A Method and System for Short-Range Wireless Secure Operation and Maintenance of Internet of Things Terminals
Through the operation and maintenance terminal as a relay, encrypted communication and fine-grained access control are adopted to solve the operation and maintenance security problems of IoT terminal devices in the network-free coverage area, and the identity authentication and legal operation and maintenance operations are realized, which improves security and efficiency.
Patent Information
- Application Number
- CN202510502706.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-04-22
AI Technical Summary
During the operation and maintenance process, IoT terminal devices have security risks such as network attacks, data leakage, and untrustworthy identity of operation and maintenance personnel. Especially in areas without network coverage, the existing short-range wireless operation and maintenance methods lack effective communication security protection mechanisms and identity authentication.
Through the operation and maintenance terminal as a relay, encrypted communication method is used to achieve identity authentication and access control of the target Internet of Things terminal and operation and maintenance platform, and a fine-grained access control mechanism is designed to ensure the legality and security of operation and maintenance operations.
Effectively prevent network attacks and data leakage, improve the identity authentication capabilities of the operation and maintenance terminal, avoid misoperation and override of access, improve operation and maintenance efficiency, and solve the operation and maintenance problems without network coverage.
Smart Images

Figure CN120018119B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and system for close - range wireless security operation and maintenance of Internet of Things (IoT) terminals, belonging to the technical field of equipment operation and maintenance. Background Art
[0002] With the rapid development of IoT technology, the number of IoT terminal devices has increased explosively. These terminal devices are widely used in various fields, such as smart grids, smart industries, and smart transportation. However, IoT terminal devices face many security problems during operation and maintenance. Currently, the operation and maintenance of IoT terminals mainly rely on remote network connections, but this method has certain security risks, such as network attacks and data leakage. In addition, for some special scenarios, such as areas without network coverage or areas with unstable networks, such as underground mines and remote mountainous areas, due to unstable network signals, remote operation and maintenance are difficult to achieve.
[0003] While close - range wireless communication technologies, such as Bluetooth, XingShan, NFC, etc., can solve these problems to a certain extent, the existing close - range wireless operation and maintenance methods lack effective communication security protection mechanisms and are easily attacked maliciously. And during operation and maintenance, most operation and maintenance tools cannot ensure the credibility of the identity of operation and maintenance personnel and the credibility of operations, there is a possibility of data leakage and malicious attacks using close - range operation and maintenance tools. Therefore, it is urgent to implement a communication security protection and operation and maintenance operation access control method based on breaking through traditional close - range communication mechanisms to achieve secure transmission of operation and maintenance instructions, on - demand authorization of operation and maintenance operations, and further improve the security protection level of IoT terminals.
[0004] The existing wireless operation and maintenance mechanism and process involve three types of entities: IoT terminals, operation and maintenance terminals, and remote operation and maintenance platforms. As Figure 1 shown, currently, terminal operation and maintenance mainly include two methods: remote operation and maintenance and close - range operation and maintenance. Among them, remote operation and maintenance is mainly based on network communication. The remote operation and maintenance platform actively initiates operation and maintenance requests and operates on IoT terminals based on standard ssh or telnet protocols. This operation and maintenance method has network security risks and is easily attacked by hackers. And when there are problems with the IoT terminal network, it cannot be carried out and must rely on operation and maintenance personnel to go to the site for operation and maintenance.
[0005] The close - range operation and maintenance method means that operation and maintenance personnel perform operation and maintenance operations on IoT terminals on - site. The operation and maintenance communication methods include wired serial ports, network ports, and wireless methods such as Bluetooth, infrared, and wifi. However, the identity authentication function in current close - range communication is relatively lacking, and the deployment locations of IoT terminals are relatively scattered and the physical environment is relatively open. Therefore, when performing close - range operation and maintenance, the legitimacy of operation and maintenance terminals and the access control of operation and maintenance operations must be considered.
[0006] The existing operation and maintenance technologies and methods have improved the operation and maintenance security of terminals to a certain extent, but there are the following deficiencies:
[0007] (1) There is no effective identity authentication mechanism for the operation and maintenance terminals, and the communication data during the operation and maintenance process lacks security protection, resulting in the security risk of launching network attacks on the Internet of Things terminals and even the intranet business system using the operation and maintenance terminals as a springboard;
[0008] (2) There is no effective access control for the operation and maintenance permissions of operation and maintenance personnel, resulting in the security risks of internal data leakage, misoperation, and malicious operation. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to provide a method for short-distance wireless secure operation and maintenance of Internet of Things terminals, using the operation and maintenance terminal as a relay between the target Internet of Things terminal and the operation and maintenance platform to establish an efficient and secure operation and maintenance operation.
