Data acquisition method and related communication method

By using encryption authentication chips and dynamic encryption methods in the device, the security problems of communication keys in transmission and storage are solved, and high-security data transmission and storage are achieved.

CN120050026APending Publication Date: 2025-05-27HONEYWELL ENVIRONMENTAL & COMBUSTION CONTROLS (TIANJIN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311594994.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-27
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The prior art is difficult to effectively ensure the security of communication keys in transmission and storage, resulting in the real-time and effectiveness of data being threatened.

Method used

By introducing an encryption authentication chip into the device, the communication key is stored for a long time, and using dynamic encryption when retrieving data, the encryption and decryption is ensured by using feature codes and timestamps for encryption and decryption.

Benefits of technology

It realizes high security during the storage and transmission of communication keys, ensures real-time and validity of data, and reduces the risk of key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050026A_ABST
    Figure CN120050026A_ABST
Patent Text Reader

Abstract

The data acquisition method comprises the following steps: a) a first device sends a request for first data to an encryption authentication unit, wherein the request comprises a feature code and a timestamp; b) the encryption authentication unit receives the request, encrypts the first data to obtain first encrypted data, and returns the first encrypted data to the first device; c) the first device performs integrity verification on the received first encrypted data; d) in response to verification success, repeating the steps a to c, so that the first device receives second first encrypted data; e) the first device compares the received two pieces of first encrypted data to determine whether the two pieces of first encrypted data are the same, and decrypts the first encrypted data to obtain first data in response to the determination that the two pieces of first encrypted data are the same; wherein the step of encrypting the first data by using the timestamp comprises the step of encrypting by using a specific data segment of the timestamp as an encryption parameter, so that the two pieces of first encrypted data are the same, and the availability of the first data can be verified. The disclosure also relates to a related communication method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communications, and more particularly to a data acquisition method and related communication methods, communication systems, and machine-readable storage media. Background Art

[0002] In the field of communications, in order to ensure the security of the communication process and data, communication keys are usually used to safeguard the communication between devices and the cloud. Therefore, once the communication key is leaked, the timeliness and validity of the transmitted data cannot be guaranteed. The transmitted data is, for example, cloud data. When the cloud data is maliciously tampered with, incorrect statistics and control will occur.

[0003] Therefore, it is necessary to ensure the security of the communication key, which includes not only the transmission security during transmission between devices in the network but also the storage security when it is stored in the device. Summary of the Invention

[0004] To this end, the present disclosure proposes a data acquisition method for improving the storage security of data when stored in a device, particularly the communication key. In addition, the present disclosure also proposes an associated communication method for improving communication security.

[0005] According to one aspect of the present disclosure, there is provided a data acquisition method, comprising the following steps: a) a first device sends a request for first data to an encryption authentication unit, the request including a feature code that can uniquely identify the first device and a timestamp indicating the local time of the first device; b) the encryption authentication unit receives the request, encrypts the first data using the included feature code and timestamp to obtain first encrypted data, and returns the first encrypted data to the first device; c) the first device receives the first encrypted data and performs an integrity check on the first encrypted data; d) in response to a successful check, repeat steps a) to c) such that the first device receives a second first encrypted data; and e) the first device compares the two received first encrypted data to determine whether they are the same, and in response to determining that the two received first encrypted data are the same, decrypts the first encrypted data to obtain the first data; wherein encrypting the first data using the timestamp includes encrypting using a specific data segment of the timestamp as an encryption parameter, such that the same two first encrypted data can verify the availability of the first data.

[0006] According to the data acquisition method of the present disclosure, first, the data is stored in the encrypted authentication chip in the long term rather than in the first device, ensuring the storage security of the data. Second, the first device dynamically retrieves the data from the encrypted authentication chip using the feature code that can uniquely identify the first device and the time stamp indicating the local time of the first device as parameters. Therefore, by means of the dynamic encryption method, the transmission security of the data between the first device and the encrypted authentication chip is guaranteed. Third, by selecting a specific data segment of the time stamp as the encryption parameter for encryption, the same encrypted data for two times can verify the availability of the data, such as authenticity, validity, etc. The first device decrypts the data retrieved from the encrypted authentication chip only when the received data is the same (in other words, when the availability of the data can be guaranteed). If they are different, it will not decrypt, further reducing the risk of data leakage in the first device.

