Load management terminal encrypted communication method and system

By replacing the communication pins in the load management terminal and using the national secret algorithm to establish an encrypted channel, the problems of insufficient data transmission security and high upgrade costs in the existing technology are solved, and low-cost, high-security and high-reliability encrypted communication is achieved.

CN119652614BActive Publication Date: 2025-10-10GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411803785.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-10-10
Estimated Expiration
2044-12-10

AI Technical Summary

Technical Problem

Existing load management terminal communication methods have problems such as insufficient data transmission security, high encryption function upgrade costs and lack of flexibility, and imperfect key management and communication link stability, which cannot meet the security requirements of modern power systems.

Method used

By replacing the terminal communication pins with encryption modules, the national encryption algorithm is used to dynamically establish an encryption channel, perform data packet encryption transmission and integrity verification, and trigger abnormal recovery or rebuild the encryption channel when communication abnormalities occur, thus realizing modular encryption design.

Benefits of technology

It reduces the cost of upgrading encryption functions, improves communication security and stability, ensures the reliability and flexibility of data transmission, and adapts to the diversity and complexity of load management terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652614B_ABST
    Figure CN119652614B_ABST
Patent Text Reader

Abstract

The application discloses a kind of load management terminal encryption communication method and system, it is related to power load management terminal communication security technical field, including by encryption module replacement terminal communication pin, complete interface adaptation between terminal and master station and data encryption function initialization;Based on the dynamic establishment of encryption channel of national secret algorithm, key issue and authentication are completed by master station, and the confidentiality of two-way communication is optimized;Data packet is encrypted transmission and integrity check, detects communication state, triggers abnormal recovery or reconstructs encryption channel operation.The method is described in the application, which avoids large-scale replacement of existing load management terminals by modular encryption design, reduces the cost of encryption function upgrade;Automatic interface identification and encryption protocol loading function greatly reduces the complexity of manual configuration, making the deployment of terminal encryption upgrade more convenient and efficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power load management terminal communication security, and in particular to a load management terminal encryption communication method and system. Background Art

[0002] With the continuous development of modern power systems, load management terminals (LMTs), as an important part of smart grids, have played a key role in power load monitoring, regulation and management. Traditional load management terminals interact with the main station through communication modules to realize the collection, transmission and control of electricity consumption information. However, as the power system's requirements for network security and data integrity continue to increase, traditional communication modules lack efficient encryption and authentication mechanisms and are vulnerable to security threats (such as data tampering and information leakage) during data transmission. In recent years, countries have introduced mandatory encryption standards to improve the confidentiality of data transmission. However, a large number of existing load management terminals cannot directly meet these encryption requirements due to the lack of suitable encryption modules, resulting in a significant gap between the security performance of existing equipment and the development needs of modern power grids.

[0003] The existing load management terminal encryption communication technology mainly relies on the communication module natively integrated in the terminal, which is difficult to flexibly adapt to security upgrade requirements. Most existing terminals are not equipped with dedicated security encryption chips, which makes it impossible to effectively prevent data tampering or theft during data transmission. The existing upgrade plan usually requires replacing the entire terminal equipment, which is costly and has a long implementation cycle. The existing technology has deficiencies in encryption channel establishment and key management, and cannot meet the requirements of modern power systems for dynamic key updates and two-way authentication, increasing the risk of key leakage. The existing technology does not provide sufficient support for data packet integrity verification and abnormal recovery. When communication is interrupted or fails, it cannot quickly detect and repair the communication link, affecting the stability and reliability of the system. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problems solved by the present invention are: the existing load management terminal communication method has the problem of insufficient data transmission security, the encryption function upgrade cost is high and lacks flexibility, the key management and communication link stability are imperfect, and how to achieve a low-cost, high-security and high-reliability load management terminal encryption communication method through modular encryption design.

[0006] To solve the above technical problems, the present invention provides the following technical solutions: a load management terminal encryption communication method, comprising replacing the terminal communication pin with an encryption module to complete the interface adaptation and data encryption function initialization between the terminal and the master station; dynamically establishing an encryption channel based on the national secret algorithm, completing key issuance and authentication through the master station, and optimizing the confidentiality of two-way communication; encrypting and transmitting data packets and performing integrity verification, detecting the communication status, and triggering abnormal recovery or reconstruction of the encryption channel operation.

