Ecological and environmental quality monitoring system

By deploying gateway devices and remote servers at environmental monitoring sites, the problem of environmental monitoring data tampering is solved, ensuring secure data transmission and integrity, and guaranteeing that remote servers obtain the original, tamper-free monitoring data.

CN119814831BActive Publication Date: 2025-10-28CHINA NAT ENVIRONMENTAL MONITORING CENT
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411981135.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-10-28
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

The existing environmental monitoring equipment system architecture is prone to the risk of monitoring data being tampered with, especially due to the leakage of access passwords for the host industrial control computer.

Method used

By using a gateway device as a relay, the monitoring equipment control software is deployed on the remote server. The gateway device forwards the control commands from the remote server to the environmental monitoring equipment and encrypts the data before reporting it directly to the remote server. This eliminates the direct physical connection with the host computer and ensures that the data cannot be tampered with at the gateway device.

Benefits of technology

This ensures the originality and integrity of environmental monitoring data, allowing remote servers to directly obtain untampered monitoring data and guaranteeing the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814831B_ABST
    Figure CN119814831B_ABST
Patent Text Reader

Abstract

This disclosure provides an ecological environment quality monitoring system, including: environmental monitoring equipment and gateway equipment deployed at monitoring points, and a remote server with monitoring equipment control software installed. The gateway equipment's monitoring equipment connection interface is connected to the data I / O interface of the environmental monitoring equipment, and its network communication interface is connected to the remote server via a communication network. The gateway equipment forwards control commands issued by the remote server to the environmental monitoring equipment and reports the output data of the environmental monitoring equipment to the remote server. The remote server issues control commands to the gateway equipment and receives the output data reported by the gateway equipment. Using this solution, the output data transmitted through the gateway equipment cannot be tampered with and is directly forwarded to the remote server. The remote server can obtain various raw data output by the environmental monitoring equipment and thus obtain the corresponding environmental monitoring data based on the raw data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of Internet of Things (IoT) technology, specifically to an ecological environment quality monitoring system. Background Technology

[0002] To achieve comprehensive environmental quality monitoring, numerous monitoring stations for air and water quality monitoring have been deployed across all levels of government in China. These monitoring stations are equipped with monitoring devices for specific environmental quality parameters. These devices collect data on the corresponding types of environmental quality parameters at each station and report the monitoring data in real time.

[0003] Currently, the environmental monitoring stations employ a system architecture consisting of a host industrial control computer and lower-level monitoring devices. The host industrial control computer is used to perform quality control and data acquisition on the lower-level monitoring devices, and to report the collected monitoring data to various data sources. Although the host industrial control computer can be operated remotely via a desktop and an access password can be set, the use of customized commercial software systems still poses a risk of password leakage, which could lead to the risk of tampering with the monitoring data collected by the lower-level monitoring devices. Summary of the Invention

[0004] To address the problem that the existing equipment architecture of environmental monitoring sites is prone to data tampering, this disclosure provides an ecological environment monitoring system.

[0005] In a first aspect, embodiments of this disclosure provide an ecological environment quality monitoring system, including: environmental monitoring equipment and gateway equipment deployed at monitoring points, and a remote server on which monitoring equipment control software is installed;

[0006] The monitoring device connection interface of the gateway device is connected to the data IO interface of the environmental monitoring device, and the network communication interface is connected to the remote server through the communication network. It is used to forward the control commands issued by the remote server to the environmental monitoring device and to report the output data of the environmental monitoring device to the remote server.

[0007] The remote server is used to send control commands to the gateway device for controlling the environmental monitoring device, and to receive the output data reported by the gateway device.

[0008] Optionally, the remote server is also used to send a short-time encryption program to the gateway device, the short-time encryption program being an encryption program used only within a set duration;

[0009] The gateway device reports the output data of the environmental monitoring device to the remote server, including:

[0010] The output data is encrypted using the short-time encryption procedure to obtain encrypted reporting data, and the encrypted reporting data is sent to the remote server.

