A Remote Operation and Maintenance Method, System, Device and Medium for Edge Terminals
By responding to heartbeat requests, decrypting the encrypted request body and verifying it, opening the VPN channel, the security risks and lack of flexibility caused by the operation and maintenance of the public network triggered interface are solved, and the secure transmission of edge terminal data and timely handling of unexpected problems are realized.
Patent Information
- Application Number
- CN202410048818.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-01-12
AI Technical Summary
In the construction of industrial informationization, equipment operation and maintenance is carried out through the public network trigger interface, resulting in the industrial network exposure of security risks and the inability to flexibly deal with equipment emergencies.
It provides a remote operation and maintenance method for edge terminals. By responding to the heartbeat request of edge terminals, it receives and decrypts the encrypted request body, verifies the decryption result and opens the VPN channel to realize the secure transmission of operation and maintenance data.
It improves security during data transmission, prevents tampering and loss, enhances the security and reliability of the network, and can promptly deal with unexpected problems at edge terminals.
Smart Images

Figure CN117938479B_ABST
Abstract
Description
Background Art
[0002] In the process of industrial informatization construction, it often involves the construction of edge systems at the factory site and centralized management and control in the cloud. Taking the coal mine electronic seal as an example, the video recognition of the electronic seal often requires video processing and AI analysis based on the boxes at the edge of the enterprise site. However, the training of the AI analysis model and the update of the system rely on the cloud on the central side. Since similar products are often deployed in multiple enterprises, off-site maintenance often has problems such as high cost and slow response. Similar products often use the form of interface triggering to send instructions from the cloud to the edge terminal. After receiving the instructions, the edge terminal requests from the cloud to obtain the corresponding updates. However, this method often has several drawbacks. First, it requires the enterprise side to open the public network port, exposing the industrial network to the outside, resulting in security risks. Second, this method can often only pull some model files for updates, and other in-depth updates such as the underlying operating system often cannot be completed. Third, the edge information that can be obtained by the cloud in this way is limited, and only some preset problems can be solved, and some sudden problems are difficult to troubleshoot and solve.
[0003] This method of selecting the corresponding operation and maintenance plan for equipment through the trigger interface in the public network will expose the industrial network and cause network security risks, and it is also impossible to flexibly handle sudden problems of equipment. Summary of the Invention
[0004] In order to overcome the problems that the method of selecting the corresponding operation and maintenance plan for equipment through the trigger interface in the public network will expose the industrial network and cause network security risks, and it is also impossible to flexibly handle sudden problems of equipment, the present invention provides a remote operation and maintenance method, system, device and medium for edge terminals.
[0005] In a first aspect, to solve the above technical problems, the present invention provides a remote operation and maintenance method for edge terminals, which is applied to the cloud and includes:
[0006] Respond to the heartbeat request sent by the edge terminal and receive the encrypted request body sent by the edge terminal;
[0007] Decrypt the encrypted request body to determine the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature;
[0008] Decrypt the encrypted edge terminal information stamp to determine the first decryption result, and decrypt the encrypted MD5 signature to determine the second decryption result;
[0009] If the first decryption result and the address information meet the first preset requirement, and the second decryption result, the address information, and the encrypted edge terminal information stamp meet the second preset requirement, then open the VPN channel corresponding to the edge terminal and transmit operation and maintenance data through the VPN channel.
[0010] In a second aspect, the present invention further provides a remote operation and maintenance system for an edge terminal, including:
[0011] a receiving module, configured to receive an encrypted request body sent by the edge terminal in response to a heartbeat request sent by the edge terminal;
[0012] a first decryption module, configured to decrypt the encrypted request body to determine an encrypted edge - end information stamp, the address information of the edge terminal, and an encrypted MD5 signature;
[0013] a second decryption module, configured to decrypt the encrypted edge - end information stamp to determine a first decryption result, and decrypt the encrypted MD5 signature to determine a second decryption result;
[0014] a transmission module, configured to open a VPN channel corresponding to the edge terminal and transmit operation and maintenance data through the VPN channel if the first decryption result and the address information meet a first preset requirement, and the second decryption result, the address information, and the encrypted edge - end information stamp meet a second preset requirement.
