Civil electronic detonator initiation system and encryption transmission method
By using modular design and SM2 algorithm for data encryption and digital signature authentication in the electronic detonator detonation system, the problem of lack of security protection during data transmission is solved, and the security and reliability of data transmission is achieved.
Patent Information
- Application Number
- CN202510119356.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-27
AI Technical Summary
The existing electronic detonator detonator detonation system lacks security protection during data transmission, resulting in important data being intercepted or tampered with by criminals, causing bad impact.
The modularly designed civil electronic detonator detonator detonation system is adopted to generate and exchange public and private keys through the SM2 algorithm, and data encryption and digital signature authentication are carried out to ensure the security of the data during transmission.
It effectively prevents interception and tampering of data during transmission, improves the security and reliability of the system, and avoids the risk of illegal operation of detonators.
Smart Images

Figure CN120050072A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic detonators, and in particular to a civilian electronic detonator initiation system and an encryption transmission method. Background Art
[0002] With the continuous development of electronic detonator technology, its technical superiority has been increasingly widely recognized in the global blasting industry.
[0003] Currently, most initiation terminals in the industry adopt a non-modular design, which has weak scalability and is difficult to meet more blasting operation requirements. Moreover, many initiation systems transmit the collected blasting data to the public security civilian explosives platform through the mobile network, but lack corresponding security protection measures during the data transmission process. When important blasting data is intercepted or even tampered with by lawbreakers, it will cause extremely bad effects. Therefore, modular design of the initiation terminal and encrypted transmission of blasting data have strong practical significance. Summary of the Invention
[0004] The purpose of the present invention is to provide a civilian electronic detonator initiation system and an encryption transmission method, aiming to solve the problem that it will cause bad effects when important blasting data is intercepted or even tampered with by lawbreakers.
[0005] To achieve the above purpose, in the first aspect, the present invention provides an encryption transmission method for a civilian electronic detonator initiation system, including the following steps:
[0006] Step 1: The initiation terminal performs module initialization and establishes a wireless communication link with the civilian explosives platform;
[0007] Step 2: Transmit the electronic detonator-related data to the MCU module through the detonator interface module for parsing and caching;
[0008] Step 3: The encryption module and the civilian explosives platform respectively generate public and private keys and key validity periods according to the SM2 algorithm and exchange the public keys;
[0009] Step 4: The encryption module and the civilian explosives platform respectively generate private key signatures according to the SM2 algorithm and exchange them;
[0010] Step 5: Perform signature verification between the initiation terminal and the civilian explosives platform. If successful, the encryption chip encrypts the electronic detonator-related data with the public key of the civilian explosives platform. If the signature verification fails, repeat steps 2 to 4;
[0011] Step 6: The encryption chip verifies whether the encryption is successful. If successful, the encryption chip returns the encrypted data to the MCU; if it fails, the data transmitted this time will be discarded;
[0012] Step 7: The MCU sends the returned ciphertext to the civilian explosives platform;
[0013] Step 8: The civilian explosive platform checks the validity period of the secret key. After successful verification, it decrypts the data according to the private key generated by the civilian explosive platform and parses the data according to the custom protocol, and displays it on the platform interface; if the verification fails, the data transmitted this time will be discarded.
[0014] Among them, in the process of "the encryption module and the civilian explosive platform respectively generate public and private keys and the validity period of the secret key according to the SM2 algorithm and exchange the public keys", the following steps are included:
[0015] The encryption module and the civilian explosive platform respectively generate random integers and use elliptic curve calculations to obtain key pairs respectively. The key pairs include public keys and private keys;
[0016] After the encryption module and the civilian explosive platform exchange public keys respectively, they generate the validity period of the secret key respectively and record the key generation time.
[0017] Among them, in the process of "the encryption module and the civilian explosive platform respectively generate private key signatures according to the SM2 algorithm and exchange them", the generation of signatures includes:
[0018] Let M be the unsigned data that A will transmit to B. First, perform operations, and then calculate and convert its data type to an integer. Subsequently, A generates a random number k ∈ [ 1,n - 1 ] , and uses the elliptic curve to calculate the point (x 1 , y 1 ) = [k]G and convert the data type of x 1 to an integer, and then calculate r A =(e + x 1 ) mod n. If r A ≠0 and r A + k ≠ n, then calculate s A =((1 + d A ) -1 ·(k - r A ·d A )) mod n. If s A ≠0, then convert the data types of r A and s A to strings to obtain the signature of the transmission data M of A. Similarly, the signature of B can be obtained. Finally, the signatures of A and B are transmitted to each other;
[0019] A is the encryption module; B is the civilian explosive platform; (r A, s A ) is the signature of the encryption module; (r B , s B ) is the signature of the civilian explosive platform; P A is the public key of the encryption chip, PB is the public key of the civilian explosive platform, d A is the private key of the encryption chip, d B is the private key of the civilian explosive platform; G is a base point of the elliptic curve, and the order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k-fold point of point G on the elliptic curve; Z A is the hash value of the distinguishable identifier of A, part of the elliptic curve system parameters, and the public key of A.
