Equipment communication method and system, electronic equipment and storage medium

By encrypting the device serial number of edge computing devices and sending registration requests, the problem of inefficient access in traditional devices is solved, simplifying and improving device access is achieved, and the security of the system is enhanced.

CN120017322APending Publication Date: 2025-05-16江西冠英智能科技股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510042254.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the industrial Internet of Things environment, traditional IoT management platforms need to add device information and keys in advance before the device is accessed, resulting in inefficient access to the device, prone to errors, and consume a lot of manpower and time.

Method used

By encrypting the device serial number of the edge computing device based on the default encryption algorithm and the default key, obtaining the encrypted serial number and sending a registration request to the management platform, the device registration process is simplified.

Benefits of technology

This method not only ensures the uniqueness and authenticity of edge computing devices, but also improves the efficiency of device access, reduces labor and time costs, and enhances the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017322A_ABST
    Figure CN120017322A_ABST
Patent Text Reader

Abstract

The invention provides an equipment communication method and system, electronic equipment and a storage medium, which are applied to the technical field of communication, and the method comprises the following steps: encrypting an equipment serial number of edge computing equipment based on a default encryption algorithm and a default key to obtain an encrypted serial number, and sending a registration request to a management platform, the registration request comprises the equipment serial number and an encrypted serial number; and in response to the received registration request passing information sent by the management platform, sending the equipment information of the edge computing equipment to the management platform. According to the invention, the uniqueness of the edge computing device and the authenticity of the identity are ensured, the registration process of the edge computing device is simplified, and the access efficiency of the edge computing device is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a device communication method, system, electronic device and storage medium. Background Art

[0002] In the current industrial IoT environment, device access and management is a complex and critical link. Traditional IoT management platforms usually require that device information be added in advance before device access, and relevant key information be written into the device. Although it can ensure the security of the device to a certain extent, there are many inconveniences in actual operation, especially when a large number of devices need to be accessed, which is inefficient and prone to errors. It also requires a lot of manpower and time. Summary of the invention

[0003] In view of this, the purpose of the present application is to propose a device communication method, system, electronic device and storage medium to improve the efficiency of device access.

[0004] Based on the above purpose, the present application provides a device communication method, including:

[0005] Encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to the management platform, where the registration request includes the device serial number and the encrypted serial number;

[0006] In response to receiving the registration request passed information sent by the management platform, the device information of the edge computing device is sent to the management platform.

[0007] Based on the same inventive concept, the present application also provides a device communication system, including: an edge computing device and a management platform;

[0008] The edge computing device is configured to: encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to a management platform, wherein the registration request includes the device serial number and the encrypted serial number; in response to receiving the registration request pass information sent by the management platform, send the device information of the edge computing device to the management platform;

[0009] The management platform is configured to: in response to receiving a registration request sent by an edge computing device, decrypt the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number; in response to determining that the decrypted serial number is the same as the device serial number, send registration request approval information to the edge computing device.

[0010] Based on the same inventive concept, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the method as described above when executing the computer program.

[0011] Based on the same inventive concept, the present application also provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute the method as described above.

[0012] From the above, it can be seen that the device communication method, system, electronic device and storage medium provided by the present application include: encrypting the device serial number of the edge computing device based on the default encryption algorithm and the default key to obtain the encrypted serial number, and sending a registration request to the management platform, wherein the registration request includes the device serial number and the encrypted serial number; in response to receiving the registration request information sent by the management platform, the device information of the edge computing device is sent to the management platform. It not only ensures the uniqueness of the edge computing device and the authenticity of the identity, but also simplifies the registration process of the edge computing device and improves the efficiency of edge computing device access. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions in the present application or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0014] Figure 1 This is a flow chart of a device communication method according to an embodiment of the present application;

[0015] Figure 2 This is a flow chart of a device communication method according to another embodiment of the present application;

[0016] Figure 3 A schematic diagram of a device communication apparatus according to an embodiment of the present application;

[0017] Figure 4 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0018] In order to make the objectives, technical solutions and advantages of the present application more clearly understood, the present application is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.

