Ecological environment quality monitoring system

Through the non-network interface connection between the failed gateway device and the replacement gateway device, dynamic ID verification and encryption policies are used to solve the problem that data cannot be safely transmitted when the gateway device fails, and the secure transmission and integrity of data are achieved.

CN119814832BActive Publication Date: 2025-07-25CHINA NAT ENVIRONMENTAL MONITORING CENT
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411981144.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-07-25
Estimated Expiration
2044-12-31

AI Technical Summary

Technical Problem

In the ecological environment monitoring system, the network interface failure of the gateway device causes the reported data to be unable to be sent to the remote server, and the existing technology cannot safely export the data buffered by the failed gateway device, which poses a risk of data leakage.

Method used

Through the non-network interface connection between the failed gateway device and the replacement gateway device, dynamic ID verification and encryption policies are used to ensure the secure transmission of data to the remote server, including generating verification request messages, dynamic ID verification and fingerprint information encryption, and establishing a trusted connection.

Benefits of technology

It realizes the secure transmission of data of the failed gateway equipment without human data reading, ensuring the security and integrity of the data and avoiding data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814832B_ABST
    Figure CN119814832B_ABST
Patent Text Reader

Abstract

An embodiment of the present disclosure provides an ecological environment monitoring system, including a gateway device deployed at a monitoring point and locally connected to the data interfaces of various environmental monitoring devices, and a remote server communicatively connected to the gateway device through a communication network; the faulty gateway device sends the buffered reported data to the replacement gateway device through a non-network interface, and the replacement gateway device forwards the reported data to the remote server. The replacement gateway device can also act as a relay device to forward the reported data to the remote server. In this way, the storage of the data temporarily stored by the faulty gateway device can be achieved without manual data reading, ensuring the security of the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of Internet of Things technology, and more particularly to an ecological environment quality monitoring system. Background Art

[0002] To reduce the problems of environmental monitoring data leakage and tampering caused by loopholes in intermediate links, an ecological environment monitoring system using a remote server and a local gateway device architecture system has been proposed in related technologies. The local gateway device is used as a data transmission relay to enable the remote server to directly control the local environmental monitoring devices at the environmental monitoring sites, and to directly report the reported data generated by the local environmental monitoring devices to the remote server. However, under the foregoing monitoring system architecture, it is inevitable that the gateway device cannot send the reported data generated by the environmental monitoring device to the remote server due to its own failure (mostly network interface failure, that is, network card failure). In practical applications, in this case, the gateway device generally cannot be immediately replaced and updated, but needs to continue to buffer and store data as a data relay device. Subsequently, when the device is replaced, the buffered reported data is exported and reported to the remote server. In this case, how to safely export the reported data buffered by the gateway device is another problem that needs to be considered. Summary of the Invention

[0003] To solve the problem of possible data leakage when replacing the gateway device in the existing environmental monitoring system, an embodiment of the present disclosure provides a new ecological environment quality monitoring system.

[0004] In a first aspect, an embodiment of the present disclosure provides an ecological environment monitoring system, including a gateway device deployed at a monitoring point and locally connected to the data interfaces of each environmental monitoring device, and a remote server communicatively connected to the gateway device through a communication network;

[0005] When the network interface of the faulty gateway device communicating with the remote server fails and cannot upload the reported data sent by the environmental monitoring device, a replacement gateway device replaces the faulty gateway device to establish a trusted connection with the remote server, and after the non-network interface of the faulty gateway device is connected to the replacement gateway device, the faulty gateway device sends the buffered reported data to the replacement gateway device through the non-network interface, and the replacement gateway device forwards the reported data to the remote server.

[0006] Optionally, before the faulty gateway device forwards the buffered reported data to the replacement gateway device through the non-network interface, it further includes:

[0007] The faulty gateway device generates a verification request message and sends it to the replacement gateway device;

[0008] After receiving the verification request message, the replacement gateway device sends the verification request message to the remote server;

[0009] When the remote server receives the verification request message and determines that the replacement gateway device has passed the remote verification, it generates a return message based on the first dynamic ID and sends the return message to the replacement gateway device; the first dynamic ID is the dynamic ID generated by the remote server and sent to the faulty gateway device when the faulty gateway device was connected to the remote server before the communication failure occurred;

[0010] After receiving the return message, the replacement gateway device sends the return message to the faulty gateway device;

[0011] After receiving the return message, the faulty gateway device verifies whether the first dynamic ID is the same as the dynamic ID stored locally, and if the first dynamic ID is the same as the dynamic ID stored locally, it sends the reported data to the replacement gateway device.