[0020] Among them, in "Perform signature verification between the detonation terminal and the civilian explosive platform. If successful, the encryption chip encrypts the relevant data of the electronic detonator using the public key of the civilian explosive platform. If the signature verification fails, repeat steps two to four", the principle of the verification is: Suppose B receives the data and signature from A as M′ and (r A ′, s A ′) respectively. First, check if r A ′ ∈ [1, n - 1]. If it holds, then proceed to the next step. Check if s A ′ ∈ [1, n - 1]. If it holds, then proceed to the next step Then calculate and t = (r A ′ + s A ′) modn and convert the data types of e′, r A ′, s A ′ to integers. If t ≠ 0, then proceed to the next step to calculate the elliptic curve point (x 1 ′, y 1 ′) = [s A ′]G + [t]P A and convert the data type of x 1 ′ to an integer. Finally, calculate R = (e′ + x 1 ′) modn. Check if R = r A ′. If so, the signature verification is successful. Similarly for B, only when both A and B's signature verifications are successful can the next step of encryption be performed;
[0021] A is the encryption module; B is the civilian explosive platform; (r A ′, s A ′) is the signature received by the civilian explosive platform from the encryption module; (r B ′, s B ′) is the signature received by the encryption module from the civilian explosive platform; P A is the public key of the encryption chip, P B is the public key of the civilian explosive platform, d A is the private key of the encryption chip, d Bis the private key of the civilian explosive platform; G is a base point of the elliptic curve with a prime order; H V () is a cryptographic hash function of length v bits; mod n is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k-fold point of point G on the elliptic curve; Z A is the hash value of the distinguishable identifier of A, part of the elliptic curve system parameters, and the public key of A.
[0022] Among them, the principle of encryption and verification of success in the fifth and sixth steps is: A generates a random number k ∈ [ 1, n - 1 ] , and then calculates the elliptic curve point C 1 =(x 1 , y 1 ) = [k]G, and converts the data type of the coordinates of the point (x 1 , y 1) ) into a bit string, then calculates the elliptic curve point [h]P B . If this point is not the infinite point, proceed to the next step. Calculate the elliptic curve point (x 2 , y 2 ) = [k]P B , and convert the data type of the coordinates of the point (x 2 , y 2 ) into a bit string. Calculate t = KDF(x 2 ∥y 2 , klen). If t is not a bit string of all 0s, proceed to the next calculation C 2 = M ⊕ t and C 3 = Hash(x 2 ∥M∥y 2 ). Finally, obtain the ciphertext C = C 1 ∥C 2 ∥C 3 ;
[0023] A is the encryption module; B is the civilian explosive platform; (r A, s A ) is the signature of the encryption module; (r B , s B ) is the signature of the civilian explosive platform; P A is the public key of the encryption chip, P B is the public key of the civilian explosive platform, d A is the private key of the encryption chip, d B is the private key of the civilian explosive platform; G is a base point of the elliptic curve with a prime order; H V() is a cryptographic hash function of length v bits; mod n is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k - fold point of point G on the elliptic curve; KDF represents generating a bit string of length klen; Hash() is a hash function, representing calculating the hash value; klen is the bit length of M, h is [ 1, n - 1 ] any random number within the range.
[0024] Among them, in "The civilian explosive platform checks the validity period of the key. After successful verification, according to the private key generated by the civilian explosive platform, it decrypts it and parses the data according to the custom protocol, and displays it on the platform interface; if the verification fails, the data transmitted this time will be discarded", the decryption includes: Let klen be the 2 bit length of C. First, take out C 1 from the ciphertext C obtained from A and convert its data type to a point on the elliptic curve. If C 1 satisfies the elliptic curve equation, then perform the next calculation S = [h]C 1 . If S is not the infinite point, then perform the next calculation (x 2 , y 2 ) = [d B C 1 , and convert the data type of its coordinates to a bit string. Then calculate t = KDF(x 2 ∥y 2 , klen). If t is not a bit string of all 0s, then perform the next step of taking out C 2 from C and calculating Then calculate u = Hash(x 2 ∥M′∥y 2 ). Finally, take out C 3 from C. If C 3 = u, then it is proved that M′ is the data after decryption;
[0025] A is the encryption module; B is the civilian explosive platform; (r A, s A ) is the signature of the encryption module; (r B , s B ) is the signature of the civilian explosive platform; P A is the public key of the encryption chip, P B is the public key of the civilian explosive platform, d A is the private key of the encryption chip, d B is the private key of the civilian explosive platform; G is a base point of the elliptic curve, and the order is a prime number; H V() is a cryptographic hash function with a length of v bits; mod n is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k-fold point of point G on the elliptic curve; KDF represents generating a bit string with a length of klen; Hash() is a hash function, indicating calculating the hash value; klen is the bit length of M, and h is [ 1, n - 1 ] any random number within the range.
[0026] In a second aspect, a civilian electronic detonator initiation system is used for the encrypted transmission method of the civilian electronic detonator initiation system described in the first aspect, and includes an electronic detonator, an initiation terminal, and a civil explosive platform. The electronic detonator and the initiation terminal are connected through a wired or wireless communication method for two-way communication. The initiation terminal and the civil explosive platform are connected through a wireless communication method for two-way communication.