[0010] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs a method for short-distance wireless secure operation and maintenance of Internet of Things terminals. Based on the target Internet of Things terminal communicating with the operation and maintenance platform through the operation and maintenance terminal, and the target Internet of Things terminal not communicating directly with the operation and maintenance platform, in an encrypted communication manner, the present invention realizes the identity authentication of the target Internet of Things terminal to the operation and maintenance platform through the operation and maintenance terminal, and the operation and maintenance platform obtains the access control rules corresponding to the target Internet of Things terminal. Then, according to the access control rules, in an encrypted communication manner, the operation and maintenance terminal is used to perform operation and maintenance on the target Internet of Things terminal.
[0011] As a preferred technical solution of the present invention: The following steps A to F are executed to realize the identity authentication of the target Internet of Things terminal to the operation and maintenance platform and the operation and maintenance platform to obtain the access control rules corresponding to the target Internet of Things terminal in an encrypted communication manner;
[0012] Step A. Based on the operation and maintenance terminal receiving the operation and maintenance task of the target Internet of Things terminal issued by the operation and maintenance platform, the operation and maintenance terminal initiates the operation and maintenance task to the target Internet of Things terminal and enters Step B;
[0013] Step B. The target Internet of Things terminal generates a random number according to the operation and maintenance task, and uses its preset key to encrypt its device identifier , the random number , and the current timestamp according to to obtain the identity authentication ciphertext , and sends it to the operation and maintenance terminal. The operation and maintenance terminal combines its device identifier with the ciphertext and sends it to the operation and maintenance platform, and then enters Step C; where Represents the ECB encryption function based on the standard national cryptographic algorithm SM4;
[0014] Step C. The operation and maintenance platform, based on the received and , calls the key of the target Internet of Things terminal in the operation and maintenance task corresponding to the operation and maintenance terminal , and decrypts for to obtain , , , and enters Step D; where represents the device identifier after being transmitted to the operation and maintenance platform by the target Internet of Things terminal, represents the random number after being transmitted to the operation and maintenance platform by the target Internet of Things terminal, represents the timestamp after being transmitted to the operation and maintenance platform by the target Internet of Things terminal, represents the ECB decryption function based on the standard national cryptographic algorithm SM4;
[0015] Step D. The operation and maintenance platform determines whether is consistent with the device identifier of the target Internet of Things terminal in the operation and maintenance task corresponding to the operation and maintenance terminal , and determines whether the time difference between and the current time does not exceed the preset time difference threshold. If both determinations are yes, the operation and maintenance platform uses the key of the target Internet of Things terminal to encrypt the preset access control rule corresponding to the target Internet of Things terminal, and according to to obtain the ciphertext , and sends it to the operation and maintenance terminal. The operation and maintenance terminal forwards the ciphertext to the target Internet of Things terminal, and the operation and maintenance terminal creates a session key according to , and then enters Step E; represents the hash function based on the standard national cryptographic algorithm SM3;
[0016] Otherwise, the operation and maintenance platform terminates the operation and maintenance task for the target Internet of Things terminal;
[0017] Step E. The target Internet of Things terminal applies its key to decrypt the received ciphertext according to to obtain the corresponding access control rule and the random number in it, and determines Whether it is consistent. If so, the target Internet of Things terminal stores the access control rules , and the target Internet of Things terminal creates a session key according to , and then enters step F; otherwise, the target Internet of Things terminal terminates the operation and maintenance task; , and then enters step F; otherwise, the target Internet of Things terminal terminates the operation and maintenance task; , and then enters step F; otherwise, the target Internet of Things terminal terminates the operation and maintenance task;
[0018] Step F. Based on the encrypted communication method between the operation and maintenance terminal and the target Internet of Things terminal according to the session key 、 , and the access control rules corresponding to the target Internet of Things terminal , the operation and maintenance terminal performs operation and maintenance on the target Internet of Things terminal.
[0019] As a preferred technical solution of the present invention: The access control rules include the operation and maintenance target file , the operation and maintenance operation , and the operation and maintenance time domain set by the operation and maintenance platform according to the current time in step B .
