed in directories according to the hierarchical arrangement, and the implementation path of the code realizes that each preset encryption library 2 works independently at the same time.

[0090] It can be understood that the client 3 can also configure only one preset encryption library 2 to be generated. When communicating with multiple terminal devices 4 concurrently, a number of threads corresponding to the terminal devices 4 are started to communicate with the network encryption machine 1. This process only needs to be implemented through macro definition, and the program can call multiple preset encryption libraries 2 with the same function at the same time. The random number results, dispersion factors or MAC data generated by the preset encryption libraries 2 are independent of each other, thereby realizing the concurrent communication of the network encryption machine 1.

[0091] Whether in the actual testing or production process of the terminal device 4, such as configuring the device number of the terminal device 4, configuring the negotiation time limit, configuring the asset management number, configuring the turning current, configuring the minimum current, etc., or in the communication process between the client 3 and the network encryption machine 1, such as logging into the server permission, logging into the server, creating a random number, connecting the network encryption machine, main station session negotiation, authentication negotiation, reading data authentication, reporting data verification, secure transmission encryption and decryption, broadcast data encryption and decryption, setting ESAM parameter encryption, reading ESAM parameter verification, wallet operation, electric energy meter update symmetric key, software comparison encryption comparison, etc., all involve communication operations that need to be encrypted. Therefore, the client 3 is provided with a preset encryption library 2 corresponding to each terminal device 4, which realizes the concurrent encryption communication of the network encryption machine 1 and effectively improves the communication efficiency.

[0092] Referring to FIG. 1, Figure 4 In an embodiment, the above step S101 can further include, but is not limited to, the following steps S301 to S304.

[0093] In step S301, the ESAM serial number of the terminal device 4 is obtained.

[0094] In an embodiment, the client 3 communicates with the terminal device 4 to obtain the ESAM serial number, which is the unique identification number of the ESAM module. After the client 3 obtains the ESAM serial number of the terminal device 4, the ESAM module can be used. The ESAM module realizes secure storage, data encryption / decryption, two-way identity authentication, and other secure control transmission. The parameter setting, pre-stored fee, information rewriting, and other operations of the terminal device 4 need to pass through strict password verification or ESAM module security authentication to ensure the security and reliability of data transmission. Therefore, the client 3 obtaining the ESAM serial number of the terminal device 4 provides a guarantee for the secure transmission of data.

[0095] In step S302, the ESAM serial number is stored in the first array of the preset encryption library 2.

[0096] In an embodiment, after the client 3 obtains the ESAM serial numbers of different terminal devices 4, the ESAM serial numbers are stored in the first array of the preset encryption library 2 corresponding to the terminal devices 4. It can be understood that the first array is a memory array for storing ESAM serial numbers.

[0097] In step S303, the key version information of the terminal device 4 is obtained.

[0098] In an embodiment, the device information of the terminal device 4 further includes key version information. Different key versions correspond to different parsed ciphertext data. In order to ensure that the terminal device 4 successfully parses the encrypted communication data, the client 3 obtains the key version information of the terminal device, so that the network encryption machine 1 encrypts the communication data according to different key version information.

[0099] In step S304, the key version information is stored in the first array of the preset encryption library 2.

[0100] In an embodiment, after the client 3 obtains the key version information of different terminal devices 4, the key version information is stored in the second array of the preset encryption library 2 corresponding to the terminal devices 4. It can be understood that the second array is a memory array for storing key version information.

[0101] The client 3 obtains the device information corresponding to different terminal devices 4 and stores it in the memory array of the corresponding preset encryption library 2, which provides a basis and security guarantee for the encrypted communication between the client 3, the network encryption machine 1, and the plurality of terminal devices 4.

[0102] Referring to Figure 5 In an embodiment, the above step S103 can further include but is not limited to steps S401-S402.

[0103] In step S401, the device information and operation information of the terminal device 4 are sent to the main station session interface of the corresponding preset encryption library 2.

[0104] In an embodiment, different preset encryption libraries 2 store device information and operation information of different terminal devices 4, and the client 3 sends the device information and operation information of different terminal devices 4 to the host session interface of the corresponding preset encryption library 2, and the host session interface calls the underlying related functions, such as the host session negotiation function, as input conditions.

[0105] In step S402, the host session interface is used to communicate with the network encryption machine 1.