[0027] Among them, the initiation terminal includes a detonator interface module, an MCU module, a wireless communication module, a power supply module, a storage module, a code scanning module, an encryption module, a GPS module, and an LCD module;
[0028] The MCU module is respectively connected to the detonator interface module, the wireless communication module, the power supply module, the storage module, the code scanning module, the encryption module, the GPS module, and the LCD module; the power supply module supplies power to the MCU module unidirectionally, and the remaining modules communicate with the MCU module bidirectionally.
[0029] An encryption transmission method for a civilian electronic detonator initiation system of the present invention includes the following steps: Step 1: The initiation terminal performs module initialization and establishes a wireless communication link with the civilian explosive platform; Step 2: Transmit the relevant data of the electronic detonator to the MCU module through the detonator interface module for parsing and caching; Step 3: The encryption module and the civilian explosive platform respectively generate public and private keys and the key validity period according to the SM2 algorithm and exchange the public keys; Step 4: The encryption module and the civilian explosive platform respectively generate private key signatures according to the SM2 algorithm and exchange them; Step 5: Perform signature verification between the initiation terminal and the civilian explosive platform. If successful, the encryption chip encrypts the relevant data of the electronic detonator using the public key of the civilian explosive platform. If the signature verification fails, repeat Steps 2 to 4; Step 6: The encryption chip verifies whether the encryption is successful. If successful, the encryption chip returns the encrypted data to the MCU; if failed, the data of this transmission will be discarded; Step 7: The MCU sends the returned ciphertext to the civilian explosive platform; Step 8: The civilian explosive platform checks the key validity period. After successful verification, decrypt it according to the private key generated by the civilian explosive platform and parse the data according to the custom protocol, and display it on the platform interface; if the verification fails, the data of this transmission will be discarded. The blasting data is transmitted to the main control MCU through the detonator interface module. The MCU communicates with the encryption module through the serial port and calls the improved SM2 encryption algorithm inside to perform data encryption and digital signature authentication. The communication module completes the wireless transmission of data through the serial port. Before the encrypted transmission of the blasting data, the initiation terminal first exchanges public keys and performs private key signature verification with the civilian explosive platform through the wireless communication module; after the successful authentication of both parties, the blasting data is encrypted using SM2; then the encrypted data is transmitted to the civilian explosive platform through the wireless communication module. The platform first checks the key validity period. On the premise that it has not expired, decrypt and parse the received blasting encrypted data according to the corresponding key and protocol. The modular design makes the functional operation more convenient and has stronger scalability, which can meet more blasting operation requirements. The improved SM2 encryption algorithm improves the ability of the existing electronic detonator initiation system to resist information attacks, avoids the danger of illegal operation of detonators by forging communication instructions, and avoids the danger of illegal operation of detonators during non-blasting operation time, thus solving the problem that the interception and even tampering of important data of blasting by lawbreakers will cause adverse effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1It is a flowchart of an encryption transmission method for a civil electronic detonator initiation system provided by the present invention.
[0032] Figure 2 It is the overall flowchart of data encrypted communication.
[0033] Figure 3 It is a flowchart of the recording system in which the encryption module and the civil explosive platform respectively generate public and private keys and key validity periods according to the SM2 algorithm and exchange public keys.
[0034] Figure 4 It is a schematic diagram of a civil electronic detonator initiation system provided by the present invention.
[0035] In the figure: 1 - electronic detonator, 2 - initiation terminal, 3 - civil explosive platform, 201 - MCU module, 202 - detonator interface module, 203 - wireless communication module, 204 - power module, 205 - storage module, 206 - code scanning module, 207 - encryption module, 208 - GPS module, 209 - LCD module. Specific embodiments
[0036] The following details the embodiments of the present invention. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present invention and should not be construed as a limitation of the present invention.
[0037] Please refer to Figures 1 to 3 , in the first aspect, the present invention provides an encryption transmission method for a civil electronic detonator initiation system, including the following steps:
[0038] S1 The initiation terminal 2 performs module initialization and establishes a wireless communication link with the civil explosive platform 3;
[0039] Specifically, the initiation terminal 2 performs initial settings for each module, including clock, circuit settings, port initialization, and timer interrupt enabling. Mainly, the MCU sends relevant instructions to the wireless communication module 203 through the serial port to complete the configuration of the mobile network, so as to establish a reliable wireless communication link between the initiation terminal 2 and the civil explosive platform 3.
[0040] S2 Transmit the relevant data of the electronic detonator 1 to the MCU module 201 through the detonator interface module 202 for parsing and caching;
[0041] Specifically, wait for the relevant data of the electronic detonator 1 to be transmitted to the MCU through the wired or wireless detonator interface. The MCU parses, processes, and caches the data, and waits to transmit it to the encryption module 207 through serial communication after successful signature verification.