[0015] In a third aspect, the present invention further provides a computing device, including a memory, a processor, and a program stored in the memory and running on the processor. When the processor executes the program, the steps of a remote operation and maintenance method for an edge terminal as described above are implemented.
[0016] In a fourth aspect, the present invention further provides a computer - readable storage medium. Instructions are stored in the computer - readable storage medium. When the instructions run on a terminal device, the terminal device is enabled to execute the steps of a remote operation and maintenance method for an edge terminal.
[0017] The beneficial effects of the present invention are as follows: By responding to the heartbeat request sent by the edge terminal and receiving the encrypted request body of the edge terminal, the encrypted and secure transmission of data of the edge terminal is achieved. Decrypting the encrypted request body to obtain the encrypted edge - end information stamp, the address information of the edge terminal, and the encrypted MD5 signature, and when both the first decryption result determined by decrypting the encrypted edge - end information stamp and the second decryption result determined by decrypting the encrypted MD5 signature meet the corresponding preset requirements, that is, when the data in the encrypted request body sent by the edge terminal is successfully verified, the VPN channel corresponding to the edge terminal is opened to transmit operation and maintenance data. In this way, since the edge terminal needs to be operated and maintained only when a sudden problem occurs, at this time, responding to the heartbeat request sent by the edge terminal facilitates opening the VPN channel in a timely and secure manner, enabling the operation and maintenance personnel to handle the sudden problems of the edge terminal in a timely manner. This method of encrypting the transmission request body and transmitting operation and maintenance data through the VPN channel after successful decryption and verification not only improves the security of data during transmission but also prevents the transmission of incorrect data such as tampering and loss, which poses a threat to network security. Description of the Drawings
[0018] Figure 1 It is a schematic flow chart of a remote operation and maintenance method for an edge terminal of the present invention;
[0019] Figure 2 It is an information diagram of the certificate file of the edge terminal of the present invention;
[0020] Figure 3 It is a schematic diagram of the certificate file structure of the edge terminal of the present invention;
[0021] Figure 4 It is another schematic flow chart of a remote operation and maintenance method for an edge terminal of the present invention;
[0022] Figure 5 It is an entity relationship architecture diagram of the present invention;
[0023] Figure 6 It is a schematic diagram of the structure of a remote operation and maintenance system for an edge terminal of the present invention. Detailed implementation manners
[0024] The following embodiments are further explanations and supplements to the present invention and do not constitute any limitation to the present invention.
[0025] The following describes a remote operation and maintenance method, system, device, and medium for an edge terminal according to an embodiment of the present invention with reference to the accompanying drawings.
[0026] A remote operation and maintenance method for an edge terminal according to an embodiment of the present invention, which is applied to a terminal device. In the solution of the present application, the terminal device is used as the execution subject to illustrate the solution of the present application, and the terminal device is used to execute the steps of a remote operation and maintenance method for an edge terminal.
[0027] As Figure 1 shown, the present invention provides a remote operation and maintenance method for an edge terminal, which is applied to the cloud and includes:
[0028] Step S1, in response to a heartbeat request sent by the edge terminal, receive an encrypted request body sent by the edge terminal;
[0029] Step S2, decrypt the encrypted request body to determine an encrypted edge - end information stamp, the address information of the edge terminal, and an encrypted MD5 signature;
[0030] Step S3, decrypt the encrypted edge - end information stamp to determine a first decryption result, and decrypt the encrypted MD5 signature to determine a second decryption result;
[0031] Step S4, if the first decryption result and the address information meet the first preset requirement, and the second decryption result, the address information, and the encrypted edge terminal information stamp meet the second preset requirement, then open the VPN channel corresponding to the edge terminal, and transmit the operation and maintenance data through the VPN channel.
