Security operation method and system, server, operation equipment and intelligent terminal

CN116346426BActive Publication Date: 2026-09-15BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310190458.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-23
Publication Date
2026-09-15
Estimated Expiration
2043-02-23

AI Technical Summary

Technical Problem

[0004](1)静态密码是最简便的身份认证方式,然而也是风险最高的方式,容易受到网络钓鱼、暴力破解、撞库等攻击;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116346426B_ABST
    Figure CN116346426B_ABST
Patent Text Reader

Abstract

The application relates to the field of electric power, and discloses a safe operation and maintenance method and system, a server, an operation and maintenance device and an intelligent terminal. The safe operation and maintenance method suitable for the server comprises the following steps: in response to a first session request initiated by the operation and maintenance device, negotiating a first combined algorithm matched with a security level with the operation and maintenance device; in response to a channel access request initiated by the operation and maintenance device, performing access authentication based on the operation and maintenance device identifier, the terminal identifier and the first combined algorithm; if the access authentication is successful, generating a session key based on the operation and maintenance device identifier, the terminal identifier and the first combined algorithm, and delivering the session key to the operation and maintenance device; and in response to a second session request initiated by the terminal, delivering the session key to the terminal, so that the terminal and the operation and maintenance device establish a session based on the session key and a second combined algorithm, thereby the application proposes a cipher system of a session, a key and a set of combined algorithms, so that a safe session between the operation and maintenance device and the terminal can be established without changing the convenient experience of operation and maintenance personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power, and more specifically to a safe operation and maintenance method and system, server, operation and maintenance equipment and intelligent terminal. Background Technology

[0002] Information security requires confidentiality, integrity, and non-repudiation, specifically manifested in the following key aspects: authentication, data protection, tamper-proofing, and non-repudiation. In existing technologies, cryptography (stream ciphers, block ciphers, public-key cryptography, reversible encryption transformations, keyed hash functions (such as OTP), etc.) all exist in the form of algorithms and keys. The algorithm is common, but different users use different keys. In practice, the algorithm may or may not be public, but the key (user's private key) must always be kept secret to achieve information protection.

[0003] A complete technical system is generally built upon a combination of public-key cryptography and symmetric-key cryptography, that is, an information security system based on a PKI architecture. To achieve the ideal security of this system, users must protect their private keys; however, traditional security methods have limitations.

[0004] (1) Static passwords are the simplest way to authenticate an identity, but they are also the riskiest, as they are vulnerable to phishing, brute-force attacks, and credential stuffing attacks.

[0005] (2) SMS verification code is currently the most widely used and accepted mobile authentication method. However, its session security level is low, the transaction risk is high, and the transaction cost is increased.

[0006] (3) Hardware security products, such as USB keys and dynamic password generators, inevitably suffer from inconvenience in carrying and complexity in operation, regardless of their form or usage, resulting in low user acceptance. Even more problematic is the extreme difficulty in management, as they involve mobile phone manufacturers, telecommunications operators, and service providers.

[0007] (4) Although soft tokens solve the problem of hardware carrying to some extent, the security of user private keys will be greatly reduced without the protection of a security chip due to the use of traditional cryptographic algorithms, which cannot meet regulatory requirements.

[0008] In low-voltage power distribution IoT, the various terminals are scattered along with the transformers, lacking boundary protection. The private key, serving as the security root, is difficult to store and is easily compromised. During operation, smart terminals require parameter settings, upgrades, and fault handling. On-site maintenance necessitates the use of handheld devices, which, being mobile devices, also face the challenge of storing private keys. This increases the risks during maintenance (e.g., unauthorized access and eavesdropping on data communication). Summary of the Invention

[0009] The purpose of this invention is to provide a secure operation and maintenance method and system, server, operation and maintenance equipment and smart terminal. It proposes a cryptographic system of one session, one key and one set of combined algorithms, so as to establish a secure session between operation and maintenance equipment and smart terminal without changing the user experience of operation and maintenance personnel.

[0010] To achieve the above objectives, a first aspect of the present invention provides a secure operation and maintenance method applicable to servers. The secure operation and maintenance method includes: responding to a first session request initiated by an operation and maintenance device, negotiating with the operation and maintenance device a first combination algorithm to match the session security level in the first session request; responding to a first channel access request initiated by the operation and maintenance device, performing a first access authentication based on the operation and maintenance device identifier and the smart terminal identifier in the first channel access request and the first combination algorithm; if the first access authentication is successful, generating a session key based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and sending the session key to the operation and maintenance device; and responding to a second session request initiated by a smart terminal, sending the session key to the smart terminal so that the smart terminal and the operation and maintenance device can establish a session based on the session key and the second combination algorithm.

[0011] Preferably, the first channel access request further includes a first current time. Accordingly, the first access authentication includes: responding to the first channel access request initiated by the maintenance device, performing access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm; if the maintenance device's access authentication is successful, determining a first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time, and sending the first value to the maintenance device; and responding to the maintenance device's feedback signal indicating successful access authentication of the server, confirming the first access authentication is successful, wherein the successful access authentication of the server is confirmed by the maintenance device when the first value and a second value are equal, and the second value is the value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time.

[0012] Preferably, the access authentication of the maintenance equipment includes: responding to the action of the maintenance equipment initiating a first channel access request and sending a third value of the first combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier, determining a fourth value of the first combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the maintenance equipment is successful if the third value is equal to the fourth value.

[0013] Preferably, the access authentication of the maintenance equipment includes: in response to a first channel access request initiated by the maintenance equipment, sending a random number to the maintenance equipment; in response to the maintenance equipment sending a fifth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining a sixth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the fifth value is equal to the sixth value, confirming that the access authentication of the maintenance equipment is successful.

[0014] Preferably, while performing the step of negotiating and matching the session security level in the first session request with the maintenance equipment, the security maintenance method further includes: sending the maintenance equipment identifier to the maintenance equipment.

[0015] Preferably, the step of sending the session key to the smart terminal includes: in response to a second session request initiated by the smart terminal, negotiating with the smart terminal a third combination algorithm to match the session security level in the second session request; in response to a second channel access request initiated by the smart terminal, performing a second access authentication based on the maintenance equipment identifier and the smart terminal identifier in the second channel access request and the third combination algorithm; and, if the second access authentication is successful, sending the session key to the smart terminal.

[0016] Preferably, the second channel access request further includes a second current time. Accordingly, the second access authentication includes: responding to the second channel access request from the smart terminal, performing access authentication on the smart terminal based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; if the smart terminal's access authentication is successful, determining a seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, and sending the seventh value to the smart terminal; and responding to the smart terminal's feedback signal indicating successful access authentication from the server, confirming the second access authentication is successful, wherein the server's successful access authentication is confirmed by the smart terminal when the seventh value and an eighth value are equal, and the eighth value is the value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time.

[0017] Preferably, the access authentication of the smart terminal includes: responding to the second channel access request of the smart terminal and the action of sending the ninth value of the third combination algorithm for both the operation and maintenance equipment identifier and the smart terminal identifier, determining the tenth value of the third combination algorithm for both the operation and maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the smart terminal is successful if the ninth value is equal to the tenth value.

[0018] Preferably, the access authentication of the smart terminal includes: in response to the second channel access request of the smart terminal, sending a random number to the smart terminal; in response to the smart terminal sending the eleventh value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining the twelfth value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the eleventh value is equal to the twelfth value, confirming that the access authentication of the smart terminal is successful.

[0019] Preferably, in response to a second session request initiated by the smart terminal, a third combination algorithm for matching the session security level in the second session request is negotiated with the smart terminal. The security operation and maintenance method further includes sending the smart terminal identifier to the smart terminal.

[0020] Preferably, the first combined algorithm for negotiating and matching the session security level in the first session request with the maintenance equipment includes: in response to the first session request initiated by the maintenance equipment, selecting a first algorithm library from multiple algorithm libraries that matches the session security level in the first session request; randomly selecting multiple algorithms from the first algorithm library, generating the first combined algorithm according to preset rules, and forming a generation identifier for the first combined algorithm; and sending the generation identifier for the first combined algorithm to the maintenance equipment. And / or the third combined algorithm for negotiating and matching the session security level in the second session request with the smart terminal includes: in response to the second session request initiated by the smart terminal, selecting a second algorithm library from multiple algorithm libraries that matches the session security level in the second session request; randomly selecting multiple algorithms from the second algorithm library, generating the third combined algorithm according to preset rules, and forming a generation identifier for the third combined algorithm; and sending the generation identifier for the third combined algorithm to the smart terminal.

[0021] Through the above technical solution, this invention creatively responds to a first session request initiated by the maintenance equipment by negotiating a first combination algorithm with the maintenance equipment that matches the session security level in the first session request; responds to a first channel access request initiated by the maintenance equipment by performing a first access authentication based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm in the first channel access request; if the first access authentication is successful, a session key is generated based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm, and the session key is sent to the maintenance equipment; and responds to a second session request initiated by the smart terminal by sending the session key to the smart terminal, so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm. Thus, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby enabling the establishment of a secure session between the maintenance equipment and the smart terminal without changing the user experience of maintenance personnel.

[0022] A second aspect of the present invention provides a secure operation and maintenance method applicable to operation and maintenance equipment. The secure operation and maintenance method includes: initiating a first session request to a server; in response to the result of a first combination algorithm negotiated with the server to match the session security level in the first session request, initiating a first channel access request to the server, wherein the first channel request includes: an operation and maintenance equipment identifier and a smart terminal identifier; performing a first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm; if the first access authentication is successful, in response to the server issuing an action based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm in response to a second session request initiated by the smart terminal, receiving the session key; initiating a third session request to the smart terminal; in response to the smart terminal comparing the session key in the third session request with the received session key and finding that they are the same, negotiating a second combination algorithm with the smart terminal to match the session security level in the third session request; and establishing a session with the smart terminal based on the session key and the second combination algorithm.

[0023] Preferably, the first channel access request further includes a first current time. Accordingly, the first access authentication includes: performing access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm, in conjunction with the server; if the maintenance device's access authentication is successful, in response to the server sending the first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the current time, determining a second value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time; and if the first value and the second value are equal, confirming that the server's access authentication is successful.

[0024] Preferably, the step of cooperating with the server to perform access authentication for the maintenance equipment includes: determining a third value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the third value to the server so that the server can confirm that the access authentication of the maintenance equipment is successful based on the fact that the third value is equal to a fourth value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0025] Preferably, the step of cooperating with the server to perform access authentication for the maintenance equipment includes: in response to the server sending a random number, determining a fifth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier, and sending the fifth value to the server, so that the server can confirm the successful access authentication of the maintenance equipment based on the fact that the fifth value is equal to a sixth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

[0026] Preferably, the maintenance equipment identifier is sent by the server in response to the first session request.

[0027] Preferably, the second combination algorithm for negotiating and matching the session security level in the third session request with the smart terminal includes: in response to the smart terminal comparing the session key in the third session request with the received session key and finding that they are the same, selecting a third algorithm library from multiple algorithm libraries that matches the session security level in the third session request; randomly selecting multiple algorithms from the third algorithm library, generating the second combination algorithm according to a preset rule, and forming a generation identifier for the second combination algorithm; and sending the generation identifier for the second combination algorithm to the smart terminal.

