Method, device, equipment, medium and product for updating policy of end-side device

By encrypting the policy files of the edge devices and performing signature array verification, the security issues of the policy files during transmission and application are solved, the security and accuracy of policy updates are achieved, and the stable operation of the devices is ensured.

CN119788352BActive Publication Date: 2025-10-17GUANGZHOU KETENG INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411872363.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-10-17
Estimated Expiration
2044-12-18

AI Technical Summary

Technical Problem

In the prior art, during the policy update process of edge devices, there is a risk that the policy file may be tampered with, stolen, or forged during transmission and application, affecting the security and stability of device operation.

Method used

By encrypting the newly added policy file, an encrypted policy file is generated, and hashing is used to obtain a first hash value. The signature array is determined based on the first hash value, the current signing time, the preset private key and the preset elliptic curve parameters. The signature array is verified to be decrypted under the preset configuration conditions to ensure the integrity and security of the policy file.

Benefits of technology

It improves the security and accuracy of edge device policy updates and ensures the security and stability of device operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788352B_ABST
    Figure CN119788352B_ABST
Patent Text Reader

Abstract

The application discloses an edge device policy updating method, device, equipment, medium and product. The method comprises the following steps: when a new policy file corresponding to an edge device is received, the new policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value; based on the first hash value, a current signature time, a preset private key and a preset elliptic curve parameter, a signature array corresponding to the encrypted policy file is determined; in the case that the encrypted policy file meets a preset configuration condition, the signature array is verified to obtain a verification result; in the case that the verification result is consistent with a preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file. The technical scheme provided by the embodiment of the application can ensure the integrity of the policy file, improve the security of the edge device policy updating, and ensure the stability of the equipment operation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, and particularly relates to a strategy updating method and device for edge devices, equipment, media and products. BACKGROUND

[0002] With the rapid development of smart grids, the power grid not only includes traditional power generation, transmission and distribution facilities, but also integrates a large number of intelligent edge devices. These devices include smart meters, power distribution automation terminals, substation automation devices, etc., which are distributed in various corners of the power grid and are responsible for data acquisition, monitoring, protection and control functions. In order to adapt to the changing power grid operating environment and safety requirements, the operation strategies of these devices need to be updated and optimized regularly.

[0003] Currently, the strategy updating method for edge devices is usually to transmit a strategy file through a remote network, and when the edge device receives the strategy file, the operation strategy of the device is updated based on the strategy file. However, due to the wide distribution of edge devices and the fact that they are usually in an open network environment, there is a risk of tampering, stealing or forgery of the strategy file during transmission and application, which affects the safety and stability of device operation. SUMMARY

[0004] The present application provides a strategy updating method and device for edge devices, equipment, media and products to ensure the integrity of the strategy file while improving the security of the edge device strategy update and ensuring the safety and stability of device operation.

[0005] According to an aspect of the present application, a strategy updating method for edge devices is provided, which comprises:

[0006] When a new strategy file corresponding to the edge device is received, the new strategy file is encrypted to obtain an encrypted strategy file, and the encrypted strategy file is hashed to obtain a first hash value;

[0007] Based on the first hash value, the current signature time, the preset private key and the preset elliptic curve parameters, a signature array corresponding to the encrypted strategy file is determined;

[0008] If the encrypted strategy file meets the preset configuration condition, the signature array is verified to obtain a verification result;

[0009] If the verification result is consistent with the preset result, the encrypted strategy file is decrypted to obtain a decrypted strategy file, and the strategy file in the edge device is updated based on the decrypted strategy file.

[0010] According to another aspect of the present application, there is provided a policy updating apparatus of an edge device, the apparatus comprising:

[0011] a file encryption module configured to, when receiving a newly added policy file corresponding to the edge device, encrypt the newly added policy file to obtain an encrypted policy file, and hash the encrypted policy file to obtain a first hash value;

[0012] a signature array determination module configured to determine a signature array corresponding to the encrypted policy file based on the first hash value, a current signature time, a preset private key and a preset elliptic curve parameter;

[0013] a verification result determination module configured to, when the encrypted policy file satisfies a preset configuration condition, verify the signature array to obtain a verification result;

[0014] a decryption module configured to, when the verification result is consistent with a preset result, decrypt the encrypted policy file to obtain a decrypted policy file, and update a policy file in the edge device based on the decrypted policy file.

[0015] According to another aspect of the present application, there is provided an electronic device, the electronic device comprising:

[0016] at least one processor; and a memory connected with the at least one processor in communication; wherein

[0017] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the policy updating method of the edge device according to any one of the embodiments of the present application.

[0018] According to another aspect of the present application, there is provided a computer readable storage medium storing computer instructions for enabling a processor to perform the policy updating method of the edge device according to any one of the embodiments of the present application when executed by the processor.

[0019] According to another aspect of the present application, there is provided a computer program product comprising a computer program for implementing the policy updating method of the edge device according to any one of the embodiments of the present application when executed by a processor.

[0020] The technical scheme of the embodiment of the application is that when a newly added policy file corresponding to an edge device is received, the newly added policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value; based on the first hash value, a current signature time, a preset private key and a preset elliptic curve parameter, a signature array corresponding to the encrypted policy file is determined; in the case that the encrypted policy file meets a preset configuration condition, the signature array is verified to obtain a verification result; in the case that the verification result is consistent with a preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file, thereby solving the problem that in the prior art, the policy file is updated based on network transmission, and the operation policy of the edge device is updated, which results in low security and poor accuracy of policy updating, and the encrypted policy file corresponding to the newly added policy file of the edge device is first encrypted, the encrypted policy file is hashed to obtain a first hash value, then the signature array corresponding to the encrypted policy file is determined in combination with the first hash value, the current signature time, the preset private key and the preset elliptic curve parameter, and the encryption strength of the signature array is improved. In the case that the encrypted policy file meets the preset configuration condition, the signature array is verified to ensure the integrity of the policy file, and in the case that the verification result is consistent with the preset result, the encrypted policy file is decrypted, and the policy file in the edge device is updated based on the decrypted policy file, thereby improving the security and accuracy of policy updating of the edge device, and achieving the effect of ensuring the security and stability of device operation.

[0021] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the application, nor is it used to limit the scope of the application. Other features of the application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can also be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0023] Figure 1 is a flowchart of a policy updating method of an edge device according to an embodiment of the application;

[0024] Figure 2 is a flowchart of a policy updating method of an edge device according to an embodiment of the application;

[0025] Figure 3 is a flowchart of a policy updating method of an edge device according to an embodiment of the application;

[0026] Figure 4 is a flow chart of a policy updating method of an edge device according to an embodiment four of the present application;

[0027] Figure 5 is a structural schematic diagram of a policy updating device of an edge device according to an embodiment five of the present application;

[0028] Figure 6 is a structural schematic diagram of an electronic device for implementing a policy updating method of an edge device according to an embodiment of the present application. DETAILED DESCRIPTION

[0029] In order to make the personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present application.

[0030] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0031] Embodiment one

[0032] Figure 1 is a flow chart of a policy updating method of an edge device according to an embodiment one of the present application. The present embodiment can be applicable to the case of updating the policy file of the edge device safely. The method can be executed by a policy updating device of the edge device, which can be realized in the form of hardware and / or software, and can be configured in a computing device. As shown in the figure, the method comprises: Figure 1

[0033] S110, when a new policy file corresponding to the edge device is received, the new policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value. ​

[0034] The end-side device can be a device in the power grid with functions of collection, monitoring, protection, control, and / or network connection, etc. For example, the end-side device can be a smart meter, a power distribution automation terminal, a substation automation device, a feeder terminal device, an open-close lock terminal device, a distribution transformer terminal device, a data transmission unit, a transformer temperature collection unit, etc. The above are examples, and the end-side device is not limited in the embodiment. The new policy file can be a policy file used to define and manage the operation behavior and permission of the device. For example, the file can contain policy information, configuration parameters, rule information, or other setting information, etc. so that the device can perform corresponding work according to the information in the file. The encrypted policy file can be a policy file obtained by encrypting the new policy file.

