A photovoltaic terminal data transmission protection method and system based on trusted computing

By building a trusted computing framework at the photovoltaic system terminal and establishing a trust chain using trusted digital identity chips and proxy modules, the security issues of data transmission at the photovoltaic system terminal are solved, and the security and stability of the system are improved.

CN119834997BActive Publication Date: 2025-10-10GUIZHOU POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411662469.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-10-10
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

Existing technologies lack effective security protection in photovoltaic system terminal data transmission, making it difficult to cope with attacks, which affects system stability and security.

Method used

Trusted computing technology is used to build a terminal protection framework, including user space, kernel space, monitoring space and hardware space, and a trust chain is established using trusted digital identity chips and agent modules to ensure the security and integrity of data transmission.

Benefits of technology

By building a terminal protection framework for trusted computing, the overall security performance of the photovoltaic system is improved, ensuring the reliability of data transmission and the stable operation of the system, reducing resource usage, and is suitable for terminal devices with limited resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119834997B_ABST
    Figure CN119834997B_ABST
Patent Text Reader

Abstract

The application discloses a photovoltaic terminal data transmission protection method and system based on trusted computing, which comprises the following steps: constructing a terminal protection framework based on trusted technology, wherein the terminal protection framework comprises a user space, a kernel space, a monitoring space and a hardware space; the user space interacts with a user and exchanges data with the kernel space; the kernel space calls and allocates data resources according to a safety evaluation result of the monitoring space; and the hardware space provides underlying support services for other spaces to realize transmission protection of photovoltaic terminal data. The application creates a safe trusted space in a photovoltaic system terminal and a terminal device trusted chain, ensures high trustworthiness of a terminal system in a data transmission process, improves the overall safety performance of the photovoltaic system, and stores all safety strategies in a special database of a trusted digital identity chip, so that the terminal system memory resources are not occupied, and a plurality of trusted functions can be provided under the condition of a terminal device with limited resources.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network data security, and in particular to a photovoltaic terminal data transmission protection method and system based on trusted computing. BACKGROUND

[0002] It is well known that the traditional coal reserves for power generation are limited, and the harm to the environment is increasingly prominent, at the same time, the supply of electric power energy still cannot meet the needs, in recent years, with the continuous development of science and technology and the protection of the environment, the whole world has turned its attention to renewable energy, among which solar energy as cheap and inexhaustible energy, and its zero-pollution characteristics is expected to change the energy structure of human beings. The domestic photovoltaic power generation industry has ushered in a new stage of rapid development, in 2022, the newly added photovoltaic power generation capacity in China reached 87.41GW, and it is estimated that by 2050, the renewable energy power installation in China will account for 25% of the national power installation. Nowadays, there is a trend of intelligentization in power grid, and the basic functions such as operation and management of photovoltaic system also tend to be intelligent, which requires a large amount of data for analysis, and once these terminal data are tampered with or attacked, it will seriously affect the normal operation of the photovoltaic system.

[0003] At present, the conventional security protection means often lacks coverage in the terminal part, and it is difficult to deal with attacks on the terminal. Trusted computing technology fundamentally improves the system security. Trusted computing is a technical innovation from logical correctness verification, computing architecture and computing mode, etc. to solve the problem that logical defects are not used by attackers, form the unity of attack and defense contradiction, and ensure that security protection can realize full coverage. In summary, how to build a terminal data security protection system for photovoltaic system is a key to maintain the stable operation of photovoltaic system. SUMMARY

[0004] This section aims to summarize some aspects of the embodiments of the present application and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the abstract and title of the specification to avoid obscuring the purpose of this section, abstract and title, and such simplifications or omissions cannot be used to limit the scope of the present application.

[0005] In view of the above existing problems, the present application is proposed.

[0006] Therefore, the present application provides a photovoltaic terminal data transmission protection method and system based on trusted computing to solve the problems mentioned in the background art.