[0028] Through the above technical solution, this invention creatively initiates a first session request to a server via an operation and maintenance device; responds to the result of a first combination algorithm negotiated with the server that matches the session security level in the first session request, and initiates a first channel access request to the server, wherein the first channel request includes: an operation and maintenance device identifier and a smart terminal identifier; performs a first access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm; if the first access authentication is successful, responds to the server issuing an action based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm to generate a session key in response to a second session request initiated by the smart terminal, and receives the session key; initiates a third session request to the smart terminal; responds to the smart terminal comparing the session key in the third session request with the received session key and finding that they are the same, negotiates a second combination algorithm with the smart terminal that matches the session security level in the third session request; and establishes a session between the operation and maintenance device and the smart terminal based on the session key and the second combination algorithm. Thus, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby establishing a secure session between the operation and maintenance device and the smart terminal without changing the user experience of operation and maintenance personnel.

[0029] A third aspect of the present invention provides a secure operation and maintenance method applicable to smart terminals. The secure operation and maintenance method includes: initiating a second session request to a server; receiving the session key in response to the server issuing an action based on the operation and maintenance device identifier, smart terminal identifier, and a session key generated by a first combination algorithm in a first session request initiated by the operation and maintenance device; comparing the session key in the third session request with the received session key in response to a third session request initiated by the operation and maintenance device; negotiating a second combination algorithm with the operation and maintenance device to match the session security level in the third session request if the session key in the third session request is the same as the received session key; and establishing a session with the operation and maintenance device based on the session key and the second combination algorithm.

[0030] Preferably, after performing the step of initiating a second session request to the server, the security operation and maintenance method further includes: in response to the result of a third combination algorithm that negotiates and matches the session security level in the second session request with the server, initiating a second channel access request to the server, wherein the second channel request includes: an operation and maintenance device identifier and a smart terminal identifier; performing a second access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the third combination algorithm; and, if the second access authentication is successful, notifying the server to issue the session key.

[0031] Preferably, the second channel access request further includes a second current time. Accordingly, the second access authentication includes: performing access authentication on the smart terminal based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm, in cooperation with the server; if the access authentication of the smart terminal is successful, in response to the server sending the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, determining the eighth value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time; and if the seventh value and the eighth value are equal, confirming that the server's access authentication is successful.

[0032] Preferably, the step of cooperating with the server to perform access authentication for the smart terminal includes: determining the ninth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the ninth value to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the ninth value is equal to the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0033] Preferably, the step of cooperating with the server to perform access authentication for the smart terminal includes: in response to the server sending a random number, determining the eleventh value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier, and sending the eleventh value to the server, so that the server can confirm the successful access authentication of the smart terminal based on the fact that the eleventh value is equal to the twelfth value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

[0034] Preferably, the smart terminal identifier is sent by the server in response to the second session request.

[0035] Through the above technical solution, this invention creatively initiates a second session request from a smart terminal to a server; in response to the server's action of sending a session key generated by the first session request initiated by the maintenance device and the smart terminal identifier, along with a first combination algorithm, the session key is received; in response to a third session request initiated by the maintenance device, the session key in the third session request is compared with the received session key; if the session key in the third session request is the same as the received session key, a second combination algorithm for matching the session security level in the third session request is negotiated with the maintenance device; and a session is established between the maintenance device and the smart terminal based on the session key and the second combination algorithm. Thus, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby enabling the establishment of a secure session between the maintenance device and the smart terminal without altering the user experience of maintenance personnel.

[0036] A fourth aspect of the present invention provides a security operation and maintenance system applicable to servers. The security operation and maintenance system includes: a negotiation device, configured to negotiate with the operation and maintenance device a first combination algorithm matching the session security level in the first session request in response to a first session request initiated by the operation and maintenance device; an authentication device, configured to perform a first access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm in the first channel access request in response to a first channel access request initiated by the operation and maintenance device; and a key generation device, configured to perform the following operations: if the first access authentication is successful, generate a session key based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and send the session key to the operation and maintenance device; and in response to a second session request initiated by the smart terminal, send the session key to the smart terminal so that the smart terminal and the operation and maintenance device can establish a session based on the session key and the second combination algorithm.

[0037] For specific details and benefits of the security operation and maintenance system for servers provided in the embodiments of the present invention, please refer to the above description of the security operation and maintenance method for servers, which will not be repeated here.

[0038] A fifth aspect of the present invention provides a secure operation and maintenance system applicable to operation and maintenance equipment. The secure operation and maintenance system includes: a first initiating device for initiating a first session request to a server; a second initiating device for initiating a first channel access request to the server in response to a result of a first combination algorithm negotiated with the server to match the session security level in the first session request, wherein the first channel request includes: an operation and maintenance equipment identifier and a smart terminal identifier; an authentication device for performing a first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm; a receiving device for receiving the session key, in response to the server issuing an action based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm when the first access authentication is successful, in response to the server responding to a second session request initiated by the smart terminal; a third initiating device for initiating a third session request to the smart terminal; a negotiation device for negotiating a second combination algorithm with the smart terminal to match the session security level in the third session request in response to the smart terminal comparing the session key in the third session request with the received session key; and a session establishment device for establishing a session with the smart terminal based on the session key and the second combination algorithm.

[0039] For specific details and benefits of the secure operation and maintenance system for operation and maintenance equipment provided in the embodiments of the present invention, please refer to the above description of the secure operation and maintenance method for operation and maintenance equipment, which will not be repeated here.

[0040] A sixth aspect of the present invention provides a security operation and maintenance system applicable to smart terminals. The security operation and maintenance system includes: an initiating device for initiating a second session request to a server; a receiving device for receiving the session key in response to an action by the server to send an action based on the operation and maintenance device identifier and the smart terminal identifier in a first session request initiated by the operation and maintenance device and a session key generated by a first combination algorithm; an authentication device for comparing the session key in the third session request with the received session key in response to a third session request initiated by the operation and maintenance device; a negotiation device for negotiating a second combination algorithm with the operation and maintenance device to match the session security level in the third session request if the session key in the third session request is the same as the received session key; and a session establishment device for establishing a session between the operation and maintenance device and the smart terminal based on the session key and the second combination algorithm.

[0041] For specific details and benefits of the security operation and maintenance system for smart terminals provided in the embodiments of the present invention, please refer to the above description of the security operation and maintenance method for smart terminals, which will not be repeated here.

[0042] A seventh aspect of the present invention provides a server for executing the security operation and maintenance method described above.

[0043] The eighth aspect of the present invention provides an operation and maintenance device for performing the security operation and maintenance method described above.

[0044] A ninth aspect of the present invention provides a smart terminal for executing the security operation and maintenance method described above.

[0045] The tenth aspect of the present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described security operation and maintenance method.

[0046] The eleventh aspect of the present invention also provides a chip for executing a computer program, which, when executed by the chip, implements the aforementioned security operation and maintenance method.

[0047] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description

[0048] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:

[0049] Figure 1 This is a flowchart of a security operation and maintenance method for servers provided in an embodiment of the present invention;

[0050] Figure 2 This is a schematic diagram of the first transformation algorithm provided in an embodiment of the present invention;

[0051] Figure 3 This is a schematic diagram of a second transformation algorithm provided in an embodiment of the present invention;

[0052] Figure 4 This is a flowchart of the interaction process between the handheld device, the main station, and the smart terminal provided in an embodiment of the present invention;

[0053] Figure 5 This is a flowchart of a secure operation and maintenance method for operation and maintenance equipment provided in an embodiment of the present invention;

[0054] Figure 6 This is a session establishment process between maintenance equipment and a smart terminal provided in an embodiment of the present invention;

[0055] Figure 7 This is a flowchart of a security operation and maintenance method for smart terminals provided in an embodiment of the present invention; and

[0056] Figure 8 This is a flowchart illustrating the interaction between the main station, the handheld device, and the smart terminal, according to an embodiment of the present invention. Detailed Implementation

[0057] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0058] Figure 1 This is a flowchart of a security operation and maintenance method for servers provided in an embodiment of the present invention. For example... Figure 1 As shown, the security operation and maintenance method may include:

[0059] Step S101: In response to the first session request initiated by the operation and maintenance equipment, negotiate with the operation and maintenance equipment a first combination algorithm to match the session security level in the first session request;

[0060] Step S102: In response to the first channel access request initiated by the maintenance equipment, perform first access authentication based on the maintenance equipment identifier and smart terminal identifier in the first channel access request and the first combination algorithm;

[0061] Step S103: If the first access authentication is successful, a session key is generated based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and the session key is sent to the operation and maintenance device.

[0062] Step S104: In response to the second session request initiated by the smart terminal, the session key is sent to the smart terminal so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm.

[0063] The following sections will explain and illustrate steps S101-S104.

[0064] Step S101: In response to the first session request initiated by the operation and maintenance device, negotiate with the operation and maintenance device a first combination algorithm to match the session security level in the first session request.

[0065] The maintenance equipment may be a handheld device.

[0066] The first combined algorithm for negotiating and matching the session security level in the first session request with the maintenance equipment includes: in response to the first session request initiated by the maintenance equipment, selecting a first algorithm library from multiple algorithm libraries that matches the session security level in the first session request; randomly selecting multiple algorithms from the first algorithm library, generating the first combined algorithm according to preset rules, and forming a generation identifier for the first combined algorithm; and sending the generation identifier of the first combined algorithm to the maintenance equipment. In other words, both parties establish a connection based on algorithm S. 组合1 Safety passages, such as Figure 8 As shown.

[0067] If a handheld device is used to perform corresponding operation and maintenance management on a smart terminal (such as an electricity meter), a session needs to be established between the handheld device and the smart terminal. First, the handheld device can initiate a first session request to the server (e.g., the main station), where the first session request may include the session security level.

[0068] Secondly, after receiving the first session request, the master station determines the corresponding algorithm library based on the session security level. It then randomly selects n algorithms from the algorithm library and combines them into a first combined algorithm (e.g., a set of nested functions) according to preset rules (e.g., nesting rules). This forms a generation identifier for the first combined algorithm (i.e., a unique identifier identifying how the first combined algorithm was generated). The generation identifier is then sent to the handheld device, which can generate the first combined algorithm based on the generation identifier and its stored multiple algorithm libraries. This embodiment proposes an algorithm library and algorithm generation method based on security classification.

[0069] For example, session security levels can be categorized based on the permissions involved in the operation and maintenance. Preferably, three levels can be set: high, medium, and low, with corresponding key designs of 128 bits, 64 bits, and 32 bits (the key length corresponds to the session security level of the combination algorithm), ensuring that algorithm instances are sparsely distributed across 2... 128 2 64 and 2 32 The configuration data is divided into three spaces. Each of these three spaces constitutes an algorithm library for a block cipher algorithm family, where each algorithm can be called an algorithm instance.

[0070] S 库1 ={S 11 S 12 , ...S 12 128},

[0071] S 库2 ={S 21 S 22 , ...S 22 64},

[0072] S 库3 ={S 31 S 32 , ...S 32 32}

[0073] In various embodiments of the present invention, the first combination algorithm, the second combination algorithm, and the third combination algorithm are all composed of algorithm instances randomly selected from the algorithm library of the block cipher algorithm family.

[0074] S 组合 ={S a1 S a2 , ...S an} = S an (…S a2 (S a1 (X))),

[0075] Where X is plaintext (e.g., one or more of the following: maintenance equipment identifier, smart terminal identifier, current time, random number, etc.), S a1 S a2 , ...S an These are n algorithms randomly selected from the same algorithm library that match the session security level.

