External device processing method and device based on electric vehicle system, equipment and medium

By identifying the type of external device and configuring isolation environment parameters in the Elec-Hong system, the security risks of external device access are resolved, unified management and encrypted communication are achieved, and the security and reliability of device access are ensured.

CN119728224BActive Publication Date: 2025-11-28GUANGZHOU KETENG INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411862222.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-17
Publication Date
2025-11-28
Estimated Expiration
2044-12-17

AI Technical Summary

Technical Problem

The existing Dianhong system lacks a unified management strategy when handling external device access, leading to security risks and problems such as unauthorized access and malicious operations.

Method used

By determining the device type of external devices, configuring isolation environment parameters based on security assessment attributes, and connecting external devices after the target management information is verified, unified security management and encrypted communication can be achieved.

Benefits of technology

It enables unified security management of external devices, prevents unauthorized access and malicious operations, and ensures the security and reliability of device access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728224B_ABST
    Figure CN119728224B_ABST
Patent Text Reader

Abstract

The application discloses a kind of external device processing method, device and equipment based on electric Hong system and medium.Specific scheme is: when receiving external device access request, the device type of external device is determined based on access request;Based on the device type, the security evaluation attribute corresponding to the external device is determined, wherein the security evaluation attribute is used to represent the isolation environment parameter to be allocated for the external device when accessing the external device;When the security evaluation attribute meets the preset condition, the isolation environment parameter is configured for the external device, to deploy the target management information corresponding to the external device based on the isolation environment parameter;When the request parameter compliance check in device access request is passed based on target management information, access external device, to obtain the external device corresponding to electric Hong system.The application guarantees the security of the accessed external device, realizes the unified security management to external device, effectively prevents illegal access and malicious operation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to an external device processing method and device based on an electric terminal system, a device and a medium. BACKGROUND

[0002] The electric terminal system is an industrial Internet of Things operating system for power equipment or power terminals, which is used to realize the interconnection between different types of equipment and different brands of power equipment, thereby improving the intelligent and automated level of power grid operation.

[0003] At present, when external devices are accessed and managed, the access method and management strategy relied on lack unified standards. It is impossible to realize unified management of external devices, and it is easy to cause security risks of accessed external devices, so that the electric terminal system is illegally accessed and maliciously operated by attackers. SUMMARY

[0004] The present application provides an external device processing method and device based on an electric terminal system, which ensures the security of accessed external devices, realizes unified security management of external devices, and effectively prevents illegal access and malicious operation.

[0005] According to an aspect of the present application, an external device processing method based on an electric terminal system is provided, the electric terminal system comprising a system layer for processing external devices, characterized in that the method comprises:

[0006] Upon receiving an external device access request, determining the device type of the external device based on the access request;

[0007] Based on the device type, determining the security evaluation attribute corresponding to the external device, wherein the security evaluation attribute is used to represent the isolation environment parameters to be allocated to the external device when the external device is accessed;

[0008] When the security evaluation attribute meets the preset condition, configuring the isolation environment parameters for the external device, so as to deploy the target management information corresponding to the external device based on the isolation environment parameters;

[0009] When the request parameter compliance check in the device access request passes based on the target management information, accessing the external device to obtain the external device corresponding to the electric terminal system.

[0010] According to another aspect of the present application, an external device processing device based on an electric terminal system is provided, the electric terminal system comprising a system layer for processing external devices, characterized in that the device comprises:

[0011] The device type determination module is configured to determine the device type of the external device based on the access request when receiving the external device access request.

[0012] The evaluation attribute determination module is configured to determine a security evaluation attribute corresponding to the external device based on the device type, wherein the security evaluation attribute is used to represent an isolation environment parameter to be allocated to the external device when accessing the external device.

[0013] The management information determination module is configured to configure the isolation environment parameter for the external device when the security evaluation attribute meets a preset condition, and to deploy target management information corresponding to the external device based on the isolation environment parameter.

[0014] The external device access module is configured to access the external device to obtain an external device corresponding to the electronic system when the request parameter compliance check in the device access request passes based on the target management information.

[0015] According to another aspect of the present application, an electronic device is provided, which comprises:

[0016] at least one processor; and

[0017] a memory connected with the at least one processor in communication; wherein

[0018] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the external device processing method based on the electronic system according to any one of the embodiments of the present application.

[0019] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to execute the external device processing method based on the electronic system according to any one of the embodiments of the present application when the processor executes the computer instructions.

[0020] According to another aspect of the present application, a computer program product is provided, which comprises a computer program, and the computer program, when executed by a processor, implements the external device processing method based on the electronic system according to any one of the embodiments of the present application.

[0021] The technical scheme of the embodiment of the present application, when receiving an external device access request, determines the device type of the external device according to the access request. According to the device type, the security evaluation attribute corresponding to the external device is determined. When the security evaluation attribute meets the preset condition, the isolated environment parameter is allocated to the external device, and the target management information corresponding to the external device is deployed according to the isolated environment parameter. Based on this, the isolated environment is allocated to the external device with different security evaluation attributes. When the request parameter compliance verification in the device access request based on the target management information is passed, the external device is accessed to obtain the external device corresponding to the electric system, which is convenient for subsequent security communication between the external device and the electric system according to the target management information. The present application solves the problems of lack of unified management strategy in the prior art when processing external device access and security risk of the accessed external device, ensures the security of the accessed external device, realizes unified security management of the external device, and effectively prevents illegal access and malicious operation.