[0035] In the embodiment, when the policy generation end generates a new policy configuration file for a certain end-side device, the policy configuration file is taken as the new policy file of the end-side device. That is, the new policy file is a policy file generated by the policy generation end and not configured into the end-side device. The new policy file can be encrypted by using a symmetric encryption algorithm to obtain an encrypted policy file. For example, the symmetric encryption algorithm can be a DES (Data Encryption Standard) algorithm, a 3DES (Triple Data Encryption) algorithm, an AES (Advanced Encryption Standard) algorithm, etc. Further, the encrypted policy file can be hashed by using a SHA-512 algorithm (Secure Hash Algorithm) to obtain a hash value as a first hash value. The digital signature of the encrypted policy file is determined based on the first hash value to verify the integrity and security of the policy file, and to ensure that the policy file has not been tampered with.

[0036] For example, the calculation formula for determining the first hash value can be represented as: H(C) = SHA-512(C); where SHA-512() represents the objective function of the SHA-512 algorithm, C represents the encrypted policy file, and H(C) represents the first hash value. The length of the first hash value is 512 bits (i.e., 64 bytes).

[0037] In the embodiment, the new policy file is encrypted to obtain the encrypted policy file, including: generating an initialization vector and a random key based on a random number generation algorithm; converting the new policy file to obtain byte data; and encrypting the byte data based on the initialization vector and the random key to obtain the encrypted policy file.

[0038] The random number generation algorithm can be at least one of a pseudo-random number generator, a true random number generator, and a cryptographically secure random number generator. The vector values of the initialization vector and the random key can be different; the vector lengths of the initialization vector and the random key are the same, for example, the vector lengths can each be 128 bits (i.e., 16 bytes). The data structure of the byte data is a byte array, and the byte data includes a plurality of block data, each block data occupying a preset number of bytes of the entire byte array. For example, the size of each block data can be 128 bits.

[0039] Specifically, two random vectors can be randomly generated using a random number generation algorithm, one as an initialization vector and the other as a random key. The file content in the new policy file is read and converted into binary data, which is stored in a byte array to obtain byte data. Then, the byte data is divided into a plurality of block data according to the block size (e.g., 128 bits) of the AES algorithm. If the byte data is not an integer multiple of the block size, the byte data can be padded to meet the block size requirement. Further, the plurality of block data can be encrypted using the AES algorithm in combination with the CBC (Cipher Block Chaining) mode to obtain the encrypted data corresponding to each block data in the byte data. When encrypting the first block data, the initialization vector can be used to encrypt the first block data to obtain the encrypted data corresponding to the first block data. When encrypting each block data after the first block data, the random key and the encrypted data corresponding to the block data before the current block data can be used to encrypt the current block data. For example, the current block data is subjected to a bitwise XOR operation with the encrypted data of the previous block data, and the second random vector is used to encrypt the data after the bitwise XOR operation to obtain the encrypted data corresponding to the current block data. The encrypted data corresponding to each block data can be integrated to obtain an encrypted policy file. After encryption, the original new policy file is converted into an encrypted policy file, which cannot be directly used, and only by having the same random vector and performing corresponding restoration processing can the encrypted policy file be decrypted.

[0040] For example, the calculation formula for determining the random key can be expressed as: K = RandomBytes(128); wherein, RandomBytes() represents a target function of the random number generation algorithm, K represents the random key, and the length is 128 bits. Meanwhile, an initialization vector IV is generated by using the random number generation algorithm, and the length is also 128 bits. The calculation formula for determining the encrypted policy file can be expressed as: C = AES_CBC_Encrypt(P_bytes, K, IV); wherein, C represents the encrypted policy file; P_bytes represents byte data; and AES_CBC_Encrypt represents a target function of the AES algorithm. The target function of the AES algorithm can be expressed as: C i = E K (P i ⊕C i-1 )(i = 1, 2, …, n); wherein, P i represents the ith block data in the byte data; C i represents the encrypted data corresponding to the ith block data; E K represents an AES encryption operation using the random key K; C i-1 represents the encrypted data corresponding to the (i-1)th block data (the encrypted data corresponding to the first block data is the initialization vector, that is, C0 = IV); and represents a bitwise XOR operation. All encrypted Cis combined to form the final encrypted policy file C.

[0041] The technical solution provided in the embodiment generates a random key and an initialization vector, then encrypts the new policy file by using the AES-CBC mode, and in the CBC mode, each block data is XORed with the encrypted data of the previous block data during encryption, so that the encryption result of the same block data is different each time, thereby ensuring the security of the policy file during storage and transmission.

[0042] In S120, a signature array corresponding to the encrypted policy file is determined based on the first hash value, the current signature moment, the preset private key, and the preset elliptic curve parameter.

[0043] The preset private key is a key used for signing. The preset elliptic curve parameter refers to a mathematical parameter describing an elliptic curve, and the preset elliptic curve parameter includes an order and a base point. The base point of the preset elliptic curve parameter is a fixed point on the elliptic curve corresponding to the preset elliptic curve parameter. The order can refer to the number of all points on the elliptic curve, or the order of the base point, which refers to the number of points that can be generated from the base point through an addition operation. The order and the base point depend on the selected elliptic curve, and the present embodiment does not make specific limitations thereto. The current signature time can be a timestamp, used to ensure the timeliness of the signature array. The signature array includes at least two signature values, and the first signature value can be a signature value determined based on the first hash value, the current signature time, and the preset elliptic curve parameter; and the second signature value can be a signature value determined based on the first hash value, the first signature value, the preset private key, and the preset elliptic curve parameter.

[0044] In the present embodiment, the preset private key and the preset elliptic curve parameter can be used to digitally sign the first hash value at the current signature time and the current signature time, to generate a signature array corresponding to the encryption policy file, so as to verify the correctness and integrity of the encryption policy file based on the signature array.

[0045] In the present embodiment, the signature array corresponding to the encryption policy file is determined based on the first hash value, the current signature time, the preset private key, and the preset elliptic curve parameter, including: determining a random vector based on the first hash value and the current signature time according to a message authentication code algorithm based on a hash function; determining a first signature value based on the random vector and the preset elliptic curve parameter; determining a second signature value based on the preset private key, the first signature value, the first hash value, the random vector, and the preset elliptic curve parameter; and determining the signature array based on the first signature value and the second signature value.

[0046] The message authentication code algorithm based on a hash function can be a message authentication code algorithm based on a SHA-256 hash function (HMAC-SHA-256 algorithm), used to generate a message authentication code in combination with a hash function and a key.