[0012] Optionally, before sending the reported data to the replacement gateway device, the faulty gateway device encrypts the reported data using the target encryption policy to obtain the encrypted reported data; sending the reported data to the replacement gateway device specifically means: sending the encrypted reported data to the replacement gateway device;

[0013] The target encryption policy is an encryption policy that only the remote server has the corresponding decryption policy, or only the remote server and the faulty gateway device have the corresponding decryption policies.

[0014] Optionally, before the faulty gateway device forwards the buffered reported data to the replacement gateway device through a non-network interface, it further includes:

[0015] The replacement gateway device sends a verification request message to the remote server;

[0016] After the remote server receives the verification request message, it generates a return message including the first dynamic ID and sends it to the remote server; the first dynamic ID is the dynamic ID generated by the remote server and sent to the faulty gateway device when the faulty gateway device was connected to the remote server before the communication failure occurred;

[0017] After receiving the return message, the updated gateway device sends the return message to the faulty gateway device;

[0018] When the faulty gateway device verifies that the first dynamic ID of the return message is the dynamic ID stored in itself, it sends the reported data to the replacement gateway device.

[0019] Optionally, the replacement gateway device replaces the faulty gateway device to establish a trusted connection with the remote server, including:

[0020] The replacement gateway device sends its fingerprint information to the remote server;

[0021] After the remote server receives the fingerprint information, it processes the fingerprint information using a private conversion algorithm to obtain the replacement gateway ID, stores the association relationship between the fingerprint information and the replacement gateway ID in a data table, and returns the gateway ID to the replacement gateway device;

[0022] After the replacement gateway device receives the replacement gateway ID, it determines to establish a trusted connection with the remote server.

[0023] Optionally, the replacement gateway device sending its fingerprint information to the remote server includes:

[0024] Encrypt the fingerprint information using a first encryption method to obtain a first encrypted message, and send the first encrypted message to the remote server;

[0025] Before processing the fingerprint information using the private conversion algorithm to obtain the replacement gateway ID, the remote server processes the first encrypted message using a first decryption method that matches the first encryption method to obtain the decrypted fingerprint information;

[0026] Returning the replacement gateway ID to the gateway device includes: obtaining a second encrypted message by using a second encryption method for the replacement gateway ID and sending the second encrypted message to the gateway device;

[0027] After the gateway device receives the second encrypted message, it decrypts the second encrypted message using a second decryption method that matches the second encryption method to obtain the replacement gateway ID.

[0028] Optionally, before the faulty gateway device sends the buffered reported data to the replacement gateway device through a non-network interface, it further includes:

[0029] The replacement gateway device symmetrically encrypts its fingerprint information to obtain a first encrypted fingerprint and sends the first encrypted fingerprint to the faulty gateway device; where the first encrypted fingerprint is obtained by the hardware encryption and decryption chip of the replacement gateway device performing the encryption operation;

[0030] After the faulty gateway device receives the first encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the updated gateway device, it sends the buffered reported data to the replacement gateway device through a non-network interface.

[0031] Optionally, before the faulty gateway device sends the buffered reported data to the replacement gateway device through a non-network interface, it further includes:

[0032] The faulty gateway device symmetrically encrypts its own fingerprint information to obtain a second encrypted fingerprint and sends the second encrypted fingerprint to the replacement gateway device; wherein the second encrypted fingerprint is obtained by the hardware encryption and decryption chip of the faulty gateway device performing the encryption operation;

[0033] After the encryption gateway device receives the second encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the faulty gateway device, it receives the reported data sent by the faulty gateway device.

[0034] Optionally, after the replacement gateway device forwards all the reported data to the remote server and receives the reception success indication information replied by the remote server, the replacement gateway device generates a prompt message.