[0007] To solve the above technical problems, the present application provides the following technical solutions:

[0008] The first aspect, the embodiment of the present application provides a photovoltaic terminal data transmission protection method based on trusted computing, comprising: constructing a terminal protection framework based on trusted technology, wherein the terminal protection framework comprises a user space, a kernel space, a monitoring space and a hardware space;

[0009] The user space comprises a normal execution space and a trusted execution space, wherein the normal execution space and the trusted execution space interact with the user and interact with the kernel space for data interaction;

[0010] The kernel space cooperates with the monitoring space, and the kernel space calls and allocates data resources according to the security evaluation result of the monitoring space;

[0011] The hardware space provides underlying support services for the other spaces to realize the transmission protection of photovoltaic terminal data.

[0012] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, the monitoring space comprises a proof agent module, a measurement agent module and an electric energy management service; the hardware space comprises a photovoltaic system hardware and a trusted digital identity chip; and the kernel space comprises a thread management, a file management, a system call and an inter-process communication.

[0013] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, the user space further comprises a normal execution space and a trusted execution space which are separated from each other; the normal execution space contains normal application programs; the trusted execution space contains a plurality of trusted applications and a trusted service module; and the trusted service module is used for providing a security management function.

[0014] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, the kernel space calling and allocating data resources according to the security evaluation result of the monitoring space comprises: when any terminal transmits data with a photovoltaic system, the terminal is authenticated according to the agent module in the monitoring space, a measurement root is generated and uploaded to a trusted service platform;

[0015] The trusted service platform provides an access interface with the trusted computing chip, the agent module initiates an access photovoltaic system to establish a transmission channel request to the trusted digital identity chip through the access interface, and after the trusted platform module verifies the request, the terminal device is allocated a specific channel to establish a transmission link and perform data transmission.

[0016] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, wherein: the authentication based on the agent module in the monitoring space comprises: the agent module is a proof agent module and a measurement agent module;

[0017] The proof agent module is used for judging whether the device is attacked in the physical layer, and confirming that the terminal device is not tampered or forged; and the measurement agent module is used for being responsible for the integrity of the terminal device, and calculating and submitting the measurement root.

[0018] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, wherein: further comprising:

[0019] When the terminal device is running, the proof agent module confirms that the physical layer of the device is not tampered or forged by asking for a device certificate from a trusted third party, generates a device identity proof report, and provides the report to the server.

[0020] When a user side requests to access the system, the measurement agent module performs integrity checking on the terminal device based on the report of the integrity of the terminal device as a link in the trust chain, generates a measurement report, and participates in the establishment of the trusted chain.

[0021] As a preferred scheme of the photovoltaic terminal data transmission protection method based on trusted computing, wherein: the authentication of the trusted service platform comprises: the trusted service module establishes and manages a complete trust chain based on a trusted digital identity chip, the trusted digital identity chip comprises a hardware module and a control module; the hardware module at least comprises a policy implementation component, a policy judgment component and a storage component; and the control module is responsible for coordinating the cooperative operation among the components.

[0022] The trusted service module provides an interactive interface for the terminal device, and access permission for the trusted computing function of the trusted digital identity chip; after the trusted digital identity chip receives the authentication request sent by the agent module and the measurement root generated by the agent, the terminal device is authorized to prove its own trustworthiness by comparing the trusted root, and after the proof is completed, the trusted service module allows the terminal device to use the assigned channel to perform data transmission with the photovoltaic system, and generates a log and saves the log to a database.

[0023] In a second aspect, the application provides a photovoltaic terminal data transmission protection system based on trusted computing, comprising:

[0024] A framework building module is configured to build a terminal protection framework based on trusted technology, and the terminal protection framework comprises a user space, a kernel space, a monitoring space and a hardware space.

[0025] A user space module, wherein the user space comprises a normal execution space and a trusted execution space, the normal execution space and the trusted execution space interact with a user and exchange data with the kernel space;

[0026] A kernel and monitoring space module, wherein the kernel space cooperates with the monitoring space, and the kernel space calls for allocation of data resources according to a security evaluation result of the monitoring space;

[0027] A hardware space module, wherein the hardware space provides underlying support services for the other spaces to realize transmission protection of photovoltaic terminal data.

