A Gas Meter Security Authentication Method Based on SM Cryptography Algorithm and Related Devices
Through the gas meter safety authentication method based on the Guomi algorithm, the key management model and ESAM module are used to solve the security vulnerabilities of the gas meter remote meter reading system, and efficient and secure data transmission and storage are achieved, improving the overall operating efficiency and security of the system.
Patent Information
- Application Number
- CN202411552012.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-01
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-11-01
AI Technical Summary
The existing remote meter reading system of gas meter is mainly based on the certification of software modules, with security vulnerabilities and is easily compromised by attackers, resulting in illegal access or data tampering. There may be security risks during software updates and upgrades, threatening personal privacy and data security of gas companies.
The gas meter security authentication method based on the national secret algorithm is adopted. By obtaining the key negotiation file issued by the server, a key management model is used to generate a key allocation strategy, access the ESAM module to obtain preconfigured encrypted files, encrypt the gas meter data, and upload the encrypted data to the server. The server decrypts based on the pre-deployed decryption policy to ensure the security of data transmission and storage.
It improves the security and operation efficiency of the gas meter system, reduces the communication overhead caused by key updates, ensures high security and reliability of the data transmission process, and realizes flexible key management and intelligent key update strategies.
Smart Images

Figure CN119483935B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data processing, and particularly relates to a gas meter security authentication method based on national cryptographic algorithms and related devices. Background Art
[0002] In the traditional gas meter industry, the prepayment method is mainly adopted. Users need to hold a gas IC card to go to the gas business hall or the gas charging representative point to purchase gas, and then insert the gas card with the gas purchase record into the gas meter IC card socket to complete the process of gas purchase recharge. The whole process requires traveling back and forth between the gas business hall and home, which brings inconvenience to users' daily lives.
[0003] With the gradual maturity of wireless technology, the penetration of wireless signals is getting stronger and the coverage is getting wider. Wireless remote meter reading has started its performance, which gets rid of the bondage of wired remote meter reading. With the development of the Internet of Things technology, the Internet of Everything is quietly happening, and the Internet of Things meters have also emerged, making remote meter reading more "intelligent". In recent years, intelligent meter reading has become increasingly popular, and the gas industry has also kept up with the times and has started to research, produce, and promote intelligent gas meters. The development of intelligent gas meters and the emergence of remote meter reading in the gas industry have brought great convenience, but at the same time, security is an urgent problem to be solved, especially involving the security of people's livelihood infrastructure, which requires an effective security authentication method to ensure.
[0004] Currently, the gas meter remote meter reading system mainly relies on software module authentication, but this software authentication based on network carriers has great security vulnerabilities. No matter what security algorithms and protocols are adopted, it may be broken by professional attackers, thereby obtaining illegal access rights or tampering with data. Moreover, there may also be security vulnerabilities during the software update and upgrade process. If strict testing and verification are not carried out, new security problems may occur. Hackers may steal data through the network, and then steal user information, which poses a threat to both personal privacy and the data security of gas companies.
[0005] Therefore, to solve the above at least one technical problem, there is an urgent need to propose a brand-new gas meter security authentication scheme based on national cryptographic algorithms. Summary of the Invention
[0006] This application provides a gas meter security authentication method based on national cryptographic algorithms and related devices to solve the technical problems existing in the current security authentication scheme mainly based on software modules.
[0007] In a first aspect, this application provides a gas meter security authentication method based on national cryptographic algorithms, and the method includes:
[0008] The gas meter obtains a key negotiation file sent by the server;
[0009] Adopt a key management model, perform prediction processing according to the key negotiation file, and obtain a key distribution strategy corresponding to the gas meter;
[0010] Access the ESAM module based on the key distribution strategy, and obtain a pre-configured encryption file in the ESAM module that matches the key distribution strategy; the ESAM module is pre-deployed in the gas meter, and the ESAM module is built based on a national cryptographic security chip;
[0011] Use the pre-configured encryption file to perform data encryption in the gas meter, and upload the encrypted gas meter data to the server, so that the server can complete the decryption of the gas meter data based on a pre-deployed decryption strategy; the decryption strategy matches the key distribution strategy predicted based on the key negotiation file.
[0012] In a second aspect, an embodiment of the present application provides a gas meter security authentication device based on a national cryptographic algorithm, and this device is applied to a gas meter; this device includes:
[0013] An acquisition unit, configured to acquire a key negotiation file sent by the server;
[0014] A prediction unit, configured to adopt a key management model and perform prediction processing according to the pre-configured key information in the key negotiation file to obtain a key distribution strategy corresponding to the gas meter;
[0015] A configuration unit, configured to access the ESAM module based on the key distribution strategy, and obtain a pre-configured encryption file in the ESAM module that matches the key distribution strategy; the ESAM module is pre-deployed in the gas meter, and the ESAM module is built based on a national cryptographic security chip;
[0016] An encryption unit, configured to use the pre-configured encryption file to perform data encryption in the gas meter, and upload the encrypted gas meter data to the server, so that the server can complete the decryption of the gas meter data based on a pre-deployed decryption strategy; the decryption strategy matches the key distribution strategy predicted based on the key negotiation file.
[0017] In a third aspect, an embodiment of the present application provides a computing device, and this computing device includes:
[0018] At least one processor, a memory, and an input-output unit;
[0019] Wherein, the memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute a gas meter security authentication method based on a national cryptographic algorithm in the first aspect.
[0020] In a fourth aspect, a computer-readable storage medium is provided, which includes instructions that, when executed on a computer, cause the computer to execute a gas meter security authentication method based on a national cryptographic algorithm according to the first aspect.
[0021] In the technical solution provided by the embodiments of the present application, first, the gas meter obtains a key negotiation file sent by the server. Then, using a key management model, prediction processing is performed according to the key negotiation file to obtain a key distribution strategy corresponding to the gas meter. Furthermore, based on the key distribution strategy, the ESAM module is accessed, and a pre-configured encryption file matching the key distribution strategy in the ESAM module is obtained. The ESAM module is pre-deployed in the gas meter and is constructed based on a national cryptographic security chip. Finally, the pre-configured encryption file is used to perform data encryption in the gas meter, and the encrypted gas meter data is uploaded to the server so that the server can complete the decryption of the gas meter data based on a pre-deployed decryption strategy. The decryption strategy matches the key distribution strategy predicted based on the key negotiation file.