[0042] The S3 encryption module 207 and the civilian explosive platform 3 respectively generate public keys, private keys and key validity periods according to the SM2 algorithm and exchange the public keys;
[0043] The S31 encryption module 207 and the civilian explosive platform 3 respectively generate random integers and use elliptic curve calculations to obtain key pairs, where the key pairs include public keys and private keys;
[0044] Specifically, taking A as the encrypting party as an example, first generate a random integer d A ∈[1, n - 2], and then use the elliptic curve to calculate P A =[d A G to obtain the key pair (d A , P A ) of user A. Similarly, user B obtains the key pair (d B , P B ) , .
[0045] After the S32 encryption module 207 and the civilian explosive platform 3 exchange the public keys respectively, they generate key validity periods respectively and record the key generation time.
[0046] Specifically, then the public key P A generated by A is transmitted to B, and the public key P B generated by B is transmitted to A. At the same time, A and B respectively generate key validity periods t A and t B , and record the key generation times t A1 and t B1 , where d A , d B are private keys, and P A , P B are public keys.
[0047] The S4 encryption module 207 and the civilian explosive platform 3 respectively generate private key signatures according to the SM2 algorithm and exchange them;
[0048] Generating a signature includes:
[0049] Let M be the unsigned data that A will transmit to B. First, perform operations, then calculate and convert its data type to an integer. Subsequently, A generates a random number k ∈ [ 1, n - 1 ] , uses the elliptic curve to calculate the point (x 1 , y 1 ) = [k]G and convert the data type of x 1 to an integer, and then calculate r A =(e + x 1 ) mod n. If r A ≠0 and r A+k ≠ If n is given, then calculate s A = ((1 + d A )) -1 · (k - r A · d A )) mod n. If s A ≠ 0, then convert the data types of r A and s A to strings to obtain the signature of the transmission data M of A. Similarly, the signature of B can be obtained. Finally, the signatures of A and B are passed to each other;
[0050] Let A be the encryption module 207; B be the civilian explosive platform 3; (r A, s A ) be the signature of the encryption module 207; (r B , s B ) be the signature of the civilian explosive platform 3; P A be the public key of the encryption chip, P B be the public key of the civilian explosive platform 3, d A be the private key of the encryption chip, d B be the private key of the civilian explosive platform 3; G be a base point of the elliptic curve with prime order; H V () be a cryptographic hash function of length v bits; mod n be the modulo n operation; n be the order of the base point G; ∥ denote concatenating the strings or bit strings on both sides; [k]G denote the k - fold point of point G on the elliptic curve; Z A be the hash value of the distinguishable identifier of A, partial elliptic curve system parameters, and the public key of A.
[0051] Specifically, the encryption module 207 negotiates with the civilian explosive platform 3 and generates private key signatures and exchanges them respectively according to the SM2 algorithm. In step four, the specific principle of generating the signature is as follows: Taking A as the encrypting party as an example, let M be the unsigned data that A will transmit to B. First, perform operation, then calculate and convert its data type to an integer. Subsequently, A generates a random number k ∈ [ 1, n - 1 ] , calculate the point (x 1 , y 1 ) = [k]G using the elliptic curve and convert the data type of x 1 to an integer. Then calculate r A = (e + x 1 ) mod n. If r A ≠ 0 and r A + k ≠ n, then calculate s A = ((1 + d A )) -1 · (k - r A · d A)) mod n, if s A ≠ 0, then convert the data types of r A , s A to strings to obtain the signature (r A , s A ) of the transmission data M of A. Similarly, the signature (r B , s B ) of B can be obtained. Finally, the signatures of A and B are passed to each other.
[0052] S5 performs signature verification on the detonation terminal 2 and the civil explosive platform 3. If successful, the encryption chip encrypts the relevant data of the electronic detonator 1 using the public key of the civil explosive platform 3. If the signature verification fails, repeat steps two to four;
[0053] The principle of the verification is as follows: Suppose the data and signature received by B from A are M' and (r A ', s A ') respectively. First, check if r A ' ∈ [1, n - 1]. If it holds, then proceed to the next step. Check if s A ' ∈ [1, n - 1]. If it holds, then proceed to the next step Then calculate and t = (r A ' + s A ') mod n, and convert the data types of e', r A ', s A ' to integers. If t ≠ 0, then proceed to the next calculation of the elliptic curve point (x 1 ', y 1 ') = [s A ']G + [t]P A and convert the data type of x 1 ' to an integer. Finally, calculate R = (e' + x 1 ') mod n, and check if R = r A '. If the signature verification is successful, the same applies to B. Only when the signature verifications of both A and B are successful can the next encryption be performed;
[0054] A is the encryption module 207; B is the civil explosive platform 3; (r A ', s A ') is the signature received by B from A; (r B ', s B ') is the signature received by A from B; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform 3, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform 3; G is a base point of the elliptic curve with prime order; H V() is a cryptographic hash function of length v bits; mod n is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k - fold point of point G on the elliptic curve; Z A is the hash value of the distinguishable identifier of A, partial elliptic curve system parameters, and A's public key.