[0028] In a third aspect, the present application provides a computing device, comprising:

[0029] a memory and a processor;

[0030] The memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions, so as to realize the steps of the photovoltaic terminal data transmission protection method based on trusted computing.

[0031] In a fourth aspect, the present application provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are executed by a processor to realize the steps of the photovoltaic terminal data transmission protection method based on trusted computing.

[0032] Compared with the prior art, the present application has the following beneficial effects: the present application uses trusted computing technology to create a secure trusted space in a photovoltaic system terminal, and constructs a reliable terminal device trusted chain by using a proxy module, so as to ensure high trustworthiness of the terminal system during data transmission and improve the overall security performance of the photovoltaic system. In addition, all security policies are stored in a special database of a trusted digital identity chip, so that the terminal system memory resources are not occupied, and a variety of trusted function targets can be provided under the condition of limited resources of the terminal device, so as to ensure stable operation of the photovoltaic system. BRIEF DESCRIPTION OF DRAWINGS

[0033] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor. Among them:

[0034] Fig. 1 A photovoltaic terminal protection framework schematic diagram of a photovoltaic terminal data transmission protection method and system based on trusted computing according to an embodiment of the present application;

[0035] Fig. 2 A terminal device data transmission flowchart of a photovoltaic terminal data transmission protection method and system based on trusted computing according to an embodiment of the present application;

[0036] Fig. 3 A trusted platform module authentication flowchart of a photovoltaic terminal data transmission protection method and system based on trusted computing according to an embodiment of the present application. DETAILED DESCRIPTION

[0037] In order to make the above objectives, features and advantages of the present application more apparent, specific embodiments of the present application will be described in detail below with the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the protection scope of the present application.

[0038] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application. However, the present application can be implemented in other different manners than those described herein, and those skilled in the art can make similar generalizations without departing from the spirit and scope of the present application. Therefore, the present application is not limited to the specific embodiments disclosed below.

[0039] Secondly, the "one embodiment" or "embodiment" referred to herein can include specific features, structures or characteristics contained in at least one implementation of the present application. The "in one embodiment" appearing in different places in the specification does not refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments.

[0040] The present application is described in detail in conjunction with the schematic diagram. In the detailed description of the embodiments of the present application, the cross-sectional view of the device structure is locally enlarged without the general proportion for the convenience of description, and the schematic diagram is only an example, which should not limit the scope of protection of the present application herein. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in actual manufacture.

[0041] Meanwhile, in the description of the present application, it should be noted that the terms "up, down, in and out" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the indicated device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first, second or third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance.

[0042] Unless otherwise defined, the terms "mounting, connecting, associating" in the present application should be interpreted broadly, for example: it can be fixed connection, detachable connection or integral connection; it can also be mechanical connection, electrical connection or direct connection, it can also be indirectly connected through intermediate medium, or it can be the internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0043] Embodiment 1

[0044] Reference Figs. 1-3 For an embodiment of the present application, the embodiment provides a photovoltaic terminal data transmission protection method based on trusted computing. It should be noted that there is a large amount of data transmission in the photovoltaic system terminal, and these data may contain a lot of critical information. Once leaked, it will affect the normal operation of the system or even make it unable to operate normally. However, there are relatively few special protection schemes for photovoltaic system terminal devices at present, and there are various means to attack them, which makes these devices easy targets for malicious attacks, which may eventually lead to data leakage, malicious tampering or service interruption and a series of problems. The present application ensures the security of photovoltaic terminal data by means of trusted computing technology.

[0045] The current security protection means has a variety of vulnerability problems in the field of terminal data transmission protection. For the security problem of photovoltaic system terminal data transmission, the present application improves the existing photovoltaic system terminal framework, adds a trusted digital identity chip, a proof agent module, a measurement agent module and the like, and separates the normal execution environment NEE and the trusted execution environment TEE, as shown in Fig. 1 , which includes:

[0046] S100: Construct a terminal protection framework based on trusted technology. The terminal protection framework includes user space, kernel space, monitoring space and hardware space.

