Internet of Things terminal short-distance wireless security operation and maintenance method and system
Through the operation and maintenance terminal as a relay, encrypted communication and strict security authentication mechanism are adopted, the security risks of IoT terminals during operation and maintenance are solved, efficient and secure operation and maintenance operations are achieved, and the security and operation and maintenance efficiency of IoT terminals are improved.
Patent Information
- Application Number
- CN202510502706.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-22
AI Technical Summary
IoT terminals face security risks during operation and maintenance, especially in short-range wireless communication, lack of effective communication security protection mechanisms and credibility of identity authentication of operation and maintenance personnel, resulting in the possibility of data leakage and malicious attacks.
Through the operation and maintenance terminal as the relay between the target IoT terminal and the operation and maintenance platform, the identity authentication and operation and maintenance of the target IoT terminal are realized by encrypted communication, a strict security authentication mechanism and a fine-grained access control mechanism are established to ensure the secure transmission of operation and maintenance instructions and the on-demand authorization of operation and maintenance operations.
Effectively prevent network attacks and data leakage, improve the security of IoT terminal devices, improve the identity authentication capabilities of operation and maintenance terminals, reduce the risk of misoperation or overprivileged access, and solve the operation and maintenance problems of IoT terminals when network restrictions are restricted.
Smart Images

Figure CN120018119A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a short-range wireless security operation and maintenance method and system for an Internet of Things terminal, belonging to the technical field of equipment operation and maintenance. Background Art
[0002] With the rapid development of IoT technology, the number of IoT terminal devices has exploded, and these terminal devices are widely used in various fields, such as smart grid, smart industry, smart transportation, etc. However, IoT terminal devices face many security issues during operation and maintenance. At present, the operation and maintenance of IoT terminals are mainly carried out through remote network connection, but this method has certain security risks, such as network attacks and data leakage. In addition, for some special scenarios, such as in areas without network coverage or when the network is unstable, such as underground mines and remote mountainous areas, remote operation and maintenance is difficult to achieve due to unstable network signals.
[0003] Although short-range wireless communication technologies, such as Bluetooth, Star Flash, and NFC, can solve these problems to a certain extent, the existing short-range wireless operation and maintenance methods lack effective communication security protection mechanisms and are vulnerable to malicious attacks. In addition, during the operation and maintenance process, most operation and maintenance tools cannot guarantee the credibility of the identity of the operation and maintenance personnel and the credibility of the operation, and there is a possibility of data leakage and malicious attacks using short-range operation and maintenance tools. Therefore, it is urgent to implement a communication security protection and operation and maintenance operation access control method based on the traditional short-range communication mechanism, realize the secure transmission of operation and maintenance instructions, and authorize operation and maintenance operations on demand, so as to further improve the security protection level of IoT terminals.
[0004] The existing wireless operation and maintenance mechanism and process involve three entities: IoT terminals, operation and maintenance terminals, and remote operation and maintenance platforms. Figure 1 As shown, the current terminal operation and maintenance mainly includes two modes: remote operation and maintenance and short-distance operation and maintenance. Among them, remote operation and maintenance is mainly based on network communication. The remote operation and maintenance platform actively initiates operation and maintenance requests and operates the IoT terminal based on the standard ssh or telnet protocol. This operation and maintenance method has network security risks and is vulnerable to hacker attacks. When there are problems with the IoT terminal network, it cannot be carried out and must rely on operation and maintenance personnel to go to the site for operation and maintenance.
[0005] Close-range operation and maintenance refers to the operation and maintenance of IoT terminals by operation and maintenance personnel on site. The operation and maintenance communication methods include wired serial ports, network ports, wireless Bluetooth, infrared, WiFi, etc. However, the identity authentication function is relatively scarce in close-range communication, and the deployment locations of IoT terminals are relatively scattered, and the physical environment is relatively open. Therefore, when performing close-range operation and maintenance, the legitimacy of the operation and maintenance terminals and the access control of the operation and maintenance operations must be considered.