[0022] In the technical solution of the present application, a national cryptographic security chip (such as algorithms like SM2, SM3, SM4, etc.) is used to ensure the security of key storage and transmission and avoid the risk of key leakage. Through key negotiation and dynamic key distribution, it is ensured that different keys are used at different times and communication stages to prevent replay attacks and eavesdropping. The key time management model is used to intelligently predict the key update timing and distribution strategy, reducing the communication burden caused by overly frequent key updates while ensuring the timeliness of the keys. Through pre-configured encryption files and a distributed key management mode, the frequent communication between the device side and the server is reduced, improving the operating efficiency of the system. The gas meter uses the ESAM module to locally encrypt the data to ensure that the data uploaded to the server will not be tampered with during transmission. The server decrypts the data based on a decryption strategy consistent with the key negotiation to ensure the integrity and availability of the uploaded data. In summary, by introducing a key management model with a multi-layer structure, the gas meter can intelligently predict the key update strategy and flexibly respond to security challenges in communication. At the same time, relying on the support of the ESAM module and national cryptographic algorithms, the entire data transmission and storage process has high security and reliability. This solution not only ensures the flexibility of key management but also reduces the communication overhead caused by key updates, improving the overall operating efficiency and security of the gas meter system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0024] Figure 1It is a schematic flowchart of a gas meter security authentication method based on national cryptography algorithms according to an embodiment of the present application;
[0025] Figure 2 It is a schematic diagram of the principle of a gas meter security authentication method based on national cryptography algorithms according to an embodiment of the present application;
[0026] Figure 3 It is a schematic structural diagram of a gas meter security authentication device based on national cryptography algorithms according to an embodiment of the present application;
[0027] Figure 4 It is a schematic structural diagram of an electronic device according to an embodiment of the present application. Detailed implementation manners
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application herein are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0030] Currently, the gas meter remote meter reading system mainly focuses on the authentication of software modules. However, this software authentication based on a network carrier has significant security vulnerabilities. No matter what security algorithms and protocols are adopted, it may be broken by professional attackers, thereby obtaining unauthorized access rights or tampering with data. Moreover, there may also be security vulnerabilities during the software update and upgrade process. If strict testing and verification are not carried out, new security problems may occur. Hackers may steal data through the network and then steal user information, which poses a threat to both personal privacy and the data security of gas companies.
[0031] In the related art, the existing gas meter security authentication is mainly divided into two methods: One is the authentication scheme without a dedicated cryptographic algorithm. The gas meter and the gas background server pre-agree on a software protocol and perform data interaction through general logical processing, and basically do not use specific security algorithms. This authentication scheme without a dedicated cryptographic algorithm has almost no security. The data between the gas meter and the background server is transmitted in plain text, and sensitive information is directly exposed on the public network, posing serious security risks.
[0032] Another is the software password algorithm authentication scheme. The gas meter and the background server perform software security authentication through a specific algorithm. The algorithm implementation and key storage are both completed in the software. Although this software password algorithm authentication scheme introduces a specific security algorithm, its security is still relatively low, and the highest security level is EAL2+. Since the core authentication algorithm and key information are only stored in the software storage area, and there may be security vulnerabilities in the operating system and the software itself, the key information is actually in a potentially exposed state, and the security is difficult to be effectively guaranteed.
[0033] To solve the above at least one technical problem, the embodiments of the present application provide a gas meter security authentication method and related device based on the national cryptographic algorithm.
[0034] Specifically, first, the gas meter obtains the key negotiation file sent by the server. Then, using the key management model, predictive processing is performed according to the key negotiation file to obtain the key distribution strategy corresponding to the gas meter. Furthermore, based on the key distribution strategy, the ESAM module is accessed, and the pre-configured encryption file matching the key distribution strategy in the ESAM module is obtained. The ESAM module is pre-deployed in the gas meter and is built based on the national cryptographic security chip. Finally, the pre-configured encryption file is used to perform data encryption in the gas meter, and the encrypted gas meter data is uploaded to the server so that the server completes the decryption of the gas meter data based on the pre-deployed decryption strategy. The decryption strategy matches the key distribution strategy predicted based on the key negotiation file.
[0035] In the technical solution of the present application, on the one hand, a secure connection is first established between the gas meter and the server to obtain the key negotiation file sent by the server. This file contains the key information during communication (such as key types, update strategies) and the update rules triggered by time periods or events. On the other hand, the gas meter analyzes the information in the key negotiation file through the pre-set key management model and performs predictive processing. For example, this model can analyze the communication mode of the device based on the Temporal Convolutional Network (TCN) and predict the appropriate key update period in the future. Thus, according to the prediction result, the corresponding key distribution strategy is generated, specifying which keys should be used or when to trigger key updates at different time points. This model makes the key update more accurate, reduces the unnecessary update frequency, and ensures the security and communication efficiency of the system. Moreover, the key negotiation file contains the key update rules and strategies during the communication cycle. The gas meter predicts the key requirements at different stages through the model. The distribution strategy specifies when to extract the encryption file from the ESAM module and which keys to use to encrypt the data.
[0036] Furthermore, according to the key distribution policy, the gas meter accesses the local ESAM module, in which a set of encrypted files has been pre-deployed. The gas meter obtains the pre-configured encrypted file that matches the current distribution policy from the ESAM module. Here, ESAM (Embedded Secure Access Module) is a hardware module based on the national cryptographic chip, which supports encryption, decryption, and digital signature operations, ensuring the secure storage and use of keys within the device.
[0037] Furthermore, the gas meter uses the matching pre-configured encrypted file to encrypt the collected data. The encrypted data is uploaded to the server through the communication network. At this time, the data is secure during the transmission process, preventing it from being tampered with or eavesdropped on by a third party. After receiving the encrypted gas meter data, the server completes the data decryption according to the pre-deployed decryption policy. The decryption policy corresponds one-to-one with the previously negotiated key distribution policy, ensuring that the server can correctly decrypt the uploaded data. After the server successfully decrypts the data, it will perform an integrity verification on the data to ensure that the data has not been tampered with during the transmission process.
[0038] Finally, the decrypted data will be used for gas metering, bill generation, or other applications. The decryption policy on the server is consistent with the encryption policy of the gas meter. By matching the corresponding keys through the information in the negotiated file, the consistency of the data during upload and storage is ensured.
[0039] Through the technical solution of this application, by introducing a multi-layer key management model, the gas meter can intelligently predict the key update policy and flexibly cope with security challenges in communication. At the same time, relying on the support of the ESAM module and the national cryptographic algorithm, the entire data transmission and storage process has high security and reliability. This solution not only ensures the flexibility of key management but also reduces the communication overhead caused by key updates, improving the overall operation efficiency and security of the gas meter system.
[0040] A gas meter security authentication scheme based on the national cryptographic algorithm provided by the embodiments of this application can be executed by an electronic device, which can be a server, a server cluster, or a cloud server. The electronic device can also be a terminal device such as a mobile phone, a computer, a tablet computer, a wearable device, or a dedicated device (such as a dedicated terminal device with a gas meter security authentication system based on the national cryptographic algorithm, etc.). In an optional embodiment, a service program for executing a gas meter security authentication scheme based on the national cryptographic algorithm can be installed on the electronic device.
[0041] Figure 1 As shown in the schematic diagram of a gas meter security authentication method based on the national cryptographic algorithm provided by the embodiments of this application, Figure 1 as shown, the method includes the following steps:
[0042] 101. The gas meter obtains the key negotiation file sent by the server;
[0043] 102. Adopt a key management model, perform prediction processing according to the key negotiation file, and obtain the key distribution strategy corresponding to the gas meter;
[0044] 103. Access the ESAM module based on the key distribution strategy, and obtain the pre-configured encryption file in the ESAM module that matches the key distribution strategy;
[0045] 104. Use the pre-configured encryption file to perform data encryption in the gas meter, and upload the encrypted gas meter data to the server, so that the server can complete the decryption of the gas meter data based on the pre-deployed decryption strategy.
[0046] In the embodiment of the present application, the key negotiation file is a file sent by the server to the gas meter, which contains relevant information for key management and update during communication. Specifically, the key type indicates the type of key to be used for encryption and decryption, such as a key based on the national cryptographic algorithm (such as SM2, SM3, SM4). The key update strategy stipulates the update rules of the key, including when the key needs to be updated or replaced (based on time, data volume or specific events). The time period or event trigger rule specifies in what time period or based on which events to trigger the key update or renegotiation. The role of the key negotiation file is to provide all the information required for key management for the gas meter, including how to generate, distribute and update keys, so that the gas meter can use appropriate encryption keys at different time periods according to this information, ensuring the security and effectiveness of communication.