[0007] In some embodiments, the method according to the present disclosure further includes the following steps: f) In response to the first device determining that the two first encrypted data received in step e) are different, steps a) to c) are repeated again so that the first device receives the third first encrypted data; g) The first device compares the last two first encrypted data received to determine whether they are the same. In response to determining that the last two first encrypted data received are the same, the first encrypted data is decrypted to obtain the first data.

[0008] In some embodiments, the method according to the present disclosure further includes an authentication method between the first device and the encrypted authentication unit before executing the data acquisition method, including: h) The first device obtains the public key of the encrypted authentication unit, encrypts the second data with the public key to obtain the second encrypted data, and sends the second encrypted data to the encrypted authentication unit; i) The encrypted authentication unit receives the second encrypted data, decrypts the second encrypted data with the private key of the encrypted authentication unit that matches the public key, and compares the decrypted data with the data pre-stored in the encrypted authentication unit to determine whether they are the same; j) In response to the encrypted authentication unit determining that they are the same, the encrypted authentication unit confirms that the first device is a trusted device and allows the execution of the data acquisition method; and k) In response to the encrypted authentication unit determining that they are different, the encrypted authentication unit confirms that the first device is not a trusted device and blocks the execution of the data acquisition method.

[0009] In some embodiments, the method according to the present disclosure further includes: l) The first device encrypts the third data with the first encryption algorithm to obtain the second data; wherein, the third data is the data pre-agreed and stored by the first device and the encrypted authentication unit respectively, and wherein, the data pre-stored in the encrypted authentication unit is in a non-plaintext form obtained by encrypting the third data with the first encryption algorithm.

[0010] In some embodiments, the third data is an authentication string, and the first encryption algorithm is a hashing operation.

[0011] According to another aspect of the present disclosure, there is provided a communication method, including the following steps: a first device obtains first data and stores the first data in an encryption authentication unit, where the first data is a communication key, the first device is a gateway device, and the gateway device includes a microcontroller and the encryption authentication unit; when the communication key is to be used, the data acquisition method as described above is executed, so that the gateway device retrieves the communication key from the encryption authentication unit, where the feature code is the unique identification serial number of the microcontroller; and the gateway device uses the communication key for communication.

[0012] According to this communication method of the present disclosure, first, the method has the advantages of the data acquisition method and its various preferred embodiments as described above, improving the storage security of the communication key in the gateway device. Second, the microcontroller and the encryption authentication unit are physically located in the same gateway device. That is to say, even the communication between two units on the same circuit board still uses dynamic encryption for data transmission, ensuring the security of the communication key. Third, this communication method can quickly determine whether the communication key is correct by means of this data acquisition method when the microcontroller retrieves the communication key from the encryption authentication unit, that is, judge the usability of the communication key, instead of waiting until the communication attempt or decryption attempt using the communication key fails later to find out whether the communication key is correct, thus saving time. Finally, this method ensures that the communication key is only stored on the encryption authentication unit in the gateway device for a long time. Specifically, when the gateway device first obtains the communication key, the communication key is directly stored in the encryption authentication unit by means of, for example, transparent transmission, without retaining any original or copy of the communication key in the non-encrypted part of the gateway device. In addition, each time the communication key needs to be used subsequently, the gateway device dynamically obtains and uses the communication key as a parameter from the encryption authentication unit, and immediately releases the memory after use (in other words, does not retain any original or copy of the communication key in the non-encrypted part of the gateway device), thereby further ensuring the security of the key during storage and communication.

[0013] In some embodiments, the first device obtains first data, i.e., the gateway device obtains the communication key, which includes: the program download device generates a first key pair and sends a program download signal to the gateway device, where the program download signal includes a request for the unique identification serial number of the microcontroller and a timestamp indicating the local time of the gateway device; the gateway device receives the program download signal, returns the requested unique identification serial number and timestamp to the program download device, and generates a second key pair; the program download device and the gateway device exchange the public keys in the key pairs they generate respectively, and each uses the unique identification serial number and the timestamp as parameters to generate their respective shared keys using the ECDH algorithm; the program download device encrypts the communication key using the shared key it generates and sends the encrypted communication key to the gateway device; and the gateway device receives the encrypted communication key and decrypts it using the shared key it generates to obtain the communication key.