[0020] As a preferred technical solution of the present invention: Step F includes the following steps F1 to F3;
[0021] Step F1. The operation and maintenance terminal applies the session key to encrypt the target operation and maintenance project according to to obtain the ciphertext , and sends it to the target Internet of Things terminal, and then enters step F2;
[0022] Step F2. The target Internet of Things terminal applies the session key to decrypt the received ciphertext according to to obtain the target operation and maintenance project , and determines whether the target operation and maintenance project exceeds the operation and maintenance target file , the operation and maintenance operation , and the operation and maintenance time domain in the access control rules. If so, the target Internet of Things terminal prohibits the execution of the target operation and maintenance project ; otherwise, the target Internet of Things terminal allows and completes the execution of the target operation and maintenance project , completes, and enters step F3;
[0023] Step F3. The target Internet of Things terminal applies the session key and Encrypt it to obtain the ciphertext of the operation and maintenance result, and return it to the operation and maintenance terminal. The operation and maintenance terminal applies the session key and to decrypt the received ciphertext of the operation and maintenance result to obtain the operation and maintenance result.
[0024] As a preferred technical solution of the present invention: The target Internet of Things terminal and the operation and maintenance terminal communicate with each other using a short-range wireless communication protocol, and the operation and maintenance terminal and the operation and maintenance platform communicate with each other using a long-range wireless communication protocol.
[0025] Correspondingly, the technical problem to be solved by the present invention is to provide a system for the short-range wireless security operation and maintenance method of the Internet of Things terminal. The modular design realizes each operation in the operation and maintenance method respectively, improving the working efficiency of the design and application.
[0026] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs a system for the short-range wireless security operation and maintenance method of the Internet of Things terminal. The operation and maintenance terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; the target Internet of Things terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module;
[0027] Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target Internet of Things terminal, a short-range communication connection between the operation and maintenance terminal and the target Internet of Things terminal is realized. Based on the communication between the wireless remote communication module in the operation and maintenance terminal and the operation and maintenance platform, a remote communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized;
[0028] The identity authentication module in the operation and maintenance terminal is respectively connected to the short-range communication module, the data encryption and decryption module, and the wireless remote communication module. The identity authentication module is used to forward the communication data between the target Internet of Things terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key and store it in the data encryption and decryption module; the data encryption and decryption module is respectively connected to the operation and maintenance module and the short-range communication module. The operation and maintenance module is used to receive the target operation and maintenance project and encrypt it through the data encryption and decryption module using the session key and send it to the target Internet of Things terminal through the short-range communication module. And the data encryption and decryption module decrypts the ciphertext of the operation and maintenance result received from the target Internet of Things terminal through the short-range communication module using the session key to obtain the operation and maintenance result and feedback it to the operation and maintenance module;
[0029] In the target Internet of Things (IoT) terminal, the identity authentication module is respectively connected to the short-range communication module, the data encryption and decryption module, and the access control module. The identity authentication module constructs identity authentication data and uses the data encryption and decryption module to encrypt it to obtain the identity authentication ciphertext. Then, it transmits the ciphertext to the operation and maintenance terminal through the short-range communication module. The identity authentication module receives the ciphertext from the operation and maintenance platform through the short-range communication module. It then calls the data encryption and decryption module to decrypt the ciphertext. The identity authentication module completes the identity authentication based on the decryption result and sends the access control rules in the decryption result to the access control module for storage. At the same time, the data encryption and decryption module is respectively connected to the short-range communication module and the access control module, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module decrypts the ciphertext received from the operation and maintenance terminal through the short-range communication module. to obtain the target operation and maintenance project. and sends it to the access control module. The access control module performs permission control on the target operation and maintenance project. based on the access control rules, and the operation and maintenance module realizes the execution of the target operation and maintenance project. based on the permission control of the access control module.
[0030] As a preferred technical solution of the present invention: The access control module in the target IoT terminal includes a permission control module and an access control rule library that are connected to each other. Among them, the access control rule library is connected to the identity authentication module in the target IoT terminal. The identity authentication module sends the access control rules in the decryption result to the access control rule library in the access control module for storage. The permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target IoT terminal. The permission control module receives the target operation and maintenance project obtained by decrypting the ciphertext by the data encryption and decryption module. The permission control module performs permission control on the target operation and maintenance project based on the access control rules in the access control rule library, and the operation and maintenance module realizes the execution of the target operation and maintenance project based on the permission control of the access control rules. based on the access control rules in the access control rule library, and the operation and maintenance module realizes the execution of the target operation and maintenance project based on the permission control of the access control rules. based on the access control rules in the access control rule library, and the operation and maintenance module realizes the execution of the target operation and maintenance project based on the permission control of the access control rules. based on the permission control of the access control rules.
