Root key management method and device of energy storage system and energy storage system
By splitting and managing the root key on the control terminal of the energy storage system, the problems of poor root key management, high hardware cost and vulnerability in the prior art are solved, and more efficient and secure key management is achieved.
Patent Information
- Application Number
- CN202510577923.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-05-06
AI Technical Summary
The root key management effect of existing energy storage systems is poor, the hardware cost is high, and it is susceptible to single hardware attacks to cause key leakage.
The root key is split on the control terminal of the energy storage system, and it is split into multiple root key shares, and is jointly held and managed by multiple root key permission parties, and stored in their respective storage areas. Only when multiple root key permissions are coordinated at the same time can the energy storage root key be restored.
It improves the management effect of root key management in energy storage systems, reduces hardware costs, and enhances the security of key management, avoids key leakage caused by a single hardware attack.
Smart Images

Figure CN120105403A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular to a root key management method and device for an energy storage system, and an energy storage system. Background Art
[0002] With the continuous development of science and technology, energy storage systems have been widely used in many fields. In order to ensure the security of energy storage data in the energy storage system, a key protection system is usually set up for the energy storage system. In the key management protection system, the root key is used to derive encryption keys and integrity protection keys. Therefore, it is very necessary to securely manage the root key of the energy storage system.
[0003] At present, in the process of root key management of energy storage systems, the root key is usually stored by setting up physical hardware such as HSM (Hardware Security Module) or encrypted USB (Universal Serial Bus) disk. However, the hardware cost is often relatively high. At the same time, the root key that relies on single hardware management is prone to leakage when the device is attacked. Therefore, the current root key management of energy storage systems has poor management effect. Summary of the invention
[0004] Based on this, it is necessary to provide a root key management method, device and energy storage system for an energy storage system to improve the management effect of the root key management of the energy storage system in order to solve the above technical problems.
[0005] In a first aspect, the present application provides a root key management method for an energy storage system, which is applied to a control terminal of the energy storage system, including:
[0006] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, the multiple root key authority parties hold second management authority of their respective corresponding root key shares, the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system;
[0007] Storing each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key;
[0008] According to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one by one;
[0009] When it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0010] In a second aspect, the present application further provides a root key management device for an energy storage system, which is applied to a control terminal of the energy storage system, including:
[0011] A splitting module is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates an energy storage root key, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold the second management authority of the root key shares corresponding to each other, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system;
[0012] A storage module, used to store each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key;
[0013] A determination module, configured to locate, in all storage areas, a plurality of target storage areas required for restoring the energy storage root key according to a root key restoration operation triggered by a root key restoration party, wherein the plurality of target storage areas correspond one to one to the plurality of root key authority parties;
[0014] The restoration module is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas.
[0015] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0016] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0017] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0018] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0019] In a fifth aspect, the present application further provides a computer program product, including a computer program, which implements the following steps when executed by a processor:
[0020] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0021] In the above-mentioned root key management method, device and energy storage system of the energy storage system, the control terminal of the energy storage system first performs real-time detection on the energy storage system, and after detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and the management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively, and the management authority held by different root key authority parties is isolated from each other, and multiple root key authority parties include a root key management object that manages the energy storage system, a root key that uses the energy storage system, and a root key management object that uses the energy storage system. By using at least two of the object, the management and control terminal of the energy storage system, and the cloud providing the energy storage system cloud service, the energy storage root key can be split into multiple root key shares managed by at least two root key authority parties related to the energy storage system, and then each root key share is stored in a storage area managed by a respective matching root key authority party, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key, thereby storing the multiple root key shares in storage areas where different root key authority parties have management authority, and then according to the root key restoration operation triggered by the key restoration party, The multiple target storage areas required for restoring the energy storage root key are located in all storage areas. Finally, when it is detected that the root key restoration party has access rights to multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas. Since the root key shares that the multiple root key authority parties have management rights are isolated from each other, and the root key shares corresponding to the amount of root key shares that any root key authority party can manage cannot be restored to obtain the energy storage root key alone, after receiving the root key restoration request, it is necessary to cooperate with at least two of the root key management object, the root key user object, the control terminal and the cloud to locate the multiple target storage areas required for restoring the energy storage root key. Finally, the energy storage root key can be restored by extracting multiple target root key shares from multiple target storage areas managed by the root key authority party, thereby avoiding the situation where a single root key authority party is attacked and the root key is leaked, and the purpose of securely managing the root key at the software level can be achieved, so as to overcome the technical defects that the hardware cost is often relatively high. At the same time, the root key that relies on a single hardware encryption is prone to the risk of leakage when the device is attacked, so as to improve the management effect of the root key management of the energy storage system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related technologies, the drawings required for use in the embodiments or the related technical descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0023] Figure 1 A schematic diagram of a process flow of a root key management method for an energy storage system in one embodiment;
[0024] Figure 2 A schematic diagram of a process flow of a root key management method for an energy storage system in another embodiment;
[0025] Figure 3 A schematic diagram of a process for splitting an energy storage root key in a root key management method for an energy storage system in another embodiment;
[0026] Figure 4 A schematic diagram of a scenario in which different root key restoration parties of a root key management method for an energy storage system perform energy storage root key restoration in another embodiment;
[0027] Figure 5 is a structural block diagram of a root key management device for an energy storage system in one embodiment;
[0028] Figure 6 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0029] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0030] First of all, it should be understood that ESS (Energy Storage System) refers to a system that stores energy in a certain form through specific media or devices and releases it in a specific form when needed. In order to ensure the security of energy storage data in the energy storage system, a hardware security module is usually deployed in the energy storage system to store the root key. The root key is at the highest level in the key protection system and is used to generate and manage the next level of keys, such as master keys and working keys. By setting the root key, each unit and battery pack inside the energy storage system can be protected in advance, thereby ensuring the safe storage and management of the key. At present, the root key is often stored in an HSM or a trusted execution environment. And dynamically update when necessary to serve the scenarios of data transmission, firmware update and status monitoring of energy storage systems. However, for the highly competitive energy storage industry, the use of hardware such as HSM to manage root keys often increases hardware costs. At the same time, since the root keys are managed by relying on a single hardware, they are still prone to leakage when the device is attacked. Therefore, whether from the perspective of management cost or management security, the current management effect of energy storage system root key management is not good. Therefore, there is an urgent need for a root key management method for energy storage systems that can improve the root key management effect of energy storage systems.
