Device access method and apparatus for power system, and electronic device
By authenticating based on device information and signature information when cross-regional power equipment is connected, and issuing temporary and target certificates, the security risks caused by different access methods for cross-regional power equipment are resolved, achieving secure and flexible access for equipment and consistency of the system.
Patent Information
- Application Number
- CN202411872365.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2044-12-18
AI Technical Summary
Different access methods for cross-regional power equipment lead to increased communication complexity and security risks, making it impossible to guarantee equipment security.
Upon receiving a device access request, the system determines the authentication result based on device information and signature information, issues temporary certificates to devices without security certificates, generates target certificates, controls the device access process, and ensures the security and consistency of devices.
It enables safe and flexible access for cross-regional power equipment, reduces access risks, and ensures the safety and consistency of the power system.
Smart Images

Figure CN119788353B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular to a device access method and device for a power system and an electronic device. BACKGROUND
[0002] With the development of power systems and informatization and intelligentization, the demand for cross-regional access and cross-regional cooperation of power devices has gradually emerged.
[0003] At present, due to the different device information of power devices that need to be accessed cross-regionally, the access methods when accessing the corresponding regional power system are also different, resulting in an increase in the complexity and risk of cross-regional communication. Moreover, when accessing cross-regional power devices, the device security of the power device cannot be guaranteed, resulting in a security risk of the power system after accessing the power device. SUMMARY
[0004] The present application provides a device access method and device for a power system and an electronic device, which realizes the access of a to-be-accessed power device to a cross-regional power system in the case where there is a security certificate or a target certificate of the to-be-accessed power device, and guarantees the consistency, flexibility and security of the access of the to-be-accessed power device.
[0005] According to an aspect of the present application, a device access method for a power system is provided, which is applied to access a power device in a first region to a power system corresponding to a second region, the power systems used by the first region and the second region are different, and the method comprises the following steps:
[0006] In the case where a device access request is received and no security certificate is included in the device access request, an authentication result of the to-be-accessed power device is determined based on the device information in the device access request and the signature information corresponding to the to-be-accessed power device; wherein the to-be-accessed power device is a power device in the first region;
[0007] In the case where the authentication result is consistent with a preset result, a temporary certificate is issued for the to-be-accessed power device, so as to control the access of the to-be-accessed power device based on the temporary certificate;
[0008] In the case where the access of the to-be-accessed power device is detected, system access parameters are configured for the to-be-accessed power device, so as to generate a target certificate corresponding to the to-be-accessed power device based on the system access parameters and the temporary certificate.
[0009] According to another aspect of the present application, a device access device for a power system is provided, which is applied to access a power device in a first region to a power system corresponding to a second region, the power systems used by the first region and the second region are different, and the device comprises the following steps:
[0010] The authentication result determination module is configured to, in a case where the device access request is received and the security certificate is not included in the device access request, determine an authentication result of the power device to be accessed based on device information in the device access request and signature information corresponding to the power device to be accessed, wherein the power device to be accessed is a power device in the first region.
[0011] The temporary certificate issuing module is configured to, in a case where the authentication result is consistent with the preset result, issue a temporary certificate for the power device to be accessed, so as to control the power device to be accessed to access based on the temporary certificate.
[0012] The target certificate generation module is configured to, in a case where it is detected that the power device to be accessed accesses, configure system access parameters for the power device to be accessed, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate.
[0013] According to another aspect of the present application, an electronic device is provided, which comprises:
[0014] at least one processor; and
[0015] a memory connected with the at least one processor in communication; wherein
[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the device access method of the application power system according to any one of the embodiments of the present application.
[0017] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to execute the device access method of the application power system according to any one of the embodiments of the present application when the processor executes the computer instructions.
[0018] According to another aspect of the present application, a computer program product is provided, which comprises a computer program, and the computer program, when executed by a processor, implements the device access method of the application power system according to any one of the embodiments of the present application.
[0019] The technical scheme of the embodiment of the present application comprises the following steps: when a device access request is received, and the device access request does not comprise a security certificate, determining an authentication result of a to-be-accessed power device according to device information in the device access request and signature information of the to-be-accessed power device, thereby ensuring the security of the to-be-accessed power device. When the authentication result is consistent with a preset result, issuing a temporary certificate for the to-be-accessed power device, thereby controlling the access process of the to-be-accessed power device based on the temporary certificate, and reducing the security risk when the power device is accessed. When the to-be-accessed power device is detected to be accessed, configuring system access parameters for the to-be-accessed power device, thereby generating a target certificate corresponding to the to-be-accessed power device based on the system access parameters and the temporary certificate, and controlling the access permission of the to-be-accessed power device through the target certificate, thereby ensuring the security of the power system after the power device is accessed. The present application solves the problems in the prior art that the access modes are different due to different device information, and the security of the power system after the power device is accessed cannot be ensured. The present application unifies the access modes of the to-be-accessed power devices across regions, and through the device authentication, the temporary certificate and the target certificate issuing process for the to-be-accessed power device without a security certificate, the to-be-accessed power device with a security certificate or a target certificate can access the power system across regions, thereby ensuring the consistency, flexibility and security of the to-be-accessed power device access.
[0020] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0022] Figure 1 is a flowchart of a device access method for an application power system provided by an embodiment of the present application;
[0023] Figure 2 is a flowchart of a device access method for an application power system provided by an embodiment of the present application;
[0024] Figure 3 is a structural schematic diagram of a device access apparatus for an application power system provided by an embodiment of the present application;
[0025] Figure 4 is a structural schematic diagram of an electronic device for implementing the device access method for an application power system of the embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to make the personnel in the technical field better understand the present application scheme, the technical scheme in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the scope of protection of the present application.