[0031] For the method and system for short-range wireless secure operation and maintenance of an IoT terminal of the present invention, compared with the prior art using the above technical solutions, it has the following technical effects:
[0032] (1) The present invention designs a method and system for close-range wireless security operation and maintenance of Internet of Things terminals. Using the operation and maintenance terminal as a relay between the target Internet of Things terminal and the operation and maintenance platform, and applying an encrypted communication method to achieve identity authentication and operation and maintenance between the target Internet of Things terminal and the operation and maintenance platform. By establishing a strict security authentication mechanism, it effectively prevents network attacks and data leakage, improves the security of the target Internet of Things terminal device, and enhances the identity authentication ability of the target Internet of Things terminal for the operation and maintenance terminal. And a fine-grained access control mechanism is designed. By comparing access control factors such as operation and maintenance time, operation and maintenance object, and operation and maintenance operation during the operation and maintenance process and the identity authentication process, the security protection ability during the operation and maintenance stage of the target Internet of Things terminal is enhanced, avoiding the impact of malicious operation and maintenance behaviors such as misoperation or unauthorized access on the terminal. The design solution does not rely on the network connection between the target Internet of Things terminal and the operation and maintenance platform, solves the operation and maintenance problem under the condition of limited network of the target Internet of Things terminal, reduces the workload of operation and maintenance personnel, and improves the operation and maintenance efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 is a schematic diagram of the architecture of the prior art wireless operation and maintenance mechanism;
[0034] Figure 2 is a schematic diagram of the architecture of the method and system for close-range wireless security operation and maintenance of Internet of Things terminals designed by the present invention;
[0035] Figure 3 is a flowchart of the method for close-range wireless security operation and maintenance of Internet of Things terminals designed by the present invention;
[0036] Figure 4 is a schematic diagram of the operation and maintenance terminal in the method and system for close-range wireless security operation and maintenance of Internet of Things terminals designed by the present invention;
[0037] Figure 5 is a schematic diagram of the target Internet of Things terminal in the method and system for close-range wireless security operation and maintenance of Internet of Things terminals designed by the present invention;
[0038] Figure 6 is a schematic diagram of the application and implementation of the access control module in the method and system for close-range wireless security operation and maintenance of Internet of Things terminals designed by the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0039] The following further details the specific implementation manners of the present invention in conjunction with the accompanying drawings of the specification.
[0040] The present invention designs a method and system for close-range wireless security operation and maintenance of Internet of Things terminals, and the specific design idea is as follows:
[0041] (1) Design an identity authentication and key negotiation mechanism between the operation and maintenance terminal and the target Internet of Things terminal to be operated and maintained during the close-range operation and maintenance process, ensuring that only legitimate operation and maintenance personnel can perform operation and maintenance operations on the target Internet of Things terminal device;
[0042] (2) Design an access control mechanism for close-range operation and maintenance, and control the operations of operation and maintenance personnel during operation and maintenance to ensure that operation and maintenance personnel operate according to the established operation and maintenance process, and ensure the efficient and orderly progress of operation and maintenance work;
[0043] (3) Provide a close-range wireless security operation and maintenance system for target Internet of Things terminals, including target Internet of Things terminals, operation and maintenance platforms, and operation and maintenance terminals; after receiving the operation and maintenance tasks issued by the operation and maintenance platform, the operation and maintenance terminals complete identity authentication with the target Internet of Things terminals based on a close-range communication method, and perform operation and maintenance operations according to the operation and maintenance requirements of the operation and maintenance platform. On the basis of ensuring the security and trustworthiness of the operation and maintenance terminals, fine-grained authorization and access control of operation and maintenance operations are realized.
[0044] According to the above design idea, the present invention designs a method for close-range wireless security operation and maintenance of Internet of Things terminals, as Figure 2 shown. Based on the target Internet of Things terminal communicating with the operation and maintenance platform through the operation and maintenance terminal, and the target Internet of Things terminal not communicating directly with the operation and maintenance platform, in an encrypted communication manner, the operation and maintenance terminal realizes the identity authentication of the target Internet of Things terminal to the operation and maintenance platform, and the operation and maintenance platform obtains the access control rules corresponding to the target Internet of Things terminal. Then, according to the access control rules, in an encrypted communication manner, the operation and maintenance terminal performs operation and maintenance on the target Internet of Things terminal to ensure the identity legality of the terminal and the minimum authorization of operation and maintenance operations.
[0045] In practical applications, as Figure 3 shown, the present invention is specifically implemented as follows in steps A to F. In an encrypted communication manner, the operation and maintenance terminal realizes the identity authentication of the target Internet of Things terminal to the operation and maintenance platform, and the operation and maintenance platform obtains the access control rules corresponding to the target Internet of Things terminal.