[0031] In one embodiment, Figure 1As shown, a root key management method for an energy storage system is provided. This embodiment takes the method applied to a control terminal of an energy storage system as an example. The control terminal of the energy storage system refers to a terminal deployed at a user end of the energy storage system, which can both collect data at the user end of the energy storage system and interactively control the user end of the energy storage system. The user end of the energy storage system refers to a deployment site of the energy storage system on the user side, which can be specifically composed of an energy storage cabinet, an energy management system, communication equipment, and a control terminal of the energy storage system. The control equipment of the energy storage system can specifically be a personal computer, a laptop computer, a smart phone, and a tablet computer. The control terminal of the energy storage system monitors the energy storage system. It can be understood that the operation and maintenance personnel perform energy storage system parts at the control terminal of the energy storage system. During the deployment process, an energy storage root key will be dynamically generated in the hardware security module of the energy storage system, and then the encryption key and integrity protection key will be derived based on the energy storage root key. Finally, the above keys are used to ensure the secure transmission and storage of data related to the energy storage system. The management and control terminal of the energy storage system includes a splitting module, a storage module, a determination module and a restoration module. The splitting module is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system has generated an energy storage root key. Among them, the first management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and multiple root key authority parties hold the second management authority of their respective corresponding root key shares. The multiple second management authorities are isolated from each other, and the multiple root key authority parties include the root key management system. At least two of the following four: a key management object, an object using the root key of the energy storage system, a control terminal of the energy storage system, and a cloud providing cloud services for the energy storage system; a storage module is used to store each root key share in a storage area managed by a respective matching root key authority party, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key; a determination module is used to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to a root key restoration operation triggered by a root key restoration party, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; and a restoration module is used to detect that the root key restoration party has access rights to access multiple target storage areas, according to The target root key shares selected from multiple target storage areas are restored to obtain the energy storage root key. It can be understood that in the process of managing the root key of the energy storage system, through the information interaction between the splitting module, the storage module, the determination module and the restoration module, first, after receiving the energy storage root key, the energy storage root key is split into multiple root key shares, and at least two of the root key management object, the root key use object, the management and control terminal of the energy storage system and the cloud providing cloud services for the energy storage system hold management permissions for different root key shares. Since the root key shares with management permissions of multiple root key authority parties are isolated from each other, and the root key shares corresponding to the amount of root key shares that can be managed by any root key authority party cannot be restored separately to obtain the energy storage root key,After receiving the root key restoration request, it is necessary to cooperate with at least two of the root key management object, the root key user object, the control terminal and the cloud to locate the multiple target storage areas required to restore the energy storage root key. Finally, by extracting multiple target root key shares from multiple target storage areas managed by the root key authority, the energy storage root key can be restored, thereby avoiding the situation where a single root key authority is attacked and the root key is leaked, thereby improving the root key management effect of the energy storage system. In this embodiment, the method includes the following steps 202 to 208. Among them:,
[0032] Step 202, after detecting that the energy storage system generates an energy storage root key, split the energy storage root key into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold the second management authority of the root key shares corresponding to each other, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key user object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system;
[0033] It should be noted that the operation and maintenance personnel can complete the generation and splitting process of the energy storage root key through the interaction between the energy storage system's management and control terminal and the energy storage system. Specifically, the operation and maintenance personnel deploy the energy storage system through the energy storage system's management and control terminal. In the initialization stage of the energy storage system deployment, the energy storage system's hardware security module will generate the energy storage root key through its internal secure random number generator. The hardware security module can be integrated into the energy storage system's controller or gateway device. The energy storage root key is generated in a secure hardware module such as an HSM or an encrypted USB disk to prevent it from being maliciously stolen. However, the energy storage root key that relies on single hardware management is still prone to leakage after the device is attacked. Therefore, after the energy storage root key is generated, the key splitting technology can be used to split the energy storage root key into multiple root key shares, and multiple root key authorities hold the management authority of their corresponding root key shares, thereby increasing the difficulty for hackers to attack the energy storage cabinet and destroy the confidentiality of the system.
[0034] It should be noted that the control terminal of the energy storage system detects that the energy storage system generates an energy storage root key. Specifically, the control terminal of the energy storage system detects that the energy storage root key is generated in the hardware security module, and after the energy storage root key is generated, it issues a control instruction to split the energy storage root key into multiple root key shares. It can be understood that the execution subject of splitting the energy storage root key is the hardware security module in the energy storage system. The multiple root key shares can be 5, 6 or 7, etc. The share amount of the multiple root key shares can be specifically determined by the splitting instruction issued by the control terminal of the energy storage system. Among them, after the energy storage root key is split into multiple root key shares, the first management authority of the energy storage root key as a whole is jointly held by multiple root key authority parties who manage the energy storage root key, and different root key authority parties hold the second management authority of their respective corresponding root key shares. Different second management authorities are isolated from each other. The root key authority party refers to an entity with the management authority of the energy storage root key, which can be specifically an object, a system or a terminal, etc. The multiple root key authority parties include the root key management object that manages the energy storage system, the root key management object that uses the energy storage system, and the root key management object that uses the energy storage system. The key user object, the control terminal of the energy storage system and the cloud that provides cloud services for the energy storage system, wherein the root key management object that manages the energy storage system can be specifically the supplier, the root key user object that uses the energy storage system can be specifically the customer site manager, the control terminal of the energy storage system can be specifically a computer or a mobile phone, etc., and the cloud can be specifically a cloud server. It can be understood that since different root key authority parties are independent of each other, the second management authority of multiple root key shares is isolated from each other, and the amount of root key shares with management authority of different root key authority parties can be the same or different. For example, in an implementable manner, the energy storage root key is split into root key share 1, root key share 2, root key share 3, root key share 4 and root key share 5, wherein the second management authority of root key share 1 can be held by the supplier operation and maintenance personnel, the second management authority of root key share 2 can be held by the customer site manager, the second management authority of root key share 3 and root key share 4 is held by the control terminal of the energy storage system, and the management authority of root key share 5 can be held by the cloud server.