[0032] A remote operation and maintenance method for an edge terminal provided in this embodiment realizes the encrypted and secure transmission of data of the edge terminal by responding to a heartbeat request sent by the edge terminal and receiving the encrypted request body of the edge terminal. Decrypt the encrypted request body to obtain the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature, and when both the first decryption result determined by decrypting the encrypted edge terminal information stamp and the second decryption result determined by decrypting the encrypted MD5 signature meet the corresponding preset requirements, that is, when the data in the encrypted request body sent by the edge terminal is successfully verified, open the VPN channel corresponding to the edge terminal to transmit the operation and maintenance data. In this way, since the edge terminal needs to be operated and maintained only when a sudden problem occurs, at this time, respond to the heartbeat request sent by the edge terminal, which is convenient for timely and securely opening the VPN channel, enabling the operation and maintenance personnel to handle the sudden problems of the edge terminal in time. This method of encrypting the transmission request body and transmitting the operation and maintenance data through the VPN channel after successful decryption verification not only improves the security of the data during transmission but also prevents the transmission of incorrect data such as tampering and loss in the VPN channel, posing a threat to network security.
[0033] In some embodiments, the heartbeat request is a request sent by the edge terminal to open the VPN channel. The edge terminal sends a heartbeat request to the cloud every preset time interval. When the operation and maintenance personnel need to perform remote operation and maintenance on a certain edge terminal, they need to respond to the heartbeat request on the operation and management platform of the cloud, receive the encrypted request body sent by the edge terminal, and use it to determine whether to open the VPN virtual private network channel; when it is confirmed that the VPN channel needs to be opened, the cloud decrypts the received encrypted request body and verifies the decrypted data. When the verification is successful, that is, the first decryption result and the address information meet the first preset requirement, and the second decryption result, the address information, and the encrypted edge terminal information stamp meet the second preset requirement, then open the VPN channel corresponding to the edge terminal, and transmit the operation and maintenance data through the VPN channel, so as to realize timely and secure opening of the corresponding VPN channel to transmit the operation and maintenance data to the edge terminal when the edge terminal needs to be operated and maintained. At the same time, when it is confirmed that the VPN channel needs to be opened, the edge terminal stops sending the heartbeat request to the cloud every preset time interval, which can reduce the misresponse of the cloud to the heartbeat request, thereby improving the data processing performance of the server.
[0034] Optionally, receiving the encrypted request body sent by the edge terminal includes:
[0035] Obtain the edge terminal certificate and address information of the edge terminal; among them, the edge terminal certificate includes an encrypted edge terminal information stamp, an RSA public key, and a DES key;
[0036] Use the MD5 algorithm to generate the MD5 signature corresponding to the encrypted edge terminal information stamp and address information;
[0037] Use the RSA public key to encrypt the MD5 signature to obtain the encrypted MD5 signature;
[0038] Use the DES key to encrypt the encrypted edge terminal information stamp, address information, and encrypted MD5 signature as a whole to obtain the encrypted request body.
[0039] In this embodiment, the RSA public key in the edge terminal certificate of the edge terminal is used to encrypt the MD5 signature corresponding to the encrypted edge terminal information stamp and address information to obtain the encrypted MD5 signature, and the DES key in the edge terminal certificate of the edge terminal is used to encrypt the encrypted edge terminal information stamp, address information, and encrypted MD5 signature as a whole to obtain the encrypted request body. In this way, the keys in the edge terminal certificate in the edge terminal are used to perform secondary encryption on the data that the cloud needs to receive, which can ensure the data integrity of the encrypted request body before transmission, so as to facilitate subsequent verification of whether the data in the received encrypted request body is complete in the cloud.
[0040] In some embodiments, a certificate file (i.e., the edge terminal certificate) issued by the cloud is stored in the system of the edge terminal. As Figure 2 shown, the certificate file (i.e., the edge terminal certificate) includes a factory information stamp (i.e., the edge terminal information stamp), an RSA public key, and a DES key. Among them, the factory information stamp is Information_stamp; eyJhbGciOiJIUzUxMiJ9.eyJsb2dpbl91c2, the RSA public key is Information_stamp:MEgCQQDLahzJ2LShhI7HYAXO8DFf7qIzyLCfrKhEoO6flOqHeEs35+v8qCFOj3sheMWNXXEr0cBkAILX / eoUaxKIOa / 7AgMBAAE=, and the DES key is DES_Key:VHulxxM2EJHEGowyQcGHBobk.
