Remote upgrade method and system for an intelligent thermostat
Through key management, certificate management, load awareness and encryption transmission modules, combined with breakpoint continuous transmission technology, the security risks and network interruption problems of remote upgrade of intelligent thermostats are solved, and an efficient and secure remote upgrade solution is realized, suitable for security-sensitive scenarios.
Patent Information
- Application Number
- CN202510534185.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The remote upgrade solution of existing smart thermostats poses security risks, such as plain text transmission firmware packets are susceptible to man-in-the-middle attacks, weak identity authentication and network interruption, resulting in loss of transmission progress, and failing to take into account the needs of low power consumption and high real-time, affecting applications in security-sensitive scenarios.
The key management module and certificate management module are used for authentication, the load-aware module monitors the load status of the equipment, the encrypted transmission module ensures data security, the breakpoint transmission module handles network interrupts, and ensures data integrity and security through the ECDH protocol and SM4-CTR encryption algorithm.
It improves the security and reliability of remote upgrade of intelligent thermostats, ensures the real-time and stability of temperature control functions, is suitable for safe and sensitive scenarios, and has network interrupt recovery capabilities and emergency response mechanisms.
Smart Images

Figure CN120074955B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of device function management, and particularly to a remote upgrade method and system for an intelligent thermostat. Background Art
[0002] In the fields of smart home and industrial control, as a core device, the function iteration of an intelligent thermostat relies on remote upgrade technology (OTA) to implement firmware update and vulnerability repair. However, there are certain security risks in existing remote upgrade solutions: First, the upgrade process lacks a perfect security verification mechanism. Traditional methods mostly use plaintext transmission of firmware packages, which are easily tampered with by man-in-the-middle attacks, possibly leading to device out-of-control or data leakage. Second, identity authentication and permission control are relatively weak. Illegal terminals may disguise themselves as upgrade servers to issue instructions and hijack the communication link, infringing on user privacy. Finally, abnormal interruption will cause the loss of transmission progress, resulting in the incomplete transmission of the upgrade package or the repeated execution of tasks.
[0003] Although current technologies can achieve basic OTA functions, they fail to design an optimized solution for the characteristics of low power consumption and high real-time performance of intelligent thermostats, making it difficult to balance upgrade efficiency and security. In addition, existing solutions lack dynamic monitoring of the device operation status, and the upgrade process may interfere with the core temperature control function.
[0004] These problems have restricted the application of intelligent thermostats in security-sensitive scenarios such as hospitals and laboratories to a certain extent. Therefore, there is an urgent need for an efficient and secure remote upgrade method and system for intelligent thermostats to meet the actual needs. Summary of the Invention
[0005] To solve the above problems existing in the prior art, the present invention provides a remote upgrade method and system for an intelligent thermostat, which solves the problems of identity forgery and upgrade instruction hijacking through a key management module and a certificate management module, dynamically monitors the device load status through a load perception module to ensure a safe and reliable upgrade environment, and also effectively avoids the tampering and eavesdropping of the target upgrade package during transmission and actively responds to network interruption problems during the upgrade process through an encryption transmission module and a breakpoint resume module, improving the security and reliability of the remote upgrade of the intelligent thermostat.
[0006] In a first aspect, the present invention provides a remote upgrade method for an intelligent thermostat, including the steps of:
[0007] Receiving an upgrade instruction and verifying the identity information of the target device;
[0008] If the identity information verification is passed, trace and verify the credibility of the upgrade instruction;
[0009] After the credibility verification is passed, evaluate the task priority and resource occupancy status of the current target device;
[0010] If the task priority of the temperature control function of the current target device is higher than that of the upgrade task and the resource occupancy rate is lower than the preset threshold, the upgrade operation is allowed; otherwise, the upgrade is suspended until the conditions are met;
[0011] Divide the target upgrade package into multiple data blocks and assign a unique identification number to each data block;
[0012] Perform encryption processing on the data blocks and generate encrypted data packets;
[0013] After the target device receives the encrypted data packet, it compares the integrity of the data blocks through the verification key; if the data blocks pass the verification, they are decrypted and stored in the temporary storage area;
[0014] If a network interruption occurs, record the identification numbers of the data blocks that have been successfully transmitted; after the network resumes, continue to transmit the data blocks that have not been successfully transmitted according to the recorded identification numbers of the data blocks;
[0015] When all data blocks are transmitted, splice them in the order of the identification numbers to generate a complete upgrade package; calculate the overall digest value of the spliced complete upgrade package and compare it with the digest value of the target upgrade package; if the comparison result is consistent, write the complete upgrade package into the storage area of the target device and replace the currently running firmware; if the comparison result is inconsistent, clear the data blocks in the temporary storage area and try to upgrade again;
[0016] If multiple upgrade attempts fail, try to restore the original firmware data from the backup; write the backup data of the original firmware data into the main storage area and calculate its digest value; if the obtained digest value is consistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed but the original firmware was successfully restored; if the obtained hash value is inconsistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed and the original firmware restoration failed.