[0035] Optionally, after the replacement gateway device receives the reception success indication information, it sends the reception success indication information to the faulty gateway device;

[0036] After the faulty gateway device receives the success indication information, it deletes the reported data stored in the local buffer.

[0037] In the ecological environment monitoring system provided by the embodiments of the present disclosure, the gateway device can be connected through a non-network interface, and send the temporarily stored reported data to the replacement gateway device through the non-network interface. Accordingly, the replacement gateway device can also be used as a relay device to forward the reported data to the remote server. In this way, without manual data reading, the storage of the temporarily stored data of the faulty gateway device can be realized, ensuring data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The drawings herein are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.

[0039] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings, where

[0040] Figure 1 is a schematic structural diagram of the ecological environment quality monitoring system provided by the embodiments of the present disclosure;

[0041] Figure 2 is a flowchart of a method for implementing the verification of the replacement gateway device in some embodiments;

[0042] Figure 3 is a flowchart of a method for implementing the verification of the replacement gateway device in other embodiments;

[0043] Figure 4 It is a flowchart of a method for verifying the replacement of a gateway device provided by some embodiments. Specific embodiments

[0044] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not used to limit the protection scope of the present disclosure.

[0045] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. In this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0046] Figure 1 It is a schematic structural diagram of an ecological environment quality monitoring system provided by an embodiment of the present disclosure. As Figure 1 shown, the ecological environment quality monitoring system 100 provided by the embodiment of the present disclosure includes an environmental monitoring device 101, a gateway device 102, and a remote server 103.

[0047] Both the aforementioned environmental monitoring device 101 and the gateway device 102 are local devices deployed at environmental monitoring points. In a specific implementation, multiple different types of environmental monitoring devices 101 and one gateway device 102 can be deployed at one environmental monitoring point. The monitoring device connection interface of the aforementioned gateway device 102 is connected to the data IO interfaces of each environmental monitoring device 101, and data transmission with each environmental monitoring device 101 is achieved through a local communication link.

[0048] Each environmental monitoring device 101 can be connected in series with the gateway device 102 (that is, only one environmental monitoring device 101 is directly connected to the gateway device 102, and other environmental monitoring devices 101 communicate with the gateway device 102 through the aforementioned environmental monitoring device 101), or can be connected in parallel with the gateway device 102 (that is, each environmental monitoring device 101 is respectively connected to the gateway device 102 through an independent monitoring device connection interface). The embodiments of the present disclosure do not make any limitations. In some embodiments, the gateway device 102 and the environmental monitoring device 101 can also be connected by a short-range wireless communication method on the premise of ensuring data communication security and reliability.

[0049] In the embodiments of the present disclosure, the gateway device 102 does not have the function of directly controlling the environmental monitoring device 101, that is, no monitoring device control software for directly controlling the environmental monitoring device 101 is installed in the gateway device 102.

[0050] The remote server 103 is a server that is not deployed at the environmental monitoring point, but is installed with monitoring device control software. The remote server 103 can send control instructions to the environmental monitoring device 101 through network communication and receive the reported data reported by the environmental monitoring device 101. In specific implementation, the remote server 103 is mostly deployed in the server room of the environmental supervision entity.

[0051] As Figure 1 shown, in the embodiments of the present disclosure, the remote server 103 is not directly connected to the aforementioned environmental monitoring device 101, but is indirectly connected to the environmental monitoring device 101 through the gateway device 102. Specifically, the gateway device 102, as an intermediate communication device, forwards the control instructions sent by the remote server 103 to the corresponding environmental monitoring device 101, and reports various reported data output by the environmental monitoring device 101 to the remote server 103.

[0052] In specific implementation, when the network card device or interface in the gateway device that communicates with the remote server 103 is damaged and cannot send the reported data to the remote server, and the reported data can only be buffered and stored in the local cache, the forwarding and uploading of the reported data can be realized through the solution of the embodiments of the present disclosure.

[0053] For convenience, the aforementioned gateway device with a damaged network card device or interface is called a faulty gateway device, and the replacement gateway device is called a replacement gateway device.

