Remote upgrading method and system for intelligent temperature controller

By introducing key management, certificate management, load awareness, encrypted transmission and breakpoint transmission modules into the remote upgrade system of the intelligent thermostat, the security risks and reliability problems of remote upgrade of the intelligent thermostat in the existing technology are solved, and an efficient and secure upgrade process is achieved, which is suitable for security-sensitive scenarios.

CN120074955AActive Publication Date: 2025-05-30GUANGDONG HUILONG ELECTRIC CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510534185.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-05-30
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

The existing remote upgrade solution for smart thermostats poses security risks, lacks effective identity verification and permission control, and the upgrade process may interfere with the temperature control function, making it difficult to take into account both security and reliability.

Method used

Authentication is carried out through the key management module and the certificate management module to ensure the credibility of the upgrade instructions; the load-aware module is used to dynamically monitor the load status of the equipment to ensure the safety and reliability of the upgrade environment; the encrypted transmission module and breakpoint transmission module are used to ensure the secure transmission of the upgrade packet and the handling of network interruptions.

Benefits of technology

It improves the safety and reliability of remote upgrade of smart thermostats, ensures that the upgrade process will not interfere with the temperature control function, and is suitable for safety-sensitive scenarios such as hospitals and laboratories.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074955A_ABST
    Figure CN120074955A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of equipment function management, in particular to a remote upgrading method and system for an intelligent temperature controller. The method comprises the steps that the secret key management module and the certificate management module are adopted to verify equipment identity information and an upgrading instruction, the load sensing module is adopted to monitor the load condition of the intelligent temperature controller, the encryption transmission module is adopted to encrypt an upgrading package, and the breakpoint resume module is adopted to actively cope with the network interruption problem. The problems of identity forgery and upgrade instruction hijacking are solved through the key management module and the certificate management module, and the load condition of the equipment is dynamically monitored through the load sensing module to ensure that the upgrade environment is safe and reliable; and the target upgrade package is effectively prevented from being tampered and eavesdropped in the transmission process through the encryption transmission module and the breakpoint resuming module, meanwhile, the network interruption problem occurring in the upgrade process is actively solved, and the safety and reliability of remote upgrade of the intelligent temperature controller are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of device function management, and particularly to a remote upgrade method and system for an intelligent thermostat. Background Art

[0002] In the fields of smart home and industrial control, as a core device, the function iteration of an intelligent thermostat relies on remote upgrade technology (OTA) to implement firmware updates and vulnerability repairs. However, there are certain security risks in existing remote upgrade solutions: Firstly, the upgrade process lacks a perfect security verification mechanism. Traditional methods mostly transmit firmware packages in plain text, making them vulnerable to man-in-the-middle attacks and tampering, which may lead to device out-of-control or data leakage. Secondly, identity authentication and permission control are relatively weak. Illegal terminals may disguise themselves as upgrade servers to issue instructions, hijack the communication link, and violate user privacy. Finally, abnormal interruptions will cause the loss of transmission progress, resulting in the inability to transmit the upgrade package completely or the repeated execution of tasks.

[0003] Although current technologies can achieve basic OTA functions, they fail to design an optimized solution for the characteristics of low power consumption and high real-time performance of intelligent thermostats, resulting in difficulties in balancing upgrade efficiency and security. In addition, existing solutions lack dynamic monitoring of the device operation status, and the upgrade process may interfere with the core temperature control function.

[0004] These problems have restricted the application of intelligent thermostats in security-sensitive scenarios such as hospitals and laboratories to a certain extent. Therefore, there is an urgent need for an efficient and secure remote upgrade method and system for intelligent thermostats to meet actual requirements. Summary of the Invention

[0005] To solve the above problems existing in the prior art, the present invention provides a remote upgrade method and system for an intelligent thermostat, which solves the problems of identity forgery and upgrade instruction hijacking through a key management module and a certificate management module, dynamically monitors the device load status through a load perception module to ensure a safe and reliable upgrade environment; and also effectively avoids the tampering and eavesdropping of the target upgrade package during transmission through an encrypted transmission module and a breakpoint resumption module, and actively responds to network interruptions during the upgrade process, improving the security and reliability of the remote upgrade of the intelligent thermostat.