[0019] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should be the usual meanings understood by people with ordinary skills in the field to which the present application belongs. The "first", "second" and similar words used in the embodiments of the present application do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0020] In the related technology, in the current industrial Internet of Things environment, the access and management of devices is a complex and critical link. Traditional Internet of Things management platforms usually require that the device information be pre-added and the relevant key information be written into the device before the device is accessed. Although the security of the device can be guaranteed to a certain extent, there are many inconveniences in actual operation, especially when a large number of devices need to be accessed, which is inefficient and prone to errors. The process of pre-adding device information and key writing requires a lot of manpower and time. This not only increases operating costs, but may also lead to an extension of the device online cycle and affect production efficiency. In addition, this method also relies on manual operation, which is prone to human errors, such as information entry errors or key configuration errors, which in turn lead to the inability of the device to register normally or the reduction of communication security. Secondly, traditional industrial control systems usually rely on fixed communication keys for data transmission. Although this method is simple, it is easy to become a breakthrough in the face of complex network attacks. Once the fixed key is cracked, the security of the entire system will be seriously threatened.

[0021] Based on the above problems, the applicant found that the device serial number of the edge computing device is encrypted based on the default encryption algorithm and the default key to obtain the encrypted serial number, and a registration request is sent to the management platform, the registration request includes the device serial number and the encrypted serial number; in response to receiving the registration request information sent by the management platform, the device information of the edge computing device is sent to the management platform. This not only ensures the uniqueness of the edge computing device and the authenticity of the identity, but also simplifies the registration process of the edge computing device and improves the efficiency of device access.

[0022] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0023] In some embodiments, Figure 1As shown, a device communication method is applied to an edge computing device, and the method includes:

[0024] S101. Encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to a management platform, where the registration request includes the device serial number and the encrypted serial number;

[0025] In specific implementation, when the edge computing device leaves the factory, a default encryption algorithm and a default key are usually configured. The default encryption algorithm can be a symmetric encryption algorithm. Each edge computing device will have a globally unique device serial number, which is used to identify the uniqueness of the edge computing device. Before the edge computing device is registered, the device serial number needs to be encrypted using the default encryption algorithm and the default key. The purpose of encryption is to protect the identity information of the edge computing device and prevent it from being intercepted or tampered with during transmission. The serial number processed by the encryption algorithm is called an encrypted serial number. After the serial number encryption is completed, the edge computing device will send a registration request to the management platform. The registration request contains the plain text of the device serial number and the encrypted encrypted serial number. The device serial number is used for preliminary identification, while the encrypted serial number is used to verify the legitimacy and authenticity of the device. It effectively prevents unauthorized device access, thereby improving the security and reliability of the entire system. It not only ensures the uniqueness and authenticity of the edge computing device, but also simplifies the registration process of the edge computing device and improves the efficiency of device access.

[0026] S102: In response to receiving the registration request approval information sent by the management platform, send the device information of the edge computing device to the management platform.

[0027] In specific implementation, after receiving the registration request, the management platform will use the same default encryption algorithm and default key to decrypt the encrypted serial number and obtain a decrypted serial number. Then the management platform compares the decrypted serial number with the device serial number. If the two are consistent, it means that the registration request of the edge computing device is legal, and the edge computing device can be allowed to access the management platform and send the registration request to the edge computing device. After receiving the confirmation information from the management platform, the edge computing device will send the device information of the edge computing device to the management platform. The device information may include the model, hardware specifications, software version, sensor configuration, etc. of the device. It not only helps the management platform to monitor and maintain the device status, but also provides a basis for data analysis and optimization for the management platform. For example, the management platform can optimize the data processing process based on the device information, or provide a faster response when the device fails. Through this process, the edge computing device not only completes the initial registration, but also establishes a deeper connection with the management platform. It ensures the security and reliability of device access, and provides support for the device management and data processing of the management platform.