[0054] In specific implementation, when no reporting message sent by a certain gateway device is received within a certain set duration (for example, continuously for 2 hours), it can generally be determined that the aforementioned gateway device has failed, that is, a faulty gateway device has occurred. In this case, the device operation and maintenance personnel will go to the corresponding environmental monitoring points for on-site device maintenance and replace the faulty gateway device with a replacement gateway device.

[0055] After replacing the faulty gateway device with a replacement gateway device (specifically, after connecting the network interface of the replacement gateway device to the communication network), the replacement gateway device can establish a trusted connection with the remote server based on the internal configuration data and firmware program. In addition, after replacing the faulty gateway device with a replacement gateway device, the operation and maintenance personnel will also connect the non-network interfaces of the faulty gateway device and the replacement gateway device, so that the faulty gateway device can send the buffered reporting data to the replacement gateway device through the non-network interface; correspondingly, the replacement gateway device will send the reporting data to the remote server, so that the remote server can obtain the environmental monitoring data during the network communication failure stage of the faulty gateway device.

[0056] As analyzed above, in the ecological environment monitoring system provided by the embodiments of the present disclosure, the gateway device can connect through the non-network interface and send the temporarily stored reporting data to other gateway devices through the non-network interface. Correspondingly, the other gateway devices can also act as relay devices to forward the reporting data to the remote server. In this way, without manual data reading, the storage of the temporarily stored data of the faulty gateway device can be realized, ensuring the security of the data.

[0057] In specific implementation, there may be a problem that the aforementioned replacement gateway device is a cracked gateway device or an illegal gateway device. In this case, the reporting data sent by the faulty gateway device to the replacement gateway device may have the risk of being leaked. To solve this problem, it is necessary to verify that the replacement gateway device is a legally authenticated secure network device.

[0058] Figure 2 It is a flowchart of a method for implementing the verification of the replacement gateway device in some embodiments. As Figure 2 shown, in some embodiments, the ecological environment monitoring system uses the following S110 - S150 to enable the faulty gateway device to determine whether the replacement gateway device is a legal device.

[0059] S110: The faulty gateway device generates a verification request message and sends it to the replacement gateway device.

[0060] The verification request message is sent by the faulty gateway device to the remote server and is used to verify whether the replacement gateway device is legal. The verification request message mentioned here can be a plaintext message or a ciphertext message, and the embodiments of the present disclosure do not make any limitations.

[0061] S120: After receiving the authentication request message, the replacement gateway device sends the authentication request message to the remote server.

[0062] S130: When the remote server receives the authentication request message and determines that the replacement gateway device has passed the remote authentication, it generates a return message based on the first dynamic ID and sends the return message to the replacement gateway device.

[0063] The first dynamic ID is a dynamic ID generated and sent by the remote server to the faulty gateway device when the faulty gateway device is connected to the remote server before the communication of the faulty gateway device fails. The first dynamic ID is an ID known only to the remote server and the faulty gateway device. It should be noted here that since the faulty gateway device has disconnected its network connection with the remote server and the remote server cannot obtain its heartbeat signal, it will not use the first dynamic ID as a legal and available authentication ID, but only stores the first dynamic ID as historical data. Even if other gateway devices obtain the first dynamic ID, they cannot forge and replace the faulty gateway device to access the network. Correspondingly, the first dynamic ID can be transmitted in plain text or in cipher text, which is not limited in the embodiments of the present disclosure.

[0064] S140: After receiving the return message, the replacement gateway device sends the return message to the faulty gateway device.

[0065] S150: After receiving the return message, the faulty gateway device verifies whether the first dynamic ID is the same as the dynamic ID stored locally.

[0066] After the faulty gateway device receives the return message, it verifies whether the first dynamic ID is the same as the dynamic ID stored locally. If they are the same, it indicates that the first dynamic ID is sent by the remote server, and correspondingly, the replacement gateway device has passed the authentication of the remote server; at this time, the reported data can be sent to the replacement gateway device. If the first dynamic ID is different from the dynamic ID stored locally, it indicates that the received first dynamic ID is a forged dynamic ID, so the reported data will not be sent to the replacement gateway device.