[0047] In the embodiment, the first hash value can be taken as a key, the current signature moment can be taken as a message, and the key and the message are subjected to a hash operation by using the SHA-256 algorithm to generate a 256-bit message authentication code, which is the random vector. For example, the key and the message are subjected to a combination process, which can be an exclusive or process or a splicing process, and the combined key and message are subjected to a first hash operation to obtain a result of the first hash operation; the result of the first hash operation and the key (i.e., the first hash value) are subjected to a second hash operation, and the result of the second hash operation is taken as the message authentication code. Further, the random vector can be subjected to digital signature based on the elliptic curve digital signature algorithm (ECDSA, Elliptic Curve Digital Signature Algorithm) by using preset elliptic curve parameters to obtain a first signature value. Further, the first signature and a preset private key can be subjected to a product process to obtain a first product value; the first hash value and the first product value are subjected to a summation process to obtain a sum value; a modular inverse of the random vector under an order of the preset elliptic curve parameter is calculated as a first modular inverse, that is, a product value of the first modular inverse and the random vector divided by the order is equal to 1. The sum value and the first modular inverse are subjected to a product process to obtain a second product value; the second product value and the order of the preset elliptic curve parameter are subjected to a modulo operation to obtain a second signature value, that is, a remainder obtained by dividing the second product value by the order is taken as the second signature value. Further, the first signature value and the second signature value can be taken as two signature values in a signature array.

[0048] For example, the calculation formula for determining the random vector can be represented as: k = HMAC-SHA-256 (H(C) || T); in the formula: HMAC-SHA-256 represents a target function of a hash function-based message authentication code algorithm; H(C) represents the first hash value; T represents the current signature moment; and k represents the generated signature random number, i.e., the random vector. The calculation formula for determining the second signature value can be represented as: s = k -1 ·(H(C) + r·d) mod n; wherein: k -1 represents the modular inverse of the random vector k under the order n of the preset elliptic curve parameter, i.e., the first modular inverse; mod represents a modulo operation, i.e., a remainder operation; d represents the preset private key; H(C) represents the first hash value; n represents the order of the preset elliptic curve parameter; r represents the first signature value; and the final signature array is a two-element tuple composed of r and s, i.e., (r, s).

[0049] The technical solution provided in the embodiment can ensure that the signature time and the hash value are different each time while making the determined random vector each time have high randomness and high security, thereby enhancing the security of the signature value. Meanwhile, the first signature value is determined by using the random vector and the preset elliptic curve parameter, and the second signature value is determined by using the preset private key, the first signature value, the first hash value, the random vector and the preset elliptic curve parameter, thereby further enhancing the security of the signature array and guaranteeing the integrity of the policy file.

[0050] In the embodiment, the first signature value is determined based on the random vector and the preset elliptic curve parameter, including: determining an elliptic curve coordinate based on a base point of the random vector and the preset elliptic curve parameter; and determining the first signature value based on a coordinate value on a first coordinate axis in the elliptic curve coordinate and an order of the preset elliptic curve. The first coordinate axis can be an X coordinate axis.

[0051] Specifically, the base point of the random vector and the preset elliptic curve parameter can be multiplied to obtain the elliptic curve coordinate; and an abscissa value on the X coordinate axis in the elliptic curve coordinate can be extracted, and a modulus operation is performed on the abscissa value and the order of the preset elliptic curve, and a remainder obtained by the modulus operation is taken as the first signature value.

[0052] For example, the calculation formula for determining the elliptic curve coordinate can be P k =k·G; in the formula, k represents the random vector; G represents the base point; P k represents the elliptic curve coordinate, and the coordinate of P k is (x k ,y k ), wherein x k is the abscissa value of P k on the elliptic curve. The calculation formula for determining the first signature value can be r x =kmod n; wherein: n represents the order of the preset elliptic curve parameter; mod represents the modulus operation; and r represents the first signature value. The technical solution provided in the embodiment generates the first signature value in this way, calculates the second signature value s based on the preset private key, the first hash value, the random vector, the first signature value r and the order of the elliptic curve, and obtains the final signature array (r, s) based on the calculated signature values r and s, thereby improving the security of the signature array.

[0053] S130, in the case where the encrypted policy file meets a preset update condition, verifying the signature array to obtain a verification result.

[0054] The preset update condition can be a condition for judging whether to configure the encrypted policy file to an edge device.

[0055] In this embodiment, it can be judged whether the encryption policy file meets the preset update condition. Optionally, the preset update condition can be that a timing update task is triggered; or the signature array corresponding to the encryption policy file is determined; or an instruction of configuring the encryption policy file to the edge device is received; or the encryption policy file and the signature array corresponding to the encryption policy file are received by the edge device. In this way, when the encryption policy file meets the preset update condition, the signature array can be checked using the public key corresponding to the preset private key; or it is judged whether each signature in the signature array is within the preset interval to check its validity. If the validity is checked, it is determined that the check result is that the check is passed; if the validity is not checked, it is determined that the check result is that the check is not passed.

[0056] In the case where the check result is consistent with the preset result, the encryption policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file.

[0057] In this embodiment, if the check result is consistent with the preset result, it means that the signature array is checked successfully. At this time, the encryption policy file can be decrypted using the random key and the initialization vector, and the encryption policy file is restored to the original new policy file through the decryption operation, which is used as the decrypted policy file. Further, the decrypted policy file can be configured to the edge device to update and upgrade the policy file in the edge device. For example, the calculation formula of the decrypted policy file can be represented as: P = AES-Decrypt (E, K, IV); wherein: AES-Decrypt represents a function of decrypting using the AES algorithm; P represents the decrypted new policy file, i.e. the decrypted policy file; E represents the received encryption policy file; K represents the shared random key; and IV represents the initialization vector.

[0058] The technical scheme provided by the embodiment of the application comprises the following steps: when a new policy file corresponding to an edge device is received, the new policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value; based on the first hash value, a current signature time, a preset private key and a preset elliptic curve parameter, a signature array corresponding to the encrypted policy file is determined; in the case that the encrypted policy file meets a preset configuration condition, the signature array is verified to obtain a verification result; in the case that the verification result is consistent with a preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file, thereby solving the problem that the operation policy of the edge device is updated based on the network transmission of the policy file in the prior art, and the security and accuracy of the policy update are low, the encrypted policy file corresponding to the new policy file of the edge device is first processed, the encrypted policy file is hashed to obtain the first hash value, then the signature array corresponding to the encrypted policy file is determined in combination with the first hash value, the current signature time, the preset private key and the preset elliptic curve parameter, and the encryption strength of the signature array is improved. In the case that the encrypted policy file meets the preset configuration condition, the signature array is verified to ensure the integrity of the policy file, and in the case that the verification result is consistent with the preset result, the encrypted policy file is decrypted, the policy file in the edge device is updated based on the decrypted policy file, the security and accuracy of the policy update of the edge device are improved, and the security and stability of the device operation are ensured.

[0059] Embodiment two

[0060] Figure 2 is a flowchart of a policy update method of an edge device according to the embodiment two of the application, and the "S130" is further introduced on the basis of the foregoing embodiment. The specific implementation can be referred to the technical scheme of the embodiment. The same or corresponding technical terms as the foregoing embodiment are not described herein.

[0061] As Figure 2 shown, the method specifically comprises the following steps:

[0062] S210, when a new policy file corresponding to an edge device is received, the new policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value.

[0063] S220, based on the first hash value, a current signature time, a preset private key and a preset elliptic curve parameter, a signature array corresponding to the encrypted policy file is determined.

[0064] S230. When the encryption policy file meets the preset update conditions, determine whether the first signature value and the second signature value in the signature array are within a preset range. If not, execute step S240; if so, execute step S250.

[0065] The preset range is determined based on the order and preset value of the preset elliptic curve parameter. The preset value may be 1, and the preset range may be [1, order).

[0066] In this embodiment, it can be determined whether the first signature value and the second signature value in the signature array are within a preset range. If so, step S250 is executed; if not, the verification result is determined to be verification failure.