[0046] Step A. Based on the operation and maintenance terminal receiving the operation and maintenance tasks for the target Internet of Things terminal issued by the operation and maintenance platform, the operation and maintenance terminal initiates the operation and maintenance tasks to the target Internet of Things terminal and enters step B.
[0047] Step B. The target Internet of Things terminal generates a random number , and uses its preset key to encrypt its device identifier , random number , and the current timestamp according to to obtain an identity authentication ciphertext , and sends it to the operation and maintenance terminal. The operation and maintenance terminal combines its device identifier with the ciphertext and sends it to the operation and maintenance platform, and then enters step C; where Represents the ECB encryption function based on the standard national cryptographic algorithm SM4. Since the timestamp is introduced, it can ensure the freshness and non-repetitiveness of identity authentication.
[0048] Step C. The operation and maintenance platform, based on the received and , invokes the key of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal , and decrypts for to obtain , , , and proceeds to Step D; where represents the device identifier after being transmitted from the target IoT terminal to the operation and maintenance platform, represents the random number after being transmitted from the target IoT terminal to the operation and maintenance platform, represents the timestamp after being transmitted from the target IoT terminal to the operation and maintenance platform, represents the ECB decryption function based on the standard national cryptographic algorithm SM4.
[0049] Step D. The operation and maintenance platform determines whether is consistent with the device identifier of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal , and determines whether the time difference from the current time does not exceed the preset time difference threshold. If both determinations are yes, the operation and maintenance platform uses the key of the target IoT terminal to encrypt the preset access control rule corresponding to the target IoT terminal, and for to obtain the ciphertext , and sends it to the operation and maintenance terminal. The operation and maintenance terminal forwards the ciphertext to the target IoT terminal, and the operation and maintenance terminal creates a session key for , and then proceeds to Step E; represents the hash function based on the standard national cryptographic algorithm SM3; otherwise, the operation and maintenance platform terminates the operation and maintenance task for the target IoT terminal.
[0050] Here, the designed access control rule includes the operation and maintenance target file , the operation and maintenance operation , and the operation and maintenance time domain set by the operation and maintenance platform according to the current time in Step B.
[0051] Step E. The target Internet of Things terminal applies its key , for the received ciphertext , decrypt according to to obtain the corresponding access control rule , and the random number therein , and judge and are consistent. If so, the target Internet of Things terminal stores the access control rule , and the target Internet of Things terminal creates a session key according to , and then enters Step F; otherwise, the target Internet of Things terminal terminates the operation and maintenance task.
[0052] Step F. Based on the encrypted communication method between the operation and maintenance terminal and the target Internet of Things terminal according to the session key , , and the access control rule corresponding to the target Internet of Things terminal , the operation and maintenance terminal performs operation and maintenance on the target Internet of Things terminal.
[0053] In the actual application of the above Step F, as Figure 6 shown, the specific design is executed as follows in Steps F1 to F3.
[0054] Step F1. The operation and maintenance terminal applies the session key , for the target operation and maintenance project , encrypt according to to obtain the ciphertext , and send it to the target Internet of Things terminal, and then enter Step F2.
[0055] Step F2. The target Internet of Things terminal applies the session key , for the received ciphertext , decrypt according to to obtain the target operation and maintenance project , and judge whether the target operation and maintenance project exceeds the operation and maintenance target file, operation and maintenance operation , operation and maintenance time domain in the access control rule . If so, the target Internet of Things terminal prohibits the execution of the target operation and maintenance project ; otherwise, the target Internet of Things terminal allows and completes the execution of the target operation and maintenance project , completes, and enters Step F3.
[0056] Step F3. The target Internet of Things terminal applies the session key for the operation and maintenance result of the target Internet of Things terminal in Step F2 , and Encrypt it to obtain the ciphertext of the operation and maintenance result, and return it to the operation and maintenance terminal. The operation and maintenance terminal applies the session key and to decrypt the received ciphertext of the operation and maintenance result to obtain the operation and maintenance result.
[0057] Apply the method for short-range wireless secure operation and maintenance of the Internet of Things terminal designed in the present invention to practice. For example Figure 2 as shown, short-range wireless communication protocols such as Bluetooth, Wi-Fi, and XingShan are used for communication between the target Internet of Things terminal and the operation and maintenance terminal, and long-range wireless communication protocols such as 4G and 5G are used for communication between the operation and maintenance terminal and the operation and maintenance platform. And specifically design the corresponding application system. For example Figure 4 as shown, the designed operation and maintenance terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; as Figure 5 shown, the target Internet of Things terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module.