[0035] It should be noted that after the hardware security module of the energy storage system receives the splitting instruction issued by the control terminal of the energy storage system, the hardware security module can generate multiple root key shares based on the preset splitting algorithm running internally, wherein the preset splitting algorithm can be specifically the Shamir polynomial difference algorithm, and the shares obtained by splitting can be expressed as , , , where n represents the total number of root key shares. After splitting to obtain multiple root key shares, the management and control terminal of the energy storage system can establish a mapping relationship between different root key shares and different root key authority parties, so that different root key authority parties have the second management authority of their corresponding root key shares. Specifically, based on the share identification information of the root key share and the authority identity information of the root key authority party, a mapping relationship between different key shares and different root key authority parties can be established, where the share identification information can specifically be a share number, and the authority identity information can specifically be an object identity information or a terminal number information, etc. It can be understood that there are at least two root key authority parties with the second management authority, and multiple root key authority parties with the second management authority jointly hold the first management authority of the energy storage root key. For example, in an implementable manner, the multiple root key authority parties can be a root key management object and a root key use object, can be a root key management object and a management and control terminal of the energy storage system, can be a management and control terminal of the energy storage system and a cloud, or can also be a root key management object, a root key use object and a management and control terminal of the energy storage system, etc.
[0036] As an example, step 202 includes: after determining that the hardware security module of the energy storage system generates an energy storage root key based on the root key generation progress information fed back by the energy storage system, generating a root key splitting instruction, and according to the root key splitting instruction, controlling the hardware security module to split the energy storage root key into multiple root key shares, wherein the root key generation progress information is used to characterize the generation progress of the energy storage root key generated by the hardware security module of the energy storage system, and the root key splitting instruction is used to instruct the splitting of the energy storage root key.
[0037] In one practicable manner, it is assumed that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 4, then the hardware security module splits the energy storage root key into , , and .
[0038] Step 204, storing each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key;
[0039] It should be noted that after the hardware security module completes the splitting of the energy storage root key and obtains multiple root key shares, in order to achieve physical isolation of different root key shares when they are managed by multiple root key authority parties, the management and control terminal of the energy storage system can control the distribution and storage of multiple root key shares in the storage area managed by the root key authority party. For example, in an implementable manner, assuming that the energy storage root key is split into 4 root key shares, the root key management object, the root key use object, the management and control terminal and the cloud each have a second management authority for a root key share, then the root key share 1 can be stored in the first preset storage area associated with the first associated terminal of the root key management object. Storage area, storing root key share 2 in a second preset storage area of a second associated terminal associated with the root key user object, storing root key share 3 in a third preset storage area of the management and control terminal, and storing root key share 4 in a fourth preset storage area of the cloud, wherein the first associated terminal that has an association relationship with the root key management object can be a mobile phone terminal held by the root key management object, and the second associated terminal that has an association relationship with the root key user object can be a mobile phone terminal held by the root key user object. In this way, since the storage spaces of different terminals have independent storage media, real isolation of different root key shares can be achieved at the physical level.
[0040] It should be noted that in order to avoid the leakage of the energy storage root key caused by a single root key authority, it can be set that the root key share that each root key authority can manage cannot be restored to obtain the energy storage root key, and the energy storage root key can only be restored by the cooperation of two or more root key authority parties, that is, the first root key share stored in any storage area is set to be smaller than the second root key share required to restore the energy storage root key. For example, in an implementable manner, assuming that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, and the root key splitting instruction simultaneously indicates that the minimum number of shares for restoring the energy storage root key is 4. Then, in the process of establishing a mapping relationship between the root key shares and the root key authority to distribute the root key shares to different storage areas for storage, the number of root key shares stored in any depository area is less than 4.
[0041] As an example, step 204 includes: extracting share allocation strategy information from the root key splitting instruction, determining the root key share allocation amount corresponding to each of the multiple root key authority parties based on the share allocation strategy information, and receiving a mapping relationship between multiple root key shares and multiple root key authority parties, and according to the root key share allocation amount and the mapping relationship, controlling the hardware security module to store the multiple root key shares in the root key authority parties that match each other, wherein the root key share allocation amount is used to characterize the number of root key shares allocated to different root key authority parties.
[0042] Step 206: according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one by one;
[0043] It should be noted that the root key restoration party refers to the entity that performs energy storage root key restoration, which can be a role, object or terminal. It can be understood that the root key restoration operation can be manually triggered by a role, such as a supplier operation and maintenance personnel, a customer site administrator or a hacker, etc., or it can be automatically triggered by a terminal, such as a management and control terminal or the cloud, etc. After receiving the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key can be located in all storage areas. That is, multiple root key shares of a combination of multiple target storage areas can meet the minimum root key share required to restore the energy storage root key, and multiple target storage areas and multiple root key authority parties are one-to-one corresponding. For example, in an implementable manner, assuming that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, and the root key splitting instruction synchronously indicates that the minimum number of shares for restoring the energy storage root key is 4, wherein the 7 root key shares are respectively stored in the storage areas of the root key authority parties that match them, specifically, root key share 1 is stored in the first storage area of the control terminal, root key share 2 is stored in the second storage area of the control terminal, root key share 3 is stored in the third storage area of the control terminal, root key share 4 is stored in the fourth storage area of the cloud, root key share 5 is stored in the fifth storage area of the cloud, root key share 6 is stored in the sixth storage area of the cloud, and root key share 7 is stored in the first storage area of the first associated terminal associated with the root key management object. Seven storage areas, the multiple target storage areas can be the first storage area, the second storage area, the third storage area and the fourth storage area, or the first storage area, the second storage area, the third storage area and the seventh storage area, or the first storage area, the second storage area, the fourth storage area and the fifth storage area, or the first storage area, the second storage area, the third storage area, the fourth storage area and the sixth storage area, etc. Therefore, without considering the access rights of the root key restorer to all storage areas, there can be multiple combinations of the multiple target storage areas, as long as the root key shares of the combined multiple target storage areas are at least the second root key shares.
[0044] As an example, step 206 includes: according to the root key restoration operation triggered by the root key restoration party, based on the amount of the second root key share required to restore the energy storage root key, locating multiple target storage areas required to restore the energy storage root key in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one, and the root key authority parties corresponding to different target storage areas may be the same or different.
[0045] Step 208, when it is detected that the root key restorer has access rights to multiple target storage areas, the energy storage root key is restored based on the target root key shares selected from the multiple target storage areas.
[0046] It should be noted that, since multiple root key shares are physically isolated through different storage areas, the root key restorer does not have the ability to access all storage areas, that is, any root key restorer cannot have the ability to extract root key shares in all combinations of multiple target storage areas, and thus it is necessary to detect the access rights of multiple target storage areas in different combinations of areas for the root key restorer. For example, in one practicable manner, assuming that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, the root key splitting instruction synchronously indicates that the minimum number of shares for restoring the energy storage root key is 4, the root key restorer is the management and control terminal, wherein the root key restorer has access rights to root key share 1, root key share 2 and root key share 3 to access its own storage area, and has root key share 7 to access the cloud storage area, then it is determined that the root key restorer has access rights to access multiple target storage areas, wherein the root key restorer's access rights to different storage areas can be set in advance based on the restorer identity information of the root key restorer. For example, when the root key restorer needs to access a storage area other than its own terminal, it can be detected based on the root key restorer's identity information whether the root key restorer is in the access whitelist of the terminal to which the storage area to be accessed belongs.