[0028] In this embodiment, the device serial number is encrypted using the default encryption algorithm and key, which simplifies the device registration process. The device can automatically generate an encrypted serial number and send a registration request without manual intervention, which greatly improves the efficiency of device access, especially when a large number of devices are accessed, which can significantly reduce manpower and time costs. The use of encrypted serial numbers ensures the security of device identity information during transmission to prevent it from being intercepted or tampered with. By decrypting and verifying the encrypted serial number, the management platform can effectively prevent unauthorized device access and improve the overall security and reliability of the system. The automated registration process reduces the need for manual operations, thereby reducing the risk of information entry errors or key configuration errors. Not only does it improve accuracy, it also reduces the extension of the device online cycle.

[0029] In some embodiments, Figure 2 As shown, a device communication method is applied to a management platform, and the method includes:

[0030] S201, in response to receiving a registration request sent by an edge computing device, decrypting the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number;

[0031] In specific implementation, when the edge computing device first connects to the management platform, it sends a registration request. The registration request contains the device serial number and encrypted serial number of the device. The device serial number is used to identify the identity of the device, while the encrypted serial number is used to verify the legitimacy of the device. In the initial communication between the edge computing device and the management platform, a default encryption algorithm and default key are usually used to ensure the security of the initial communication. After receiving the registration request, the management platform will use the default encryption algorithm and default key to decrypt the encrypted serial number sent by the device. The purpose of decryption is to restore the original serial number of the device (that is, the decrypted serial number) for subsequent verification. Through the decryption process, the management platform obtains the decrypted serial number.

[0032] S202: In response to determining that the decrypted serial number is the same as the device serial number, send registration request approval information to the edge computing device.

[0033] In specific implementation, after the management platform obtains the decrypted serial number by decrypting the encrypted serial number, it compares the decrypted serial number with the device serial number. Verify the authenticity of the device identity. The decrypted serial number is the same as the device serial number, indicating that the encrypted information sent by the device is reliable and the identity of the edge computing device has been confirmed. The management platform will send a registration request to the edge computing device. This indicates that the edge computing device can be officially connected and start communicating with the management platform. The management platform not only confirms the legitimacy of the edge computing device, but also provides necessary support for the normal operation and data exchange of the device. This ensures the security and reliability of the system, while simplifying the access process of edge computing devices.

[0034] In this embodiment, by verifying the consistency between the decrypted serial number and the device serial number, the management platform can confirm the uniqueness and authenticity of the device. This prevents the risk of device forgery and impersonation, and ensures that only verified devices can access the system. At the same time, it supports large-scale device access and adapts to the rapid growth of the number of devices in the industrial Internet of Things environment.

[0035] In some embodiments, the method further comprises:

[0036] In response to determining that the edge computing device logs into the management platform, determining whether the edge computing device logs in for the first time according to the device serial number of the edge computing device;

[0037] In specific implementation, when the edge computing device logs in to the management platform, the management platform will check its login status according to the device serial number. Specifically, the management platform will check its device database or records to see whether the device serial number already exists in the list of registered devices, that is, determine whether the edge computing device is logging in for the first time according to the device serial number of the edge computing device.

[0038] In response to determining that the edge computing device is logging in for the first time, a communication key is generated and sent to the edge computing device, so that the edge computing device encrypts the collected data based on the communication key and sends it to the management platform.

[0039] In specific implementation, if the device serial number does not exist in the records of the management platform, it indicates that the device is logging in for the first time. The management platform generates a new communication key and sends it to the edge computing device for encrypted communication between the edge computing device and the management platform to ensure the confidentiality and integrity of the data. When the edge computing device receives the communication key, it configures it into its own encryption module. The communication key will be used to encrypt and decrypt all communication data between the edge computing device and the management platform to ensure the confidentiality and integrity of the data during transmission, prevent unauthorized access and data leakage, and ensure the security of the data.

