Data configuration method, system and equipment and storage medium

By performing secure authentication of user login information in industrial control systems and encrypting data using domestic encryption algorithms, the problem that traditional encryption technology is easily cracked is solved, the security and accuracy of data configuration are improved, and the stable operation of the system is ensured.

CN120012129APending Publication Date: 2025-05-16CHINA TECHENERGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510086094.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-20
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the field of industrial control, the encryption technology used by traditional equipment is old and easy to be cracked, cannot meet the requirements of high security levels, and cannot guarantee absolute security and autonomous control.

Method used

By obtaining the user's login information and performing security authentication, including the complexity and timeliness verification of the login password and the verification of the user's identity permissions, the configuration data is encrypted using a domestic encryption algorithm, and the data configuration of the lower computer is completed based on the encrypted data.

Benefits of technology

It significantly improves the security and accuracy of data configuration, effectively prevents unauthorized access and tampering, and ensures data integrity and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012129A_ABST
    Figure CN120012129A_ABST
Patent Text Reader

Abstract

The invention provides a data configuration method, system and device and a storage medium, and relates to the technical field of industrial control, and the method greatly improves the system security through obtaining the login information of a user and carrying out strict security authentication, including the complexity and timeliness verification of a login password and the verification of user identity permission. And secondly, the to-be-configured data is verified in detail, so that the accuracy and consistency of the data are ensured, and a solid foundation is laid for subsequent data configuration. In addition, according to the method, a domestic encryption algorithm is adopted to encrypt the verified to-be-configured data, so that the security of the data is greatly enhanced. And finally, based on the encrypted to-be-configured data, safe and reliable data configuration of the lower computer is realized, and the stability and high efficiency of the whole data configuration process are effectively guaranteed. In conclusion, according to the data configuration method, the safety and accuracy of data configuration are remarkably improved, and a powerful guarantee is provided for stable operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of industrial control technology, and in particular to a data configuration method, system, device and storage medium. Background Art

[0002] High-security equipment refers to equipment with higher security requirements. During the data configuration process of high-security equipment, in order to ensure that the data is not accessed or stolen by unauthorized third parties during transmission, encryption technology is required to protect the data from unauthorized access and theft. With the significant technological progress in the field of domestic cryptography, the relevant domestic encryption has already possessed higher security and performance.

[0003] Most traditional equipment or systems in the field of industrial control use relatively old encryption technologies, such as RC4, MD5 and other encryption algorithms, which are easy to be cracked, especially when the key length is short or the key is reused. The above encryption algorithms are vulnerable to attacks and there are also some known weaknesses, such as key stream bias and plaintext correlation. When the security level requirements for these devices using old encryption technologies are increased, there are often huge hidden dangers. At the same time, the implementation of the domestic confidentiality law requires many devices to meet the requirements of national laws and regulations. Equipment manufactured using the above encryption algorithms cannot guarantee absolute security, nor can they meet the true autonomy and controllability of the equipment. Summary of the invention

[0004] In view of the above problems, this application provides a data configuration method, including the following contents:

[0005] In a first aspect, the present application provides a data configuration method, the method comprising:

[0006] Obtaining the user's login information and performing security authentication based on the login information; the security authentication includes performing complexity and time validity verification on the login password in the login information and verifying the identity authority of the user;

[0007] When the login information of the user is successfully verified, the configuration data is verified;

[0008] After the verification of the data to be configured is completed, the verified data to be configured is encrypted using a first encryption algorithm to obtain encrypted data to be configured; the first encryption algorithm is a domestic encryption algorithm;

[0009] The data configuration of the lower computer is completed based on the encrypted data to be configured.

[0010] Optionally, the method further includes:

[0011] Encrypting the data read back request by using the first encryption algorithm to obtain an encrypted data read back request;

[0012] Sending the encrypted data read-back request to the lower computer;

[0013] Obtaining the encrypted configured data sent by the lower computer;

[0014] Decrypting the encrypted configured data and comparing it with the data to be configured;

[0015] When the decrypted configured data is inconsistent with the data to be configured, an early warning is issued.

[0016] Optionally, the login password in the login information is encrypted using a second encryption method, and the performing complexity and time verification on the login password in the login information includes:

[0017] Determining whether the complexity of the login password meets a preset complexity standard;

[0018] Determine whether the time interval between the login password and the first generation time or the last modification time is greater than a preset time interval.

