Root key management method, device and energy storage system of an energy storage system
By splitting the energy storage root key into multiple shares and managing it by multiple permission parties, the high cost and easy leakage problems caused by single hardware management are solved, and a more secure and efficient root key management is achieved.
Patent Information
- Application Number
- CN202510577923.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-06
AI Technical Summary
The root key management method of existing energy storage systems relies on a single hardware management, resulting in high hardware costs and vulnerability to attacks and the risk of leakage, and poor management results.
Split the energy storage root key into multiple root key shares, and is managed and stored by multiple permission parties. Through collaborative operations, the root key is restored to ensure that the management rights of each permission party are isolated from each other and avoid leakage of a single permission party.
It improves the security and management effect of root key management of energy storage systems, reduces hardware costs, and increases the difficulty of resisting attacks.
Smart Images

Figure CN120105403B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of information security technology, and in particular, to a method and device for managing a root key of an energy storage system, and an energy storage system. Background Art
[0002] With the continuous development of technology, energy storage systems have been widely used in many fields. To ensure the security of energy storage data in the energy storage system, a key protection system is usually set up for the energy storage system. In the key management protection system, the root key is used to derive encryption keys and integrity protection keys. Therefore, it is very necessary to manage the root key of the energy storage system securely.
[0003] Currently, in the process of managing the root key of the energy storage system, the storage of the root key is usually completed by setting up physical hardware such as an HSM (Hardware Security Module) or an encrypted USB (Universal Serial Bus) drive. However, the hardware cost is often relatively high. At the same time, the root key managed by a single piece of hardware is prone to the risk of leakage in the event of an attack on the device. Therefore, the management effect of the current root key management of the energy storage system is poor. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a method and device for managing the root key of an energy storage system, and an energy storage system, which can improve the management effect of the root key management of the energy storage system.
[0005] In a first aspect, the present application provides a method for managing a root key of an energy storage system, which is applied to a control terminal of the energy storage system, and includes:
[0006] After detecting that the energy storage system generates an energy storage root key, splitting the energy storage root key into multiple root key shares, where the first management authority of the energy storage root key is jointly held by multiple root key authorities that manage the energy storage system, and the multiple root key authorities hold the second management authorities of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other. The multiple root key authorities include at least two of a root key management object that manages the energy storage system, a root key usage object that uses the energy storage system, the control terminal of the energy storage system, and a cloud that provides cloud services for the energy storage system;
[0007] Storing each root key share in a storage area managed by its respective matching root key authority, where the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key;
[0008] According to the root key restoration operation triggered by the root key restorer, locate multiple target storage areas required to restore the energy storage root key in all storage areas, where the multiple target storage areas correspond one-to-one with the multiple root key authorities;
[0009] When it is detected that the root key restorer has the access right to access the multiple target storage areas, restore the energy storage root key according to the target root key shares selected from the multiple target storage areas.
[0010] In a second aspect, the present application further provides a root key management device for an energy storage system, which is applied to a control terminal of the energy storage system and includes:
[0011] A splitting module, configured to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates the energy storage root key, where the first management right of the energy storage root key is jointly held by multiple root key authorities managing the energy storage system, and the multiple root key authorities hold the second management rights of their respective corresponding root key shares, and the multiple second management rights are isolated from each other. The multiple root key authorities include at least two of a root key management object managing the energy storage system, a root key usage object using the energy storage system, the control terminal of the energy storage system, and a cloud end providing cloud services for the energy storage system;
[0012] A storage module, configured to store each root key share in a storage area managed by its respective matching root key authority, where the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key;
[0013] A determination module, configured to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restorer, where the multiple target storage areas correspond one-to-one with the multiple root key authorities;
[0014] A restoration module, configured to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restorer has the access right to access the multiple target storage areas.
[0015] In a third aspect, the present application further provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0016] After detecting that the energy storage system generates an energy storage root key, split the energy storage root key into multiple root key shares. Among them, the first management right of the energy storage root key is jointly held by multiple root key authorities that manage the energy storage system. The multiple root key authorities hold the second management rights corresponding to their respective root key shares, and the multiple second management rights are isolated from each other. The multiple root key authorities include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. Store each root key share in the storage area managed by the corresponding root key authority that matches it, where the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key. According to the root key restoration operation triggered by the root key restorer, locate multiple target storage areas required to restore the energy storage root key in all storage areas, where the multiple target storage areas correspond one-to-one with the multiple root key authorities. When it is detected that the root key restorer has the access right to access the multiple target storage areas, restore the energy storage root key according to the target root key shares selected in the multiple target storage areas.