[0076] For example, when the session security level is high, S a1 S a2 , ...S an From S 库1 When the session security level is medium, S a1 S a2 , ...S an From S 库2 When the session security level is low, S a1 S a2 , ...S an From S 库3 .

[0077] The following sections will introduce algorithm examples from various algorithm libraries, which can be existing encryption algorithms. User-defined algorithm examples can be updated periodically or irregularly according to cryptographic protocols to further enhance security. For example, the following sections will primarily introduce two algorithms.

[0078] First transformation algorithm: (X, Y) → S an (X, Y) = (X′, Y′), as shown Figure 2 As shown:

[0079]

[0080] The C-transform splits the cipher bricks, and the G-transform swaps them. The algorithm uses both small and large cipher bricks, resulting in a wide variety of structural variations and a huge amount of cipher brick variation.

[0081] The second transformation algorithm: like Figure 3 As shown, the H algorithm for data backflow changes the hierarchical structure of the algorithm through XOR operation, turning the two cryptographic bricks into a composite function relationship, which can significantly increase the algorithm's complexity and increase its security strength.

[0082] The aforementioned multiple algorithm libraries are stored in servers, maintenance equipment, and smart terminals. During the negotiation of corresponding combined algorithms, any two of these components use a unique generation identifier to indicate the corresponding combined algorithm. For example, after the server sends the generation identifier of the first combined algorithm (or the third combined algorithm) to the maintenance equipment (or smart terminal), the maintenance equipment (or smart terminal) can generate the first combined algorithm (or the third combined algorithm) based on the generation identifier and its own stored multiple algorithm libraries.

[0083] In one embodiment, in the power Internet of Things, each operation and maintenance device has a unique identifier. That is, the operation and maintenance device does not need to register with the server. During the safe operation and maintenance process, the operation and maintenance device can directly include its own identifier in the first channel access request.

[0084] In another embodiment, while performing the step of negotiating and matching the session security level in the first session request with the maintenance device (i.e., step S101), the security maintenance method further includes sending the maintenance device identifier to the maintenance device.

[0085] In other words, the device identifier (e.g., handheld device identifier) ​​can be uniformly assigned by the server (e.g., the main station). Upon receiving the first session request initiated by the handheld device, the main station and the handheld device negotiate a set of combined algorithms S that match the security level. 组合1 It also sends a handheld device identifier to the handheld device, meaning that the maintenance equipment registers with the main station.

[0086] In a security operations and maintenance system, the encryption algorithms provided to users are executed using different executable codes. This is suitable for software implementation and facilitates management and updates. After the operations and maintenance device (e.g., a handheld device) obtains the first combination algorithm based on the generated identifier of the first combination algorithm, the handheld device and the server (e.g., the main station) will perform access authentication, and the two parties will establish an connection based on algorithm S. 组合1 Safety passages, such as Figure 8 As shown.

[0087] Step S102: In response to the first channel access request initiated by the maintenance equipment, perform first access authentication based on the maintenance equipment identifier and smart terminal identifier in the first channel access request and the first combination algorithm.

[0088] The first channel access request may also include the first current time.

[0089] Accordingly, for step S102, the first access authentication may include: responding to the first channel access request initiated by the maintenance device, performing access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm; if the access authentication of the maintenance device is successful, determining a first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time, and sending the first value to the maintenance device; and responding to the access authentication success signal from the maintenance device indicating that the server's access authentication is successful, confirming that the first access authentication is successful, wherein the access authentication success of the server is confirmed by the maintenance device when the first value and the second value are equal, and the second value is the value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time.

[0090] In one embodiment, the access authentication of the maintenance equipment may include: in response to the action of the maintenance equipment initiating a first channel access request and sending a third value of the first combination algorithm for both the maintenance equipment identifier and the smart terminal identifier, determining a fourth value of the first combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the maintenance equipment is successful if the third value is equal to the fourth value.

[0091] Specifically, one of the steps in establishing a secure channel between the handheld device and the server may be the following.

[0092] Step 1: The handheld device initiates a channel access request to the server. The channel access request may include: handheld device ID, current time T1, and the smart terminal ID to be connected (of course, it may also include the session security level).

[0093] Step 2, handheld device calculates S 组合1 (ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0094] Step 3, the server calculates S 组合1 (ID 掌机 +ID 终端The calculated value is compared with the value sent by the handheld device in step 2. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0095] Step 4: If authentication is successful, the server calculates S. 组合1 (ID 掌机 +ID 终端 +T1), and send the calculated value to the handheld device;

[0096] Step 5, handheld device calculates S 组合1 (ID 掌机 +ID 终端 +T1), and compare the calculated value with the value sent by the server in step 4. If they are the same, the authentication of the server is successful (i.e., the first access authentication is successful); otherwise, the authentication is unsuccessful.

[0097] In another embodiment, the access authentication of the maintenance equipment includes: in response to a first channel access request initiated by the maintenance equipment, sending a random number to the maintenance equipment; in response to the maintenance equipment sending a fifth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining a sixth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the fifth value is equal to the sixth value, confirming that the access authentication of the maintenance equipment is successful.

[0098] Specifically, the second step in establishing a secure channel between the handheld device and the server may include the following steps.

[0099] Step 1: The handheld device initiates a channel access request to the server. The channel access request may include: handheld device ID, current time T1, and the smart terminal ID to be connected (of course, it may also include the session security level).

[0100] Step 2: In response to the channel access request, the server sends a random number Y to the handheld device;

[0101] Step 3, handheld device calculation S 组合1 (Y+ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0102] Step 4, the server calculates S 组合1 (Y+ID 掌机 +ID 终端 The calculated value is compared with the value sent by the handheld device in step 3. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0103] Step 5: If authentication is successful, the server calculates S. 组合1 (ID 掌机 +ID终端 +T1), and send the calculated value to the handheld device;

[0104] Step 6, handheld device calculates S 组合1 (ID 掌机 +ID 终端 +T1), and compare the calculated value with the value sent by the server in step 5. If they are the same, the authentication of the server is successful (i.e., the first access authentication is successful); otherwise, the authentication is unsuccessful.

[0105] Step S103: If the first access authentication is successful, a session key is generated based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and the session key is sent to the operation and maintenance device.

[0106] Based on successful authentication by both parties, the server calculates S. 组合1 (ID 掌机 +ID 终端 The calculated value is used as the session key for encrypting data on subsequent connections to smart terminals (the number of bits in the session key matches the security level of the combined algorithm), and the session key is then distributed to maintenance equipment (e.g., a handheld device). In other words, based on S... 组合1 The algorithm involves the master station and the handheld device negotiating a one-time password (OTP) key, generating and distributing a session key K.

[0107] This embodiment proposes a method and flow for establishing a secure channel and negotiating a key, such as... Figure 8 As shown.

[0108] Step S104: In response to the second session request initiated by the smart terminal, the session key is sent to the smart terminal so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm.

[0109] In other words, if a smart terminal (e.g., an electricity meter) needs to be managed using a handheld device, a session needs to be established between the handheld device and the smart terminal. First, the smart terminal (e.g., the electricity meter) can initiate a second session request to the main station. Upon receiving the second session request, the server sends the session key generated in step S103 to the smart terminal. Then, the maintenance device initiates a third session request to the smart terminal. Next, upon receiving the third session request, the smart terminal compares the session key in the third session request with its own received session key; if they match, it sends a successful authentication message to the maintenance device. Finally, the maintenance device and the smart terminal negotiate a second combination algorithm that matches the session security level in the third session request. Afterward, the smart terminal and the maintenance device can establish a session based on the session key and the second combination algorithm (e.g., ...). Figure 8As shown, the specific process can be found in the following section regarding the relevant operations performed by the smart terminal and maintenance equipment.

[0110] In the following text, before the server issues the session key, an access authentication process based on a combination algorithm can also be performed between the smart terminal and the main station.

[0111] For step S104, sending the session key to the smart terminal may include: in response to a second session request initiated by the smart terminal, negotiating with the smart terminal a third combination algorithm to match the session security level in the second session request; in response to a second channel access request initiated by the smart terminal, performing a second access authentication based on the maintenance equipment identifier and the smart terminal identifier in the second channel access request and the third combination algorithm; and, if the second access authentication is successful, sending the session key to the smart terminal.

[0112] The second session request may include a session security level.

[0113] The third combination algorithm for negotiating and matching the session security level in the second session request with the smart terminal includes: responding to the second session request initiated by the smart terminal, selecting a second algorithm library from multiple algorithm libraries that matches the session security level in the second session request; randomly selecting multiple algorithms from the second algorithm library, generating the third combination algorithm according to preset rules, and forming a generation identifier for the third combination algorithm; and sending the generation identifier of the third combination algorithm to the smart terminal. In other words, both parties establish a mechanism based on algorithm S. 组合3 Safety passages, such as Figure 8 As shown.

[0114] After receiving the second session request initiated by the smart terminal, the server (e.g., the main station) determines the corresponding algorithm library based on the session security level; then, it randomly selects m algorithms from the algorithm library, combines the m algorithms into a third combined algorithm according to preset rules (e.g., nesting rules), and forms a generation identifier for the third combined algorithm (i.e., a unique identifier that identifies how the first combined algorithm was generated). The generation identifier is then sent to the smart terminal, which can generate the third combined algorithm based on the generation identifier and its own stored multiple algorithm libraries.

[0115] In one embodiment, in the power Internet of Things, each smart terminal has a unique identifier. That is, the smart terminal does not need to register with the server. During the security operation and maintenance process, the smart terminal can directly include its own identifier in the second channel access request.

[0116] In another embodiment, while performing the step of negotiating and matching the session security level in the second session request with the smart terminal, the security operation and maintenance method may further include: sending the smart terminal identifier to the smart terminal.

[0117] In other words, the smart terminal identifier can be uniformly assigned by a server (e.g., a master station). When the master station receives a second session request initiated by the smart terminal, the master station and the smart terminal negotiate a set of combined algorithms S that match the security level. 组合3 It also sends the smart terminal identifier to the smart terminal, meaning the smart terminal registers with the main station.

[0118] After the smart terminal (e.g., electricity meter) obtains the third combination algorithm based on the generated identifier, the smart terminal (e.g., electricity meter) and the server (e.g., main station) perform access authentication, and the two parties establish an access authentication based on algorithm S. 组合3 Safety passages, such as Figure 8 As shown.

[0119] The second channel access request may also include a second current time.

[0120] Accordingly, the second access authentication includes: responding to the second channel access request of the smart terminal, performing access authentication on the smart terminal based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; if the access authentication of the smart terminal is successful, determining the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, and sending the seventh value to the smart terminal; and responding to the signal from the smart terminal indicating successful access authentication of the server, confirming the success of the second access authentication, wherein the successful access authentication of the server is confirmed by the smart terminal when the seventh value and the eighth value are equal, and the eighth value is the value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time.

[0121] In one embodiment, the access authentication of the smart terminal includes: responding to the second channel access request of the smart terminal and the action of sending the ninth value of the third combination algorithm for both the operation and maintenance equipment identifier and the smart terminal identifier, determining the tenth value of the third combination algorithm for both the operation and maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the smart terminal is successful if the ninth value is equal to the tenth value.

[0122] Specifically, one of the steps in establishing a secure channel between a smart terminal and a server may be the following.

[0123] Step 1: The smart terminal initiates a channel access request to the server. The channel access request may include: smart terminal ID, current time T2, handheld device ID to be connected (and may also include session security level).