[0017] As a preferred technical solution of the present invention, the verification of the identity information of the target device includes:
[0018] Obtain the root key from the hardware encryption machine;
[0019] Generate the manufacturer key according to the root key and the discrete algorithm of the manufacturer ID of the target device;
[0020] Then generate the terminal key according to the manufacturer key and the discrete algorithm of the terminal ID of the target device;
[0021] Compare the generated terminal key with the terminal key stored in the target device; if the comparison result is consistent, the identity verification is passed; otherwise, terminate the upgrade process.
[0022] As a preferred technical solution of the present invention, the tracing and verification of the credibility of the upgrade instruction includes:
[0023] Obtain the root CA key from the hardware encryption machine;
[0024] Sign the manufacturer CA key according to the root CA key and the manufacturer ID of the target device;
[0025] Then sign the terminal CA key according to the manufacturer CA key and the terminal ID of the target device;
[0026] Trace and verify the credibility of the manufacturer CA key through the terminal CA key;
[0027] Trace and verify the credibility of the root CA key through the manufacturer CA key; if the root CA key is a trusted certificate, the instruction verification passes; otherwise, terminate the upgrade process.
[0028] As a preferred technical solution of the present invention, the evaluation of the task priority and resource occupancy status of the current target device includes:
[0029] Set three priorities: high, medium, and low, corresponding to the temperature control function, upgrade task, and other auxiliary functions respectively;
[0030] Real-time collect the CPU usage rate and the resource occupancy rate of the task process; combine the resource requirements of the temperature control function task to evaluate the resource occupancy rate of the current device; if the task priority of the temperature control function of the current target device is higher than the upgrade task priority and the resource occupancy rate is lower than the preset threshold, allow the execution of the upgrade operation; otherwise, enter the waiting queue.
[0031] As a preferred technical solution of the present invention, the encryption process for the data block includes:
[0032] The data block encryption unit negotiates and generates a data block public key and a data block private key based on the ECDH protocol;
[0033] The block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol;
[0034] Generate a shared key according to the data block public key, data block private key, block decryption unit public key, and block decryption unit private key;
[0035] The shared key derives an encryption sub-key and a verification key through the HKDF-SHA256 algorithm in combination with a random salt value;
[0036] The encryption sub-key is used by the sender to encrypt the data block using SM4-CTR to generate an encrypted data packet;
[0037] The verification key is used by the receiver to perform a SHA256 hash verification on the received encrypted data packet;
[0038] The sender generates a digest value based on the verification key and the content of the data block, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; by performing a hash check on the two digest values, it is verified that the encrypted data packet has not been tampered with or damaged during transmission.
[0039] As a preferred technical solution of the present invention, the recording of the identification numbers of the data blocks that have been successfully transmitted currently, and the transmission of the data blocks that have not been successfully transmitted after the network is reconnected, includes:
[0040] The storage area of the target device is divided into partition A and partition B. Partition A is used to store the currently running firmware, and partition B is used to store the new firmware;
[0041] After the target upgrade package passes the integrity verification, the target upgrade package is written into partition B as the new firmware. After the target upgrade package is completely written, it is replaced into partition A as the currently running firmware;
[0042] Flash sending areas and Flash receiving areas are reserved at the server side and the target device side respectively for recording the transmission progress;
[0043] The network status is detected through the heartbeat packet mechanism; if no response is received for the heartbeat packet three times in a row, it is determined that the network is interrupted; the identification number of the last successfully transmitted data block is recorded during the network interruption.
[0044] As a preferred technical solution of the present invention, the attempt to restore the original firmware data of the backup includes:
[0045] Back up according to the currently running firmware and generate a backup firmware;
[0046] A physical DIP switch is preset. The physical DIP switch is a manually operated hardware control element for recording the DIP value; the DIP value is used to record the storage location of the backup firmware;
[0047] Detect whether the physical DIP switch on the target device is triggered; if the physical DIP switch is triggered, read the DIP value;
[0048] Read the backup firmware from the preset storage location according to the DIP value; use the backup firmware as the new target upgrade package to re-execute the upgrade process.
[0049] In a second aspect, the present invention also provides a remote upgrade system for an intelligent thermostat, which executes the remote upgrade method of the intelligent thermostat, including:
[0050] The system includes a key management module, a certificate management module, a load perception module, an encrypted transmission module, a breakpoint resumption module, a storage management module, and a feedback module,
[0051] The key management module is used to generate and verify the identity information of the target device;
[0052] The certificate management module is used to trace and verify the credibility of the upgrade instruction after the authentication of the target device is passed;
[0053] The load awareness module is used to evaluate the task priority and resource occupancy status of the current device after the upgrade instruction is verified;
[0054] The encrypted transmission module is used to perform block encryption processing on the upgrade package to generate encrypted data packets after the evaluation of the load awareness module is passed; The sender generates a digest value based on the verification key and the data block content, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; By performing hash verification on the two digest values, it is verified that the encrypted data packet has not been tampered with or damaged during the transmission process;
[0055] The breakpoint resumption module is used to record the transmission progress when the network is interrupted and support resumption of transmission;
[0056] The storage management module is used to manage the firmware storage area and support the writing and rollback of the upgrade package;
[0057] The feedback module is used to provide prompt information when the upgrade fails or the original firmware recovery fails.