[0027] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] Embodiment one
[0029] Figure 1 is a flowchart of a device access method of an application power system provided by the first embodiment of the present application. The present embodiment can be applied to device authentication, temporary certificate and target certificate issuing for the power device to be accessed without a security certificate, so that the power device to be accessed with a security certificate or a target certificate can access the cross-regional power system. The method can be executed by a device access apparatus of an application power system, which can be realized in the form of hardware and / or software, and can be configured in an electronic device such as a mobile phone, a computer or a server. As shown in the figure, the method comprises: Figure 1
[0030] S110, in the case that the device access request is received and the security certificate is not included in the device access request, determining the authentication result of the power device to be accessed based on the device information in the device access request and the signature information corresponding to the power device to be accessed; wherein the power device to be accessed is a power device in a first region.
[0031] Embodiments of the present application are applied to a scenario of connecting a power device in a first region to a power system corresponding to a second region, so as to realize communication between power devices across regions. The power system used by the first region and the second region is different. When a power device in the first region is to be connected to the power system of the second region, the power device in the first region can be regarded as a to-be-connected power device. An access request sent by the to-be-connected power device to the power system of the second region is a device access request.
[0032] To ensure the security of the to-be-connected power device and the power system of the second region, it can be detected whether the device access request carries a security certificate or whether the security certificate of the current to-be-connected power device is stored in the power system of the second region. The security certificate is used to represent the security of the to-be-connected power device and the right to access the power system of the second region. Only the to-be-connected power device carrying the security certificate can access the power system of the second region and perform cross-region communication with the power devices in the power system of the second region. Through the security certificate, malicious power devices or power devices not trusted by the power system of the second region can be effectively isolated.
[0033] The device information can include the device type and device hardware information of the to-be-connected power device. The signature information can be a digital signature determined according to the device information of the to-be-connected power device before the to-be-connected power device sends the device access request. The signature information can be used to authenticate the device identity of the to-be-connected power device. Optionally, the signature information can be obtained by encrypting a hash value corresponding to the device information of the to-be-connected power device before the to-be-connected power device sends the device access request.
[0034] The authentication result is used to represent the device identity of the to-be-connected power device. In the case where the hash value corresponding to the device information of the device access request is consistent with the hash value after decryption of the signature information, the authentication result is that the authentication is passed, and the to-be-connected power device can access the power system of the second region. Correspondingly, in the case where the hash value corresponding to the device information of the device access request is not consistent with the hash value after decryption of the signature information, the authentication result is that the authentication is not passed, and the to-be-connected power device cannot access the power system of the second region.
[0035] Specifically, when receiving a device access request sent by a to-be-accessed power device in a first region to a power system in a second region, it is detected whether a security certificate is carried in the device access request. If the security certificate is not carried in the device access request, a hash value corresponding to the device information of the to-be-accessed power device is determined according to the device information in the device access request. The signature information carried in the device access request is parsed to obtain a standard hash value corresponding to the to-be-accessed power device. When the standard hash value is consistent with the hash value corresponding to the device information, the authentication result of the to-be-accessed power device is that the authentication is passed, that is, the to-be-accessed power device can access the power system in the second region.
[0036] It should be noted that the encryption algorithm applied to the device access request sent by the power device in the first region when accessing the power system in the second region can be preset. Based on this, the power system in the second region can parse the device access request according to the corresponding encryption algorithm when receiving the device access request, so as to quickly realize the device authentication of the to-be-accessed power device. The above device authentication process supports the authentication protocol, the public key infrastructure certificate system, the zero trust architecture and the lightweight cryptography protocol.
[0037] For example, when the to-be-accessed power device in the first region accesses the power system in the second region, the to-be-accessed power device can be authenticated by the RSA asymmetric encryption algorithm or the ECC asymmetric encryption algorithm. The RSA asymmetric encryption algorithm is a public key encryption algorithm, which is used for device identity verification and digital signature. Specifically, before the to-be-accessed power device sends the device access request, the device information to be sent can be encrypted by a public key encryption function according to the RSA asymmetric encryption algorithm. That is, C=M e modn, wherein M is the device information of the plaintext, e is the public key exponent, n is the modulus, and C is the encrypted device information. A digital signature corresponding to the hash value of the device information is generated by a data signature generation function. That is, S=H(M) d modn, wherein S is the signature information of the to-be-accessed power device, M is the device information of the plaintext, H(M) is the hash value of the device information, d is the private key exponent, and n is the modulus. The device access request is generated based on the signature information S and the encrypted device information C, and is sent to the power system in the second region.
[0038] After the power system in the second region receives the device access request, the encrypted device information C in the device access request is decrypted by a private key decryption function in the corresponding RSA asymmetric encryption algorithm. That is, M'=C dmodn, wherein M' is the decrypted device information, C is the encrypted device information in the device access request, d is the private key index, and n is the modulus. The decrypted device information M' is hashed to obtain a hash value H(M') corresponding to the decrypted device information. The signature information S in the device access request is parsed by a digital signature verification function to obtain a hash value H(M) corresponding to the signature information. That is, H(M) = S e modn, wherein H(M) is the hash value corresponding to the signature information, S is the signature information in the device access request, e is the public key index, and n is the modulus.