[0011] Upon receiving the encrypted reporting data, the remote server uses a short-time decryption program to decrypt the encrypted reporting data to obtain the output data; the short-time decryption program is a decryption program adapted to the short-time encryption program.

[0012] Optionally, the gateway device is further configured with a long-term encryption program, and the remote server is further configured with a long-term decryption program adapted to the long-term encryption program.

[0013] Before the gateway device encrypts the output data using the short-time encryption program to obtain encrypted reporting data, the method further includes: encrypting the output data using the long-time encryption program to obtain encrypted data once.

[0014] The gateway device uses the short-time encryption program to encrypt the output data to obtain encrypted reporting data, including: using the short-time encryption program to re-encrypt the first-encrypted data to obtain the encrypted reporting data;

[0015] The step of decrypting the encrypted reported data using a short-time decryption procedure to obtain output data includes: decrypting the encrypted reported data using the short-time decryption procedure to obtain first-time decrypted data; and then decrypting the first-time decrypted data again using a long-time decryption procedure to obtain the output data; or...

[0016] After receiving the encrypted reporting data, the gateway device uses the long-term encryption program to re-encrypt the encrypted reporting data to obtain secondary encrypted data, and then sends the secondary encrypted data to the remote server.

[0017] After receiving the secondary encrypted data, the remote server processes the secondary encrypted data using the long-time decryption program to obtain the encrypted reporting data.

[0018] Optionally, the remote server publishes the short-term encryption program to an encryption program topic, and the gateway device obtains the short-term encryption program by subscribing to the encryption program topic.

[0019] Optionally, the remote server publishes the program identifier of the new short-time encryption program at the same time as publishing the new short-time encryption program.

[0020] Upon acquiring a new short-term encryption program, the gateway device simultaneously acquires the corresponding program identifier.

[0021] The step of encrypting the output data using the short-time encryption program to obtain encrypted reporting data, and sending the encrypted reporting data to the remote server, includes:

[0022] The newly acquired output data is encrypted using a new short-time encryption procedure to obtain encrypted reporting data;

[0023] A data packet is composed of encrypted reported data and a new short-time encryption program identifier, and the data packet is sent to the remote server; or...

[0024] Simultaneously with the release of a new short-term encryption program, the remote server releases the effective period of the new short-term encryption program; simultaneously, the gateway device obtains the corresponding effective period upon receiving the new short-term encryption program.

[0025] The step of encrypting the output data using the short-time encryption program to obtain encrypted reporting data includes: determining the effective time period for entering a new short-time encryption program, encrypting the newly acquired output data using the new short-time encryption program, and obtaining encrypted reporting data.

[0026] Optionally, the remote server publishes control commands, including device identifiers and gateway identifiers, to a command distribution topic, and the gateway device obtains the control commands by subscribing to the command distribution topic;

[0027] Upon receiving the control command, the gateway device determines whether to discard the control command based on the gateway identifier and its own identifier in the control command, and if it does not discard the control command, it sends the control command to the corresponding environmental monitoring device based on the device identifier.

[0028] Optionally, the output data includes at least two different types of data;

[0029] The gateway device reports the output data of the environmental monitoring device to the remote server, including:

[0030] In response to receiving the output data, the data type is determined based on the type identifier of the output data;

[0031] Based on the data type, the output data is published to the corresponding type topic;

[0032] The remote server obtains various types of output data by subscribing to various types of topics.

[0033] Optionally, when the gateway device connects to the communication network or enters a new connection cycle, the gateway device sends its own fingerprint information to the remote server.

[0034] In response to receiving fingerprint information sent by the gateway device, the remote server generates a random site number based on the fingerprint information, stores the association between the random site number and the fingerprint information in a local data table, and sends the random site number to the gateway device.

[0035] After receiving the site random number and the output data of the monitoring device, the gateway device assembles the site random number, the encrypted fingerprint information, and the output data into a data packet and sends the data packet to the remote server.

[0036] Optionally, after receiving the data packet, the remote server parses the data packet to obtain the parsing site random number, parsing fingerprint information, and parsing output data;

[0037] If the correlation between the parsing site's random number and the parsing fingerprint information is stored in a local data table, the parsing output data will be considered valid data; and,

[0038] If the random number of the parsing site and the parsing fingerprint information are not stored in the local data table, the parsing output data is discarded.