[0007] As a preferred solution of the load management terminal encryption communication method described in the present invention, the method of replacing the terminal communication pins with an encryption module includes replacing the pins of the existing communication module of the terminal with an embedded or external encryption module, and using different communication interfaces, including UART, RS485 and Ethernet. The encryption module identifies the terminal communication interface type through an automatic detection function, and initializes the communication rate, baud rate and protocol parameters to complete the interface adaptation. After the encryption module is set up, the data encryption protocol and the configuration of the supported network standards are automatically loaded into the terminal, including automatic selection of LTE_FDD, LTE_TDD, WCDMA and GSM networks.

[0008] As a preferred solution of the load management terminal encryption communication method described in the present invention, the completion of the interface adaptation and data encryption function initialization between the terminal and the master station includes remotely configuring the master station IP address, port, heartbeat cycle and username and password through the host computer after the terminal and the encryption module complete the physical connection. The encryption module has a preset status indicator light inside to display the terminal interface adaptation and encryption function initialization status. The red light indicates initialization failure, the green light indicates successful interface adaptation, and the flashing yellow light indicates that initialization is in progress. The encryption module supports a local reset function to reload the initial parameters through the reset operation.

[0009] As a preferred solution of the load management terminal encryption communication method described in the present invention, the establishment of an encrypted channel includes the main station sending initial keys in batches to the encryption module through the platform device, and the national secret SM4 symmetric encryption algorithm is adopted in the key sending process. During the encryption channel establishment process, the encryption module verifies the digital signature and random challenge response of the main station, and performs channel identity authentication. After the key transmission is completed, the encryption module uses a dynamic key rotation mechanism to regularly update the session key in the channel.

[0010] As a preferred solution of the load management terminal encryption communication method described in the present invention, the key issuance and authentication are completed through the master station, including that after the key issuance is completed, the encryption module stores the key in a security chip that complies with national encryption standards to prevent key leakage due to external attacks. During the key update process, the master station transmits the new key to the encryption module through the VPN tunnel, the module verifies the transmitted data and replaces the old key. If illegal disassembly or module damage is detected, the encryption module deletes the key and related sensitive data through the hardware self-destruction mechanism to ensure key security.

[0011] As a preferred solution of the load management terminal encryption communication method described in the present invention, the encrypted transmission and integrity verification of data packets include: before data transmission, the encryption module segments the data and encrypts each segment of data separately, and attaches a serial number to each segment of data so that the main station can reassemble it after receiving it. The encryption module performs integrity verification on the transmitted data packet. If an erroneous data packet is found, it is discarded and requested to be resent. In high-concurrency scenarios, the encryption module uses hardware pipeline encryption technology to simultaneously process multi-channel data transmission.

[0012] As a preferred solution of the load management terminal encryption communication method described in the present invention, the triggering of abnormal recovery or reconstruction of the encryption channel operation includes that when a communication abnormality occurs, the encryption module automatically attempts to switch to a backup network format, or restores communication by rebuilding the encryption channel. After multiple recovery failures, the encryption module sends a detailed fault report to the main station, and the report content includes the module status, fault type and number of reconstruction attempts. After successful recovery, the encryption module reloads the latest communication parameters and sends a status signal of successful channel reconstruction to the main station.

[0013] Another object of the present invention is to provide a load management terminal encryption communication system, which can dynamically establish an encryption channel based on the national encryption algorithm, complete key issuance and authentication through the master station, optimize the confidentiality of two-way communication, and solve the problem that the current load management terminal communication technology contains encryption functions with high upgrade costs and lack of flexibility.

[0014] As a preferred solution of the load management terminal encryption communication system described in the present invention, it includes: an initialization module, an encryption authentication module, and an abnormality monitoring module; the initialization module is used to replace the terminal communication pin through the encryption module to complete the interface adaptation and data encryption function initialization between the terminal and the main station; the encryption authentication module is used to dynamically establish an encryption channel based on the national secret algorithm, complete key issuance and authentication through the main station, and optimize the confidentiality of two-way communication; the abnormality monitoring module is used to encrypt and transmit data packets and perform integrity verification, detect communication status, and trigger abnormal recovery or reconstruction of encryption channel operations.

[0015] A computer device comprises a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement steps of the load management terminal encrypted communication method.