[0006] In a first aspect, the present invention provides a remote upgrade method for an intelligent thermostat, including the steps of: Receiving an upgrade instruction and verifying the identity information of the target device; If the identity information verification is passed, then trace and verify the credibility of the upgrade instruction; After the credibility verification is passed, evaluate the task priority and resource occupancy status of the current target device; If the task priority of the temperature control function of the current target device is higher than the upgrade task priority and the resource occupancy rate is lower than the preset threshold, the upgrade operation is allowed; otherwise, the upgrade is suspended until the conditions are met; Divide the target upgrade package into multiple data blocks and assign a unique identification number to each data block; Encrypt the data blocks and generate encrypted data packets; After the target device receives the encrypted data packets, compare the integrity of the data blocks through the verification key; if the data blocks pass the verification, decrypt and store the data blocks in the temporary storage area; If a network interruption occurs, record the identification numbers of the data blocks that have been successfully transmitted; after the network resumes, continue to transmit the data blocks that have not been successfully transmitted according to the recorded identification numbers of the data blocks; When all the data blocks are transmitted, splice them in the order of the identification numbers to generate a complete upgrade package; calculate the overall digest value of the spliced complete upgrade package and compare it with the digest value of the target upgrade package; if the comparison result is consistent, write the complete upgrade package into the storage area of the target device and replace the currently running firmware; if the comparison result is inconsistent, clear the data blocks in the temporary storage area and try to upgrade again; If multiple upgrade attempts fail, try to restore the original firmware data from the backup; write the backup data of the original firmware data into the main storage area and calculate its digest value; if the obtained digest value is consistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed but the original firmware was successfully restored; if the obtained hash value is inconsistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed and the original firmware restoration failed.

[0007] As a preferred technical solution of the present invention, the verification of the identity information of the target device includes: Obtain the root key from the hardware encryption machine; Generate the manufacturer key according to the root key and the discrete algorithm of the manufacturer ID of the target device; Then generate the terminal key according to the manufacturer key and the discrete algorithm of the terminal ID of the target device; Compare the generated terminal key with the terminal key stored in the target device; if the comparison result is consistent, the identity verification is passed; otherwise, the upgrade process is terminated.

[0008] As a preferred technical solution of the present invention, the tracing and verification of the credibility of the upgrade instruction includes: Obtain the root CA key from the hardware encryption machine; Sign the manufacturer CA key according to the root CA key and the manufacturer ID of the target device; Then sign the terminal CA key according to the manufacturer CA key and the terminal ID of the target device; Trace and verify the credibility of the manufacturer CA key through the terminal CA key; Trace and verify the credibility of the root CA key through the manufacturer's CA key; if the root CA key is a trusted certificate, the instruction verification passes; otherwise, the upgrade process is terminated.

[0009] As a preferred technical solution of the present invention, the evaluating the task priority and resource occupancy status of the current target device includes: Set three priorities of high, medium, and low corresponding to the temperature control function, upgrade task, and other auxiliary functions respectively; Real-time collect the CPU usage rate and the resource occupancy rate of the task process; combine the resource requirements of the temperature control function task to evaluate the resource occupancy rate of the current device; if the task priority of the temperature control function of the current target device is higher than the upgrade task priority and the resource occupancy rate is lower than the preset threshold, the upgrade operation is allowed to be executed; otherwise, enter the waiting queue.

[0010] As a preferred technical solution of the present invention, the encrypting the data block includes: The data block encryption unit negotiates and generates a data block public key and a data block private key based on the ECDH protocol; The block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol; Generate a shared key according to the data block public key, data block private key, block decryption unit public key, and block decryption unit private key; The shared key derives an encryption subkey and a verification key through the HKDF-SHA256 algorithm combined with a random salt value; The encryption subkey is used by the sender to perform SM4-CTR encryption on the data block to generate an encrypted data packet; The verification key is used by the receiver to perform SHA256 hash verification on the received encrypted data packet; The sender generates a digest value based on the verification key and the data block content, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; verify that the encrypted data packet has not been tampered with or damaged during the transmission process by performing a hash check on the two digest values.

[0011] As a preferred technical solution of the present invention, the recording the identification number of the data block that has been successfully transmitted and transmitting the data block that has not been successfully transmitted after the network is reconnected includes: Divide the storage area of the target device into partition A and partition B. Partition A is used to store the currently running firmware, and partition B is used to store the new firmware; After the target upgrade package passes the integrity verification, write the target upgrade package as the new firmware into partition B, and after the target upgrade package is completely written, replace it into partition A as the currently running firmware; Reserve a Flash sending area and a Flash receiving area on the server side and the target device side respectively to record the transmission progress; Detect the network status through the heartbeat packet mechanism; if no response is received for three consecutive heartbeat packets, it is determined that the network is interrupted; during the network interruption, record the identification number of the last successfully transmitted data block.

[0012] As a preferred technical solution of the present invention, the attempt to restore the original firmware data of the backup includes: Back up according to the currently running firmware and generate a backup firmware; Preset a physical DIP switch, which is a manually operated hardware control element for recording the DIP value; the DIP value is used to record the storage location of the backup firmware; Detect whether the physical DIP switch on the target device is triggered; if the physical DIP switch is triggered, read the DIP value; Read the backup firmware from the preset storage location according to the DIP value; use the backup firmware as a new target upgrade package to re - execute the upgrade process.