[0067] For example, when the edge device receives the encrypted policy file and signature array sent by the policy generation end, it can determine whether the first signature value r and the second signature value s are within the preset range [1, n). If 1≤r <n且1≤s<n,则执行S250步骤,以使用SHA-512算法计算接收到的加密策略文件的第二哈希值H(E),否则,直接判定签名数组无效,即校验结果为校验未通过。其中,n表示为阶。

[0068] S240: Determine that the verification result is verification failure.

[0069] S250: Perform hash processing on the encryption policy file to obtain a second hash value.

[0070] In practical applications, when it is determined that the first signature value and the second signature value in the signature array are both within a preset range, the encryption policy file can be hashed using the SHA-512 algorithm to obtain a 512-bit (i.e., 64-byte) hash value as the second hash value.

[0071] S260: Determine a first intermediate value based on the preset elliptic curve parameters, the second Hash value, the preset public key, the first signature value, and the second signature value.

[0072] The preset public key corresponds to the preset private key.

[0073] In this embodiment, a verification value can be obtained by using the preset elliptic curve parameter, the second hash value, the preset public key, the first signature value and the second signature value, and the verification value is taken as the first intermediate value. The first intermediate value can be determined in the following manner: based on an order of the preset elliptic curve parameter and the second signature value, an inverse element is determined; based on the inverse element, the second hash value and the order, a second intermediate value is determined; based on the inverse element, the first signature value and the order, a third intermediate value is determined; and based on the preset elliptic curve parameter, the preset public key, the second intermediate value and the third intermediate value, the first intermediate value is determined. The second intermediate value and the third intermediate value are two integers, and correspond to the weights of the hash value and the signature value respectively.

[0074] Specifically, the modular inverse of the second signature value under the order of the preset elliptic curve parameter can be calculated as a second modular inverse, and the modular inverse of the second modular inverse under the order can be calculated as the inverse element. That is, the product of the second modular inverse and the second signature value divided by the order is equal to 1, and the product of the inverse element and the second modular inverse divided by the order is equal to 1. Further, the inverse element and the second hash value can be multiplied to obtain a third product value, and the third product value and the order can be subjected to a modulo operation to obtain a remainder as the second intermediate value. The inverse element and the second signature value can be multiplied to obtain a fourth product value, and the fourth product value and the order can be subjected to a modulo operation to obtain a remainder as the third intermediate value. Further, the first intermediate value can be determined in combination with the preset elliptic curve parameter, the preset public key, the second intermediate value and the third intermediate value.

[0075] For example, the calculation formula of the inverse element can be represented as: w = s -1 mod n; s -1 represents the inverse element of the second signature value s under the order n, that is, s -1 . w represents the inverse element of the second modular inverse s -1 under the order n. The calculation formula of the second intermediate value u1 can be represented as: u1 = H(E) · w mod n; H(E) represents the second hash value. The calculation formula of the third intermediate value u2 can be represented as: u2 = r · w mod n; r represents the second signature value.

[0076] In this embodiment, the first intermediate value is determined based on the preset elliptic curve parameter, the preset public key, the second intermediate value and the third intermediate value, including: based on the base point of the preset elliptic curve parameter, the preset public key, the second intermediate value and the third intermediate value, a verification point coordinate is determined; and based on the verification point coordinate and the order of the preset elliptic curve parameter, the first intermediate value is determined.

[0077] In actual application, the base point of the preset elliptic curve parameter and the second intermediate value can be multiplied to obtain a fifth product value, and the preset public key and the third intermediate value can be multiplied to obtain a sixth product value. The fifth product value and the sixth product value are summed to obtain a verification point coordinate on the elliptic curve. A horizontal coordinate under a first coordinate axis is extracted from the verification point coordinate. The horizontal coordinate and an order of the preset elliptic curve parameter are subjected to a modulo operation, and a remainder obtained is taken as the first intermediate value.

[0078] For example, a calculation formula for determining the verification point coordinate can be represented as: P v = u1·G + u2·PK; wherein P v represents the verification point coordinate; u1 represents the second intermediate value; u2 represents the third intermediate value; G represents the base point; PK represents the preset public key; and · represents an operator of scalar multiplication. A horizontal coordinate x v is extracted from the verification point coordinate P v , and a calculation formula for determining the first intermediate value can be represented as: j = x v mod n; n represents the order, and j represents the first intermediate value. If the first intermediate value is consistent with the second signature value, it is determined that the verification result is the preset result, that is, the signature verification is successful. If the two are inconsistent, it is determined that the verification result is that the verification fails, that is, the signature verification fails, at this time, the edge device refuses to use the policy file, and logs are recorded.

[0079] S270, when the first intermediate value is consistent with the second signature value, it is determined that the verification result is the preset result.

[0080] The preset result is that the verification passes.

[0081] Specifically, the first intermediate value and the second signature value can be compared. If the two are consistent, it is determined that the verification result is the preset result. If the two are inconsistent, it is determined that the verification result is that the verification fails.

[0082] S280, in the case that the verification result is consistent with the preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file.

[0083] The technical scheme provided in the embodiment is that, by taking the first signature value and the second signature value in the signature array in a preset range, the encrypted policy file is subjected to a hash processing to obtain a second hash value, and then based on the preset elliptic curve parameter, the second hash value, the preset public key, the first signature value and the second signature value, the first intermediate value is determined, and when the first intermediate value is consistent with the second signature value, it is determined that the verification result is that the verification passes.

[0084] Embodiment three

[0085] Figure 3is a flowchart of a policy updating method of an edge device according to Embodiment Three of the present application. On the basis of the foregoing embodiment, before updating the policy file in the edge device based on the decrypted policy file, the decrypted policy file can be detected based on a detection method of at least one detection dimension, so that the policy file in the edge device is updated based on the decrypted policy file in the case of passing the detection. The specific implementation can be referred to the technical solution of the present embodiment. Among them, the same or corresponding technical terms as the above embodiments will not be repeated here.

[0086] As shown in Figure 3 , the method specifically comprises the following steps:

[0087] S310, detecting the decrypted policy file based on a detection method of at least one detection dimension.

[0088] Among them, the detection dimension at least includes file header detection dimension, field detection dimension, nested structure detection dimension, parameter compliance detection dimension, dependency relationship detection dimension, context detection dimension, configuration conflict detection dimension and environment adaptability verification dimension.

[0089] In the case of detecting the detection dimension including the file header detection dimension, the detection method of the decrypted policy file can be: confirming whether the file type and format of the decrypted policy file meet the preset requirements; or checking whether the file header of the decrypted policy file contains a predetermined identifier, if yes, determining that the detection result under the file header detection dimension is detection pass, if not, determining that the detection result is detection fail, so as to ensure the correctness of the decrypted policy file.

[0090] In the case that the detection dimension includes the field detection dimension, the detection on the decryption policy file can be performed in the following manner: the field order, field type and data length in the decryption policy file can be verified to see if they conform to the predefined format, if yes, it is determined that the detection result under the field detection dimension is passed, otherwise, it is determined that the detection result under the field detection dimension is failed. For example, a rule-based parser can be used to check if the field type (such as string, number, boolean) in the decryption policy file matches the expectation according to the predefined JSON / YAML / XML schema rule. For example, the field max_connections (maximum number of connections) in the policy configuration should be an integer, if it is found to be a string during parsing, the format verification fails, i.e., the detection result under the field detection dimension is failed. Alternatively, a pattern matching-based verification method can be used to check if the field content in the decryption policy file conforms to the predetermined format. For example, assuming that a date field expiration_date in the policy configuration file must conform to the yyyy-mm-dd format, a regular expression can be used to match to determine if the date field content conforms to the predetermined format.