[0039] The authentication result of the power device to be accessed is determined by comparing the hash value H(M) corresponding to the signature information with the hash value H(M') of the device information in the received device access request. When H(M) is consistent with H(M'), the authentication result of the power device to be accessed is passed.
[0040] For example, the ECC asymmetric encryption algorithm can be used for device authentication of the power device to be accessed. That is, the message authentication code combined with the hash function and the key is used for device authentication of the power device to be accessed. Before sending the device access request, the message authentication code corresponding to the device information of the power device to be accessed can be determined by a hash-based message authentication code generation function. That is,
[0041]
[0042] wherein HMAC(K, M) is the message authentication code, K is the key, M is the device information, opad is the outer padding constant, ipad is the inner padding constant, and H is the hash function.
[0043] When the power system in the second region receives the device access request, the corresponding to-be-verified message authentication code is generated according to the device information in the device access request. When the to-be-verified message authentication code is consistent with the message authentication code carried by the device access request, the authentication result of the power device to be accessed is passed.
[0044] In the embodiment of the present application, the determination method of the authentication result of the power device to be accessed can be: after the signature information is decrypted, a first hash value corresponding to the power device to be accessed is obtained; after the device information in the device access request is hashed, a second hash value of the power device to be accessed is obtained; when the first hash value and the second hash value are the same, it is determined that the authentication result of the power device to be accessed is passed.
[0045] The first hash value can be a standard hash value corresponding to the device information of the power device to be accessed. The second hash value can be a hash value corresponding to the received device information.
[0046] Specifically, the signature information carried in the device access request is decrypted to obtain a first hash value corresponding to the to-be-accessed power device. The device information in the to-be-accessed request is hashed to obtain a second hash value of the to-be-accessed power device. The authentication result of the to-be-accessed power device is obtained by comparing the first hash value and the second hash value. When the first hash value is the same as the second hash value, it is determined that the authentication result of the to-be-accessed power device is passed, and then the to-be-accessed power device can access the power system in the second area. Correspondingly, when the first hash value is different from the second hash value, it is determined that the authentication result is not passed, and then the to-be-accessed power device cannot access the power system in the second area. Based on this, the device authentication of the to-be-accessed power device is realized, the power device that does not pass the authentication is prevented from accessing, and the malicious or untrusted power device is effectively isolated. Through the above automatic authentication of the to-be-accessed power device, the management process during large-scale power device access can be simplified, and the access efficiency is improved.
[0047] For example, in combination with the above example, the first hash value is H(M) in the above example, and the second hash value is H(M') in the above example. When H(M) is the same as H(M'), the authentication result of the to-be-accessed power device is passed.
[0048] Optionally, in the case that the security certificate is included in the device access request, or in the case that it is detected that the target certificate corresponding to the to-be-accessed power device has been generated, the target key is issued to the to-be-accessed power device, so that the to-be-accessed power device encrypts the data sent to the power system based on the target key; and when the data access request or the data upload request sent by the to-be-accessed power device is received, the feedback data corresponding to the request is encrypted based on the symmetric key corresponding to the target key and is fed back.
[0049] The target certificate can be a security certificate obtained after the temporary certificate issued to the to-be-accessed power device is activated after the to-be-accessed power device passes the authentication. The temporary certificate can be a certificate issued when the authentication result of the to-be-accessed power device is passed. If the to-be-accessed power device is not a device that accesses the power system in the second area for the first time, the target certificate of the to-be-accessed power device can exist in the power system in the second area. Based on this, repeated authentication and repeated issuance of certificates of the to-be-accessed power device can be avoided, and the access efficiency of the to-be-accessed power device can be improved.
[0050] The target key and the symmetric key can be determined by a preset encryption algorithm, and are used for data encryption communication between the to-be-accessed power device and the second regional power system. The preset encryption algorithm can be an algorithm used for data encryption communication between the to-be-accessed power device and the second regional power system. The target key can be stored in the to-be-accessed power device, so that the to-be-accessed power device encrypts data transmitted to the second regional power system by using the target key. The symmetric key can be stored in the second regional power system, so that the second regional power system encrypts data transmitted to the to-be-accessed power device according to the symmetric key.
[0051] The data access request is a request issued by the to-be-accessed power device, and is used for obtaining service processing data in the second regional power system. When the request is the data access request, the feedback data corresponding to the request can be service processing data of the second regional power system corresponding to the data access request. The data upload request can be a request issued by the to-be-accessed power device, and is used for uploading service processing data of the to-be-accessed power device to the second regional power system. When the request is the data upload request, the feedback data corresponding to the request can be feedback information of the second regional power system fed back to the to-be-accessed power device, and the feedback information is received service processing data of the to-be-accessed power device.
[0052] Specifically, when the second regional power system receives the device access request of the to-be-accessed power device, if it is detected that the device access request includes a security certificate, or the second regional power system generates a target certificate corresponding to the to-be-accessed power device, the target key is issued to the to-be-accessed power device according to the preset encryption algorithm. At the same time, the second regional power system saves the symmetric key corresponding to the target key. Based on this, the to-be-accessed power device can encrypt the data sent to the second regional power system according to the target key when sending data to the second regional power system. In addition, when the second regional power system receives the data access request or the data upload request sent by the to-be-accessed power device, the feedback data of the corresponding request is encrypted according to the symmetric key corresponding to the target key, and the encrypted feedback data is transmitted to the to-be-accessed power device.
[0053] S120, when the authentication result is consistent with the preset result, issuing a temporary certificate to the to-be-accessed power device, so as to control the to-be-accessed power device to access based on the temporary certificate.