[0106] In an embodiment, the client 3 can communicate with the network encryption machine 1 through the host session interface of the preset encryption library 2. Specifically, the client 3 transmits the related communication data that needs to be encrypted to the network encryption machine 1 through the host session interface of the preset encryption library 2, and the network encryption machine 1 encrypts the communication data to form ciphertext data, which is returned to the client 3 through the corresponding host session interface of the preset encryption library 2.

[0107] The interaction between the client 3 and the network encryption machine 1 is performed through the host session interface of the preset encryption library 2, so that authorized users can achieve it without obtaining the underlying principles of the network encryption machine 1, effectively reducing the difficulty of use for authorized users, and preventing the intrusion of network hackers and other illegal persons.

[0108] In an embodiment, the client 3 receives the ciphertext data encrypted by the network encryption machine 1 from the communication data through the host session interface of the preset encryption library 2. It can be understood that when the ciphertext data is the first configuration parameter, it includes but is not limited to one or more of the host random number, the application connection ciphertext, or the signature information. Specifically, the host random number is the verification basis corresponding to the subsequent configuration state, the application connection ciphertext is the encrypted information of the application connection request between the client 3 and the terminal device 4, and the signature information is the signature array information of the client 3. Through the transmission of the ciphertext data, the security of the communication data is effectively guaranteed.

[0109] Referring to Figure 6 In an embodiment, the above step S107 can further include but is not limited to the following steps S501 to S503.

[0110] In step S501, the configuration number of the terminal device 4 that needs to be configured is obtained.

[0111] In an embodiment, the client 3 obtains the configuration number of the terminal device 4 that needs to be configured, that is, obtains the device number in the operation information of the terminal device 4, and according to the configuration number, the terminal device 4 that needs to be configured can be determined.

[0112] In step S502, the configuration parameter returned by the network encryption machine 1 is obtained according to the configuration operation in the configuration requirement.

[0113] In an embodiment, the configuration requirement information includes, in addition to the configuration number of the terminal device 4 to be configured, a configuration operation for configuring the terminal device 4, and the network encryption machine 1 returns the configuration parameters to the client 3 by encrypting the configuration operation. It can be understood that when the client 3 needs to configure the terminal device 4 with the device number, the client 3 obtains the device number to be set by scanning the nameplate or inputting, and the corresponding configuration operation information includes: the device number, the input symmetric key state, the ciphertext operation mode, the ESAM serial number, the session key, the master station random number, 4 bytes of InOAD+1 byte of content length+the device number to be set and other related information, which is transmitted to the network encryption machine 1 by calling the parameter function of the corresponding preset encryption library 2 for encryption. The configuration parameters formed after encryption include: return security identification type, security additional data, output data, MAC check data and other related information.

[0114] In step S503, the configuration parameters are sent to the terminal device 4 according to the configuration number, so that the terminal device 4 performs configuration operation with the configuration parameters to complete the configuration requirement.

[0115] In an embodiment, the client 3 determines the corresponding terminal device 4 according to the configuration number, and sends the received configuration parameters and other ciphertext data to the terminal device 4 in the form of a message. The terminal device 4 analyzes the message and performs configuration operation with the configuration parameters to complete the configuration requirement of the client 3. It can be understood that when the terminal device 4 successfully completes the configuration requirement, it returns the relevant identification state or random number to the client 3. For example, when the terminal device 4 successfully completes the configuration requirement, it returns the identification state of '1' to the client 3, and when the terminal device 4 fails to complete the configuration requirement, it returns the identification state of '0' to the client 3.

[0116] It can be understood that the client 3 can also use the preset encryption library 2 to transmit other related target operations, such as reading the target data of the terminal device 4, to the network encryption machine 1 for encryption, thereby ensuring the security and integrity of the communication data.

[0117] In one embodiment, the parsed message generated by the terminal device 4 based on the first configuration parameters includes one or more of the following: vendor information, merchant preset information, authentication result information, and authentication supplementary information. The vendor information includes one or more of the following: vendor code, software version number, software version date, hardware version number, hardware version date, or vendor extended information; the merchant preset information includes one or more of the following: preset application layer protocol version number, preset protocol consistency block, preset functional consistency block, maximum size of frames sent by the server, maximum size of frames received by the server, maximum window size of frames received by the server, maximum APDU size that the server can process, or preset application connection timeout time; the authentication result information includes: application connection allowed or application connection not allowed; the authentication supplementary information includes one or more of the following: application session negotiation data returned by the terminal device 4, session negotiation MAC returned by the terminal device 4, or session key negotiation verification.