[0040] In this embodiment, by generating a unique communication key for the device logging in for the first time, all communication data between the edge computing device and the management platform is encrypted. This effectively prevents data from being intercepted, tampered with, or accessed without authorization during transmission, protecting the confidentiality and integrity of the data. By enhancing data security, simplifying the device management process, and improving system flexibility, this provides an efficient and reliable solution for the access and management of edge computing devices in the industrial Internet of Things environment.

[0041] In some embodiments, after sending the communication key to the edge computing device, the method further includes:

[0042] In response to receiving the collected data encrypted based on the communication key sent by the edge computing device, determining whether the collected data received within a preset historical period meets the key security condition;

[0043] During specific implementation, the management platform continuously receives collected data from edge computing devices, and the collected data is information encrypted using a communication key. Each time the collected data is received, the management platform decrypts and processes the information. In order to evaluate the security of the communication key, a preset historical duration is set (for example, the preset historical duration is set to 1 hour). The key security condition is a standard used to evaluate whether the key is still secure. For example: check whether the received data is complete and has not been tampered with; monitor whether the amount of data received and the transmission frequency within the preset historical duration are abnormal; detect whether there are abnormal access patterns or potential attack behaviors. The management platform will analyze whether the received data meets the key security conditions within the preset historical duration. If the data shows abnormal conditions, such as a sudden increase in data volume, abnormal transmission frequency, or signs of data tampering, it may indicate that there is a security risk in the communication key, respond to potential security threats in a timely manner, and protect the security of data transmission between the device and the management platform.

[0044] In response to determining that the collected data received within a preset historical time period does not meet the key security condition, an update time period for the communication key is determined and the communication key is updated within the update time period.

[0045] In specific implementation, within the preset historical time period, the management platform analyzes the received collected data to determine whether it meets the key security conditions. If the data shows abnormal conditions, such as abnormal data volume, unstable transmission frequency, or signs of data tampering, it is determined that the collected data received within the preset historical time period does not meet the key security conditions, indicating that the current communication key may have security risks. The management platform needs to determine a suitable update time period to update the communication key. The selection of the update time period can take into account a variety of factors: Select a time period with low system load for key update to minimize the impact on normal business. Update during a period with low data transmission frequency to reduce the risk of data loss or transmission interruption. Determine the urgency of the update time period based on the urgency of the security threat. After determining the update time period, the management platform will notify the edge computing device to prepare for key update. During the update time period, the management platform and the edge computing device will work together to update the key. Usually, the management platform generates a new communication key and sends it to the edge computing device through a secure channel. After receiving the new communication key, the edge computing device configures it into its own encryption module. After completing the key update, the management platform and the edge computing device need to perform a communication test to confirm the validity and correctness of the new key. After the test is successful, the edge computing device can continue normal data transmission to ensure that the new communication key has taken effect. Through the dynamic key management mechanism, the management platform can respond to potential security threats in a timely manner to ensure that the communication between the edge computing device and the management platform is always in a secure state. This not only improves the security of the system, but also enhances the ability to adapt to abnormal situations.

[0046] In this embodiment, by continuously monitoring and collecting data, the management platform can promptly identify potential security threats. If an abnormal situation is found, the communication key can be quickly updated to reduce the risk of attack and ensure the security and integrity of data transmission. By regularly and dynamically updating the communication key, even if the communication key is leaked or cracked, the attacker can only use the communication key to attack within a limited time, thereby reducing the risk of data leakage.

[0047] In some embodiments, determining whether the collected data received within a preset historical period meets the key security condition includes:

[0048] Determine the amount of collected data received within a preset historical period;

[0049] In specific implementation, the management platform will continuously monitor the amount of collected data received from the edge computing device. Changes in the amount of collected data can reflect whether the communication behavior of the edge computing device is normal and whether the security of the current communication key may be threatened. The preset historical duration is a fixed time window used to count and analyze the amount of collected data received, so as to identify potential security threats in a timely manner and take corresponding measures (such as updating communication keys) to protect the security of communications. It not only helps the management platform maintain the integrity of data transmission, but also improves the ability to respond to abnormal behavior.