[0039] Optionally, when the gateway device connects to the newly connected environmental monitoring device and receives the device identifier of the newly connected monitoring device, the gateway device further includes generating a device configuration request based on the site random number and the device identifier, and sending it to the remote server;

[0040] After receiving the device configuration request, the remote server parses the device configuration request to obtain the device identifier and the site random number;

[0041] Control commands are generated based on the parsed device identifier and sent to the gateway device corresponding to the random identifier of the site.

[0042] The ecological environment quality monitoring system in this embodiment eliminates the host computer at the environmental monitoring point, as is common in conventional architectures. Instead, it deploys a gateway device for data relay. Simultaneously, the control software for controlling the environmental monitoring equipment is deployed on a remote server. Control commands issued by the remote server are forwarded to the environmental monitoring equipment through the gateway device, and various data output by the environmental monitoring equipment are also directly sent to the remote server through the gateway device. Using this solution, the output data transmitted through the gateway device cannot be tampered with and is directly forwarded to the remote server. The remote server can obtain various raw data output by the environmental monitoring equipment and thus derive the corresponding environmental monitoring data based on the raw data. Attached Figure Description

[0043] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0044] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without any creative effort, wherein:

[0045] Figure 1 This is a schematic diagram of the structure of the ecological environment quality monitoring system provided in this embodiment;

[0046] Figure 2 These are timing diagrams of communication between remote servers and gateway devices in some embodiments. Detailed Implementation

[0047] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0048] The term "comprising" and its variations as used herein are open-ended inclusion, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below. In this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0049] To address the problem that the existing ecological environment quality monitoring system's architecture, which consists of a host industrial control computer and lower-level monitoring equipment, is prone to data tampering, this disclosure provides a new ecological environment quality monitoring system.

[0050] Figure 1 This is a schematic diagram of the structure of the ecological environment quality monitoring system provided in this embodiment. Figure 1As shown, the ecological environment quality monitoring system 100 provided in this embodiment includes an environmental monitoring device 101, a gateway device 102, and a remote server 103.

[0051] The aforementioned environmental monitoring device 101 and gateway device 102 are both deployed locally at the environmental monitoring point. In specific implementations, multiple different types of environmental monitoring devices 101 and one gateway device 102 can be deployed at one environmental monitoring point. The monitoring device connection interface of the gateway device 102 is connected to the data IO interface of each environmental monitoring device 101, and data transmission with each environmental monitoring device 101 is realized through a local communication link.

[0052] Each environmental monitoring device 101 can be connected in series with the gateway device 102 (that is, only one environmental monitoring device 101 is directly connected to the gateway device 102, and other environmental monitoring devices 101 communicate with the gateway device 102 through the aforementioned environmental monitoring device 101), or it can be connected in parallel with the gateway device 102 (that is, each environmental monitoring device 101 is connected to the gateway device 102 through an independent monitoring device connection interface). This disclosure does not limit the scope of the embodiments. In some embodiments, while ensuring the security and reliability of data communication, the gateway device 102 and the environmental monitoring devices 101 can also be connected using a short-range wireless communication method.

[0053] In this embodiment of the disclosure, the gateway device 102 does not have the function of directly controlling the environmental monitoring device 101, that is, the gateway device 102 does not have monitoring device control software installed for directly controlling the environmental monitoring device 101.

[0054] Remote server 103 is a server not deployed at the environmental monitoring site, but equipped with the monitoring equipment control software. Remote server 103 can send control commands to environmental monitoring equipment 101 via network communication and receive output data reported by environmental monitoring equipment 101. In practice, remote server 103 is often deployed in the server room of the environmental regulatory body.

[0055] like Figure 1 As shown in this embodiment, the remote server 103 is not directly connected to the aforementioned environmental monitoring device 101, but is indirectly connected to the environmental monitoring device 101 through the gateway device 102. Specifically, the gateway device 102 acts as an intermediate communication device, forwarding control commands issued by the remote server 103 to the corresponding environmental monitoring device 101, and reporting various output data output by the environmental monitoring device 101 to the remote server 103.