[0124] Step 2, intelligent terminal computing S 组合3 (ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0125] Step 3, the server calculates S 组合3 (ID 掌机 +ID 终端 The system then compares the calculated value with the value sent by the smart terminal in step 2. If they match, the authentication of the smart terminal is successful; otherwise, the authentication fails.

[0126] Step 4: If authentication is successful, the server calculates S. 组合3 (ID 掌机 +ID 终端 +T2), and send the calculated value to the smart terminal;

[0127] Step 5, Smart terminal computing S 组合3 (ID 掌机 +ID 终端 +T2), and compare the calculated value with the value sent by the server in step 4. If they are the same, the authentication of the server is successful (i.e., the second access authentication is successful); otherwise, the authentication is unsuccessful.

[0128] In another embodiment, the access authentication of the smart terminal includes: in response to the second channel access request of the smart terminal, sending a random number to the smart terminal; in response to the smart terminal sending the eleventh value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining the twelfth value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the eleventh value is equal to the twelfth value, confirming that the access authentication of the smart terminal is successful.

[0129] Specifically, the second step in establishing a secure channel between a smart terminal and a server may include the following steps.

[0130] Step 1: The smart terminal initiates a channel access request to the server. The channel access request may include: smart terminal ID, current time T2, handheld device ID to be connected (and may also include session security level).

[0131] Step 2: In response to the channel access request, the server sends a random number Y to the smart terminal;

[0132] Step 3, intelligent terminal computing S 组合3 (Y+ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0133] Step 4, the server calculates S 组合3 (Y+ID 掌机 +ID 终端 The calculated value is compared with the value sent by the handheld device in step 3. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0134] Step 5: If authentication is successful, the server calculates S. 组合3 (ID 掌机 +ID 终端 +T2), and send the calculated value to the smart terminal;

[0135] Step 6, Smart terminal calculates S 组合3 (ID 掌机 +ID 终端 +T2), and compare the calculated value with the value sent by the server in step 5. If they are the same, the authentication of the server is successful (i.e., the second access authentication is successful); otherwise, the authentication is unsuccessful.

[0136] In other words, based on S 组合3 The algorithm involves the main station sending the session key K to the smart terminal.

[0137] Through steps S101-S104 above, both the smart terminal and the maintenance equipment obtain the session key. Therefore, the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm to carry out security maintenance services. After the session ends, the session key becomes invalid. That is, each communication between the smart terminal and the handheld device achieves "one session, one key". In other words, throughout the entire security maintenance process, the combination algorithm S... 组合1 S 组合2 S 组合3 Replace as needed based on security policy (i.e., security level) to achieve "one algorithm per device".

[0138] like Figure 4 As shown, the interaction process between the handheld console, the main station, and the smart terminal may include the following steps S401-S428.

[0139] Step S401: The handheld device initiates the first session request.

[0140] Step S402, the main station and the handheld device negotiate the first combination algorithm S 组合1 And send handheld device ID 掌机 .

[0141] The first combination algorithm is matched with the session security level in the first session request.

[0142] Step S403: The handheld device initiates the first channel access request.

[0143] The first channel access request includes an ID. 掌机 Smart terminal identifier ID 终端 Current time T1.

[0144] Step S404: The main station sends a random number Y.

[0145] Step S405, the handheld device calculates and sends S 组合1 (Y+ID 掌机 +ID 终端 ).

[0146] Step S406, the main station calculates S 组合1 (Y+ID 掌机 +ID 终端 ).

[0147] Step S407, the main station determines the two S's. 组合1 (Y+ID 掌机 +ID 终端 If the values ​​are equal, proceed to step S408; otherwise, authentication fails.

[0148] Step S408, the master station calculates and sends S 组合1 (ID 掌机 +ID 终端 +T1).

[0149] Step S409, handheld device calculation S 组合1 (ID 掌机 +ID 终端 +T1).

[0150] Step S410, the handheld device determines the two S's. 组合1 (ID 掌机 +ID 终端 If +T1) is equal to the value of T1, then proceed to step S411; otherwise, authentication fails.

[0151] Step S411: The handheld device notifies the main site that authentication was successful.

[0152] Step S412: The main site confirms the first authentication was successful.

[0153] Step S413, the main station calculates S 组合1 (ID 掌机 +ID 终端 To generate a session key.

[0154] Step S414: The master station sends the session key to the handheld device.

[0155] In step S415, the smart terminal initiates a second session request.

[0156] Step S416: The main station and the smart terminal negotiate the third combination algorithm S. 组合3 And send terminal identifier ID 终端 .

[0157] The third combination algorithm is matched with the session security level in the second session request.

[0158] Step S417: The smart terminal initiates a second channel access request.

[0159] The second channel access request includes an ID. 掌机 Smart terminal identifier ID 终端 Current time T2.

[0160] Step S418: The main station sends a random number Y.

[0161] Step S419, the smart terminal calculates and sends S 组合3 (Y+ID 掌机 +ID 终端 ).

[0162] Step S420, the main station calculates S 组合3 (Y+ID 掌机 +ID 终端 ).

[0163] Step S421, the main station determines the two S's. 组合3 (Y+ID 掌机 +ID 终端 If the values ​​are equal, proceed to step S422; otherwise, authentication fails.

[0164] Step S422, the master station calculates and sends S 组合3 (ID 掌机 +ID 终端 +T2).

[0165] Step S423, the intelligent terminal calculates S 组合3 (ID 掌机 +ID 终端 +T2).

[0166] Step S424, the smart terminal determines the two S 组合3 (ID 掌机 +ID 终端 If +T2) are equal, proceed to step S425; otherwise, authentication fails.

[0167] Step S425: Notify the main site that authentication was successful.

[0168] Step S426: The main site confirms the second authentication was successful.

[0169] Step S427: The master station issues the session key.

[0170] Step S428: Establish a session between the maintenance equipment and the smart terminal based on the session key and the second combination algorithm.

[0171] It should be noted that in each embodiment of the present invention, the identifier (e.g., the maintenance equipment identifier or the smart terminal identifier) ​​is unique.

[0172] This embodiment achieves user authentication and session key negotiation between the user and the server through authentication between the smart terminal and the main station, and authentication between the handheld device and the main station. A combined algorithm (which can be called an algorithm generator) is used to generate keys, and the secure session between the handheld device and the smart terminal is implemented based on these keys (i.e., one session, one key, and a set of combined algorithm security mechanisms).

[0173] It should be noted that in the various embodiments of this document, the first value, the second value, the third value, the fourth value, the fifth value, and the sixth value are all function values ​​of the first combination algorithm with respect to multiple parameters. For example, the first value and the second value are both function values ​​of the first combination algorithm with respect to three parameters (the maintenance equipment identifier, the smart terminal identifier, and the first current time); the third value and the fourth value are both function values ​​of the first combination algorithm with respect to two parameters (the maintenance equipment identifier and the smart terminal identifier); the fifth value and the sixth value are both function values ​​of the first combination algorithm with respect to three parameters (the random number, the maintenance equipment identifier, and the smart terminal identifier). The seventh value, the eighth value, the ninth value, the tenth value, the eleventh value, and the twelfth value are all function values ​​of the third combination algorithm with respect to multiple parameters. The seventh and eighth values ​​are both function values ​​of the third combination algorithm with respect to three parameters (the maintenance equipment identifier, the smart terminal identifier, and the second current time); the ninth and tenth values ​​are both function values ​​of the third combination algorithm with respect to two parameters (the maintenance equipment identifier and the smart terminal identifier); the eleventh and twelfth values ​​are both function values ​​of the third combination algorithm with respect to three parameters (the random number, the maintenance equipment identifier, and the smart terminal identifier).

[0174] In summary, this invention creatively responds to a first session request initiated by the maintenance equipment by negotiating a first combination algorithm with the maintenance equipment that matches the session security level in the first session request; responds to a first channel access request initiated by the maintenance equipment by performing a first access authentication based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm in the first channel access request; if the first access authentication is successful, a session key is generated based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm, and the session key is sent to the maintenance equipment; and responds to a second session request initiated by the smart terminal by sending the session key to the smart terminal, so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm. Thus, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby enabling the establishment of a secure session between the maintenance equipment and the smart terminal without changing the user experience of maintenance personnel.

[0175] Figure 5 This is a flowchart of a secure operation and maintenance method for equipment provided in an embodiment of the present invention. For example... Figure 5 As shown, the security operation and maintenance method may include:

[0176] Step S501: Initiate the first session request to the server;

[0177] Step S502: In response to the result of the first combination algorithm that matches the session security level in the first session request negotiated with the server, a first channel access request is initiated to the server, wherein the first channel request includes: maintenance equipment identifier and smart terminal identifier;

[0178] Step S503: Perform first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm;

[0179] Step S504: If the first access authentication is successful, in response to the server's response to the second session request initiated by the smart terminal, the server issues an action based on the operation and maintenance equipment identifier, the smart terminal identifier, and the session key generated by the first combination algorithm, and receives the session key;

[0180] Step S505: Initiate a third session request to the smart terminal;

[0181] Step S506: In response to the result that the smart terminal compares the session key in the third session request with the received session key and finds that they are the same, negotiate with the smart terminal a second combination algorithm to match the session security level in the third session request;

[0182] Step S507: Establish a session between the maintenance equipment and the smart terminal based on the session key and the second combination algorithm.

[0183] The following sections will explain and describe steps S501-S507 respectively. The maintenance equipment mentioned may be a handheld device.

[0184] Step S501: Initiate the first session request to the server.

[0185] If a handheld device is used to perform corresponding operation and maintenance management on a smart terminal (such as an electricity meter), a session needs to be established between the handheld device and the smart terminal. First, the handheld device can initiate a first session request to the server (e.g., the main station), where the first session request may include the session security level.

[0186] Step S502: In response to the result of a first combination algorithm that matches the session security level in the first session request negotiated with the server, a first channel access request is initiated to the server.

[0187] The first channel request may include: maintenance equipment identifier and smart terminal identifier.

[0188] After receiving the first session request, the server (e.g., the main site) determines the corresponding algorithm library based on the session security level. It then randomly selects n algorithms from the library and combines them into a first combined algorithm according to preset rules or randomly, forming a generation identifier for the first combined algorithm (i.e., a unique identifier identifying how the first combined algorithm was generated). This generation identifier is then sent to the handheld device, which can generate the first combined algorithm based on the generation identifier and its stored multiple algorithm libraries. In other words, the handheld device and the smart terminal establish a connection based on algorithm S... 组合2 Safety passages, such as Figure 8 As shown.

[0189] In one embodiment, in the power Internet of Things, each operation and maintenance device has a unique identifier. That is, the operation and maintenance device does not need to register with the server. During the safe operation and maintenance process, the operation and maintenance device can directly include its own identifier in the first channel access request.

[0190] In another embodiment, the maintenance device identifier may be sent by the server in response to the first session request in step S501. That is, the maintenance device identifier (e.g., handheld device identifier) ​​may be uniformly assigned by the server (e.g., the main station). Upon receiving the first session request initiated by the handheld device, the main station and the handheld device negotiate a set of combined algorithms S that match the security level. 组合1 It also sends a handheld device identifier to the handheld device, meaning that the maintenance equipment registers with the main station.

[0191] After the maintenance device (e.g., a handheld device) obtains the first combined algorithm based on the generated identifier of the first combined algorithm, the handheld device and the server (e.g., the main site) will perform access authentication, and the two parties will establish an connection based on algorithm S. 组合1 Safety passages, such as Figure 8 As shown.

[0192] Step S503: Perform first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm.