[0006] Existing operation and maintenance technologies and methods have improved the operation and maintenance security of terminals to a certain extent, but they still have the following shortcomings:
[0007] (1) There is a lack of effective identity authentication mechanism for operation and maintenance terminals, and the communication data during the operation and maintenance process lacks security protection. There is a security risk of using the operation and maintenance terminals as a springboard to launch network attacks on IoT terminals and even intranet business systems;
[0008] (2) There is a lack of effective access control over the operation and maintenance permissions of operation and maintenance personnel, which poses security risks such as internal data leakage, misoperation, and malicious operation. Summary of the invention
[0009] The technical problem to be solved by the present invention is to provide a short-range wireless security operation and maintenance method for an Internet of Things terminal, using the operation and maintenance terminal as a relay between the target Internet of Things terminal and the operation and maintenance platform to establish efficient and secure operation and maintenance operations.
[0010] In order to solve the above technical problems, the present invention adopts the following technical scheme: the present invention designs a short-range wireless security operation and maintenance method for an Internet of Things terminal, based on the target Internet of Things terminal communicating with an operation and maintenance platform via an operation and maintenance terminal, and the target Internet of Things terminal does not communicate directly with the operation and maintenance platform, and uses an encrypted communication method to realize identity authentication of the target Internet of Things terminal to the operation and maintenance platform through the operation and maintenance terminal, and the operation and maintenance platform obtains the access control rules corresponding to the target Internet of Things terminal, and then according to the access control rules, uses the operation and maintenance terminal to perform operation and maintenance on the target Internet of Things terminal in an encrypted communication method.
[0011] As a preferred technical solution of the present invention: perform the following steps A to F, in an encrypted communication manner, to achieve identity authentication of the target IoT terminal to the operation and maintenance platform via the operation and maintenance terminal, and obtain the access control rules corresponding to the target IoT terminal by the operation and maintenance platform;
[0012] Step A. The operation and maintenance terminal receives the operation and maintenance task issued by the operation and maintenance platform to the target IoT terminal, and the operation and maintenance terminal initiates the operation and maintenance task to the target IoT terminal, and then proceeds to step B;
[0013] Step B. The target IoT terminal generates a random number based on the operation and maintenance task , and use its provisioned key For its device identification , random numbers , and the current timestamp ,according to Encrypt to obtain the identity authentication ciphertext , and sent to the operation and maintenance terminal, which combines its device identification With ciphertext , sent to the operation and maintenance platform, and then enter step C; where, Represents the ECB encryption function based on the standard national encryption SM4;
[0014] Step C: The operation and maintenance platform receives and , call The key of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal ,according to against Decrypt and obtain , , , and proceed to step D; wherein, Indicates the device identifier after being transmitted to the operation and maintenance platform via the target IoT terminal. Represents the random number after being transmitted to the operation and maintenance platform via the target IoT terminal. Indicates the timestamp after being transmitted from the target IoT terminal to the operation and maintenance platform. Represents the ECB decryption function based on the standard national encryption SM4;
[0015] Step D. Determine the operation and maintenance platform and The device identifier of the target IoT terminal in the operation and maintenance task corresponding to the corresponding operation and maintenance terminal Whether it is consistent and whether it is judged Whether the time difference with the current time does not exceed the preset time difference threshold. If both judgments are yes, the operation and maintenance platform uses the key of the target IoT terminal to , preset access control rules corresponding to the target IoT terminal ,as well as and ,according to Encrypt and obtain ciphertext , and sent to the operation and maintenance terminal, which converts the ciphertext Forwarded to the target IoT terminal, and the operation and maintenance terminal , create a session key , then proceed to step E; Represents a hash function based on the standard national encryption SM3;
[0016] Otherwise, the operation and maintenance platform terminates the operation and maintenance tasks for the target IoT terminal;
[0017] Step E. The target IoT terminal applies its key , for the received ciphertext ,according to Decrypt and obtain the corresponding access control rules , and the random numbers in it , and judge and Are they consistent? If yes, the target IoT terminal stores access control rules. , and the target IoT terminal presses , create a session key , and then proceed to step F; otherwise, the target IoT terminal terminates the operation and maintenance task;
[0018] Step F: Based on the session key between the operation and maintenance terminal and the target IoT terminal , The encrypted communication method under the target IoT terminal and the corresponding access control rules , the application operation and maintenance terminal performs operation and maintenance on the target IoT terminal.
[0019] As a preferred technical solution of the present invention: the access control rule includes the operation and maintenance target file , Operation and maintenance , and the operation and maintenance time domain set by the operation and maintenance platform in step B according to the current time .