[0055] The principle of the encryption and whether its verification is successful is as follows: A generates a random number k ∈ [1, n - 1], and then calculates the elliptic curve point C 1 =(x 1 , y 1 ) = [k]G, and converts the data type of the coordinates of the point (x 1 , y 1 ) into a bit string, then calculates the elliptic curve point [h]P B . If this point is not the infinite point, then proceed to the next step. Calculate the elliptic curve point (x 2 , y 2 ) = [k]P B , and convert the data type of the coordinates of the point (x 2 , y 2 ) into a bit string, calculate t = KDF(x 2 ∥y 2 , klen). If t is not a bit string of all 0s, then proceed to the next calculation and C 3 = Hash(x 2 ∥M∥y 2 ). Finally, obtain the ciphertext C = C 1 ∥C 2 ∥C 3 ;
[0056] A is the encryption module 207; B is the civil explosive platform 3; (r A, s A ) is the signature of the encryption module 207; (r B , s B ) is the signature of the civil explosive platform 3; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform 3, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform 3; G is a base point of the elliptic curve with prime order; H V () is a cryptographic hash function of length v bits; mod n is the modulo n operation; n is the order of the base point G; ∥ represents concatenating the strings or bit strings on both sides; [k]G represents the k - fold point of point G on the elliptic curve; KDF represents generating a bit string of length klen; Hash() is a hash function representing calculating the hash value; klen is the bit length of M; h is [1, n - 1 ] Any random number within the range.
[0057] Specifically, for the signature verification between the detonation terminal 2 and the civilian explosive platform 3, after successfully confirming the communication object, the encryption chip encrypts the relevant data of the electronic detonator 1 using the public key of the civilian explosive platform 3. If the signature verification fails, steps three, four, and five are repeated; the specific principle of signature verification is as follows: taking B as the decryption party as an example, assume that the data and signature received by B from A are M′ and (r A ′, s A ′) respectively. First, check if r A ′ ∈ [1, n - 1]. If it holds, proceed to the next step. Then, check if s A ′ ∈ [1, n - 1]. If it holds, proceed to the next step Then calculate and t = (r A ′ + s A ′) mod n, and convert the data types of e′, r A ′, and s A ′ to integers. If t ≠ 0, then calculate the elliptic curve point (x 1 ′, y 1 ′) = [s A ′]G + [t]P A and convert the data type of x 1 ′ to an integer. Finally, calculate R = (e′ + x 1 ′) mod n. If R = r A ′, the signature verification is successful. Similarly for user B, only when both A and B's signature verifications are successful can the next step of encryption be carried out.
[0058] S6 The encryption chip verifies whether the encryption is successful. If successful, the encryption chip returns the encrypted data to the MCU; if failed, the data of this transmission will be discarded;
[0059] The principle of the encryption and the verification of whether it is successful in the above step five and step six is as follows: A generates a random number k ∈ [ 1, n - 1 ] , then calculates the elliptic curve point C 1 = (x 1 , y 1 ) = [k]G, and converts the coordinates of the point (x 1 , y 1 ) to a bit string. Then calculates the elliptic curve point [h]P B . If this point is not the infinite point, proceed to the next step. Calculate the elliptic curve point (x 2 , y 2 ) = [k]P B , and convert the coordinates of the point (x 2 , y2 ) Convert the data type of the coordinates to a bit string, and calculate t = KDF(x 2 ∥y 2 , klen). If t is not an all-zero bit string, proceed to the next calculation and C 3 = Hash(x 2 ∥M∥y 2 ), and finally obtain the ciphertext C = C 1 ∥C 2 ∥C 3 ;
[0060] A is the encryption module 207; B is the civilian explosive platform 3; (r A, s A ) is the signature of the encryption module 207; (r B , s B ) is the signature of the civilian explosive platform 3; (r A ′, s A ′) is the signature received by the civilian explosive platform 3 from the encryption module 207; (r B ′, s B ′) is the signature received by the encryption module 207 from the civilian explosive platform 3; P A is the public key of the encryption chip, P B is the public key of the civilian explosive platform 3, d A is the private key of the encryption chip, d B is the private key of the civilian explosive platform 3; G is a base point of the elliptic curve with order prime; H V () is a cryptographic hash function of length v bits; modn is the modulo n operation; n is the order of the base point G; ∥ means concatenating the strings or bit strings on both sides; [k]G represents the k-fold point of point G on the elliptic curve; KDF represents generating a bit string of length klen; Hash() is a hash function representing calculating the hash value; klen is the bit length of M; h is an arbitrary random number in the range [1, n - 1]; Z A is the hash value of the distinguishable identifier of A, part of the elliptic curve system parameters, and the public key of A.
[0061] Specifically, the encryption chip verifies whether the encryption is successful. If successful, the encryption chip returns the encrypted data to the MCU; if failed, the data transmitted this time will be discarded; in steps five and six, the specific principle of encryption and its verification of success is as follows: taking A as the encrypting party as an example, let M be the data to be encrypted, klen be the bit length of M. First, A generates a random number k ∈ [1, n - 1], and then calculates the elliptic curve point C 1 =(x 1 , y 1 ) = [k]G, and sends the point (x 1 , y1 ) Convert the data type of the coordinates to a bit string, and then calculate the elliptic curve point [h]P B , if the point is not the point at infinity, then proceed to the next step, calculate the elliptic curve point (x 2 , y 2 ) = [k]P B , and convert the data type of the coordinates of the point (x 2 , y 2 ) to a bit string, calculate t = KDF(x 2 ∥ y 2 , klen), if t is not a bit string of all 0s, then proceed to the next calculation and C 3 = Hash(x 2 ∥ M ∥ y 2 ), and finally obtain the ciphertext C = C 1 ∥ C 2 ∥ C 3 .