[0058] As a preferred technical solution of the present invention, the key management module obtains the root key from the hardware encryption machine, and generates the manufacturer key and the terminal key according to the manufacturer ID and the terminal ID of the target device to verify the identity information of the target device.
[0059] As a preferred technical solution of the present invention, the breakpoint resumption module detects the network status through the heartbeat packet mechanism, and records the identification number of the last successfully transmitted data block during the network interruption, so as to continue transmitting the unfinished data block after the network is restored.
[0060] The beneficial effects of the present invention include:
[0061] The present invention solves the problems of identity forgery and upgrade instruction hijacking through a key management module and a certificate management module, authenticates and identifies the intelligent thermostat safely and reliably, and makes up for the lack of security verification and weak identity authentication authority in the previous upgrade process; through a load perception module, it monitors the load status of the intelligent thermostat in real time, gives priority to ensuring the real-time performance and reliability of the temperature control task, and avoids the imbalance of system security caused by the excessive occupation of resources by the upgrade task, so as to be able to take into account the temperature control function of the intelligent thermostat used in places with high security sensitivity such as hospitals and laboratories; in addition, the present invention avoids the tampering and eavesdropping of the target upgrade package of the intelligent thermostat during transmission through an encrypted transmission module, realizes the efficient and secure transmission of the target upgrade package, and actively responds to the network interruption problem that occurs during the upgrade process through a breakpoint resumption module, ensuring accurate positioning and resumption after the network interruption and avoiding repeated transmission.
[0062] After multiple upgrade attempts fail, the system can automatically attempt to restore the original firmware data and make an upgrade feedback through a feedback module, further enhancing the emergency handling ability of upgrade failures. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0064] Figure 1 It is a schematic flowchart of a remote upgrade method for an intelligent thermostat provided by an embodiment of the present invention.
[0065] Figure 2 It is a schematic operation flowchart of a remote upgrade method for an intelligent thermostat provided by an embodiment of the present invention.
[0066] Figure 3 It is a schematic flowchart of a key management module, a certificate management module and a load perception module provided by an embodiment of the present invention.
[0067] Figure 4 It is a schematic structural diagram of a remote upgrade system for an intelligent thermostat provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0068] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all of them. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts also belong to the scope of protection of the present application.
[0069] The following further describes the best embodiment of the present invention in conjunction with the accompanying drawings;
[0070] Example 1
[0071] See also Figures 1-3 This embodiment provides a remote upgrade method for an intelligent thermostat, including:
[0072] When the target device receives the upgrade request, it first calls the key management module to verify the identity information of the target device to ensure that only legitimate devices can participate in the upgrade operation and prevent illegal devices from accessing, including:
[0073] The key management module obtains the root key from the hardware encryption machine, generates a manufacturer key based on the root key and the manufacturer ID discrete algorithm of the target device, and then generates a terminal key based on the manufacturer key and the terminal ID discrete algorithm of the target device; compares the generated terminal key with the terminal key stored in the target device; if the comparison result of the generated terminal key is consistent with the terminal key stored in the target device, the identity authentication of the target device is passed; otherwise, the identity authentication fails and the upgrade process is terminated;
[0074] After the identity authentication is passed, the certificate management module is called to retroactively verify the credibility of the upgrade instruction to prevent the upgrade instruction from being hijacked or tampered with, including:
[0075] It is necessary to obtain the manufacturer's CA key through the terminal CA key and terminal ID, and then compare the obtained manufacturer's CA key with the original manufacturer's CA key of the terminal device. If they are consistent, continue to obtain the root CA key through the manufacturer CA key and manufacturer ID. If they are inconsistent, the upgrade process is terminated; if the obtained root CA key is consistent with the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction verification is passed; otherwise, the upgrade process is terminated; This step ensures the security of the upgrade instruction by tracing back step by step through a multi-layer certificate verification mechanism, thereby avoiding the risk of man-in-the-middle attacks or instruction hijacking;
[0076] The certificate management module obtains the root CA key from the hardware encryption machine and issues the manufacturer CA key according to the manufacturer ID of the target device. The manufacturer CA key issues the terminal CA key according to the terminal ID of the target device.