[0017] In a fourth aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0018] After detecting that the energy storage system generates an energy storage root key, split the energy storage root key into multiple root key shares. Among them, the first management right of the energy storage root key is jointly held by multiple root key authorities that manage the energy storage system. The multiple root key authorities hold the second management rights corresponding to their respective root key shares, and the multiple second management rights are isolated from each other. The multiple root key authorities include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. Store each root key share in the storage area managed by the corresponding root key authority that matches it, where the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key. According to the root key restoration operation triggered by the root key restorer, locate multiple target storage areas required to restore the energy storage root key in all storage areas, where the multiple target storage areas correspond one-to-one with the multiple root key authorities. When it is detected that the root key restorer has the access right to access the multiple target storage areas, restore the energy storage root key according to the target root key shares selected in the multiple target storage areas.
[0019] Fifth aspect, the present application further provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0020] After detecting that the energy storage system generates an energy storage root key, splitting the energy storage root key into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties managing the energy storage system, the multiple root key authority parties hold the second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other. The multiple root key authority parties include at least two of a root key management object managing the energy storage system, a root key usage object using the energy storage system, a control terminal of the energy storage system, and a cloud end providing cloud services for the energy storage system; storing each root key share in a storage area managed by its respective matching root key authority party, wherein the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key; positioning multiple target storage areas required to restore the energy storage root key in all storage areas according to a root key restoration operation triggered by a root key restoration party, wherein the multiple target storage areas and the multiple root key authority parties correspond one by one; and restoring the energy storage root key according to the target root key shares selected in the multiple target storage areas when it is detected that the root key restoration party has the access authority to access the multiple target storage areas.
[0021] The above root key management method, device and energy storage system for an energy storage system. First, the control terminal of the energy storage system performs real-time detection on the energy storage system. After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares. Among them, the management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system. The management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively. The management authorities held by different root key authority parties are isolated from each other. The multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. That is, it can be realized that the energy storage root key is split into multiple root key shares managed by at least two root key authority parties related to the energy storage system. Then, each root key share is stored in the storage area managed by the respective matching root key authority party. Among them, the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key. Thus, multiple root key shares are respectively stored in the storage areas with management authority by different root key authority parties. Then, according to the root key restoration operation triggered by the key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas. Finally, when it is detected that the key restoration party has the access authority to access multiple target storage areas, the energy storage root key is restored according to the target root key shares selected in the multiple target storage areas. Since the root key shares with management authority by multiple root key authority parties are isolated from each other, and the root key shares corresponding to the amount of root key shares that any root key authority party can manage cannot be used to restore the energy storage root key alone. Therefore, after receiving the root key restoration request, at least two of the root key management object, the root key usage object, the control terminal, and the cloud need to cooperate to locate multiple target storage areas required to restore the energy storage root key. Finally, the energy storage root key can be restored by extracting multiple target root key shares from multiple target storage areas managed by root key authority parties. This can avoid the situation of root key leakage due to a single root key authority party being attacked. That is, the purpose of securely managing the root key at the software level can be achieved. Therefore, it overcomes the technical defect that the hardware cost is often relatively high. At the same time, the root key relying on single hardware encryption is prone to leakage risk when the device is attacked. Therefore, the management effect of managing the root key of the energy storage system is improved. Description of the Drawings
[0022] To more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the drawings required for the description of the embodiments or the related art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0023] Figure 1 It is a schematic flowchart of the root key management method for an energy storage system in an embodiment.
[0024] Figure 2 It is a schematic flowchart of the root key management method for an energy storage system in another embodiment.
[0025] Figure 3 It is a schematic flowchart of the splitting process of the energy storage root key for the root key management method of the energy storage system in another embodiment.
[0026] Figure 4 It is a schematic diagram of the scenario for restoring the energy storage root key by different root key restoration methods for the root key management method of the energy storage system in another embodiment.
[0027] Figure 5 It is a structural block diagram of the root key management device for an energy storage system in an embodiment.