[0062] The S7 MCU sends the returned ciphertext to the civilian explosive platform 3;
[0063] Specifically, the MCU module 201 sends the returned ciphertext to the civilian explosive platform 3.
[0064] S8 The civilian explosive platform 3 checks the key validity period. After successful verification, it decrypts it according to the private key generated by the civilian explosive platform 3 and parses the data according to the custom protocol, and displays it on the platform interface; if the verification fails, the data transmitted this time will be discarded.
[0065] The decryption includes: Let klen be the bit length of C 2 , first, take out C in the ciphertext C obtained from A and convert its data type to a point on the elliptic curve. If C 1 satisfies the elliptic curve equation, then proceed to the next calculation S = [h]C 1 , if S is not the point at infinity, then proceed to the next calculation (x 1 , y 2 ) = [d 2 C B , and convert the data type of its coordinates to a bit string, then calculate t = KDF(x 1 ∥ y 2 , klen). If t is not a bit string of all 0s, then proceed to the next step to take out C in C 2 , and calculate 2 Then calculate u = Hash(x ∥ M′ ∥ y 2 , and finally take out C in C 2 ), if C 3 , if C 3= u, then it is proved that M' is the data after decryption;
[0066] A is the encryption module 207; B is the civil explosive platform 3; (r A, s A ) is the signature of the encryption module 207; (r B , s B ) is the signature of the civil explosive platform 3; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform 3, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform 3; G is a base point of the elliptic curve, and the order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is the modulo n operation; n is the order of the base point G; ∥ means concatenating the strings or bit strings on both sides; [k]G represents the k-fold point of the point G on the elliptic curve; KDF represents generating a bit string with a length of klen; Hash() is a hash function, which means calculating the hash value; klen is the bit length of M; h is [ 1, n - 1 ] any random number within the range.
[0067] Specifically, the civil explosive platform 3 checks the key validity period. After successful verification, it decrypts according to the private key generated by the civil explosive platform 3 and parses the data according to the custom protocol, and displays it on the platform interface; if the verification fails, the data transmitted this time will be discarded; in step eight, the specific principle of verifying the key validity period is: taking B as the decrypting party as an example, record the time t A2 , if t A ≤ t A2 - t A1 then proceed to the next step of decryption. In step eight, the specific principle of decryption is: taking B as the decrypting party as an example, let klen be the bit length of C 2 , first, take out C in the ciphertext C obtained from A 1 and convert its data type to a point on the elliptic curve. If C 1 satisfies the elliptic curve equation, then proceed to the next step of calculation S = [h]C 1 , if S is not the infinite point, then proceed to the next step of calculation (x 2 , y 2 ) = [d B C 1 and convert the data type of its coordinates to a bit string, then calculate t = KDF(x 2 ∥ y 2 , klen), if t is not an all-zero bit string, then proceed to the next step of taking out C in C 2 and calculate Calculate u = Hash(x 2 ∥M′∥y 2 ), and finally retrieve C 3 from C. If C 3 = u, it proves that M′ is the decrypted data.
[0068] Please refer to Figure 4 , in a second aspect, a civilian electronic detonator initiation system for the encrypted transmission method of the civilian electronic detonator initiation system described in the first aspect, including an electronic detonator 1, an initiation terminal 2, and a civil explosive platform 3. The electronic detonator 1 and the initiation terminal 2 are connected through a wired or wireless communication method for two-way communication. The initiation terminal 2 and the civil explosive platform 3 are connected through a wireless communication method for two-way communication.
[0069] The initiation terminal 2 includes a detonator interface module 202, an MCU module 201, a wireless communication module 203, a power supply module 204, a storage module 205, a barcode scanning module 206, an encryption module 207, a GPS module 208, and an LCD module 209;
[0070] The MCU module 201 is respectively connected to the detonator interface module 202, the wireless communication module 203, the power supply module 204, the storage module 205, the barcode scanning module 206, the encryption module 207, the GPS module 208, and the LCD module 209. The power supply module 204 supplies power to the MCU module 201 unidirectionally, and the remaining modules communicate with the MCU module 201 bidirectionally.