[0118] Understandably, the information included in the parsed message corresponds to the target operation performed by client 3 on terminal device 4, and also to the communication data of network encryption device 1. Specifically, when client 3 wants to set the device number of terminal device 4, the parsed message includes authentication result information allowing the establishment of an application connection, application session negotiation data returned by terminal device 4, and additional authentication information such as session negotiation MAC or session key negotiation verification. Depending on the target operation performed on terminal device 4, the parsed message received by client 3 also differs, thus improving the confidentiality and security of communication between client 3, network encryption device 1, and terminal device 4.

[0119] Reference Figure 7 The schematic diagram of the concurrent communication system for the network encryption machine shown illustrates, in one embodiment, the communication process between client 3 and one of the terminal devices 4 as follows: Client 3 obtains device information and operation information from terminal device 4, and returns first configuration parameters to terminal device 4 based on the obtained information. Terminal device 4 parses the received first configuration parameters and responds, forming a corresponding parsing message which is sent to client 3. Client 3 returns configuration parameters to terminal device 4 based on the parsing message and the configuration requirements for terminal device 4. Terminal device 4 uses the received and parsed configuration parameters to fulfill the configuration requirements of client 3. It can be understood that after successfully fulfilling the configuration requirements, terminal device 4 returns a corresponding identifier status or random number to client 3.

[0120] Reference Figure 8The network encryption machine concurrent communication system schematic diagram shown, in an embodiment, the interaction between the client 3 and the network encryption machine 1 is realized through the preset encryption library 2, specifically, the client 3 transmits the device information and operation information of the terminal device 4 obtained through the corresponding preset encryption library 2 to the network encryption machine 1, the network encryption machine encrypts the received communication data to form ciphertext data, that is, the first configuration parameter, and returns to the client 3 through the corresponding preset encryption library 2, and the client 3 transmits the parsed message data and related target operation data, that is, the configuration operation information, received and parsed to the network encryption machine 1 through the preset encryption library 2, and the network encryption machine 1 continues to encrypt the received communication data to form ciphertext data, that is, the configuration parameter, and returns to the client 3 through the preset encryption library 2. It can be understood that the interaction steps of the client 3 and the network encryption machine 1 are determined according to the specific target operation, and are not limited to the above steps, and the target operation of the terminal device 4 is completed step by step through a similar iterative process.

[0121] Referring to Figure 9 The network encryption machine concurrent communication system schematic diagram shown, in an embodiment, the communication process of the network encryption machine 1, the client 3 and the terminal device 4 is specifically that the client 3 generates a preset encryption library 2 corresponding to the terminal device in the memory, transmits the device information and operation information obtained to the network encryption machine 1 through the preset encryption library 2, receives the communication data encrypted by the network encryption machine 1, that is, the first configuration parameter, through the preset encryption library 2, and sends it to the terminal device 4, and the terminal device 4 returns the parsed message corresponding to the terminal device to the client 3, and the client 3 analyzes the parsed message, combines the configuration requirements of the terminal device 4, continues to transmit to the network encryption machine 1 through the preset encryption library 2 for encryption, receives the encrypted communication data, that is, the configuration parameter, through the preset encryption library 2, and sends it to the terminal device 4, and the terminal device 4 realizes the corresponding configuration requirements according to the parsed configuration parameter, and returns the corresponding identification state or random number after successful completion to the client 3.

[0122] Specifically, the device information of the terminal device 4 includes ESAM serial number, key version information, etc., and the operation information includes device number, current counter value, etc., and when the client 3 communicates with the terminal device 4 through the network encryption machine 1 every step, the current counter value will increase. The first configuration parameter encrypted by the network encryption machine 1 includes the master station random number, the application connection ciphertext and the client 3 signature array information, and the parsed message formed by the terminal device 4 after obtaining the first configuration parameter can include one or more of manufacturer information, merchant preset information, authentication result information or authentication additional information according to actual requirements, and further, the network encryption machine 1 generates the configuration parameter of the configuration requirements of the client 3 based on this, including output data, MAC check data, security additional data, etc.