[0028] Figure 6 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0029] In order to make the purpose, technical solutions and advantages of the present application clearer, the following further details the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0030] First, it should be understood that an ESS (Energy Storage System) refers to a system that stores energy in a certain form through a specific medium or device and releases it in a specific form when needed. To ensure the security of the stored energy data in the energy storage system, a hardware security module is usually deployed in the energy storage system to store the root key. Among them, the root key is at the highest level in the key protection system and is used to generate and manage the next-level keys, such as the master key and the working key, etc. By setting the root key, it is possible to provide early protection for each unit and battery pack inside the energy storage system, thereby ensuring the secure storage and management of the key. Currently, the root key is often stored in an HSM or a trusted execution environment and is dynamically updated when necessary to serve scenarios such as data transmission, firmware update, and status monitoring of the energy storage system. However, for the highly competitive energy storage industry, using hardware such as an HSM to manage the root key often increases the hardware cost. At the same time, since the root key is managed by relying on a single piece of hardware, there is still a risk of leakage in the event of an attack on the device. Therefore, whether from the perspective of management cost or management security, the current management effect of the root key management of the energy storage system is not good. Therefore, there is an urgent need for a root key management method for an energy storage system that can improve the management effect of the root key of the energy storage system.
[0031] In one embodiment, as Figure 1As shown, a root key management method for an energy storage system is provided. In this embodiment, taking the application of this method to the control terminal of the energy storage system as an example, the control terminal of the energy storage system refers to the terminal deployed at the user side of the energy storage system, which can both collect data at the user side of the energy storage system and perform interactive control on the user side of the energy storage system. Among them, the user side of the energy storage system refers to the deployment site of the energy storage system on the user side, which can be specifically composed of energy storage cabinets, energy management systems, communication devices, and the control terminal of the energy storage system, etc. The control device of the energy storage system can specifically be a personal computer, laptop, smartphone, tablet computer, etc. The control terminal of the energy storage system monitors the energy storage system. It can be understood that during the process of deploying the energy storage system by the operation and maintenance personnel at the control terminal of the energy storage system, an energy storage root key is dynamically generated in the hardware security module of the energy storage system, and then an encryption key and an integrity protection key are derived based on the energy storage root key. Finally, the above keys are used to ensure the secure transmission and storage of the relevant data of the energy storage system. The control terminal of the energy storage system includes a splitting module, a storage module, a determination module, and a restoration module. The splitting module is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates the energy storage root key. Among them, the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and multiple root key authority parties hold the second management authority of their respective corresponding root key shares. The multiple second management authorities are isolated from each other. The multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. The storage module is used to store each root key share in the storage area managed by its respective matching root key authority party. Among them, the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key. The determination module is used to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restoration party. Among them, the multiple target storage areas correspond one-to-one with the multiple root key authority parties. The restoration module is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when detecting that the root key restoration party has the access authority to access the multiple target storage areas. It can be understood that during the process of managing the root key of the energy storage system, through the information interaction among the splitting module, the storage module, the determination module, and the restoration module, first, after receiving the energy storage root key, the energy storage root key is split into multiple root key shares, and at least two of the root key management object, the root key usage object, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system hold the management authorities of different root key shares. Since the root key shares with management authorities held by multiple root key authority parties are isolated from each other, and the root key shares corresponding to the amount of root key shares that any root key authority party can manage cannot be used to restore the energy storage root key alone,Furthermore, after receiving a root key restoration request, it is necessary to cooperate with at least two of the root key management object, root key usage object, control terminal, and cloud to locate multiple target storage areas required for restoring the energy storage root key. Finally, by extracting multiple target root key shares from multiple target storage areas managed by the root key authority parties, the energy storage root key can be restored, thus avoiding the situation of root key leakage due to a single root key authority party being attacked. Therefore, the root key management effect of the energy storage system is improved. In this embodiment, the method includes the following steps 202 to 208. Among them:
[0032] Step 202, after detecting that the energy storage system generates an energy storage root key, split the energy storage root key into multiple root key shares. Among them, the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system. Multiple root key authority parties hold the second management authority of their respective corresponding root key shares, and multiple second management authorities are isolated from each other. The multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system;
[0033] It should be noted that through the interaction between the control terminal of the energy storage system and the energy storage system, the operation and maintenance personnel can complete the generation and splitting process of the energy storage root key. Specifically, the operation and maintenance personnel deploy the energy storage system through the control terminal of the energy storage system. In the initialization stage of the energy storage system deployment, the hardware security module of the energy storage system will generate the energy storage root key through the internal secure random number generator. Among them, the hardware security module can be integrated into the controller or gateway device of the energy storage system. The generation of the energy storage root key is carried out entirely in a secure hardware module such as an HSM or an encrypted USB drive to prevent it from being maliciously stolen. However, the energy storage root key relying on single hardware management is still prone to leakage after the device is attacked. Therefore, after generating the energy storage root key, the key splitting technology can be used to split the energy storage root key into multiple root key shares, and multiple root key authorities hold the management authority of their respective corresponding root key shares, thereby increasing the difficulty for hackers to attack the energy storage cabinet and destroy the system confidentiality.