[0013] In a second aspect, the present invention also provides a remote upgrade system for an intelligent thermostat, which executes the remote upgrade method of the intelligent thermostat, including: The system includes a key management module, a certificate management module, a load perception module, an encryption transmission module, a breakpoint resumption module, a storage management module and a feedback module, The key management module is used to generate and verify the identity information of the target device; The certificate management module is used to trace and verify the credibility of the upgrade instruction after the identity authentication of the target device passes; The load perception module is used to evaluate the task priority and resource occupancy status of the current device after the upgrade instruction is verified; The encryption transmission module is used to perform block encryption processing on the upgrade package to generate encrypted data packets after the evaluation of the load perception module passes; the sender generates a digest value based on the verification key and the data block content, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; by performing hash verification on the two digest values, it is verified that the encrypted data packet has not been tampered with or damaged during the transmission process; The breakpoint resumption module is used to record the transmission progress when the network is interrupted and support resumption; The storage management module is used to manage the firmware storage area and support the writing and rollback of the upgrade package; The feedback module is used to provide prompt information when the upgrade fails or the original firmware recovery fails.

[0014] As a preferred technical solution of the present invention, the key management module obtains the root key from the hardware encryption machine, and generates the manufacturer key and the terminal key according to the manufacturer ID and the terminal ID of the target device to verify the identity information of the target device.

[0015] As a preferred technical solution of the present invention, the breakpoint resumption module detects the network status through the heartbeat packet mechanism, and records the identification number of the last successfully transmitted data block during the network interruption, so as to continue transmitting the unfinished data block after the network resumes.

[0016] The beneficial effects of the present invention include: The present invention solves the problems of identity forgery and upgrade instruction hijacking through the key management module and the certificate management module, authenticates and identifies the intelligent thermostat safely and reliably, and makes up for the lack of security verification and weak identity authentication authority in the previous upgrade process; the load perception module monitors the load status of the intelligent thermostat in real time, gives priority to ensuring the real-time performance and reliability of the temperature control task, and avoids the system security imbalance caused by the upgrade task overoccupying resources, so as to be able to take into account the temperature control function of the intelligent thermostat used in places with high security sensitivity such as hospitals and laboratories; in addition, the present invention avoids the target upgrade package of the intelligent thermostat being tampered with and eavesdropped during transmission through the encrypted transmission module, realizes the efficient and secure transmission of the target upgrade package, and actively responds to the network interruption problem during the upgrade process through the breakpoint resumption module, ensuring accurate positioning and resumption after the network interruption and avoiding repeated transmission.

[0017] After multiple upgrade attempts fail, the system can automatically attempt to restore the original firmware data and make an upgrade feedback through the feedback module, further enhancing the emergency handling ability of upgrade failure. Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic flowchart of a remote upgrade method for an intelligent thermostat provided by an embodiment of the present invention.

[0020] Figure 2 It is a schematic operation flowchart of a remote upgrade method for an intelligent thermostat provided by an embodiment of the present invention.

[0021] Figure 3Schematic flow diagram of the key management module, certificate management module, and load awareness module provided by the embodiments of the present invention.

[0022] Figure 4 Schematic structure diagram of a remote upgrade system for an intelligent thermostat provided by the embodiments of the present invention. Detailed implementation manners

[0023] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts also belong to the scope of protection of the present application.