[0041] The method for obtaining the edge terminal certificate is as Figure 3As shown, when the edge terminal leaves the factory, it stores the serial number generated from the corresponding factory information in the cloud. The factory information includes the serial number, customer number, factory time, MAC address, and public network IP address. The serial number of the factory information is encrypted using the RSA public key in the cloud to obtain the edge terminal information stamp. The cloud uses this edge terminal information stamp, the RSA public key, and a DES key as the edge terminal certificate file, which facilitates the edge terminal to use this edge terminal certificate file for verification during use and avoids network security issues caused by illegal devices using this edge terminal certificate file.
[0042] Optionally, the encrypted request body is the request body encrypted with the DES key; decrypt the encrypted request body to determine the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature, including:
[0043] Find the DES password corresponding to the DES key in the DES password library;
[0044] Use the DES password to decrypt the encrypted request body to obtain the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature.
[0045] In this embodiment, compared with the method of decrypting the encrypted request body with multiple DES passwords in sequence, the present invention uses the DES key corresponding to the encrypted request body to find the corresponding DES password to decrypt the encrypted request body, which can reduce the decryption time and thus improve the decryption efficiency.
[0046] Optionally, the encrypted edge terminal information stamp is the factory information encrypted with the RSA public key; decrypt the encrypted edge terminal information stamp to determine the first decryption result, including:
[0047] Find the RSA private key corresponding to the RSA public key in the preset private key library;
[0048] Use the RSA private key to decrypt the encrypted edge terminal information stamp to obtain the factory information, which includes the factory time, device serial number, customer number, MAC address, and IP address;
[0049] Determine the factory information as the first decryption result.
[0050] In this embodiment, compared with the method of decrypting the encrypted edge terminal information stamp with multiple RSA private keys in sequence, the present invention uses the RSA public key corresponding to the encrypted edge terminal information stamp to find the corresponding RSA private key to decrypt the encrypted edge terminal information stamp, which can reduce the decryption time and thus improve the decryption efficiency.
[0051] Optionally, the encrypted MD5 signature is the MD5 information encrypted with the RSA public key; decrypt the encrypted MD5 signature to determine the second decryption result, including:
[0052] Find the RSA private key corresponding to the RSA public key in the preset private key library;
[0053] Use the RSA private key to decrypt the encrypted MD5 signature to obtain the decrypted MD5 signature;
[0054] Determine the decrypted MD5 signature as the second decryption result.
[0055] In this embodiment, compared with the method of decrypting the encrypted MD5 signature sequentially using multiple RSA private keys, the present invention uses the RSA public key corresponding to the encrypted MD5 signature to find the corresponding RSA private key to decrypt the encrypted MD5 signature, which can reduce the decryption time and thus improve the decryption efficiency.
[0056] Optionally, if the first decryption result and the address information meet the first preset requirement, and the second decryption result, the address information, and the encrypted edge terminal information stamp meet the second preset requirement, then open the VPN channel corresponding to the edge terminal, including:
[0057] Determine the MD5 signature jointly corresponding to the encrypted edge terminal information stamp and the address information; wherein, the address information includes the edge terminal MAC address and the edge terminal IP address;
[0058] If the first decryption result contains information identical to the address information, and the second decryption result is the same as the MD5 signature, then open the VPN channel corresponding to the edge terminal.
[0059] In this embodiment, the fact that the first decryption result contains information identical to the address information indicates that all the data information in the edge terminal information stamp is the data information of this edge terminal. The fact that the second decryption result is the same as the MD5 signature jointly corresponding to the encrypted edge terminal information stamp and the address information indicates that the data in the encrypted request body has not been tampered with and / or lost during the transmission from the edge terminal to the cloud, and the encrypted request body received by the cloud is complete. Therefore, when the first decryption result contains information identical to the address information and the second decryption result is the same as the MD5 signature, it indicates that this edge terminal is legitimate and the data transmission channel of this edge terminal is secure. At this time, opening the VPN channel corresponding to the edge terminal can make the subsequent operation and maintenance data transmitted through this VPN channel be secure data, thereby improving the security of remote operation and maintenance of the edge terminal and ensuring the data integrity of data transmission with the edge terminal.
[0060] Optionally, the method further includes:
[0061] Generate an operation audit record corresponding to the operation and maintenance data;
[0062] Store the operation audit record.