[0020] As a preferred technical solution of the present invention: the step F includes the following steps F1 to F3;
[0021] Step F1. The operation and maintenance terminal applies the session key , for target operation and maintenance projects ,according to Encrypt and obtain ciphertext , and send it to the target IoT terminal, and then go to step F2;
[0022] Step F2. Target IoT terminal application session key , for the received ciphertext ,according to Decrypt and obtain the target operation and maintenance project , and determine the target operation and maintenance project Whether it exceeds the operation and maintenance target file in the access control rules , Operation and maintenance , Operation and maintenance time domain , then the target IoT terminal prohibits the target operation and maintenance project Otherwise, the target IoT terminal allows and completes the target operation and maintenance project. Execution is completed and the process goes to step F3;
[0023] Step F3. The target IoT terminal applies the session key to the operation and maintenance results of the target IoT terminal in step F2. ,as well as Encrypt the operation and maintenance results to obtain the ciphertext, and return it to the operation and maintenance terminal, which uses the session key ,as well as , decrypt the received operation and maintenance result ciphertext to obtain the operation and maintenance result.
[0024] As a preferred technical solution of the present invention: the target IoT terminal and the operation and maintenance terminal communicate with each other using a short-range wireless communication protocol, and the operation and maintenance terminal and the operation and maintenance platform communicate with each other using a long-range wireless communication protocol.
[0025] Corresponding to the above, the technical problem that the present invention also needs to solve is to provide a system for a short-range wireless security operation and maintenance method for an Internet of Things terminal, with a modular design that implements each operation in the operation and maintenance method respectively, thereby improving the work efficiency of the design application.
[0026] In order to solve the above technical problems, the present invention adopts the following technical solutions: the present invention designs a system of a short-range wireless security operation and maintenance method for an Internet of Things terminal, wherein the operation and maintenance terminal comprises a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; the target Internet of Things terminal comprises a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module;
[0027] Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target IoT terminal, the short-range communication connection between the operation and maintenance terminal and the target IoT terminal is realized, and based on the communication between the wireless long-range communication module in the operation and maintenance terminal and the operation and maintenance platform, the long-range communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized;
[0028] The identity authentication module in the operation and maintenance terminal is connected to the short-distance communication module, the data encryption and decryption module, and the wireless remote communication module respectively. The identity authentication module is used to forward the communication data between the target IoT terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key. , and stored in the data encryption and decryption module; the data encryption and decryption module is connected to the operation and maintenance module and the short-range communication module respectively, and the operation and maintenance module is used to receive the target operation and maintenance project , and apply the session key through the data encryption and decryption module After encryption, it is sent to the target IoT terminal via the short-distance communication module, and the data encryption and decryption module applies the session key to the ciphertext of the operation and maintenance results received from the target IoT terminal via the short-distance communication module. Decrypt and obtain the operation and maintenance results and feed them back to the operation and maintenance module;
[0029] The identity authentication module in the target IoT terminal is connected to the short-distance communication module, the data encryption and decryption module, and the access control module respectively. The identity authentication module constructs the identity authentication data, and the data encryption and decryption module is used to encrypt the identity authentication ciphertext. , and then transmit it to the operation and maintenance terminal through the short-distance communication module; the identity authentication module receives the ciphertext from the operation and maintenance platform through the short-distance communication module , and calls the data encryption and decryption module for decryption, the identity authentication module completes the identity authentication based on the decryption result, and sends the access control rules in the decryption result to the access control module for storage; at the same time, the data encryption and decryption module is connected to the short-distance communication module and the access control module respectively, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module receives the ciphertext from the operation and maintenance terminal via the short-distance communication module. Decrypt and obtain the target operation and maintenance project And send it to the access control module, the access control module will control the target operation and maintenance project according to the access control rules. Perform authority control, and the operation and maintenance module implements the target operation and maintenance project based on the authority control of the access control module execution.
[0030] As a preferred technical solution of the present invention: the access control module in the target IoT terminal includes a permission control module and an access control rule base connected to each other, wherein the access control rule base is connected to the identity authentication module in the target IoT terminal, the identity authentication module sends the access control rules in the decryption result to the access control rule base in the access control module for storage, the permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target IoT terminal, and the permission control module receives the data encryption and decryption module's Decrypted to obtain the target operation and maintenance project The permission control module controls the target operation and maintenance project according to the access control rules in the access control rule library. Perform permission control. The operation and maintenance module implements the target operation and maintenance project based on the permission control of access control rules. execution.