[0024] The following further describes the optimal embodiments of the present invention with reference to the accompanying drawings; Embodiment 1 Please refer to Figures 1-3 , this embodiment provides a remote upgrade method for an intelligent thermostat, including: After the target device receives an upgrade request, it first calls the key management module to verify the identity information of the target device to ensure that only legitimate devices can participate in the upgrade operation and prevent illegal devices from accessing, including: The key management module obtains the root key from the hardware encryption machine, generates the manufacturer key according to the root key and the discrete algorithm of the manufacturer ID of the target device, and then generates the terminal key according to the manufacturer key and the discrete algorithm of the terminal ID of the target device; compares the generated terminal key with the terminal key stored in the target device; if the comparison result of the generated terminal key and the terminal key stored in the target device is consistent, the identity verification of the target device passes; otherwise, the identity verification fails and the upgrade process is terminated; After the identity verification passes, call the certificate management module to trace and verify the credibility of the upgrade instruction to prevent the upgrade instruction from being hijacked or tampered with, including: It is necessary to trace and obtain the manufacturer CA key through the terminal CA key and the terminal ID, and then compare the obtained manufacturer CA key with the original manufacturer CA key of the terminal device. If they are consistent, continue to trace and obtain the root CA key through the manufacturer CA key and the manufacturer ID. If they are inconsistent, the upgrade process is terminated; if the obtained root CA key is consistent with the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction verification passes; otherwise, the upgrade process is terminated; This step ensures the security of the upgrade instruction through a multi-level certificate verification mechanism that traces step by step, thereby avoiding the risk of man-in-the-middle attacks or instruction hijacking; The certificate management module obtains the root CA key from the hardware encryption machine and issues the manufacturer CA key according to the manufacturer ID of the target device. The manufacturer CA key issues the terminal CA key according to the terminal ID of the target device; Each intelligent temperature controller terminal device is attached with a unique terminal CA key. Since the signing order of the CA certificate is from the root CA key to the manufacturer CA key, and then from the manufacturer CA key to the terminal CA key, and the root CA key and the manufacturer CA key of the terminal device are inaccessible, while the terminal CA key of the terminal device is accessible. It is necessary to trace and obtain the manufacturer CA key through the terminal CA key and the terminal ID, and then compare the obtained manufacturer CA key with the original manufacturer CA key of the terminal device. If they are the same, continue to trace and obtain the root CA key through the manufacturer CA key and the manufacturer ID. If they are different, terminate the upgrade process; if the obtained root CA key is the same as the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction is verified and passed; otherwise, terminate the upgrade process; After the upgrade instruction is verified and passed, the load perception module evaluates the task priority and resource occupancy status of the current device, including: The load perception module sets three priorities: high, medium, and low, corresponding to the temperature control function, upgrade task, and other auxiliary functions respectively; by collecting the CPU usage rate and the resource occupancy rate of the task process in real time, and combining with the resource requirements of the temperature control function task, evaluate the resource occupancy rate of the current device; if the priority of the temperature control function task of the current target device is higher than the priority of the upgrade task and the resource occupancy rate is lower than the preset threshold, allow the execution of the upgrade operation; otherwise, enter the waiting queue until the conditions of the preset threshold are met; thus avoiding the over - occupancy of resources by the upgrade task resulting in the imbalance of system security, ensuring that the upgrade task does not interfere with the operation of the device's temperature control function, and improving the stability of the system; After determining that the upgrade operation can be executed, use the encryption transmission module to encrypt the target upgrade package, including: The encryption transmission module includes a block decryption unit and a data block encryption unit; Calculate the overall digest value of the target upgrade package through the hash algorithm; The encryption transmission module first divides the target upgrade package into multiple data blocks and assigns a unique identification number to each data block; The data block encryption unit negotiates based on the ECDH protocol and generates a data block public key and a data block private key through a predefined elliptic curve parameter exchange mechanism. The block decryption unit negotiates based on the ECDH protocol and generates a block decryption unit public key and a block decryption unit private key through a predefined elliptic curve parameter exchange mechanism. The data block encryption unit sends the data block public key to the block decryption unit, and the block decryption unit sends the block decryption unit public key to the data block encryption unit. The data block encryption unit multiplies the obtained block decryption unit public key by the data block private key to obtain a shared key. The block decryption unit multiplies the obtained data block public key by the block decryption unit private key to obtain the same shared key. The shared key is used for symmetric encryption communication to ensure the security of information transmission. The shared key derives an encryption subkey and a verification key through the HKDF-SHA256 algorithm combined with a random salt value. The encryption subkey is used to encrypt the data block using SM4-CTR and generate an encrypted data packet. The verification key is used to perform a hash verification on the received encrypted data