[0063] In this embodiment, operation and maintenance data generates corresponding operation audit records during the transmission process, and stores the operation audit records, which is convenient for subsequent tracing and sorting out the problems that occur in each edge terminal and the corresponding operation and maintenance processes and times, so as to achieve real-time and effective supervision of each edge terminal. When an operation and maintenance personnel needs to perform remote operation and maintenance on a certain edge terminal with problems, after opening the operation and maintenance switch corresponding to the edge terminal (that is, opening the corresponding VPN channel) on the operation and management platform in the cloud, the corresponding operation and maintenance data is transmitted to handle the problems that occur in the edge terminal, and the system will automatically generate relevant operation audit records at the same time. Among them, the operation audit records include the VPN channel opening time, the transmission content and transmission time of the operation and maintenance data, etc.
[0064] Figure 4 Another process schematic diagram of a remote operation and maintenance method for an edge terminal of the present invention is as Figure 4 shown, including a cloud device and an edge side (edge terminal). The edge terminal contains an edge-side certificate issued by the cloud. The edge-side certificate contains an encrypted edge-side information stamp, an RSA public key, and a DES key. The edge terminal also contains the MAC address of the built-in network card, the IP address obtained from the network, and the Internet time. When a remote operation and maintenance method for an edge terminal is executed, first, the encrypted edge-side information stamp, RSA public key, and DES key are obtained from the edge-side certificate. The encrypted edge-side information stamp, MAC address, IP address, and other information that the edge terminal needs to transmit are combined into request data, and the encrypted edge-side information stamp, MAC address, IP address, and other information that the edge terminal needs to transmit are jointly MD5-signed. The request data is encrypted using the RSA public key in the edge-side certificate to determine the encrypted request data, and the MD5 signature is encrypted using the RSA public key in the edge-side certificate to obtain the encrypted MD5 signature. The encrypted request data and the encrypted MD5 signature are combined into a request body, and the request body is encrypted using the DES key in the edge-side certificate to obtain the encrypted request body (that is, the encrypted request body).
[0065] The edge terminal sends a heartbeat request to the cloud every preset time interval, requesting to open the VPN channel. When a problem occurs with the edge terminal, the cloud responds to the heartbeat request sent by the edge terminal at the current time and receives the encrypted request body sent by the edge terminal. The cloud looks up the DES password corresponding to the DES key in the DES password library and uses the DES password to decrypt the encrypted request body to determine the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature. The cloud looks up the RSA private key corresponding to the RSA public key in the preset private key library and uses the RSA private key to decrypt the encrypted edge terminal information stamp to determine the first decryption result, that is, to determine the factory information, which includes the serial number, customer number, factory time, MAC address, and public network IP address, and uses the RSA private key to decrypt the encrypted MD5 signature to determine the second decryption result, that is, to determine the decrypted MD5 signature, which includes the encrypted edge terminal information, MAC address, IP address, and other information to be transmitted by the edge terminal. Information comparison is performed on the first decryption result, MAC address, and IP address to verify whether the first decryption result and the address information meet the first preset requirement. At the same time, signature comparison is performed on the MD5 signature jointly corresponding to the MAC address, IP address, encrypted edge terminal information stamp, and other information to be transmitted by the edge terminal and the second decryption result to verify whether the second decryption result, address information, and encrypted edge terminal information stamp meet the second preset requirement. That is, if the first decryption result contains information identical to the address information and the second decryption result is the same as the MD5 signature jointly of the encrypted edge terminal information stamp and the address information, the VPN channel corresponding to the edge terminal is opened, and operation and maintenance data are transmitted through the VPN channel.
[0066] In some embodiments, after the edge terminal is deployed to the customer site, the system obtains information such as the MAC address and system time of the device where it is located. The data request content of the edge terminal includes: the edge terminal information stamp, the locally obtained MAC address encrypted with the RSA public key, the locally obtained IP, and other service information, and all content is encrypted as a whole using the DES key to ensure the confidentiality of the data through DES encryption. After receiving the request, the cloud verifies the encrypted edge terminal information. First, it decrypts the request body using the DES key to obtain the edge terminal information stamp, and then uses the RSA private key stored in the cloud to decrypt the edge terminal information stamp to obtain the IP information and MAC information recorded at the time of leaving the factory. The IP and MAC information obtained from the edge terminal information stamp are compared with the local information in the request body, and the legitimacy of the request is confirmed by judging whether the data is consistent; then the RSA private key is used to decrypt the encrypted MD5 signature to complete the MD5 signature verification, realize the integrity verification of the data, and ensure the non-repudiation of the data.