[0050] In response to determining that the number is greater than or equal to the preset number, it is determined that the collected data received within the preset historical time period does not meet the key security condition.

[0051] In specific implementation, a preset number is usually set in the management platform to evaluate whether the amount of data received within a preset historical period is normal. The preset number is set based on the normal communication behavior of the edge computing device and the expected data transmission volume. Within the preset historical period, if the amount of data received is greater than or equal to the preset number (for example, the preset number can be set to 100), it indicates that the attacker may be using the current communication key to send a large amount of forged data during the communication process in an attempt to break through the security line of the management platform; or the device may have an abnormal increase in data transmission due to configuration errors or software failures. At this time, the management platform will determine that the current communication key no longer meets the security conditions. The management platform needs to take immediate measures to protect communication security. Common measures include: generating new communication keys and distributing them to edge computing devices to interrupt the attacker's use of old keys; strengthening the monitoring of edge computing device communications, analyzing the source and nature of abnormal behavior, and preventing recurrence. The management platform can dynamically evaluate and respond to security risks in communication to ensure that data transmission between edge computing devices and the management platform is always in a secure state. Not only does it improve the security of the system, but it also enhances the sensitivity and response speed to potential threats.

[0052] In this embodiment, by real-time monitoring of the amount of received data, the management platform can promptly identify abnormal data transmission behavior. Once an abnormal amount of data transmission is detected, the management platform can quickly take measures, such as updating the communication key, to help interrupt the attacker's activities in a timely manner and protect the communication process from further security threats.

[0053] In some embodiments, determining an update time period of the communication key includes:

[0054] Determine all receiving times for receiving collected data within a preset historical time period, arrange all receiving times in chronological order, and determine the time difference between adjacent receiving times;

[0055] In specific implementation, the management platform will record the receiving time of each collected data within the preset historical time. The receiving time provides detailed time information of the communication between the edge computing device and the management platform. Arrange all receiving times in chronological order. It helps to analyze the receiving frequency and interval of the collected data and reveal the time pattern of device communication. In the time-series receiving time, calculate the time difference between each two adjacent receiving times. The size and change of the time difference can reveal the regularity and anomalies of device communication. For example: If the time difference is roughly the same, it means that the device transmits data at a stable frequency. If the time difference changes greatly, it may indicate that the device communication is unstable or there is external interference. Through this time analysis method, the management platform can better understand the communication behavior of the edge computing device and take measures to adjust the communication strategy or update the security settings when necessary.

[0056] A standard deviation of all time differences is determined, and an update period of the communication key is determined based on the standard deviation.

[0057] In specific implementation, after obtaining the time difference between all adjacent reception times, the standard deviation of these time differences is calculated. The standard deviation reflects the degree of fluctuation of the time difference, that is, the stability of the data reception interval. If the standard deviation is small, it means that the time difference does not change much, the data reception frequency is relatively stable, and the communication between the edge computing device and the management platform is normal and consistent. If the standard deviation is large, it means that the time difference changes greatly and the data reception frequency is unstable. This may indicate that there are abnormal conditions in the communication process, such as network fluctuations, communication disruption, or potential security threats. If the standard deviation is small, it may not be necessary to update the communication key frequently because the communication environment is relatively safe and stable. A longer update period can be selected. If the standard deviation is large, it indicates that the communication is unstable or there are potential risks. At this time, the update period of the communication key may need to be shortened to improve security and respond to potential threats. The management platform can dynamically adjust the update period of the communication key. It ensures that the key management strategy can adapt to changes in different communication environments to improve the security and reliability of the system. Ensure that the communication between the edge computing device and the management platform is always in a safe and efficient state.