[0193] The first channel access request may also include the first current time.

[0194] Accordingly, the first access authentication may include: performing access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm, in conjunction with the server; if the access authentication of the maintenance device is successful, in response to the server sending the first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the current time, determining the second value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the current time; and if the first value and the second value are equal, confirming that the server's access authentication is successful.

[0195] In one embodiment, the step of cooperating with the server to perform access authentication for the maintenance equipment may include: determining a third value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the third value to the server so that the server can confirm that the access authentication of the maintenance equipment is successful based on the fact that the third value is equal to a fourth value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0196] Specifically, one of the steps in establishing a secure channel between the handheld device and the server may be the following.

[0197] Step 1: The handheld device initiates a channel access request to the server. The channel access request may include: handheld device ID, current time T1, and the smart terminal ID to be connected (of course, it may also include the session security level).

[0198] Step 2, handheld device calculates S 组合1 (ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0199] Step 3, the server calculates S 组合1 (ID 掌机 +ID 终端The calculated value is compared with the value sent by the handheld device in step 2. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0200] Step 4: If authentication is successful, the server calculates S. 组合1 (ID 掌机 +ID 终端 +T1), and send the calculated value to the handheld device;

[0201] Step 5, handheld device calculates S 组合1 (ID 掌机 +ID 终端 +T1), and compare the calculated value with the value sent by the server in step 4. If they are the same, the authentication of the server is successful (i.e., the first access authentication is successful); otherwise, the authentication is unsuccessful.

[0202] In another embodiment, the step of cooperating with the server to perform access authentication for the maintenance device may include: in response to the server sending a random number, determining a fifth value of the first combination algorithm with respect to the random number, the maintenance device identifier, and the smart terminal identifier, and sending the fifth value to the server, so that the server can confirm the successful access authentication of the maintenance device based on the fact that the fifth value is equal to a sixth value of the first combination algorithm with respect to the random number, the maintenance device identifier, and the smart terminal identifier.

[0203] Specifically, the second step in establishing a secure channel between the handheld device and the server may include the following steps.

[0204] Step 1: The handheld device initiates a channel access request to the server. The channel access request may include: handheld device ID, current time T1, and the smart terminal ID to be connected (of course, it may also include the session security level).

[0205] Step 2: In response to the channel access request, the server sends a random number Y to the handheld device;

[0206] Step 3, handheld device calculation S 组合1 (Y+ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0207] Step 4, the server calculates S 组合1 (Y+ID 掌机 +ID 终端 The calculated value is compared with the value sent by the handheld device in step 3. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0208] Step 5: If authentication is successful, the server calculates S. 组合1 (ID 掌机 +ID 终端+T1), and send the calculated value to the handheld device;

[0209] Step 6, handheld device calculates S 组合1 (ID 掌机 +ID 终端 +T1), and compare the calculated value with the value sent by the server in step 5. If they are the same, the authentication of the server is successful (i.e., the first access authentication is successful); otherwise, the authentication is unsuccessful.

[0210] In various embodiments, the fifth value, the sixth value, the third value, and the fourth value are all function values ​​of the first combination algorithm with respect to multiple parameters. For example, the first value and the second value are both function values ​​of the first combination algorithm with respect to three parameters (the maintenance equipment identifier, the smart terminal identifier, and the current time); the third value and the fourth value are both function values ​​of the first combination algorithm with respect to two parameters (the maintenance equipment identifier and the smart terminal identifier).

[0211] Step S504: If the first access authentication is successful, in response to the second session request initiated by the smart terminal, the server issues an action based on the operation and maintenance equipment identifier, the smart terminal identifier, and the session key generated by the first combination algorithm, and receives the session key.

[0212] First, the smart terminal (e.g., an electricity meter) can initiate a second session request to the main station. Second, upon receiving the second session request, the server sends the generated session key to the smart terminal. The process by which the server generates and sends the session key based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm is detailed in the description of step S103. In response to the server's action of sending the session key generated based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm, the maintenance device receives the session key.

[0213] Step S505: Initiate a third session request to the smart terminal.

[0214] Upon receiving the session key, if the smart terminal (e.g., an electricity meter) needs to perform corresponding operation and maintenance management using a handheld device, a session needs to be established between the handheld device and the smart terminal. The operation and maintenance device (e.g., the handheld device) initiates a third session request to the smart terminal. Upon receiving the third session request and the session key issued by the server (e.g., the main station), the smart terminal compares the session key in the third session request with the session key it received, and sends the authentication result back to the operation and maintenance device (e.g., the handheld device).

[0215] Step S506: In response to the result that the smart terminal compares the session key in the third session request with the received session key and finds that they are the same, negotiate with the smart terminal a second combination algorithm to match the session security level in the third session request.

[0216] For step S506, the second combination algorithm for negotiating and matching the session security level in the third session request with the smart terminal may include: in response to the result that the smart terminal compares the session key in the third session request with the received session key and finds that they are the same, selecting a third algorithm library from multiple algorithm libraries that matches the session security level in the third session request; randomly selecting multiple algorithms from the third algorithm library, generating the second combination algorithm according to preset rules, and forming a generation identifier for the second combination algorithm; and sending the generation identifier for the second combination algorithm to the smart terminal.

[0217] If the smart terminal successfully authenticates (the session key in the third session request is the same as the session key it received), the maintenance device (e.g., a handheld device) determines the corresponding algorithm library based on the session security level in the third session request. Then, it randomly selects k algorithms from the algorithm library and combines them into a second combined algorithm (e.g., a set of nested functions) according to preset rules (e.g., nesting rules). This forms a generation identifier for the second combined algorithm (i.e., a unique identifier identifying how the second combined algorithm was generated). The generation identifier is then sent to the smart terminal, which can generate the second combined algorithm based on the generation identifier and its stored multiple algorithm libraries. This embodiment proposes an algorithm library and algorithm generation method based on security classification.

[0218] Step S507: Establish a session between the maintenance equipment and the smart terminal based on the session key and the second combination algorithm.

[0219] Based on the session key and the second combination algorithm, the communication data in the session is encrypted and / or decrypted.

[0220] Specifically, the session establishment process between the handheld device and the smart terminal (step S428) may include the following steps S601-S603, such as... Figure 6 As shown.

[0221] In step S601, the handheld device receives the session key and initiates a third session request.

[0222] The third session request includes a session key.

[0223] In step S602, the smart terminal receives the session key and compares the session key in the third session request with the received session key. If they are equal, then step S603 is executed; otherwise, authentication fails.

[0224] The smart terminal receives the session key issued by the server (e.g., the main station) and authenticates the session key in the third session request with the session key it received.

[0225] Step S603: Based on the session key and the second combination algorithm, encrypt and / or decrypt the communication data in the session between the handheld device and the smart terminal.

[0226] In summary, this invention creatively initiates a first session request from the maintenance device to the server; responds to the server sending a first combination algorithm that matches the session security level in the first session request, and initiates a first channel access request to the server, wherein the first channel request includes: maintenance device identifier and smart terminal identifier; performs a first access authentication based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm; if the first access authentication is successful, responds to the server issuing an action based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm to generate a session key in response to the second session request initiated by the smart terminal, and receives the session key; initiates a third session request to the smart terminal; responds to the smart terminal comparing the session key in the third session request with the received session key and finding that they are the same, negotiates a second combination algorithm with the smart terminal that matches the session security level in the third session request; and establishes a session between the maintenance device and the smart terminal based on the session key and the second combination algorithm. Therefore, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby establishing a secure session between the maintenance device and the smart terminal without changing the user experience of maintenance personnel.

[0227] Figure 7 This is a flowchart of a security operation and maintenance method for smart terminals provided by an embodiment of the present invention. For example... Figure 7 As shown, the security operation and maintenance method may include: step S701, initiating a second session request to the server;

[0228] Step S702: In response to the server's action of sending the operation and maintenance device identifier and smart terminal identifier in the first session request initiated by the operation and maintenance device and the session key generated by the first combination algorithm, the session key is received;

[0229] Step S703: In response to the third session request initiated by the maintenance equipment, compare the session key in the third session request with the received session key;

[0230] Step S704: If the session key in the third session request is the same as the received session key, negotiate with the maintenance equipment a second combination algorithm to match the session security level in the third session request;

[0231] Step S705: Establish a session between the maintenance equipment and the smart terminal based on the session key and the second combination algorithm.

[0232] When the server receives a second session request initiated by a smart terminal, the server issues a session key generated by the first combination algorithm based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm from the first session request initiated by the maintenance device. For details on the process of the server generating the session key based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm from the first session request initiated by the maintenance device, please refer to the relevant description in step S103.

[0233] If a smart terminal (e.g., an electricity meter) needs to be managed using a handheld device, a session needs to be established between the handheld device and the smart terminal. First, the smart terminal (e.g., the electricity meter) can initiate a second session request to the main station. Upon receiving the second session request, the server sends the generated session key to the smart terminal. Upon receiving the second session request from the smart terminal, the server sends a session key generated based on the maintenance device identifier, the smart terminal identifier, and a first combination algorithm from the first session request initiated by the maintenance device. The smart terminal receives the session key and, in response to a third session request initiated by the maintenance device, compares the session key in the third session request with the received session key. If they match, the smart terminal negotiates a second combination algorithm that matches the session security level in the third session request (see the process of negotiating the second combination algorithm with the smart terminal performed by the maintenance device). The smart terminal can generate a second combination algorithm based on the generation identifier of the second combination algorithm formed during the negotiation process and its own stored multiple algorithm libraries. After determining the second combination algorithm, the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm. Specifically, based on the session key and the second combination algorithm, the communication data in the session is encrypted and / or decrypted.

[0234] Before the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm, access authentication based on the combination algorithm between the smart terminal and the server can also be performed. The session establishment process is only executed if the access authentication is successful.

[0235] After performing the step of initiating the second session request to the server (i.e., step S701), the security operation and maintenance method may further include: in response to the result of a third combination algorithm that negotiates with the server to match the session security level in the second session request, initiating a second channel access request to the server, wherein the second channel request includes: an operation and maintenance device identifier and a smart terminal identifier; performing a second access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the third combination algorithm; and, if the second access authentication is successful, notifying the server to issue the session key.

[0236] In one embodiment, in the power Internet of Things, each smart terminal has a unique identifier. That is, the smart terminal does not need to register with the server. During the security operation and maintenance process, the smart terminal can directly include its own identifier in the second channel access request.

[0237] In another embodiment, the smart terminal identifier may be sent by the server in response to the second session request in step S701. That is, the smart terminal identifier (e.g., a meter identifier) ​​may be uniformly assigned by the server (e.g., the master station). Upon receiving the second session request initiated by the smart terminal, the master station and the smart terminal negotiate a set of combined algorithms S that match the security level. 组合3 It also sends the smart terminal identifier to the smart terminal, meaning that the smart terminal registers with the main site.

[0238] The second channel access request may further include a second current time. The second current time may be equal to or different from the first current time.

[0239] Accordingly, the second access authentication may include: performing access authentication on the smart terminal based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm, in conjunction with the server; if the access authentication of the smart terminal is successful, in response to the server sending the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, determining the eighth value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time; and if the seventh value and the eighth value are equal, confirming that the server's access authentication is successful.

[0240] In one embodiment, the step of cooperating with the server to perform access authentication for the smart terminal may include: determining a ninth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the ninth value to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the ninth value is equal to the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0241] For details on the session establishment process between maintenance equipment and smart terminals, please refer to [link / reference]. Figure 6 Related descriptions.