[0056] As analyzed above, the ecological environment quality monitoring system 100 used in this embodiment eliminates the host computer at the environmental monitoring point in the conventional architecture, and instead deploys only a gateway device 102 for data relay. Meanwhile, the control software for controlling the environmental monitoring device 101 is deployed on a remote server 103. Control commands issued by the remote server 103 are forwarded to the environmental monitoring device 101 through the gateway device 102, and various data output by the environmental monitoring device 101 are also directly sent to the remote server 103 through the gateway device 102.

[0057] Because gateway device 102 does not deploy monitoring equipment control software, the output data transmitted through it cannot be tampered with by gateway device 102, but is directly forwarded to remote server 103. In the ecological environment quality monitoring system 100 using the architecture of this disclosure, remote server 103 can obtain various raw data output by environmental monitoring equipment 101, and thus obtain the corresponding environmental monitoring data based on the raw data.

[0058] In practice, the gateway device 102 can be designed to have only the aforementioned monitoring device connection interface and network communication interface, and does not have a physical interface that can directly read device status and data. Consequently, it is impossible to intercept or tamper with various data information through physical connection.

[0059] Because the various data output by the environmental monitoring device 101 are confidential and subject to interception by third parties, in practical applications, the output data from the environmental monitoring device 101, forwarded to the remote server 103 via the gateway device 102, should not be transmitted in plaintext but rather in encrypted form. In this case, the risk of the encrypted data itself being cracked needs to be considered.

[0060] Figure 2 This is a timing diagram of the communication between remote server 103 and gateway device 102 in some embodiments. For example... Figure 2 As shown, in order to achieve reliable encrypted transmission of output data, after the gateway device 102 establishes a communication connection with the remote server 103 (this can be a direct communication connection or an indirect communication connection (that is, the gateway device 102 and the remote server 103 do not directly know of each other's existence, which will be analyzed later), the remote server 103 sends a short-term encryption program to the gateway device 102.

[0061] A short-time encryption program is an encryption program that can only be used within a set duration. After its release (i.e., public disclosure by remote server 103) exceeds the set duration, the short-time encryption program becomes useless (the remote server 103 will use a different short-time decryption program, rendering the data encrypted with the short-time encryption program unusable). In practice, considering that the gateway device 102 lacks software compilation capabilities, the aforementioned short-time encryption program is a binary program compiled on the remote server 103. The set duration can be determined based on the cracking complexity of the short-time encryption program; the higher the cracking complexity, the longer the usable set duration.

[0062] like Figure 2 As shown, in order for the gateway device 102 to use a short-time encryption program to encrypt the output data, the remote server 103 needs to execute S110 to send the short-time encryption program to the gateway device.

[0063] In some embodiments, the remote server 103 and the gateway device 102 are directly connected, and the remote server 103 can directly send short-term encryption programs to the gateway device 102.

[0064] In other embodiments, to decouple the remote server 103 and a large number of gateway devices 102, the remote server 103 and gateway devices 102 use a message queue telemetry transport protocol to distribute short-term encryption programs. Specifically, (1) the remote server 103 creates an encryption program topic in a proxy service (this proxy service can be a private proxy service deployed under the subject to which the remote server 103 belongs, or it can be a public proxy service), and publishes the short-term encryption program to the aforementioned encryption program topic; (2) the gateway devices 102 subscribe to the aforementioned encryption program topic. After a new short-term encryption program is published in the encryption program topic, the proxy service pushes the short-term encryption program to the gateway devices 102, enabling the gateway devices 102 to obtain the short-term encryption program.

[0065] After obtaining and loading the aforementioned short-term encryption program, gateway device 102 executes S120: encrypting the output data using the short-term encryption program to obtain encrypted reporting data, and S130 sending the encrypted reporting data to the remote server. It should be noted that the execution of S120 is contingent upon gateway device 102 obtaining the output data sent by environmental monitoring device 101.