[0047] S200: The user space includes a normal execution space and a trusted execution space. The normal execution space and the trusted execution space interact with the user and interact with the kernel space.

[0048] S300: The kernel space works cooperatively with the monitoring space. The kernel space calls and allocates data resources according to the safety evaluation result of the monitoring space.

[0049] S400: The hardware space provides underlying support services for other spaces to realize the transmission protection of photovoltaic terminal data.

[0050] It should be noted that the application uses trusted computing technology to create a secure trusted space in the photovoltaic system terminal, and to build a reliable terminal device trusted chain by using a proxy module, thereby ensuring the high trustworthiness of the terminal system during data transmission and improving the overall security performance of the photovoltaic system. In addition, all security policies are stored in a special database of the trusted digital identity chip, which does not occupy terminal system memory resources, and can provide a variety of trusted function targets under the condition of limited terminal device resources, thereby ensuring stable operation of the photovoltaic system.

[0051] In the embodiment of the application, the monitoring space includes a proof agent module, a measurement agent module and an electric energy management service; the hardware space includes photovoltaic system hardware and a trusted digital identity chip; and the kernel space includes thread management, file management, system call and inter-process communication.

[0052] In the embodiment of the application, the user space further includes: a common execution space and a trusted execution space separated from each other; the common execution space contains common application programs; the trusted execution space contains a plurality of trusted applications and a trusted service module; and the trusted service module is used to provide security management functions such as authorization management, device management, key management, signature verification and secure storage.

[0053] It should be noted that the terminal protection framework is composed of a plurality of spaces, the user space provides an interface for interaction, and the common execution space and the trusted execution space are separated; the kernel space is responsible for resource management, and reasonable calling of resources improves efficiency; the monitoring space manages stable operation of the terminal device and judges the security of the device; and the hardware space provides underlying support services for other spaces. Through the cooperative operation of the above several modules, the protection needs of terminal data transmission can be met.

[0054] In the embodiment of the application, the kernel space calls and allocates data resources according to the safety evaluation result of the monitoring space, including: when any terminal transmits data with the photovoltaic system, the terminal is authenticated according to the agent module in the monitoring space, a measurement root is generated and uploaded to a trusted service platform;

[0055] The trusted service platform provides an access interface with the trusted computing chip, the agent module initiates a request for accessing the photovoltaic system to the trusted digital identity chip through the access interface to establish a transmission channel, and after the trusted platform module verifies the request, the terminal device is allocated a specific channel to establish a transmission link for data transmission.

[0056] Specifically, as shown in Fig. 2 Before any terminal transmits data with the photovoltaic system, the authentication step of the terminal through the agent module in the monitoring space is as follows:

[0057] A1: The terminal device first sends an authentication request to the trusted service module through the attestation agent module and the measurement agent module to prove its identity and integrity. The trusted service module decides whether to grant access rights based on the information received.

[0058] A2: If the authentication is successful, the trusted service module will allocate a specific channel for the terminal device and establish a data transmission link.

[0059] A3: The terminal device sends data to the photovoltaic system through the designated channel.

[0060] A4: After receiving the data, the photovoltaic system processes it accordingly based on business needs.

[0061] A5: After data transmission is completed, the trusted service module will generate a log and save it to the database to record key operations for subsequent troubleshooting and security audits.

[0062] In an embodiment of the present application, authentication is performed according to the agent modules in the monitoring space, and a measurement root is generated and uploaded to the trusted service platform, including: the agent modules are a certification agent module and a measurement agent module;

[0063] The proof agent module is used to determine whether the device has been attacked at the physical level and confirm that the terminal device has not been tampered with or forged; the measurement agent module is responsible for the integrity of the terminal device itself, and calculates and submits the measurement root.

[0064] In the embodiment of the present application, it also includes:

[0065] When the terminal device is running, the authentication agent module verifies that the physical layer of the device has not been tampered with or forged by requesting the device certificate from a trusted third party, generates a device identity authentication report, and provides it to the server;

[0066] When a user requests to access the system, the measurement agent module performs an integrity check on the terminal device based on its own integrity report as a link in the trust chain, and generates a measurement report to participate in the establishment of the trust chain.