[0047] As an example, step 208 includes: when it is detected that the root key restoration party has access rights to multiple target storage areas, the target root key shares selected from the multiple target storage areas are sent to the hardware security module of the energy storage system, and the hardware security module is controlled to restore the multiple target root key shares to obtain the energy storage root key.
[0048] For example, in one practicable manner, when executing the key splitting process, the hardware security module can construct an m-1 degree polynomial to split the energy storage root key into multiple root key shares, where a root key share can be understood as a fixed Coordinates, where The value of comes from the data of local operation of the energy storage cabinet, operation and maintenance environment or cloud interaction under the specified rules, that is, the share generation data of different root key shares, The value of is calculated by polynomial. Assuming m is 4, it means that only when the root key restorer obtains 4 fixed After the coordinates are obtained and polynomial interpolation is performed, the hardware security module can successfully execute the root key recovery process and restore the energy storage root key.
[0049] In the root key management method of the above energy storage system, the control terminal of the energy storage system first performs real-time detection on the energy storage system, and after detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and the management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively, and the management authorities held by different root key authority parties are isolated from each other, and the multiple root key authority parties include the root key management object that manages the energy storage system, the root key user object that uses the energy storage system, and the control of the energy storage system. At least two of the four parties, namely, the terminal and the cloud providing the energy storage system cloud service, can realize splitting the energy storage root key into multiple root key shares managed by at least two root key authority parties related to the energy storage system, and then storing each root key share in a storage area managed by a respective matching root key authority party, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key, thereby storing the multiple root key shares in storage areas respectively managed by different root key authority parties, and then locating and restoring the energy storage root key in all storage areas according to the root key restoration operation triggered by the key restoration party The multiple target storage areas required are finally restored according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas. Since the root key shares that the multiple root key authority parties have management rights to are isolated from each other, and the root key shares corresponding to the amount of root key shares that any root key authority party can manage cannot be restored to obtain the energy storage root key alone, after receiving the root key restoration request, it is necessary to cooperate with at least two of the four root key management objects, root key use objects, management and control terminals, and the cloud to locate and restore the multiple target storage areas required for the energy storage root key. Finally, the energy storage root key can be restored by extracting multiple target root key shares from the multiple target storage areas managed by the root key authority parties, thereby avoiding the situation where a single root key authority party is attacked and the root key is leaked, and the purpose of securely managing the root key at the software level can be achieved, so that the hardware cost is often relatively high. At the same time, the root key that relies on a single hardware encryption is prone to the risk of leakage when the device is attacked. Therefore, the management effect of the root key management of the energy storage system is improved from the two dimensions of saving hardware cost and improving the security of root key management.
[0050] In one embodiment, Figure 2 As shown, the multiple root key shares include multiple root key management shares jointly managed by the management and control terminal and the root key management object and the root key usage shares used by the root key usage object; the energy storage root key is split into multiple root key shares, including:
[0051] Step 302, obtaining the share configuration information corresponding to the control terminal, the root key management object and the root key use object, and obtaining the permission level information corresponding to the control terminal, the root key management object and the root key use object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key;
[0052] It should be noted that in the process where only the management and control terminal, the root key management object and the root key management user object participate in the root key authority management together as the root key authority parties, the management and control terminal can simultaneously set the total amount of root key shares required to be split from the energy storage root key during the process of generating the key splitting instruction, as well as set in detail the amount of root key shares that can be managed by different root key authority parties.
[0053] As an example, step 302 includes: extracting the share configuration information commonly required by the management and control terminal, the root key management object and the root key usage object in the root key splitting instruction, and extracting the authority level information corresponding to the management and control terminal, the root key management object and the root key usage object in the root key splitting instruction, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key.
[0054] Step 304: split the energy storage root key into a plurality of preset root key shares according to the share configuration information;
[0055] As an example, step 304: control the hardware security module to split the energy storage root key into multiple preset root key shares identified by the share configuration information using a preset key splitting algorithm, wherein the share configuration information can specifically be 7, 8 or 9, etc. It can be understood that the preset root key share refers to the root key share that has not yet established a mapping relationship with any root key authority party.
[0056] Step 306, based on the share mapping relationship between the multiple preset root key shares and the authority level information, the multiple preset root key shares are divided to obtain multiple root key management shares and root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority party under the total root key share amount.
[0057] It should be noted that, due to the different security capabilities of different root key authority parties, different authority levels can be set for different root key authority parties based on different root key authority parties, and a share mapping relationship between different authority levels and preset root key shares can be established, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority party under the total root key share, that is, different authority levels correspond to different numbers of root key shares obtained by splitting. For example, in an implementable manner, all root key authority parties include a control terminal, a supplier who manages the energy storage root key, and a customer site administrator who uses the energy storage root key, wherein the authority levels corresponding to the control terminal and the customer site administrator are both identified as level 2, and the authority level corresponding to the supplier who manages the energy storage root key is identified as 3, and the 7 root key shares are configured in the order of 2, 3 and 2 to the control terminal, the supplier and the customer site administrator.
[0058] As an example, step 306 includes: according to the share mapping relationship between multiple preset root key shares and authority level information, a preset number of preset root key shares are divided for the management and control terminal, the root key management object and the root key usage object respectively, to obtain multiple root key management shares and root key usage shares.
[0059] In this embodiment, in an application scenario involving the participation of the control terminal, the root key management object and the root key user object in the energy storage root key management, if the control terminal needs to control the hardware security module to execute the energy storage root key splitting process, the total amount of root key shares required to be divided for the energy storage root key can be determined based on the share configuration information generated by the control terminal, so that the energy storage root key can be split into multiple preset root key shares. Furthermore, considering the different security protection capabilities of different root key authority parties, a share mapping relationship between the authority level information of different root key authority parties generated by the control terminal and the multiple preset root key shares can be established to clarify the root key share components of the second management authority that different root key authority parties should have, so that the multiple preset root key shares can be allocated in sequence under the consideration of the security dimension for the purpose of authority management by different root key authority parties. Therefore, while improving the management effect of the root key management of the energy storage system, the security of the root key management of the energy storage system is further improved.