[0091] In the case that the detection dimension includes the nested structure detection dimension, the detection on the decryption policy file can be performed in the following manner: the nested structure in the decryption policy file is verified, such as checking if the JSON, XML and the like format is correct, if yes, it is determined that the detection result is passed, if not, it is determined that the detection result is failed, so as to guarantee the accuracy of the decryption policy file. For example, for the multi-layer nested configuration item (such as JSON or XML format) in the decryption policy file, the structure of each layer can be recursively verified to see if it conforms to the predetermined rule. For example, a tree structure verifier can be constructed to automatically check the dependency relationship and hierarchical order of the parent and child nodes in the decryption policy file.

[0092] In the case that the detection dimension includes the parameter compliance detection dimension, the detection on the decryption policy file can be performed in the following manner: the parameters in the decryption policy file are checked to see if they conform to the preset compliance condition, for example, whether max_connections exceeds the maximum value supported by the edge device, if yes, it is determined that the detection result under the parameter compliance detection dimension is failed, at this time, a warning or the application of the policy can be triggered to be rejected, so as to ensure that the range or value domain of each parameter value in the file conforms to the limitation of the current environment of the edge device.

[0093] In the case that the detection dimension includes the dependency relationship detection dimension, the manner of detecting the decryption policy file can be: verifying whether the dependency relationship in the decryption policy file exists incompatible, for example, there can be some fields in the policy file that depend on the value of other fields, such as network_timeout (network timeout) depends on the size of max_connections. When max_connections is set to 0, network_timeout should not be a valid numerical value. If network_timeout is a valid numerical value, it is determined that the detection result under the dependency relationship detection dimension is detection failure.

[0094] In the case that the detection dimension includes the context detection dimension, the manner of detecting the decryption policy file can be: detecting the decryption policy file according to the current state or environment configuration of the edge device. For example, if the edge device is in a low load state, the power_saving_mode (power saving mode) configuration item should be enabled, and should not be configured as a disabled state. If the power_saving_mode configuration item in the decryption policy file is in the disabled state, it is determined that the detection result under the context detection dimension is detection failure.

[0095] In the case that the detection dimension includes the configuration conflict detection dimension, the manner of detecting the decryption policy file can be: parsing the decryption policy file to extract key information therein, the key information includes but is not limited to the field and value of the policy configuration. For example, assuming that the decryption policy file is in JSON format, the fields can include max_connections (representing the maximum number of allowed connections, the number of devices that can be connected to other devices at the same time), timeout (representing the timeout time of idle connection), security_level (representing the security level), etc. The current state of the edge device (such as the current configuration, hardware capability, performance load, etc.) is obtained and compared with the key information in the decryption policy file. It is checked whether the configuration value of the key information conflicts with the existing settings of the edge device. For example, the new configuration value requires the device to enable a hardware function that is not supported, or the configured resource limit exceeds the current carrying capacity of the device, at this time it can be determined that the detection result under the configuration conflict detection dimension is detection failure.

[0096] In this embodiment, the conflict of the configuration information of the decrypted policy file can also be detected based on a preset conflict detection condition. Optionally, the preset conflict detection condition can include, but is not limited to, at least one of the following: a resource conflict detection condition, such as that the max_connections configuration exceeds the maximum number of connections supported by the device; a compatibility conflict detection condition, such as that some security protocol configurations in the new policy are incompatible with the device hardware or the existing software version; and a logical conflict detection condition, such as that an unreasonable timeout parameter is set (the timeout is too short to cause frequent reconnection).

[0097] For example, it is assumed that the maximum number of connections supported by the device is max_supported_connections, and the maximum number of connections required in the decrypted policy file is max_connections. If max_connections exceeds the maximum number of connections supported by the device, a conflict exists.

[0098] The calculation formula of such conflict detection can be represented as:

[0099]

[0100] Wherein, max_connections represents the maximum number of connections in the decrypted policy file;

[0101] max_supported_connections represents the maximum number of connections currently supported by the end-side device; if

[0102] Conflict max_connections is 1, indicating a conflict; if Conflict max_connections is 0, indicating no conflict.

[0103] For another example, it is assumed that the minimum timeout time supported by the end-side device is min_timeout_limit, and if the timeout time timeout in the decrypted policy file is less than the minimum value, a conflict exists. The calculation formula of such conflict detection can be represented as:

[0104]

[0105] Wherein: timeout represents the timeout time in the decrypted policy file; min_timeout_limit represents the minimum timeout time allowed by the end-side device; if Conflict timeout is 1, indicating a conflict; if Conflict timeout is 0, indicating no conflict.

[0106] For example, if the minimum security level of the device is min_security_level, and the security level in the decryption policy file is lower than the minimum security level, there is a conflict. The calculation formula of this conflict detection can be expressed as:

[0107]

[0108] Where: security_level represents the security level in the decryption policy file; min_security_level represents the minimum security level supported by the edge device; if Conflict security_level is 1, it means conflict; if Conflict security_level is 0, it means no conflict.

[0109] It should be noted that if the conflicts of multiple configuration parameters in the decryption policy file affect the resources (such as memory, CPU) of the edge device, these conflicts can be weighted according to the degree of influence. For example, the conflict of max_connections may be more serious, while the conflict of timeout has less influence, and different weights can be assigned; according to the detection result of each conflict type, the final detection result under the configuration conflict detection dimension can be determined, and the calculation formula can be expressed as: Where: w i represents the weight of each conflict type; Conflict i represents the detection result (1 or 0) of each conflict type; Conflict Weighted represents the final detection result.

[0110] It should also be noted that the preset conflict detection condition can be adjusted according to the update of the edge device or the new hardware characteristics. Machine learning algorithms (such as support vector machines, decision trees, etc.) can be used to dynamically adjust the preset conflict detection condition to improve the accuracy and flexibility of conflict detection.

[0111] Using the above preset conflict detection condition, the decryption policy file can be detected for conflict under the configuration conflict detection dimension, which can ensure that the policy file can be fully checked for potential conflict problems before being applied in the edge device. By combining resource limitations, hardware compatibility and security requirements, potential configuration conflicts can be detected and fed back in real time, ensuring the normal operation and security of the device. It should be noted that a conflict detection engine can also be built to find the mutual dependence relationship in the decryption policy file and compare their values to detect conflicts and determine the detection result under the configuration conflict detection dimension.

[0112] In this embodiment, when the detection dimensions include the environmental adaptability verification dimension, the detection of the decryption policy file can be performed in the following manner: for different edge device models and firmware versions, it is checked whether the decryption policy file is compatible with the hardware and software environment of the current edge device. If compatible, it is determined that the detection result under the environmental adaptability verification dimension is that the detection is passed; otherwise, the detection result is that the detection is failed. For example, assuming that there are multiple versions of network configuration of the edge device, it is verified whether the network parameters in the decryption policy file support the network hardware interface of the current edge device, and if so, the detection is passed.

[0113] For example, it is assumed that the resource allocation of CPU and memory needs to satisfy a certain proportional relationship, that is, cpu limit + memory limit ≤ total resources ; in the formula: cpu limit represents the specified CPU resource allocation percentage; memory limit represents the specified memory resource allocation percentage; and total resources represents the total resources of the edge device. If the proportional relationship of cpu_limit (CPU limit) and memory_limit (memory limit) in the decryption policy file does not satisfy this inequality, it indicates that the content of the decryption policy file is incorrect, which will cause unreasonable resource allocation and further affect the device performance or security.