[0077] Each intelligent temperature controller terminal device is attached with a unique terminal CA key. Since the signing order of the CA certificate is from the root CA key to the manufacturer CA key, and then from the manufacturer CA key to the terminal CA key, and the root CA key and the manufacturer CA key of the terminal device are inaccessible, while the terminal CA key of the terminal device is accessible. It is necessary to trace and obtain the manufacturer CA key through the terminal CA key and the terminal ID, and then compare the obtained manufacturer CA key with the original manufacturer CA key of the terminal device. If they are consistent, continue to trace and obtain the root CA key through the manufacturer CA key and the manufacturer ID. If they are inconsistent, terminate the upgrade process; if the obtained root CA key is consistent with the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction is verified and passed; otherwise, terminate the upgrade process;
[0078] After the upgrade instruction is verified and passed, the load perception module evaluates the task priority and resource occupancy status of the current device, including:
[0079] The load perception module sets three priorities: high, medium, and low, corresponding to the temperature control function, upgrade task, and other auxiliary functions respectively; by collecting the CPU usage rate and the resource occupancy rate of the task process in real time, and combining with the resource requirements of the temperature control function task, evaluate the resource occupancy rate of the current device; if the priority of the temperature control function task of the current target device is higher than the priority of the upgrade task and the resource occupancy rate is lower than the preset threshold, allow the execution of the upgrade operation; otherwise, enter the waiting queue until the conditions of the preset threshold are met; thereby avoiding the upgrade task from over-occupying resources and causing the imbalance of system security, ensuring that the upgrade task does not interfere with the operation of the device's temperature control function, and improving the stability of the system;
[0080] After determining that the upgrade operation can be executed, use the encrypted transmission module to encrypt the target upgrade package, including:
[0081] The encrypted transmission module includes a block decryption unit and a data block encryption unit;
[0082] Calculate the overall digest value of the target upgrade package through the hash algorithm;
[0083] The encrypted transmission module first divides the target upgrade package into multiple data blocks and assigns a unique identification number to each data block;
[0084] The data block encryption unit negotiates based on the ECDH protocol and generates a data block public key and a data block private key through a predefined elliptic curve parameter exchange mechanism. The block decryption unit negotiates based on the ECDH protocol and generates a block decryption unit public key and a block decryption unit private key through a predefined elliptic curve parameter exchange mechanism. The data block encryption unit sends the data block public key to the block decryption unit, and the block decryption unit sends the block decryption unit public key to the data block encryption unit. The data block encryption unit multiplies the obtained block decryption unit public key by the data block private key to obtain a shared key. The block decryption unit multiplies the obtained data block public key by the block decryption unit private key to obtain the same shared key. The shared key is used for symmetric encryption communication to ensure the security of information transmission.
[0085] The shared key is derived into an encryption sub-key and a verification key through the HKDF-SHA256 algorithm in combination with a random salt value. The encryption sub-key is used to encrypt the data block using SM4-CTR and generate an encrypted data packet. The verification key is used to perform a hash verification on the received encrypted data packet.
[0086] The sender generates a fixed-length digest value based on the verification key and the data block content through a hash algorithm. The digest value can uniquely represent the integrity characteristics of the data block. The sender sends the digest value and the complete digest value of the data block to the receiver in an attached or independently transmitted manner to provide a verification basis for the receiver.
[0087] After obtaining the encrypted data packet and the attached digest value, the receiver first negotiates based on the ECDH protocol and obtains a data block public key and a block decryption unit public key that match the sender through a predefined elliptic curve parameter exchange mechanism, and synchronously generates a shared key. Combining the random salt value parameter embedded in the transmission process, the shared key is decomposed into an encryption sub-key and a verification key, where the encryption sub-key corresponds to the reversible transformation parameter of the symmetric encryption operation. The receiver decrypts the encrypted data packet based on the encryption sub-key to obtain the data block content. Then the receiver re-executes the hash algorithm based on the decomposed verification key and the data block content to generate a new digest value. This process strictly replicates the hash calculation logic of the sender to ensure the consistency of the algorithm input.