[0047] In the embodiment of the present application, the key distribution strategy is a strategy generated by the gas meter through the key management model to analyze and predict the received key negotiation file. This strategy is used to guide how the gas meter uses and distributes keys at specific times or under specific conditions. Specifically, the key distribution strategy includes the following information: the key usage time point, which is used to clarify when to use a specific key for encryption operations to ensure data security; the key update timing, which indicates when the key in use needs to be updated, possibly based on a time interval, data transmission volume or a specific event received; the selection of the matching encryption file, which specifies which pre-configured encryption file needs to be extracted from the ESAM module to ensure that the encryption operation meets the current key distribution requirements. Through the key distribution strategy, the gas meter can effectively manage and utilize key resources, ensure security during data transmission, and at the same time ensure the efficiency of the key update process.
[0048] In the embodiments of the present application, the ESAM module is pre-deployed in the gas meter, and the ESAM module is built based on a national cryptographic security chip. The ESAM module (Embedded Secure Access Module) is a hardware module built based on a national cryptographic security chip, mainly used to ensure key management and data security in devices such as gas meters. Key files for encryption, decryption, and signature are securely stored in the ESAM module. These key files are pre-configured and matched with the key distribution policy. Due to the hardware-level security design, the keys are not easily accessible or tampered with externally, ensuring the security of the device. The ESAM module supports encryption and decryption functions based on national cryptographic algorithms. Common national cryptographic algorithms include: SM2, an elliptic curve-based public key encryption algorithm mainly used for key exchange and signature verification; SM3, a secure hash algorithm used to generate data digests to ensure data integrity; and SM4, a block encryption algorithm used for symmetric encryption of data to ensure secure transmission of communication data.
[0049] In addition, the ESAM module also supports the generation and verification of digital signatures, which are used to ensure data authenticity and anti-tampering functions. During the communication process, the digital signature can ensure that the receiving party can verify whether the data comes from a trusted source and has not been modified. Since the ESAM module is built based on a national cryptographic security chip and has hardware-level protection functions, including means such as anti-physical attacks and protection against chip probing, it further enhances the security of the device.
[0050] It can be seen that the ESAM module plays a key role in the gas meter, ensuring that key management, secure storage, and encryption and decryption operations within the device are carried out at a high security level, providing strong support for secure communication between the gas meter and the server.
[0051] In the embodiments of the present application, the decryption policy matches the key distribution policy predicted based on the key negotiation file. That is, the decryption policy is consistent and matched with the key distribution policy predicted by the gas meter based on the key negotiation file, ensuring that data transmission between the gas meter and the server can be carried out securely and reliably. The decryption policy closely cooperates with the key distribution policy at the gas meter end to ensure the security and consistency of data during transmission. Through the decryption policy formulated based on the key negotiation file, the server can dynamically adapt to the key usage situation at the gas meter end, avoiding decryption failures or data leaks, and achieving reliable data decryption and secure communication.
[0052] It can be understood that the decryption policy needs to be consistent with the key distribution policy at the gas meter end, which means that the server must accurately understand when, based on what rules, and which keys the gas meter uses to encrypt data. First of all, the decryption policy stipulates that the key version or ID used needs to be consistent with that at the gas meter end to ensure that the server can correctly decrypt the corresponding data. And if the gas meter updates the key according to the key negotiation file, the decryption policy of the server will also be dynamically adjusted to use the same key version for decryption. Secondly, data format matching is crucial. The server decryption policy needs to ensure that the data format and algorithm used in its decryption process are the same as the encryption operation at the gas meter end. For example, if the gas meter uses the SM4 symmetric encryption algorithm for data encryption, the server decryption policy also needs to use the same algorithm to decrypt the data. In addition, if the data encryption at the gas meter end contains certain metadata (such as timestamp, key ID, etc.), the server needs to be able to identify and process this information. The decryption policy also needs to ensure that the decryption algorithm and process match, using the same algorithm as when the gas meter encrypts (such as SM2, SM3, SM4), and at the same time identify and read the event trigger points or update times in the key distribution policy to ensure that the corresponding key is called for decryption at the correct time. If it is found during the decryption process that the data cannot be correctly decrypted (such as key version mismatch or data tampering), the server can trigger a retransmission request and cooperate with the gas meter to update the key or resend the data. Finally, security monitoring and logging are part of the decryption policy, recording the key operations and abnormal situations during the decryption process, which are used to track whether data has been leaked or keys are not synchronized. These log information is extremely useful for auditing and subsequent key management optimization.
[0053] As an optional embodiment, in 101, first, the gas meter uploads a preprocessing message for starting the encryption process to the server. The preprocessing message at least includes: authentication request, handshake data, security signature information, and identity authentication information. The preprocessing message undergoes a first encryption process through pre-negotiation. Further, in 101, the gas meter receives the key negotiation file sent by the server in response to the preprocessing message. The key negotiation file at least includes: key configuration type, key configuration parameters, and key configuration timing. The key negotiation file is obtained through a second encryption process that matches the first encryption process.
[0054] Specifically, in this optional embodiment, the key negotiation between the gas meter and the server is mainly divided into two steps: uploading the preprocessing message and receiving the key negotiation file. Before starting the encryption process, the gas meter first needs to send a preprocessing message containing necessary information to the server. This message mainly includes:
[0055] Authentication request: used to request the server to verify the identity of the gas meter to ensure the legitimacy of both communication parties.
[0056] Handshake data: Used to establish a preliminary communication connection, including handshake information such as protocol version, random number, etc.
[0057] Security signature information: Numerically sign the key information of the preprocessed message to provide data integrity verification.
[0058] Identity authentication information: Contains the identification information of the device, such as device ID or serial number, used for server-side identity verification.
[0059] The above information is encrypted through a pre-negotiated first encryption process. This process involves the selection of encryption algorithms and keys to ensure that the transmitted message will not be eavesdropped or tampered with during transmission.
[0060] Furthermore, the gas meter sends the encrypted preprocessed message to the server and waits for the server's response. This process ensures that only authenticated and authorized devices can initiate the subsequent key negotiation process. After verifying and processing the preprocessed message of the gas meter, the server generates a key negotiation file. This file specifically includes:
[0061] Key configuration type: Describes which type of key configuration is used, such as symmetric key or public-private key pair.
[0062] Key configuration parameters: Details of the parameters for configuring the key, such as key length, algorithm type, etc.
[0063] Key configuration timing: Indicates when or under what conditions these keys are used or updated.
[0064] Next, the key negotiation file generated by the server is encrypted through a second encryption process that matches the first encryption process. This means that this encryption process uses a compatible or negotiated algorithm and key to ensure that the gas meter can correctly decrypt and read the file content. The encrypted key negotiation file is transmitted to the gas meter. After receiving the file, the gas meter uses the corresponding decryption algorithm to interpret the key negotiation file and updates or adjusts its key distribution strategy accordingly.
[0065] Through the above two steps, a secure and efficient key negotiation mechanism is established between the gas meter and the server. The encryption processes of the preprocessed message and the key negotiation file ensure the secure transmission of data and the confidentiality of the key, effectively avoiding unauthorized access and potential security threats. This mechanism ensures the reliability of key synchronization between the gas meter and the server and realizes secure communication encryption.