[0071] In this embodiment, the LCD module 209 uses a touch-screen LCD display screen, and realizes function control through a touch-type virtual keyboard. This design can effectively improve the utilization rate of resource costs. The encryption module 207 of the present invention adopts the improved SM2 national secret algorithm, which is an asymmetric encryption algorithm, mainly including digital signature technology, key exchange protocol, public key encryption algorithm and key validity period technology. The addition of key validity period technology can prevent the adverse effects that may occur during data transmission due to transmission timeout; the detonator interface module 202 is divided into wired or wireless interface, the MCU module 201 can be divided into a chip based on uC / OS-II operating system or based on Android operating system, the communication mode of the wireless communication module 203 includes but is not limited to 4G, 5G and WIFI communication, the storage module 205 is divided into a built-in or external storage card, the positioning mode of the GPS module 208 is divided into GPS positioning, Beidou positioning and Beidou / GPS dual-mode positioning, and the LCD module 209 of the present invention is divided into touch-screen type and non-touch-screen type LCD display screen, the encryption algorithm of the encryption module 207 is divided into symmetric encryption algorithm, asymmetric encryption algorithm and hash algorithm, the blasting data is transmitted to the main control MCU through the detonator interface module 202, the MCU communicates with the encryption module 207 through the serial port, and calls its internal improved SM2 encryption algorithm to perform data encryption and digital signature authentication and the communication module to complete the wireless data transmission through the serial port communication. Before the encrypted transmission of the blasting data, the detonation terminal 2 first exchanges the public key and verifies the private key with the civil explosive platform 3 through the wireless communication module 203; after the identity authentication of both parties is successful, the blasting data is encrypted by SM2; then the wireless communication module 203 is used to transmit the encrypted data to the civil explosive platform 3, the platform first checks the validity period of the key, and under the premise of not expired, the received blasting encrypted data is decrypted and parsed according to the corresponding key and protocol.
[0072] Beneficial effects:
[0073] The modular design makes the functional operation more convenient and more scalable, and can meet more blasting operation needs. The improved SM2 encryption algorithm improves the ability of the existing electronic detonator initiation system to resist information attacks, avoids the danger of illegal operation of detonators by forging communication instructions, and avoids the danger of illegal operation of detonators during non-blasting operation time.
[0074] What is disclosed above is only a preferred embodiment of a civilian electronic detonator initiation system and an encrypted transmission method of the present invention. Of course, this cannot be used to limit the scope of rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of the above embodiments and equivalent changes made according to the claims of the present invention still fall within the scope of the invention.
Claims
1. An encrypted transmission method for a civilian electronic detonator initiation system, characterized in that: The following steps are involved: Step 1: The detonation terminal initializes the module and establishes a wireless communication link with the civil explosive platform; Step 2: Transmit the electronic detonator related data to the MCU module through the detonator interface module for parsing and caching; Step 3: The encryption module and the civil explosive platform generate public and private keys and key validity periods according to the SM2 algorithm and exchange public keys; Step 4: The encryption module and the civil explosives platform generate private key signatures according to the SM2 algorithm and exchange them; Step 5: Verify the signature between the detonation terminal and the civil explosive platform. If successful, the encryption chip uses the public key of the civil explosive platform to encrypt the electronic detonator related data. If the verification fails, repeat steps 2 to 4. Step 6: The encryption chip verifies whether the encryption is successful. If successful, the encryption chip returns the encrypted data to the MCU; if failed, the transmitted data will be discarded; Step 7: MCU sends the returned ciphertext to the civil explosives platform; Step 8: The civil explosives platform verifies the validity period of the key. After successful verification, it decrypts the key according to the private key generated by the civil explosives platform and parses the data according to the custom protocol and displays it on the platform interface. If the verification fails, the transmitted data will be discarded.
2. The encrypted transmission method of the civilian electronic detonator initiation system according to claim 1, characterized in that: In "the encryption module and the civil explosive platform generate public and private keys and key validity periods according to the SM2 algorithm and exchange public keys", the following steps are included: The encryption module and the civil explosives platform generate random integers respectively, and use elliptic curve calculations to obtain key pairs, which include a public key and a private key; After the encryption module and the civil explosives platform exchange public keys, they generate key validity periods and record the key generation time.
3. The encrypted transmission method of the civilian electronic detonator initiation system as claimed in claim 2, characterized in that: In "The encryption module and the civil explosive platform generate private key signatures and exchange them according to the SM2 algorithm", the signature generation includes: Let M be the unsigned data that A will pass to B. First Calculate and recalculate And convert its data type to an integer, then A generates a random number k∈ [ 1,n-1 ] , use the elliptic curve to calculate the point (x1, y1) = [k] G and convert the data type of x1 to an integer, and then calculate r A =(e+x1)modn, if r A ≠0 and r A +k ≠ n then calculate s A =((1+d A ) -1 ·(kr A ·d A ))modn, if s A ≠0, then r A 、s A The data type is converted into a string to obtain the signature of A's transmission data M. Similarly, the signature of B can be obtained. Finally, the signatures of A and B are transmitted to each other. A is the encryption module; B is the civil explosive platform; (r A, s A ) is the signature of the encryption module; (r B ,s B ) is the signature of the civil explosion platform; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform; G is a base point of the elliptic curve, and its order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is a modulo n operation; n is the order of the base point G; ∥ means concatenating the character strings or bit strings on both sides; [k]G means the k-fold point G on the elliptic curve; Z A is a hash value of A's distinguishable identifier, some elliptic curve system parameters and A's public key.