[0022] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0024] Figure 1 is a flowchart of an external device processing method based on an electric system provided by the embodiment of the present application;

[0025] Figure 2 is a flowchart of an external device processing method based on an electric system provided by the embodiment of the present application;

[0026] Figure 3 is a structural schematic diagram of an external device processing device based on an electric system provided by the embodiment of the present application;

[0027] Figure 4 is a structural schematic diagram of an electronic device for implementing the external device processing method based on an electric system of the embodiment of the present application. DETAILED DESCRIPTION

[0028] In the following, the technical solutions in the embodiments of the present application will be described clearly and completely with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of embodiments of the present application, rather than all embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work should fall within the protection scope of the present application.

[0029] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the application described herein can be implemented in other than the order illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a list of steps or units need not be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to such processes, methods, products or devices.

[0030] Embodiment one

[0031] Figure 1 It is a flowchart of a processing method of an external device based on an electric system provided by the embodiment one of the present application. The embodiment can be applied to the case of device authentication and security management of an external device to be accessed to an electric system. The method can be executed by an external device processing device based on an electric system. The external device processing device based on an electric system can be realized in the form of hardware and / or software. The external device processing device based on an electric system can be configured in an electronic device such as a mobile phone, a computer or a server. As shown in the figure, the method comprises: Figure 1

[0032] S110, when receiving an access request of an external device, determining a device type of the external device based on the access request.

[0033] ​In the embodiments of the present application, the electric terminal system is an industrial Internet of Things operating system for power equipment or power terminals. The electric terminal system includes a physical layer, a driver layer, a system layer, and an application layer. The physical layer is used for physical connection and communication with external devices. The driver layer is used for loading and managing external devices. The application layer is used for providing interfaces and recording logs, etc. The system layer is used for determining whether the external device can access and deploying target management information for managing the external device. The target management information can be used for managing the access of the external device and controlling the secure communication of the external device with the electric terminal system. Through the physical layer, the driver layer, the system layer, and the application layer of the electric terminal system, the whole-chain security protection of the external device from physical connection to data communication can be realized.

[0034] The external device can be understood as an external device connected to the device to which the electric terminal system belongs. The external device does not belong to the device in which the electric terminal system is deployed. The external device can communicate data with the electric terminal system. When the external device accesses the electric terminal system, the external device sends an access request to the electric terminal system. The access request contains the device type and device parameter information of the external device. The device type can be understood as the type of the external device. The device parameter information can include the running parameter of the external device when running and the device hardware parameter, etc.

[0035] Specifically, when the electric terminal system receives the access request sent by the external device, the device type of the external device is determined according to the device type carried in the access request, so as to determine whether the external device is a secure device according to the device type.

[0036] S120, based on the device type, determining a security evaluation attribute corresponding to the external device, wherein the security evaluation attribute is used to represent an isolation environment parameter to be allocated to the external device when accessing the external device.

[0037] The security evaluation attribute can be used to determine whether the external device is a secure device. Optionally, the security evaluation attribute can be the security level corresponding to the external device. According to the security evaluation attribute of the external device, it can be determined whether to allocate an isolation environment parameter to the external device. The isolation environment parameter can be used to configure an isolation environment for the external device. Optionally, the isolation environment parameter can include a system resource parameter allocated when configuring an isolation environment for the external device, an access permission parameter of the isolation environment, and the like.

[0038] Specifically, according to the device type of the external device, the security evaluation attribute of the current external device is determined. When the security evaluation attribute is a preset security evaluation attribute, it indicates that the security of the external device is poor, and the external device can be configured with an isolated environment. The isolated environment parameter to be allocated to the external device can be obtained. Correspondingly, if the security evaluation attribute is not the preset security evaluation attribute, the external device can not be configured with an isolated environment. The preset security evaluation attribute can be preset, and the security evaluation attribute of the external device needs to be configured with an isolated environment.

[0039] In the embodiment of the application, the security evaluation attribute of the external device can be determined by: calling a pre-created evaluation attribute mapping relationship table, wherein the evaluation attribute mapping relationship table includes at least one to-be-selected device type and a to-be-selected evaluation attribute corresponding to each to-be-selected device type; determining the security evaluation attribute corresponding to the device type based on the device type and the evaluation attribute mapping relationship table; wherein the device type is a type in the at least one to-be-selected device type, and the security evaluation attribute is an attribute in the to-be-selected evaluation attribute.

[0040] The evaluation attribute mapping relationship table can be used to represent the corresponding relationship between the device type and the security evaluation attribute. The evaluation attribute mapping relationship table includes at least one to-be-selected device type and a to-be-selected evaluation attribute corresponding to each to-be-selected device type. The to-be-selected device type can be preset, and at least one device type of the external device. The to-be-selected evaluation attribute can be pre-configured, and the security evaluation attribute corresponding to each to-be-selected device type.