[0067] Figure 5 For the entity relationship architecture diagram of the present invention, asFigure 5 As shown, it includes a cloud server, each factory, and the edge devices (edge terminals) produced by each factory. Each factory binds the edge terminal certificate through IP, and the edge terminal certificate is bound to the edge device through MAC. Thus, at the time of factory shipment, each edge device has a corresponding unique edge terminal certificate. Among them, the edge terminal certificate contains an edge terminal information stamp, and the edge terminal information stamp contains the factory shipment information of the edge device. At the same time, the cloud server stores the edge terminal certificates of each edge device through the device information library, and then the cloud server conducts data transmission with the edge devices corresponding to the edge terminal certificates stored in the device information library through the VPN virtual channel, thereby realizing the
[0068] The present invention provides a cloud-edge remote operation and maintenance technology based on a virtual private network, which realizes remote edge terminal control based on the method of interface interaction. Using VPN to establish a network architecture for remote control at the network level provides a safe and efficient method, enabling remote maintenance personnel to securely remotely access and control devices located within a private network. This complex network architecture includes multiple key components, providing comprehensive security protection for remote control operations.
[0069] The public network serves as a transmission channel, and data security transmission is ensured through VPN encryption. Within the private network, the VPN server is responsible for managing connection requests and establishing a secure encrypted channel. The security protocols and authentication mechanisms it adopts effectively prevent unauthorized access. The firewall, as a security guardian, monitors and controls data traffic to protect the private network from potential external threats.
[0070] The local area network in a private network includes various remote control devices, such as servers, routers, and switches. Through a VPN connection, a remote control terminal can securely access and control these devices remotely, enabling real-time monitoring and operation. The entire architecture ensures the security and privacy of data transmission while providing efficient remote control capabilities, enabling remote maintenance personnel to conveniently handle the faults, configurations, and maintenance of various network devices. The present invention can achieve the following effects: 1. Improved security: In addition to the traditional VPN encrypting data transmission to protect data from threats such as hackers and unauthorized access during transmission, the VPN channel in this solution is not a real-time connection. Each time the channel is opened, relevant personnel need to operate at the management end, forming an audit log, which strengthens the post-event supervision and traceability capabilities. 2. Authentication and authorization: By issuing certificates, it is ensured that each device has a unique certificate, and the certificate information is bound to the device and the customer, making it difficult to be stolen. 3. Convenient remote access: Allows remote maintenance personnel to remotely access and control devices within the private network at any time, improving the convenience and efficiency of operations. 4. Cost savings: Through remote control, the need for on-site maintenance can be reduced, thus saving labor costs and time costs. 5. Data privacy protection: The VPN protects the privacy of sensitive data through encrypted transmission, preventing data leakage or being obtained by third parties. 6. Cross-platform compatibility: The VPN supports connections across different operating systems and devices, making remote control operations more flexible and universal. 7. Network topology remains stable: By establishing a virtual private network through the VPN, the original network topology structure can be kept stable and not affected by remote access. 8. Real-time monitoring ability: Remote control enables remote maintenance personnel to monitor the device status and network operation in real time and handle potential problems promptly.
[0071] As Figure 6 shown, the present invention provides a remote operation and maintenance system for an edge terminal, including:
[0072] A receiving module, configured to receive an encrypted request body sent by the edge terminal in response to a heartbeat request sent by the edge terminal;
[0073] A first decryption module, configured to decrypt the encrypted request body to determine an encrypted edge terminal information stamp, the address information of the edge terminal, and an encrypted MD5 signature;
[0074] A second decryption module, configured to decrypt the encrypted edge terminal information stamp to determine a first decryption result, and decrypt the encrypted MD5 signature to determine a second decryption result;
[0075] A transmission module, configured to open the VPN channel corresponding to the edge terminal and transmit operation and maintenance data through the VPN channel if the first decryption result and the address information meet a first preset requirement, and the second decryption result, the address information, and the encrypted edge terminal information stamp meet a second preset requirement.