[0067] Figure 3 is a flowchart of a method for implementing the verification of the replacement gateway device in other embodiments. As Figure 3 shown, in some embodiments, the ecological environment monitoring system uses the following S210 - S240 to enable the faulty gateway device to determine whether the replacement gateway device is a legal device, and further determine whether to send the reported data to the replacement gateway device.

[0068] S210: The replacement gateway device sends an authentication request message to the remote server.

[0069] In the embodiments of the present disclosure, the verification request message is actively generated by the replacement gateway device and sent to the remote server, rather than being actively generated by the faulty gateway device as in the previous embodiments.

[0070] S220: After the remote server receives the verification request message, a return message including the first dynamic ID is generated and sent to the remote server.

[0071] The first dynamic ID is the dynamic ID generated and sent by the remote server to the faulty gateway device when it was connected to the remote server before the communication of the faulty gateway device failed. The first dynamic ID is an ID known only to the remote server and the faulty gateway device. It should be noted here that since the faulty gateway device has disconnected its network connection with the remote server and the remote server cannot obtain its heartbeat signal, it will not use the first dynamic ID as a legitimate and available verification ID, but only stores the first dynamic ID as historical data. Even if other gateway devices obtain the first dynamic ID, they cannot forge and replace the faulty gateway device to access the network.

[0072] S230: After the replacement gateway device receives the return message, it sends the return message to the faulty gateway device.

[0073] S240: The faulty gateway device verifies whether the first dynamic ID is the same as the dynamic ID stored locally.

[0074] After the faulty gateway device receives the return message, it verifies whether the first dynamic ID is the same as the dynamic ID stored locally. If they are the same, it indicates that the first dynamic ID is sent by the remote server and the corresponding replacement gateway device has passed the authentication of the remote server; at this time, the reported data can be sent to the replacement gateway device. If the first dynamic ID is different from the dynamic ID stored locally, it indicates that the received first dynamic ID is a forged dynamic ID, so the reported data will not be sent to the replacement gateway device.

[0075] In specific implementation, the faulty gateway device generates a reported message based on the reported data and then sends the reported message to the replacement gateway device.

[0076] In practical applications, it may occur that the faulty gateway device is an illegal device, but it disguises itself as a legal device and passes the verification of the remote server. In this case, to ensure the security of the reported message, the faulty gateway device first encrypts the reported data using the target encryption policy to obtain the encrypted reported data; then it forms a reported message with the encrypted reported data and sends it to the replacement gateway device.

[0077] The foregoing target encryption policy is an encryption policy in which only the remote server has the corresponding decryption policy, or only the remote server and the failed gateway device have the corresponding decryption policy. For example, the failed server can encrypt the reported data using the public key of the remote server. In this case, only the remote server can decrypt the encrypted data. For another example, the failed server can encrypt the reported data using a symmetric encryption key, and only the failed gateway device and the remote server know the foregoing symmetric encryption key.

[0078] In the foregoing solution, after the gateway device is replaced and a trusted connection with the remote server is established, the foregoing verification operation can be performed. Figure 4 It is a flowchart of a method for verifying the replacement of the gateway device provided by some embodiments. As Figure 4 shown, the ecological environment monitoring system implements the verification of the replaced gateway device by the following S310-S330. S310: The replaced gateway device sends its own fingerprint information to the remote server.

[0079] The fingerprint information is information characterizing the identity of the replaced gateway device. In specific implementation, the fingerprint information can be a unique identifier such as the MAC address of the replaced gateway device, or an identification information generated using the foregoing unique identifier, and can also include temporarily assigned identification information such as a dynamic IP address. In specific implementation, the replaced gateway device can generate fingerprint information based on, for example, the foregoing MAC address by executing a fingerprint generation program.

[0080] After generating the fingerprint information, the replaced gateway device sends the fingerprint information to the server. In specific implementation, to ensure the security of the fingerprint information, the replaced gateway device encrypts the fingerprint information using an encryption algorithm (the first encryption means) to obtain the encrypted fingerprint information. In specific implementation, the replaced gateway device can encrypt the fingerprint information using an asymmetric encryption algorithm, that is, encrypt the fingerprint information using the public key of the remote server.

[0081] After receiving the fingerprint information, the remote server executes S320.