[0041] Specifically, the pre-created evaluation attribute mapping relationship table is called. According to the device type of the external device, the to-be-selected device type consistent with the device type in the evaluation attribute mapping relationship table is determined. And the to-be-selected evaluation attribute corresponding to the to-be-selected device type is taken as the security evaluation attribute of the external device.

[0042] S130, when the security evaluation attribute meets the preset condition, the isolated environment parameter of the external device is configured, and the target management information corresponding to the external device is deployed based on the isolated environment parameter.

[0043] The preset condition can include at least one preset security evaluation attribute. The preset security evaluation attribute can be an attribute that needs to be configured with an isolated environment for the external device. For example, if the security evaluation attribute is a security level, the preset security evaluation attribute can be a preset security level that needs to be configured with an isolated environment for the external device. The isolated environment parameter can be used to configure an isolated environment for the external device. The isolated environment parameter can include system resource information allocated to the isolated environment, an operating system corresponding to the isolated environment, network configuration parameters, storage configuration information, and access permissions. The target management information can be used to manage the access of the external device and the secure communication between the external device and the electric home system. The target management information can be used to authenticate the identity of the external device and determine the encryption communication mode between the external device and the electric home system.

[0044] Specifically, when the security evaluation attribute is an evaluation attribute in the at least one preset security evaluation attribute, it is determined that the external device has a security risk. Then, an isolated environment configuration technology can be selected according to the isolated environment manager, and corresponding isolated environment parameters can be configured for the external device according to the isolated environment configuration technology. The isolated environment configured for the external device by the isolated environment parameters. The target management information is deployed for the isolated environment corresponding to the external device. It should be noted that if the external device does not meet the preset condition, the isolated environment does not need to be configured for the external device, and the target management information is directly applied to verify whether the external device can access, and the target management information is used to control the encrypted communication between the external device and the electric home system. The creation of an isolated environment for an external device that meets the preset condition through a security evaluation attribute can prevent the spread of security risks between different external devices.

[0045] The preset security evaluation attribute is preset security level, and the preset security level is taken as an example for description. According to the security requirement of the electric Hong system analyzed by the isolation environment manager, at least one preset security level is determined. The preset security level can be understood as a security level that needs to be isolated by the isolation environment. When the security level of the external device belongs to the security level in the at least one preset security level, the system resources such as CPU resources, memory resources and storage space are allocated to the external device. The isolation environment manager selects one of the virtualization technology or the Docker container technology as the isolation environment configuration technology. Optionally, the virtualization technology can be one of Type-1 virtual machine manager or Type-2 virtual machine manager. If the selected isolation environment configuration technology is virtualization technology, the operating system corresponding to the isolation environment, the network configuration parameter, the storage configuration information and the access permission information are configured. If the selected isolation environment configuration technology is container technology, the container image corresponding to the isolation environment, the container network information and the container storage information and the access permission information are configured. The target management information corresponding to the external device is configured in the isolation environment, so that the external device in the isolation environment communicates with the electric Hong system based on the target management information. The target management information can include the access control rule of the external device accessing the electric Hong system, and the data encryption communication mode of the external device and the electric Hong system.

[0046] In the embodiment of the present application, the preset condition includes at least one preset attribute level, and the configuration mode of the isolation environment corresponding to the external device and the deployment mode of the target management information can be: when the security evaluation attribute is an attribute in the at least one preset attribute level, the isolation environment parameters are allocated based on the device information of the external device, so as to create the isolation environment based on the isolation environment parameters; the preset management strategy consistent with the device type is called, and the target management information of the external device is obtained by analyzing the preset management strategy; the target management information is deployed in the isolation environment, so as to perform security verification and business processing on the business processing request based on the target management information when the business processing request of the external device is received; wherein the isolation environment parameters further include access permission information for accessing the electric Hong system.

[0047] The preset condition includes at least one preset attribute level. The preset attribute level can be understood as a preset security level corresponding to the external device. Optionally, the preset attribute level can be a preset security level under the request of the security evaluation attribute being a security level. The device information can include external device type information, device running parameter information, and hardware parameter information. The preset management policy can be a preconfigured security policy for controlling the access of the external device to the electric home system. Optionally, the preset management policy can be a preconfigured security policy based on a predefined security policy template, using a graphical display interface or a command line tool. Defining and editing the management policy corresponding to the external device through the graphical display interface or the command line tool can improve the flexibility and customizability of the preset management policy. The preset management policy can include access control rules for the external device to access the electric home system, data encryption requirements when the external device communicates with the electric home system, and a way of identity verification of the electric home system to the external device. Through the preset management policy, only the external device that passes the identity authentication and performs data encryption communication according to the data encryption requirements can normally communicate with the electric home system. It can be understood that by executing the preset management policy, the access and communication operations of the external device can be controlled and monitored in real time, thereby avoiding illegal access and malicious communication operations of the external device. The business processing request can be request information associated with business processing sent by the external device when communicating with the electric home system.

[0048] Specifically, when the security evaluation attribute of the external device is an attribute in the at least one preset attribute level, an isolated environment can be configured for the external device. That is, according to the information such as the external device type information, the device running parameter information, and the hardware parameter information of the external device, the isolated environment parameters corresponding to the external device are determined. The isolated environment parameters include system resource information allocated to the external device, an operating system corresponding to the isolated environment, network configuration parameters, storage configuration information, and access permission information for accessing the electric home system. Through the access permission information, the access permission of the isolated environment to the electric home system can be controlled to prevent potential security risks from spreading.