[0031] The method and system for short-range wireless security operation and maintenance of an IoT terminal described in the present invention adopt the above technical solution and have the following technical effects compared with the prior art:
[0032] (1) The present invention designs a short-range wireless security operation and maintenance method and system for an Internet of Things terminal, using the operation and maintenance terminal as a relay between the target Internet of Things terminal and the operation and maintenance platform, and applying an encrypted communication method to achieve identity authentication and operation and maintenance between the target Internet of Things terminal and the operation and maintenance platform. By establishing a strict security authentication mechanism, network attacks and data leakage are effectively prevented, the security of the target Internet of Things terminal equipment is improved, and the identity authentication capability of the target Internet of Things terminal for the operation and maintenance terminal is enhanced; and a fine-grained access control mechanism is designed to enhance the security protection capability of the target Internet of Things terminal during the operation and maintenance phase by comparing the operation and maintenance time, operation and maintenance object, operation and maintenance operation and other access control factors during the operation and maintenance operation process and the identity authentication process, thereby avoiding the impact of malicious operation and maintenance behaviors such as misoperation or unauthorized access on the terminal; the design scheme does not need to rely on the network connection between the target Internet of Things terminal and the operation and maintenance platform, which solves the operation and maintenance problem of the target Internet of Things terminal under the condition of network restriction, reduces the workload of the operation and maintenance personnel, and improves the operation and maintenance efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 It is a schematic diagram of the architecture of the wireless operation and maintenance mechanism of the prior art;
[0034] Figure 2 It is a schematic diagram of the architecture of a short-range wireless security operation and maintenance method system for an Internet of Things terminal designed by the present invention;
[0035] Figure 3 It is a flow chart of a method for designing a short-range wireless security operation and maintenance method for an Internet of Things terminal according to the present invention;
[0036] Figure 4 It is a schematic diagram of an operation and maintenance terminal in a system of a short-range wireless security operation and maintenance method for an Internet of Things terminal designed by the present invention;
[0037] Figure 5 It is a schematic diagram of a target Internet of Things terminal in the system of the Internet of Things terminal short-range wireless security operation and maintenance method designed by the present invention;
[0038] Figure 6 It is a schematic diagram of the application implementation of the access control module in the short-range wireless security operation and maintenance method system of the Internet of Things terminal designed by the present invention. DETAILED DESCRIPTION
[0039] The specific implementation modes of the present invention will be further described in detail below in conjunction with the accompanying drawings.
[0040] The present invention designs a short-range wireless security operation and maintenance method and system for an Internet of Things terminal, and the specific design ideas are as follows:
[0041] (1) Design an identity authentication and key negotiation mechanism between the operation and maintenance terminal and the target IoT terminal to be operated and maintained during the close-range operation and maintenance process, to ensure that only legitimate operation and maintenance personnel can perform operation and maintenance operations on the target IoT terminal device;
[0042] (2) Design an access control mechanism for close-range operation and maintenance operations to control the permissions of operation and maintenance personnel during the operation and maintenance process, ensure that operation and maintenance personnel operate in accordance with the established operation and maintenance process, and ensure that the operation and maintenance work is carried out efficiently and orderly;
[0043] (3) Provide a target IoT terminal short-range wireless security operation and maintenance system, including a target IoT terminal, an operation and maintenance platform and an operation and maintenance terminal; after the operation and maintenance terminal receives the operation and maintenance task issued by the operation and maintenance platform, it completes identity authentication with the target IoT terminal based on short-range communication, and performs operation and maintenance operations in accordance with the operation and maintenance requirements of the operation and maintenance platform. On the basis of ensuring the security and reliability of the operation and maintenance terminal, fine-grained authorization and access control of the operation and maintenance operations are achieved.
[0044] According to the above design ideas, the present invention designs a short-range wireless security operation and maintenance method for an Internet of Things terminal, such as Figure 2 As shown, based on the target IoT terminal communicating with the operation and maintenance platform via the operation and maintenance terminal, and the target IoT terminal not communicating directly with the operation and maintenance platform, the identity authentication of the target IoT terminal to the operation and maintenance platform is realized through the operation and maintenance terminal in an encrypted communication manner, and the operation and maintenance platform obtains the access control rules corresponding to the target IoT terminal, and then according to the access control rules, the operation and maintenance terminal is used to perform operation and maintenance on the target IoT terminal in an encrypted communication manner, so as to ensure the legitimacy of the terminal identity and the minimum authorization of the operation and maintenance operations.