[0034] It should be noted that the control terminal of the energy storage system detects that the energy storage system generates an energy storage root key. Specifically, the control terminal of the energy storage system detects that the hardware security module generates the energy storage root key. After the energy storage root key is generated, a control instruction is issued to split the energy storage root key into multiple root key shares. It can be understood that the execution entity for splitting the energy storage root key is the hardware security module in the energy storage system. The multiple root key shares can be 5, 6, 7, etc. The specific number of the multiple root key shares can be determined by the splitting instruction issued by the control terminal of the energy storage system. Among them, after the energy storage root key is split into multiple root key shares, the overall first management right of the energy storage root key is jointly held by multiple root key authorities that manage the energy storage root key. Different root key authorities hold the second management rights corresponding to their respective root key shares, and different second management rights are isolated from each other. The root key authority refers to an entity with the management right of the energy storage root key, which can specifically be an object, a system, a terminal, etc. The multiple root key authorities include the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. Among them, the root key management object that manages the energy storage system can specifically be a supplier, the root key usage object that uses the energy storage system can specifically be a customer site manager, the control terminal of the energy storage system can specifically be a computer or a mobile phone, etc., and the cloud can specifically be a cloud server. It can be understood that since different root key authorities are independent of each other, the second management rights of multiple root key shares are isolated from each other, and the number of root key shares with management rights held by different root key authorities can be the same or different. For example, in an implementable manner, the energy storage root key is split into root key share 1, root key share 2, root key share 3, root key share 4, and root key share 5. Among them, the second management right of root key share 1 can be held by the supplier's operation and maintenance personnel, the second management right of root key share 2 can be held by the customer site administrator, the second management rights of root key share 3 and root key share 4 are held by the control terminal of the energy storage system, and the management right of root key share 5 can be held by the cloud server.
[0035] It should be noted that after the hardware security module of the energy storage system receives the splitting instruction issued by the control terminal of the energy storage system, the hardware security module can generate multiple root key shares based on a preset splitting algorithm running internally. Among them, the preset splitting algorithm can specifically be the Shamir polynomial interpolation algorithm, and the split shares can be expressed as 、 、 , where n represents the total amount of root key shares. After splitting to obtain multiple root key shares, the control terminal of the energy storage system can establish a mapping relationship between different root key shares and different root key authorities, so that different root key authorities have the second management authority for their corresponding root key shares. Specifically, a mapping relationship between different key shares and different root key authorities can be established based on the share identification information of the root key shares and the authority identity information of the root key authorities. Among them, the share identification information can specifically be the share number, and the authority identity information can specifically be the object identity information or the terminal number information, etc. It can be understood that there are at least two root key authorities with the second management authority, and multiple root key authorities with the second management authority jointly hold the first management authority of the energy storage root key. For example, in an implementable manner, multiple root key authorities can be the root key management object and the root key using object, can be the root key management object and the control terminal of the energy storage system, can be the control terminal of the energy storage system and the cloud, or can also be the root key management object, the root key using object and the control terminal of the energy storage system, etc.
[0036] As an example, step 202 includes: after determining that the hardware security module of the energy storage system generates the energy storage root key based on the root key generation progress information fed back by the energy storage system, generating a root key splitting instruction, and controlling the hardware security module to split the energy storage root key into multiple root key shares according to the root key splitting instruction. Among them, the root key generation progress information is used to represent the generation progress of the hardware security module of the energy storage system generating the energy storage root key, and the root key splitting instruction is used to indicate the splitting of the energy storage root key.
[0037] In an implementable manner, assume that the energy storage root key generated by the hardware security module is , and the number of shares indicated by the root key splitting instruction for splitting the energy storage root key is 4. Then the hardware security module splits the energy storage root key into , , and .