[0060] In one embodiment, the plurality of root key management shares include a first root key management share managed by the management and control terminal; the plurality of preset root key shares are divided according to a share mapping relationship between the preset root key share and the authority level information to obtain a root key management share and a plurality of root key usage shares, including:
[0061] According to the share mapping relationship, the first root key management share component corresponding to the management and control terminal is determined; the system authentication information and system installation information generated by the management and control terminal in the process of managing the energy storage system are obtained; the first share generation data is extracted from the system authentication information, and the second share generation data is extracted from the system installation information; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is obtained by dividing the first root key management share among multiple preset root key shares.
[0062] It should be noted that the first root key management share managed by the control and management terminal can be completely stored locally in the control and management terminal, or a part of the first root key management share can be stored locally in the control and management terminal, and the other part of the first root key management share can be stored in the cloud, and the first root key management share of this part can be obtained through the interaction between the control and management terminal and the cloud. At this time, the control and management terminal and the cloud both serve as root key authority parties, that is, multiple root key authority parties include the control and management terminal, the cloud, the root key management object and the root key user object.
[0063] It should be noted that, through the share mapping relationship, the first root key management share component managed by the control terminal can be queried, which can be obtained by identifying the specific field in the root key splitting instruction. For example, in an implementable method, assuming that the identified field is 2, the first root key management share component managed by the control terminal is 2, wherein the system authentication information is used to characterize the relevant content of the cloud authentication process when the energy storage system is first online, the first share generation data can specifically be the first random value generated for the first online, the system installation information is used to characterize the relevant content of the energy storage system during the installation process, which can specifically be the system installation log, and the second share generation data can specifically be the installation time in the system installation log.
[0064] As an example, the first root key management share component managed by the control terminal is queried in a share mapping table constructed based on the share mapping relationship; the system installation information generated by the control terminal during the installation of the energy storage system is obtained, and the system authentication information sent by the cloud to the control terminal during the authentication of the energy storage system to the cloud is obtained; the installation time is extracted from the system installation information as the first share generation data, and the random value is extracted from the system authentication information as the second share generation data; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is divided into multiple preset root key shares.
[0065] In this embodiment, in the process of dividing the first root key management share managed by the control terminal, the divided first root key management share is divided into a first root key management share and a second root key management share, wherein the management authority of the first root key management share is held by the control terminal, and the management authority of the second root key management share is held by the cloud, that is, the first root key management share managed by the control terminal is further divided into root key shares jointly managed by the control terminal and the cloud, and different operation information of the energy storage system is used to generate share generation data respectively, thereby ensuring the accurate division of the first root key management share managed by the control terminal, thereby laying a foundation for improving the management effect of the root key management of the energy storage system.
[0066] In one embodiment, the plurality of root key management shares include a second root key management share managed by a root key management object; the plurality of preset root key shares are divided according to a share mapping relationship between the preset root key share and the permission level information to obtain a root key management share and a plurality of root key usage shares, including:
[0067] According to the share mapping relationship, determine the second root key management share component corresponding to the root key management object; obtain the system hard-coded information set by the root key management object on the energy storage system; extract the third share generation data from the system hard-coded information; according to the first query information input by the root key management object, query and obtain the fourth share generation data; according to the second root key management share component, the third share generation data and the fourth share generation data, divide the second root key management share among multiple preset root key shares.
[0068] It should be noted that, through the share mapping relationship, the second root key management share component managed by the root key management object can be queried, the system hard-coded information is used to characterize sensitive parameters in the source code, which can be passwords or configuration parameters, etc. The first query information is used to query the non-public technical files stored in the management and control terminal. It can be understood that both the system hard-coded information and the first query information are independently set by the root key management object. The storage rules are private and cannot be known by other objects. Then, in the share generation data acquisition stage corresponding to the second root key management share, only the root key management object can obtain specific third share generation data and fourth share generation data, wherein the third share generation data can be specifically a hard-coded value, and the fourth share generation data can be specifically a second random value stored in the non-public technical file.
[0069] As an example, a second root key management share component managed by a root key management object is queried in a share mapping table constructed based on a share mapping relationship; system hard-coded information set by the root key management object on the energy storage system is obtained; the hard-coded value stored in the system hard-coded information is used as the third share generation data; the first query information input by the root key management object is used as an index to locate the non-public technical file, and the second random value stored in the non-public technical file is used as the fourth share generation data, wherein the first query information can specifically be query path information for querying the second random value; according to the second root key management share component, the third share generation data and the fourth share generation data, the second root key management share is obtained by dividing the plurality of preset root key shares.
[0070] In this embodiment, in the process of dividing the second root key management share managed by the root key management object, the divided second root key management share is divided into a third root key management share and a fourth root key management share, wherein the third share generation data for generating the third root key management share is hard-coded in the source code by the root key management object, and cannot be directly read during the actual operation of the energy storage system. It can only be returned by the root key management object after access through a specific access interface to generate the fourth share generation data for the fourth root key management share, and the query path information for querying the second random value is solely known by the root key management object. Therefore, the third share generation data and the fourth share generation data are both private, thereby ensuring the precise division of the second root key management share managed by the root key management object, and thus laying a foundation for improving the management effect of the root key management of the energy storage system.
[0071] In one embodiment, according to the share mapping relationship between the preset root key share and the permission level information, multiple preset root key shares are divided to obtain a root key management share and multiple root key use shares, including:
[0072] According to the share mapping relationship, determine the root key usage share component corresponding to the root key usage object; obtain the system login information set by the root key usage object on the energy storage system; extract the fifth share generation data from the system login information; according to the key generation time of the energy storage root key, query the target battery status information associated with the key generation time in the battery status information of the energy storage system; generate the sixth share generation data according to the target battery status information; according to the root key usage share component, the fifth share generation data and the sixth share generation data, divide the root key usage share among multiple preset root key shares to obtain the root key usage share.