[0054] The preset result can be a result of passing the authentication of the to-be-accessed power device. The temporary certificate is used to provide a temporary identity and a temporary permission for the to-be-accessed power device to access the second regional power system. Through the temporary certificate, the to-be-accessed power device can access the second regional power system within a certain time range, and perform cross-regional encryption communication with the second regional power system. Optionally, the temporary certificate can include device information of the to-be-accessed power device, time range of temporary access and the like.
[0055] Specifically, when the authentication result is consistent with the preset result, it indicates that the to-be-accessed power device meets the requirements for accessing the second regional power system, and a temporary certificate can be issued to the to-be-accessed power device, so that the to-be-accessed power device can perform cross-regional encrypted communication with the second regional power system within a certain temporary access time range. Through the temporary certificate, the second regional power system can effectively control and manage the to-be-accessed power device. For example, the second regional power system can monitor the running state of the to-be-accessed power device to ensure that it will not adversely affect the entire power system; at the same time, the second regional power system can also automatically disconnect the to-be-accessed power device from the power system after the temporary certificate expires according to the access validity period of the temporary certificate, to ensure the long-term safety of the power system.
[0056] S130, when detecting that the to-be-accessed power device is accessed, configuring system access parameters for the to-be-accessed power device, to generate a target certificate corresponding to the to-be-accessed power device based on the system access parameters and the temporary certificate.
[0057] The system access parameters can include permission information of the to-be-accessed power device for accessing the second regional power system. For example, the to-be-accessed power device can obtain which type of business processing data in the second regional power system, or which power device corresponding to the business processing data. The target certificate can be a security certificate obtained after the temporary certificate is activated. Generally, the access validity period corresponding to the target certificate is longer than the access validity period of the temporary certificate. The access validity period can be the effective time length for accessing the second regional power system. Optionally, the target certificate can also specify the business data type and power device of the second regional power system that the to-be-accessed power device can access.
[0058] Specifically, when detecting that the to-be-accessed power device accesses the second regional power system, system access parameters are configured for the to-be-accessed power device. Based on this, the temporary certificate can be activated as a target certificate according to the system access parameters before the access validity period corresponding to the temporary certificate of the to-be-accessed power device expires.
[0059] Optionally, according to the region to which the to-be-accessed power device belongs, the target certificate is stored in a database corresponding to the region; the usable period information corresponding to the target certificate is recorded, and the usable period information, the target certificate, and the device information of the to-be-accessed power device are stored in association.
[0060] The usable period information can be understood as the access validity period of the to-be-accessed power device for accessing the second regional power system. For example, the usable period information is one year, and from the issuance of the target certificate, the to-be-accessed power device can access the second regional power system and perform cross-regional encrypted communication with the second regional power system within the next one year. And after one year, the target certificate expires.
[0061] Specifically, when cross-region communication, there can be one or more to be accessed power equipment needs to be accessed to the power system of the second region cross-region encryption communication. Then according to the processing mode of the above S110 to S130, the target certificate corresponding to the to be accessed power equipment is generated respectively. And according to the region to which each to be accessed power equipment belongs, the target certificate is stored in the database corresponding to the region. In order to realize the encryption communication between the to be accessed power equipment of multiple regions and the power system, the use period information corresponding to each target certificate can be recorded, and the use period information, target certificate and device information of the to be accessed power equipment corresponding to multiple to be accessed power equipment are stored in the database of the power system of the second region. Based on this, the cross-domain certificate mutual trust mechanism is realized, which can enable the to be accessed power equipment of multiple regions to perform cross-domain encryption communication with the power system of the second region, and enhance the flexibility of data communication.
[0062] Optionally, the use period information, target certificate and device information of the to be accessed power equipment corresponding to multiple to be accessed power equipment can be associated and processed to establish a multi-level certificate trust chain. And through the distributed PKI (Public Key Infrastructure) model, large-scale to be accessed power equipment of different regions and different device types are managed, and the efficiency and security of power equipment management are improved. By updating the use period information of the to be accessed power equipment of different regions in real time, the validity of the target certificate of the to be accessed power equipment is guaranteed. It should be noted that when it is detected that the use period information of the target certificate of the to be accessed power equipment has expired, the target certificate of the to be accessed power equipment is revoked and the target certificate is generated again according to the above process. The distributed PKI model also supports the updating and conversion of the target certificate. By establishing a multi-level certificate trust chain, the problem of forging or tampering with the security certificate is avoided, so that the power equipment and the power system of different regions can authenticate and communicate with each other, and support cross-region, cross-platform device management and data exchange.
[0063] The technical scheme of the embodiment guarantees the security of the to-be-accessed power device by determining the authentication result of the to-be-accessed power device according to the device information in the device access request and the signature information of the to-be-accessed power device when the device access request is received and the security certificate is not included in the device access request. When the authentication result is consistent with the preset result, the temporary certificate is issued to the to-be-accessed power device, so that the access process of the to-be-accessed power device is controlled based on the temporary certificate, thereby reducing the security risk when the power device is accessed. When the to-be-accessed power device is detected to be accessed, the system access parameter is configured for the to-be-accessed power device, so that the target certificate corresponding to the to-be-accessed power device is generated based on the system access parameter and the temporary certificate, thereby controlling the access permission of the to-be-accessed power device through the target certificate, and guaranteeing the security of the power system after the power device is accessed. The application solves the problems in the prior art that the access modes are different due to different device information, and the security of the power system after the power device is accessed cannot be guaranteed. The application unifies the access mode of the to-be-accessed power device across regions, and through device authentication, temporary certificate and target certificate issuing for the to-be-accessed power device without a security certificate, the to-be-accessed power device with a security certificate or a target certificate can access the power system across regions, thereby guaranteeing the consistency, flexibility and security of the to-be-accessed power device access.