[0067] Furthermore, as the starting point of the trust chain, the proof agent module and the measurement agent module can transform the space mode from the insecure ordinary execution space to the secure trusted execution space mode, generate a measurement root, and connect with the trusted service module to implement subsequent trusted computing related functions. The measurement root must follow the following rules:

[0068] PCR inew =Hash(PCR iold value)

[0069] Among them, PCR inew Indicates the new PCR value, PCR ioldvalue represents the old PCR value, Hash(·) represents a hash function

[0070] In the embodiment of the present application, the trusted service platform authentication comprises: the trusted service module establishes and manages a complete trust chain based on a trusted digital identity chip, the trusted digital identity chip comprises a hardware module and a control module; the hardware module at least comprises a policy implementation component, a policy judgment component, and a storage component; the control module is responsible for coordinating the cooperative operation among the components;

[0071] The trusted service module provides an interactive interface for the terminal device and access permission for the trusted computing function of the trusted digital identity chip; after the trusted digital identity chip receives the authentication request sent by the agent module and the measurement root generated by the agent, the terminal device is authorized to prove its own trustworthiness by comparing the trusted root, and after the proof is completed, the trusted service module allows the terminal device to use the allocated channel to perform data transmission with the photovoltaic system and generates a log to save to a database.

[0072] Specifically, as shown in Fig. 3 The trusted digital identity chip authentication device and the channel allocation steps are as follows:

[0073] B1: the control module TPCM sends a request to the policy judgment component to obtain the integrity report of the current policy; the policy judgment component returns the integrity report of the policy in response to the request of the TPCM.

[0074] B2: the policy judgment component receives the policy integrity report request from the TPCM and returns the policy integrity report to the TPCM.

[0075] B3: the policy judgment component issues the policy to the policy implementation component.

[0076] B4: receiving the policy from the policy judgment component, executing the policy, generating a verification report; feeding back the verification report to the TPCM, generating a log record and storing it into a database.

[0077] B5: the storage policy implementation component generates a log record.

[0078] B6: the policy implementation component interacts with the terminal device through the transmission management module.

[0079] B7: submit the trusted root to the TPCM and perform authentication interaction with the terminal device.

[0080] B8: perform authentication interaction with the agent module and obtain the channel allocation result.

[0081] Embodiment 2

[0082] In the exemplary embodiment, a photovoltaic terminal data transmission protection system based on trusted computing in the embodiment is also provided, comprising:

[0083] a framework building module configured to build a terminal protection framework based on trusted technology, the terminal protection framework including a user space, a kernel space, a monitoring space, and a hardware space;

[0084] a user space module configured to cause the user space to include a normal execution space and a trusted execution space, the normal execution space and the trusted execution space to interact with a user and to interact with the kernel space in data;

[0085] a kernel and monitoring space module configured to cause the kernel space to work in cooperation with the monitoring space, the kernel space to invoke allocation of data resources according to a security evaluation result of the monitoring space;

[0086] a hardware space module configured to cause the hardware space to provide underlying support services for other spaces to implement transmission protection of photovoltaic terminal data.

[0087] Further, the photovoltaic terminal data transmission protection system further includes: the monitoring space includes a proof agent module, a measurement agent module, and an electric energy management service; the hardware space includes a photovoltaic system hardware and a trusted digital identity chip; the kernel space includes a thread management, a file management, a system call, and an inter-process communication.

[0088] Further, the user space further includes: the normal execution space and the trusted execution space are separated in execution environment; the normal execution space contains normal application programs; the trusted execution space contains a plurality of trusted applications and a trusted service module; the trusted service module is configured to provide a security management function.

[0089] In an optional embodiment, the photovoltaic terminal data transmission protection system based on trusted computing can perform the following steps:

[0090] When any terminal transmits data with a photovoltaic system, the terminal is authenticated according to an agent module in the monitoring space, a measurement root is generated and uploaded to a trusted service platform;

[0091] The trusted service platform provides an access interface with a trusted computing chip, the agent module initiates a request for accessing the photovoltaic system to establish a transmission channel to the trusted digital identity chip through the access interface, and after the trusted platform module verifies the request, the terminal device is allocated a specific channel to establish a transmission link for data transmission.