[0088] Subsequently, the recipient performs a bit-by-bit comparison of the two digest values: the original digest value is attached or independently transmitted by the sender, and the newly generated digest value is calculated based on the decrypted plaintext data block; if the two digest values match exactly, it indicates that the data block has not been tampered with or damaged during transmission, and the recipient stores the decrypted plaintext data block in the temporary storage area for subsequent processing; if there are differences, the integrity check failure mechanism is triggered to notify the sender to re-transmit the data block; during the verification process, the avalanche effect and collision resistance characteristics of the hash algorithm ensure that minor data changes will result in significant changes in the digest value, thus effectively defending against tampering attacks;
[0089] In case of a network interruption, the breakpoint resumption module records the identification number of the data block that has been successfully transmitted, and continues to transmit the data block that has not been successfully transmitted after the network resumes, including:
[0090] The breakpoint resumption module divides two independent partitions in the storage area of the target device. Partition A is the main partition, which is used to store the currently running firmware and prohibits write operations; Partition B is the backup partition, which is used to write the new firmware, clear all data and perform verification before the upgrade; at the same time, a Flash transmission area is reserved on the server side, and a Flash reception area is reserved on the target device side to record the transmission progress;
[0091] The network status is detected through the heartbeat packet mechanism. A network determination sending unit is reserved on the target device side, and a network determination receiving unit is preset on the server side. The network determination sending unit sends a heartbeat packet to the network determination receiving unit once every fixed time. The heartbeat packet contains the current transmission progress. After receiving the heartbeat packet, the network determination receiving unit feeds back the transmission progress in real time; if the heartbeat packet does not receive a response three times in a row, it is determined that the network is interrupted; during the network interruption, the identification number of the last successfully transmitted data block is recorded; after the network resumes, the data block that has not been completed is continued to be transmitted according to the recorded data block identification number, thereby avoiding re-transmission of the completed data block;
[0092] After all data blocks are transmitted, the storage management module splices and generates a complete upgrade package in the order of the data block identification numbers. Subsequently, the method of chained aggregation is used to accumulate the digest values carried by each data block to obtain the overall digest value of the complete upgrade package. The system compares the calculated overall digest value with the digest value of the pre-stored target upgrade package bit by bit. Only when the generated overall digest value exactly matches the digest value of the target upgrade package and the data block sequence is complete, can the generated complete upgrade package be written into Partition B and replace the currently running firmware after the writing is complete; if the generated overall digest value does not match the digest value of the target upgrade package, the intermediate data in the temporary storage area is cleared and an attempt is made to upgrade again;
[0093] If the feedback module is called after multiple upgrade attempts fail, attempt to restore the original firmware data from the backup; replace the original firmware data into partition A and calculate its digest value; if the digest value of the original firmware replaced into partition A is the same as the digest value of the backup data, then feedback a prompt message indicating that the upgrade failed but the original firmware was successfully restored; if the digest value of the original firmware replaced into partition A is different from the digest value of the backup data, then feedback a prompt message indicating that the upgrade failed and the original firmware restoration failed; thus providing an effective emergency handling solution for the upgrade failure.
[0094] In addition, a physical DIP switch is preset. The physical DIP switch is a manually operated hardware control element used to provide a localized upgrade remediation mechanism for the intelligent thermostat; record the DIP value, and the DIP value records the storage location of the backup firmware; if it is detected that the physical DIP switch on the target device is triggered, then read the current DIP value, and read the backup firmware from the preset storage location according to the DIP value, and use the backup firmware as the new target upgrade package to re-execute the upgrade process; further enhancing the flexibility and fault tolerance of the system.
[0095] Embodiment 2
[0096] Please refer to Figures 2-4 This embodiment provides a remote upgrade system for an intelligent thermostat, which executes the remote upgrade method of the intelligent thermostat. The system includes a key management module, a certificate management module, a load awareness module, an encryption transmission module, a breakpoint resumption module, a storage management module, and a feedback module.
[0097] The key management module is used to generate and verify the identity information of the target device.
[0098] The certificate management module is used to trace and verify the credibility of the upgrade instruction when the identity authentication of the target device passes.
[0099] The load awareness module is used to evaluate the task priority and resource occupancy status of the current device when the upgrade instruction verification passes.
[0100] The encryption transmission module, when the evaluation of the load awareness module passes, the sender performs block encryption processing on the upgrade package, and the receiver first performs a hash check on the encrypted data packet, and then decrypts the encrypted data packet after the check passes.
[0101] The breakpoint resumption module is used to record the transmission progress when the network is interrupted and support resumption.
[0102] The storage management module is used to manage the firmware storage area and support the writing and rollback of the upgrade package.
[0103] The feedback module is used to provide a prompt message when the upgrade fails or the original firmware restoration fails.