[0019] Optionally, the second encryption method is the SM3 domestic encryption method.

[0020] Optionally, the verifying the configuration data includes:

[0021] The naming method, upper and lower limits of data values ​​and data identification information of the data to be configured are respectively compared with preset standards.

[0022] Optionally, the encrypting the verified data to be configured by using the first encryption algorithm includes:

[0023] The domestic encryption algorithm SM4 algorithm is used to encrypt the data to be configured after the verification is completed.

[0024] In a second aspect, the present application provides a data configuration system, the system comprising a host computer and a slave computer;

[0025] The host computer includes: an acquisition module, which is used to obtain the user's login information and perform security authentication based on the login information; the security authentication includes performing complexity and time verification on the login password in the login information and verifying the identity authority of the user;

[0026] A configuration data verification module is used to verify the configuration data after the login information of the user is successfully verified;

[0027] an encryption module, configured to encrypt the verified data to be configured using a first encryption algorithm after verifying the data to be configured, to obtain encrypted data to be configured; the first encryption algorithm is a domestic encryption algorithm;

[0028] The data configuration module is used to complete the data configuration of the lower computer based on the encrypted data to be configured.

[0029] Optionally, the host computer configuration system also includes:

[0030] The configuration data read-back verification module is used to send a data read-back request and verify the received configured data.

[0031] Optionally, the acquisition module performs complexity and time validity verification on the login password in the login information specifically including:

[0032] Determining whether the complexity of the login password meets a preset complexity standard;

[0033] Determine whether the time interval between the login password and the first generation time or the last modification time is greater than a preset time interval.

[0034] Optionally, the second encryption method is the SM3 domestic encryption method.

[0035] Optionally, the configuration data read-back verification module verifies the configuration data including:

[0036] The naming method, upper and lower limits of data values ​​and data identification information of the data to be configured are respectively compared with preset standards.

[0037] Optionally, the encryption module encrypts the verified data to be configured using a first encryption algorithm, including:

[0038] The domestic encryption algorithm SM4 algorithm is used to encrypt the data to be configured after the verification is completed.

[0039] In a third aspect, the present application provides a device comprising a memory and a processor, wherein the memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the data configuration method introduced in any implementation of the first aspect.

[0040] In a fourth aspect, the present application provides a computer-readable storage medium, in which codes are stored. When the codes are executed, a device executing the codes implements the data configuration method introduced in any implementation of the first aspect.

[0041] The present application provides a data configuration method. First, by obtaining the user's login information and performing strict security authentication, including the complexity and time verification of the login password and the verification of the user's identity authority, the security of the system is greatly improved, and unauthorized users are effectively prevented from accessing and tampering with the configuration data. Secondly, the configuration data is thoroughly verified to ensure the accuracy and consistency of the data, laying a solid foundation for subsequent data configuration. In addition, the method uses a domestic encryption algorithm to encrypt the verified data to be configured, thereby enhancing the security of the data. Finally, based on the encrypted data to be configured, the secure and reliable data configuration of the lower computer is realized, effectively ensuring the stability and efficiency of the entire data configuration process.

[0042] In summary, the data configuration method of the present application significantly improves the security and accuracy of data configuration, and provides a strong guarantee for the stable operation of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions in this embodiment or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0044] Figure 1 A flowchart of a data configuration method provided in an embodiment of the present application;

[0045] Figure 2 A schematic diagram of the connection and deployment of an automated device provided in an embodiment of the present application;

[0046] Figure 3 A schematic diagram of the structure of a data configuration system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0048] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards of relevant countries and regions.

[0049] Figure 1 A flowchart of a data configuration method provided in an embodiment of the present application. Figure 1 As shown, the data configuration method provided in the embodiment of the present application may include:

[0050] S101. Obtain login information of a user, and perform security authentication based on the login information.

[0051] Before the user configures data to the lower computer (high-security device) through the configuration device of the upper computer, it is necessary to complete the login process first to ensure that the user performing the configuration operation has the corresponding authority. Through this process, the device can be protected from unauthorized access and data tampering. In an automated control system or a data processing system, the upper computer generally refers to a computer system responsible for monitoring, controlling and managing the lower computer. In an embodiment of the present application, the user performs various operations such as data configuration, device monitoring, etc. through the upper computer interface. The lower computer refers to a device or system controlled or monitored by the upper computer, and usually has specific functions, such as data acquisition, device control, etc. In the application embodiment, the lower computer is specifically pointed out as a high-security device, which means that it has a high degree of security protection measures to protect the stored or processed data from unauthorized access and tampering.