[0049] The isolated environment is created for the external device according to the isolated environment parameters. It should be noted that the system resources allocated to the isolated environment can be dynamically adjusted according to the system resource usage of the isolated environment. For example, if the system resource usage of the current isolated environment is high, more system resources are allocated to it.

[0050] According to the device type of the external device, a preset management strategy corresponding to the external device is invoked. The preset management strategy is parsed and processed to obtain target management information of the external device. Optionally, the target management information obtained by parsing can also be verified to ensure the accuracy and effectiveness of the target management information. The target management information is applied in the isolation environment and the electric system to perform security verification on the service processing request of the external device according to the access control rule in the target management information when the electric system receives the service processing request of the external device, and to perform service processing according to the service processing request after the verification is passed.

[0051] For example, the security evaluation attribute is the security level, the preset attribute level is the preset security level, the preset management strategy is the pre-set security strategy, and the isolation environment is the isolation environment created based on the Docker container technology. When the security level of the external device is at least one of the preset security levels, the isolation environment configuration technology is determined to be the Docker container technology according to the device information of the external device and the requirements of the electric system, and the isolation environment parameters are allocated to the external device. According to the Docker container technology and the isolation environment parameters, a container instance corresponding to the external device is created using a container image, and the storage space and system resources of the container instance are configured. The resource limit function of the Docker container technology and the system resource information that can be allocated to the external device in the isolation environment parameters are used to configure the usage limit of CPU resources and memory resources of the container instance. The security strategy corresponding to the device type of the external device is applied in the container instance. The isolation between container instances is realized by using the Linux Namespace mechanism to ensure that the processes in the container instance cannot access the resources of other container instances. The monitoring and logging function of the Docker container technology is used to monitor the running state and log information of the container instance, and to generate monitoring reports or log reports regularly or as needed. The container image and data corresponding to the container instance are regularly backed up to perform data recovery processing through backup data when the container instance fails.

[0052] S140, when the request parameter compliance verification in the device access request based on the target management information is passed, the external device is accessed to obtain an external device corresponding to the electric system.

[0053] The request parameter can be authentication parameter information sent by the external device for identity authentication of the external device. The external device can be understood as an external device accessing the electric system.

[0054] Specifically, the request parameter in the device access request of the external device is subjected to compliance verification processing according to the target management information and a preset verification algorithm. When the request parameter is consistent with the pre-stored device parameter of the external device, it is determined that the request parameter passes the compliance verification, that is, the identity authentication of the external device is passed. At this time, the external device accesses the electric Hong system, and the external device accessing the electric Hong system is regarded as an external device.

[0055] It should be noted that the external device can be subjected to compliance verification processing based on at least one authentication algorithm or authentication mode in the authentication algorithm library to realize identity authentication of the external device. For example, the authentication algorithm can be Public Key Infrastructure (PKI) or Open Authorization (OAuth). The authentication mode can be subjected to compliance verification processing through a digital certificate or an authentication password.

[0056] In the embodiment of the application, the target management information includes device verification information corresponding to the external device, and the compliance verification of the request parameter in the device access request based on the target management information includes: obtaining a device association parameter of the external device in the device access request; wherein the device association parameter is an unencrypted or decrypted parameter; and performing compliance verification on the request parameter based on the pre-stored device parameter corresponding to the device type in the device verification information and the device association parameter.

[0057] The target management information includes device verification information corresponding to the external device. The device verification information can be understood as parameter information for identity authentication of the external device. The device verification information includes pre-stored device parameters. The pre-stored device parameters can be understood as standard device association parameters corresponding to the external device. The device association parameter can include hardware parameter information and running parameter information corresponding to the external device. The compliance verification can be used to verify whether the external device is a legal external device.

[0058] Specifically, the device access request sent by the external device carries a device association parameter of the external device. If the received device management parameter is an encrypted parameter, the device management parameter can be decrypted. Correspondingly, if the received device management parameter is not an encrypted parameter, the device management parameter does not need to be decrypted. And the pre-stored device parameter corresponding to the device type in the device verification information and the device management parameter corresponding to the external device are subjected to compliance verification processing. When the pre-stored device parameter and the device management parameter are consistent, the compliance verification result of the request parameter is passed, and the identity authentication of the external device is passed. When the pre-stored device parameter and the device management parameter are inconsistent, the compliance verification of the request parameter is not passed, and the identity authentication of the external device is not passed. Based on this, the device security and reliability of the external device accessing the electric Hong system can be ensured, and the external device with risks is avoided.

[0059] An example is taken as an example of the device management parameter as authentication information. When receiving the device access request of the external device, the authentication information is decrypted based on at least one pre-stored authentication information and the key in the authentication information database, and the identity authentication of the external device is processed according to the decrypted authentication information and the pre-stored authentication information. In the case where the decrypted authentication information and the pre-stored authentication information are consistent, the identity authentication of the external device is passed.