[0114] It should be noted that the detection result under at least one detection dimension can be recorded in the log and a verification report is generated for subsequent audit and analysis. For example, the log can include but is not limited to: whether the format verification is passed, if failed, the error position and type are recorded in detail; the content verification result, including specific legality detection, conflict detection, etc.; and the calculation formula used in the verification process and its result.

[0115] S320, in the case that the detection result under at least one detection dimension is passed, updating the policy file in the edge device based on the decryption policy file.

[0116] In this embodiment, when the detection result under all or part of the detection dimensions is passed, the decryption policy file can be updated to the edge device to replace the old policy file on the edge device and apply the new policy file.

[0117] The technical solution provided by the embodiment can ensure the correctness and integrity of the decrypted policy file content, so that the end-side device uses the policy file in actual operation in line with expectations, and ensures the stability of device operation.

[0118] Embodiment Four

[0119] Figure 4 is a flowchart of a policy updating method of an end-side device according to Embodiment Four of the present application. On the basis of the foregoing embodiments, before updating the policy file in the end-side device based on the decrypted policy file, a virtual running environment corresponding to the end-side device can also be constructed; the decrypted policy file is run in the virtual running environment to obtain monitoring data under a plurality of monitoring indexes, so that the policy file in the end-side device is updated based on the decrypted policy file when the monitoring data meets a preset running condition. The specific implementation can be referred to the technical solution of the present embodiment. Among them, the same or corresponding technical terms as the above embodiments will not be repeated here.

[0120] As shown in Figure 4 , the method specifically comprises the following steps:

[0121] S410, a virtual running environment corresponding to the end-side device is constructed.

[0122] In the present embodiment, a virtual running environment similar to the end-side device can be created using virtualization technology (such as VMware, Hyper-V, KVM) or container technology (such as Docker, Kubernetes); an isolated virtual environment or sandbox environment can also be created in the end-side device as the virtual running environment. This allows the decrypted policy file to be run in the virtual running environment, simulating the execution of the new policy while not interfering with the normal operation of the end-side device.

[0123] Specifically, the way to construct a virtual running environment corresponding to the end-side device can be to deploy a lightweight virtualization technology (such as container-based virtualization) in the end-side device. The container can simulate the configuration of device hardware and software, allowing the simulated policy to run on the "virtual device", and the container can be used as a sandbox environment. The resources (such as CPU, memory, disk I / O, network bandwidth, etc.) configured in the sandbox environment and the current workload of the device should match the resource status of the actual end-side device, so as to ensure that the virtual running environment and the real environment have sufficient similarity by monitoring the device state and performance in real time.

[0124] S420, running the decrypted policy file in a virtual running environment to obtain monitoring data under a plurality of monitoring indexes, so as to update the policy file in the edge device based on the decrypted policy file when the monitoring data meets a preset running condition.

[0125] The monitoring indexes include, but are not limited to, CPU usage, memory usage, network traffic, response time, error rate, etc. The preset running condition can be a condition for judging whether the expected running data of the decrypted policy file meets an expectation.

[0126] In this embodiment, the decrypted policy file can be deployed into the virtual running environment, loaded and executed in the virtual running environment, and simulated to run on the real edge device. The monitoring data of the decrypted policy file under a plurality of monitoring indexes can be determined according to the policy running data at runtime. Further, it can be judged whether the monitoring data under each monitoring index meets the preset running condition. If yes, the old policy file in the actual edge device can be replaced based on the decrypted policy file. If no, the decrypted policy file is not used.

[0127] Optionally, the monitoring indexes include at least system resource consumption indexes, response delay indexes, system stability indexes, security vulnerability indexes, etc. The monitoring data under the system resource consumption indexes are used to reflect the consumption of resources such as CPU, memory, disk and network of the device in the process of policy execution, such as whether there is excessive resource consumption, memory leakage or CPU load, etc. The monitoring data under the response delay indexes are used to reflect whether the response time (such as request response, data transmission delay) of the device after applying the policy is within a reasonable range. If the delay is too high, it means that the policy may cause a performance bottleneck. The monitoring data under the system stability indexes are used to reflect problems such as crash, abnormal restart or resource conflict in the simulation running of the policy, which can be analyzed through crash logs, error reports, etc. The monitoring data under the security vulnerability indexes can be detected by integrated security tools (such as vulnerability scanning tools) to detect whether new security vulnerabilities are generated.

[0128] For example, it is assumed that the CPU usage and memory occupancy of the device in the virtual running environment are U cpu and U mem The monitoring data under the two monitoring indexes of resource consumption rate and memory consumption rate can be calculated. The calculation formula of the monitoring data under the resource consumption rate can be represented as: wherein: U cpu represents the usage rate of the CPU in the simulation running process; U cpu0 represents the initial usage rate of the CPU of the device before applying the policy; and U cpumaxrepresents the maximum CPU load available to the device. The calculation formula of the monitoring data under the memory consumption rate can be represented as:

[0129] wherein: U mem represents the usage rate of the memory during the simulation process; U mem0 represents the initial usage rate of the memory of the device before the application of the strategy; U memmax represents the maximum memory available to the device.

[0130] If the resource consumption rate exceeds a certain threshold (for example, R cpu > 90% or R mem > 85%), it indicates that the new strategy may have a large burden on the device, and it can be considered that the monitoring data does not meet the preset running condition, and the applicability of the strategy can be re-evaluated.

[0131] In this embodiment, during the process of running the decryption strategy file in the virtual running environment, historical performance data and preset security specifications can also be combined to analyze the monitoring data in real time to determine whether the decryption strategy file meets the expected goal. For example, by comparing the simulation running results with the standard performance data of the end-side device, the influence of the decryption strategy file on the device performance can be evaluated. In combination with security vulnerability scanning, log analysis and other methods, the possibility of introducing new security risks by the decryption strategy file can be evaluated.

[0132] If problems are found during the simulation process (such as significant performance degradation, system instability, etc.), an automatic feedback mechanism is triggered, and the abnormal event is recorded. The state before the application of the strategy can be restored according to the preset “rollback strategy”.

[0133] As an optional implementation manner of this embodiment, each step and result in the entire strategy file updating process can be recorded, and the logs are audited regularly to analyze and handle potential security problems. The manner can be that during the entire updating process of the strategy file, log recording operations can be triggered at each key step (such as file transmission, signature verification, decryption process, etc.). The log not only records the timestamp, operation type, but also records detailed information (such as file size, version number, verification result, etc.) of the operation. Among them, the log types can include information logs, warning logs, error logs and security logs, etc. Each log in the log content should at least include an operation identifier, an operation type, an operation time, a device ID, a file name, a file size, version information, an operation result (success or failure), abnormal information, etc.

[0134] In this embodiment, a structured log format (such as JSON) can be used to facilitate automated analysis and archiving. The log is encrypted using file encryption technology to ensure the security of the log file content and prevent external tampering. A log rotation mechanism can be used on the device side to prevent the log file from becoming too large and occupying storage space. Automated auditing of the log can also be performed, such as setting a log auditing period (e.g., every hour, every day, etc.), automatically scanning all log files to identify abnormal or potentially risky operations, performing log analysis based on pre-defined security rules, such as checking whether the modification time of a certain policy file is abnormal, whether there are unauthorized decryption operations, etc., and triggering an early warning and recording relevant logs if access beyond the authority is detected in the log (such as unauthorized device access to the policy configuration file). Machine learning or rule-based anomaly detection algorithms can be used to classify and analyze log data, automatically identifying unusual operations. For example, if a certain edge device frequently updates policy files in a short period of time, this may be abnormal behavior. The log content can be matched in real time in combination with pre-defined security rules (such as "a certain device should not frequently download policy configuration files"). For example, if the log shows that "device ID edge_device_123 received 3 configuration file updates in 5 minutes", the system may trigger an alarm. By auditing the log, it is possible to trace back to historical operations and promptly identify potential security vulnerabilities. For example, if a device fails to decrypt multiple times, it may indicate a problem with key management or a key leak. In this case, the auditing system needs to trigger a security analysis and report to the administrator. If potential security problems are found in the device policy update process (e.g., malicious file tampering), the device can be rolled back to a safe state through automated policies, the current policy application is stopped, and a security warning is triggered. When a security risk is detected, the device management user can be notified through an event response system (such as automatically sending an email, SMS, or triggering an alarm), and detailed information about the potential security problem is provided so that the management user can take further preventive measures to ensure the security of the device and the stable operation of the system.