[0052] The user first needs to enter the login information, which consists of at least two parts: identity information (such as user name) and password. The identity information is used to uniquely identify the user, ensuring that the host computer can accurately identify the login user, and the password is used as a second layer of protection to further ensure the security of data configuration. In order to improve security, the password must follow certain complexity requirements when setting. Specifically, the password should contain a combination of three symbols: numbers, letters (uppercase and lowercase), and special characters. For example, a password that meets the requirements is: A1b@C2d#.

[0053] After obtaining the user's login information, the host computer will perform a double check on the password entered by the user: including correctness check, verifying whether the entered password matches the password stored in the host computer, and timeliness check, checking whether the password generation time exceeds the validity period set by the host computer. This helps prevent the use of expired or leaked passwords for login. After the password verification is passed, the host computer must also authenticate the user's identity and permissions, which includes verifying whether the user has the permission to perform data configuration. By checking the user's role, permission group, or specific permission flag, the host computer can ensure that only users with corresponding permissions can perform data configuration.

[0054] In order to protect the security of the password, the host computer uses the SM3 domestic encryption method when storing and transmitting the password. SM3 is a block cipher structure with a message block length of 512 bits and a digest value of 256 bits. This encryption method has high security and anti-attack capabilities, and can effectively prevent the password from being cracked or leaked.

[0055] Through the above process, the host computer can ensure that only users with corresponding permissions and passwords that meet the requirements can access and operate the data configuration, thereby effectively protecting the security of the device and the integrity of the data.

[0056] S102: After the user's login information is successfully verified, the configuration data is verified.

[0057] After the user successfully passes the login information verification, the host computer enters the verification phase of the data to be configured to ensure the accuracy and security of the data configuration and prevent equipment failure or safety risks caused by data errors or non-compliance with specifications.

[0058] First, the naming method of the data to be configured is compared with the preset standard to ensure that the naming of the data complies with the specification and facilitates subsequent management and maintenance. Then, the data value is checked in the range to ensure that the data value is within the preset upper and lower limits to prevent abnormal operation of the device due to data anomalies. In addition, the identification information of the data, such as data ID, version number, etc., can be verified by comparing the identification information of the data, such as data ID, version number, etc., with the preset standard to ensure the uniqueness and version consistency of the data.

[0059] During verification, the user submits the data to be configured to the host computer through the configuration data verification module. The host computer automatically executes the above verification steps and compares each data one by one. If the data does not meet the preset standards, the host computer will return an error message to prompt the user to make corrections.

[0060] S103: After the verification of the data to be configured is completed, the verified data to be configured is encrypted using a first encryption algorithm to obtain encrypted data to be configured.

[0061] After the data verification is passed, the host computer will use the domestic password encryption module to encrypt the configuration data. The encryption algorithm used here is the SM4 algorithm, which is a symmetric encryption algorithm with a packet length of 128 bits and a key length of 128 bits. The SM4 algorithm provides a high data encryption strength through 32 rounds of iterative calculations, which can effectively prevent the data from being stolen or tampered with during transmission. The encrypted configuration data will be sent to the lower computer (high-security device) through the secure communication component in the upper computer. The secure communication component uses advanced encryption technology and communication protocols to ensure the security and integrity of data during transmission. After receiving the configuration data, the high-security device will decrypt it and perform corresponding device configuration according to the configuration data.

[0062] Through this step, the host computer can ensure the accuracy and security of the data to be configured, providing strong guarantee for the normal operation of the equipment. At the same time, the use of domestic encryption algorithms and secure communication components also further improves the security and reliability of the host computer.

[0063] S104: completing data configuration of the lower computer based on the encrypted data to be configured.

[0064] After receiving the encrypted configuration data from the upper computer, the lower computer decrypts the encrypted configuration data and completes the configuration of the lower computer based on the decrypted configuration data. After the lower computer decrypts the received encrypted data, it also needs to perform a legality check on the decrypted configuration data. When the legality requirements are not met, the error code information will be fed back to the data configuration tool so that it can obtain the specific cause of the error, which is convenient for users to quickly check.