[0073] It should be noted that, through the share mapping relationship, the root key usage share component managed by the root key management object can be queried, wherein the system login information is used to characterize the login content of the client system that logs into the energy storage system, and may specifically include a login password and a login welcome message, etc. It can be understood that the system login information is usually used to prevent the system service from being counterfeited, and is a measure for users to identify the authenticity of the service. The system login information is entered by the root key usage object in the account management and stored in the database. The fifth share generation data may specifically be a first fixed value set in the system login information. The battery status information is used to characterize the operating status of the battery, and may specifically be the health of the battery cluster or the average voltage of the battery cluster, etc. Since the battery status information will change over time, but at a certain point in time, it has a certain value, and then this feature can be used to combine the battery status information of the energy storage system with the root key splitting process, which is responsible for generating data as part of the root key share. In the process of splitting the energy storage root key, in order to split the root key usage share, the control terminal will first obtain the battery health state (State of Health (SOH) curve, and although the battery health status curve will have certain differences with different algorithms, no matter in the aging curve table lookup or real-time correction query, there must be only one value for the same battery cell or corresponding cluster statistical information at the same time. Therefore, by setting the specific association between the generation time of the energy storage root key and the battery health status curve, the query can obtain the unique target battery status information, and then rely on the target battery status information to generate the sixth share generation data. For example, in an implementable method, assuming that the key generation time point A is later than the first collection time of the battery SOH curve, the battery status information is the SOH curve at each The SOH value collected at the collection time point can then default to the SOH value corresponding to the collection time point closest to the key generation time A as the target battery status information, and generate the sixth share generation data based on the SOH value according to the preset rules. For example, in another feasible method, assuming that the key generation time point is B, the average voltage of the battery cluster in the real-time curve collected at the key generation time point B can be used as the battery status information, and the sixth share generation data is generated based on the average voltage according to the preset rules. It can be understood that the preset rules for generating the sixth share generation data based on the target battery status information can be hard-coded in the database or stored in the database in advance as source code.
[0074] As an example, a third root key management share component used by a root key usage object is queried in a share mapping table constructed based on a share mapping relationship; system login information set by the root key usage object on the energy storage system is obtained; a second fixed value is extracted from the system login information as fifth share generation data; multiple information collection time points of the battery status information of the energy storage system are obtained, and the multiple information collection time points are respectively subtracted from the key generation time point to obtain multiple time difference values, and the battery status information corresponding to the information collection time point with the smallest time difference value among the multiple time difference values is used as the target battery status information; the third fixed value is extracted from the target battery status information as the sixth share generation data; and according to the root key usage share component, the fifth share generation data and the sixth share generation data, the root key usage share is obtained by dividing the multiple preset root key shares.
[0075] In this embodiment, in the process of dividing the root key usage share managed by the root key usage object, the divided root key usage share is divided into a first part of the root key usage share and a second part of the root key usage share, wherein the fifth share generation data of the first part of the root key usage share is generated by extracting from the system login information independently set by the root key usage object, and the sixth share generation data of the second part of the root key usage share is generated by combining the uniqueness of the battery status information at a single point in time, and is finally generated after the root key usage object alone knows the preset query rules and generation rules. Therefore, the fifth share generation data and the sixth share generation data are both private, thereby ensuring the accurate division of the root key usage share managed by the root key usage object, thereby laying a foundation for improving the management effect of the root key management of the energy storage system.
[0076] In one practicable manner, referring to Figure 3 , Figure 3The figure is a schematic diagram of the splitting process of the energy storage root key, wherein the root key shares obtained by splitting the energy storage root key may specifically be root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6 and root key share x7. In combination with the above embodiment, the first share generation data of the root key share x1 is obtained by cloud transmission when the hardware is first put on the cloud, wherein the cloud is persistently stored in the database, and the first share generation data extracted from the system authentication information may be extracted in a manner specified by the cloud according to the device identification rule, or may be an ordered number automatically calculated according to the time; the second share generation data of the root key share x2 is extracted at the installation time of the system installation information, and can only be obtained locally. It can be understood that it can be obtained when the customer site administrator has the local file read permission, and the security time is usually stored in the installation log file Or in the database, the operation and maintenance stage usually attempts to obtain the installation time for positioning; the third root key share generation data of root key share x3 is hard-coded in the source code and held by the root key management object. It only supports returning after accessing a specific interface through the key splitting process; the fourth root key share generation data of root key share x4 and root key share x5 can be extracted from different files in the non-public technical folder, and the query path is only known to the root key management object; the sixth share generation data of root key share x6 is obtained in combination with the battery status information of the energy storage system, and the seventh share generation data of root key share x7 is set by the root key user object in the system login information of the energy storage system, and the acquisition method is only known to the root key user object. In this way, the energy storage root key can be split into 7 root key shares, stored in the storage areas of different terminals, and managed by the corresponding root key authority.
[0077] In an practicable manner, in one embodiment, each root key share is stored in a storage area managed by a respective matching root key authority, including:
[0078] Selection step: select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in a storage area managed by the root key authority identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0079] As an example, the selection step is: randomly selecting any one root key share from multiple root key shares as the target root key share; determining the storage area managed by the root key authority that stores the target root key share based on the share identification information of the target root key share, and storing the target storage root key share in the storage area, and returning to the execution step: randomly selecting any one root key share from multiple root key shares as the target root key share.
[0080] In this embodiment, the root key authority party and its storage area that manages different root key shares are determined through the share identification information corresponding to different root key shares, and all root key shares are stored in one-to-one corresponding storage areas, so that in the subsequent energy storage root key restoration scenario, different root key restoration parties can extract the corresponding root key shares to restore the energy storage root key based on their access rights, thereby further laying a foundation for improving the management effect of the root key management of the energy storage system.
[0081] In one embodiment, according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, including:
[0082] Extract the identity information of the root key restorer in the root key restore operation; determine the first target storage area in all storage areas that stores the first root key management share; generate share path information of the target root key usage share required to restore the energy storage root key based on the identity information; determine the second target storage area in all storage areas that stores the target root key usage share based on the share path information; and use the first target storage area and the second target storage area together as multiple target storage areas.
[0083] It should be noted that, through the identity information of the root key restorer, a part of the root key share that can be restored by the root key restorer can be determined, so that the share path information for restoring the part of the root key share can be further generated, so as to extract the part of the root key share from the designated storage area for restoring the energy storage root key, and in combination with another part of the root key share managed by the management and control terminal, the energy storage root key is successfully restored. For example, in an implementable manner, assuming that the energy storage root key generated by the hardware security module is The root key splitting instruction indicates that the number of shares of the energy storage root key split is 4, wherein the storage area of the first associated terminal associated with the root key management object stores two root key shares, and the storage area of the control terminal stores three root key shares. Then, four root key shares are randomly selected from the five root key shares to restore the energy storage root key, wherein the share path information is used to identify different paths storing different root key shares in the storage area of the first associated terminal, and the root key restoration operation can be manually triggered or automatically triggered by the root key restoration party.
[0084] As an example, the identity information of the root key restorer is extracted in the root key restoration operation; based on the root key restoration operation, a query is automatically triggered for the first target storage area storing the first root key management share in all storage areas; based on the identity information and the restoration information input by the root key restorer, the share path information of the target root key usage share required to restore the energy storage root key is generated; using the share path information as an index, a query is performed for the second target storage area storing the target root key usage share in all storage areas; and the first target storage area and the second target storage area are collectively used as multiple target storage areas.