[0060] The technical scheme of the embodiment, when receiving the external device access request, determines the device type of the external device according to the access request. According to the device type, the security evaluation attribute corresponding to the external device is determined. When the security evaluation attribute meets the preset condition, the isolation environment parameter is allocated to the external device, and the target management information corresponding to the external device is deployed according to the isolation environment parameter. Based on this, the isolation environment is allocated to the external device with different security evaluation attributes. When the request parameter compliance verification in the device access request is passed based on the target management information, the external device is accessed to obtain the external device corresponding to the electric system, which is convenient for subsequent security communication between the external device and the electric system according to the target management information. The present application solves the problems of lack of unified management strategy in the prior art when the external device access processing is performed, and security risk of the accessed external device, ensures the security of the accessed external device, realizes unified security management of the external device, and effectively prevents illegal access and malicious operation.

[0061] Embodiment two

[0062] Figure 2 It is a flowchart of a kind of external device processing method based on electric system provided by the embodiment two of the application, and the embodiment of the application is based on the above-mentioned embodiment, after accessing external device, the encryption communication mode between external device and electric system can also be set, to realize data encryption transmission between electric system and external device by encryption communication mode. Its specific implementation can be referred to the technical scheme of the embodiment. Wherein, same or corresponding technical terms as the above-mentioned embodiment are not described here. As shown in the figure, the method comprises: Figure 2

[0063] S210, when receiving the external device access request, the device type of the external device is determined based on the access request.

[0064] S220, based on the device type, the security evaluation attribute corresponding to the external device is determined, wherein the security evaluation attribute is used to represent the isolation environment parameter to be allocated to the external device when accessing the external device.

[0065] ​S230, configuring an isolation environment parameter for the external device when the security assessment attribute meets the preset condition, to deploy target management information corresponding to the external device based on the isolation environment parameter.

[0066] Optionally, when it is detected that a condition for updating the target management information is met, the target management information stored in the isolation environment is updated; wherein the condition for updating the target management information includes at least one of a condition for changing the target management information based on an upstream system, a condition for updating the target management information based on a timing task, and a condition for detecting a change in the target management information.

[0067] The upstream system can be understood as a superior system in communication with the electric terminal system. The timing task can include a preset time length for updating the target management information. When the time length from the last update of the target management information reaches the preset time length, the target management information is updated.

[0068] Specifically, if it is detected that the update instruction sent by the upstream system through the application layer interface of the electric terminal system, or the time length between the current time and the time of the last update of the target management information reaches the preset time length, or a change in the target management information is detected, the target management information is updated. The updated target management information is deployed in the isolation environment.

[0069] For example, when receiving the update instruction triggered by the application layer interface of the upstream system, or receiving the update instruction issued by the security policy library when detecting a change in the current target management information, the update instruction is parsed to obtain parsed information. The target management information is updated according to the parsed information, and the updated target management information is synchronized to the electric terminal system and the isolation environment to ensure the timeliness and consistency of the target management information.

[0070] S240, when the compliance check of the request parameter in the device access request based on the target management information is passed, the external device is accessed to obtain the external device corresponding to the electric terminal system.

[0071] S250, after accessing the external device, a first target key is issued to the external device, so that when the external device receives feedback information corresponding to a business processing request, the feedback information is decrypted based on the first target key.

[0072] The first target key can be a key used by the external device to decrypt data information sent by the electric terminal system. That is, the first target key is used to decrypt the feedback information. The business processing request can be used to request business data corresponding to the electric terminal system. The feedback information can be business data corresponding to the business processing request sent by the electric terminal system.

[0073] Specifically, after the external device is accessed, a data encryption communication channel between the external device and the electric Hong system can be established to ensure the confidentiality and integrity of data transmission between the external device and the electric Hong system. Specifically, a first target key can be issued to the external device, so that the external device decrypts the feedback information corresponding to the business processing request using the first target key when receiving the feedback information corresponding to the business processing request fed back by the electric Hong system.

[0074] S260, when receiving the business processing request sent by the external device, decrypting the business processing request based on the stored second target key corresponding to the first target key to determine the feedback information corresponding to the decrypted business processing request.

[0075] The business processing request can be request information associated with business processing sent by the external device. The electric Hong system can feed back business data corresponding to the business processing request, i.e. feedback information, through the business processing request sent by the external device. The second target key can be used to decrypt the business processing request sent by the external device. It should be noted that the first target key in S250 and the second target key in S260 are a key pair determined based on the same encryption algorithm. For example, the encryption algorithm can be an advanced encryption standard (AES) encryption algorithm or an RSA encryption algorithm. The key pair can be managed and stored by a corresponding key management module to ensure the security and reliability of the key.

[0076] Specifically, when receiving the business processing request sent by the external device, the business processing request is decrypted according to the second target key corresponding to the first target key stored in the key management module to obtain the decrypted business processing request. And according to the decrypted business processing request, the corresponding feedback information is fed back to the external device.

[0077] Optionally, the method further comprises: recording an interaction log during communication with the external device; obtaining an interaction report in the communication process by extracting and analyzing log data in the interaction log; wherein the interaction report includes interaction results in at least one dimension, and the at least one dimension includes at least one of the following: isolated environment running dimension, isolated environment system resource allocation dimension, data encryption communication dimension and isolated environment fault handling dimension.