[0065] In order to further ensure the security of the configuration data, in one implementation of the embodiment of the present application, a data readback check is performed to determine whether the configured data has been tampered with, the data readback request is first encrypted using the first encryption algorithm to obtain an encrypted data readback request, and then the encrypted data readback request is sent to the lower computer. The encrypted configured data sent by the lower computer is obtained, the encrypted configured data is decrypted, and compared with the data to be configured, and when the decrypted configured data is inconsistent with the data to be configured, an early warning is issued.

[0066] Specifically, first, a data read back request is generated in the upper computer to obtain the configured data in the lower computer and detect it, and then the data read back request is encrypted using the first encryption algorithm to obtain the encrypted data read back request. In order to ensure the security of the request during transmission, the data read back request is encrypted using the same password as the password used to encrypt the data to be configured after verification, that is, the domestic SM4 algorithm is used for encryption, and the encrypted data read back request is sent to the lower computer through a secure communication channel.

[0067] After receiving the encrypted data readback request, the lower computer first decrypts the encrypted data readback request to obtain the specific request. Then, the configured data is further read, and the CPU of the lower computer uses the corresponding encryption algorithm to encrypt these data, such as using the domestic SM4 algorithm for encryption. Then, these added configured data are fed back to the upper computer through the communication module. In this way, by encrypting the configured data, the security of the data can be ensured during the feedback process to prevent it from being intercepted or tampered by unauthorized third parties.

[0068] After receiving the encrypted configured data sent from the lower computer, the upper computer uses the corresponding decryption algorithm (corresponding to the encryption algorithm used by the lower computer) to decrypt the data. The decrypted configured data is then compared and verified with the information to be configured before, that is, the data to be configured, to further confirm the correctness and reliability of the configuration data. If the decrypted configured data is consistent with the data to be configured, it means that the configuration process is successful and the data is accurate; if it is inconsistent, it means that there may be a configuration error or the data has been tampered with. At this time, the configuration device of the upper computer will immediately trigger the early warning mechanism. This early warning mechanism may include sounding an alarm, displaying an error message, recording an error log, etc. By issuing an early warning, relevant personnel can be reminded of possible security issues or configuration errors so that timely measures can be taken to correct and repair them.

[0069] In addition, the data configuration method in this application is applicable to both remote and near-end devices, such as Figure 2 As shown, it is a schematic diagram of the connection and deployment of an automated device provided by an embodiment of the present application, which includes multiple cabinet devices at the far end and the near end, and can realize remote batch data configuration and one-to-one configuration of near-end devices. Specifically, when performing data configuration on the near-end cabinet device, connecting the configuration device in the present application with the cabinet's protocol conversion can realize the data configuration of a single near-end cabinet, that is, when near the device, through direct connection or short-distance communication, detailed data configuration of a single device is performed to ensure the accuracy and pertinence of the configuration. For remote data, connecting the configuration device and the switch can perform data configuration on multiple devices at the same time, greatly improving the configuration efficiency.

[0070] The above are some specific implementations of a data configuration method provided in the embodiment of the present application. Based on this, the present application also provides a corresponding system. The system provided in the embodiment of the present application will be introduced from the perspective of functional modularization.

[0071] Figure 3 A schematic diagram of the structure of a data configuration system provided in an embodiment of the present application. Figure 3 As shown, the data configuration system 300 provided in the embodiment of the present application includes:

[0072] A host computer 310 and a slave computer 320;

[0073] The host computer includes: an acquisition module, which is used to obtain the user's login information and perform security authentication based on the login information; the security authentication includes performing complexity and time verification on the login password in the login information and verifying the identity authority of the user;

[0074] A configuration data verification module is used to verify the configuration data after the login information of the user is successfully verified;

[0075] an encryption module, configured to encrypt the verified data to be configured using a first encryption algorithm after completing verification of the data to be configured, to obtain encrypted data to be configured; the first encryption algorithm is a domestic encryption algorithm;

[0076] The data configuration module is used to complete the data configuration of the lower computer based on the encrypted data to be configured.

[0077] In one implementation of the embodiment of the present application, the host computer configuration system also includes:

[0078] The configuration data read-back verification module is used to send a data read-back request and verify the received configured data.

[0079] In one implementation of the embodiment of the present application, the acquisition module performs complexity and time validity verification on the login password in the login information, specifically including:

[0080] Determining whether the complexity of the login password meets a preset complexity standard;

[0081] Determine whether the time interval between the login password and the first generation time or the last modification time is greater than a preset time interval.