[0058] Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target Internet of Things terminal, a short-range communication connection between the operation and maintenance terminal and the target Internet of Things terminal is realized. Based on the communication between the wireless remote communication module in the operation and maintenance terminal and the operation and maintenance platform, a remote communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized.
[0059] Such as Figure 4 and Figure 5 shown, the identity authentication module in the operation and maintenance terminal is respectively connected to the short-range communication module, the data encryption and decryption module, and the wireless remote communication module. The identity authentication module is used to forward the communication data between the target Internet of Things terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key and store it in the data encryption and decryption module; the data encryption and decryption module is respectively connected to the operation and maintenance module and the short-range communication module. The operation and maintenance module is used to receive the target operation and maintenance project and encrypt it through the data encryption and decryption module using the session key and send it to the target Internet of Things terminal through the short-range communication module. And the data encryption and decryption module applies the session key to decrypt the ciphertext of the operation and maintenance result received from the target Internet of Things terminal through the short-range communication module, and obtain the operation and maintenance result and feedback it to the operation and maintenance module.
[0060] The identity authentication module in the target Internet of Things terminal is respectively connected to the short-range communication module, the data encryption and decryption module, and the access control module. The identity authentication module constructs identity authentication data and encrypts it using the data encryption and decryption module to obtain the identity authentication ciphertext , and then transmit it to the operation and maintenance terminal through the short-range communication module; the identity authentication module receives the ciphertext from the operation and maintenance platform through the short-range communication module , and calls the data encryption and decryption module for decryption. The identity authentication module completes the identity authentication according to the decryption result, and sends the access control rules in the decryption result to the access control module for storage; at the same time, the data encryption and decryption module is respectively connected to the short-range communication module and the access control module, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module decrypts the ciphertext received from the operation and maintenance terminal through the short-range communication module to obtain the target operation and maintenance project and send it to the access control module. The access control module performs permission control on the target operation and maintenance project according to the access control rules , and the operation and maintenance module realizes the execution of the target operation and maintenance project according to the permission control of the access control module .
[0061] In a further practical application, the access control module in the designed target Internet of Things terminal includes a permission control module and an access control rule library that are connected to each other. Among them, the access control rule library is connected to the identity authentication module in the target Internet of Things terminal. The identity authentication module sends the access control rules in the decryption result to the access control rule library in the access control module for storage. The permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target Internet of Things terminal. The permission control module receives the target operation and maintenance project obtained by decrypting the by the data encryption and decryption module . The permission control module performs permission control on the target operation and maintenance project according to the access control rules in the access control rule library , and the operation and maintenance module realizes the execution of the target operation and maintenance project according to the permission control of the access control rules .
[0062] The above-described Internet of Things terminal short-range wireless security operation and maintenance method and system use the operation and maintenance terminal as a relay between the target Internet of Things terminal and the operation and maintenance platform, apply an encrypted communication method to achieve identity authentication and operation and maintenance between the target Internet of Things terminal and the operation and maintenance platform. By establishing a strict security authentication mechanism, it effectively prevents network attacks and data leakage, improves the security of the target Internet of Things terminal device, and enhances the identity authentication ability of the target Internet of Things terminal for the operation and maintenance terminal. In addition, a fine-grained access control mechanism is designed. By comparing access control factors such as operation and maintenance time, operation and maintenance object, and operation and maintenance operation during the operation and maintenance process and the identity authentication process, the security protection ability during the operation and maintenance stage of the target Internet of Things terminal is enhanced, and the impact of malicious operation and maintenance behaviors such as misoperation or unauthorized access on the terminal is avoided. The design solution does not rely on the network connection between the target Internet of Things terminal and the operation and maintenance platform, solves the operation and maintenance problem under the condition of network limitation of the target Internet of Things terminal, reduces the workload of operation and maintenance personnel, and improves the operation and maintenance efficiency.
[0063] The embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those of ordinary skill in the art, various changes can be made without departing from the gist of the present invention.