[0066] As another alternative embodiment, in 101, first, the gas meter receives the key negotiation file sent by the server based on a preset policy. This key negotiation file is similar to the previous one and will not be elaborated here. The difference is that the key negotiation file is obtained through a pre-negotiated third encryption process.
[0067] In this alternative embodiment, the gas meter receives the key negotiation file sent by the server based on a preset policy. The main difference from the previous embodiment lies in the different encryption processing methods. Specifically, the server generates and sends the key negotiation file to the gas meter according to the preset key management policy. The information contained in this file is similar to that in the previous embodiment, such as key configuration type, key configuration parameters, key configuration timing, etc. The difference is that the key negotiation file here is encrypted through a pre-negotiated third encryption process. This encryption process may adopt a more suitable encryption algorithm or key to meet specific security requirements or compatibility requirements. For example, it may adopt a specific symmetric encryption algorithm or asymmetric encryption scheme, which has been agreed upon in advance by both parties. Here, the third encryption process uses a higher-strength encryption algorithm, improving the security performance and preventing potential eavesdropping and tampering. The selected encryption algorithm is to meet certain specific protocol or device capability requirements to ensure that there are no compatibility issues between the two devices during the encryption and decryption processes. According to the preset policy, the most suitable encryption scheme for the current environment and requirements is flexibly selected. After receiving the key negotiation file, the gas meter needs to use the decryption mechanism corresponding to the third encryption process for decryption. This requires that the gas meter device supports this encryption method and holds the corresponding key or decryption information. Once the decryption is successful, the gas meter will update its key configuration according to the information in the file to ensure the security and synchronization of subsequent communications with the server.
[0068] By using the third encryption process, this embodiment enhances the protection of the aforementioned file and adjusts the encryption scheme according to specific requirements. In this way, while meeting the security requirements, the flexibility and compatibility of the encryption and decryption processes are also ensured. This adjustment makes the key negotiation process not only have higher security protection but also be able to adapt to the requirements of specific application environments.
[0069] 102. Adopt a key management model, and perform prediction processing according to the key negotiation file to obtain the key distribution policy corresponding to the gas meter.
[0070] As an alternative embodiment, assume that the key management model at least includes: a key space management model and a key time management model. Based on the above assumption, in 102, adopt a key management model, and perform prediction processing according to the key negotiation file to obtain the key distribution policy corresponding to the gas meter. See Figure 2 , as shown, can be implemented as:
[0071] 201. Extract the pre-configured key information from the key negotiation file;
[0072] 202. Adopt the key space management model to perform prediction on the pre-configured key information to obtain the key storage space configuration information corresponding to the gas meter;
[0073] 203. Use the key time management model to predict the pre-configured key information to obtain the key time configuration information corresponding to the gas meter.
[0074] 204. Generate the key distribution policy based on the key storage space configuration information and the key time configuration information; the key distribution policy is used to dynamically adjust the storage area location and key distribution timing of the key distribution.
[0075] Through steps 201 to 204, the key management model is used to perform prediction processing according to the key negotiation file, so as to obtain the key distribution policy corresponding to the gas meter, which helps to further increase the dynamics and unpredictability of the key.
[0076] In this embodiment, the key management model is used to perform prediction processing on the key distribution policy of the gas meter, and the key distribution policy is generated by analyzing the information in the key negotiation file. The following is a detailed introduction to steps 201 to 204:
[0077] In step 201, first, the gas meter or the server extracts the pre-configured key information from the key negotiation file. The pre-configured key information may include the type of the key, the initial key, the encryption algorithm, the key length, the usage range of the key, etc. This information provides the basic data for key management in subsequent steps and is the starting point for predicting and configuring the key distribution policy.
[0078] In step 202, the key space management model is used to predict the extracted pre-configured key information, and the purpose is to determine the key storage space configuration. The key space management model is a model that manages the distribution and layout of keys in the device storage space. It predicts how to best allocate and manage the key storage space according to the device's storage resources, performance requirements, and the number and size of keys. The predicted content includes but is not limited to: the specific storage location of the key in the gas meter memory, the storage area allocated to different keys, and the possibility of dynamic adjustment according to future key usage requirements. Through this prediction, the gas meter can efficiently manage limited storage resources and avoid excessive key storage or space waste.
[0079] The key management algorithm optimized by the neural network can dynamically adjust the key distribution policy to ensure that the key is not exposed at a fixed position. Even if there are vulnerabilities in the software storage area, the dynamics and unpredictability of key management can greatly improve security.
[0080] Further optionally, assume that the key space management model at least includes: a construction layer, an analysis layer, a prediction layer, and an optimization layer. Based on this, in step 202, the use of the key space management model to predict the pre-configured key information to obtain the key storage space configuration information corresponding to the gas meter can be implemented as:
[0081] Through the construction layer, according to the gas meter deployment information carried in the pre-configured key information, construct the target graph node corresponding to the gas meter in the target graph structure; the gas meter deployment information at least includes: the location information in the area where the gas meter is located, the spatial connection relationship between the gas meter and the server, and the associated architecture information in the communication network where the gas meter is located; the target graph structure corresponds to the deployment architecture of the communication network where the gas meter is located; each graph node in the target graph structure corresponds to a gas meter;
[0082] Through the analysis layer, based on the target graph structure, analyze the key correlation degree between the target graph node and other graph nodes, and the key usage frequency of the target graph node;
[0083] Through the prediction layer, predict the target key storage area of the gas meter based on the key correlation degree and the key usage frequency;
[0084] Through the optimization layer, perform risk prediction on the target key storage area to obtain the key storage space configuration information for indicating the target key storage area.
[0085] The above key space management model consists of a construction layer, an analysis layer, a prediction layer, and an optimization layer, and dynamically optimizes the key storage space configuration of the gas meter through multiple steps.
[0086] First, through the construction layer, according to the gas meter deployment information carried in the pre-configured key information, a target graph structure corresponding to the gas meter communication network architecture is constructed. Each graph node represents a gas meter, and this information includes the location information of the gas meter, the connection relationship with the server, and the network architecture. Next, in the parsing layer, based on the target graph structure, the key correlation degree and key usage frequency between graph nodes and other nodes are parsed to determine the key interaction situation of each node. Then, the prediction layer predicts the target key storage area of the gas meter according to the key correlation degree and usage frequency, and decides which specific storage area the key should be allocated to. Finally, the optimization layer evaluates the security risk by performing risk prediction on the target key storage area and generates the final key storage space configuration information to ensure the security and optimized distribution of the key in the storage area. In addition, a model based on the graph neural network (GNN) can capture the complex relationships between keys, dynamically optimize the key storage space configuration, and prevent security hazards caused by centralized key storage. Through this neural network-optimized key management algorithm, the storage location and allocation time of the key will be highly dynamic and unpredictable, greatly improving the security of the system. Even if there are vulnerabilities in the software storage area, the dynamic management of the key can still effectively prevent security risks.
[0087] Next, in step 203, the pre-configured key information is predicted using the key time management model to determine the usage timing and update period of the key. The key time management model is responsible for managing the life cycle of the key, including the time arrangements for key generation, usage, expiration, and update. It predicts the usage strategy of the key in different time periods according to factors such as the communication requirements of the device, the security policy, and the validity period of the key. The predicted content includes, but is not limited to: the usage timing of the key, the validity period, whether it needs to be updated regularly or triggered for update when specific events occur (such as device restart, key leakage risk, etc.). Through this time management, the gas meter can dynamically adjust the usage of the key to ensure the security and effectiveness of the key throughout its life cycle.