[0123] It can be understood that when the client 3 has a configuration requirement for the terminal device 4, such as setting a device number, setting a negotiation time limit, setting an asset management number, setting a turning current, or setting a minimum current, and other configuration operations, the client 3 obtains the device number, the negotiation time limit, the asset management number, the turning current, the minimum current, and other related information to be set through scanning a nameplate or inputting, and the network encryption machine generates corresponding configuration parameters in combination with a parsing message so that the terminal device 4 performs configuration according to a target operation. Further, if the terminal device 4 successfully completes the configuration requirement, the terminal device 4 returns an identification state of '1' to the client 3, and if the terminal device 4 fails to complete the configuration requirement, the terminal device 4 returns an identification state value of '0' to the client 3.

[0124] The client 3 interacts with the network encryption machine 1 through the preset encryption library 2 corresponding to each of the plurality of terminal devices 4, and performs communication in parallel, thereby solving the problem that the client 3 can only perform serial operation on different terminal devices 4, and effectively improving the efficiency of communication and operation.

[0125] Figure 10 An electronic device 1000 provided by an embodiment of the present application is shown. The electronic device 1000 includes a processor 1001, a memory 1002, and a computer program stored in the memory 1002 and executable on the processor 1001, and the computer program is configured to execute the network encryption machine concurrent communication method described above when executed.

[0126] The processor 1001 and the memory 1002 can be connected through a bus or other means.

[0127] The memory 1002 is a non-transitory computer readable storage medium, and can be used to store non-transitory software programs and non-transitory computer executable programs, such as the network encryption machine concurrent communication method described in the embodiments of the present application. The processor 1001 executes the non-transitory software programs and instructions stored in the memory 1002, thereby implementing the network encryption machine concurrent communication method described above.

[0128] The memory 1002 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; and the data storage area can store the network encryption machine concurrent communication method described above. In addition, the memory 1002 can include a high-speed random access memory 1002, and can also include a non-transitory memory 1002, such as at least one storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory 1002 can optionally include a memory 1002 remotely arranged with respect to the processor 1001, and these remote memories 1002 can be connected to the electronic device 1000 through a network. Examples of the network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0129] The non-transitory software programs and instructions required to implement the network encryption machine concurrent communication method described above are stored in the memory 1002, and when executed by one or more processors 1001, perform the network encryption machine concurrent communication method described above, for example, perform the method steps S101 to S107 in Figure 1 , the method steps S301 to S304 in Figure 4 , the method steps S501 to S503 in Figure 6 .

[0130] The embodiments of the present application also provide a storage medium, which is a computer readable storage medium, and the storage medium stores a computer program. The computer program is executed by a processor to implement the network encryption machine concurrent communication method described above. The memory is a non-transitory computer readable storage medium, and can be used to store non-transitory software programs and non-transitory computer executable programs. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory disposed remotely with respect to the processor, and these remote memories can be connected to the processor through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0131] The network encryption machine concurrent communication method, system, electronic device and storage medium provided by the embodiments of the present application can realize simultaneous operation of multiple terminal devices for encryption communication by configuring a preset encryption library corresponding to each terminal device in the client, and transmitting the communication data between the client and different terminal devices to the network encryption machine through the corresponding preset encryption library for encryption, so that the client can realize encryption communication of multiple terminal devices at the same time, and save the result information of each operation to make different terminal devices complete their own target operation smoothly. The problem of data loss of part of the terminal devices caused by interleaved execution between different terminal devices in related technologies, data interaction error, and communication encryption failure is solved. The client can use the network encryption machine concurrently, synchronously or asynchronously, which effectively improves the efficiency and saves the cost in large-scale communication production or testing of terminal devices.

[0132] The device embodiments described above are only schematic, and the units described as separate components can or can not be physically separate, that is, they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0133] Those of ordinary skill in the art will appreciate that all or certain steps, systems of the methods disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Certain physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application specific integrated circuit. Such software can be distributed on computer readable media, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, storage devices storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. Further, it should be appreciated by those skilled in the art that communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism and includes any information delivery media.

[0134] It should also be appreciated that various embodiments provided by the present application can be combined in any manner to achieve different technical effects. The above is a specific description of the preferred embodiments of the present application, but the present application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the present application.