Claims
1. A method for short-range wireless secure operation and maintenance of an Internet of Things terminal, characterized in that: Based on the fact that the target Internet of Things (IoT) terminal communicates with the operation and maintenance platform via the operation and maintenance terminal, and the target IoT terminal does not communicate directly with the operation and maintenance platform, the following steps A to F are executed. In an encrypted communication mode, the operation and maintenance terminal is used to implement the identity authentication of the target IoT terminal to the operation and maintenance platform, and the operation and maintenance platform obtains the access control rules corresponding to the target IoT terminal. Then, based on the access control rules, in an encrypted communication mode, the operation and maintenance terminal is used to perform operation and maintenance on the target IoT terminal; Step A. Based on the operation and maintenance terminal receiving the operation and maintenance task for the target IoT terminal issued by the operation and maintenance platform, the operation and maintenance terminal initiates the operation and maintenance task to the target IoT terminal and enters Step B; Step B. The target Internet of Things terminal generates a random number R1 according to the operation and maintenance task, and uses its preset key K B for its device identifier ID B , the random number R1, and the current timestamp T B , and performs encryption according to ENC B =SM4_ECB_enc(K B , ID B ||R1||T B ) to obtain the identity authentication ciphertext ENC B , and sends it to the operation and maintenance terminal. The operation and maintenance terminal combines its device identifier ID A with the ciphertext ENC B , sends it to the operation and maintenance platform, and then enters Step C; where SM4_ECB_enc() represents the ECB encryption function based on the standard national cryptography SM4; Step C. The operation and maintenance platform receives the ID A With ENC B , call ID A The key K of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal B , press SM4_ECB_dec(K B , ENC B ) for ENC B Decrypt and obtain the ID' B , R'1, T' B , and proceed to step D; wherein, ID' B represents the device identifier after being transmitted to the operation and maintenance platform via the target IoT terminal, R'1 represents the random number after being transmitted to the operation and maintenance platform via the target IoT terminal, T' B It indicates the timestamp after being transmitted from the target IoT terminal to the operation and maintenance platform. SM4_ECB_dec() indicates the ECB decryption function based on the standard national encryption SM4. Step D. The operation and maintenance platform determines the ID' B With ID A The device ID of the target IoT terminal in the operation and maintenance task corresponding to the operation and maintenance terminal B Is it consistent, and judge T' B Whether the time difference with the current time does not exceed the preset time difference threshold. If both judgments are yes, the operation and maintenance platform uses the key K of the target IoT terminal to B , for the preset access control rule P corresponding to the target IoT terminal B , and ID A With R'1, press ENC C =SM4_ECB_enc(K B ,ID A ||R'1||P B ) to encrypt and obtain the ciphertext ENC C , and sent to the operation and maintenance terminal, which converts the ciphertext ENC C Forward it to the target IoT terminal, and the operation and maintenance terminal presses K AB =SM3(ID A ||ENC B ), create a session key K AB , and then proceed to step E; SM3() represents a hash function based on the standard national encryption SM3; Otherwise, the operation and maintenance platform terminates the operation and maintenance task for the target IoT terminal; Step E. The target IoT terminal applies its key K B , for the received ciphertext ENC C , press SM4_ECB_dec(K B ,ENC C ) to decrypt and obtain the corresponding access control rule P B , and the random number R″1 therein, and judge whether R″1 is consistent with R1. If so, the target IoT terminal stores access control rule P B , and the target IoT terminal presses K BA =SM3(ID A ||ENC B ), create a session key K BA , and then proceed to step F; otherwise, the target IoT terminal terminates the operation and maintenance task; Step F. Based on the encrypted communication method between the operation and maintenance terminal and the target Internet of Things terminal according to the session keys K AB 、K BA and the access control rule P corresponding to the target Internet of Things terminal B , the operation and maintenance terminal performs operation and maintenance on the target Internet of Things terminal.
2. The method for short-range wireless secure operation and maintenance of an Internet of Things terminal according to claim 1, wherein: The access control rules include an operation and maintenance target file OBJ, an operation and maintenance operation ACT, and an operation and maintenance time domain [TIME set by the operation and maintenance platform according to the current time in step B start , TIME end .
3. The method for short-range wireless security operation and maintenance of an Internet of Things terminal according to claim 2, characterized in that: Step F includes the following steps F1 to F3; Step F1. The operation and maintenance terminal applies the session key K AB , for the target operation and maintenance project M, according to ENC D =SM4_ECB_enc(K AB , M) for encryption to obtain the ciphertext ENC D , and send it to the target Internet of Things terminal, and then enter Step F2; Step F2. The target Internet of Things terminal applies the session key K BA , for the received ciphertext ENC D , decrypt it according to SM4_ECB_dec(K BA , ENC D ) to obtain the target operation and maintenance project M, and determine whether the target operation and maintenance project M exceeds the operation and maintenance target file OBJ, operation and maintenance operation ACT, and operation and maintenance time domain [TIME start , TIME end in the access control rule. If so, the target Internet of Things terminal prohibits the execution of the target operation and maintenance project M; otherwise, the target Internet of Things terminal allows and completes the execution of the target operation and maintenance project M, completes, and enters step F3; Step F3. The target IoT terminal applies the session key K to the operation and maintenance result of the target IoT terminal in step F2 BA , and uses SM4_ECB_enc() to encrypt it to obtain the ciphertext of the operation and maintenance result, and returns it to the operation and maintenance terminal. The operation and maintenance terminal applies the session key K AB , and uses SM4_ECB_dec() to decrypt the received ciphertext of the operation and maintenance result to obtain the operation and maintenance result.