[0085] In this embodiment, through the collaboration of the management and control terminal and the root key restoration party, the first target storage area and the second target storage area of the root key share required to restore the energy storage root key are located in all storage areas, so that after the root key restoration party triggers the root key restoration operation, the purpose of accurately locating the target storage area from which the energy storage root key can be restored can be achieved, thereby laying the foundation for the subsequent accurate restoration of the energy storage root key.
[0086] In one practicable manner, referring to Figure 4 , Figure 4 The following are schematic diagrams showing the scenarios of different root key restoration parties performing energy storage root key restoration, where (a) is a schematic diagram of the scenario of the root key management object performing root key restoration, (b) is a schematic diagram of the scenario of the root key use object performing root key restoration, and (c) is a schematic diagram of the scenario of the root key theft object performing root key restoration. Assume that the energy storage root key is Figure 3 As shown, there are 7 root key shares, namely root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6 and root key share x7. Since the root key management object can successfully restore 5 of the 7 root key shares (root key share x1, root key share x2, root key share x3, root key share x4 and root key share x5), the root key management object can accurately restore the energy storage root key; since the root key usage object can successfully restore the 7 root keys There are 4 root key shares in the share (root key share x1, root key share x2, root key share x6 and root key share x7), so the root key user object can accurately restore the energy storage root key; because the root key theft object can neither obtain root key share x3, root key share x4 and root key share x5, nor can it obtain root key share x6 and root key share x7, and even cannot invade the cloud to obtain root key share x1, and thus cannot have access to the storage area of the 4 root key shares, so it cannot successfully restore the energy storage root key.
[0087] In one embodiment, determining, according to the share path information, a second target storage area storing the target root key usage share in all storage areas includes:
[0088] According to the identity information, the restoration level information of the root key restorer is queried; according to the restoration level information, a second target storage area storing the target root key usage share is determined among all storage areas.
[0089] It should be noted that different root key restorers have different restoration capabilities. Although more root key shares used for energy storage root key restoration does not mean an increase in restoration capabilities, it can improve the robustness of restoring the energy storage root key to a certain extent. For example, root key restorer y1 can only obtain four root key shares, while root key restorer y2 can obtain six root key shares. Therefore, even if root key restorer y2 cannot obtain any two of the six root key shares, it can still guarantee the share level of the energy storage root key. Therefore, considering the identities of different root key restorers, different restoration levels can be opened for different root key restorers. For example, in an implementable manner, a root key restorer with a high authority level can know all second target storage areas storing the target root key usage share, while a root key restorer with a low authority level can only know part of the second target storage areas storing the target root key usage share.
[0090] As an example, the root key restoration level information is queried with the identity information as an index; based on the restoration level information, all storage areas that are selected to store the target root key usage share are used as the second target storage area.
[0091] In this embodiment, in the process of determining the second target storage area for storing the target root key usage share, different restoration levels can be appropriately configured for the root key restorer based on the identity of the root key restorer, so that the root key restorer can obtain different amounts of root key shares for energy storage root key restoration, so as to achieve dynamic control of the restoration authority of different root key restorers, thereby improving the management flexibility of the root key management of the energy storage system.
[0092] It should be understood that, although the steps in the flowcharts involved in the above embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0093] Based on the same inventive concept, the embodiment of the present application also provides a root key management device for an energy storage system for implementing the root key management method for an energy storage system involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in the embodiments of the root key management device for one or more energy storage systems provided below can refer to the limitations of the root key management method for the energy storage system above, and will not be repeated here.
[0094] In an exemplary embodiment, Figure 5 As shown, a root key management device for an energy storage system is provided, which is applied to a control terminal of the energy storage system, including: a splitting module 401, a storage module 402, a determination module 403 and a restoration module 404, wherein:
[0095] A splitting module 401 is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates an energy storage root key, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold the second management authority of the root key shares corresponding to each other, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key user object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system;
[0096] A storage module 402 is used to store each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key;
[0097] The determination module 403 is used to locate multiple target storage areas required for restoring the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restoration party, wherein the multiple target storage areas correspond to the multiple root key authority parties one by one;
[0098] The restoration module 404 is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to access multiple target storage areas.
[0099] In one embodiment, the plurality of root key shares include a plurality of root key management shares jointly managed by the management and control terminal and the root key management object and a root key usage share used by the root key usage object; the splitting module 401 is further used to:
[0100] Obtain the share configuration information corresponding to the management and control terminal, the root key management object and the root key usage object, and obtain the authority level information corresponding to the management and control terminal, the root key management object and the root key usage object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; according to the share configuration information, split the energy storage root key into multiple preset root key shares; according to the share mapping relationship between the multiple preset root key shares and the authority level information, divide the multiple preset root key shares to obtain multiple root key management shares and root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority under the total amount of root key shares.
[0101] In one embodiment, the plurality of root key management shares include a first root key management share managed by the management and control terminal; the splitting module 401 is further used to:
[0102] According to the share mapping relationship, the first root key management share component corresponding to the management and control terminal is determined; the system authentication information and system installation information generated by the management and control terminal in the process of managing the energy storage system are obtained; the first share generation data is extracted from the system authentication information, and the second share generation data is extracted from the system installation information; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is obtained by dividing the first root key management share among multiple preset root key shares.
[0103] In one embodiment, the plurality of root key management shares include a second root key management share managed by a root key management object; the split module 401 is further configured to:
[0104] According to the share mapping relationship, determine the second root key management share component corresponding to the root key management object; obtain the system hard-coded information set by the root key management object on the energy storage system; extract the third share generation data from the system hard-coded information; according to the first query information input by the root key management object, query and obtain the fourth share generation data; according to the second root key management share component, the third share generation data and the fourth share generation data, divide the second root key management share among multiple preset root key shares.
[0105] In one embodiment, the splitting module 401 is further used to:
[0106] According to the share mapping relationship, determine the root key usage share component corresponding to the root key usage object; obtain the system login information set by the root key usage object on the energy storage system; extract the fifth share generation data from the system login information; according to the key generation time of the energy storage root key, query the target battery status information associated with the key generation time in the battery status information of the energy storage system; generate the sixth share generation data according to the target battery status information; according to the root key usage share component, the fifth share generation data and the sixth share generation data, divide the root key usage share among multiple preset root key shares to obtain the root key usage share.