Claims

1. A network encryptor concurrent communication method characterized by, The method comprises the following steps: obtaining device information of one or more terminal devices, the terminal devices corresponding to preset encryption libraries one by one, the preset encryption libraries being in communication connection with the network encryption machine; obtaining operation information of each terminal device, the operation information comprising a device number and a current counter value; sending the device information and the operation information of each terminal device to the corresponding preset encryption library; receiving first configuration parameters of each terminal device generated by the preset encryption library according to the device information and the current counter value; if the connection with the terminal device is successful, sending the first configuration parameters to the terminal device based on the device number; receiving an analysis packet generated by the terminal device according to the first configuration parameters; based on the analysis packet, obtaining configuration parameters according to configuration requirements, and sending the configuration parameters to the terminal device, so that the terminal device implements the configuration requirements by using the configuration parameters.

2. The method of claim 1, wherein, Before the step of obtaining device information of one or more terminal devices, the method comprises the following steps: obtaining the number of terminal devices; generating a corresponding number of preset encryption libraries according to the number of terminal devices.

3. The method of claim 1, wherein the network encryption machine concurrently communicates. The step of obtaining device information of one or more terminal devices comprises the following steps: obtaining an ESAM serial number of the terminal device, and storing the ESAM serial number in a first array; obtaining key version information of the terminal device, and storing the key version information in a second array.

4. The method of claim 3, wherein the network encryption machine concurrently communicates, The preset encryption library comprises a master station session interface; the step of sending the device information and the operation information of each terminal device to the corresponding preset encryption library comprises the following steps: ​ sending the device information and the operation information of each terminal device to the master station session interface of the corresponding preset encryption library, so that the preset encryption library communicates with the network encryption machine through the master station session interface.

5. The method of claim 4, wherein the network encryption machine concurrently communicates, The step of receiving first configuration parameters of each terminal device generated by the preset encryption library according to the device information and the current counter value comprises the following steps: ​ receiving first configuration parameters of each terminal device returned by the preset encryption library through the master station session interface, the first configuration parameters comprising one or more of a master station random number, application connection ciphertext or signature information.

6. The method of claim 1, wherein the network encryption machine concurrently communicates. The configuration requirements comprise a configuration number and a configuration operation; the step of obtaining configuration parameters according to configuration requirements based on the analysis packet, and sending the configuration parameters to the terminal device, so that the terminal device implements the configuration requirements by using the configuration parameters, comprises the following steps: obtaining the device number of the terminal device that needs to be configured, the device number being the configuration number; obtaining configuration parameters returned by the network encryption machine using the preset encryption library based on the configuration operation; based on the configuration number, sending the configuration parameters to the terminal device, so that the terminal device performs the configuration operation by using the configuration parameters, and implements the configuration requirements.

7. The method of claim 1, wherein the network encryption machine concurrently communicates. The analysis packet comprises one or more of vendor information, merchant preset information, authentication result information and authentication additional information. The vendor information includes one or more of a vendor code, a software version number, a software version date, a hardware version number, a hardware version date, or vendor extension information; The merchant preset information includes one or more of a preset application layer protocol version number, a preset protocol conformance block, a preset function conformance block, a server sending frame maximum size, a server receiving frame maximum size, a server receiving frame maximum window size, a server maximum processable APDU size, or a preset application connection timeout time; The authentication result information includes one or more of allowing establishment of an application connection or not allowing establishment of an application connection; The authentication additional information includes one or more of application session negotiation data returned by the terminal device, session negotiation MAC returned by the terminal device, or session key negotiation verification.

8. A network concurrent communication system comprising a network encryptor, a preset encryption library, a client, and a terminal device, characterized in that, The preset encryption library is configured in the client, the client is in communication connection with more than one terminal device, the preset encryption library corresponds to the terminal device one by one, and the preset encryption library is in communication connection with the network encryption machine; The client obtains device information and operation information of the terminal device and sends the device information and the operation information to the network encryption machine by using the preset encryption library; The client receives first configuration parameters generated by the network encryption machine according to the device information and the operation information, and sends the first configuration parameters to the terminal device; The client receives a parsing message generated by the terminal device according to the first configuration parameters; The client sends the parsing message and configuration requirements to the network encryption machine by using the preset encryption library; The client receives configuration parameters generated by the network encryption machine according to the parsing message and the configuration requirements; The client sends the configuration parameters to the terminal device, so that the terminal device implements the configuration requirements by using the configuration parameters.

9. An electronic device, comprising: The memory stores a computer program, and the processor implements the network encryption machine concurrent communication method in any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, The storage medium stores a program, and the program is executed by the processor to implement the network encryption machine concurrent communication method in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Power consumption information acquisition master station system based on distributed technology

    CN111432295A

  • Data processing method, server, client and encryption machine

    CN112861148A