[0082] S320: Process the fingerprint information using a private conversion algorithm to obtain the replaced gateway ID, store the association relationship between the fingerprint information and the replaced gateway ID in a data table, and return the gateway ID to the replaced gateway device.

[0083] The private conversion algorithm is a conversion algorithm held only by the remote server, that is, only the remote server can determine the corresponding gateway ID based on the fingerprint information, and other devices cannot determine the gateway ID based on the fingerprint information. After the remote server obtains the gateway ID, it will store the gateway ID and the corresponding fingerprint information in a relational data table for verifying the legality of subsequent reported messages.

[0084] As analyzed above, in the case where the gateway device is replaced and the fingerprint information is encrypted to obtain the encrypted fingerprint information, the remote server first decrypts the encrypted fingerprint information (specifically, decrypts it using the first decryption method opposite to the first encryption method), obtains the decrypted fingerprint information, and then obtains the replaced gateway ID based on the decrypted fingerprint information. Corresponding to the case where the public key of the remote server is used to encrypt the fingerprint information, the remote server uses its own private key to decrypt the encrypted fingerprint information.

[0085] Similarly, to ensure the security of the replaced gateway ID, in specific implementation, the remote server encrypts the replaced gateway ID (using the second encryption method), and then sends the encrypted replaced gateway ID to the gateway replacement device. For example, the public key of the gateway replacement device is used to encrypt the gateway ID (using the second decryption method opposite to the second encryption method), and then the encrypted ID is sent to the gateway replacement device.

[0086] After the gateway replacement device receives the replaced gateway ID, the gateway replacement device executes S330.

[0087] S330: After the gateway replacement device receives the replaced gateway ID, it determines to establish a trusted connection with the remote server.

[0088] Based on the aforementioned replaced gateway ID, the gateway replacement device can determine a trusted connection with the remote server. Specifically, for the gateway replacement device to establish a trusted connection with the remote server, it generates a reporting message based on the replaced gateway ID, fingerprint information, and the reporting data sent by the environmental monitoring device, and then sends the reporting message to the remote server.

[0089] As mentioned above, the remote server uses a private conversion algorithm to process the fingerprint information to obtain the replaced gateway ID. In specific implementation, the remote server can obtain the replaced gateway ID through the following S321 - S322.

[0090] S321: Process the fingerprint information based on the private conversion algorithm to obtain a random private key.

[0091] S322: Generate a corresponding encrypted public key based on the random private key, and use the encrypted public key as the replaced gateway ID.

[0092] In specific implementation, to process the fingerprint information based on the private conversion algorithm to obtain a random key, a random number generation algorithm can be used to generate a random number using the fingerprint information to obtain the private key. Or, the remote server assigns a random number to the fingerprint information as the corresponding random private key. After obtaining the random private key, the remote server can process the random private key according to the asymmetric encryption algorithm used to obtain the encrypted public key, and use the encrypted public key as the replaced gateway ID.

[0093] In the case of using the aforementioned encryption public key as the replacement gateway ID, after the replacement gateway device obtains the aforementioned replacement gateway ID, the replacement gateway ID encrypts the fingerprint information and the received forwarded report data based on the replacement gateway ID to obtain an encrypted message, and adds the fingerprint information to the header of the encrypted message; subsequently, the message is used as a report message to send the encrypted message to the remote server. That is to say, the replacement gateway ID serves as the encryption public key for encrypting the fingerprint information and the report message. In this case, only the remote server holding the random private key can decrypt the encrypted message.

[0094] As mentioned above, after the replacement gateway device and the faulty gateway device are connected through a non-network interface, data can be transmitted between them. In practical applications, to ensure data security and prevent other devices masquerading as gateway devices from establishing connections with the faulty gateway device and obtaining data. Before transmitting the aforementioned report data between the two, it is also necessary to authenticate the replacement gateway device. Specifically, it includes the following S410 - S420.

[0095] S410: The replacement gateway device symmetrically encrypts its own fingerprint information to obtain a first encrypted fingerprint and sends the first encrypted fingerprint to the faulty gateway device.

[0096] S420: After the faulty gateway device receives the first encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the replacement gateway device, it sends the buffered report data to the replacement gateway device through the non-network interface.