[0064] Embodiment two
[0065] Figure 2 is a flowchart of a device access method of an application power system provided by the embodiment two of the application. The embodiment is a refinement of the step of "configuring a system access parameter for the to-be-accessed power device, and generating a target certificate corresponding to the to-be-accessed power device based on the system access parameter" based on the above-mentioned embodiment. The specific implementation can be referred to the technical scheme of the embodiment. The same or corresponding technical terms as the above-mentioned embodiment are not described here. As shown in the figure, the method comprises: Figure 2
[0066] S210, when the device access request is received and the security certificate is not included in the device access request, determining the authentication result of the to-be-accessed power device based on the device information in the device access request and the signature information corresponding to the to-be-accessed power device; wherein the to-be-accessed power device is a power device in a first region.
[0067] S220, when the authentication result is consistent with the preset result, issuing a temporary certificate to the to-be-accessed power device, so as to control the access of the to-be-accessed power device based on the temporary certificate.
[0068] S230, in response to detecting that the to-be-accessed power device is accessing, configuring a system access parameter for the to-be-accessed power device according to a device type of the to-be-accessed power device and data collection authority corresponding to the to-be-accessed power device in the first region, wherein the system access parameter comprises authority information for accessing the power system.
[0069] The device type can be understood as the device type of the to-be-accessed power device. The data collection authority can be understood as the business processing authority that the to-be-accessed power device can collect in the first region to which the to-be-accessed power device belongs. The system access parameter comprises the authority information for accessing the power system in the second region. The authority information can comprise which business processing data of which power device in the second region power system the to-be-accessed power device can access, or which type of business processing data the to-be-accessed power device can access.
[0070] Specifically, in response to detecting that the to-be-accessed power device is accessing, the data type of the business processing data that the to-be-accessed power device can collect can be determined according to the device type of the to-be-accessed power device and the data collection authority corresponding to the to-be-accessed power device in the first region. Correspondingly, the data type when the to-be-accessed power device communicates data with the power system in the second region is also determined. According to the data type, the authority information for the to-be-accessed power device to access the power system in the second region, i.e., the system access parameter, can be configured.
[0071] S240, determining an activation code corresponding to the to-be-accessed power device based on the device type, the system access parameter, and an application range of the to-be-accessed power device.
[0072] The application range of the to-be-accessed power device can be used to represent the power device of the power system in the second region that the to-be-accessed power device can access. Through the application range, it can be determined that the to-be-accessed power device can communicate with which power device in the power system in the second region. The activation code can be a code for converting a temporary certificate into a target certificate.
[0073] Specifically, the activation code corresponding to the to-be-accessed power device is determined according to the device type of the to-be-accessed power device, the system access parameter, and the application range of the to-be-accessed power device.
[0074] Exemplarily, the system access parameter is taken as an authorized parameter of the to-be-accessed power device, and the coverage applied by the to-be-accessed power device is taken as an example for description of a use scenario of the to-be-accessed power device. According to the device type of the to-be-accessed power device, the authorized parameter, and the use scenario, a unique activation code is generated by encryption by the activation code management system, and the activation code is verified to prevent the activation code from being tampered with or forged. Based on this, the temporary certificate of the to-be-accessed power device can be converted into a target certificate through the activation code. It should be noted that the activation code management system can support large-scale temporary certificate activation processing of the to-be-accessed power device, and can efficiently and securely ensure the normal generation of the activation code and effectively prevent malicious attacks.
[0075] S250, converting the temporary certificate into a target certificate based on the activation code.
[0076] It should be noted that the target certificate can be understood as a formal security certificate corresponding to the to-be-accessed power device.
[0077] Specifically, according to the activation code corresponding to the to-be-accessed power device, the temporary certificate of the to-be-accessed power device is converted into a target certificate to control cross-domain encrypted communication between the to-be-accessed power device and the second regional power system through the target certificate.
[0078] Optionally, when it is detected that the system access parameter of the to-be-accessed power device changes, the target certificate corresponding to the to-be-accessed power device is regenerated, and the currently used target certificate is updated.
[0079] Specifically, in actual application, the system access parameter configured by the to-be-accessed power device can change. When it is detected that the system access parameter of the to-be-accessed power device changes, the changed system access parameter is obtained. According to the device type of the to-be-accessed power device, the changed system access parameter, and the coverage applied by the to-be-accessed power device, the target certificate corresponding to the to-be-accessed power device is updated to control cross-domain communication processing between the to-be-accessed power device and the second regional power system based on the updated target certificate.
[0080] Optionally, the historical interaction behavior and the historical power device of the second regional power system accessed by the to-be-accessed power device can be dynamically evaluated through a zero trust model, the system access parameter of the to-be-accessed power device is adjusted, and the target certificate is updated based on the adjusted system access parameter. Based on this, the defense capability of the power system against internal threats can be enhanced, and the overall security can be improved.
[0081] Optionally, the to-be-accessed power device can also be an edge device, and the second regional power system can also be a cloud system. Through the processing mode of S210 to S260, the cloud system can implement device authentication of the edge device, and the cloud system can issue, update, and revoke the target certificate for the edge device, thereby ensuring the data integrity, security, and confidentiality of cloud-edge communication.