[0088] In this step, the neural network is used to learn the communication pattern, dynamically generate and allocate keys, and update and rotate them at appropriate times to minimize the risk of key exposure.
[0089] Further optionally, assume that the key time management model at least includes: an input layer, a multi-layer causal convolutional layer, an extended convolutional layer, an optimization layer, and a fully connected layer. Based on this, in step 203, the adoption of the key time management model to predict the pre-configured key information to obtain the key time configuration information corresponding to the gas meter can be realized as:
[0090] Through the input layer, convert the pre-configured key information into gas meter feature information; the gas meter feature information at least includes: communication data characteristics, communication time characteristics, and signaling transmission characteristics in the communication network where the gas meter is located;
[0091] Through multiple causal convolutional layers, use a convolutional kernel sliding window to perform communication time pattern recognition on the gas meter feature information to obtain the communication time pattern in the communication network where the gas meter is located;
[0092] Through the dilated convolutional layer, identify the long-term dependence pattern in the communication network where the gas meter is located from the gas meter feature information;
[0093] Through the optimization layer, perform optimization processing on different feature information under the communication time pattern and the long-term dependence pattern;
[0094] Through the fully connected layer, fuse all the feature information after optimization processing to obtain the key time configuration information corresponding to the gas meter.
[0095] Specifically, the design of the key time management model aims to effectively predict the timing of key update and distribution by analyzing the communication pattern of the gas meter, improving the security of the system. The model mainly consists of an input layer, multiple causal convolutional layers, a dilated convolutional layer, an optimization layer, and a fully connected layer. The input layer converts the pre-configured key information into the feature information of the gas meter, which includes communication data characteristics, communication time characteristics, and signaling transmission characteristics. This conversion provides the basic data for subsequent pattern recognition and prediction. The multiple causal convolutional layers use a convolutional kernel sliding window to identify the communication time pattern in the gas meter feature information. This process utilizes the characteristics of causal convolution to ensure that the model output does not depend on future information, thus accurately capturing the current and historical communication time patterns. The dilated convolutional layer identifies the long-term dependence pattern from the gas meter feature information. Dilated convolution can expand the receptive field of the model, enabling it to effectively capture long-term communication dependencies and thus determine the optimal timing of key update. The optimization layer performs optimization processing on different feature information under the communication time pattern and the long-term dependence pattern. This process optimizes the key time management strategy by weighing the influence of each feature to fully adapt to the complex communication environment. The fully connected layer fuses all the feature information after optimization processing to generate the key time configuration information corresponding to the gas meter. Through the complete feature fusion, this layer ensures that the generated configuration information can guide dynamic and timely key update and distribution.
[0096] In summary, by capturing changes in the communication mode of the gas meter, the model can dynamically adjust the timing of key updates and distribution, thereby enhancing system security. Frequent key updates and rotations reduce the risk of key exposure. Even in the face of cyberattacks or security vulnerabilities, the system can promptly adjust the key configuration. The temporal convolutional network has strong parallelism and can quickly process large-scale temporal data, making it suitable for complex communication environments such as Internet of Things devices. The use of dilated convolutions enhances the model's ability to capture long-term dependencies, ensuring more accurate timing of key updates and avoiding potential security risks caused by premature or delayed updates.
[0097] Generally speaking, the core of the key time management model lies in efficiently analyzing and predicting time patterns in gas meter communication to dynamically adjust the timing of key updates and distribution. The model consists of multiple key structures, each with a specific role, and achieves complex time series data processing through collaborative work. Through the learning and analysis of communication patterns by the neural network, the model effectively realizes dynamic key management, ensuring the update and distribution of keys at the appropriate time and minimizing security risks. It is applicable to complex communication environments that require flexible key management, especially the communication management of Internet of Things devices. The model achieves efficient analysis and prediction of gas meter communication patterns through causal convolutions, dilated convolutions, and optimization techniques. Using a multi-layer structure, the model can capture complex time dependencies and dynamically adjust key distribution and updates to ensure the security and reliability of the system. This structure is particularly suitable for application scenarios with high security requirements and complex communication patterns such as Internet of Things devices.
[0098] In step 204, based on the key storage space configuration information in step 202 and the key time configuration information in step 203, a comprehensive key distribution strategy is generated. The core of the key distribution strategy lies in dynamically adjusting the storage area and usage timing of keys. It will determine when keys are distributed, when they are updated, and the specific location of keys in the device's memory or storage area. For example, the strategy can specify that a certain key is distributed to a specific storage area within a specific time period, or the key is immediately updated when a certain condition is triggered (such as detecting an attack on the device). This step ensures that the gas meter always maintains flexibility and security in key management during the secure communication process, avoiding security issues caused by improper key management.
[0099] Through the above four steps, this embodiment realizes predictive processing based on the key management model and generates a key distribution strategy for the gas meter. This process, through the joint application of the key space and time management models, not only optimizes the use of key storage space but also ensures the effective management and use of keys throughout their life cycle. The generated key distribution strategy provides strong support for secure communication between the gas meter and the server.
[0100] As an alternative embodiment, in 102, a key management model is adopted. After performing prediction processing according to the pre-configured key information in the key negotiation file to obtain the key distribution policy corresponding to the gas meter, a key policy optimization model can also be adopted to predict the risk distribution of the key management policy running in the key management model, and dynamically update the key management policy based on the risk distribution prediction result. Among them, the risk probability distribution of the key management policy in the key policy optimization model is expressed as the following expression:
[0101]
[0102] Where P(I j h) represents the risk probability distribution I of the j-th key management policy in the key management environment h j . Based on the risk prediction result, the key management policy can be dynamically updated. Using the above risk probability distribution, the model can predict the risk level of the current key management policy in different environments. By identifying this risk, the system can identify potential weak links or high-risk areas, and thus make targeted adjustments.
[0103] Furthermore, adjust the weight and priority of each policy according to the real-time risk assessment, so as to optimize the overall key distribution policy and ensure security and reliability. That is, in the above formula, w h represents the weight term corresponding to the key management environment h, which is the influence weight of different environmental factors. b h represents the bias term corresponding to the key management environment h, which takes into account the basic risk level of the environment. represents the weight term corresponding to the j-th key management policy, which reflects the inherent risk degree of the policy itself. n is the maximum number of configurable keys in the key management environment h. By adjusting the key management environment weight and bias term, the model can adaptively change the policy selection to reflect the changes in the current environment. For example, in the case of detecting an increase in potential threats, the policy can be biased towards a more secure key distribution scheme.
[0104] In this alternative embodiment, the optimization of the key management policy enables the system to dynamically adjust the key management policy by introducing the key policy optimization model, so as to improve security and adaptability. By predicting and analyzing the risk probability distribution of the key management policy, possible security threats can be identified in advance, and the policy can be dynamically adjusted to reduce these risks. The model allows the key management policy to be adjusted according to the risk distribution evaluated in real time, enabling the system to adapt to the changing network environment and potential attacks. Through more precise policy adjustment, the system can more effectively allocate and use key resources, avoiding unnecessary resource waste. The model can be extended to apply to IoT devices and network environments of different scales and complexities, enhancing the flexibility of the system.
[0105] Generally speaking, the core of this embodiment lies in closely integrating risk prediction with the selection of key management strategies. By continuously evaluating and adjusting the strategies, it ensures that the system always maintains the best security state in a changing communication environment. This method is particularly suitable for applications in the Internet of Things and large-scale networks and can effectively cope with various dynamic security challenges.