[0076] Optionally, the receiving module is specifically configured to:
[0077] Obtain the edge terminal certificate and address information of the edge terminal; wherein, the edge terminal certificate includes an encrypted edge terminal information stamp, an RSA public key, and a DES key;
[0078] Use the MD5 algorithm to generate an MD5 signature corresponding to the encrypted edge terminal information stamp and address information;
[0079] Use the RSA public key to encrypt the MD5 signature to obtain an encrypted MD5 signature;
[0080] Use the DES key to encrypt the encrypted edge terminal information stamp, address information, and encrypted MD5 signature as a whole to obtain an encrypted request body.
[0081] Optionally, the first decryption module is specifically configured to:
[0082] Find the DES password corresponding to the DES key in the DES password library;
[0083] Use the DES password to decrypt the encrypted request body to obtain the encrypted edge terminal information stamp, the address information of the edge terminal, and the encrypted MD5 signature.
[0084] Optionally, the second decryption module is specifically configured to:
[0085] Find the RSA private key corresponding to the RSA public key in the preset private key library;
[0086] Use the RSA private key to decrypt the encrypted edge terminal information stamp to obtain the factory information, where the factory information includes the factory time, device serial number, customer number, MAC address, and IP address;
[0087] Determine the factory information as the first decryption result.
[0088] Optionally, the second decryption module is specifically configured to:
[0089] Find the RSA private key corresponding to the RSA public key in the preset private key library;
[0090] Use the RSA private key to decrypt the encrypted MD5 signature to obtain the decrypted MD5 signature;
[0091] Determine the decrypted MD5 signature as the second decryption result.
[0092] Optionally, the transmission module is specifically configured to:
[0093] Determine the MD5 signature corresponding to the encrypted edge terminal information stamp and address information;
[0094] If the first decryption result contains information identical to the address information and the second decryption result is the same as the MD5 signature, then the VPN channel corresponding to the edge terminal is opened.
[0095] Optionally, the system further includes a storage module. The storage module is specifically configured to:
[0096] Generate an operation audit record corresponding to the operation and maintenance data;
[0097] Store the operation audit record.
[0098] A computing device according to an embodiment of the present invention includes a memory, a processor, and a program stored in the memory and running on the processor. When the processor executes the program, it implements some or all of the steps of the above remote operation and maintenance method for an edge terminal.
[0099] Among them, the computing device can be a computer. Correspondingly, its program is computer software. And the above parameters and steps in a computing device according to the present invention can refer to the parameters and steps in the embodiment of the remote operation and maintenance method for an edge terminal in the foregoing text, and will not be elaborated herein.
[0100] A computer-readable storage medium according to an embodiment of the present invention stores instructions therein. When the instructions are running, they execute the steps of the above remote operation and maintenance method for an edge terminal.
[0101] Among them, the computer-readable storage medium can be a transient computer-readable storage medium or a non-transient computer-readable storage medium.
[0102] The technical solution of the embodiment of the present disclosure can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes one or more instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method of the embodiment of the present disclosure. And the foregoing computer-readable storage medium can be a non-transient computer-readable storage medium, including: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes, or can also be a transient computer-readable storage medium.
[0103] Those skilled in the art of the present technology know that the present invention can be implemented as a system, a method, or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms, namely: it can be entirely hardware, can also be entirely software (including firmware, resident software, microcode, etc.), or can also be in the form of a combination of hardware and software, which is generally referred to as "circuit", "module", or "system" in this article. In addition, in some embodiments, the present invention can also be implemented in the form of a computer program product in one or more computer-readable media, which contain computer-readable program codes. Computer-readable storage media can be, for example, but not limited to - electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above.
[0104] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0105] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A remote operation and maintenance method for an edge terminal, characterized in that: Applied in the cloud, including: When an edge terminal has a sudden problem, in response to a heartbeat request sent by the edge terminal at intervals of a preset time length, receiving an encrypted request body sent by the edge terminal; Decrypt the encrypted request body to determine the encrypted edge information stamp, the address information of the edge terminal and the encrypted MD5 signature; wherein the encrypted edge information stamp is the factory information encrypted by the RSA public key, and the factory information includes the serial number, customer number, factory time, MAC address and public IP address; Decrypting the encrypted edge information stamp to determine a first decryption result, and decrypting the encrypted MD5 signature to determine a second decryption result; wherein the second decryption result is a signature generated using the MD5 algorithm; Determine the MD5 signature corresponding to the encrypted edge information stamp and the address information; If the first decryption result contains information that is the same as the address information, and the second decryption result is the same as the MD5 signature, the VPN channel corresponding to the edge terminal is opened, and operation and maintenance data is transmitted through the VPN channel, and the edge terminal is controlled to stop sending heartbeat requests at every preset time interval.