packet. The sender generates a fixed-length digest value based on the verification key and the data block content through a hash algorithm. The digest value can uniquely represent the integrity characteristics of the data block. The sender sends the digest value and the complete digest value of the data block to the receiver in an attached or independently transmitted manner to provide a verification basis for the receiver. After obtaining the encrypted data packet and the attached digest value, the receiver first negotiates based on the ECDH protocol and obtains the data block public key and the block decryption unit public key that match the sender through a predefined elliptic curve parameter exchange mechanism, and synchronously generates a shared key. Combining the random salt value parameter embedded in the transmission process, the shared key is decomposed into an encryption subkey and a verification key, where the encryption subkey corresponds to the reversible transformation parameter of the symmetric encryption operation. The receiver decrypts the encrypted data packet based on the encryption subkey to obtain the data block content. Then the receiver re-executes the hash algorithm based on the decomposed verification key and the data block content to generate a new digest value. This process strictly replicates the hash calculation logic of the sender to ensure the consistency of the algorithm input. Subsequently, the receiver performs a bit-by-bit comparison of the two digest values: the original digest value is attached or independently transmitted by the sender, and the newly generated digest value is calculated based on the decrypted plaintext data block. If the two digest values match exactly, it indicates that the data block has not been tampered with or damaged during transmission. The receiver stores the decrypted plaintext data block in a temporary storage area for subsequent processing. If there are differences, it triggers an integrity check failure mechanism to notify the sender to re-transmit the data block. During the verification process, the avalanche effect and collision resistance characteristics of the hash algorithm ensure that minor data changes will result in significant changes in the digest value, thus effectively defending against tampering attacks. If a network interruption occurs, the breakpoint resumption module records the identification numbers of the data blocks that have been successfully transmitted, and continues to transmit the data blocks that have not been successfully transmitted after the network is restored, including: The breakpoint resumption module divides two independent partitions in the storage area of the target device. Partition A is the main partition, which is used to store the currently running firmware and prohibits write operations; Partition B is the backup partition, which is used to write the new firmware, clear all data and perform verification before the upgrade; at the same time, a Flash transmission area is reserved on the server side, and a Flash reception area is reserved on the target device side to record the transmission progress; The network status is detected through the heartbeat packet mechanism. A network determination sending unit is reserved on the target device side, and a network determination receiving unit is preset on the server side. The network determination sending unit sends a heartbeat packet to the network determination receiving unit once every fixed time. The heartbeat packet contains the current transmission progress. After receiving the heartbeat packet, the network determination receiving unit feeds back the transmission progress in real time; if the heartbeat packet does not receive a response three times in a row, it is determined that the network is interrupted; during the network interruption, the identification number of the last successfully transmitted data block is recorded; after the network is restored, the unfinished data blocks are continued to be transmitted according to the recorded data block identification numbers, thus avoiding repeated transmission of the completed data blocks; After all data blocks are transmitted, the storage management module splices and generates a complete upgrade package in the order of the data block identification numbers, and then accumulates the digest values carried by each data block by using the chained aggregation method to obtain the overall digest value of the complete upgrade package. The system compares the calculated overall digest value with the digest value of the pre-stored target upgrade package bit by bit. Only when the generated overall digest value completely matches the digest value of the target upgrade package and the data block sequence is complete, can the generated complete upgrade package be written into Partition B and replace the currently running firmware after the writing is complete; if the generated overall digest value does not match the digest value of the target upgrade package, the intermediate data in the temporary storage area is cleared and the upgrade is attempted again; If the upgrade fails after multiple attempts, the feedback module is called to attempt to restore the original firmware data of the backup; the original firmware data is replaced into Partition A and its digest value is calculated; if the digest value of the original firmware replaced into Partition A is consistent with the digest value of the backup data, a prompt message indicating that the upgrade failed but the original firmware was successfully restored is fed back; if the digest value of the original firmware replaced into Partition A is inconsistent with the digest value of the backup data, a prompt message indicating that the upgrade failed and the original firmware restoration failed is fed back; thus providing an effective emergency handling solution for the upgrade failure; In addition, a physical DIP switch is preset. The physical DIP switch is a manually operated hardware control element, which is used to provide a localized upgrade and remediation mechanism for the intelligent thermostat; the DIP value is recorded, and the DIP value records the storage location of the standby firmware; if it is detected that the physical DIP switch on the target device is triggered, the current DIP value is read, and the standby firmware is read from the preset storage location according to the DIP value, and the standby firmware is used as a new target upgrade package to re - execute the upgrade process, further enhancing the flexibility and fault tolerance of the system.