[0016] A computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement steps of the load management terminal encrypted communication method.

[0017] The load management terminal encrypted communication method provided by the present application avoids large-scale replacement of existing load management terminals through modular encryption design, reduces the cost of encryption function upgrade, and optimizes the security of bidirectional communication between the terminal and the master station based on the dynamic key management and encryption channel construction mechanism of the national encryption algorithm, effectively prevents data tampering and leakage, ensures the stability of data transmission through segmented encryption, integrity check and communication exception recovery function, and provides flexible adaptation capability in complex communication environment, automatic interface identification and encryption protocol loading function greatly reduces the complexity of manual configuration, and makes the deployment of terminal encryption upgrade more convenient and efficient, and the present application achieves better results in cost, efficiency and reliability. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0019] Figure 1 The present application provides a load management terminal encrypted communication method for the first embodiment.

[0020] Figure 2 The present application provides a load management terminal encrypted communication system for the third embodiment. DETAILED DESCRIPTION

[0021] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0022] Embodiment 1, refer to Figure 1 For an embodiment of the present application, a load management terminal encrypted communication method is provided, comprising:

[0023] S1: Replace the terminal communication pin by the encryption module, complete the interface adaptation and data encryption function initialization between the terminal and the host station.

[0024] Further, replacing the terminal communication pin by the encryption module includes replacing the pin of the existing communication module of the terminal with an embedded or external encryption module, using different communication interfaces including UART, RS485 and Ethernet, the encryption module identifies the terminal communication interface type through automatic detection function, initializes the communication rate, baud rate and protocol parameters, completes the interface adaptation, and after the encryption module is set, automatically loads the data encryption protocol and the configuration of the supported network system to the terminal, including the automatic selection of LTE_FDD, LTE_TDD, WCDMA and GSM network.

[0025] It should be noted that the completion of the interface adaptation and data encryption function initialization between the terminal and the host station includes the remote configuration of the host station IP address, port, heartbeat period and username password by the upper computer after the physical connection between the terminal and the encryption module is completed, the encryption module has a pre-installed state indicator, which displays the terminal interface adaptation and encryption function initialization state, a red light indicates initialization failure, a green light indicates interface adaptation success, and a yellow light flickers indicates that the initialization is in progress, the encryption module supports local reset function, which reloads the initial parameters by reset operation.

[0026] It should also be noted that the embedded or external encryption module is used to replace the pin of the existing communication module, supports multiple communication interfaces such as UART, RS485 and Ethernet, the module identifies the communication interface type through automatic detection function, initializes the communication rate, baud rate and protocol parameters, and automatically loads the data encryption protocol and the supported network system (such as LTE_FDD, LTE_TDD, WCDMA and GSM), realizes the initialization of the interface adaptation and data encryption function between the terminal and the host station, upgrades the communication security performance without large-scale replacement of terminal equipment, reduces the upgrade cost through modular design, improves the adaptation flexibility, adapts to the diversity and complexity of existing load management terminals, in addition, the module supports automatic network selection and encryption protocol loading, reduces manual intervention and improves deployment efficiency.

[0027] S2: Dynamically establish an encrypted channel based on the national encryption algorithm, complete key distribution and authentication through the host station, and optimize the confidentiality of bidirectional communication.

[0028] Furthermore, establishing an encryption channel involves the master station sending initial keys in batches to the encryption module through the platform device. The national secret SM4 symmetric encryption algorithm is used in the key sending process. During the encryption channel establishment process, the encryption module verifies the master station's digital signature and random challenge response to perform channel identity authentication. After the key transmission is completed, the encryption module uses a dynamic key rotation mechanism to regularly update the session key in the channel.

[0029] It should be noted that the key distribution and authentication are completed through the master station. After the key distribution is completed, the encryption module stores the key in a security chip that meets the national encryption standards to prevent key leakage due to external attacks. During the key update process, the master station transmits the new key to the encryption module through the VPN tunnel. The module verifies the transmitted data and replaces the old key. If illegal disassembly or module damage is detected, the encryption module deletes the key and related sensitive data through the hardware self-destruction mechanism to ensure key security.