[0045] In practical applications, such as Figure 3 As shown, the design of the present invention specifically executes the following steps A to F, using encrypted communication to realize identity authentication of the target IoT terminal to the operation and maintenance platform through the operation and maintenance terminal, and the operation and maintenance platform obtains the access control rules corresponding to the target IoT terminal.
[0046] Step A: The operation and maintenance terminal receives the operation and maintenance task about the target IoT terminal issued by the operation and maintenance platform, and initiates the operation and maintenance task to the target IoT terminal, and then proceeds to step B.
[0047] Step B. The target IoT terminal generates a random number based on the operation and maintenance task , and use its provisioned key For its device identification , random numbers , and the current timestamp ,according to Encrypt to obtain the identity authentication ciphertext , and sent to the operation and maintenance terminal, which combines its device identification With ciphertext , sent to the operation and maintenance platform, and then enter step C; where, It represents the ECB encryption function based on the standard national encryption SM4. Due to the introduction of the timestamp, the freshness and non-repetitiveness of identity authentication can be guaranteed.
[0048] Step C: The operation and maintenance platform receives and , call The key of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal ,according to against Decrypt and obtain , , , and proceed to step D; wherein, Indicates the device identifier after being transmitted to the operation and maintenance platform via the target IoT terminal. Represents the random number after being transmitted to the operation and maintenance platform via the target IoT terminal. Indicates the timestamp after being transmitted from the target IoT terminal to the operation and maintenance platform. Represents the ECB decryption function based on the standard national encryption SM4.
[0049] Step D. Determine the operation and maintenance platform and The device identifier of the target IoT terminal in the operation and maintenance task corresponding to the corresponding operation and maintenance terminal Whether it is consistent and whether it is judged Whether the time difference with the current time does not exceed the preset time difference threshold. If both judgments are yes, the operation and maintenance platform uses the key of the target IoT terminal to , preset access control rules corresponding to the target IoT terminal ,as well as and ,according to Encrypt and obtain ciphertext , and sent to the operation and maintenance terminal, which converts the ciphertext Forwarded to the target IoT terminal, and the operation and maintenance terminal , create a session key , then proceed to step E; Indicates a hash function based on the standard national encryption SM3; otherwise, the operation and maintenance platform terminates the operation and maintenance tasks for the target IoT terminal.
[0050] Design access control rules here Including operation and maintenance target files , Operation and maintenance , and the operation and maintenance time domain set by the operation and maintenance platform in step B according to the current time .
[0051] Step E. The target IoT terminal applies its key , for the received ciphertext ,according to Decrypt and obtain the corresponding access control rules , and the random numbers in it , and judge and Are they consistent? If yes, the target IoT terminal stores access control rules. , and the target IoT terminal presses , create a session key , and then proceed to step F; otherwise, the target IoT terminal terminates the operation and maintenance task.
[0052] Step F: Based on the session key between the operation and maintenance terminal and the target IoT terminal , The encrypted communication method under the target IoT terminal and the corresponding access control rules , the application operation and maintenance terminal performs operation and maintenance on the target IoT terminal.
[0053] In practical application, the above step F is Figure 6 As shown, the specific design executes the following steps F1 to F3.
[0054] Step F1. The operation and maintenance terminal applies the session key , for target operation and maintenance projects ,according to Encrypt and obtain ciphertext , and send it to the target IoT terminal, and then go to step F2.
[0055] Step F2. Target IoT terminal application session key , for the received ciphertext ,according to Decrypt and obtain the target operation and maintenance project , and determine the target operation and maintenance project Whether it exceeds the operation and maintenance target file in the access control rules , Operation and maintenance , Operation and maintenance time domain , then the target IoT terminal prohibits the target operation and maintenance project Otherwise, the target IoT terminal allows and completes the target operation and maintenance project. Execution is completed and the process goes to step F3.
[0056] Step F3. The target IoT terminal applies the session key to the operation and maintenance results of the target IoT terminal in step F2. ,as well as Encrypt the operation and maintenance results to obtain the ciphertext, and return it to the operation and maintenance terminal, which uses the session key ,as well as , decrypt the received operation and maintenance result ciphertext to obtain the operation and maintenance result.