[0025] Embodiment 2 Please refer to Figures 2-4 , this embodiment provides a remote upgrade system for an intelligent thermostat, which executes the remote upgrade method of the intelligent thermostat. The system includes a key management module, a certificate management module, a load awareness module, an encrypted transmission module, a breakpoint resume module, a storage management module and a feedback module. The key management module is used to generate and verify the identity information of the target device. The certificate management module is used to trace and verify the credibility of the upgrade instruction after the identity authentication of the target device passes. The load awareness module is used to evaluate the task priority and resource occupancy status of the current device after the upgrade instruction is verified. The encrypted transmission module, after the evaluation of the load awareness module passes, the sender performs block encryption processing on the upgrade package, and the receiver first performs a hash check on the encrypted data packet, and then decrypts the encrypted data packet after the check passes. The breakpoint resume module is used to record the transmission progress when the network is interrupted and support resume. The storage management module is used to manage the firmware storage area and support the writing and rollback of the upgrade package. The feedback module is used to provide prompt information when the upgrade fails or the original firmware recovery fails.

[0026] Embodiment 3 Please refer to Figures 1-4 , in order to better enable relevant personnel in the technical field to fully understand and implement the present invention, the following further supplements and explains the specific implementation principle of the present invention in combination with a specific application scenario: In a smart home environment, the user sends an upgrade request to the smart thermostat through a mobile phone APP. After the target device receives the request, it first calls the key management module, which obtains the root key from the hardware encryption machine, and generates a manufacturer key based on the root key and the manufacturer ID discrete algorithm of the target device, and then generates a terminal key based on the manufacturer key and the terminal ID discrete algorithm of the target device; the manufacturer key and the terminal key are completed based on the discrete algorithm; then, if the generated terminal key is consistent with the terminal key stored in the target device, the identity authentication of the target device is passed; otherwise, the identity authentication fails and the upgrade process is terminated; this step effectively prevents the possibility of illegal device access through the participation of the hardware encryption machine; After the identity authentication is passed, the certificate management module is called. The certificate management module obtains the root CA key from the hardware encryption machine and issues the manufacturer CA key according to the manufacturer ID of the target device. The manufacturer CA key issues the terminal CA key according to the terminal ID of the target device. Each intelligent thermostat terminal device is attached with a unique terminal CA key. Since the issuance order of the CA certificate is from the root CA key to the manufacturer CA key, and then from the manufacturer CA key to the terminal CA key, and the root CA key and the manufacturer CA key of the terminal device are inaccessible, and the terminal CA key of the terminal device is accessible, it is necessary to trace the manufacturer CA key through the terminal CA key and the terminal ID, and then compare the obtained manufacturer CA key with the original manufacturer CA key of the terminal device. If they are consistent, continue to trace the root CA key through the manufacturer CA key and the manufacturer ID. If they are inconsistent, the upgrade process is terminated; if the obtained root CA key is consistent with the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction verification is passed; otherwise, the upgrade process is terminated; This step ensures the security of the upgrade instruction by tracing back the multi-layer certificate verification mechanism step by step, thereby avoiding the risk of man-in-the-middle attack or instruction hijacking; After the upgrade instruction is verified, the load sensing module evaluates the task priority and resource occupancy status of the current device. The resource occupancy of the current device is evaluated by real-time collection of CPU usage and task process resource occupancy, combined with the resource requirements of the temperature control function task; if the temperature control function task priority of the current target device is higher than the upgrade task priority, and the resource occupancy rate is lower than the preset threshold, the upgrade operation is allowed; otherwise, it enters the waiting queue until the preset threshold condition is met; thereby avoiding the imbalance of system security caused by excessive resource occupation of the upgrade task, ensuring that the upgrade task does not interfere with the operation of the temperature control function of the device, and improving the stability of the system; After confirming that the upgrade operation can be executed, the encrypted transmission module first divides the target upgrade package into multiple data blocks and assigns a unique identification number to each data block; the data block encryption unit negotiates and generates a data block public key and a data block private key based on the ECDH protocol, and the block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol. The data block encryption unit sends the data block public key to the block decryption unit, and the block decryption unit sends the block decryption unit public key to the data block encryption unit. The data block encryption unit multiplies the obtained block decryption unit public key by the data block private key to obtain a shared key, and the block decryption unit multiplies the obtained data block public key by the block decryption unit private key to obtain the same shared key; the shared key is used for symmetric encryption communication to ensure the security of information transmission; The shared key derives an encryption sub-key and a verification key through the HKDF-SHA256 algorithm in combination with a random salt value; the encryption sub-key is used to encrypt the data block by SM4-CTR and generate an encrypted data packet, The verification key is used to perform a hash verification on the received encrypted data packet; The sender generates a fixed-length digest value based on the verification key and the data block content through a hash algorithm. The digest value can uniquely represent the integrity characteristics of the data block and provides a verification basis for the receiver by being attached to the encrypted data packet or transmitted independently; After obtaining the encrypted data packet and the attached digest value, the receiver first negotiates based on the ECDH protocol and obtains the data block public key and the block decryption unit public key that match the sender through a predefined elliptic curve parameter exchange mechanism, and synchronously generates a shared key; combining the random salt value parameter embedded in the transmission process, the shared key is decomposed into an encryption sub-key and a verification key, where the encryption sub-key corresponds to the reversible transformation parameter of the symmetric encryption operation. The receiver decrypts the encrypted data packet based on the encryption sub-key to obtain the data block content; then the receiver re-executes the hash algorithm based on the decomposed verification key and the data block content to generate a new digest value. This process strictly replicates the hash calculation logic of the sender to ensure the consistency of the algorithm input; Subsequently, the receiver compares the two digest values bit by bit: the original digest value is attached or transmitted independently by the sender, and the newly generated digest value is calculated based on the decrypted plaintext data block; if the two digest values match exactly, it indicates that the data block has not been tampered with or damaged during transmission, and the receiver stores the decrypted plaintext data block in the temporary storage area for subsequent processing; if there are differences, the integrity verification failure mechanism is triggered to notify the sender to re-transmit the data block; during the verification process, the avalanche effect and collision resistance characteristics of the hash algorithm ensure that minor data changes will cause significant changes in the digest value, thus effectively defending against tampering attacks.