[0030] It should also be noted that the national secret SM4 symmetric encryption algorithm is used, and the master station sends the initial keys in batches to the encryption module through the platform device, and completes the identity authentication process such as random challenge response. Subsequently, the session key in the channel is regularly updated through the dynamic key rotation mechanism, and the construction of a secure encryption channel and key management between the terminal and the master station are realized, ensuring the confidentiality and integrity of data transmission. The dynamic key update mechanism can prevent security risks caused by long-term non-replacement of keys. The random challenge response mechanism enhances the channel's anti-attack capability, effectively improves the security of the communication link, and enhances the security and credibility of the communication between the load management terminal and the master station, solving the problem that static key management in the existing technology is easily cracked. At the same time, through the dynamic update mechanism, the risk of key leakage is further reduced, and the confidentiality of two-way communication is optimized.

[0031] S3: Encrypts data packets for transmission and performs integrity verification, detects communication status, and triggers abnormal recovery or reconstruction of encrypted channels.

[0032] Furthermore, the encrypted transmission and integrity verification of data packets include: before data transmission, the encryption module segments the data and encrypts each segment separately, attaches a serial number to each segment so that the master station can reassemble it after receiving it, and performs integrity verification on the transmitted data packet. If an erroneous data packet is found, it is discarded and requested to be resent. In high-concurrency scenarios, the encryption module uses hardware pipeline encryption technology to handle multiple data transmissions at the same time.

[0033] It should be noted that triggering abnormal recovery or rebuilding the encryption channel operation includes the encryption module automatically attempting to switch to the backup network format or restore communication by rebuilding the encryption channel when a communication abnormality occurs. After multiple recovery failures, the encryption module sends a detailed fault report to the master station. The report content includes the module status, fault type and number of reconstruction attempts. After successful recovery, the encryption module reloads the latest communication parameters and sends a status signal of successful channel reconstruction to the master station.

[0034] It should also be noted that before data transmission, the data is segmented and each segment is encrypted separately, and a serial number is attached so that the main station can reassemble it after receiving it. The encryption module performs integrity check on each data packet. If an erroneous data packet is found, it is discarded and retransmission is requested. In the event of communication abnormality, the module automatically switches to the backup network standard or rebuilds the encryption channel, and sends a fault report to the main station after multiple recovery failures, thereby realizing the secure transmission and integrity check of encrypted data packets, as well as the rapid recovery and fault notification functions after communication abnormalities. Segmented encryption improves the efficiency of large data packet transmission, and integrity check ensures the authenticity and reliability of data. The abnormal recovery mechanism reduces the impact of communication interruption on system operation, and the fault reporting function provides a basis for system maintenance and diagnosis, enhances the security and stability of data transmission, and solves the problem of data loss due to communication interruption in the existing technology. In addition, the abnormal recovery and reconstruction mechanism shortens the recovery time of communication failures and improves the overall reliability and availability of the system.

[0035] Example 2 is an embodiment of the present invention, which provides a load management terminal encryption communication method. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0036] First, 50 load management terminals are configured in 10 groups. Each group of terminals is installed with different forms of encryption modules (embedded or external). The encryption module connects to the physical interface of the terminal through the automatic detection function, identifies the terminal interface type, and initializes the communication rate and baud rate to complete the interface adaptation. All terminals are remotely configured through the host computer, including the master station IP address, communication port, heartbeat cycle, user name and password. The status indicator of the encryption module displays the interface adaptation and encryption function initialization status respectively. After completing the physical connection between the terminal and the encryption module, the communication parameters between the terminal and the master station are configured through the host computer. After the interface adaptation is successful, the green light is on. If the adaptation fails, the red light is on. All modules reload the initialization parameters through the reset function to ensure successful adaptation. The adaptation success rate of the 10 groups of equipment is recorded in the data table. The initial keys are sent in batches to the encryption module through the main station device, using the SM4 symmetric encryption algorithm. During the key transmission process, the encryption module verifies the digital signature and random challenge response of the main station, completes identity authentication, and records the key transmission time. The established encryption channel is regularly updated through a dynamic key rotation mechanism. Each group of terminals transmits 100 simulated data packets to the main station, which contain sensor data, load status, and control instructions. The encryption module performs segmented encryption and integrity verification on each data packet, and attaches a serial number to facilitate the main station to reassemble the data. If an erroneous data packet is found, it will immediately request retransmission. Under simulated communication anomalies (such as signal loss and network switching), the encryption module automatically switches to the backup network or attempts to rebuild the encryption channel. If recovery fails, the encryption module sends a fault report to the main station, including module status, fault type, and number of reconstruction attempts.