[0014] According to one aspect of the present disclosure, there is provided a communication system, including: a gateway device, which includes a microcontroller and an encryption and authentication unit; and a server that can communicate with the gateway device using the communication key; wherein, the gateway device and the encryption and authentication unit are configured to execute the data acquisition method as described above, so that the gateway device retrieves the communication key from the encryption and authentication unit; and / or wherein, the gateway device and the server are configured to execute the communication method as described above, so as to communicate using the communication key.

[0015] According to one aspect of the present disclosure, there is provided a machine-readable storage medium, on which code instructions are stored, and when the code instructions are executed by one or more machines, the one or more machines are caused to implement the method as described above.

[0016] Therefore, it can be seen that the solution proposed by the present disclosure further ensures the security of important data such as communication keys, including not only the transmission security during the transmission of the data among devices in the network, but also the storage security when the data is stored in the devices.

[0017] It should be noted that the aspects of the present disclosure related to the communication system or the machine-readable storage medium may have the advantages corresponding to those described above regarding the method aspects and the preferred embodiments, and the preferred embodiments. Unless otherwise stated or clearly mutually exclusive, the above embodiments can be combined arbitrarily within the same aspect and / or between aspects.

[0018] According to the embodiments described below, these and other aspects of the present disclosure will be clear and will be elucidated with reference to the embodiments described below. Description of the Drawings

[0019] In the following description of exemplary embodiments in conjunction with the accompanying drawings, more details, features, and advantages of the technical solutions of the present application are disclosed. In the drawings: Figure 1 Schematically shows an overall communication process according to the present disclosure; Figure 2 Schematically shows a communication key retrieval process according to the present disclosure; Figure 3 Schematically shows a flowchart of a data acquisition method according to the present disclosure; and Figure 4 Schematically shows a flowchart of a communication method according to the present disclosure. Detailed implementation manners

[0020] Example embodiments will now be described more fully with reference to the accompanying drawings.

[0021] Figure 1 Schematically shows an overall communication process according to the present disclosure.

[0022] As described above, in the field of communications, in order to ensure the security of the communication process and data, communication keys are usually used to safeguard the communication between devices and the cloud. The device may refer to a lower-level machine such as a gateway device, and the cloud may refer to a remote computing device such as a server. The communication key may be provided to the gateway device by the program when an application program or firmware update is installed on the device for the gateway device to communicate with the cloud subsequently.

[0023] Regarding this communication key provision process, more specifically, and referring to Figure 1 , a program download device (for example, the upper computer APP in the figure) may generate a first key pair and send a program download signal to the gateway. The program download signal includes a request for a feature code that can uniquely identify the gateway device (for example, the MCU ID of the microcontroller of the gateway device) and its local time (for example, a timestamp indicating its local time). Thereafter, the gateway device that receives the signal may return the requested MCU ID and timestamp to the upper computer APP and generate a second key pair. Thereafter, the upper computer APP may exchange the public keys in the key pairs generated by each party with the gateway, and each use the MCU ID and timestamp known to both as dynamic parameters to generate their respective shared keys using the ECDH (Elliptic Curve Diffie-Hellman) algorithm. Then, the upper computer APP may encrypt the communication key using the shared key it generated and send the encrypted communication key to the gateway device. Finally, the gateway device may receive the encrypted communication key and decrypt it using the shared key it generated to finally obtain the communication key.

[0024] As can be seen, according to the present disclosure, in such a key provision process, on the one hand, the ECDH algorithm can be used to increase the data security of the key. In this way, even if the communication key is intercepted, it is very difficult to be deciphered. On the other hand, the MCU ID and local time that can uniquely identify the gateway device can be used as dynamic parameters to further ensure that the key is dynamically encrypted each time it is transmitted.

[0025] Preferably, according to the present disclosure, after the gateway device, especially the microcontroller of the gateway device, obtains the communication key, the communication key is immediately stored in the encryption authentication chip of the gateway device, and no original or copy of the communication key is retained in a non-confidential part such as the microcontroller, ensuring the absolute security of the key storage area. The encryption authentication chip can be, for example, an ECC508 encryption chip. In one embodiment, this can be achieved by the pipe-through transmission technology to directly store the obtained communication key in the encryption authentication chip.

[0026] After obtaining the communication key, each time the communication key is needed to communicate with the cloud (for example, when establishing a connection with the cloud or transmitting specific data), the gateway device retrieves the communication key from the encryption authentication chip according to a specific process of the present disclosure.