[0027] If a network interruption occurs, the breakpoint resumption module records the identification numbers of the data blocks that have been successfully transmitted, and continues to transmit the incomplete data blocks after the network is restored, including: The breakpoint resumption module divides two independent partitions in the storage area of the target device. Partition A is the main partition, which is used to store the currently running firmware and prohibits write operations; Partition B is the backup partition, which is used to write the new firmware, clear all data before upgrading and perform verification; at the same time, a Flash transmission area is reserved on the server side, and a Flash reception area is reserved on the target device side to record the transmission progress; The network status is detected through the heartbeat packet mechanism. A network determination sending unit is reserved on the target device side, and a network determination receiving unit is preset on the server side. The network determination sending unit sends a heartbeat packet to the network determination receiving unit once every fixed time. The heartbeat packet contains the current transmission progress. After receiving the heartbeat packet, the network determination receiving unit feeds back the transmission progress in real time; if the heartbeat packet fails to receive a response three times in a row, it is determined that the network is interrupted; during the network interruption, the identification number of the last successfully transmitted data block is recorded; after the network is restored, the incomplete data blocks are continued to be transmitted according to the recorded data block identification numbers, thereby avoiding repeated transmission of the completed data blocks; After all data blocks are transmitted, the storage management module splices and generates a complete upgrade package in the order of the data block identification numbers. The currently running firmware then accumulates the digest values carried by each data block using the chained aggregation method to obtain the overall digest value of the complete upgrade package. The system compares the calculated overall digest value with the digest value of the pre-stored target upgrade package bit by bit. Only when the generated overall digest value completely matches the digest value of the target upgrade package and the data block sequence is complete, can the generated complete upgrade package be written into Partition B and replace the currently running firmware after the writing is complete; if the generated overall digest value does not match the digest value of the target upgrade package, the intermediate data in the temporary storage area is cleared and the upgrade is attempted again; If the upgrade fails after multiple attempts, the feedback module is called to attempt to restore the original firmware data from the backup; the original firmware data is replaced into Partition A and its digest value is calculated; if the digest value of the original firmware replaced into Partition A is the same as the backup data, a prompt message indicating that the upgrade failed but the original firmware was successfully restored is fed back; if the digest value of the original firmware replaced into Partition A is different from the digest value of the backup data, a prompt message indicating that the upgrade failed and the original firmware restoration failed is fed back; thereby providing an effective emergency handling solution for upgrade failures; In addition, a physical DIP switch is preset. The physical DIP switch is a manually operated hardware control component used to provide a localized upgrade and remediation mechanism for the intelligent thermostat; the DIP value is recorded, and the DIP value records the storage location of the backup firmware; if it is detected that the physical DIP switch on the target device is triggered, the current DIP value is read, and the backup firmware is read from the preset storage location according to the DIP value, and the backup firmware is used as the new target upgrade package to re-execute the upgrade process; further enhancing the flexibility and fault tolerance of the system.

[0028] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A remote upgrade method for an intelligent thermostat, characterized in that: Includes steps: Receive upgrade instructions and verify the identity information of the target device; If the identity information verification is successful, the credibility of the upgrade instruction is traced and verified; After the credibility verification is passed, the task priority and resource occupancy status of the current target device are evaluated; If the temperature control task priority of the current target device is higher than the upgrade task priority and the resource usage is lower than the preset threshold, the upgrade operation is allowed; Otherwise, the upgrade will be suspended until the conditions are met; Dividing the target upgrade package into multiple data blocks and assigning a unique identification number to each data block; Encrypt the data block and generate an encrypted data packet; After receiving the encrypted data packet, the target device compares the integrity of the data block by verifying the key; If the data block passes the verification, it is decrypted and the data block is stored in a temporary storage area; If a network interruption occurs, the identification number of the data block that has been successfully transmitted is recorded; After the network is restored, the data blocks that have not been successfully transmitted are continued to be transmitted according to the recorded data block identification numbers; After all data blocks are transmitted, they are assembled in the order of identification numbers to generate a complete upgrade package; Calculate the overall summary value of the spliced ​​complete upgrade package and compare it with the summary value of the target upgrade package; if the comparison results are consistent, write the complete upgrade package to the storage area of ​​the target device and replace the currently running firmware; if the comparison results are inconsistent, clear the data blocks in the temporary storage area and try to upgrade again; If multiple upgrade attempts fail, try to restore the backed-up original firmware data; Writing the backup data of the original firmware data into the main storage area and calculating its summary value; If the obtained digest value is consistent with the digest value of the backup data, a prompt message is fed back that the upgrade failed but the original firmware was successfully restored; if the obtained digest value is inconsistent with the digest value of the backup data, a prompt message is fed back that the upgrade failed and the original firmware failed to be restored.

2. The remote upgrade method of the intelligent thermostat according to claim 1, characterized in that: The verification target device identity information includes: Get the root key from the hardware encryption machine; Generate a manufacturer key based on the root key and the manufacturer ID of the target device using a discrete algorithm; Then generate the terminal key based on the manufacturer key and the terminal ID of the target device through a discrete algorithm; The generated terminal key is compared with the terminal key stored in the target device; if the comparison results are consistent, the identity authentication is passed; otherwise, the upgrade process is terminated.

3. The remote upgrade method of the intelligent thermostat according to claim 2, characterized in that: The tracing and verifying the credibility of the upgrade instruction includes: Get the root CA key from the hardware encryption machine; Issue the manufacturer CA key based on the root CA key and the manufacturer ID of the target device; Then issue the terminal CA key based on the manufacturer's CA key and the terminal ID of the target device; Verify the credibility of the manufacturer's CA key through terminal CA key tracing; The credibility of the root CA key is verified through the manufacturer's CA key traceability; if the root CA key is a trusted certificate, the command verification passes; otherwise, the upgrade process is terminated.