[0106] In 103, access the ESAM module based on the key distribution strategy, and obtain the pre-configured encrypted file in the ESAM module that matches the key distribution strategy. In the embodiment of the present application, the ESAM module is pre-deployed in the gas meter, and the ESAM module is constructed based on the national cryptographic security chip.
[0107] In this embodiment, the ESAM module is a key security component in the gas meter, responsible for storing and processing the pre-configured encrypted file related to the key distribution strategy. By accessing the ESAM module based on the key distribution strategy, it can ensure that the communication and data transmission in the gas meter comply with the security standards.
[0108] Specifically, ESAM is a security hardware module dedicated to processing sensitive data. In this embodiment, the ESAM module is designed based on the national cryptographic algorithm (China National Cryptography Standard), ensuring the data security during the communication process of the gas meter. The ESAM module is pre-integrated in the gas meter device and serves as the security execution unit of the entire key management system. In the ESAM module of the gas meter, some encrypted files that match the key distribution strategy are pre-stored. These files are encrypted according to the national cryptographic algorithm standard and are used to protect and transmit the sensitive data of the gas meter. These encrypted files can include encrypted communication keys, authentication information, or other confidential data, which are used to ensure the integrity and confidentiality of the data in actual operations.
[0109] In the key management model, the system determines when to access the ESAM module based on the key distribution strategy obtained through prediction and analysis. This strategy determines how to obtain the appropriate encryption key and perform encryption operations within a specific time period. Once the key management model generates the key distribution strategy, the system will access the ESAM module through this strategy to ensure that the correct encrypted file is obtained from the module. By querying the key distribution strategy, the encrypted file that matches the current strategy is found within the ESAM module. This file contains the encryption key or data that needs to be used in a specific time period and specific communication environment. After obtaining the pre-configured encrypted file, the ESAM module performs related operations such as encryption, decryption, and key generation through national cryptographic algorithms to ensure the security and reliability of the data transmission process between the gas meter and the external system. The core of the ESAM module is based on national cryptographic standards (such as SM2, SM3, SM4, etc.), and these algorithms are used to ensure that the key management system of the gas meter meets national security standards in aspects such as data encryption, authentication, signature, and data integrity protection. The ESAM module is built based on a hardware security chip and has a high level of physical security, capable of resisting various hardware attacks such as side-channel attacks and differential power analysis.
[0110] In this way, by storing and accessing the pre-configured encrypted file in the ESAM module, it is ensured that all key operations in the gas meter are carried out in a highly secure hardware environment, effectively preventing key leakage and unauthorized access. Combining the key distribution strategy, the ESAM module can dynamically obtain the corresponding encrypted file according to the actual needs of the gas meter, realizing a flexible key update and management mechanism, and enhancing the adaptability of the system. The ESAM module with national cryptographic algorithms ensures that the gas meter system meets the requirements of China's national information security standards, especially in critical infrastructures such as the gas metering system, which is crucial. The ESAM module is designed as a low-power hardware and can operate efficiently on resource-constrained devices such as gas meters, ensuring both security and normal device functions.
[0111] In this embodiment, the ESAM module, as the core component based on the national cryptographic security chip, guarantees the security of the key management and encryption process of the gas meter system. By combining the key distribution strategy, the system can dynamically access and obtain the encrypted file that matches the strategy in the ESAM module, thus ensuring the security of data encryption and transmission. At the same time, this solution complies with national cryptographic standards and is applicable to application scenarios with high security requirements in critical infrastructures, such as the gas metering system in Internet of Things devices.
[0112] In 104, the pre-configured encryption file is used to perform data encryption in the gas meter, and the encrypted gas meter data is uploaded to the server, so that the server can complete the decryption of the gas meter data based on the pre-deployed decryption policy. In the embodiments of the present application, the decryption policy matches the key distribution policy predicted based on the key negotiation file.
[0113] In this embodiment, the data in the gas meter is encrypted by a pre-configured encryption file, and the encrypted data is uploaded to the server. The server completes the decryption of the data according to the pre-deployed decryption policy. This process ensures the security of the entire data transmission and storage.
[0114] Specifically, inside the gas meter, the system first generates a key distribution policy through the key management model, and obtains a pre-configured encryption file from the ESAM module based on this policy. This encryption file usually contains encryption keys generated based on national cryptographic standards (such as SM2, SM4, etc.) and is used to encrypt sensitive data in the gas meter (such as measurement data, communication records, etc.). The pre-configured key is used to encrypt the data in the gas meter, and the encryption algorithm may be based on symmetric or asymmetric encryption, and the specific choice depends on the security requirements and resource limitations of the system. Once the data is encrypted, the gas meter uploads the encrypted data to the server. This is usually transmitted through a wireless communication network (such as NB-IoT, LoRa, or a cellular network). The encrypted data cannot be directly tampered with or interpreted, ensuring the confidentiality and integrity of the data during transmission and preventing man-in-the-middle attacks or data tampering.
[0115] The server side has pre-deployed a decryption policy that matches the key distribution policy, that is, the server can correctly select the corresponding decryption key for decryption operations according to the key distribution policy used by the gas meter. This decryption policy is usually based on the information in the key negotiation file and decrypts through the previously negotiated key or key distribution policy. The server will obtain the corresponding key from the decryption policy for decrypting the transmitted encrypted data. After receiving the encrypted data, the server uses the pre-configured decryption policy, combines the content of the key negotiation file, and performs decryption operations using the corresponding decryption key. Since the decryption policy matches the key distribution policy, the server can successfully restore the encrypted data uploaded by the gas meter to plaintext data for further processing or storage.
[0116] In this way, throughout the entire process, the data of the gas meter is always transmitted and stored in an encrypted form, avoiding the risk of being stolen or tampered with by malicious attackers on the transmission link. Encryption algorithms based on national cryptographic standards (such as the SM4 symmetric encryption algorithm or the SM2 asymmetric encryption algorithm) further enhance the security of the system, meeting the national security requirements for critical information infrastructure. The decryption policy is kept in line with the key distribution policy to ensure that the server and the gas meter use the same encryption and decryption keys, avoiding inconsistencies in key management and improving the reliability of the decryption operation. By using pre-configured encryption files and decryption policies, the system can reduce the burden of dynamically generating keys. The pre-configuration method not only saves the computing resources of the device but also simplifies the key management process, which is especially suitable for resource-constrained Internet of Things devices. In a wireless network environment, encryption technology ensures the secure transmission of data, and the matching of the key distribution policy and the decryption policy guarantees the efficiency of decryption without the need for repeated negotiation or additional key calculation.
[0117] In this embodiment, the system encrypts the gas meter data through pre-configured encryption files and uses a decryption policy that matches the key distribution policy on the server side to ensure the secure transmission and processing of data from the gas meter to the server. This mechanism not only enhances the security of the data but also simplifies the key management and encryption / decryption processes, which is very suitable for the security requirements in a large-scale Internet of Things environment, especially for resource-constrained devices such as gas meters.
[0118] In summary, by introducing a multi-layer key management model, the gas meter can intelligently predict the key update strategy and flexibly respond to security challenges in communication. At the same time, relying on the support of the ESAM module and national cryptographic algorithms, the entire data transmission and storage process has high security and reliability. This solution not only ensures the flexibility of key management but also reduces the communication overhead caused by key updates, improving the overall operation efficiency and security of the gas meter system.