2. The method according to claim 1, characterized in that The receiving an encrypted request body sent by the edge terminal includes: Obtaining an edge terminal certificate and address information of the edge terminal; wherein the edge terminal certificate includes an encrypted edge terminal information stamp, an RSA public key, and a DES key; Using the MD5 algorithm, generate an MD5 signature corresponding to the encrypted edge information stamp and the address information; Encrypt the MD5 signature using the RSA public key to obtain an encrypted MD5 signature; The encrypted edge information stamp, the address information and the encrypted MD5 signature are encrypted as a whole using a DES key to obtain an encrypted request body.
3. The method according to claim 1, characterized in that The encrypted request body is a request body encrypted by a DES key; the decrypting of the encrypted request body to determine the encrypted edge terminal information stamp, the address information of the edge terminal and the encrypted MD5 signature includes: Find out the DES password corresponding to the DES key in the DES password library; The encrypted request body is decrypted using the DES cipher to obtain the encrypted edge terminal information stamp, the address information of the edge terminal and the encrypted MD5 signature.
4. The method according to claim 1, characterized in that: The decrypting the encrypted edge information stamp to determine a first decryption result includes: Find the RSA private key corresponding to the RSA public key in the preset private key library; Decrypt the encrypted edge information stamp using the RSA private key to obtain factory information, where the factory information includes factory time, device serial number, customer number, MAC address, and IP address; The factory information is determined as a first decryption result.
5. The method according to claim 1, characterized in that The encrypted MD5 signature is MD5 information encrypted by an RSA public key; and decrypting the encrypted MD5 signature to determine a second decryption result includes: Find the RSA private key corresponding to the RSA public key in the preset private key library; Decrypt the encrypted MD5 signature using the RSA private key to obtain a decrypted MD5 signature; The decrypted MD5 signature is determined as the second decryption result.
6. The method according to any one of claims 1 to 5, characterized in that: Also includes: Generate an operation audit record corresponding to the operation and maintenance data; The operation audit record is stored.
7. A remote operation and maintenance system for an edge terminal, characterized in that: include: A receiving module, configured to receive an encrypted request body sent by the edge terminal in response to a heartbeat request sent by the edge terminal at intervals of a preset duration when an emergency problem occurs at the edge terminal; A first decryption module is used to decrypt the encrypted request body to determine the encrypted edge information stamp, the address information of the edge terminal and the encrypted MD5 signature; wherein the encrypted edge information stamp is the factory information encrypted by the RSA public key, and the factory information includes a serial number, a customer number, a factory time, a MAC address and a public IP address; A second decryption module is used to decrypt the encrypted edge information stamp to determine a first decryption result, and to decrypt the encrypted MD5 signature to determine a second decryption result; wherein the second decryption result is a signature generated using the MD5 algorithm; A transmission module is used to determine the MD5 signature corresponding to the encrypted edge information stamp and the address information; if the first decryption result contains the same information as the address information, and the second decryption result is the same as the MD5 signature, then open the VPN channel corresponding to the edge terminal, and transmit operation and maintenance data through the VPN channel, and control the edge terminal to stop sending heartbeat requests at every preset time interval.
8. A computing device comprising a memory, a processor, and a program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the steps of a remote operation and maintenance method of an edge terminal as described in any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, and when the instructions are executed on the terminal device, the terminal device executes the steps of a remote operation and maintenance method of an edge terminal as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Data source device authentication method and device and network device
CN107579999A
Information encryption method and device, server and medium
CN114422109A
Equipment fingerprint generation method and device, equipment and medium
CN116723032A
Method for sharing authentication key between terminal and maintenance server and method for terminal remote maintenance implementation
JP2001197058A