4. The remote upgrade method of the intelligent thermostat according to claim 3, characterized in that: The evaluating the task priority and resource occupancy status of the current target device includes: Set three priorities: high, medium, and low, corresponding to temperature control function, upgrade tasks, and other auxiliary functions respectively; Collect CPU usage and resource occupancy of task processes in real time; evaluate resource occupancy of current device in combination with resource requirements of temperature control task; if the temperature control task priority of current target device is higher than upgrade task priority and resource occupancy is lower than preset threshold, upgrade operation is allowed; otherwise, enter waiting queue.

5. The remote upgrade method of the intelligent thermostat according to claim 4, characterized in that: The encryption process of the data block includes: The data block encryption unit generates a data block public key and a data block private key through negotiation based on the ECDH protocol; The block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol; Generate a shared key based on a data block public key, a data block private key, a block decryption unit public key, and a block decryption unit private key; The shared key is combined with a random salt value through the HKDF-SHA256 algorithm to derive an encryption subkey and a verification key; The cipher is used by the sender to perform SM4-CTR encryption on the data block to generate an encrypted data packet; The verification key is used by the receiver to perform SHA256 hash verification on the received encrypted data packet; The sender generates a summary value based on the verification key and the data block content, and sends the encrypted data packet and the summary value to the receiver. After receiving the encrypted data packet and the summary value, the receiver decrypts the encrypted data packet based on the key agreement mechanism and generates a new summary value. By performing a hash check on the two summary values, it is verified that the encrypted data packet has not been tampered with or destroyed during transmission.

6. The remote upgrade method of the intelligent thermostat according to claim 5, characterized in that: The record of the data block identification number that has been successfully transmitted currently includes: Divide the storage area of ​​the target device into partition A and partition B, wherein partition A is used to store the currently running firmware and partition B is used to store the new firmware; After the target upgrade package passes the integrity verification, the target upgrade package is written into the B partition as the new firmware. After the target upgrade package is completely written, it is replaced into the A partition as the current running firmware. A Flash sending area and a Flash receiving area are reserved on the server side and the target device side respectively to record the transmission progress; The network status is detected through the heartbeat packet mechanism; if the heartbeat packet does not receive a response for three consecutive times, the network is determined to be interrupted; during the network interruption, the data block identification number of the last successful transmission is recorded.

7. The remote upgrade method of the intelligent thermostat according to claim 6, characterized in that: The attempt to restore the backed-up original firmware data includes: Backing up the currently running firmware to generate backup firmware; A physical dip switch is preset, wherein the physical dip switch is a manually operated hardware control element used to record a dip value; the dip value is used to record the storage location of the backup firmware; Detect whether the physical DIP switch on the target device is triggered; if the physical DIP switch is triggered, read the DIP value; The backup firmware is read from a preset storage location according to the dial code value; and the upgrade process is re-executed using the backup firmware as a new target upgrade package.

8. A remote upgrade system for an intelligent thermostat, characterized in that: The remote upgrade method of the intelligent thermostat according to any one of claims 1 to 7 is executed, wherein the system comprises a key management module, a certificate management module, a load sensing module, an encryption transmission module, a breakpoint resume module, a storage management module and a feedback module. The key management module is used to generate and verify the identity information of the target device; The certificate management module is used to retroactively verify the credibility of the upgrade instruction after the identity authentication of the target device is passed; The load sensing module is used to evaluate the task priority and resource occupancy status of the current device after the upgrade instruction is verified; The encryption transmission module is used to perform block encryption processing on the upgrade package to generate an encrypted data packet after the evaluation of the load sensing module is passed; the sender generates a summary value based on the verification key and the data block content, and sends the encrypted data packet and the summary value to the receiver. After receiving the encrypted data packet and the summary value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new summary value; by performing a hash check on the two summary values, it is verified that the encrypted data packet has not been tampered with or destroyed during the transmission process; The breakpoint resume module is used to record the transmission progress when the network is interrupted and support resume transmission; The storage management module is used to manage the firmware storage area and support the writing and rolling back of the upgrade package; The feedback module is used to provide prompt information when the upgrade fails or the original firmware fails to be restored.

9. The remote upgrade system of the intelligent thermostat according to claim 8, characterized in that: The key management module obtains the root key from the hardware encryption machine, and generates a manufacturer key and a terminal key according to the manufacturer ID and the terminal ID of the target device to verify the identity information of the target device.

10. The remote upgrade system of the intelligent thermostat according to claim 9, characterized in that: The breakpoint resume module detects the network status through the heartbeat packet mechanism and records the data block identification number of the last successful transmission during the network interruption, so as to continue to transmit the unfinished data block after the network is restored.

Citation Information

Patent Citations

  • Method for generating and distributing movable IP Key

    CN101075870A

  • Interaction information system based on industrial digitization

    CN118282531A

  • Secure Information Exchange In Federated Authentication

    US20220078007A1