[0082] Specifically, with the deep integration of edge computing and cloud computing, the cloud system and the edge device can only exchange data and cooperate in services after establishing a mutual trust relationship. Therefore, the target certificate can be issued to the edge device according to the processing mode of S210 to S260 to establish a mutual trust relationship between the edge device and the cloud system. It should be noted that under the framework of cloud-edge mutual trust, data exchange can be encrypted and verified, thereby effectively preventing data leakage and tampering. The centralized certificate management platform manages the distribution, update, revocation, and other operations of the target certificate of the edge device, thereby improving the management efficiency and flexibility.
[0083] Optionally, after issuing the target certificate to the to-be-accessed power device, a communication encryption parameter is established with the to-be-accessed power device to encrypt data transmission between the to-be-accessed power device and the power system based on the communication encryption parameter.
[0084] The communication encryption parameter can include a key for encrypted communication between the to-be-accessed power device and the power system, an access control parameter, a security management parameter, and the like.
[0085] Specifically, after issuing the target certificate to the to-be-accessed power device, a communication encryption parameter for cross-domain encrypted communication between the second regional power system and the to-be-accessed power device can be established, so that the second regional power system and the to-be-accessed power device perform data transmission through the communication encryption parameter.
[0086] Exemplary, the communication encryption parameters are taken as examples of access control parameters and security management parameters in the communication process. After issuing the target certificate to the to-be-accessed power device, the access control rule between the to-be-accessed power device and the second regional power system can be set according to the access control parameter in the communication encryption parameter. The security strategy of the communication between the to-be-accessed power device and the second regional power system is configured through the security management parameter. And the data transmission layer security protection mechanism is established. Based on the above, in the case that the target certificate corresponding to the to-be-accessed power device is detected, the target key is issued to the to-be-accessed power device according to the preset encryption algorithm, so that the to-be-accessed power device encrypts the data sent to the power system based on the target key, and transmits the encrypted data to the second regional power system through the access control rule and the security strategy. After receiving the encrypted data, the second regional power system decrypts the encrypted data according to the decryption key in the preset encryption algorithm, and stores the decrypted data in the corresponding position of the power system. Through the above process, it can be ensured that the data is not stolen, tampered or forged in the cross-regional transmission process, supports the cross-regional transmission between the power devices and the power system in different regions, effectively resists external attacks such as man-in-the-middle attack, replay attack, etc., enhances the overall security of data exchange, promotes data sharing and cooperation, and improves the work efficiency of the whole power system.
[0087] Optionally, in the cross-domain encryption communication process between the to-be-accessed power device and the second regional power system, the cross-domain trust evaluation of the above cross-domain communication process can be performed through the secure multi-party computation technology, so as to encrypt and protect the privacy of the communication process according to the evaluation result. By using the block chain technology, the device authentication of the to-be-accessed power device and the process of data communication with the power system are recorded in a decentralized manner, improving the transparency and traceability of data communication. Among them, the secure multi-party computation technology is used to protect the device information and authentication result of the to-be-accessed power device in the cross-domain trust evaluation process, so as to ensure that the data exchange between the to-be-accessed power devices in multiple regions and the cross-domain power system does not leak sensitive information.
[0088] Optionally, when detecting the interaction with the to-be-accessed power device, the generated interaction data is recorded.
[0089] Among them, the interaction data can be the device authentication between the second regional power system and the to-be-accessed power device, and the corresponding data in the cross-domain data interaction process.
[0090] Specifically, when detecting that there is data interaction between the second regional power system and the to-be-accessed power device, such as device authentication of the to-be-accessed power device, issuing a temporary certificate and a target certificate for the to-be-accessed power device, and cross-domain data encryption communication with the to-be-accessed power device, the corresponding interaction data can be recorded and a log can be generated to facilitate subsequent data tracing. Abnormal interaction behaviors can also be detected through the log to discover and respond to potential security issues, such as unauthorized access, certificate abuse, and the like, in a timely manner, thereby ensuring the security of the interaction process. Through the recording and auditing of all interaction operations, the transparency of data interaction is enhanced, and data tampering and operation concealment are avoided. The management of the log needs to comply with the security compliance requirements of various regulations such as ISO 27001, GDPR, and the like, thereby improving the compliance and reliability of data interaction.
[0091] The technical scheme of the embodiment, by receiving the device access request, and the device access request does not include the security certificate, according to the device information in the device access request and the signature information of the to-be-accessed power device, determine the authentication result of the to-be-accessed power device, ensure the security of the to-be-accessed power device. When the authentication result is consistent with the preset result, a temporary certificate is issued for the to-be-accessed power device to control the access process of the to-be-accessed power device based on the temporary certificate, thereby reducing the security risk when the power device accesses. When detecting that the to-be-accessed power device accesses, according to the device type of the to-be-accessed power device and the data collection authority corresponding to the to-be-accessed power device in the first region, configure system access parameters for the to-be-accessed power device. Based on the device type, the system access parameters and the coverage range applied by the to-be-accessed power device, determine the activation code corresponding to the to-be-accessed power device. The temporary certificate is converted into a target certificate based on the activation code to control the access authority of the to-be-accessed power device through the target certificate, thereby ensuring the security of the power system after accessing the power device. The present application solves the problem that the access mode is different due to different device information in the prior art, and cannot guarantee the security of the power system after accessing the power device. The present application unifies the access mode of the to-be-accessed power device across regions, and performs device authentication, temporary certificate and target certificate issuance for the to-be-accessed power device without security certificate, so that the to-be-accessed power device with security certificate or target certificate can access the power system across regions, thereby ensuring the consistency, flexibility and security of the to-be-accessed power device access.