[0058] In this embodiment, by analyzing the stability of the receiving time, the management platform can identify abnormal behavior or potential threats in the communication. When the standard deviation is large, shortening the key update period can reduce the chance of attackers using unstable communication to attack, thereby improving the security of the system. When the communication is stable (i.e., the standard deviation is small), a longer key update period can be selected to reduce unnecessary key update operations. This helps to reduce the system's computing burden and resource consumption and improve overall efficiency.

[0059] In some embodiments, determining the update time period of the communication key based on the standard deviation includes:

[0060] In response to determining that the standard deviation is less than or equal to a preset standard deviation, determining a time period within a preset time length from the current moment as an update time period;

[0061] In specific implementation, if the standard deviation is less than or equal to the preset standard deviation (the preset standard deviation is used to evaluate the stability of data reception), it indicates that the time interval of data reception is relatively stable and the communication frequency has not fluctuated significantly. The key update time period is set to a preset time length from the current moment (exemplarily, the preset time length can be set to 1 minute), indicating that the communication key will be updated within the next preset time length to ensure that even under stable conditions, the key will not be used for too long and increase security risks. Specifically, the communication key is updated within the update time period. A specific time point can be selected by a random algorithm within the update time period for key update. A pseudorandom number generator (PRNG) can be used to implement this process. A pseudorandom number generator is used to generate a random number between 0 and 1. The random number is multiplied by the preset time length to determine the specific time point of the update. For example, if the preset time length is 60 seconds and the generated random number is 0.5, the update will be performed at the 30th second in the update time period. The flexibility of the key update strategy is ensured, and it is impossible to predict when the communication key will be updated, thereby ensuring the security of communication.

[0062] In response to determining that the standard deviation is greater than the preset standard deviation, an adjustment coefficient is determined based on the difference between the standard deviation and the preset standard deviation, the product of the adjustment coefficient and the preset duration is determined as the target duration, and the time period within the target duration at the current moment is determined as the update time period.

[0063] During specific implementation, if the standard deviation is greater than the preset standard deviation, it indicates that the fluctuation of the data reception interval is large and the communication is not stable enough. At this time, the adjustment coefficient is determined according to the difference between the standard deviation and the preset standard deviation (difference = standard deviation - preset standard deviation), and the adjustment coefficient is inversely proportional to the difference (the adjustment coefficient range is between 0 and 1). The adjustment coefficient is multiplied by the preset duration to obtain the target duration, and the time period within the target duration at the current moment is determined as the update time period, so that the target duration will be less than the preset duration, so as to update the communication key faster. By shortening the update time period, it is possible to respond to potential security threats more quickly and reduce the risk of communication keys being abused. Specifically, Where F represents the adjustment coefficient, △X represents the difference between the standard deviation and the preset standard deviation, α represents the preset coefficient (exemplarily, the preset coefficient can be set to 0.8), and e represents the natural constant. After determining the time period within the target duration from the current moment as the update time period, the communication key is updated within the update time period. A specific time point can be selected for key update through a random algorithm within the update time period. A pseudo-random number generator can be used to generate a random number between 0 and 1, and the random number is multiplied by the target duration to determine the specific time point of the update. For example, if the target duration is 50 seconds and the generated random number is 0.5, the update will be performed at the 25th second in the update time period. The flexibility of the key update strategy is ensured, and it is impossible to predict when the communication key will be updated, thereby ensuring the security of communication.

[0064] In this embodiment, dynamically adjusting the key update time period can effectively deal with instability and potential security threats in communication. By shortening the key update time period under unstable conditions, the key can be updated faster, reducing the window period for the key to be exploited by attackers, thereby improving overall security. By using a random algorithm to select a specific key update time point within the update time period, the unpredictability of the key update is increased. It is difficult for attackers to foresee and exploit the timing of the key update, thereby further enhancing security.

[0065] It should be noted that the method of the embodiment of the present application can be performed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present application, and the multiple devices will interact with each other to complete the described method.