[0037] The encryption module transmits keys using the SM4 encryption algorithm, with an average transmission time of approximately 12.5ms and high stability (standard deviation less than 1ms). Prior art systems do not employ dedicated encryption chips or dynamic key update mechanisms, resulting in poor key transmission speed and security. The present invention's dynamic key rotation mechanism improves communication's anti-attack capabilities, achieving a packet integrity check success rate exceeding 99%, demonstrating that segmented encryption and error packet retransmission mechanisms can significantly improve data transmission reliability. Compared with the high bit error rates observed in prior art systems, the present invention's design can better ensure data transmission accuracy. In simulation tests of communication interruptions, the encryption module achieved an average communication recovery time of 35ms, with a channel reconstruction success rate exceeding 98%. Prior art systems often experience long communication interruptions during network switching, but the present invention effectively addresses this problem through backup network switching and fast channel reconstruction. Compared with prior art systems, the present invention can achieve encryption upgrades for load management terminals at a lower cost, while significantly improving communication security, data transmission reliability, and abnormality recovery capabilities.

[0038] Example 3, reference Figure 2For an embodiment of the present application, a load management terminal encryption communication system is provided, comprising an initialization module, an encryption authentication module, and an exception monitoring module.

[0039] The initialization module is configured to replace the terminal communication pin through the encryption module, complete the interface adaptation and data encryption function initialization between the terminal and the host station; the encryption authentication module is configured to dynamically establish an encryption channel based on a national encryption algorithm, complete key distribution and authentication through the host station, and optimize the confidentiality of bidirectional communication; and the exception monitoring module is configured to perform encrypted transmission and integrity check on the data packet, detect the communication state, and trigger the exception recovery or encryption channel reconstruction operation.

[0040] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the present application that essentially contribute to the prior art or the parts of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The aforementioned storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0041] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered a list of executable instructions for implementing logic functions, and can be specifically embodied in any computer-readable medium for use by an instruction execution system, apparatus or device, such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, apparatus or device and execute the instructions, or in conjunction with these instruction execution systems, apparatus or devices. For the purpose of this specification, the "computer-readable medium" can be any device that can contain, store, communicate, propagate or transport programs for use by an instruction execution system, apparatus or device, or in conjunction with these instruction execution systems, apparatus or devices.

[0042] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection with one or more wires (electronic devices), a portable computer disk cartridge (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), a fiber optic device, and a portable compact disc read-only memory (CDROM). In addition, the computer-readable medium may even be paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a computer memory.

[0043] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having logic gate circuits for implementing logical functions on data signals, an application-specific integrated circuit having suitable combinational logic gate circuits, a programmable gate array (PGA), a field-programmable gate array (FPGA), etc. It should be noted that the above embodiments are merely illustrative of the technical solutions of the present invention and are not intended to be limiting. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced with equivalents without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications should be encompassed by the claims of the present invention.

[0044] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A load management terminal encryption communication method, characterized in that: include: The terminal communication pin is replaced by the encryption module to complete the interface adaptation and data encryption function initialization between the terminal and the main station; Dynamically establish an encryption channel based on the national encryption algorithm, complete key distribution and authentication through the master station, and optimize the confidentiality of two-way communication; Encrypt transmission and integrity verification of data packets, detect communication status, trigger abnormal recovery or rebuild encryption channel operations; The method of replacing the terminal communication pins with the encryption module includes replacing the pins of the existing communication module of the terminal with an embedded or external encryption module, using different communication interfaces, including UART, RS485 and Ethernet. The encryption module identifies the terminal communication interface type through an automatic detection function, initializes the communication rate, baud rate and protocol parameters, and completes the interface adaptation. After the encryption module is set up, the data encryption protocol and the configuration of the supported network standards are automatically loaded into the terminal, including automatic selection of LTE_FDD, LTE_TDD, WCDMA and GSM networks; The key issuance and authentication completed by the master station includes that after the key issuance is completed, the encryption module stores the key in a security chip that meets the national secret standards to prevent key leakage due to external attacks. During the key update process, the master station transmits the new key to the encryption module through the VPN tunnel. The module verifies the transmitted data and replaces the old key. If illegal disassembly or module damage is detected, the encryption module deletes the key and related sensitive data through the hardware self-destruct mechanism to ensure key security; The operation of triggering abnormal recovery or rebuilding the encryption channel includes that when a communication abnormality occurs, the encryption module automatically attempts to switch to a backup network format, or restores communication by rebuilding the encryption channel. After multiple recovery failures, the encryption module sends a detailed fault report to the main station. The report content includes the module status, fault type and number of reconstruction attempts. After successful recovery, the encryption module reloads the latest communication parameters and sends a status signal of successful channel reconstruction to the main station.