4. The method for close-range wireless secure operation and maintenance of an Internet of Things terminal according to any one of claims 1 to 3, characterized in that: The target IoT terminal and the operation and maintenance terminal communicate with each other using a short-range wireless communication protocol, and the operation and maintenance terminal and the operation and maintenance platform communicate with each other using a long-range wireless communication protocol.
5. A system for implementing the method for short - range wireless secure operation and maintenance of an Internet of Things terminal described in any one of claims 1 to 4, characterized in that: The operation and maintenance terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an operation and maintenance module, and a wireless remote communication module; the target IoT terminal includes a short-range communication module, an identity authentication module, a data encryption and decryption module, an access control module, and an operation and maintenance module; Among them, based on the communication between the short-range communication module in the operation and maintenance terminal and the short-range communication module in the target IoT terminal, the short-range communication connection between the operation and maintenance terminal and the target IoT terminal is realized. Based on the communication between the wireless remote communication module in the operation and maintenance terminal and the operation and maintenance platform, the remote communication connection between the operation and maintenance terminal and the operation and maintenance platform is realized; The identity authentication module in the operation and maintenance terminal is respectively connected to the short-range communication module, the data encryption and decryption module, and the wireless remote communication module. The identity authentication module is used to forward the communication data between the target Internet of Things terminal and the operation and maintenance platform, and the identity authentication module is used to create a session key K AB and store it in the data encryption and decryption module; the data encryption and decryption module is respectively connected to the operation and maintenance module and the short-range communication module. The operation and maintenance module is used to receive the target operation and maintenance project M and apply the session key K through the data encryption and decryption module AB After encryption, it is sent to the target Internet of Things terminal through the short-range communication module, and the data encryption and decryption module applies the session key K to the operation and maintenance result ciphertext received from the target Internet of Things terminal through the short-range communication module AB to decrypt and obtain the operation and maintenance result and feedback it to the operation and maintenance module; In the target Internet of Things terminal, the identity authentication module is respectively connected to the short-range communication module, the data encryption and decryption module, and the access control module. The identity authentication module constructs identity authentication data and encrypts it using the data encryption and decryption module to obtain the identity authentication ciphertext ENC. B Then, it transmits the ciphertext ENC to the operation and maintenance terminal through the short-range communication module. The identity authentication module receives the ciphertext ENC from the operation and maintenance platform through the short-range communication module. C It calls the data encryption and decryption module to decrypt the ciphertext ENC, and the identity authentication module completes the identity authentication based on the decryption result. It also sends the access control rules in the decryption result to the access control module for storage. At the same time, the data encryption and decryption module is respectively connected to the short-range communication module and the access control module, and the access control module is connected to the operation and maintenance module. The data encryption and decryption module decrypts the ciphertext ENC received from the operation and maintenance terminal through the short-range communication module. D to obtain the target operation and maintenance project M and send it to the access control module. The access control module performs permission control on the target operation and maintenance project M according to the access control rules, and the operation and maintenance module executes the target operation and maintenance project M according to the permission control of the access control module.
6. The system according to claim 5, wherein: The access control module in the target Internet of Things terminal includes a permission control module and an access control rule library that are connected to each other. Among them, the access control rule library is connected to the identity authentication module in the target Internet of Things terminal. The identity authentication module sends the access control rules in the decryption result to the access control rule library in the access control module for storage. The permission control module is respectively connected to the data encryption and decryption module and the operation and maintenance module in the target Internet of Things terminal. The permission control module receives the target operation and maintenance item M obtained by decrypting ENC by the data encryption and decryption module. D The permission control module performs permission control on the target operation and maintenance item M according to the access control rules in the access control rule library, and the operation and maintenance module realizes the execution of the target operation and maintenance item M according to the permission control of the access control rules.
Citation Information
Patent Citations
Method for user administration of a field device
CN110120866A