[0082] In one implementation of an embodiment of the present application, the second encryption method is the SM3 domestic encryption method.

[0083] In an implementation of the embodiment of the present application, the configuration data read-back verification module verifies the configuration data including:

[0084] The naming method, upper and lower limits of data values ​​and data identification information of the data to be configured are respectively compared with preset standards.

[0085] In an implementation of the embodiment of the present application, the encryption module encrypts the verified data to be configured using a first encryption algorithm, including:

[0086] The domestic encryption algorithm SM4 algorithm is used to encrypt the data to be configured after the verification is completed.

[0087] The embodiments of the present application also provide corresponding devices and computer storage media for implementing the solutions provided by the embodiments of the present application.

[0088] The device includes a memory and a processor, the memory is used to store instructions or codes, and the processor is used to execute the instructions or codes so that the device executes the method described in any embodiment of the present application.

[0089] The computer storage medium stores codes, and when the codes are executed, a device executing the codes implements the method described in any embodiment of the present application.

[0090] Through the description of the above implementation methods, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above-mentioned embodiment method can be implemented by means of software plus a general hardware platform. Based on such an understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment of the present application or some parts of the embodiments.

[0091] It is understandable that in the specific implementation of the present application, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved, when the above embodiments of the present application are applied to specific products or technologies, need to obtain user permission or consent, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0092] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0093] It should also be noted that the various embodiments in this specification are described in a progressive manner, and the same and similar parts between the various embodiments can refer to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments. The device and system embodiments described above are merely schematic, in which the units described as separate components may or may not be physically separated, and the components indicated as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0094] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A data configuration method, characterized in that: The method comprises: Obtaining the user's login information and performing security authentication based on the login information; the security authentication includes performing complexity and time validity verification on the login password in the login information and verifying the identity authority of the user; When the login information of the user is successfully verified, the configuration data is verified; After the verification of the data to be configured is completed, the verified data to be configured is encrypted using a first encryption algorithm to obtain encrypted data to be configured; the first encryption algorithm is a domestic encryption algorithm; The data configuration of the lower computer is completed based on the encrypted data to be configured.

2. The method according to claim 1, characterized in that The method further comprises: Encrypting the data read back request by using the first encryption algorithm to obtain an encrypted data read back request; Sending the encrypted data read-back request to the lower computer; Obtaining the encrypted configured data sent by the lower computer; Decrypting the encrypted configured data and comparing it with the data to be configured; When the decrypted configured data is inconsistent with the data to be configured, an early warning is issued.

3. The method according to claim 1, characterized in that The login password in the login information is encrypted using a second encryption method, and the complexity and time validity verification of the login password in the login information includes: Determining whether the complexity of the login password meets a preset complexity standard; Determine whether the time interval between the login password and the first generation time or the last modification time is greater than a preset time interval.

4. The method according to claim 3, characterized in that The second encryption method is the SM3 domestic encryption method.

5. The method according to claim 1, characterized in that The verification of the configuration data includes: The naming method, upper and lower limits of data values ​​and data identification information of the data to be configured are respectively compared with preset standards.

6. The method according to claim 1, characterized in that The encrypting the verified data to be configured by using the first encryption algorithm comprises: The domestic encryption algorithm SM4 algorithm is used to encrypt the data to be configured after the verification is completed.

7. A data configuration system, characterized in that: The system includes an upper computer and a lower computer; The host computer includes: an acquisition module, which is used to obtain the user's login information and perform security authentication based on the login information; the security authentication includes performing complexity and time verification on the login password in the login information and verifying the identity authority of the user; A configuration data verification module is used to verify the configuration data after the login information of the user is successfully verified; an encryption module, configured to encrypt the verified data to be configured using a first encryption algorithm after verifying the data to be configured, to obtain encrypted data to be configured; the first encryption algorithm is a domestic encryption algorithm; The data configuration module is used to complete the data configuration of the lower computer based on the encrypted data to be configured.

8. The system according to claim 7, characterized in that The host computer configuration system also includes: The configuration data read-back verification module is used to send a data read-back request and verify the received configured data.

9. A computing device, characterized in that The computing device includes: a memory and a processor; The memory is used to store computer programs; The processor is configured to implement the method according to any one of claims 1 to 6 when executing the computer program.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.