[0066] After receiving the encrypted reporting data sent by the gateway device 102, the remote server 103 executes S140: decrypting the encrypted reporting data using a short-time decryption program to obtain the output data. The short-time decryption program is a decryption program adapted to the short-time encryption program, which is generated by the remote server 103 based on the short-time encryption program.

[0067] Because short-time encryption and short-time decryption procedures correspond, the system can decrypt encrypted reported data to obtain output data. After obtaining the output data, the remote server 103 can analyze the output data and obtain the corresponding output results.

[0068] For example, when the output data is environmental quality monitoring data, the remote server 103 can determine the environmental quality statistics of the environmental monitoring points based on the environmental quality monitoring data; when the output data is the status data of the environmental monitoring equipment 101, the remote server 103 can determine whether the environmental monitoring equipment 101 is in an abnormal state and the cause of the abnormal state based on the status data; when the output data is the quality control result data of the environmental monitoring equipment 101, the remote server 103 can determine whether the quality control is qualified based on the quality control result data.

[0069] In some embodiments, in addition to the aforementioned short-time encryption program, the gateway device 102 is also configured with a long-time encryption program. Accordingly, it can encrypt output data using both the short-time and long-time encryption programs. Specifically, there may be two scenarios.

[0070] 1. Before the gateway device 102 encrypts the output data using a short-time encryption procedure to obtain encrypted reporting data, the gateway device 102 encrypts the output data using a long-time encryption procedure to obtain encrypted data once. Specifically, the aforementioned S120 involves S121 re-encrypting the encrypted data using a short-time encryption procedure to obtain encrypted reporting data. When S121 is executed, the preceding S140 specifically involves: decrypting the encrypted reporting data using a short-time decryption procedure to obtain decrypted data once; subsequently, re-decrypting the decrypted data using a long-time decryption procedure to obtain output data.

[0071] 2. After decrypting the encrypted reported data using a short-time decryption procedure to obtain the output data, the gateway device 102 uses a long-time encryption procedure to re-encrypt the encrypted reported data, obtaining secondary encrypted data, and then sends the secondary encrypted data to the remote server 103. Correspondingly, after receiving the secondary encrypted data, the remote server 103 uses a long-time available interface program to process the secondary encrypted data to obtain encrypted reported data, and then executes the aforementioned S140.

[0072] In specific implementation, the aforementioned long-time encryption program and long-time decryption program can be programs that use symmetric encryption and decryption or programs that use asymmetric encryption and decryption. This disclosure does not limit the implementation.

[0073] As analyzed earlier, the short-time encryption program is only available for a short period. When it is transmitted to gateway device 102 using a publish-subscribe mechanism, the asynchronous transmission between remote server 103 and gateway device 102 (i.e., when gateway device 102 obtains the short-time encryption program is uncertain, but the general timeframe is determined) affects the coordination between gateway device 102 using the short-time encryption program and remote server 103 using the short-time decryption program. In this case, it is necessary to consider how the old and new short-time encryption programs can be used in coordination, and how to ensure that remote server 103 determines the corresponding short-time decryption program.

[0074] To address the aforementioned issues, in some embodiments, the remote server 103 publishes a program identifier for the new short-term encryption program simultaneously with its release. The corresponding gateway device 102, upon acquiring the new short-term encryption program, also acquires the corresponding program identifier. In this case, the gateway device 102 can use the new short-term encryption program to encrypt the newly acquired output data, obtaining encrypted reporting data. To enable the remote server 103 to determine which short-term decryption program interface to use, the gateway device 102 composes a transmission data packet based on the encrypted reporting data and the new short-term encryption program identifier, and sends the transmission data packet to the remote server 103.

[0075] In some other embodiments, the remote server 103 publishes the validity period of the new short-term encryption program simultaneously with its release. The corresponding gateway device 102, upon receiving the new short-term encryption program, also acquires the corresponding validity period. In this case, the gateway device 102, upon determining that it has entered the validity period of the new short-term encryption program, encrypts the newly acquired output data using the new short-term encryption program to obtain encrypted reporting data. Correspondingly, the remote server 103, upon determining that the short-term encryption program is within its validity period, decrypts the received confidential reporting data using the corresponding short-term interface program.