[0066] It should be noted that the above describes some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0067] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides a device communication system. The device communication system includes: an edge computing device and a management platform;

[0068] The edge computing device is configured to: encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to a management platform, wherein the registration request includes the device serial number and the encrypted serial number; in response to receiving the registration request pass information sent by the management platform, send the device information of the edge computing device to the management platform;

[0069] The management platform is configured to: in response to receiving a registration request sent by the edge computing device, decrypt the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number; in response to determining that the decrypted serial number is the same as the device serial number, send a registration request to the edge computing device.

[0070] Request a pass message.

[0071] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a device communication apparatus.

[0072] refer to Figure 3 , the device communication device is arranged in the edge computing device, including:

[0073] An encryption module 601 is configured to encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to a management platform, wherein the registration request includes the device serial number and the encrypted serial number;

[0074] The first sending module 602 is configured to send the device information of the edge computing device to the management platform in response to receiving the registration request passing information sent by the management platform.

[0075] refer to Figure 3 , the equipment communication device is arranged in the management platform, including:

[0076] A decryption module 701 is configured to, in response to receiving a registration request sent by an edge computing device, decrypt the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number;

[0077] The second sending module 702 is configured to send registration request approval information to the edge computing device in response to determining that the decrypted serial number is the same as the device serial number.

[0078] The key management module 703 is configured to, in response to determining that the edge computing device logs into the management platform, determine whether the edge computing device is logging in for the first time based on the device serial number of the edge computing device; in response to determining that the edge computing device is logging in for the first time, generate a communication key, and send the communication key to the edge computing device, so that the edge computing device encrypts the collected data based on the communication key and sends it to the management platform.

[0079] Further, the key management module 703 is specifically used for:

[0080] In response to receiving the collected data encrypted based on the communication key sent by the edge computing device, determining whether the collected data received within a preset historical period meets the key security condition;

[0081] In response to determining that the collected data received within a preset historical time period does not meet the key security condition, an update time period for the communication key is determined and the communication key is updated within the update time period.

[0082] Furthermore, the key management module 703 is also specifically used for:

[0083] Determine the amount of collected data received within a preset historical period;

[0084] In response to determining that the number is greater than or equal to the preset number, it is determined that the collected data received within the preset historical time period does not meet the key security condition.

[0085] Furthermore, the key management module 703 is also specifically used for:

[0086] Determine all receiving times for receiving collected data within a preset historical time period, arrange all receiving times in chronological order, and determine the time difference between adjacent receiving times;

[0087] A standard deviation of all time differences is determined, and an update period of the communication key is determined based on the standard deviation.

[0088] Furthermore, the key management module 703 is also specifically used for:

[0089] In response to determining that the standard deviation is less than or equal to a preset standard deviation, determining a time period within a preset time length from the current moment as an update time period;

[0090] In response to determining that the standard deviation is greater than the preset standard deviation, an adjustment coefficient is determined based on the difference between the standard deviation and the preset standard deviation, the product of the adjustment coefficient and the preset duration is determined as the target duration, and the time period within the target duration at the current moment is determined as the update time period.

[0091] For the convenience of description, the above device is described in terms of functions divided into various modules. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0092] The apparatus of the above embodiment is used to implement the corresponding device communication method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0093] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments, the present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the device communication method described in any of the above-mentioned embodiments is implemented.

[0094] Figure 4 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.

[0095] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0096] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0097] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0098] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).

[0099] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0100] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.

[0101] The electronic device of the above embodiment is used to implement the corresponding device communication method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0102] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the device communication method described in any of the above embodiments.

[0103] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.

[0104] The computer instructions stored in the storage medium of the above embodiments are used to enable the computer to execute the device communication method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0105] Based on the same concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides a computer program product, including computer program instructions. When the computer program instructions are run on a computer, the computer executes the method described in any of the above embodiments, which has the beneficial effects of the corresponding method embodiments and will not be repeated here.

[0106] It is understandable that before using the technical solutions of each embodiment of the present disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.