[0242] Specifically, one of the steps in establishing a secure channel between a smart terminal and a server may be the following.

[0243] Step 1: The smart terminal initiates a channel access request to the server. The channel access request may include: smart terminal ID, current time T2, handheld device ID to be connected (and may also include session security level).

[0244] Step 2, intelligent terminal computing S 组合3 (ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0245] Step 3, the server calculates S 组合3 (ID 掌机 +ID 终端 The system then compares the calculated value with the value sent by the smart terminal in step 2. If they match, the authentication of the smart terminal is successful; otherwise, the authentication fails.

[0246] Step 4: If authentication is successful, the server calculates S. 组合3 (ID 掌机 +ID 终端 +T2), and send the calculated value to the smart terminal;

[0247] Step 5, Smart terminal computing S 组合3 (ID 掌机 +ID 终端 +T2), and compare the calculated value with the value sent by the server in step 4. If they are the same, the authentication of the server is successful (i.e., the second access authentication is successful); otherwise, the authentication is unsuccessful.

[0248] In another embodiment, the step of cooperating with the server to perform access authentication for the smart terminal includes: in response to the server sending a random number, determining the eleventh value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier, and sending the eleventh value to the server, so that the server can confirm the successful access authentication of the smart terminal based on the fact that the eleventh value is equal to the twelfth value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

[0249] Specifically, the second step in establishing a secure channel between a smart terminal and a server may include the following steps.

[0250] Step 1: The smart terminal initiates a channel access request to the server. The channel access request may include: smart terminal ID, current time T2, handheld device ID to be connected (and may also include session security level).

[0251] Step 2: In response to the channel access request, the server sends a random number Y to the smart terminal;

[0252] Step 3, intelligent terminal computing S 组合3 (Y+ID 掌机 +ID 终端 ), and send the calculated value to the server;

[0253] Step 4, the server calculates S 组合3 (Y+ID 掌机 +ID 终端 The calculated value is compared with the value sent by the handheld device in step 3. If they are the same, the authentication of the handheld device is successful; otherwise, the authentication fails.

[0254] Step 5: If authentication is successful, the server calculates S. 组合3 (ID 掌机 +ID 终端 +T2), and send the calculated value to the smart terminal;

[0255] Step 6, Smart terminal calculates S 组合3 (ID 掌机 +ID 终端 +T2), and compare the calculated value with the value sent by the server in step 5. If they are the same, the authentication of the server is successful (i.e., the second access authentication is successful); otherwise, the authentication is unsuccessful.

[0256] In other words, based on S 组合3 The algorithm involves the main station sending the session key K to the smart terminal.

[0257] In summary, this invention creatively initiates a second session request from a smart terminal to a server; in response to the server's action of sending a session key generated by the maintenance device identifier, smart terminal identifier, and a first combination algorithm based on the first session request initiated by the maintenance device, the invention receives the session key; in response to a third session request initiated by the maintenance device, the invention compares the session key in the third session request with the received session key; if the session key in the third session request is the same as the received session key, the invention negotiates a second combination algorithm with the maintenance device that matches the session security level in the third session request; and establishes a session between the maintenance device and the smart terminal based on the session key and the second combination algorithm. Therefore, this invention proposes a cryptographic system of one session, one key, and one set of combination algorithms, thereby enabling the establishment of a secure session between the maintenance device and the smart terminal without altering the user experience of maintenance personnel.

[0258] The various embodiments of this invention achieve different operations and data flows through deep integration of key and algorithm logic, thereby ensuring that all users use different cryptographic algorithms. From an attacker's perspective, each user uses a cryptographic algorithm specifically designed for their own use, which can be described as "one person, one key, one algorithm," greatly improving the system's security.

[0259] An embodiment of the present invention provides a security operation and maintenance system applicable to servers. The security operation and maintenance system includes: a negotiation device, configured to negotiate with the operation and maintenance device a first combination algorithm matching the session security level in the first session request in response to a first session request initiated by the operation and maintenance device; an authentication device, configured to perform a first access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm in the first channel access request in response to a first channel access request initiated by the operation and maintenance device; and a key generation device, configured to perform the following operations: if the first access authentication is successful, generate a session key based on the operation and maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and send the session key to the operation and maintenance device; and in response to a second session request initiated by the smart terminal, send the session key to the smart terminal so that the smart terminal and the operation and maintenance device can establish a session based on the session key and the second combination algorithm.

[0260] Preferably, the first channel access request further includes a first current time. Correspondingly, the authentication device includes: an authentication unit, configured to, in response to the first channel access request initiated by the maintenance device, perform access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm; a value determination unit, configured to, if the maintenance device's access authentication is successful, determine a first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time, and send the first value to the maintenance device; and a result confirmation unit, configured to, in response to the maintenance device's feedback signal indicating successful access authentication of the server, confirm the first access authentication is successful, wherein the successful access authentication of the server is confirmed by the maintenance device when the first value and a second value are equal, and the second value is the value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time.

[0261] Preferably, the authentication unit for authenticating the access of the maintenance equipment includes: responding to the action of the maintenance equipment initiating a first channel access request and sending a third value of the first combination algorithm for both the maintenance equipment identifier and the smart terminal identifier, determining a fourth value of the first combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the maintenance equipment is successful if the third value is equal to the fourth value.

[0262] Preferably, the authentication unit for authenticating access to the maintenance equipment includes: in response to a first channel access request initiated by the maintenance equipment, sending a random number to the maintenance equipment; in response to the maintenance equipment sending a fifth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining a sixth value of the first combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the fifth value is equal to the sixth value, confirming that the access authentication of the maintenance equipment is successful.

[0263] Preferably, the key generation device for sending the session key to the smart terminal includes: in response to a second session request initiated by the smart terminal, negotiating with the smart terminal a third combination algorithm to match the session security level in the second session request; in response to a second channel access request initiated by the smart terminal, performing a second access authentication based on the maintenance equipment identifier and the smart terminal identifier in the second channel access request and the third combination algorithm; and, if the second access authentication is successful, sending the session key to the smart terminal.

[0264] Preferably, the second channel access request further includes a second current time. Accordingly, the key generation device for performing the second access authentication includes: responding to the second channel access request of the smart terminal, performing access authentication on the smart terminal based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; if the access authentication of the smart terminal is successful, determining a seventh value of the third combination algorithm with respect to the maintenance equipment identifier, the smart terminal identifier, and the second current time, and sending the seventh value to the smart terminal; and responding to the signal from the smart terminal indicating successful access authentication of the server, confirming the success of the second access authentication, wherein the successful access authentication of the server is confirmed by the smart terminal when the seventh value and the eighth value are equal, and the eighth value is the value of the third combination algorithm with respect to the maintenance equipment identifier, the smart terminal identifier, and the second current time.

[0265] Preferably, the key generation device for access authentication of the smart terminal includes: responding to the second channel access request of the smart terminal and the action of sending the ninth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier, determining the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and confirming that the access authentication of the smart terminal is successful if the ninth value is equal to the tenth value.

[0266] Preferably, the key generation device for access authentication of the smart terminal includes: in response to the second channel access request of the smart terminal, sending a random number to the smart terminal; in response to the smart terminal sending the eleventh value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, determining the twelfth value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier; and if the eleventh value is equal to the twelfth value, confirming that the access authentication of the smart terminal is successful.

[0267] For specific details and benefits of the security operation and maintenance system for servers provided in the embodiments of the present invention, please refer to the above description of the security operation and maintenance method for servers, which will not be repeated here.

[0268] An embodiment of the present invention provides a secure operation and maintenance system applicable to operation and maintenance equipment. The secure operation and maintenance system includes: a first initiating device for initiating a first session request to a server; a second initiating device for initiating a first channel access request to the server in response to the result of a first combination algorithm negotiated with the server to match the session security level in the first session request, wherein the first channel request includes: an operation and maintenance equipment identifier and a smart terminal identifier; an authentication device for performing a first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm; a receiving device for receiving the session key in response to the server issuing a session key based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm when the first access authentication is successful, in response to the server responding to a second session request initiated by the smart terminal; a third initiating device for initiating a third session request to the smart terminal; a negotiation device for negotiating a second combination algorithm matching the session security level in the third session request with the smart terminal in response to the result that the session key in the third session request is the same as the received session key; and a session establishment device for establishing a session between the smart terminals based on the session key and the second combination algorithm.

[0269] Preferably, the first channel access request further includes a first current time. Correspondingly, the authentication device includes: an authentication unit, configured to perform access authentication on the maintenance device in cooperation with the server based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm; a value confirmation unit, configured to, in response to the server sending a first value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the current time, determine a second value of the first combined algorithm regarding the maintenance device identifier, the smart terminal identifier, and the first current time, when the maintenance device's access authentication is successful; and a result confirmation unit, configured to confirm that the server's access authentication is successful when the first value and the second value are equal.

[0270] Preferably, the authentication unit, in cooperation with the server, performs access authentication for the maintenance equipment by: determining a third value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the third value to the server, so that the server can confirm successful access authentication of the maintenance equipment based on the fact that the third value is equal to a fourth value of the first combined algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0271] Preferably, the authentication unit, in conjunction with the server, performs access authentication for the maintenance equipment by: responding to the server sending a random number, determining a fifth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier, and sending the fifth value to the server, so that the server can confirm successful access authentication of the maintenance equipment based on the fifth value being equal to a sixth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

[0272] For specific details and benefits of the secure operation and maintenance system for operation and maintenance equipment provided in the embodiments of the present invention, please refer to the above description of the secure operation and maintenance method for operation and maintenance equipment, which will not be repeated here.

[0273] An embodiment of the present invention provides a security operation and maintenance system applicable to smart terminals. The security operation and maintenance system includes: an initiating device for initiating a second session request to a server; a receiving device for receiving the session key in response to the server issuing an action based on the operation and maintenance device identifier, the smart terminal identifier, and a session key generated by a first combination algorithm in a first session request initiated by the operation and maintenance device; an authentication device for comparing the session key in the third session request with the received session key in response to a third session request initiated by the operation and maintenance device; a negotiation device for negotiating a second combination algorithm with the operation and maintenance device to match the session security level in the third session request if the session key in the third session request is the same as the received session key; and a session establishment device for establishing a session with the operation and maintenance device based on the session key and the second combination algorithm.

[0274] Preferably, the security operation and maintenance system further includes: a second initiating device, configured to initiate a second channel access request to the server in response to the result of a third combination algorithm that negotiates and matches the session security level in the second session request with the server, wherein the second channel request includes: an operation and maintenance device identifier and a smart terminal identifier; a second authentication device, configured to perform second access authentication based on the operation and maintenance device identifier, the smart terminal identifier, and the third combination algorithm; and a notification device, configured to notify the server to issue the session key if the second access authentication is successful.

[0275] Preferably, the second channel access request further includes a second current time. Accordingly, the second authentication device for performing the second access authentication includes: based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm, cooperating with the server to perform access authentication on the smart terminal; if the access authentication of the smart terminal is successful, in response to the server sending the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, determining the eighth value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time; and if the seventh value is equal to the eighth value, confirming that the server's access authentication is successful.

[0276] Preferably, the second authentication device, in conjunction with the server, performs access authentication for the smart terminal by: determining a ninth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier; and sending the ninth value to the server, so that the server can confirm the successful access authentication of the smart terminal based on the fact that the ninth value is equal to the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier.