[0092] The agent module is a proof agent module and a measurement agent module; the proof agent module is configured to determine whether a device is attacked at a physical level, and to confirm that the terminal device is not tampered with or forged; the measurement agent module is configured to be responsible for integrity of the terminal device, to calculate and submit a measurement root.

[0093] When the terminal device is running, the attestation agent module confirms that the physical layer of the device is not tampered or forged by asking the device certificate from the trusted third party, generates a device identity attestation report, and provides it to the server;

[0094] When the user side requests to access the system, the integrity report of the user side is used as a link in the trust chain, the measurement agent module performs integrity check on the terminal device, generates a measurement report, and participates in the establishment of the trusted chain.

[0095] The trusted service module is based on a trusted digital identity chip to establish and manage a complete trust chain, the trusted digital identity chip includes a hardware module and a control module; the hardware module at least includes a policy implementation component, a policy judgment component, and a storage component; the control module is responsible for coordinating the cooperative operation between the components;

[0096] The trusted service module provides an interactive interface for the terminal device and access permission for the trusted computing function of the trusted digital identity chip; after the trusted digital identity chip receives the authentication request sent by the agent module and the measurement root generated by the agent, the terminal device is authorized to prove its own trustworthiness by comparing the trusted root, after the proof is completed, the trusted service module allows the terminal device to use the assigned channel to transmit data with the photovoltaic system, and generates a log and saves it to the database.

[0097] The embodiment also provides a computing device suitable for the photovoltaic terminal data transmission protection method based on trusted computing, comprising:

[0098] A memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the photovoltaic terminal data transmission protection method based on trusted computing proposed in the above embodiment.

[0099] The embodiment also provides a storage medium having a computer program stored thereon, the program being executed by a processor to realize the photovoltaic terminal data transmission protection method based on trusted computing proposed in the above embodiment.

[0100] The storage medium proposed in the embodiment and the photovoltaic terminal data transmission protection method based on trusted computing proposed in the above embodiment belong to the same inventive concept, and the technical details not described in detail in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0101] Those skilled in the art can clearly understand the present application by the description of the above embodiments. The present application can be realized by software and necessary general hardware, and of course can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH, a hard disk, or an optical disc, and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the method of each embodiment of the present application.

[0102] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, which should be covered in the scope of the claims of the present application.

Claims

1. A photovoltaic terminal data transmission protection method based on trusted computing, characterized in that: include: Building a terminal protection framework based on trusted technology, the terminal protection framework includes user space, kernel space, monitoring space and hardware space; The user space includes a normal execution space and a trusted execution space, wherein the normal execution space and the trusted execution space interact with the user and perform data exchange with the kernel space; The kernel space works in conjunction with the monitoring space, and the kernel space calls and allocates data resources according to the security assessment result of the monitoring space; The hardware space provides underlying support services for other spaces to achieve transmission protection of photovoltaic terminal data; The kernel space calls and allocates data resources according to the security assessment result of the monitoring space, including: when any terminal transmits data with the photovoltaic system, it performs authentication according to the agent module in the monitoring space, generates a measurement root and uploads it to the trusted service platform; The trusted service platform provides an access interface to the trusted computing chip. The proxy module initiates a request to the trusted digital identity chip through the access interface to access the photovoltaic system and establish a transmission channel. After the trusted platform module verifies the request, it allocates a specific channel to the terminal device to establish a transmission link for data transmission. The metric root must follow the rules: PCR inew =Hash(PCR iold value) Among them, PCR inew Indicates the new PCR value, PCR iold value represents the old PCR value, Hash(·) represents the hash function; The steps of the trusted digital identity chip authentication device and channel allocation are as follows: B1: The control module TPCM sends a request to the policy judgment component to obtain the integrity report of the current policy; the policy judgment component responds to the request of TPCM and returns the policy integrity report; B2: The policy judgment component receives the policy integrity report request from the TPCM and returns the policy integrity report to the TPCM; B3: The policy judgment component sends the policy to the policy implementation component; B4: Receives the policy from the policy judgment component, executes the policy, and generates a verification report; feeds the verification report back to the TPCM, generates a log record, and stores it in the database; B5: Log records generated by storage policy implementation components; B6: The policy implementation component interacts with the terminal device through the transmission management module; B7: Submit the trusted root to TPCM and perform authentication interaction with the terminal device; B8: Perform authentication interaction with the proxy module to obtain the channel allocation result.