[0092] Embodiment three
[0093] Figure 3 is a structural schematic diagram of a device access apparatus of an application power system provided by the embodiment three of the present application. As shown in the figure, Figure 3 The device includes an authentication result determination module 310, a temporary certificate issuance module 320, and a target certificate generation module 330.
[0094] The authentication result determination module 310 is configured to, in a case where the device access request is received and the security certificate is not included in the device access request, determine an authentication result of the power device to be accessed based on the device information in the device access request and the signature information corresponding to the power device to be accessed; the power device to be accessed is a power device in the first region; the temporary certificate issuing module 320 is configured to, in a case where the authentication result is consistent with a preset result, issue a temporary certificate for the power device to be accessed, so as to control the power device to be accessed to access based on the temporary certificate; and the target certificate generation module 330 is configured to, in a case where it is detected that the power device to be accessed accesses, configure system access parameters for the power device to be accessed, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate.
[0095] The technical scheme of the embodiment, by determining the authentication result of the power device to be accessed based on the device information in the device access request and the signature information corresponding to the power device to be accessed in a case where the device access request is received and the security certificate is not included in the device access request, guarantees the security of the power device to be accessed. In a case where the authentication result is consistent with a preset result, a temporary certificate is issued for the power device to be accessed, so as to control the access process of the power device to be accessed based on the temporary certificate, thereby reducing the security risk when the power device accesses. In a case where it is detected that the power device to be accessed accesses, system access parameters are configured for the power device to be accessed, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate, thereby controlling the access permission of the power device to be accessed through the target certificate, and guaranteeing the security of the power system after the power device accesses. The application solves the problems of different access modes due to different device information and the inability to guarantee the security of the power system after the power device accesses in the prior art. The application unifies the access mode of the power device to be accessed across regions, and through the device authentication, the issuing of the temporary certificate and the target certificate for the power device to be accessed without the security certificate, the power device to be accessed with the security certificate or the target certificate can access the power system across regions, thereby guaranteeing the consistency, flexibility and security of the power device to be accessed.
[0096] On the basis of the above-mentioned embodiment, the device further comprises a data encryption communication module, configured to, in a case where the security certificate is included in the device access request, or in a case where it is detected that the target certificate corresponding to the power device to be accessed has been generated, issue a target key for the power device to be accessed, so as to enable the power device to be accessed to encrypt data sent to the power system based on the target key; and, in a case where a data access request or a data upload request sent by the power device to be accessed is received, encrypt and feed back feedback data corresponding to the request based on a symmetric key corresponding to the target key.
[0097] Optionally, the authentication result determining module is configured to, after the signature information is decrypted, obtain a first hash value corresponding to the power device to be accessed; hash the device information in the device access request to obtain a second hash value of the power device to be accessed; and when the first hash value and the second hash value are the same, determine that the authentication result of the power device to be accessed is passed.
[0098] Optionally, the target certificate generating module is configured to configure system access parameters for the power device to be accessed according to the device type of the power device to be accessed and the data collection authority corresponding to the power device to be accessed in the first region, wherein the system access parameters include authority information for accessing the power system; determine an activation code corresponding to the power device to be accessed based on the device type, the system access parameters, and the coverage range applied by the power device to be accessed; and convert the temporary certificate into the target certificate based on the activation code.
[0099] Optionally, the device further includes an information association storage module configured to store the target certificate into a database corresponding to the region according to the region to which the power device to be accessed belongs; record the usable period information corresponding to the target certificate, and store the usable period information, the target certificate, and the device information of the power device to be accessed in association.
[0100] Optionally, the device further includes a target certificate updating module configured to, when detecting that the system access parameters of the power device to be accessed change, regenerate the target certificate corresponding to the power device to be accessed, and update the currently used target certificate.
[0101] Optionally, the device further includes an encryption parameter determining module configured to establish communication encryption parameters with the power device to be accessed, so as to perform data transmission between the power device to be accessed and the power system based on the communication encryption parameters.
[0102] Optionally, the device further includes an interactive data recording module configured to, when detecting interaction with the power device to be accessed, record the generated interactive data.
[0103] The device access device for the power system provided by the embodiments of the present application can perform the device access method for the power system provided by any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of the execution method.
[0104] Embodiment four
[0105] Figure 4is a structural schematic diagram of an electronic device provided by Embodiment Four of the present application. The electronic device 10 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.
[0106] As shown in Figure 4 The electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., connected in communication with the at least one processor 11, wherein the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded into the random access memory (RAM) 13 from the storage unit 18. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0107] A plurality of components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0108] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the device access method of the application power system.
[0109] In some embodiments, the device access method of applying power system can be implemented as a computer program tangibly embodied in a computer readable storage medium, e.g., storage unit 18. In some embodiments, parts or all of the computer program can be loaded and / or installed onto electronic device 10 via, e.g., ROM 12 and / or communication unit 19. When the computer program is loaded onto RAM 13 and executed by processor 11 as a result, one or more steps of the device access method of applying power system described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the device access method of applying power system by way of other any suitable means, e.g., by way of firmware.
[0110] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, specially designed application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0111] Computer programs implementing the device access method of applying power system of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program running on the processor implements the functions / operations specified in the flowcharts and / or the block diagrams. The computer program can be executed entirely on a machine, partly on a machine and partly on a remote machine or entirely on a remote machine or server.