[0078] The external device is an external device connected to the electric Hong system. For the convenience of subsequent description, the external device in the following description is an external device connected to the electric Hong system. The interaction log can be used to record the loading time of the external device, the record of the external device accessing the electric Hong system, the running status of the isolated environment to which the external device belongs, the system resource information allocated to the isolated environment, and the fault processing of the isolated environment. The interaction report can be a report obtained by analyzing and processing the log data, which can enable the corresponding management personnel to monitor the access and encrypted communication of the external device using the interaction report and trace abnormal problems. The interaction report can be generated regularly or on demand according to the interaction results in at least one dimension.

[0079] The interaction result can be understood as the result of data interaction between the electric Hong system and the external device. The interaction result can be the result in at least one dimension. The at least one dimension includes at least one of the isolated environment running dimension, the system resource allocation dimension of the isolated environment, the data encryption communication dimension, and the isolated environment fault processing dimension. The interaction result of the isolated environment running dimension can be used to represent information for interacting with the running state of the isolated environment. For example, the running state of the isolated environment can include the system resource usage of the isolated environment and the security event of the isolated environment. The interaction result of the system resource allocation dimension of the isolated environment can be used to represent information for interacting with the system resources allocated to the isolated environment. The interaction result of the data encryption communication dimension can be used to represent information for data encryption communication when the external device and the electric Hong system process business. The interaction result of the isolated environment fault processing dimension can be used to represent information for interacting with the fault condition of the isolated environment. For example, when the isolated environment fails, the corresponding isolated environment manager of the isolated environment can be used to automatically repair the isolated environment or report to the electric Hong system and provide fault repair suggestions, so as to remind the corresponding management personnel to troubleshoot and repair the isolated environment.

[0080] Specifically, when the electric Hong system communicates with the external device, the log information corresponding to the external device and the log information corresponding to the electric Hong system can be recorded to obtain the interaction log. For example, the log information corresponding to the external device can include the version and type of the external device, the loading duration at the time of access, the access information of the external device accessing the electric Hong system, and the like. The log data in the interaction log is extracted, and the extracted log data is analyzed and processed to detect whether there is an abnormal interaction behavior and a security problem in the communication process between the electric Hong system and the external device, and obtain an interaction report corresponding to the communication process. The interaction report can include at least one of the interaction results in the isolation environment running dimension, the system resource allocation dimension of the isolation environment, the data encryption communication dimension, and the isolation environment fault handling dimension, so as to monitor and detect abnormalities of the external device, the isolation environment to which the external device belongs, and the encrypted communication between the external device and the electric Hong system through the interaction report.

[0081] The technical scheme of the embodiment, when receiving the external device access request, determines the device type of the external device according to the access request. According to the device type, the security evaluation attribute corresponding to the external device is determined. When the security evaluation attribute meets the preset condition, the isolation environment parameter of the external device is allocated, and the target management information corresponding to the external device is deployed according to the isolation environment parameter. Based on this, the isolation environment for external devices with different security evaluation attributes is allocated. When the request parameter compliance check in the device access request based on the target management information is passed, the external device is accessed. Based on this, the security and reliability of the accessed external device are guaranteed. After accessing the external device, the first target key is issued to the external device, so that when the external device receives the feedback information corresponding to the business processing request, the feedback information is decrypted based on the first target key. And when receiving the business processing request sent by the external device, the business processing request is decrypted based on the second target key stored corresponding to the first target key to determine the feedback information corresponding to the decrypted business processing request. By encrypting the communication data between the external device and the electric Hong system, the security of data transmission is enhanced. The present application solves the problem of lack of unified management strategy in the prior art when the external device accesses, and the security risk of the accessed external device, guarantees the security of the accessed external device, realizes the unified security management of the external device, and effectively prevents illegal access and malicious operation.

[0082] Embodiment three

[0083] Figure 3 It is a structure schematic view of an external device processing device based on an electric Hong system provided by the embodiment three of the present application. As shown in Figure 3As shown, the device comprises a device type determination module 310, an evaluation attribute determination module 320, a management information determination module 330, and an external device access module 340.

[0084] The device type determination module 310 is configured to determine the device type of the external device based on the access request when the external device access request is received; the evaluation attribute determination module 320 is configured to determine the security evaluation attribute corresponding to the external device based on the device type, wherein the security evaluation attribute is used to represent the isolation environment parameter to be allocated to the external device when the external device is accessed; the management information determination module 330 is configured to configure the isolation environment parameter for the external device when the security evaluation attribute meets the preset condition, so as to deploy the target management information corresponding to the external device based on the isolation environment parameter; and the external device access module 340 is configured to access the external device when the request parameter compliance check in the device access request passes based on the target management information, so as to obtain the external device corresponding to the electric system.

[0085] The technical scheme of the embodiment, when receiving the external device access request, determines the device type of the external device according to the access request. According to the device type, the security evaluation attribute corresponding to the external device is determined. When the security evaluation attribute meets the preset condition, the isolation environment parameter is allocated to the external device, so as to deploy the target management information corresponding to the external device according to the isolation environment parameter. Based on this, the isolation environment is allocated to the external device with different security evaluation attributes. When the request parameter compliance check in the device access request passes based on the target management information, the external device is accessed, so as to obtain the external device corresponding to the electric system, which facilitates subsequent security communication between the external device and the electric system according to the target management information. The present application solves the problems of lack of unified management strategy in the prior art when the external device is accessed and security risk of the accessed external device, ensures the security of the accessed external device, realizes unified security management of the external device, and effectively prevents illegal access and malicious operation.