2. The photovoltaic terminal data transmission protection method based on trusted computing according to claim 1, characterized in that: Also includes: The monitoring space includes a proof agent module, a measurement agent module and a power management service; The hardware space includes photovoltaic system hardware and a trusted digital identity chip; The kernel space includes thread management, file management, system calls and inter-process communication.

3. The photovoltaic terminal data transmission protection method based on trusted computing according to claim 1, characterized in that: The user space also includes: a normal execution space and a trusted execution space separated by execution environments; the normal execution space contains normal applications; the trusted execution space contains multiple trusted applications and a trusted service module; the trusted service module is used to provide security management functions.

4. The photovoltaic terminal data transmission protection method based on trusted computing according to claim 3, characterized in that: Authentication is performed according to the agent modules in the monitoring space, and measurement roots are generated and uploaded to the trusted service platform, including: the agent modules are a certification agent module and a measurement agent module; The proof agent module is used to determine whether the device has been attacked at the physical level and confirm that the terminal device has not been tampered with or forged; the measurement agent module is responsible for the integrity of the terminal device itself, and calculates and submits the measurement root.

5. The photovoltaic terminal data transmission protection method based on trusted computing according to claim 4, characterized in that: Also includes: When the terminal device is running, the certification agent module verifies that the physical layer of the device has not been tampered with or forged by requesting the device certificate from a trusted third party, generates a device identity certification report, and provides it to the server; When a user requests to access the system, based on its own integrity report as a link in the trust chain, the measurement agent module performs integrity checks on the terminal device and generates a measurement report, thereby participating in the establishment of the trust chain.

6. The photovoltaic terminal data transmission protection method based on trusted computing according to claim 5, characterized in that: Trusted service platform certification includes: the trusted service module is based on the trusted digital identity chip to establish and manage a complete trust chain. The trusted digital identity chip includes a hardware module and a control module. The hardware module includes at least a policy implementation component, a policy judgment component, and a storage component. The control module is responsible for coordinating the collaborative operation between various components. The trusted service module provides an interactive interface for the terminal device and access rights to the trusted computing function of the trusted digital identity chip. After the trusted digital identity chip receives the authentication request sent by the proxy module and the measurement root generated by the proxy, it compares the trusted root and authorizes the terminal device to prove its own credibility. After the proof is completed, the trusted service module allows the terminal device to use the allocated channel to transmit data with the photovoltaic system and generates a log to save it in the database.

7. A photovoltaic terminal data transmission protection system based on trusted computing, characterized in that: The photovoltaic terminal data transmission protection method based on trusted computing as claimed in claim 1 includes: A framework building module is used to build a terminal protection framework based on trusted technology, which includes user space, kernel space, monitoring space and hardware space; A user space module, for the user space including a normal execution space and a trusted execution space, wherein the normal execution space and the trusted execution space interact with the user and perform data exchange with the kernel space; A kernel and monitoring space module, configured to coordinate the kernel space with the monitoring space, wherein the kernel space allocates data resources based on a security assessment result of the monitoring space; The hardware space module is used for the hardware space to provide underlying support services for other spaces to achieve transmission protection of photovoltaic terminal data.

8. An electronic device comprising: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the photovoltaic terminal data transmission protection method based on trusted computing according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the photovoltaic terminal data transmission protection method based on trusted computing as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Terminal trust state collection system and method and computer equipment

    CN112035844A

  • Credible acquisition and transmission method and system for key data of DCS (Distributed Control System) and storage medium

    CN117155685A