[0119] In another embodiment of the present application, a gas meter security authentication device based on national cryptographic algorithms is further provided. Refer to Figure 3 As shown, this device is applied to a gas meter and includes the following units:
[0120] An acquisition unit, configured to acquire a key negotiation file sent by the server;
[0121] A prediction unit, configured to use a key management model to perform prediction processing according to the pre-configured key information in the key negotiation file to obtain a key distribution policy corresponding to the gas meter;
[0122] A configuration unit, configured to access the ESAM module based on the key distribution policy and obtain a pre-configured encryption file in the ESAM module that matches the key distribution policy; the ESAM module is pre-deployed in a gas meter, and the ESAM module is built based on a national cryptographic security chip;
[0123] An encryption unit, configured to perform data encryption in the gas meter using the pre-configured encryption file and upload the encrypted gas meter data to a server so that the server can complete the decryption of the gas meter data based on a pre-deployed decryption policy; the decryption policy matches the key distribution policy predicted based on the key negotiation file.
[0124] Further optionally, an acquisition unit, which acquires a key negotiation file sent by the server, is specifically configured as follows:
[0125] The gas meter uploads a preprocessing message for starting the encryption process to the server; the preprocessing message at least includes: an authentication request, handshake data, security signature information, and identity authentication information; the preprocessing message undergoes a first encryption process through pre-negotiation;
[0126] The gas meter receives the key negotiation file sent by the server in response to the preprocessing message; the key negotiation file at least includes: a key configuration type, key configuration parameters, and a key configuration timing; the key negotiation file is obtained through a second encryption process that matches the first encryption process.
[0127] Further optionally, an acquisition unit, which acquires a key negotiation file sent by the server, is specifically configured as follows:
[0128] The gas meter receives the key negotiation file sent by the server based on a preset policy; the key negotiation file at least includes: a key configuration type, key configuration parameters, and a key configuration timing; the key negotiation file is obtained through a third encryption process through pre-negotiation.
[0129] Further optionally, the key management model at least includes: a key space management model and a key time management model;
[0130] A prediction unit, using the key management model, performs prediction processing based on the key negotiation file to obtain a key distribution policy corresponding to the gas meter, and is specifically configured as follows:
[0131] Extract pre-configured key information from the key negotiation file;
[0132] Use the key space management model to perform prediction on the pre-configured key information to obtain key storage space configuration information corresponding to the gas meter;
[0133] Using the said key time management model, predict the said pre-configured key information to obtain the key time configuration information corresponding to the gas meter;
[0134] Based on the said key storage space configuration information and the said key time configuration information, generate the said key distribution policy; the key distribution policy is used to dynamically adjust the storage area location and key distribution timing of key distribution.
[0135] Further optionally, the said key space management model at least includes: a construction layer, a parsing layer, a prediction layer, and an optimization layer;
[0136] The prediction unit uses the said key space management model to predict the said pre-configured key information to obtain the key storage space configuration information corresponding to the gas meter, and is specifically configured as:
[0137] Through the construction layer, according to the gas meter deployment information carried in the said pre-configured key information, construct the target graph node corresponding to the gas meter in the target graph structure; the gas meter deployment information at least includes: location information in the area where the gas meter is located, spatial connection relationship between the gas meter and the server, and associated architecture information in the communication network where the gas meter is located; the target graph structure corresponds to the deployment architecture of the communication network where the gas meter is located; each graph node in the target graph structure corresponds to a gas meter;
[0138] Through the parsing layer, based on the target graph structure, parse the key association degree between the target graph node and other graph nodes, and the key usage frequency of the target graph node;
[0139] Through the prediction layer, predict the target key storage area of the gas meter based on the key association degree and the key usage frequency;
[0140] Through the optimization layer, perform risk prediction on the target key storage area to obtain the said key storage space configuration information for indicating the target key storage area.
[0141] Further optionally, the said key time management model at least includes: an input layer, a multi-layer causal convolution layer, an extended convolution layer, an optimization layer, and a fully connected layer;
[0142] The prediction unit uses the said key time management model to predict the said pre-configured key information to obtain the key time configuration information corresponding to the gas meter, and is specifically configured as:
[0143] Through the input layer, convert the said pre-configured key information into gas meter feature information; the gas meter feature information at least includes: communication data features, communication time features, and signaling transmission features in the communication network where the gas meter is located;
[0144] Through multiple layers of causal convolutional layers, a convolutional kernel sliding window is used to perform communication time pattern recognition on the gas meter feature information, and the communication time pattern in the communication network where the gas meter is located is obtained;
[0145] Through an extended convolutional layer, a long-term dependence pattern in the communication network where the gas meter is located is identified from the gas meter feature information;
[0146] Through an optimization layer, different feature information under the communication time pattern and the long-term dependence pattern is optimized;
[0147] Through a fully connected layer, all the optimized feature information is fused to obtain the key time configuration information corresponding to the gas meter.
[0148] Further optionally, a prediction unit, using a key management model, after performing prediction processing according to the pre-configured key information in the key negotiation file to obtain the key distribution strategy corresponding to the gas meter, is further configured to:
[0149] Using a key policy optimization model, perform risk distribution prediction on the key management policy running in the key management model, and dynamically update the key management policy based on the risk distribution prediction result;
[0150] Among them, the risk probability distribution of the key management policy in the key policy optimization model is expressed as the following expression:
[0151]
[0152] Among them, P(I j h) represents the risk probability distribution I of the jth key management policy in the key management environment h j , w h represents the weight term corresponding to the key management environment h, b h represents the bias term corresponding to the key management environment h, represents the weight term corresponding to the jth key management policy, and n is the maximum number of configurable keys in the key management environment h.
[0153] In the embodiment of the present application, by introducing a key management model with a multi-layer structure, the key update strategy is intelligently predicted, so that the data transmission and storage processes have high security and reliability, ensuring the flexibility of key management, reducing the communication overhead caused by key updates, and improving the overall operation efficiency and security of the gas meter system.
[0154] In another embodiment of the present application, an electronic device is further provided, including: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0155] A memory for storing a computer program;
[0156] A processor, when executing the program stored in the memory, implements a gas meter security authentication method based on national cryptographic algorithms described in the method embodiments.
[0157] The communication bus 1140 mentioned in the above electronic device may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus 1140 can be divided into an address bus, a data bus, a control bus, etc.
[0158] For ease of representation, Figure 4 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0159] The communication interface 1120 is used for communication between the above electronic device and other devices.
[0160] The memory 1130 may include a Random Access Memory (RAM), and may also include a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located far from the aforementioned processor.
[0161] The above-mentioned processor 1110 may be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it may also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0162] Correspondingly, the embodiments of the present application also provide a computer-readable storage medium storing a computer program, and when the computer program is executed, it can implement each step executable by the electronic device in the above method embodiments.