[0097] The aforementioned first encrypted fingerprint is obtained by the hardware encryption and decryption chip of the replacement gateway device performing the encryption operation. Similarly, the faulty gateway device needs to use the decryption program on its own hardware encryption chip to decrypt the first encrypted fingerprint to obtain the corresponding decrypted information. Only by cracking the aforementioned hardware encryption chip is it possible to crack the aforementioned verification method. And it is very difficult to break the hardware encryption chip, so using the aforementioned verification method can ensure that the replacement gateway device is authenticated by the faulty gateway device.

[0098] Similar to the method described above, the replacement gateway device can also authenticate the faulty gateway device before receiving the report message including the report data forwarded by it. Specifically, it includes the following S430 - S440.

[0099] S430: The faulty gateway device symmetrically encrypts its own fingerprint information to obtain a second encrypted fingerprint and sends the second encrypted fingerprint to the replacement gateway device.

[0100] S440: After the encryption gateway device receives the second encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the faulty gateway device, it receives the report data sent by the faulty gateway device.

[0101] In specific implementation, through the method described above, the faulty gateway device can successfully send the reported data to the remote server. After all the reported data has been sent, the faulty gateway device sends a message including a data sending completion flag to the replacement gateway device; correspondingly, the replacement gateway device forwards the aforementioned message including the data sending completion flag to the remote server. After determining that the reported data has been received, the remote server generates a reception success indication message and sends it to the replacement gateway device. After receiving the success indication message, the replacement gateway device generates a corresponding prompt message through its own hardware device and prompts that the data has been transmitted and the connection with the faulty gateway device can be disconnected.

[0102] In some embodiments, after receiving the success prompt message, the replacement gateway device also sends the success prompt message to the faulty gateway device. After receiving the success indication message, the faulty gateway device deletes the reported data stored in its local buffer to prevent other people from obtaining the aforementioned data later.

[0103] The communication connection between the replacement gateway device and the remote server was mentioned above. In specific implementation, to achieve decoupling between the two, a topic-subscription mechanism can be adopted between the replacement gateway device and the remote server, and a proxy service is used to implement data transmission. Specifically, the replacement gateway device publishes the corresponding reported data to the corresponding publish topic, and the remote server obtains the reported data by subscribing to the corresponding topic; similarly, the remote server publishes the corresponding instructions or data to its own publish topic, and the replacement gateway device obtains the aforementioned instructions or data by subscribing to the corresponding topic. The above are only specific implementation manners of the present disclosure to enable those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An ecological environment monitoring system, characterized in that, It includes a gateway device deployed at a monitoring point and locally connected to the data interfaces of various environmental monitoring devices, and a remote server communicatively connected to the gateway device through a communication network; When the network interface for the faulty gateway device to communicate with the remote server fails and the reported data sent by the environmental monitoring device cannot be uploaded, a replacement gateway device is used to replace the faulty gateway device to establish a trusted connection with the remote server. After the non-network interface of the faulty gateway device is connected to the replacement gateway device, the faulty gateway device sends the buffered reported data to the replacement gateway device through the non-network interface, and the replacement gateway device forwards the reported data to the remote server; Before the faulty gateway device forwards the buffered reported data to the replacement gateway device through the non-network interface, it further includes: The faulty gateway device generates a verification request message and sends it to the replacement gateway device; After receiving the verification request message, the replacement gateway device sends the verification request message to the remote server; When the remote server receives the verification request message and determines that the replacement gateway device has passed the remote verification, it generates a return message based on the first dynamic ID and sends the return message to the replacement gateway device; the first dynamic ID is the dynamic ID generated and sent by the remote server to the faulty gateway device when the faulty gateway device was connected to the remote server before the communication failure; After receiving the return message, the replacement gateway device sends the return message to the faulty gateway device; After receiving the return message, the faulty gateway device verifies whether the first dynamic ID is the same as the locally stored dynamic ID, and when the first dynamic ID is the same as the locally stored dynamic ID, it sends the reported data to the replacement gateway device.