[0277] Preferably, the second authentication device, in conjunction with the server, performs access authentication for the smart terminal by: responding to the server sending a random number, determining the eleventh value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier, and sending the eleventh value to the server, so that the server can confirm the successful access authentication of the smart terminal based on the fact that the eleventh value is equal to the twelfth value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

[0278] For specific details and benefits of the security operation and maintenance system for smart terminals provided in the embodiments of the present invention, please refer to the above description of the security operation and maintenance method for smart terminals, which will not be repeated here.

[0279] One embodiment of the present invention provides a server for executing the security operation and maintenance method described above.

[0280] One embodiment of the present invention provides an operation and maintenance device for executing the security operation and maintenance method described above.

[0281] One embodiment of the present invention provides a smart terminal, which is used to execute the security operation and maintenance method described above.

[0282] An embodiment of the present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described security operation and maintenance method.

[0283] An embodiment of the present invention also provides a chip for executing a computer program, which, when executed by the chip, implements the aforementioned security operation and maintenance method.

[0284] Specifically, this embodiment provides a chip, including: a processor; a memory for storing a computer program executed by the processor; the processor is used to read the computer program from the memory and execute the computer program to implement the security operation and maintenance method.

[0285] The preferred embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the specific details of the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solution of the present invention, and these simple modifications all fall within the protection scope of the present invention.

[0286] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, the present invention will not describe the various possible combinations separately.

[0287] Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a microcontroller, chip, or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0288] Furthermore, various different embodiments of the present invention can be combined in any way, as long as they do not violate the spirit of the present invention, they should also be regarded as the content disclosed by the present invention.

Claims

1. A security operation and maintenance method, applicable to servers, characterized in that, The security operation and maintenance methods include: In response to a first session request initiated by the maintenance equipment, negotiate with the maintenance equipment a first combination algorithm to match the session security level in the first session request; In response to the first channel access request initiated by the maintenance equipment, a first access authentication is performed based on the maintenance equipment identifier and the smart terminal identifier in the first channel access request and the first combination algorithm; If the first access authentication is successful, a session key is generated based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and the session key is sent to the maintenance device; and In response to a second session request initiated by the smart terminal, the session key is sent to the smart terminal so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm.

2. The security operation and maintenance method according to claim 1, characterized in that, The first channel access request also includes the first current time. Accordingly, the first access authentication includes: In response to the first channel access request initiated by the maintenance device, the maintenance device is authenticated for access based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm. Upon successful access authentication of the maintenance equipment, a first value of the first combined algorithm is determined regarding the maintenance equipment identifier, the smart terminal identifier, and the first current time, and this first value is sent to the maintenance equipment; and In response to the signal from the maintenance equipment indicating successful access authentication of the server, the first access authentication is confirmed to be successful. The successful access authentication of the server is confirmed by the maintenance equipment when the first value and the second value are equal, and the second value is the value of the first combination algorithm for the maintenance equipment identifier, the smart terminal identifier, and the first current time.

3. The security operation and maintenance method according to claim 2, characterized in that, The access authentication of the maintenance equipment includes: In response to the first channel access request initiated by the maintenance equipment and the action of sending the third value of the first combined algorithm regarding both the maintenance equipment identifier and the smart terminal identifier, a fourth value of the first combined algorithm regarding both the maintenance equipment identifier and the smart terminal identifier is determined; and If the third value is equal to the fourth value, the access authentication of the maintenance equipment is confirmed to be successful.

4. The security operation and maintenance method according to claim 2, characterized in that, The access authentication of the maintenance equipment includes: In response to the first channel access request initiated by the maintenance equipment, a random number is sent to the maintenance equipment; In response to the operation and maintenance equipment sending a fifth value of the first combination algorithm regarding the random number, the operation and maintenance equipment identifier, and the smart terminal identifier, a sixth value of the first combination algorithm regarding the random number, the operation and maintenance equipment identifier, and the smart terminal identifier is determined; and If the fifth value is equal to the sixth value, the access authentication of the maintenance equipment is confirmed to be successful.

5. The security operation and maintenance method according to claim 1, characterized in that, While performing the step of negotiating and matching the session security level in the first session request with the maintenance equipment, the security maintenance method further includes: sending the maintenance equipment identifier to the maintenance equipment.

6. The security operation and maintenance method according to claim 1, characterized in that, Sending the session key to the smart terminal includes: In response to the second session request initiated by the smart terminal, negotiate with the smart terminal a third combination algorithm to match the session security level in the second session request; In response to the second channel access request initiated by the smart terminal, a second access authentication is performed based on the maintenance equipment identifier and smart terminal identifier in the second channel access request and the third combination algorithm; If the second access authentication is successful, the session key is sent to the smart terminal.

7. The security operation and maintenance method according to claim 6, characterized in that, The second channel access request also includes a second current time. Accordingly, the second access authentication includes: In response to the second channel access request of the smart terminal, the smart terminal is authenticated for access based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; If the access authentication of the smart terminal is successful, the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time is determined, and the seventh value is sent to the smart terminal; and In response to the signal from the smart terminal indicating successful access authentication to the server, the second access authentication is confirmed to be successful. The successful access authentication to the server is confirmed by the smart terminal when the seventh value and the eighth value are equal, and the eighth value is the value of the third combination algorithm for the maintenance equipment identifier, the smart terminal identifier, and the second current time.

8. The security operation and maintenance method according to claim 7, characterized in that, The access authentication of the smart terminal includes: In response to the second channel access request from the smart terminal and the action of sending the ninth value of the third combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier, the tenth value of the third combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier is determined; and If the ninth value is equal to the tenth value, the access authentication of the smart terminal is confirmed to be successful.

9. The security operation and maintenance method according to claim 7, characterized in that, The access authentication of the smart terminal includes: In response to the second channel access request from the smart terminal, a random number is sent to the smart terminal; In response to the smart terminal sending the eleventh value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, the twelfth value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier is determined; and If the eleventh value is equal to the twelfth value, the access authentication of the smart terminal is confirmed to be successful.

10. The security operation and maintenance method according to claim 6, characterized in that, While performing the step of negotiating and matching the session security level in the second session request with the smart terminal, the security operation and maintenance method further includes: sending the smart terminal identifier to the smart terminal.

11. The security operation and maintenance method according to claim 6, characterized in that, The first combination algorithm for negotiating and matching the session security level in the first session request with the maintenance equipment includes: In response to the first session request initiated by the maintenance equipment, a first algorithm library that matches the session security level in the first session request is selected from multiple algorithm libraries; Multiple algorithms are randomly selected from the first algorithm library, and the randomly selected algorithms are used to generate the first combined algorithm according to preset rules, forming a generation identifier for the first combined algorithm; and Send the generation identifier of the first combined algorithm to the operation and maintenance equipment, and / or The third combination algorithm for negotiating and matching the session security level in the second session request with the smart terminal includes: In response to a second session request initiated by a smart terminal, a second algorithm library that matches the session security level in the second session request is selected from multiple algorithm libraries; Multiple algorithms are randomly selected from the second algorithm library, and the randomly selected algorithms are used to generate the third combined algorithm according to preset rules, forming a generation identifier for the third combined algorithm; and Send the generation identifier of the third combination algorithm to the smart terminal.

12. A safe operation and maintenance method, applicable to the operation and maintenance of equipment, characterized in that, The security operation and maintenance methods include: Initiate the first session request to the server; In response to the result of a first combination algorithm that matches the session security level in the first session request negotiated with the server, a first channel access request is initiated to the server, wherein the first channel access request includes: maintenance equipment identifier and smart terminal identifier; Based on the maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm, a first access authentication is performed; If the first access authentication is successful, the server responds to the second session request initiated by the smart terminal by issuing an action based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm to generate a session key, and receives the session key; Initiate a third session request to the smart terminal; In response to the result that the session key in the third session request is the same as the received session key, the smart terminal negotiates a second combination algorithm with the smart terminal to match the session security level in the third session request; and A session is established between the session key and the smart terminal based on the session key and the second combination algorithm.

13. The security operation and maintenance method according to claim 12, characterized in that, The first channel access request also includes the first current time. Accordingly, the first access authentication includes: Based on the maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm, the server performs access authentication for the maintenance equipment. Upon successful access authentication of the maintenance equipment, in response to the server sending the first value of the first combined algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the current time, a second value of the first combined algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the current time is determined; and If the first value and the second value are equal, the access authentication of the server is confirmed to be successful.

14. The security operation and maintenance method according to claim 13, characterized in that, The step of cooperating with the server to perform access authentication for the maintenance equipment includes: Determine the third value of the first combined algorithm with respect to both the maintenance equipment identifier and the smart terminal identifier; and The third value is sent to the server so that the server can confirm the successful access authentication of the maintenance device based on the fact that the third value is equal to the fourth value of the first combination algorithm regarding both the maintenance device identifier and the smart terminal identifier.

15. The security operation and maintenance method according to claim 13, characterized in that, The step of cooperating with the server to perform access authentication for the maintenance equipment includes: In response to the server sending a random number, a fifth value of the first combination algorithm is determined for the random number, the maintenance equipment identifier, and the smart terminal identifier. The fifth value is then sent to the server so that the server can confirm the successful access authentication of the maintenance equipment based on the fact that the fifth value is equal to the sixth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

16. The security operation and maintenance method according to claim 12, characterized in that, The maintenance equipment identifier is sent by the server in response to the first session request.

17. The security operation and maintenance method according to claim 12, characterized in that, The second combination algorithm for negotiating and matching the session security level in the third session request with the smart terminal includes: In response to the result that the smart terminal finds that the session key in the third session request is the same as the received session key, a third algorithm library that matches the session security level in the third session request is selected from multiple algorithm libraries; Multiple algorithms are randomly selected from the third algorithm library, and the randomly selected algorithms are used to generate the second combined algorithm according to preset rules, forming a generation identifier for the second combined algorithm; and Send the generation identifier of the second combination algorithm to the smart terminal.

18. A security operation and maintenance method, applicable to smart terminals, characterized in that, The security operation and maintenance methods include: Initiate a second session request to the server; In response to the server's action of sending the maintenance device identifier, the smart terminal identifier, and the session key generated by the first combination algorithm in the first session request initiated by the maintenance device, the session key is received. In response to a third session request initiated by the maintenance equipment, the session key in the third session request is compared with the received session key; If the session key in the third session request is the same as the received session key, negotiate with the maintenance equipment a second combination algorithm to match the session security level in the third session request; and A session is established between the session key and the maintenance equipment based on the session key and the second combination algorithm.

19. The security operation and maintenance method according to claim 18, characterized in that, After performing the step of initiating a second session request to the server, the security operation and maintenance method further includes: In response to the result of a third combination algorithm that negotiates and matches the session security level in the second session request with the server, a second channel access request is initiated to the server, wherein the second channel access request includes: maintenance equipment identifier and smart terminal identifier; Based on the maintenance equipment identifier, the smart terminal identifier, and the third combined algorithm, a second access authentication is performed; and If the second access authentication is successful, the server is notified to issue the session key.

20. The security operation and maintenance method according to claim 19, characterized in that, The second channel access request also includes a second current time. Accordingly, the second access authentication includes: Based on the maintenance equipment identifier, the smart terminal identifier, and the third combined algorithm, the server performs access authentication for the smart terminal. Upon successful access authentication of the smart terminal, in response to the server sending the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, the eighth value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time is determined; and If the seventh value is equal to the eighth value, the server's access authentication is confirmed to be successful.