[0057] The short-range wireless security operation and maintenance method for the Internet of Things terminal designed by the present invention is applied in practice, such as Figure 2 As shown in the figure, the target IoT terminal and the operation and maintenance terminal use short-range wireless communication protocols such as Bluetooth, WiFi, and Star Flash for communication, and the operation and maintenance terminal and the operation and maintenance platform use long-range wireless communication protocols such as 4G and 5G for communication, and specifically design the corresponding application system, such as Figure 4 As shown, the designed operation and maintenance terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; Figure 5 As shown, the target IoT terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module.
[0058] Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target Internet of Things terminal, the short-range communication connection between the operation and maintenance terminal and the target Internet of Things terminal is realized, and based on the communication between the wireless long-range communication module in the operation and maintenance terminal and the operation and maintenance platform, the long-range communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized.
[0059] like Figure 4 and Figure 5 As shown, the identity authentication module in the operation and maintenance terminal is connected to the short-distance communication module, the data encryption and decryption module, and the wireless remote communication module respectively. The identity authentication module is used to forward the communication data between the target IoT terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key , and stored in the data encryption and decryption module; the data encryption and decryption module is connected to the operation and maintenance module and the short-range communication module respectively, and the operation and maintenance module is used to receive the target operation and maintenance project , and apply the session key through the data encryption and decryption module After encryption, it is sent to the target IoT terminal via the short-distance communication module, and the data encryption and decryption module applies the session key to the ciphertext of the operation and maintenance results received from the target IoT terminal via the short-distance communication module. Decrypt and obtain the operation and maintenance results and feed them back to the operation and maintenance module.
[0060] The identity authentication module in the target IoT terminal is connected to the short-distance communication module, the data encryption and decryption module, and the access control module respectively. The identity authentication module constructs the identity authentication data, and the data encryption and decryption module is used to encrypt the identity authentication ciphertext. , and then transmit it to the operation and maintenance terminal through the short-distance communication module; the identity authentication module receives the ciphertext from the operation and maintenance platform through the short-distance communication module , and calls the data encryption and decryption module for decryption, the identity authentication module completes the identity authentication based on the decryption result, and sends the access control rules in the decryption result to the access control module for storage; at the same time, the data encryption and decryption module is connected to the short-distance communication module and the access control module respectively, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module receives the ciphertext from the operation and maintenance terminal via the short-distance communication module. Decrypt and obtain the target operation and maintenance project And send it to the access control module, the access control module will control the target operation and maintenance project according to the access control rules. Perform authority control, and the operation and maintenance module implements the target operation and maintenance project based on the authority control of the access control module execution.
[0061] In further practical applications, the access control module in the target IoT terminal is designed to include a permission control module and an access control rule base connected to each other, wherein the access control rule base is connected to the identity authentication module in the target IoT terminal, the identity authentication module sends the access control rules in the decryption result to the access control rule base in the access control module for storage, the permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target IoT terminal, and the permission control module receives the data encryption and decryption module's Decrypted to obtain the target operation and maintenance project The permission control module controls the target operation and maintenance project according to the access control rules in the access control rule library. Perform permission control. The operation and maintenance module implements the target operation and maintenance project based on the permission control of access control rules. execution.
[0062] The short-range wireless security operation and maintenance method and system of the Internet of Things terminal designed by the above technical scheme uses the operation and maintenance terminal as the relay between the target Internet of Things terminal and the operation and maintenance platform, and applies encrypted communication to realize identity authentication and operation and maintenance between the target Internet of Things terminal and the operation and maintenance platform. By establishing a strict security authentication mechanism, it can effectively prevent network attacks and data leakage, improve the security of the target Internet of Things terminal equipment, and enhance the identity authentication capability of the target Internet of Things terminal for the operation and maintenance terminal; and design a fine-grained access control mechanism, by comparing the operation and maintenance time, operation and maintenance object, operation and maintenance operation and other access control factors during the operation and maintenance operation process and the identity authentication process, to enhance the security protection capability of the target Internet of Things terminal during the operation and maintenance stage, and avoid the impact of malicious operation and maintenance behaviors such as misoperation or unauthorized access on the terminal; the design scheme does not need to rely on the network connection between the target Internet of Things terminal and the operation and maintenance platform, which solves the operation and maintenance problem of the target Internet of Things terminal under the condition of network restriction, reduces the workload of operation and maintenance personnel, and improves operation and maintenance efficiency.