[0107] In one embodiment, the storage module 402 is further configured to:
[0108] Selection step: select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in a storage area managed by the root key authority identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0109] In one embodiment, the determination module 403 is further configured to:
[0110] Extract the identity information of the root key restorer in the root key restore operation; determine the first target storage area in all storage areas that stores the first root key management share; generate share path information of the target root key usage share required to restore the energy storage root key based on the identity information; determine the second target storage area in all storage areas that stores the target root key usage share based on the share path information; and use the first target storage area and the second target storage area together as multiple target storage areas.
[0111] In one embodiment, the determination module 403 is further configured to:
[0112] According to the identity information, the restoration level information of the root key restorer is queried; according to the restoration level information, a second target storage area storing the target root key usage share is determined among all storage areas.
[0113] Each module in the root key management device of the energy storage system can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.
[0114] In an exemplary embodiment, an energy storage system is provided, the energy storage system includes a management and control terminal of the energy storage system, and the internal structure diagram of the management and control terminal of the energy storage system can be as follows: Figure 6 As shown. The management and control terminal of the energy storage system includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the management and control terminal of the energy storage system is used to provide computing and control capabilities. The memory of the management and control terminal of the energy storage system includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the management and control terminal of the energy storage system is used to exchange information between the processor and external devices. The communication interface of the management and control terminal of the energy storage system is used to communicate with an external terminal in a wired or wireless manner, and the wireless method can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a root key management method for an energy storage system is implemented. Those skilled in the art can understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the scheme of the present application, and does not constitute a limitation on the control and management terminal of the energy storage system to which the scheme of the present application is applied. The control and management terminal of the specific energy storage system may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0115] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0116] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0117] The above embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A root key management method for an energy storage system, characterized in that: A control terminal applied to an energy storage system, the method comprising: After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, the multiple root key authority parties hold second management authority of their respective corresponding root key shares, the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; Storing each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key; According to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one by one; When it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
2. The method according to claim 1, characterized in that The multiple root key shares include multiple root key management shares jointly managed by the management and control terminal and the root key management object and a root key usage share used by the root key usage object; The step of splitting the energy storage root key into a plurality of root key shares includes: Obtain the share configuration information corresponding to the control terminal, the root key management object, and the root key usage object, and obtain the permission level information corresponding to the control terminal, the root key management object, and the root key usage object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; According to the share configuration information, split the energy storage root key into a plurality of preset root key shares; According to the share mapping relationship between the multiple preset root key shares and the authority level information, the multiple preset root key shares are divided to obtain the multiple root key management shares and the root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any one of the root key authority parties under the total root key shares.
3. The method according to claim 2, characterized in that The multiple root key management shares include a first root key management share managed by the management and control terminal; the multiple preset root key shares are divided according to the share mapping relationship between the preset root key share and the authority level information to obtain the root key management share and the multiple root key usage shares, including: Determine, according to the share mapping relationship, a first root key management share component corresponding to the control terminal; Acquire system authentication information and system installation information generated by the control terminal in the process of managing the energy storage system; extracting first share generation data from the system authentication information, and extracting second share generation data from the system installation information; The first root key management share is obtained by dividing the first root key management share among the multiple preset root key shares according to the first root key management share component, the first share generation data and the second share generation data.
4. The method according to claim 2, characterized in that: The multiple root key management shares include a second root key management share managed by the root key management object; and the dividing the multiple preset root key shares according to the share mapping relationship between the preset root key share and the authority level information to obtain the root key management share and the multiple root key usage shares includes: Determine, according to the share mapping relationship, a second root key management share component corresponding to the root key management object; Acquire system hard-coded information set by the root key management object on the energy storage system; extracting third share generation data from the system hard-coded information; querying and obtaining fourth share generation data according to the first query information input by the root key management object; The second root key management share is obtained by dividing the plurality of preset root key shares according to the second root key management share component, the third share generation data and the fourth share generation data.
5. The method according to claim 2, characterized in that: The dividing the plurality of preset root key shares according to the share mapping relationship between the preset root key shares and the authority level information to obtain the root key management share and the plurality of root key usage shares includes: Determine, according to the share mapping relationship, a root key usage share component corresponding to the root key usage object; Obtaining system login information set by the root key usage object on the energy storage system; Extracting fifth share generation data from the system login information; According to the key generation time of the energy storage root key, querying the target battery status information associated with the key generation time in the battery status information of the energy storage system; generating sixth share generation data according to the target battery status information; The root key usage share is obtained by dividing the root key usage share among the multiple preset root key shares according to the root key usage share component, the fifth share generation data and the sixth share generation data.
6. The method according to claim 1, characterized in that The storing of each root key share in a storage area managed by a respective matching root key authority includes: Selection step: selecting a target root key share from the multiple root key shares; Obtaining share identification information of the target root key share; The target root key share is stored in a storage area managed by the root key authority identified by the share identification information, and the selection step is returned to be executed until all root key shares are selected.
7. The method according to claim 3, characterized in that The root key restoration operation triggered by the root key restoration party locates multiple target storage areas required for restoring the energy storage root key in all storage areas, including: Extracting the identity information of the root key restoration party in the root key restoration operation; Determine a first target storage area among all the storage areas for storing the first root key management share; Generate, based on the identity information, share path information of the target root key usage share required to restore the energy storage root key; Determine, according to the share path information, a second target storage area storing the target root key usage share in all the storage areas; The first target storage area and the second target storage area are collectively used as the plurality of target storage areas.
8. The method according to claim 7, characterized in that The determining, according to the share path information, a second target storage area in all the storage areas storing the target root key usage share comprises: According to the identity information, query the restoration level information of the root key restoration party; According to the restoration level information, a second target storage area storing the target root key usage share is determined among all the storage areas.
9. A root key management device for an energy storage system, characterized in that: A control terminal applied to an energy storage system, the device comprising: A splitting module is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates an energy storage root key, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold the second management authority of the root key shares corresponding to each other, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; A storage module, used to store each root key share in a storage area managed by a respective matching root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key; A determination module, configured to locate, in all storage areas, a plurality of target storage areas required for restoring the energy storage root key according to a root key restoration operation triggered by a root key restoration party, wherein the plurality of target storage areas correspond one to one to the plurality of root key authority parties; The restoration module is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas.
10. An energy storage system, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Information management method and device, electronic equipment and storage medium
CN113468584A
Root key management system, backup method, recovery method, device and electronic equipment
CN115549907A
Secure storage method and device of power grid privilege access credential and storage medium
CN119358003A
Encryption key management
US20130177157A1