21. The security operation and maintenance method according to claim 20, characterized in that, The step of cooperating with the server to perform access authentication for the smart terminal includes: Determine the ninth value of the third combination algorithm with respect to both the maintenance equipment identifier and the smart terminal identifier; and The ninth value is sent to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the ninth value is equal to the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier.

22. The security operation and maintenance method according to claim 20, characterized in that, The step of cooperating with the server to perform access authentication for the smart terminal includes: In response to the server sending a random number, the third combination algorithm determines the eleventh value of the random number, the maintenance equipment identifier, and the smart terminal identifier, and sends the eleventh value to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the eleventh value is equal to the twelfth value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

23. The security operation and maintenance method according to claim 19, characterized in that, The smart terminal identifier is sent by the server in response to the second session request.

24. A security operation and maintenance system, applicable to servers, characterized in that, The security operation and maintenance system includes: A negotiation device is used to negotiate with the maintenance equipment a first combination algorithm that matches the session security level in the first session request in response to a first session request initiated by the maintenance equipment. An authentication device is configured to, in response to a first channel access request initiated by the maintenance equipment, perform first access authentication based on the maintenance equipment identifier and the smart terminal identifier in the first channel access request and the first combination algorithm; and A key generation device is used to perform the following operations: If the first access authentication is successful, a session key is generated based on the maintenance device identifier, the smart terminal identifier, and the first combination algorithm, and the session key is then sent to the maintenance device; and In response to a second session request initiated by the smart terminal, the session key is sent to the smart terminal so that the smart terminal and the maintenance equipment can establish a session based on the session key and the second combination algorithm.

25. The security operation and maintenance system according to claim 24, characterized in that, The first channel access request also includes the first current time. Accordingly, the authentication device includes: An authentication unit is configured to respond to a first channel access request initiated by the maintenance device and perform access authentication on the maintenance device based on the maintenance device identifier, the smart terminal identifier, and the first combined algorithm. The numerical determination unit is configured to, upon successful access authentication of the maintenance equipment, determine a first value of the first combined algorithm for the maintenance equipment identifier, the smart terminal identifier, and the first current time, and send the first value to the maintenance equipment; and The result confirmation unit is used to respond to the signal from the operation and maintenance equipment that the server has successfully completed access authentication, and to confirm that the first access authentication is successful. The successful access authentication of the server is confirmed by the operation and maintenance equipment when the first value and the second value are equal, and the second value is the value of the first combination algorithm for the operation and maintenance equipment identifier, the smart terminal identifier, and the first current time.

26. The security operation and maintenance system according to claim 25, characterized in that, The authentication unit is used to perform access authentication for the maintenance equipment, including: In response to the first channel access request initiated by the maintenance equipment and the action of sending the third value of the first combined algorithm regarding both the maintenance equipment identifier and the smart terminal identifier, a fourth value of the first combined algorithm regarding both the maintenance equipment identifier and the smart terminal identifier is determined; and If the third value is equal to the fourth value, the access authentication of the maintenance equipment is confirmed to be successful.

27. The security operation and maintenance system according to claim 25, characterized in that, The authentication unit is used to perform access authentication for the maintenance equipment, including: In response to the first channel access request initiated by the maintenance equipment, a random number is sent to the maintenance equipment; In response to the operation and maintenance equipment sending a fifth value of the first combination algorithm regarding the random number, the operation and maintenance equipment identifier, and the smart terminal identifier, a sixth value of the first combination algorithm regarding the random number, the operation and maintenance equipment identifier, and the smart terminal identifier is determined; and If the fifth value is equal to the sixth value, the access authentication of the maintenance equipment is confirmed to be successful.

28. The security operation and maintenance system according to claim 24, characterized in that, The key generation device for sending the session key to the smart terminal includes: In response to the second session request initiated by the smart terminal, negotiate with the smart terminal a third combination algorithm to match the session security level in the second session request; In response to the second channel access request initiated by the smart terminal, a second access authentication is performed based on the maintenance equipment identifier and the smart terminal identifier in the second channel access request and the third combination algorithm; and If the second access authentication is successful, the session key is sent to the smart terminal.

29. The security operation and maintenance system according to claim 28, characterized in that, The second channel access request also includes a second current time. Accordingly, the key generation device for performing the second access authentication includes: In response to the second channel access request of the smart terminal, the smart terminal is authenticated for access based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; If the access authentication of the smart terminal is successful, the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time is determined, and the seventh value is sent to the smart terminal; and In response to the second access authentication success signal fed back by the smart terminal, wherein the access authentication success of the server is confirmed by the smart terminal when the seventh value and the eighth value are equal, and the eighth value is the value of the third combination algorithm for the operation and maintenance equipment identifier, the smart terminal identifier and the second current time.

30. The security operation and maintenance system according to claim 29, characterized in that, The key generation device is used for access authentication of the smart terminal, including: In response to the second channel access request from the smart terminal and the action of sending the ninth value of the third combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier, the tenth value of the third combination algorithm regarding both the maintenance equipment identifier and the smart terminal identifier is determined; and If the ninth value is equal to the tenth value, the access authentication of the smart terminal is confirmed to be successful.

31. The security operation and maintenance system according to claim 29, characterized in that, The key generation device is used for access authentication of the smart terminal, including: In response to the second channel access request from the smart terminal, a random number is sent to the smart terminal; In response to the smart terminal sending the eleventh value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier, the twelfth value of the third combination algorithm regarding the random number, the maintenance equipment identifier, and the smart terminal identifier is determined; and If the eleventh value is equal to the twelfth value, the access authentication of the smart terminal is confirmed to be successful.

32. A security operation and maintenance system, applicable to the operation and maintenance of equipment, characterized in that, The security operation and maintenance system includes: The first initiating device is used to initiate a first session request to the server; The second initiating device is used to initiate a first channel access request to the server in response to the result of a first combination algorithm that matches the session security level in the first session request negotiated with the server, wherein the first channel access request includes: maintenance equipment identifier and smart terminal identifier; An authentication device is used to perform a first access authentication based on the operation and maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm; A receiving device is configured to, upon successful first access authentication, respond to the server's action of issuing a session key based on the maintenance equipment identifier, the smart terminal identifier, and the first combination algorithm in response to a second session request initiated by the smart terminal, and receive the session key; The third initiating device is used to initiate a third session request to the smart terminal; A negotiation device, configured to, in response to the result that the smart terminal compares the session key in the third session request with the received session key and finds that they are the same, negotiate with the smart terminal a second combination algorithm to match the session security level in the third session request; and A session establishment device is used to establish a session with the smart terminal based on the session key and a second combination algorithm.

33. The security operation and maintenance system according to claim 32, characterized in that, The first channel access request also includes the first current time. Accordingly, the authentication device includes: The authentication unit is used to perform access authentication of the maintenance equipment based on the maintenance equipment identifier, the smart terminal identifier, and the first combined algorithm, in conjunction with the server. The numerical verification unit is configured to, upon successful access authentication of the maintenance equipment, respond to the server sending a first value of the first combined algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the current time, determine a second value of the first combined algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the current time; and The result confirmation unit is used to confirm that the server's access authentication is successful when the first value and the second value are equal.

34. The security operation and maintenance system according to claim 33, characterized in that, The authentication unit is used in conjunction with the server to perform access authentication for the maintenance equipment, including: Determine the third value of the first combined algorithm with respect to both the maintenance equipment identifier and the smart terminal identifier; and The third value is sent to the server so that the server can confirm the successful access authentication of the maintenance device based on the fact that the third value is equal to the fourth value of the first combination algorithm regarding both the maintenance device identifier and the smart terminal identifier.

35. The security operation and maintenance system according to claim 33, characterized in that, The authentication unit is used in conjunction with the server to perform access authentication for the maintenance equipment, including: In response to the server sending a random number, a fifth value of the first combination algorithm is determined for the random number, the maintenance equipment identifier, and the smart terminal identifier. The fifth value is then sent to the server so that the server can confirm the successful access authentication of the maintenance equipment based on the fact that the fifth value is equal to the sixth value of the first combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

36. A security operation and maintenance system, applicable to smart terminals, characterized in that, The security operation and maintenance system includes: The first initiating device is used to initiate a second session request to the server; The receiving device is configured to receive the session key in response to the server sending the operation and maintenance equipment identifier, the smart terminal identifier, and the session key generated by the first combination algorithm in the first session request initiated by the operation and maintenance equipment; The first authentication device is used to compare the session key in the third session request with the received session key in response to the third session request initiated by the maintenance equipment. A negotiation device is configured to negotiate with the maintenance equipment a second combination algorithm to match the session security level in the third session request, provided that the session key in the third session request is the same as the received session key; and A session establishment device is used to establish a session with the maintenance equipment based on the session key and a second combination algorithm.

37. The security operation and maintenance system according to claim 36, characterized in that, The security operation and maintenance system also includes: The second initiating device is used to initiate a second channel access request to the server in response to the result of a third combination algorithm that negotiates and matches the session security level in the second session request with the server, wherein the second channel access request includes: maintenance equipment identifier and smart terminal identifier; The second authentication device is used to perform second access authentication based on the maintenance equipment identifier, the smart terminal identifier, and the third combination algorithm; and A notification device is used to notify the server to issue the session key when the second access authentication is successful.

38. The security operation and maintenance system according to claim 37, characterized in that, The second channel access request also includes a second current time. Accordingly, the second authentication device for performing the second access authentication includes: Based on the maintenance equipment identifier, the smart terminal identifier, and the third combined algorithm, the server performs access authentication for the smart terminal. Upon successful access authentication of the smart terminal, in response to the server sending the seventh value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time, the eighth value of the third combination algorithm regarding the maintenance equipment identifier, the smart terminal identifier, and the second current time is determined; and If the seventh value is equal to the eighth value, the server's access authentication is confirmed to be successful.

39. The security operation and maintenance system according to claim 38, characterized in that, The second authentication device is used in conjunction with the server to perform access authentication for the smart terminal, including: Determine the ninth value of the third combination algorithm with respect to both the maintenance equipment identifier and the smart terminal identifier; and The ninth value is sent to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the ninth value is equal to the tenth value of the third combination algorithm for both the maintenance equipment identifier and the smart terminal identifier.

40. The security operation and maintenance system according to claim 38, characterized in that, The second authentication device is used in conjunction with the server to perform access authentication for the smart terminal, including: In response to the server sending a random number, the third combination algorithm determines the eleventh value of the random number, the maintenance equipment identifier, and the smart terminal identifier, and sends the eleventh value to the server so that the server can confirm the successful access authentication of the smart terminal based on the fact that the eleventh value is equal to the twelfth value of the third combination algorithm for the random number, the maintenance equipment identifier, and the smart terminal identifier.

41. A server, characterized in that, The server is used to execute the security operation and maintenance method according to any one of claims 1-11.

42. A maintenance equipment, characterized in that, The maintenance equipment is used to perform the security maintenance method according to any one of claims 12-17.

43. A smart terminal, characterized in that, The smart terminal is used to execute the security operation and maintenance method according to any one of claims 18-23.

44. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the security operation and maintenance method according to any one of claims 1-23.

45. A chip, characterized in that, Used to execute a computer program, which, when executed by the chip, implements the security operation and maintenance method according to any one of claims 1-23.

Citation Information

Patent Citations

  • Data transmission method, system and device in WiMAX system

    CN101895882A

  • Method and a device for safely interacting on-site operation and maintenance data

    CN109257328A