[0027] For example, continuing to refer to Figure 1 , in some embodiments, when the communication key needs to be retrieved, the microcontroller of the gateway device can optionally first authenticate with the encryption authentication chip to ensure that the device retrieving the communication key from the encryption authentication chip is a trusted device. Only when the verification is successful is it allowed to retrieve the communication key from the encryption authentication chip, otherwise retrieving the communication key will be prohibited.

[0028] According to the present disclosure, when retrieving the communication key, the microcontroller needs to provide its MCU ID and local time to the encryption authentication chip. The encryption authentication chip uses the MCU ID and timestamp provided by the microcontroller to dynamically encrypt the communication key and transmits the encrypted communication key to the microcontroller. The microcontroller uses the decrypted communication key to communicate with the cloud. In this way, even the communication between two chips on the same circuit board in the same device still uses dynamic encryption for data transmission, further ensuring the data security of the communication key.

[0029] Next, refer to Figure 2 to describe in more detail how the gateway device, more specifically the non-encrypted part of the gateway device (such as its microcontroller), retrieves the communication key from the encryption authentication chip. Figure 2 Schematically shows the communication key retrieval process 200 according to the present disclosure, which starts from block 201.

[0030] As Figure 2As shown, first, authentication can be optionally performed between the microcontroller and the encryption authentication chip, as shown in Figure 2 from 202 to 208. Specifically, the microcontroller obtains (e.g., reads) the public key of the encryption authentication chip at 202, encrypts the data to be transmitted with the public key at 203, and sends the encrypted data to the encryption authentication chip at 204. In one embodiment, the data to be transmitted can be a verification string pre-agreed between the microcontroller and the encryption authentication chip. However, in a preferred embodiment, the data to be transmitted can be the ciphertext form of the verification string. For example, a hash value obtained by performing a hash operation on it, and then transmits the hash value to the encryption authentication chip, as shown in 203. Then, at 205, the encryption authentication chip receives the encrypted data transmitted from the microcontroller, decrypts the received encrypted data with its private key, and compares the decrypted data with the data pre-stored in the encryption authentication chip at 206 to determine whether they are the same. Here, if the data to be transmitted is the ciphertext form of the verification string, the hash value of the string can also be stored in the encryption authentication chip, thereby improving security. Next, if the encryption authentication chip determines that they are the same, the encryption authentication chip confirms that the microcontroller is a trusted device and allows the key reading process to continue, as shown in 207. Conversely, if the encryption authentication chip determines that they are different, the encryption authentication chip considers that the microcontroller is not a trusted device (208), and blocks the microcontroller from reading the communication key from the encryption authentication chip, and this process ends at 222.

[0031] After the optional authentication process, that is, after Figure 2 the box 207, the microcontroller reads the communication key from the encryption authentication chip according to a predetermined process. First, the microcontroller sends a request for the communication key to the encryption authentication chip, and the request includes a feature code that can uniquely identify the microcontroller and a timestamp indicating the local time of the microcontroller, such as the MCU ID and the local time, as shown in 209. At 210, the encryption authentication chip uses the MCU ID and the local time to encrypt the communication key, and returns the encrypted data to the microcontroller at 211. The microcontroller receives the encrypted data and performs an integrity check on the encrypted data at 212, such as a CRC check. In response to a check failure, the microcontroller re-sends the MCU ID and the local time to the encryption authentication chip to re-request the communication key, as shown in Figure 2As shown in branch 214. In one embodiment, the number of attempts for re-request can be set to 3 times. If the number of attempts exceeds this limit, it jumps to the end, and an alarm can also be generated to notify the error. In response to successful verification, the microcontroller increments the counter associated with the communication key (as shown in 213, reading the key record and adding 1), and then the microcontroller determines whether it has been read twice, that is, determines whether the record is less than 2, as shown in 215. If it has not been requested twice, that is, the data record in the counter is less than 2, it returns to step 209 and re-executes boxes 209 to 213. Otherwise, if it has been requested twice, the microcontroller compares the two received encrypted data at 216 to determine whether they are the same. If they are the same, proving that the obtained data is trustworthy, then at 218, the encrypted data is decrypted using the above MCU ID and local time to obtain the communication key, and the counter is reset (for example, reading the key storage and clearing it). According to the present disclosure, using a timestamp to encrypt the communication key includes encrypting using a specific data segment of the timestamp as an encryption parameter, so that the same two first encrypted data can verify the availability of the first data.