[0063] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments, and various changes can be made within the knowledge scope of ordinary technicians in this field without departing from the purpose of the present invention.
Claims
1. A short-range wireless security operation and maintenance method for an Internet of Things terminal, characterized by: Based on the target IoT terminal communicating with the operation and maintenance platform via the operation and maintenance terminal, and the target IoT terminal not communicating directly with the operation and maintenance platform, the identity authentication of the target IoT terminal to the operation and maintenance platform is realized through the operation and maintenance terminal in an encrypted communication manner, and the operation and maintenance platform obtains the access control rules corresponding to the target IoT terminal, and then according to the access control rules, the operation and maintenance terminal is used to perform operation and maintenance on the target IoT terminal in an encrypted communication manner.
2. According to claim 1, a method for short-range wireless security operation and maintenance of an Internet of Things terminal is characterized by: Execute the following steps A to F, and use encrypted communication to authenticate the target IoT terminal to the operation and maintenance platform through the operation and maintenance terminal, and obtain the access control rules corresponding to the target IoT terminal through the operation and maintenance platform; Step A. The operation and maintenance terminal receives the operation and maintenance task issued by the operation and maintenance platform to the target IoT terminal, and the operation and maintenance terminal initiates the operation and maintenance task to the target IoT terminal, and then proceeds to step B; Step B. The target IoT terminal generates a random number based on the operation and maintenance task , and use its provisioned key For its device identification , random numbers , and the current timestamp ,according to Encrypt to obtain the identity authentication ciphertext , and sent to the operation and maintenance terminal, which combines its device identification With ciphertext , sent to the operation and maintenance platform, and then enter step C; where, Represents the ECB encryption function based on the standard national encryption SM4; Step C: The operation and maintenance platform receives and , call The key of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal ,according to against Decrypt and obtain , , , and proceed to step D; wherein, Indicates the device identifier after being transmitted to the operation and maintenance platform via the target IoT terminal. Represents the random number after being transmitted to the operation and maintenance platform via the target IoT terminal. Indicates the timestamp after being transmitted from the target IoT terminal to the operation and maintenance platform. Represents the ECB decryption function based on the standard national encryption SM4; Step D. Determine the operation and maintenance platform and The device identifier of the target IoT terminal in the operation and maintenance task corresponding to the corresponding operation and maintenance terminal Whether it is consistent and whether it is judged Whether the time difference with the current time does not exceed the preset time difference threshold. If both judgments are yes, the operation and maintenance platform uses the key of the target IoT terminal to , preset access control rules corresponding to the target IoT terminal ,as well as and ,according to Encrypt and obtain ciphertext , and sent to the operation and maintenance terminal, which converts the ciphertext Forwarded to the target IoT terminal, and the operation and maintenance terminal , create a session key , then proceed to step E; Represents a hash function based on the standard national encryption SM3; Otherwise, the operation and maintenance platform terminates the operation and maintenance tasks for the target IoT terminal; Step E. The target IoT terminal applies its key , for the received ciphertext ,according to Decrypt and obtain the corresponding access control rules , and the random numbers in it , and judge and Are they consistent? If yes, the target IoT terminal stores access control rules. , and the target IoT terminal presses , create a session key , and then proceed to step F; otherwise, the target IoT terminal terminates the operation and maintenance task; Step F: Based on the session key between the operation and maintenance terminal and the target IoT terminal , The encrypted communication method under the target IoT terminal and the corresponding access control rules , the application operation and maintenance terminal performs operation and maintenance on the target IoT terminal.
3. According to claim 2, a method for short-range wireless security operation and maintenance of an Internet of Things terminal is characterized by: The access control rules include operation and maintenance target files , Operation and maintenance , and the operation and maintenance time domain set by the operation and maintenance platform in step B according to the current time .