[0104] Example 3
[0105] See also Figures 1-4 In order to better enable relevant personnel in the technical field to fully understand and implement the present invention, the specific implementation principle of the present invention is further explained in combination with a specific application scenario below:
[0106] In a smart home environment, the user sends an upgrade request to the smart thermostat through a mobile phone APP. After the target device receives the request, it first calls the key management module, which obtains the root key from the hardware encryption machine, and generates a manufacturer key based on the root key and the manufacturer ID discrete algorithm of the target device, and then generates a terminal key based on the manufacturer key and the terminal ID discrete algorithm of the target device; the manufacturer key and the terminal key are completed based on the discrete algorithm; then, if the generated terminal key is consistent with the terminal key stored in the target device, the identity authentication of the target device is passed; otherwise, the identity authentication fails and the upgrade process is terminated; this step effectively prevents the possibility of illegal device access through the participation of the hardware encryption machine;
[0107] After the identity authentication is passed, the certificate management module is called. The certificate management module obtains the root CA key from the hardware encryption machine and issues the manufacturer CA key according to the manufacturer ID of the target device. The manufacturer CA key issues the terminal CA key according to the terminal ID of the target device. Each intelligent thermostat terminal device is attached with a unique terminal CA key. Since the issuance order of the CA certificate is from the root CA key to the manufacturer CA key, and then from the manufacturer CA key to the terminal CA key, and the root CA key and the manufacturer CA key of the terminal device are inaccessible, and the terminal CA key of the terminal device is accessible, it is necessary to trace the manufacturer CA key through the terminal CA key and the terminal ID, and then compare the obtained manufacturer CA key with the original manufacturer CA key of the terminal device. If they are consistent, continue to trace the root CA key through the manufacturer CA key and the manufacturer ID. If they are inconsistent, the upgrade process is terminated; if the obtained root CA key is consistent with the original root CA key of the terminal device, it proves that the root CA key is a trusted certificate, and the upgrade instruction verification is passed; otherwise, the upgrade process is terminated; This step ensures the security of the upgrade instruction by tracing back the multi-layer certificate verification mechanism step by step, thereby avoiding the risk of man-in-the-middle attack or instruction hijacking;
[0108] After the upgrade instruction is verified, the load awareness module evaluates the task priority and resource occupancy status of the current device. By collecting the CPU usage rate and the resource occupancy rate of the task process in real time, and combining with the resource requirements of the temperature control function task, it evaluates the resource occupancy rate of the current device. If the task priority of the temperature control function of the current target device is higher than the upgrade task priority, and the resource occupancy rate is lower than the preset threshold, the upgrade operation is allowed to be executed; otherwise, it enters the waiting queue until the conditions of the preset threshold are met; thereby avoiding the upgrade task from over-occupying resources and causing the imbalance of system security, ensuring that the upgrade task does not interfere with the operation of the device's temperature control function, and improving the stability of the system;
[0109] After confirming that the upgrade operation can be executed, the encryption transmission module first divides the target upgrade package into multiple data blocks and assigns a unique identification number to each data block. The data block encryption unit negotiates and generates a data block public key and a data block private key based on the ECDH protocol. The block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol. The data block encryption unit sends the data block public key to the block decryption unit, and the block decryption unit sends the block decryption unit public key to the data block encryption unit. The data block encryption unit multiplies the obtained block decryption unit public key by the data block private key to obtain a shared key. The block decryption unit multiplies the obtained data block public key by the block decryption unit private key to obtain the same shared key. The shared key is used for symmetric encryption communication to ensure the security of information transmission;
[0110] The shared key derives an encryption sub-key and a verification key through the HKDF-SHA256 algorithm in combination with a random salt value. The encryption sub-key is used to encrypt the data block by SM4-CTR and generate an encrypted data packet.
[0111] The verification key is used to perform a hash verification on the received encrypted data packet.
[0112] The sender generates a fixed-length digest value based on the verification key and the data block content through a hash algorithm. The digest value can uniquely represent the integrity characteristics of the data block and provides a verification basis for the receiver in the form of being attached to the encrypted data packet or transmitted independently.
[0113] After the recipient obtains the encrypted data packet and the attached digest value, it first negotiates based on the ECDH protocol, obtains the data block public key and the block decryption unit public key that match the sender through a predefined elliptic curve parameter exchange mechanism, and synchronously generates a shared key; combining the random salt value parameter embedded in the transmission process, the shared key is decomposed into an encryption sub-key and a verification key, where the encryption sub-key corresponds to the reversible transformation parameter of the symmetric encryption operation; the recipient decrypts the encrypted data packet based on the encryption sub-key to obtain the data block content; then the recipient re-executes the hash algorithm based on the verification key and the data block content obtained by decomposition to generate a new digest value. This process strictly replicates the hash calculation logic of the sender to ensure the consistency of the algorithm input;
[0114] Subsequently, the recipient compares the two digest values bit by bit: the original digest value is attached or independently transmitted by the sender, and the newly generated digest value is calculated based on the decrypted plaintext data block; if the two digest values match exactly, it indicates that the data block has not been tampered with or damaged during transmission, and the recipient stores the decrypted plaintext data block in the temporary storage area for subsequent processing; if there are differences, it triggers the integrity check failure mechanism to notify the sender to re-transmit the data block; during the verification process, the avalanche effect and collision resistance characteristics of the hash algorithm ensure that minor data changes will result in significant changes in the digest value, thus effectively defending against tampering attacks.