[0107] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly remind the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can independently choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present disclosure according to the prompt message.

[0108] As an optional but non-limiting implementation, in response to receiving the user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0109] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet relevant laws and regulations may also be applied to the implementation of the present disclosure.

[0110] A person skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.

[0111] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the following fact, that is, the details of the implementation method of these block diagram devices are highly dependent on the management platform to be implemented in the embodiments of the present application (that is, these details should be completely within the scope of understanding of those skilled in the art). In the case of elaborating specific details (for example, circuit) to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.

[0112] Although the present application has been described in conjunction with specific embodiments of the present application, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.

[0113] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the protection scope of the present application.

Claims

1. A device communication method, characterized in that: Applied to edge computing devices; the method comprises: Encrypt the device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to the management platform, where the registration request includes the device serial number and the encrypted serial number; In response to receiving the registration request passed information sent by the management platform, the device information of the edge computing device is sent to the management platform.

2. A device communication method, characterized in that: Applied to a management platform; the method comprises: In response to receiving a registration request sent by the edge computing device, decrypting the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number; In response to determining that the decrypted serial number is the same as the device serial number, sending a registration request approval message to the edge computing device.

3. The device communication method according to claim 2, characterized in that: The method further comprises: In response to determining that the edge computing device logs into the management platform, determining whether the edge computing device logs in for the first time according to the device serial number of the edge computing device; In response to determining that the edge computing device is logging in for the first time, a communication key is generated and sent to the edge computing device, so that the edge computing device encrypts the collected data based on the communication key and sends it to the management platform.

4. The device communication method according to claim 3, characterized in that: After sending the communication key to the edge computing device, the method further includes: In response to receiving the collected data encrypted based on the communication key sent by the edge computing device, determining whether the collected data received within a preset historical period meets the key security condition; In response to determining that the collected data received within a preset historical time period does not meet the key security condition, an update time period for the communication key is determined and the communication key is updated within the update time period.

5. The device communication method according to claim 4, characterized in that: The determining whether the collected data received within a preset historical period meets the key security condition includes: Determine the amount of collected data received within a preset historical period; In response to determining that the number is greater than or equal to the preset number, it is determined that the collected data received within the preset historical time period does not meet the key security condition.

6. The device communication method according to claim 4, characterized in that: The determining of the update time period of the communication key comprises: Determine all receiving times for receiving collected data within a preset historical time period, arrange all receiving times in chronological order, and determine the time difference between adjacent receiving times; A standard deviation of all time differences is determined, and an update period of the communication key is determined based on the standard deviation.

7. The device communication method according to claim 6, characterized in that: The determining of the update time period of the communication key based on the standard deviation comprises: In response to determining that the standard deviation is less than or equal to a preset standard deviation, determining a time period within a preset time length from the current moment as an update time period; In response to determining that the standard deviation is greater than the preset standard deviation, an adjustment coefficient is determined based on the difference between the standard deviation and the preset standard deviation, the product of the adjustment coefficient and the preset duration is determined as the target duration, and the time period within the target duration at the current moment is determined as the update time period.

8. A device communication system, characterized in that: include: Edge computing devices and management platforms; The edge computing device is configured to: encrypt a device serial number of the edge computing device based on a default encryption algorithm and a default key to obtain an encrypted serial number, and send a registration request to a management platform, wherein the registration request includes the device serial number and the encrypted serial number; In response to receiving the registration request passing information sent by the management platform, sending the device information of the edge computing device to the management platform; The management platform is configured to: in response to receiving a registration request sent by the edge computing device, decrypt the encrypted serial number according to a default encryption algorithm and a default key to obtain a decrypted serial number; In response to determining that the decrypted serial number is the same as the device serial number, sending a registration request approval message to the edge computing device.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the method according to claim 1 or any one of claims 2 to 7 is implemented.

10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to enable a computer to execute the method according to claim 1 or any one of claims 2 to 7.