[0076] Based on the actual situation of environmental quality monitoring, there are a large number of environmental monitoring stations in practical applications, and correspondingly a large number of gateway devices 102. In this case, if the data receiving interfaces of each gateway device 102 and the remote server 103 are directly coupled, the system will be too complex and inconvenient for the online use and offline maintenance of environmental monitoring points. To solve this problem, the gateway device 102 and the remote server 103 can also use a publish-subscribe mechanism to transmit output data. Specifically, a data topic is created in the proxy service, and the gateway device 102 publishes the output data (or the aforementioned encrypted reporting data, sent data packets) to the aforementioned data topic, and the remote server 103 subscribes to the aforementioned data topic. After the output data is published to the output data topic, the proxy service pushes the output device to the remote server 103, and the remote server 103 can obtain the output data from the corresponding message queue.

[0077] In some embodiments, different output data have different processing priorities. For example, quality control data and equipment status data have higher priority than environmental quality monitoring data, requiring the establishment of different data topics. The aforementioned different types of output data are published to their respective data topics. To achieve this objective, after receiving output data from environmental monitoring device 101, gateway device 102 determines the data type based on the output data type identifier, and then sends the output data (or encrypted data) to the corresponding type topic according to the data type. Correspondingly, remote server 103 obtains various types of output data by subscribing to various topics. It should be noted that the aforementioned publish-subscribe mechanism for output data does not conflict with the encryption method for output data described above; both can be used simultaneously. That is, before gateway device 102 publishes output data, the aforementioned encryption method can be used to encrypt the output data before it is published to the corresponding type topic.

[0078] As analyzed above, remote server 103 needs to send control commands to environmental monitoring device 101. In cases where it is necessary to decouple the strong coupling between remote server 103 and gateway device 102, remote server 103 can also use a message publish-subscribe mechanism to send control commands. Specifically, firstly, a command sending topic is created in the proxy service, and gateway device 102 subscribes to the aforementioned command sending topic. Subsequently, remote server 103 publishes the control command, including the device identifier and gateway identifier, to the command sending topic, and sends the control command to all gateway devices 102 through the proxy service. After receiving the aforementioned control command, gateway device 102 determines whether the control command is a command sent to its own site based on the gateway identifier and its own identifier in the control command: (1) If it is not a command sent to its own site, the control command is discarded directly; (2) If it is a control command sent to its own site, the corresponding environmental monitoring device 101 is determined based on the device identifier, and the control command is sent to this environmental monitoring device 101.

[0079] In the aforementioned solution, when gateway device 102 interacts with remote server 103, it needs to write fingerprint information (identification information) in the header of the corresponding data packet so that remote server 103 can determine the source of the data packet. In this case, there is a possibility of intentionally interfering with the packet information sent by a specific gateway device 102, causing remote server 103 to malfunction (especially by actively discarding data packets). To avoid the aforementioned problem, it is necessary to hide the fingerprint information of gateway device 102.

[0080] To achieve the aforementioned objectives, in some embodiments, when gateway device 102 connects to the communication network or enters a new connection cycle, gateway device 102 acquires its own fingerprint information and sends it to remote server 103. Upon receiving the fingerprint information from gateway device 102, remote server 103 generates a random site number based on the fingerprint information (in specific implementations, the time of receiving the fingerprint information may also be considered to make the generated random site number more uncrackable). Subsequently, remote server 103 stores the association between the random site number and the fingerprint information in a local data table and sends the random site number to gateway device 102. In specific implementations, remote server 103 can send the fingerprint information and the aforementioned random site number using the aforementioned publish-subscribe mechanism, so that all gateway devices 102 receive the fingerprint information and the random site number, and then use the fingerprint information to determine their own random site number. In practice, the remote server 103 can encrypt the aforementioned data before publishing the correspondence between fingerprint information and site random number to ensure that the corresponding data cannot be easily obtained by a third party (for example, by using asymmetric encryption, only a specific gateway device 102 can obtain the corresponding fingerprint information and site random number).