[0135] The technical solution of the embodiment can ensure that the decrypted policy file updated to the edge device can be correctly applied, thereby ensuring the accuracy of the policy update of the edge device.

[0136] Embodiment Five

[0137] Figure 5 is a structural schematic diagram of a policy updating device for an edge device according to Embodiment Five of the present application. As shown in Figure 5As shown, the device comprises a file encryption module 510, a signature array determination module 520, a verification result determination module 530, and a decryption module 540.

[0138] The file encryption module 510 is configured to, when receiving an added policy file corresponding to an edge device, encrypt the added policy file to obtain an encrypted policy file, and hash the encrypted policy file to obtain a first hash value. The signature array determination module 520 is configured to determine a signature array corresponding to the encrypted policy file based on the first hash value, a current signature time, a preset private key, and a preset elliptic curve parameter. The verification result determination module 530 is configured to, when the encrypted policy file meets a preset configuration condition, verify the signature array to obtain a verification result. The decryption module 540 is configured to, when the verification result is consistent with a preset result, decrypt the encrypted policy file to obtain a decrypted policy file, and update a policy file in the edge device based on the decrypted policy file.

[0139] The technical scheme of the embodiment is as follows: when receiving an added policy file corresponding to an edge device, the added policy file is encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value; a signature array corresponding to the encrypted policy file is determined based on the first hash value, a current signature time, a preset private key, and a preset elliptic curve parameter; when the encrypted policy file meets a preset configuration condition, the signature array is verified to obtain a verification result; when the verification result is consistent with a preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and a policy file in the edge device is updated based on the decrypted policy file. The problems of low security and poor accuracy of updating the operation policy of the edge device based on network transmission of the policy file in the prior art are solved. The added policy file corresponding to the edge device is first encrypted to obtain an encrypted policy file, and the encrypted policy file is hashed to obtain a first hash value. Then, the signature array corresponding to the encrypted policy file is determined based on the first hash value, a current signature time, a preset private key, and a preset elliptic curve parameter, so as to improve the encryption strength of the signature array. When the encrypted policy file meets a preset configuration condition, the signature array is verified to ensure the integrity of the policy file. When the verification result is consistent with a preset result, the encrypted policy file is decrypted, and the policy file in the edge device is updated based on the decrypted policy file, so as to improve the security and accuracy of updating the policy of the edge device, thereby ensuring the security and stability of the device operation.

[0140] On the basis of the above device, optionally, the file encryption module 510 comprises

[0141] The key determination unit is configured to generate an initialization vector and a random key based on a random number generation algorithm;

[0142] The byte data determination unit is configured to convert the new policy file to obtain byte data.

[0143] The encrypted policy file determination unit is configured to encrypt the byte data based on the initialization vector and the random key to obtain an encrypted policy file.

[0144] On the basis of the above device, the signature array determination module 520 comprises, optionally:

[0145] The random vector determination unit is configured to determine a random vector based on a message authentication code algorithm of a hash function according to the first hash value and a current signature time.

[0146] The first signature value determination unit is configured to determine a first signature value based on the random vector and a preset elliptic curve parameter.

[0147] The second signature value determination unit is configured to determine a second signature value based on a preset private key, the first signature value, the first hash value, the random vector and the preset elliptic curve parameter.

[0148] The signature array determination unit is configured to determine a signature array based on the first signature value and the second signature value.

[0149] On the basis of the above device, the first signature value determination unit comprises, optionally:

[0150] The elliptic curve coordinate determination unit is configured to determine an elliptic curve coordinate based on the random vector and a base point of a preset elliptic curve parameter.

[0151] The first signature value determination subunit is configured to determine a first signature value based on a coordinate value on a first coordinate axis in the elliptic curve coordinate and an order of the preset elliptic curve.

[0152] On the basis of the above device, the verification result determination module 530 comprises, optionally:

[0153] The second hash value determination unit is configured to perform hash processing on the encrypted policy file to obtain a second hash value if the first signature value and the second signature value in the signature array are within a preset range; wherein the preset range is determined based on an order of the preset elliptic curve parameter and a preset numerical value.

[0154] The first intermediate value determination unit is configured to determine a first intermediate value based on the preset elliptic curve parameter, the second hash value, a preset public key, the first signature value and the second signature value.

[0155] The check result determination unit is configured to determine the check result as a preset result when the first intermediate value is consistent with the second signature value, wherein the preset result is a check pass.

[0156] On the basis of the above device, optionally, the first intermediate value determination unit comprises:

[0157] The inverse element determination unit is configured to determine an inverse element based on an order of the preset elliptic curve parameter and the second signature value.

[0158] The second intermediate value determination unit is configured to determine a second intermediate value based on the inverse element, the second hash value and the order.

[0159] The third intermediate value determination unit is configured to determine a third intermediate value based on the inverse element, the first signature value and the order.

[0160] The first intermediate value determination sub-unit is configured to determine a first intermediate value based on the preset elliptic curve parameter, a preset public key, the second intermediate value and the third intermediate value.

[0161] On the basis of the above device, optionally, the first intermediate value determination sub-unit comprises:

[0162] The verification point coordinate determination unit is configured to determine a verification point coordinate based on a base point of the preset elliptic curve parameter, a preset public key, the second intermediate value and the third intermediate value.

[0163] The first intermediate value determination sub-unit is configured to determine a first intermediate value based on the verification point coordinate and the order of the preset elliptic curve parameter.

[0164] On the basis of the above device, optionally, the device further comprises:

[0165] The detection result determination unit is configured to detect the decryption strategy file based on a detection method of at least one detection dimension, so as to update a strategy file in the edge device based on the decryption strategy file in a case where a detection result in at least one detection dimension is a detection pass, wherein the detection dimension at least comprises a file header detection dimension, a field detection dimension, a nested structure detection dimension, a parameter compliance detection dimension, a dependency relationship detection dimension, a context detection dimension, a configuration conflict detection dimension and an environment adaptability verification dimension.

[0166] On the basis of the above device, optionally, the device further comprises:

[0167] The virtual running environment construction unit is configured to construct a virtual running environment corresponding to the edge device.

[0168] The monitoring data determination unit is configured to run the decryption policy file in the virtual running environment to obtain monitoring data under a plurality of monitoring indexes, and to update a policy file in the edge device based on the decryption policy file when the monitoring data meets preset running conditions.

[0169] The policy updating apparatus of the edge device provided in the embodiments of the present application can perform the policy updating method of the edge device provided in any of the embodiments of the present application, and has the function modules and beneficial effects corresponding to the execution method.