4. According to claim 3, a method for short-range wireless security operation and maintenance of an Internet of Things terminal is characterized by: The step F includes the following steps F1 to F3; Step F1. The operation and maintenance terminal applies the session key , for target operation and maintenance projects ,according to Encrypt and obtain ciphertext , and send it to the target IoT terminal, and then go to step F2; Step F2. Target IoT terminal application session key , for the received ciphertext ,according to Decrypt and obtain the target operation and maintenance project , and determine the target operation and maintenance project Whether it exceeds the operation and maintenance target file in the access control rules , Operation and maintenance , Operation and maintenance time domain , then the target IoT terminal prohibits the target operation and maintenance project Otherwise, the target IoT terminal allows and completes the target operation and maintenance project. Execution is completed and the process goes to step F3; Step F3. The target IoT terminal applies the session key to the operation and maintenance results of the target IoT terminal in step F2. ,as well as Encrypt the operation and maintenance results to obtain the ciphertext, and return it to the operation and maintenance terminal, which uses the session key ,as well as , decrypt the received operation and maintenance result ciphertext to obtain the operation and maintenance result.
5. A method for short-range wireless security operation and maintenance of an Internet of Things terminal according to any one of claims 1 to 4, characterized in that: The target IoT terminal and the operation and maintenance terminal communicate with each other using a short-range wireless communication protocol, and the operation and maintenance terminal and the operation and maintenance platform communicate with each other using a long-range wireless communication protocol.
6. A system for implementing the method for short-range wireless security operation and maintenance of an Internet of Things terminal as described in claim 4, characterized in that: The operation and maintenance terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; the target Internet of Things terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module; Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target IoT terminal, the short-range communication connection between the operation and maintenance terminal and the target IoT terminal is realized, and based on the communication between the wireless long-range communication module in the operation and maintenance terminal and the operation and maintenance platform, the long-range communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized; The identity authentication module in the operation and maintenance terminal is connected to the short-distance communication module, the data encryption and decryption module, and the wireless remote communication module respectively. The identity authentication module is used to forward the communication data between the target IoT terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key. , and stored in the data encryption and decryption module; the data encryption and decryption module is connected to the operation and maintenance module and the short-range communication module respectively, and the operation and maintenance module is used to receive the target operation and maintenance project , and apply the session key through the data encryption and decryption module After encryption, it is sent to the target IoT terminal via the short-distance communication module, and the data encryption and decryption module applies the session key to the ciphertext of the operation and maintenance results received from the target IoT terminal via the short-distance communication module. Decrypt and obtain the operation and maintenance results and feed them back to the operation and maintenance module; The identity authentication module in the target IoT terminal is connected to the short-distance communication module, the data encryption and decryption module, and the access control module respectively. The identity authentication module constructs the identity authentication data, and the data encryption and decryption module is used to encrypt the identity authentication ciphertext. , and then transmit it to the operation and maintenance terminal through the short-distance communication module; the identity authentication module receives the ciphertext from the operation and maintenance platform through the short-distance communication module , and calls the data encryption and decryption module for decryption, the identity authentication module completes the identity authentication based on the decryption result, and sends the access control rules in the decryption result to the access control module for storage; at the same time, the data encryption and decryption module is connected to the short-distance communication module and the access control module respectively, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module receives the ciphertext from the operation and maintenance terminal via the short-distance communication module. Decrypt and obtain the target operation and maintenance project And send it to the access control module, the access control module will control the target operation and maintenance project according to the access control rules. Perform authority control, and the operation and maintenance module implements the target operation and maintenance project based on the authority control of the access control module execution.
7. The system for implementing a short-range wireless security operation and maintenance method for an Internet of Things terminal according to claim 6 is characterized in that: The access control module in the target IoT terminal includes a permission control module and an access control rule base connected to each other, wherein the access control rule base is connected to the identity authentication module in the target IoT terminal, the identity authentication module sends the access control rules in the decryption result to the access control rule base in the access control module for storage, the permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target IoT terminal, and the permission control module receives the data encryption and decryption module's Decrypted to obtain the target operation and maintenance project The permission control module controls the target operation and maintenance project according to the access control rules in the access control rule library. Perform permission control. The operation and maintenance module implements the target operation and maintenance project based on the permission control of access control rules. execution.
Citation Information
Patent Citations
Method for user administration of a field device
CN110120866A
Security access system of novel power business terminal based on SDP
CN114553430A
Bid invitation information encryption system, method and device based on big data
CN114727282A
5G user equipment access authentication method and system
CN116782222A
Evolved packed core (EPC) solution for restricted local operator services (RLOST) access using device authentication
US20220132315A1