[0032] Therefore, by means of the above process, first, the communication key is stored in the encryption authentication chip for a long time instead of in the microcontroller, ensuring the storage security of the communication key. Second, the microcontroller dynamically retrieves the communication key from the encryption authentication chip according to the process proposed in the present disclosure using the feature code that can uniquely identify the first device (for example, its MCU ID) and the timestamp indicating the local time of the first device as parameters. Therefore, by means of dynamic encryption, the transmission security of data between the microcontroller and the encryption authentication chip is guaranteed. Third, by selecting a specific data segment of the timestamp as an encryption parameter to encrypt the communication key, the same encrypted data twice can verify the availability of the communication key, such as authenticity, validity, etc. The gateway device (or its microcontroller) decrypts the data retrieved from the encryption authentication chip to obtain the plaintext communication key only when the received encrypted data is the same (in other words, when the availability of the data is guaranteed), and does not decrypt if they are not the same, which further reduces the risk of data leakage in the first device. Finally, during the process of retrieving the communication key, it is verified whether the communication key is trustworthy, without waiting until subsequent communication attempts or decryption attempts using the communication key fail to find out whether the communication key is correct, thus saving time.

[0033] It should be noted that regarding the specific data segment of the timestamp, as a specific example, in Figure 2If the execution time of this process is on the order of seconds, microseconds, milliseconds, etc. (for example, about 2 seconds), then the data segment of the timestamp up to the minute can be intercepted for encryption. In this way, as long as the timestamps are sent to the encryption authentication chip twice within the same minute, the availability of the communication key can be verified by comparing the data encrypted with this data segment twice. However, there are cases where the data received twice is accidentally different. For example, these two requests happen to span minutes, hours, or even days. Therefore, in this case, a request can be made from the encryption authentication chip again. As Figure 2 shown, if the comparison result at 216 is different, then at 217, the read record in the counter is decremented by 1, and boxes 209 to 215 are repeated again so that the microcontroller receives the third encrypted data. Then at 216, the microcontroller compares the last two encrypted data received to determine whether they are the same. If they are the same, it proves that the obtained data is trustworthy, and the microcontroller decrypts the encrypted data to obtain the communication key. In other embodiments, other data segments of the timestamp can be selected as the encryption parameter as long as the comparison of the data after two encryptions can help verify the effectiveness of the communication key.

[0034] In addition, it should be noted that the descriptions of the counter, storing data records, etc. in Figure 2 are only exemplary. As is known to those skilled in the art, the role of the counter is to enable the machine to understand the loop execution, iterative execution, etc. of the method, process, and / or steps. The same is true in this technical solution. In the key retrieval process 200 described above in combination with Figure 2 the counter, storing data records, etc. are only used for the machine to repeat steps such as sending and receiving at the appropriate time. Therefore, any other similar method can be adopted, not limited to using a counter. Similarly, the descriptions such as "increment the record by 1", "decrement the record by 1", "reset the counter", "clear the record", etc. are also the same, and any other method can be adopted, not limited to these specific descriptions.

[0035] Finally, the gateway device communicates with the cloud using the decrypted communication key, as shown in 219. Optionally, the gateway device can determine whether the communication status is normal at 220. If it is not normal, it prompts a communication key error at 221 and contacts the upper computer APP to obtain the communication key again.

[0036] Figure 3A flowchart of a data acquisition method 300 according to the present disclosure is schematically shown. The data acquisition method 300 generally corresponds to steps 209 to 218 of the communication key retrieval process 200, and thus can be executed by the gateway device and the encryption authentication chip described above. However, the present disclosure is not limited thereto. For example, the device for obtaining data from the encryption authentication chip is not necessarily the gateway device or the microcontroller of the gateway device, and the data to be obtained is not necessarily the communication key.

[0037] The method 300 may include, at 302, a first device sending a request for first data to an encryption authentication unit (e.g., a chip), the request including a feature code that can uniquely identify the first device and a timestamp indicating the local time of the first device. Thus, if the method 300 is used for the process of the gateway device retrieving the communication key from the encryption authentication chip, the first device may be the gateway device, or more specifically, the microcontroller of the gateway device, and the first data may be the communication key, as described above in connection with Figure 1 and Figure 2 described. In one embodiment, the feature code that can uniquely identify the first device may be the serial number of the microcontroller included in the gateway device, such as the MCU ID. However, the feature code that can uniquely identify the first device may also be other parameters, as long as it can facilitate dynamic encryption and authentication between the first device and the encryption authentication chip.