[0086] On the basis of the above-mentioned embodiment, optionally, the evaluation attribute determination module is configured to call a pre-created evaluation attribute mapping relationship table, wherein the evaluation attribute mapping relationship table comprises at least one to-be-selected device type and at least one to-be-selected evaluation attribute corresponding to the at least one to-be-selected device type; the security evaluation attribute corresponding to the device type is determined based on the device type and the evaluation attribute mapping relationship table; wherein the device type is a type in the at least one to-be-selected device type, and the security evaluation attribute is an attribute in the to-be-selected evaluation attribute.

[0087] Optionally, the preset condition comprises at least one preset attribute level, the management information determination module is configured to, when the security assessment attribute is an attribute in the at least one preset attribute level, assign an isolation environment parameter based on the device information of the external device to create an isolation environment based on the isolation environment parameter; retrieve a preset management policy consistent with the device type to obtain target management information of the external device by analyzing the preset management policy; and deploy the target management information in the isolation environment to perform security verification and business processing on a business processing request of the external device based on the target management information when the business processing request is received; wherein the isolation environment parameter further comprises access permission information for accessing the system.

[0088] Optionally, the target management information comprises device verification information corresponding to the external device, and the compliance verification of the request parameter in the device access request based on the target management information comprises: obtaining a device association parameter of the external device in the device access request; wherein the device association parameter is an unencrypted or decrypted parameter; and performing compliance verification of the request parameter based on a pre-stored device parameter corresponding to the device type in the device verification information and the device association parameter.

[0089] Optionally, after accessing the external device, the apparatus further comprises an encrypted communication module configured to: issue a first target key to the external device to decrypt feedback information corresponding to the business processing request based on the first target key when the feedback information is received by the external device; and decrypt the business processing request based on a second target key corresponding to the first target key stored in the apparatus to determine the feedback information corresponding to the decrypted business processing request when the business processing request is received from the external device.

[0090] Optionally, the apparatus further comprises a management information updating module configured to update the target management information stored in the isolation environment when a condition for updating the target management information is detected; wherein the condition for updating the target management information comprises at least one of a condition for changing the target management information based on an upstream system, a condition for updating the target management information based on a timing task, and a condition for detecting a change in the target management information.

[0091] Optionally, the apparatus further comprises an interaction report generation module configured to record an interaction log during communication with the external device; and obtain an interaction report in the communication process by extracting and analyzing log data in the interaction log; wherein the interaction report comprises an interaction result in at least one dimension, and the at least one dimension comprises at least one of an isolation environment running dimension, a system resource allocation dimension of the isolation environment, a data encrypted communication dimension, and an isolation environment fault handling dimension.

[0092] The external device processing device based on the Dianhong system provided in the embodiments of the present invention can execute the external device processing method based on the Dianhong system provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0093] Example 4

[0094] Figure 4 This is a schematic diagram of the structure of an electronic device provided in Embodiment 4 of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0095] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0096] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0097] The processor 11 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the electric-field-based system peripheral processing method.

[0098] In some embodiments, the electric-field-based system peripheral processing method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded onto the RAM 13 and executed by the processor 11, one or more steps of the electric-field-based system peripheral processing method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the electric-field-based system peripheral processing method by any other suitable means, such as by means of firmware.

[0099] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0100] Computer programs used to implement the electric-field-based system peripheral processing method of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor, implements the functions / operations specified in the flow charts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, and partially on a machine or a remote machine or a server.

[0101] Embodiment five

[0102] Embodiment five of the present application also provides a computer readable storage medium, which stores computer instructions for causing a processor to execute an external device processing method based on an electric Hong system, the method comprising:

[0103] Upon receiving the external device access request, determining a device type of the external device based on the access request; determining a security evaluation attribute corresponding to the external device based on the device type, wherein the security evaluation attribute is used to represent an isolation environment parameter to be allocated to the external device when accessing the external device; configuring the isolation environment parameter for the external device when the security evaluation attribute meets a preset condition, to deploy target management information corresponding to the external device based on the isolation environment parameter; and accessing the external device when a request parameter compliance check in the device access request based on the target management information is passed, to obtain an external device corresponding to the electric Hong system.

[0104] In the context of the present application, the computer readable storage medium can be a tangible medium, which can contain or store a computer program for use by or in connection with an instruction execution system, apparatus or device. The computer readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus or device, or any suitable combination of the above. Alternatively, the computer readable storage medium can be a machine readable signal medium. More specific examples of the machine readable storage medium will include one or more wires, portable computer disks, hard disks, random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), optical fiber, compact disk read only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0105] To provide interaction with the user, the system and technology described herein can be implemented on an electronic device having a display device (for example, a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user, and a keyboard and a pointing device (for example, a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (for example, visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including voice input, speech input, or tactile input).