2. The load management terminal encryption communication method according to claim 1, wherein: The completion of the interface adaptation and data encryption function initialization between the terminal and the main station includes remotely configuring the main station IP address, port, heartbeat cycle and username and password through the host computer after the terminal and the encryption module are physically connected. The encryption module has a preset status indicator light inside to display the terminal interface adaptation and encryption function initialization status. The red light indicates that the initialization failed, the green light indicates that the interface adaptation is successful, and the flashing yellow light indicates that initialization is in progress. The encryption module supports a local reset function and reloads the initial parameters through the reset operation.

3. The load management terminal encryption communication method according to claim 2, wherein: The establishment of the encryption channel includes the main station sending initial keys in batches to the encryption module through the platform device. The national secret SM4 symmetric encryption algorithm is used in the key sending process. During the encryption channel establishment process, the encryption module verifies the digital signature and random challenge response of the main station and performs channel identity authentication. After the key transmission is completed, the encryption module uses a dynamic key rotation mechanism to regularly update the session key in the channel.

4. The load management terminal encryption communication method according to claim 3, wherein: The encrypted transmission and integrity verification of data packets include: before data transmission, the encryption module segments the data and encrypts each segment separately, attaches a serial number to each segment so that the main station can reassemble it after receiving it, and performs integrity verification on the transmitted data packet. If an erroneous data packet is found, it is discarded and requested to be resent. In high-concurrency scenarios, the encryption module uses hardware pipeline encryption technology to simultaneously process multi-channel data transmission.

5. A system using the load management terminal encryption communication method according to any one of claims 1 to 4, characterized in that: Including initialization module, encryption and authentication module, and abnormality monitoring module; The initialization module is used to replace the terminal communication pins through the encryption module to complete the interface adaptation and data encryption function initialization between the terminal and the main station; the replacement of the terminal communication pins through the encryption module includes using an embedded or external encryption module to replace the pins of the existing communication module of the terminal, using different communication interfaces, including UART, RS485 and Ethernet, the encryption module identifies the terminal communication interface type through the automatic detection function, and initializes the communication rate, baud rate and protocol parameters to complete the interface adaptation. After the encryption module is set, the data encryption protocol and the configuration of the supported network standards are automatically loaded into the terminal, including automatic selection of LTE_FDD, LTE_TDD, WCDMA and GSM networks; The encryption authentication module is used to dynamically establish an encryption channel based on the national encryption algorithm, complete key issuance and authentication through the master station, and optimize the confidentiality of two-way communication; The key issuance and authentication completed by the master station includes that after the key issuance is completed, the encryption module stores the key in a security chip that meets the national secret standards to prevent key leakage due to external attacks. During the key update process, the master station transmits the new key to the encryption module through the VPN tunnel. The module verifies the transmitted data and replaces the old key. If illegal disassembly or module damage is detected, the encryption module deletes the key and related sensitive data through the hardware self-destruct mechanism to ensure key security; The anomaly monitoring module is used to encrypt transmission and integrity check of data packets, detect communication status, and trigger abnormal recovery or reconstruction of encryption channel operations; The operation of triggering abnormal recovery or rebuilding the encryption channel includes that when a communication abnormality occurs, the encryption module automatically attempts to switch to a backup network format, or restores communication by rebuilding the encryption channel. After multiple recovery failures, the encryption module sends a detailed fault report to the main station. The report content includes the module status, fault type and number of reconstruction attempts. After successful recovery, the encryption module reloads the latest communication parameters and sends a status signal of successful channel reconstruction to the main station.

6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the load management terminal encryption communication method according to any one of claims 1 to 4 are implemented.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the load management terminal encryption communication method according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Power system information security encryption system based on power distribution terminal

    CN111711625A

  • Terminal equipment security encryption device based on security chip

    CN112270020A