[0038] The method 300 may further include, at 304, the encryption authentication unit receiving the request, using the included feature code and timestamp to encrypt the first data to obtain first encrypted data, and returning the first encrypted data to the first device. It can be understood that any currently known or future available relevant encryption algorithm may be used for the encryption.

[0039] The method 300 may further include, at 306, the first device receiving the first encrypted data and performing an integrity check on the first encrypted data, such as a CRC check. At 308, in response to a successful check, steps 302 to 306 are repeated so that the first device receives a second first encrypted data. In one embodiment, the devices performing the method may implement the step repetition by means of a counter, as described above.

[0040] Method 300 may further include, at 310, the first device comparing two received first encrypted data to determine whether they are the same, and in response to determining that the two received first encrypted data are the same, decrypting the first encrypted data to obtain the first data. According to the present disclosure, encrypting the first data using a timestamp includes encrypting using a specific data segment of the timestamp as an encryption parameter, such that the same two first encrypted data can verify the availability of the first data. In one embodiment, using the specific data segment of the timestamp may include using the data segment of the timestamp up to the minute.

[0041] In addition, optionally, an authentication process may be performed between the first device and the encryption authentication chip before executing the data acquisition method 300, as Figure 2 shown in steps 202 to 208 of process 200 of. Only when the encryption authentication chip verifies the identity of the first device is the execution of the data acquisition method 300 allowed.

[0042] Figure 4 A flowchart of a communication method 400 according to the present disclosure is schematically shown.

[0043] Method 400 may include, at 402, the first device acquiring first data and storing the first data in an encryption authentication unit. In one embodiment, the first data may be a communication key, the first device may be a gateway device, and the gateway device may include a microcontroller and an encryption authentication unit. In another embodiment, the first device may be other devices or equipment that want to store specific data in the encryption authentication unit, and the specific data to be stored may be other data that needs to be securely stored.

[0044] Method 400 may further include, at 404, when the communication key is to be used, executing the data acquisition method 300 as described above, such that the gateway device retrieves the communication key from the encryption authentication unit. In one embodiment, the feature code involved in method 300 may be the unique identification serial number of the microcontroller included in the gateway device, for example, MCU ID.

[0045] Method 400 may further include, at 406, the gateway device communicating using the communication key.

[0046] Therefore, it can be seen that the present disclosure proposes to ensure the security of data such as communication keys at least from the following aspects: 1) The storage area is absolutely secure and is only in the encryption authentication chip. In the non-encryption device, it will be deleted immediately after use; 2) Limit the access authority. By authenticating with the encryption authentication chip, only the authorized devices that pass the authentication can retrieve data from the encryption authentication chip; 3) Introduce dynamic parameters so that even between the microcontroller and the encryption authentication chip in the same gateway device, data is transmitted in a dynamically encrypted manner; 4) Limit the access method. Only by executing a specific process can specific data be retrieved from the encryption authentication chip, and the specific constraints of the specific process (for example, a specific data segment of the timestamp) are used to verify the data validity; and 5) Limit the data decryption timing. Only when the data validity is verified according to the specific process, the data is decoded into plaintext, otherwise it is not decoded.

[0047] Identical reference numerals in the figures denote identical or similar elements and thus their repeated description may be omitted for brevity.

[0048] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present application. Therefore, they cannot be used to limit the protection scope of the present application. In addition, the block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices. Additionally, the flowcharts shown in the drawings are only illustrative and do not necessarily include all operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined. Therefore, the actual execution order may change according to the actual situation.

[0049] Those skilled in the art can also understand that the technical solutions of the present application can be embodied in many different forms and purposes and should not be limited to the specific embodiments described herein and illustrated in the drawings. These embodiments are provided to make the technical solutions of the present application clear and complete, but the described embodiments do not limit the protection scope of the present application.