[0170] Embodiment six

[0171] Figure 6 is a structural schematic diagram of an electronic device implementing the policy updating method of the edge device in the embodiments of the present application. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections, and their functions, as well as their implementation, are merely examples and are not intended to limit the implementations of the present application described herein and / or claimed.

[0172] As shown in Figure 6 , the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11, wherein the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0173] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunications networks.

[0174] The processor 11 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the edge device policy update method.

[0175] In some embodiments, the edge device policy update method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded onto the RAM 13 and executed by the processor 11, one or more steps of the edge device policy update method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the edge device policy update method by any other suitable means, such as by means of firmware.

[0176] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0177] Computer programs used to implement the methods of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor of the machine, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.

[0178] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0179] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0180] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0181] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. Servers can be cloud servers, also known as cloud computing servers or cloud hosts, which are a host product in the cloud computing service system to solve the defects of great management difficulty and weak business scalability in traditional physical hosts and VPS services.

[0182] The embodiment of the present application further provides a computer program product comprising a computer program which, when executed by a processor, implements the policy updating method of the edge device as provided in any embodiment of the present application.

[0183] The computer program product can be written in one or more programming languages or combinations of languages including object-oriented languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0184] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present application. For example, the steps recited in the present application can be performed in parallel, in series, or in a different order, without departing from the desired results of the technical solutions of the present application, and this is not limited herein.

[0185] The specific embodiments described above are not intended to limit the scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modification, equivalent replacement, and improvement within the spirit and principles of the present application should be included in the scope of the present application.​​​​

Claims

1. A policy update method for an edge device, characterized in that: include: Upon receiving a new policy file corresponding to the edge device, encrypting the new policy file to obtain an encrypted policy file, and hashing the encrypted policy file to obtain a first hash value; Determining a signature array corresponding to the encryption policy file based on the first hash value, the current signing time, a preset private key, and preset elliptic curve parameters includes: A message authentication code algorithm based on a hash function determines a random vector according to the first hash value and the current signing time; Determine a first signature value based on the random vector and preset elliptic curve parameters; Determine a second signature value based on a preset private key, the first signature value, the first Hash value, the random vector, and the preset elliptic curve parameters; Determine a signature array based on the first signature value and the second signature value; When the encryption policy file meets the preset configuration conditions, the signature array is verified to obtain a verification result, including: If the first signature value and the second signature value in the signature array are within a preset range, hashing the encryption policy file to obtain a second hash value; wherein the preset range is determined based on the order and preset value of the preset elliptic curve parameter; Determining a first intermediate value based on the preset elliptic curve parameter, the second hash value, a preset public key, the first signature value, and the second signature value includes: Determining an inverse element based on the order of the preset elliptic curve parameter and the second signature value; determining a second intermediate value based on the inverse element, the second hash value, and the order; determining a third intermediate value based on the inverse element, the first signature value, and the order; Determining a first intermediate value based on the preset elliptic curve parameters, the preset public key, the second intermediate value, and the third intermediate value includes: Determining verification point coordinates based on a base point of the preset elliptic curve parameters, a preset public key, the second intermediate value, and the third intermediate value; Determining a first intermediate value based on the verification point coordinates and the order of the preset elliptic curve parameters; When the first intermediate value and the second signature value are consistent, determining that the verification result is a preset result; wherein the preset result is verification passed; When the verification result is consistent with the preset result, the encrypted policy file is decrypted to obtain a decrypted policy file, and the policy file in the edge device is updated based on the decrypted policy file.

2. The method according to claim 1, characterized in that The encrypting process of the newly added policy file to obtain the encrypted policy file includes: Generate an initialization vector and a random key based on a random number generation algorithm; Converting the newly added policy file to obtain byte data; The byte data is encrypted based on the initialization vector and the random key to obtain an encryption policy file.

3. The method according to claim 1, characterized in that The determining a first signature value based on the random vector and preset elliptic curve parameters includes: Determining elliptic curve coordinates based on the random vector and a base point of preset elliptic curve parameters; A first signature value is determined based on the coordinate value of the first coordinate axis in the elliptic curve coordinates and the order of the preset elliptic curve.

4. The method according to claim 1, wherein Before updating the policy file in the edge device based on the decryption policy file, the method further includes: Testing the decryption policy file based on a detection method of at least one detection dimension, and updating the policy file in the edge device based on the decryption policy file if the detection result under at least one detection dimension is a pass. Among them, the detection dimensions include at least file header detection dimension, field detection dimension, nested structure detection dimension, parameter compliance detection dimension, dependency detection dimension, context detection dimension, configuration conflict detection dimension and environment adaptability verification dimension.

5. The method according to claim 1, characterized in that Before updating the policy file in the edge device based on the decryption policy file, the method further includes: Constructing a virtual operating environment corresponding to the edge device; The decryption policy file is run in the virtual operating environment to obtain monitoring data under multiple monitoring indicators, so as to update the policy file in the edge device based on the decryption policy file when the monitoring data meets the preset operating conditions.

6. A policy update device for an edge device, characterized in that: include: A file encryption module is configured to, upon receiving a new policy file corresponding to the edge device, encrypt the new policy file to obtain an encrypted policy file, and perform a hash process on the encrypted policy file to obtain a first hash value; a signature array determination module, configured to determine a signature array corresponding to the encryption policy file based on the first hash value, the current signing time, a preset private key, and preset elliptic curve parameters; A verification result determination module, configured to verify the signature array and obtain a verification result when the encryption policy file meets a preset configuration condition; a decryption module, configured to decrypt the encrypted policy file to obtain a decrypted policy file if the verification result is consistent with a preset result, and update the policy file in the edge device based on the decrypted policy file; The signature array determination module includes: a random vector determining unit, configured to determine a random vector based on a message authentication code algorithm of a hash function according to the first hash value and a current signing time; A first signature value determining unit, configured to determine a first signature value based on the random vector and preset elliptic curve parameters; a second signature value determining unit, configured to determine a second signature value based on a preset private key, the first signature value, the first hash value, the random vector, and the preset elliptic curve parameters; a signature array determining unit, configured to determine a signature array based on the first signature value and the second signature value; The verification result determination module includes: a second hash value determining unit, configured to perform hash processing on the encryption policy file to obtain a second hash value if the first signature value and the second signature value in the signature array are within a preset range; wherein the preset range is determined based on the order and preset value of the preset elliptic curve parameter; a first intermediate value determining unit, configured to determine a first intermediate value based on the preset elliptic curve parameter, the second hash value, a preset public key, the first signature value, and the second signature value; a verification result determining unit, configured to determine, when the first intermediate value and the second signature value are consistent, that the verification result is a preset result; wherein the preset result is verification passed; The first intermediate value determining unit includes: an inverse element determining unit, configured to determine an inverse element based on the order of the preset elliptic curve parameter and the second signature value; a second intermediate value determining unit, configured to determine a second intermediate value based on the inverse element, the second Hash value, and the order; a third intermediate value determining unit, configured to determine a third intermediate value based on the inverse element, the first signature value, and the order; a first intermediate value determining subunit, configured to determine a first intermediate value based on the preset elliptic curve parameters, the preset public key, the second intermediate value, and the third intermediate value; The first intermediate value determining subunit includes: a verification point coordinate determining unit, configured to determine the verification point coordinates based on a base point of the preset elliptic curve parameters, a preset public key, the second intermediate value, and the third intermediate value; The first intermediate value determination subunit is used to determine the first intermediate value based on the verification point coordinates and the order of the preset elliptic curve parameters.

Citation Information

Patent Citations

  • Voting-based CONSENSUS METHOD

    CN109964446A

  • Random number encryption method and device based on multiple sensors

    CN111259419A