[0081] Correspondingly, after the aforementioned specific gateway device 102 receives the corresponding site random number and the monitoring data from the local environmental monitoring device 101, the gateway device 102 combines the site random number, encrypted fingerprint information, and output data into a data packet and sends the data packet to the remote server 103. In this case, only the remote server 103 can determine which gateway device 102 sent the data packet based on the site random number.

[0082] Accordingly, after receiving the transmitted data packet, the remote server 103 can parse the transmitted data packet to obtain the site random number, the parsing fingerprint information, and the parsing output data. The remote server 103 then verifies whether the association between the parsing site random number and the parsing fingerprint information is stored in a local data table. If so, it proves that the corresponding data packet was sent by the genuine gateway device 102, and the corresponding parsing output data can be used as legitimate data. Conversely, if the parsing site random number and the parsing fingerprint information are not stored in the local data table, it is determined that the corresponding data packet is forged, and the corresponding parsing data can be discarded. In some embodiments, if the obtained site random number of the transmitted data packet is not in the data table, the corresponding data packet can be directly discarded without decryption.

[0083] In some specific applications, environmental monitoring stations may need to iterate and update environmental monitoring equipment 101 or add new environmental monitoring equipment 101. In this case, a remote server 103 needs to perform parameter configuration, quality control, and other operations on the new environmental monitoring equipment 101. After connecting to the newly connected environmental monitoring equipment 101 and receiving the device identifier of the newly connected monitoring equipment, the gateway device 102 generates a device configuration request based on the site random number and the device identifier, and sends it to the remote server 103. After receiving the device configuration request, the remote server 103 parses the device configuration request to obtain the device identifier and the site random number. Subsequently, it generates corresponding control commands based on the device identifier and sends them to the gateway device 102 corresponding to the site random identifier. As analyzed above, the aforementioned control commands can be sent using a topic publish-subscribe mechanism, so that all gateway devices 102 obtain the control commands, but only the gateway device 102 corresponding to the site random identifier will execute the aforementioned control commands.

[0084] The above are merely specific embodiments of this disclosure, enabling those skilled in the art to understand or implement this disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An ecological environment quality monitoring system, characterized in that, include: Environmental monitoring equipment and gateway equipment deployed at monitoring points, as well as remote servers that install the monitoring equipment control software; The monitoring device connection interface of the gateway device is connected to the data IO interface of the environmental monitoring device, and the network communication interface is connected to the remote server through the communication network. It is used to forward the control commands issued by the remote server to the environmental monitoring device and to report the output data of the environmental monitoring device to the remote server. The gateway device only has the monitoring device connection interface and network communication interface, and does not have a physical interface that can directly realize device status reading and data reading; The remote server is used to send control commands to the gateway device to control the environmental monitoring device, and to receive the output data reported by the gateway device. Simultaneously with the release of the new short-time encryption program, the remote server releases the program identifier corresponding to the new short-time encryption program; At the same time that the gateway device obtains the new short-term encryption program, it also obtains its corresponding program identifier; The output data is encrypted using the new short-time encryption procedure to obtain encrypted reporting data, and the encrypted reporting data is sent to the remote server, including: The output data is encrypted using the new short-time encryption procedure to obtain encrypted reporting data; A data packet is composed of the encrypted reporting data and the program identifier, and the data packet is sent to the remote server; or... Simultaneously with the release of the new short-term encryption program, the remote server releases the corresponding validity period of the new short-term encryption program; simultaneously with the acquisition of the new short-term encryption program, the gateway device acquires the corresponding validity period. The process of encrypting the output data using the new short-time encryption procedure to obtain encrypted reporting data includes: determining the valid time period corresponding to the entry of the new short-time encryption procedure, encrypting the output data using the new short-time encryption procedure, and obtaining encrypted reporting data.