[0106] The systems and techniques described herein can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described herein, or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0107] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.

[0108] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in different orders, as long as the desired results of the technical solutions of the present disclosure can be achieved, and the present disclosure is not limited herein.

[0109] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for processing an external device based on an electric field system, the electric field system including a system layer for processing an external device, the method comprising: The method comprises: ​ Upon receiving an external device access request, determining a device type of the external device based on the access request; Based on the device type, determining a security evaluation attribute corresponding to the external device, wherein the security evaluation attribute is used to represent the isolation environment parameters to be allocated to the external device when accessing the external device; When the security evaluation attribute meets a preset condition, configuring isolation environment parameters for the external device, and deploying target management information corresponding to the external device based on the isolation environment parameters; When the request parameter compliance check based on the target management information passes, accessing the external device to obtain an external device corresponding to the electric system; The preset condition includes at least one preset attribute level, and the isolation environment parameters for the external device are configured based on the security evaluation attribute meeting the preset condition, and the target management information corresponding to the external device is deployed based on the isolation environment parameters, comprising: When the security evaluation attribute is an attribute in the at least one preset attribute level, the isolation environment parameters are allocated based on the device information of the external device to create an isolation environment based on the isolation environment parameters; a preset management strategy consistent with the device type is called to obtain the target management information of the external device by analyzing the preset management strategy; the target management information is deployed in the isolation environment to perform security verification and business processing on the business processing request of the external device based on the target management information when the business processing request is received; wherein the isolation environment parameters further include access permission information for accessing the electric system.

2. The method of claim 1, wherein, The determination of the security evaluation attribute corresponding to the external device based on the device type comprises: Calling a pre-created evaluation attribute mapping relationship table, wherein the evaluation attribute mapping relationship table includes at least one selected device type and a selected evaluation attribute corresponding to the at least one selected device type; Based on the device type and the evaluation attribute mapping relationship table, the security evaluation attribute corresponding to the device type is determined; The device type is a type in the at least one selected device type, and the security evaluation attribute is an attribute in the selected evaluation attribute.

3. The method of claim 1, wherein, The target management information includes device verification information corresponding to the external device, and the request parameter compliance check based on the target management information comprises: Obtaining the device association parameter of the external device in the device access request; wherein the device association parameter is an unencrypted or decrypted parameter; Based on the pre-stored device parameter corresponding to the device type in the device verification information and the device association parameter, the request parameter compliance check is performed.

4. The method of claim 1, wherein, After accessing the external device, the method further comprises: issue a first target key for the external device, so that when the external device receives feedback information corresponding to a service processing request, the feedback information is decrypted based on the first target key; and when receiving the service processing request sent by the external device, the service processing request is decrypted based on the stored second target key corresponding to the first target key, to determine the feedback information corresponding to the decrypted service processing request.

5. The method of claim 1, wherein, The method further comprises: when it is detected that a condition for updating the target management information is met, updating the target management information stored in the isolated environment; The condition for updating the target management information includes at least one of a condition for changing the target management information based on an upstream system, a condition for updating the target management information based on a timing task, and a condition for detecting a change in the target management information.

6. The method of claim 1, wherein, The method further comprises: During the communication with the external device, an interaction log is recorded; By extracting and analyzing the log data in the interaction log, an interaction report in the communication process is obtained; The interaction report includes at least one dimension of interaction results, and the at least one dimension includes at least one of an isolated environment running dimension, an isolated environment system resource allocation dimension, a data encryption communication dimension, and an isolated environment fault handling dimension.

7. An external device processing apparatus based on an electric field system including a system layer for processing an external device, characterized by, Comprise: A device type determination module is configured to determine the device type of the external device based on the access request when receiving the access request of the external device; An evaluation attribute determination module is configured to determine a security evaluation attribute corresponding to the external device based on the device type, wherein the security evaluation attribute is used to represent the isolated environment parameters to be allocated to the external device when accessing the external device; A management information determination module is configured to configure isolated environment parameters for the external device when the security evaluation attribute meets a preset condition, to deploy target management information corresponding to the external device based on the isolated environment parameters; An external device access module is configured to access the external device when the request parameter compliance verification in the device access request passes based on the target management information, to obtain an external device corresponding to the electronic system; The preset condition includes at least one preset attribute level, and the management information determination module is configured to allocate the isolated environment parameters based on the device information of the external device when the security evaluation attribute is an attribute in the at least one preset attribute level, to create an isolated environment based on the isolated environment parameters; retrieve a preset management policy consistent with the device type, to obtain the target management information of the external device by analyzing the preset management policy; deploy the target management information in the isolated environment, to perform security verification and service processing on the service processing request of the external device based on the target management information when receiving the service processing request; wherein the access permission information for accessing the electronic system is also included in the isolated environment parameters.

8. An electronic device, comprising: The electronic device comprises: at least one processor; and A memory connected in communication with the at least one processor; wherein The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the method for processing an external device based on an electric field system according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing a processor to implement the method for processing an external device based on an electric field system according to any one of claims 1-6 when executed by the processor.

Citation Information

Patent Citations

  • Industrial control method, device and equipment

    CN108490893A

  • Scene synchronization method and device, electronic equipment and readable storage medium

    CN116074143A