Claims
1. A gas meter security authentication method based on national cryptographic algorithms, characterized in that, The method includes: The gas meter obtains the key negotiation file sent by the server; Adopt a key management model, perform prediction processing according to the key negotiation file, and obtain the key distribution strategy corresponding to the gas meter; Access the ESAM module based on the key distribution strategy, and obtain the pre-configured encryption file in the ESAM module that matches the key distribution strategy; the ESAM module is pre-deployed in the gas meter, and the ESAM module is built based on a national secret security chip; Use the pre-configured encryption file to perform data encryption in the gas meter, and upload the encrypted gas meter data to the server, so that the server can complete the decryption of the gas meter data based on the pre-deployed decryption strategy; the decryption strategy matches the key distribution strategy predicted based on the key negotiation file; Among them, the key management model at least includes: a key space management model and a key time management model; the step of adopting the key management model and performing prediction processing according to the key negotiation file to obtain the key distribution strategy corresponding to the gas meter includes: extracting pre-configured key information from the key negotiation file; using the key space management model to predict the pre-configured key information to obtain the key storage space configuration information corresponding to the gas meter; using the key time management model to predict the pre-configured key information to obtain the key time configuration information corresponding to the gas meter; generating the key distribution strategy based on the key storage space configuration information and the key time configuration information; the key distribution strategy is used to dynamically adjust the storage area location and key distribution timing of key distribution; Among them, the key space management model at least includes: a construction layer, an analysis layer, a prediction layer, and an optimization layer; the step of using the key space management model to predict the pre-configured key information to obtain the key storage space configuration information corresponding to the gas meter includes: Through the construction layer, according to the gas meter deployment information carried in the pre-configured key information, construct the target graph node corresponding to the gas meter in the target graph structure; the gas meter deployment information at least includes: location information in the area where the gas meter is located, spatial connection relationship between the gas meter and the server, and associated architecture information in the communication network where the gas meter is located; the target graph structure corresponds to the deployment architecture of the communication network where the gas meter is located; each graph node in the target graph structure corresponds to a gas meter; Through the analysis layer, based on the target graph structure, analyze the key association degree between the target graph node and other graph nodes, and the key usage frequency of the target graph node; Through the prediction layer, predict the target key storage area of the gas meter based on the key association degree and the key usage frequency; Through the optimization layer, perform risk prediction on the target key storage area to obtain the key storage space configuration information for indicating the target key storage area.
2. The gas meter safety authentication method based on the national cryptographic algorithm according to claim 1, wherein, The step that the gas meter obtains the key negotiation file sent by the server includes: The gas meter uploads a preprocessing message for starting the encryption process to the server; the preprocessing message at least includes: an authentication request, handshake data, security signature information, and identity authentication information; the preprocessing message undergoes a first encryption process through pre-negotiation. The gas meter receives the key negotiation file sent by the server in response to the preprocessing message; the key negotiation file at least includes: key configuration type, key configuration parameters, and key configuration timing; the key negotiation file is obtained by using a second encryption process matching the first encryption process.
3. A gas meter safety authentication method based on the national cryptographic algorithm according to claim 1, characterized in that The gas meter obtains the key negotiation file sent by the server, including: The gas meter receives the key negotiation file sent by the server based on a preset policy; the key negotiation file at least includes: key configuration type, key configuration parameters, and key configuration timing; the key negotiation file is obtained by using a third encryption process through pre-negotiation.
4. A gas meter security authentication method based on the national cryptographic algorithm according to claim 1, characterized in that, The key time management model at least includes: an input layer, a multi-layer causal convolution layer, an extended convolution layer, an optimization layer, and a fully connected layer. Using the key time management model to predict the pre-configured key information to obtain the key time configuration information corresponding to the gas meter, including: Through the input layer, converting the pre-configured key information into gas meter feature information; the gas meter feature information at least includes: communication data features, communication time features, and signaling transmission features in the communication network where the gas meter is located. Through the multi-layer causal convolution layer, using a convolutional kernel sliding window to perform communication time pattern recognition on the gas meter feature information to obtain the communication time pattern in the communication network where the gas meter is located. Through the extended convolution layer, identifying the long-term dependence pattern in the communication network where the gas meter is located from the gas meter feature information. Through the optimization layer, performing optimization processing on different feature information under the communication time pattern and the long-term dependence pattern. Through the fully connected layer, fusing all the optimized feature information to obtain the key time configuration information corresponding to the gas meter.
5. The gas meter safety authentication method based on the national cryptographic algorithm according to claim 1, characterized in that, After using the key management model to perform prediction processing according to the pre-configured key information in the key negotiation file to obtain the key distribution policy corresponding to the gas meter, it further includes: Using the key policy optimization model to perform risk distribution prediction on the key management policy running in the key management model, and dynamically updating the key management policy based on the risk distribution prediction result. Among them, the risk probability distribution of the key management policy in the key policy optimization model is expressed as the following expression: ; among them, represents the risk probability distribution of the j-th key management policy in the key management environment under , represents the weight term corresponding to the key management environment , represents the bias term corresponding to the key management environment , represents the weight term corresponding to the j-th key management policy, and n is the maximum number of configurable keys under the key management environment .
6. A gas meter safety authentication device based on the national cryptographic algorithm, characterized in that, The device is applied to a gas meter; the device includes: An acquisition unit configured to acquire the key negotiation file sent by the server. A prediction unit configured to use the key management model to perform prediction processing according to the pre-configured key information in the key negotiation file to obtain the key distribution policy corresponding to the gas meter. A configuration unit configured to access the ESAM module based on the key distribution policy and obtain the pre-configured encryption file matching the key distribution policy in the ESAM module; the ESAM module is pre-deployed in the gas meter, and the ESAM module is built based on a national cryptography security chip. An encryption unit, configured to perform data encryption in a gas meter by using the preconfigured encryption file and upload the encrypted gas meter data to a server, so that the server completes the decryption of the gas meter data based on a pre-deployed decryption policy; the decryption policy matches the key distribution policy predicted based on the key negotiation file; Wherein, the key management model at least includes: a key space management model and a key time management model; the prediction unit, using the key management model, performs prediction processing according to the key negotiation file to obtain a key distribution policy corresponding to the gas meter, and is configured to: extract preconfigured key information from the key negotiation file; use the key space management model to predict the preconfigured key information to obtain key storage space configuration information corresponding to the gas meter; use the key time management model to predict the preconfigured key information to obtain key time configuration information corresponding to the gas meter; generate the key distribution policy based on the key storage space configuration information and the key time configuration information; the key distribution policy is used to dynamically adjust the storage area location and key distribution timing of key distribution; Wherein, the key space management model at least includes: a construction layer, an analysis layer, a prediction layer, and an optimization layer; the prediction unit, using the key space management model, predicts the preconfigured key information to obtain key storage space configuration information corresponding to the gas meter, and is configured to: Through the construction layer, according to the gas meter deployment information carried in the preconfigured key information, construct a target graph node corresponding to the gas meter in the target graph structure; the gas meter deployment information at least includes: location information in the area where the gas meter is located, spatial connection relationship between the gas meter and the server, and associated architecture information in the communication network where the gas meter is located; the target graph structure corresponds to the deployment architecture of the communication network where the gas meter is located; each graph node in the target graph structure corresponds to a gas meter; Through the analysis layer, based on the target graph structure, analyze the key association degree between the target graph node and other graph nodes, and the key usage frequency of the target graph node; Through the prediction layer, predict the target key storage area of the gas meter based on the key association degree and the key usage frequency; Through the optimization layer, perform risk prediction on the target key storage area to obtain the key storage space configuration information for indicating the target key storage area.
7. An electronic device, characterized in that, Includes: A memory for storing computer software programs; A processor for reading and executing the computer software program, thereby implementing a gas meter security authentication method based on the national cryptographic algorithm according to any one of claims 1-5.
8. A non-transitory computer-readable storage medium, characterized in that, The computer software program is stored in the storage medium, and when the computer software program is executed by the processor, it implements a gas meter security authentication method based on the national cryptographic algorithm according to any one of claims 1-5.
Citation Information
Patent Citations
Gas meter safety certification system based on national cryptographic algorithm
CN112087301A
Adaptive key distribution method, system and device based on reinforcement learning and medium
CN118074897A