[0115] If a network interruption occurs, the breakpoint resumption module is used to record the identification number of the data block that has been successfully transmitted, and continue to transmit the incomplete data block after the network resumes, including:
[0116] The breakpoint resumption module divides two independent partitions in the storage area of the target device. Partition A is the main partition, which is used to store the currently running firmware and prohibits write operations; Partition B is the backup partition, which is used to write the new firmware, clear all data and perform verification before upgrading; at the same time, a Flash sending area is reserved on the server side and a Flash receiving area is reserved on the target device side to record the transmission progress;
[0117] The network status is detected through the heartbeat packet mechanism. The target device side reserves a network determination sending unit, and the server side presets a network determination receiving unit. The network determination sending unit sends a heartbeat packet to the network determination receiving unit once every fixed time. The heartbeat packet contains the current transmission progress. After receiving the heartbeat packet, the network determination receiving unit feeds back the transmission progress in real time; if the heartbeat packet does not receive a response three times in a row, it is determined that the network is interrupted; during the network interruption, record the identification number of the last successfully transmitted data block; after the network resumes, continue to transmit the incomplete data block according to the recorded data block identification number, thereby avoiding repeated transmission of the completed data block;
[0118] After all data blocks are transferred, the storage management module splices and generates a complete upgrade package in the order of data block identification numbers. Subsequently, the currently running firmware accumulates the digest values carried by each data block using the method of chained aggregation to obtain the overall digest value of the complete upgrade package. The system compares the calculated overall digest value with the digest value of the pre-stored target upgrade package bit by bit. Only when the generated overall digest value exactly matches the digest value of the target upgrade package and the data block sequence is complete can the generated complete upgrade package be written to partition B and replace the currently running firmware after the writing is complete; if the generated overall digest value does not match the digest value of the target upgrade package, the intermediate data in the temporary storage area is cleared and the upgrade is attempted again.
[0119] If the upgrade fails after multiple attempts, the feedback module is called to attempt to restore the original firmware data from the backup; the original firmware data is replaced into partition A and its digest value is calculated; if the digest value of the original firmware replaced into partition A is consistent with the backup data, a prompt message indicating that the upgrade failed but the original firmware was successfully restored is fed back; if the digest value of the original firmware replaced into partition A does not match the digest value of the backup data, a prompt message indicating that the upgrade failed and the original firmware restoration failed is fed back; thus providing an effective emergency handling solution for the upgrade failure.
[0120] In addition, a physical DIP switch is preset. The physical DIP switch is a manually operated hardware control element used to provide a localized upgrade remediation mechanism for the intelligent thermostat; the DIP value is recorded, and the DIP value records the storage location of the backup firmware; if it is detected that the physical DIP switch on the target device is triggered, the current DIP value is read, and the backup firmware is read from the preset storage location according to the DIP value, and the backup firmware is used as the new target upgrade package to re-execute the upgrade process; further enhancing the flexibility and fault tolerance of the system.
[0121] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application shall be included within the protection scope of the present application.
Claims
1. A remote upgrade method for an intelligent thermostat, characterized in that, Including the steps: Receive an upgrade instruction and verify the identity information of the target device; If the identity information verification is passed, trace and verify the credibility of the upgrade instruction; After the credibility verification is passed, evaluate the task priority and resource occupancy status of the current target device; If the task priority of the temperature control function of the current target device is higher than the upgrade task priority and the resource occupancy rate is lower than the preset threshold, allow the upgrade operation to be executed; Otherwise, suspend the upgrade until the conditions are met; Divide the target upgrade package into multiple data blocks and assign a unique identification number to each data block; Perform encryption processing on the data blocks and generate encrypted data packets; After the target device receives the encrypted data packet, compare the integrity of the data blocks through the verification key; If the data blocks pass the verification, decrypt and store the data blocks in the temporary storage area; If a network interruption occurs, record the identification numbers of the data blocks that have been successfully transmitted; After the network is restored, continue to transmit the data blocks that have not been successfully transmitted according to the recorded data block identification numbers; When all the data blocks are transmitted, splice them in the order of the identification numbers to generate a complete upgrade package; Calculate the overall digest value of the spliced complete upgrade package and compare it with the digest value of the target upgrade package; if the comparison result is consistent, write the complete upgrade package into the storage area of the target device and replace the currently running firmware; if the comparison result is inconsistent, clear the data blocks in the temporary storage area and try to upgrade again; If multiple upgrade attempts fail, try to restore the backed-up original firmware data; Write the backup data of the original firmware data into the main storage area and calculate its digest value; If the obtained digest value is consistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed but the original firmware was successfully restored; if the obtained digest value is inconsistent with the digest value of the backup data, feedback a prompt message indicating that the upgrade failed and the original firmware restoration failed.
2. The remote upgrade method of the intelligent temperature controller according to claim 1, characterized in that, The verification of the identity information of the target device includes: Obtain the root key from the hardware encryption machine; Generate the manufacturer key according to the root key and the discrete algorithm of the manufacturer ID of the target device; Then generate the terminal key according to the manufacturer key and the discrete algorithm of the terminal ID of the target device; Compare the generated terminal key with the terminal key stored in the target device; if the comparison result is consistent, the identity verification is passed; otherwise, terminate the upgrade process.
3. The remote upgrade method of the intelligent thermostat according to claim 2, characterized in that, The tracing and verification of the credibility of the upgrade instruction includes: Obtain the root CA key from the hardware encryption machine; Sign the manufacturer CA key according to the root CA key and the manufacturer ID of the target device; Then sign the terminal CA key according to the manufacturer CA key and the terminal ID of the target device; Trace and verify the credibility of the manufacturer CA key through the terminal CA key; Trace and verify the credibility of the root CA key through the manufacturer CA key; if the root CA key is a trusted certificate, the instruction verification is passed; otherwise, terminate the upgrade process.