2. The monitoring system according to claim 1, wherein Before sending the reported data to the replacement gateway device, the faulty gateway device encrypts the reported data using a target encryption policy to obtain encrypted reported data; sending the reported data to the replacement gateway device specifically means: sending the encrypted reported data to the replacement gateway device; Where the target encryption policy is an encryption policy that only the remote server has the corresponding decryption policy, or only the remote server and the faulty gateway device have the corresponding decryption policy.

3. The monitoring system according to claim 1, characterized in that, Before the faulty gateway device forwards the buffered reported data to the replacement gateway device through the non-network interface, it further includes: The replacement gateway device sends a verification request message to the remote server; After the remote server receives the verification request message, it generates a return message including the first dynamic ID and sends it to the remote server; the first dynamic ID is the dynamic ID generated and sent by the remote server to the faulty gateway device when the faulty gateway device was connected to the remote server before the communication failure; After receiving the return message, the updated gateway device sends the return message to the faulty gateway device; When the faulty gateway device verifies that the first dynamic ID of the return message is the locally stored dynamic ID, it sends the reported data to the replacement gateway device.

4. The monitoring system according to any one of claims 1-3, characterized in that, The replacement gateway device replaces the faulty gateway device to establish a trusted connection with the remote server, including: The replacement gateway device sends its own fingerprint information to the remote server; After the remote server receives the fingerprint information, it processes the fingerprint information using a private conversion algorithm to obtain a replacement gateway ID, stores the association relationship between the fingerprint information and the replacement gateway ID in a data table, and returns the gateway ID to the replacement gateway device; After the replacement gateway device receives the replacement gateway ID, it determines to establish a trusted connection with the remote server.

5. The monitoring system according to claim 4, characterized in that, The replacement gateway device sends its own fingerprint information to the remote server, including: encrypting the fingerprint information using a first encryption method to obtain a first encrypted message, and sending the first encrypted message to the remote server; Before processing the fingerprint information using the private conversion algorithm to obtain the replacement gateway ID, the remote server processes the first encrypted message using a first decryption method that matches the first encryption method to obtain the decrypted fingerprint information; returning the replacement gateway ID to the gateway device, including: obtaining a second encrypted message by using a second encryption method for the replacement gateway ID, and sending the second encrypted message to the gateway device; After the gateway device receives the second encrypted message, it decrypts the second encrypted message using a second decryption method that matches the second encryption method to obtain the replacement gateway ID.

6. The monitoring system according to any one of claims 1 to 3, characterized in that, Before the faulty gateway device sends the buffered reported data to the replacement gateway device through a non-network interface, it further includes: The replacement gateway device symmetrically encrypts its own fingerprint information to obtain a first encrypted fingerprint and sends the first encrypted fingerprint to the faulty gateway device; wherein the first encrypted fingerprint is obtained by the hardware encryption and decryption chip of the replacement gateway device performing the encryption operation; After the faulty gateway device receives the first encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the replacement gateway device, it sends the buffered reported data to the replacement gateway device through a non-network interface.

7. The monitoring system according to claim 6, wherein, Before the faulty gateway device sends the buffered reported data to the replacement gateway device through a non-network interface, it further includes: The faulty gateway device symmetrically encrypts its own fingerprint information to obtain a second encrypted fingerprint and sends the second encrypted fingerprint to the replacement gateway device; wherein the second encrypted fingerprint is obtained by the hardware encryption and decryption chip of the faulty gateway device performing the encryption operation; After the encrypted gateway device receives the second encrypted fingerprint and decrypts it using its own hardware encryption chip to obtain the fingerprint information of the faulty gateway device, it receives the reported data sent by the faulty gateway device.

8. The monitoring system according to any one of claims 1 to 3, characterized in that, After the replacement gateway device forwards all the reported data to the remote server and receives the reception success indication information replied by the remote server, the replacement gateway device generates a prompt message.

9. The monitoring system according to claim 8, wherein After the replacement gateway device receives the reception success indication information, it sends the reception success indication information to the faulty gateway device; After the faulty gateway device receives the success indication information, it deletes the reported data stored in the local buffer.

Citation Information

Patent Citations

  • Network fault automatic transfer method based on star networking LPWAN gateway

    CN118018392A