2. The system according to claim 1, characterized in that, The remote server is also used to send a short-time encryption program to the gateway device. The short-time encryption program is an encryption program used within a set duration. The gateway device reports the output data of the environmental monitoring device to the remote server, including: The output data is encrypted using the short-time encryption procedure to obtain encrypted reporting data, and the encrypted reporting data is sent to the remote server. Upon receiving the encrypted reporting data, the remote server uses a short-time decryption program to decrypt the encrypted reporting data to obtain the output data; the short-time decryption program is a decryption program adapted to the short-time encryption program.

3. The system according to claim 2, characterized in that, The gateway device is also configured with a long-term encryption program, and the remote server is also configured with a long-term decryption program adapted to the long-term encryption program. Before the gateway device encrypts the output data using the short-time encryption program to obtain encrypted reporting data, the method further includes: encrypting the output data using the long-time encryption program to obtain encrypted data once. The gateway device uses the short-time encryption program to encrypt the output data to obtain encrypted reporting data, including: using the short-time encryption program to re-encrypt the first-encrypted data to obtain the encrypted reporting data; The step of decrypting the encrypted reported data using a short-time decryption procedure to obtain output data includes: decrypting the encrypted reported data using the short-time decryption procedure to obtain first-time decrypted data; and then decrypting the first-time decrypted data again using a long-time decryption procedure to obtain the output data; or... After receiving the encrypted reporting data, the gateway device uses the long-term encryption program to re-encrypt the encrypted reporting data to obtain secondary encrypted data, and then sends the secondary encrypted data to the remote server. After receiving the secondary encrypted data, the remote server processes the secondary encrypted data using the long-time decryption program to obtain the encrypted reporting data.

4. The system according to claim 2, characterized in that, include: The remote server publishes the short-time encryption program to an encryption program topic, and the gateway device obtains the short-time encryption program by subscribing to the encryption program topic.

5. The system according to any one of claims 1-4, characterized in that, Also includes: The remote server publishes control commands, including device identifiers and gateway identifiers, to the command distribution topic, and the gateway device obtains the control commands by subscribing to the command distribution topic; Upon receiving the control command, the gateway device determines whether to discard the control command based on the gateway identifier and its own identifier in the control command, and if it does not discard the control command, it sends the control command to the corresponding environmental monitoring device based on the device identifier.

6. The system according to any one of claims 1-4, characterized in that, The output data includes at least two different types of data; The gateway device reports the output data of the environmental monitoring device to the remote server, including: In response to receiving the output data, the data type is determined based on the type identifier of the output data; Based on the data type, the output data is published to the corresponding type topic; The remote server obtains various types of output data by subscribing to various types of topics.

7. The system according to any one of claims 1-4, characterized in that, Also includes: When the gateway device connects to the communication network or enters a new connection cycle, the gateway device sends its own fingerprint information to the remote server. In response to receiving fingerprint information sent by the gateway device, the remote server generates a random site number based on the fingerprint information, stores the association between the random site number and the fingerprint information in a local data table, and sends the random site number to the gateway device. After receiving the site random number and the output data of the monitoring device, the gateway device assembles the site random number, the encrypted fingerprint information, and the output data into a data packet and sends the data packet to the remote server.

8. The system according to claim 7, characterized in that, Also includes: After receiving the data packet, the remote server parses the data packet to obtain the random parsing site number, parsing fingerprint information, and parsing output data. If the correlation between the random number of the parsing site and the parsing fingerprint information is stored in the local data table, the parsing output data will be regarded as legitimate data. as well as, If the random number of the parsing site and the parsing fingerprint information are not stored in the local data table, the parsing output data is discarded.

9. The system according to claim 7, characterized in that, Also includes: When the gateway device connects to the newly connected environmental monitoring device and receives the device identifier of the newly connected monitoring device, the gateway device further includes generating a device configuration request based on the site random number and the device identifier, and sending it to the remote server; After receiving the device configuration request, the remote server parses the device configuration request to obtain the device identifier and the site random number; Control commands are generated based on the device identifier and sent to the gateway device corresponding to the site's random number.

Citation Information

Patent Citations

  • A data reporting and instruction sending method based on LoRa Internet of Things

    CN108989455A