[0112] Embodiment Five
[0113] Embodiment five of the present application further provides a computer readable storage medium, which stores computer instructions for causing a processor to execute a device access method of applying power system, the method comprising:
[0114] In a case that the device access request is received and the security certificate is not included in the device access request, an authentication result of the power device to be accessed is determined based on device information in the device access request and signature information corresponding to the power device to be accessed; wherein the power device to be accessed is a power device in the first region; when the authentication result is consistent with a preset result, a temporary certificate is issued for the power device to be accessed, so as to control the power device to be accessed to access based on the temporary certificate; when the power device to be accessed is detected to access, system access parameters are configured for the power device to be accessed, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate.
[0115] In the context of the present application, a computer readable storage medium can be a tangible medium which can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, the computer readable storage medium can be a machine readable signal medium. More specific examples of the machine readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0116] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0117] The systems and techniques described herein can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described herein, or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0118] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0119] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be performed in parallel, in series, or in a different order, and the present disclosure is not limited herein as long as the desired results of the technical solutions of the present disclosure can be achieved.
[0120] The specific embodiments described above are not intended to limit the scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modification, equivalent replacement, and improvement within the spirit and principles of the present disclosure should be included in the scope of the present disclosure.
Claims
1. A method for connecting equipment to a power system, characterized in that, The method, applicable to connecting electrical equipment in a first region to the power system of a corresponding second region, wherein the first region and the second region use different power systems, includes: Upon receiving a device access request, and if the device access request does not include a security certificate, the authentication result of the power device to be accessed is determined based on the device information in the device access request and the signature information corresponding to the power device to be accessed; wherein, the power device to be accessed is a power device in the first area; When the authentication result matches the preset result, a temporary certificate is issued to the power equipment to be connected, so as to control the access of the power equipment to be connected based on the temporary certificate; When the access of the power device to be accessed is detected, system access parameters are configured for the power device to be accessed, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate; The step of configuring system access parameters for the power equipment to be connected, and generating a target certificate corresponding to the power equipment to be connected based on the system access parameters, includes: Based on the device type of the power device to be connected and the data collection permissions corresponding to the power device in the first area, system access parameters are configured for the power device to be connected, wherein the system access parameters include permission information for accessing the power system; based on the device type, the system access parameters, and the coverage area applied by the power device to be connected, an activation code corresponding to the power device to be connected is determined; based on the activation code, the temporary certificate is converted into a target certificate.
2. The method according to claim 1, characterized in that, The method further includes: If the security certificate is included in the device access request, or if a target certificate corresponding to the power device to be accessed is detected to have been generated, a target key is issued to the power device to be accessed, so that the power device to be accessed encrypts the data sent to the power system based on the target key; and, Upon receiving a data access request or data upload request from the power equipment to be connected, the system encrypts and sends back the feedback data corresponding to the request based on the symmetric key corresponding to the target key.
3. The method according to claim 1, characterized in that, The step of determining the authentication result of the power device to be accessed based on the device information in the device access request and the signature information corresponding to the power device to be accessed includes: After decrypting the signature information, a first hash value corresponding to the power equipment to be connected is obtained; After hashing the device information in the device access request, a second hash value of the power device to be accessed is obtained; When the first hash value and the second hash value are the same, the authentication result of the power equipment to be connected is determined to be successful.
4. The method according to claim 1, characterized in that, The method further includes: Based on the region to which the power equipment to be connected belongs, the target certificate is stored in the database corresponding to the region; Record the usability period information corresponding to the target certificate, and store the usability period information, the target certificate, and the equipment information of the power equipment to be connected in association.
5. The method according to claim 1, characterized in that, The method further includes: When a change is detected in the system access parameters of the power device to be connected, a new target certificate corresponding to the power device to be connected is generated, and the currently used target certificate is updated.
6. The method according to claim 1, characterized in that, The method further includes: Establish communication encryption parameters with the power equipment to be connected, so that data can be transmitted between the power equipment to be connected and the power system based on the communication encryption parameters.
7. The method according to claim 1, characterized in that, The method further includes: When interaction with the power equipment to be connected is detected, the generated interaction data is recorded.
8. A device for connecting equipment to a power system, characterized in that, An apparatus for connecting electrical equipment in a first region to the power system of a corresponding second region, wherein the first region and the second region use different power systems, the apparatus comprising: The authentication result determination module is used to determine the authentication result of the power device to be accessed based on the device information in the device access request and the signature information corresponding to the power device to be accessed when a device access request is received and the device access request does not include a security certificate; wherein the power device to be accessed is a power device in the first area; The temporary certificate issuance module is used to issue a temporary certificate to the power device to be connected when the authentication result is consistent with the preset result, so as to control the access of the power device to be connected based on the temporary certificate; The target certificate generation module is used to configure system access parameters for the power device to be accessed when the access is detected, so as to generate a target certificate corresponding to the power device to be accessed based on the system access parameters and the temporary certificate. The target certificate generation module is used to configure system access parameters for the power device to be connected according to the device type and the data collection permissions corresponding to the power device in the first area, wherein the system access parameters include permission information for accessing the power system; determine the activation code corresponding to the power device to be connected based on the device type, the system access parameters and the coverage area applied by the power device to be connected; and convert the temporary certificate into a target certificate based on the activation code.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the device access method for the applied power system as described in any one of claims 1-7.
Citation Information
Patent Citations
Cross-domain authentication method of heterogeneous Internet of Things
CN111447187A
Equipment verification method and device based on security chip, equipment and medium
CN117692900A