4. The encrypted transmission method of the civilian electronic detonator initiation system as claimed in claim 3, characterized in that: In "verify the signature between the detonation terminal and the civil explosive platform. If successful, the encryption chip uses the public key of the civil explosive platform to encrypt the electronic detonator related data. If the signature verification fails, repeat steps 2 to 4", the verification principle is: suppose that the data and signature received by B are M' and (r A ′,s A ′), first check r A ′∈[1, n-1], if it holds, proceed to the next step and check s A ′∈[1, n-1], if it holds, proceed to the next step Then calculate and t=(r A ′+s A ′)modn and e′, r A ′,s A ′ is converted to an integer. If t≠0, the next step is to calculate the elliptic curve point (x1′, y1′)=[s A ′]G+[t]P A Convert the data type of x1′ to an integer, and finally calculate R=(e′+x1′)modn, and verify that R=r A ′, the signature verification is successful, and the same is true for B. Only when both A and B have successfully verified their signatures can the next step of encryption be carried out; A is the encryption module; B is the civil explosive platform; (r A ′,s A ′) is the signature received by B from A; (r B ′,s B ') is the signature received by A from B; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform; G is a base point of the elliptic curve, and its order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is a modulo n operation; n is the order of the base point G; ∥ means concatenating the character strings or bit strings on both sides; [k]G means the k-fold point G on the elliptic curve; Z A is a hash value of A's distinguishable identifier, some elliptic curve system parameters and A's public key.
5. The encrypted transmission method of the civilian electronic detonator initiation system as claimed in claim 4, characterized in that: The principle of whether the encryption and verification in step 5 and step 6 are successful is as follows: A generates a random number k∈[1,n-1], then calculates the elliptic curve point C1=(x1,y1)=[k]G, and converts the data type of the coordinates of the point (x1,y1) into a bit string, and then calculates the elliptic curve point [h]P B If the point is not at infinity, proceed to the next step and calculate the elliptic curve point (x2, y2) = [k] P B , and convert the data type of the point (x2, y2) coordinates into a bit string, calculate t = KDF (x2 | y2, klen), if t is not an all-zero bit string, proceed to the next step of calculating C2 = M ⊕ t and C3 = Hash (x2 | ∥ M | y2), and finally obtain the ciphertext C = C1 | ∥ C2 | ∥ C3; A is the encryption module; B is the civil explosive platform; (r A, s A ) is the signature of the encryption module; (r B ,s B ) is the signature of the civil explosive platform; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform; G is a base point of the elliptic curve, and its order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is a modulo n operation; n is the order of the base point G; ∥ means concatenating the character strings or bit strings on both sides; [k]G means a point k times the point G on the elliptic curve; KDF means generating a bit string with a length of klen; Hash() is a hash function, which means calculating a hash value; klen is the bit length of M, and h is any random number in the range of 1,n-1].
6. The encrypted transmission method of the civilian electronic detonator initiation system as claimed in claim 5, characterized in that: In the "Civil Explosives Platform, check the key validity period. After successful verification, decrypt it according to the private key generated by the Civil Explosives Platform, parse the data according to the custom protocol, and display it on the platform interface; If the verification fails, the data transmitted will be discarded", the decryption Including: Let klen be the bit length of C2. First, take out C1 in the ciphertext C obtained from A and convert its data type into a point on the elliptic curve. If C1 satisfies the elliptic curve equation, then proceed to the next step of calculating S=[h]C1. If S is not a point at infinity, then proceed to the next step of calculating (x2, y2)=[d B ]C1, and convert the data type of its coordinates into a bit string, then calculate t = KDF(x2∥y2, klen). If t is not an all-0 bit string, then proceed to the next step to take out C2 from C, and calculate M′ = C2⊕t, then calculate u = Hash(x2∥M′∥y2), and finally take out C3 from C. If C3 = u, it proves that M′ is the decrypted data; A is the encryption module; B is the civil explosive platform; (r A, s A ) is the signature of the encryption module; (r B ,s B ) is the signature of the civil explosive platform; P A is the public key of the encryption chip, P B is the public key of the civil explosive platform, d A is the private key of the encryption chip, d B is the private key of the civil explosive platform; G is a base point of the elliptic curve, and its order is a prime number; H V () is a cryptographic hash function with a length of v bits; modn is a modulo n operation; n is the order of the base point G; ∥ means concatenating the character strings or bit strings on both sides; [k]G means a point k times the point G on the elliptic curve; KDF means generating a bit string with a length of klen; Hash() is a hash function, which means calculating a hash value; klen is the bit length of M, and h is 1, n-1 ] Any random number in the range.
7. A civilian electronic detonator initiation system, used in the encrypted transmission method of the civilian electronic detonator initiation system according to any one of claims 1 to 6, characterized in that: It includes an electronic detonator, a detonating terminal and a civil explosive platform. The electronic detonator and the detonating terminal are connected via wired or wireless communication for two-way communication, and the detonating terminal and the civil explosive platform are connected via wireless communication for two-way communication.
8. The civilian electronic detonator initiation system as claimed in claim 7, characterized in that: The detonation terminal includes a detonator interface module, an MCU module, a wireless communication module, a power module, a storage module, a code scanning module, an encryption module, a GPS module and an LCD module; The MCU module is respectively connected to the detonator interface module, the wireless communication module, the power module, the storage module, the code scanning module, the encryption module, the GPS module and the LCD module; the power module supplies power to the MCU module unidirectionally, and the remaining modules communicate with the MCU module bidirectionally.