[0050] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application may be practiced without one or more of the specific details, or other methods, components, modules, devices, steps, etc. may be employed. In other instances, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

Claims

1. A data acquisition method, comprising the following steps: a) A first device sends a request for first data to an encryption authentication unit, the request including a feature code that can uniquely identify the first device and a timestamp indicating the local time of the first device; b) The encryption authentication unit receives the request, uses the included feature code and timestamp to encrypt the first data to obtain first encrypted data, and returns the first encrypted data to the first device; c) The first device receives the first encrypted data and performs an integrity check on the first encrypted data; d) In response to successful verification, repeat steps a) to c) so that the first device receives a second first encrypted data; and e) The first device compares the two received first encrypted data to determine whether they are the same. In response to determining that the two received first encrypted data are the same, decrypt the first encrypted data to obtain the first data; wherein, using the timestamp to encrypt the first data includes using a specific data segment of the timestamp as an encryption parameter for encryption, so that the same two first encrypted data can verify the availability of the first data.

2. The method according to claim 1, further comprising the following steps: f) In response to the first device determining in step e) that the two received first encrypted data are different, repeat steps a) to c) again so that the first device receives a third first encrypted data; g) The first device compares the last two received first encrypted data to determine whether they are the same. In response to determining that the last two received first encrypted data are the same, decrypt the first encrypted data to obtain the first data.

3. The method according to claim 1 or 2, further comprising an authentication method between the first device and the encryption authentication unit before executing the data acquisition method, comprising: h) The first device obtains the public key of the encryption authentication unit, encrypts second data with the public key to obtain second encrypted data, and sends the second encrypted data to the encryption authentication unit; i) The encryption authentication unit receives the second encrypted data, decrypts the second encrypted data with the private key of the encryption authentication unit that matches the public key, and compares the decrypted data with the data pre-stored in the encryption authentication unit to determine whether they are the same; j) In response to the encryption authentication unit determining that they are the same, the encryption authentication unit confirms that the first device is a trusted device and allows the execution of the data acquisition method; and k) In response to the encryption authentication unit determining that they are different, the encryption authentication unit confirms that the first device is not a trusted device and blocks the execution of the data acquisition method.

4. The method according to claim 3, further comprising: l) The first device encrypts third data with a first encryption algorithm to obtain second data; wherein, the third data is data pre-agreed upon and stored separately by the first device and the encryption authentication unit, and wherein, the data pre-stored in the encryption authentication unit is in a non-plaintext form obtained by encrypting the third data with the first encryption algorithm.

5. The method according to claim 4, wherein, the third data is an authentication string, and the first encryption algorithm is a hash value operation.

6. A communication method, It includes the following steps: The first device obtains first data and stores the first data in the encryption authentication unit. Wherein, the first data is a communication key, and the first device is a gateway device, and the gateway device includes a microcontroller and the encryption authentication unit; When the communication key is to be used, the data acquisition method according to any one of claims 1 to 5 is executed, so that the gateway device retrieves the communication key from the encryption authentication unit, wherein the signature is the unique identification serial number of the microcontroller; and The gateway device uses the communication key for communication.

7. The method according to claim 6, wherein, The first device obtains the first data, that is, the gateway device obtains the communication key, which includes: The program download device generates a first key pair and sends a program download signal to the gateway device. The program download signal includes a request for the unique identification serial number of the microcontroller and a time stamp indicating the local time of the gateway device; The gateway device receives the program download signal, returns the requested unique identification serial number and time stamp to the program download device, and generates a second key pair; The program download device and the gateway device exchange the public keys in the key pairs they generate respectively, and each uses the unique identification serial number and the time stamp as parameters to generate their respective shared keys by using the ECDH algorithm; The program download device encrypts the communication key by using the shared key it generates and sends the encrypted communication key to the gateway device; and The gateway device receives the encrypted communication key and decrypts it by using the shared key it generates to obtain the communication key.

8. A communication system, including: A gateway device, which includes a microcontroller and an encryption authentication unit; and A server that can communicate with the gateway device by using a communication key; wherein, the gateway device and the encryption authentication unit are configured to execute the data acquisition method according to any one of claims 1 to 5, so that the gateway device retrieves the communication key from the encryption authentication unit; and / or wherein, the gateway device and the server are configured to execute the communication method according to claim 6 or 7, so as to communicate by using the communication key.

9. A machine-readable storage medium, on which code instructions are stored, and when the code instructions are executed by one or more machines, the one or more machines are caused to implement the method according to any one of claims 1 to 7.