4. The remote upgrade method of the intelligent thermostat according to claim 3, characterized in that, The evaluation of the task priority and resource occupancy status of the current target device includes: Set three priorities: high, medium, and low, corresponding to the temperature control function, upgrade task, and other auxiliary functions respectively; Collect the CPU usage rate and the resource occupancy rate of task processes in real time; evaluate the resource occupancy rate of the current device in combination with the resource requirements of the temperature control function task; if the priority of the temperature control function task of the current target device is higher than the priority of the upgrade task and the resource occupancy rate is lower than the preset threshold, then allow the execution of the upgrade operation; otherwise, enter the waiting queue.
5. The remote upgrade method of the intelligent thermostat according to claim 4, characterized in that, The encryption process for the data block includes: The data block encryption unit negotiates and generates a data block public key and a data block private key based on the ECDH protocol; The block decryption unit negotiates and generates a block decryption unit public key and a block decryption unit private key based on the ECDH protocol; Generate a shared key according to the data block public key, the data block private key, the block decryption unit public key, and the block decryption unit private key; The shared key derives an encryption sub-key and a verification key through the HKDF-SHA256 algorithm in combination with a random salt value; The encryption sub-key is used by the sender to perform SM4-CTR encryption on the data block to generate an encrypted data packet; The verification key is used by the receiver to perform SHA256 hash verification on the received encrypted data packet; The sender generates a digest value based on the verification key and the data block content, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; by performing hash verification on the two digest values, it is verified that the encrypted data packet has not been tampered with or damaged during transmission.
6. The remote upgrade method of the intelligent thermostat according to claim 5, wherein The recording of the currently successfully transmitted data block identification number includes: Divide the storage area of the target device into partition A and partition B. Partition A is used to store the currently running firmware, and partition B is used to store the new firmware; After the target upgrade package passes the integrity verification, write the target upgrade package as the new firmware into partition B. After the target upgrade package is completely written, replace it into partition A as the currently running firmware; Reserve a Flash sending area and a Flash receiving area on the server side and the target device side respectively for recording the transmission progress; Detect the network status through the heartbeat packet mechanism; if the heartbeat packet does not receive a response for three consecutive times, it is determined that the network is interrupted; record the identification number of the last successfully transmitted data block during the network interruption.
7. The remote upgrade method of the intelligent thermostat according to claim 6, characterized in that, The attempt to restore the original firmware data of the backup includes: Back up the currently running firmware to generate a backup firmware; Preset a physical DIP switch. The physical DIP switch is a manually operated hardware control element used to record the DIP value; the DIP value is used to record the storage location of the backup firmware; Detect whether the physical DIP switch on the target device is triggered; if the physical DIP switch is triggered, read the DIP value; Read the backup firmware from the preset storage location according to the DIP value; use the backup firmware as the new target upgrade package to re-execute the upgrade process.
8. A remote upgrade system for an intelligent thermostat, characterized in that: Execute the remote upgrade method of the intelligent thermostat according to any one of claims 1 to 7. The system includes a key management module, a certificate management module, a load awareness module, an encrypted transmission module, a breakpoint resumption module, a storage management module, and a feedback module. The key management module is used to generate and verify the identity information of the target device; The certificate management module is used to trace and verify the credibility of the upgrade instruction after the authentication of the target device is passed. The load awareness module is used to evaluate the task priority and resource occupancy status of the current device after the upgrade instruction is verified. The encrypted transmission module is used to perform block encryption processing on the upgrade package to generate encrypted data packets after the evaluation of the load awareness module passes; the sender generates a digest value based on the verification key and the data block content, and sends the encrypted data packet and the digest value to the receiver. After receiving the encrypted data packet and the digest value, the receiver decrypts the encrypted data packet based on the key negotiation mechanism to generate a new digest value; by performing hash verification on the two digest values, it is verified that the encrypted data packet has not been tampered with or damaged during the transmission process. The breakpoint resumption module is used to record the transmission progress when the network is interrupted and support resumption of transmission. The storage management module is used to manage the firmware storage area and support the writing and rollback of the upgrade package. The feedback module is used to provide prompt information when the upgrade fails or the original firmware recovery fails.
9. The remote upgrade system of the intelligent thermostat according to claim 8, wherein The key management module obtains the root key from the hardware encryption machine and generates a manufacturer key and a terminal key according to the manufacturer ID and terminal ID of the target device to verify the identity information of the target device.
10. The remote upgrade system of the intelligent temperature controller according to claim 9, wherein The breakpoint resumption module detects the network status through the heartbeat packet mechanism and records the identification number of the last successfully transmitted data block during the network interruption, so as to continue transmitting the unfinished data block after the network is restored.
Citation Information
Patent Citations
Method for generating and distributing movable IP Key
CN101075870A
Interaction information system based on industrial digitization
CN118282531A