[0038] Step 204, storing each root key share in the storage area managed by its respective matching root key authority, where the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key;
[0039] It should be noted that after the hardware security module completes the splitting of the energy storage root key to obtain multiple root key shares, in order to achieve physical isolation of different root key shares when they are managed by multiple root key authorities, the control terminal of the energy storage system can control the distribution and storage of multiple root key shares in the storage areas managed by the root key authorities. For example, in an implementable manner, assuming that the energy storage root key is split into 4 root key shares, and the root key management object, the root key usage object, the control terminal, and the cloud each have the second management authority for one root key share, then the root key share 1 can be stored in the first preset storage area of the first associated terminal associated with the root key management object, the root key share 2 can be stored in the second preset storage area of the second associated terminal associated with the root key usage object, the root key share 3 can be stored in the third preset storage area of the control terminal, and the root key share 4 can be stored in the fourth preset storage area of the cloud. Among them, the first associated terminal having an association relationship with the root key management object can be the mobile terminal held by the root key management object, and the second associated terminal having an association relationship with the root key usage object can be the mobile terminal held by the root key usage object. In this way, since the storage spaces of different terminals have independent storage media, the true isolation of different root key shares can be achieved at the physical level.
[0040] It should be noted that in order to avoid the occurrence of the leakage of the energy storage root key caused by a single root key authority, the amount of root key shares that each root key authority can manage can be set so that the energy storage root key cannot be restored. The cooperation of two or more root key authorities is required to complete the restoration of the energy storage root key. That is, the amount of the first root key shares stored in any storage area is set to be less than the amount of the second root key shares required to restore the energy storage root key. For example, in an implementable manner, assuming that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares for splitting the energy storage root key is 7, and the root key splitting instruction synchronously indicates that the minimum number of shares required to restore the energy storage root key is 4. Then, in the process of establishing the mapping relationship between the root key shares and the root key authorities to distribute the root key shares to different storage areas for storage, the amount of root key shares stored in any storage area is less than 4.
[0041] As an example, step 204 includes: extracting the share distribution policy information from the root key splitting instruction, determining the amount of root key shares allocated to each of the multiple root key authorities based on the share distribution policy information, and receiving the mapping relationship between the multiple root key shares and the multiple root key authorities. According to the amount of root key shares allocated and the mapping relationship, controlling the hardware security module to store the multiple root key shares in their respective matching root key authorities, where the amount of root key shares allocated is used to represent the number of root key shares allocated to different root key authorities.
[0042] Step 206: According to the root key restoration operation triggered by the root key restorer, locate multiple target storage areas required for restoring the energy storage root key in all storage areas, where the multiple target storage areas correspond one-to-one with multiple root key authorities;
[0043] It should be noted that the root key restorer refers to the entity that performs the energy storage root key restoration, which can specifically be a role, an object, or a terminal. It can be understood that the root key restoration operation can be manually triggered by a role, such as a supplier operation and maintenance personnel, a customer site administrator, or a hacker, etc., or can be automatically triggered by a terminal, such as a control terminal or the cloud, etc. After receiving the root key restoration operation triggered by the root key restorer, multiple target storage areas required for restoring the energy storage root key can be located in all storage areas. That is, the multiple root key shares combined by the multiple target storage areas can meet the minimum root key share quantity required for restoring the energy storage root key, and the multiple target storage areas and multiple root key authorities are in one-to-one correspondence. For example, in an implementable manner, assume that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares for splitting the energy storage root key is 7, and the root key splitting instruction synchronously indicates that the minimum share quantity for restoring the energy storage root key is 4. Among them, the 7 root key shares are respectively stored in the storage areas of their respective matching root key authorities. Specifically, root key share 1 is stored in the first storage area of the control terminal, root key share 2 is stored in the second storage area of the control terminal, root key share 3 is stored in the third storage area of the control terminal, root key share 4 is stored in the fourth storage area of the cloud, root key share 5 is stored in the fifth storage area of the cloud, root key share 6 is stored in the sixth storage area of the cloud, and root key share 7 is stored in the seventh storage area of the first associated terminal associated with the root key management object. Then, the multiple target storage areas can be the first storage area, the second storage area, the third storage area, and the fourth storage area, or can be the first storage area, the second storage area, the third storage area, and the seventh storage area, can be the first storage area, the second storage area, the fourth storage area, and the fifth storage area, or can also be the first storage area, the second storage area, the third storage area, the fourth storage area, and the sixth storage area, etc. Therefore, without considering the access rights of the root key restorer to all storage areas, there can be multiple combinations of multiple target storage areas, as long as the root key share quantity of the combined multiple target storage areas reaches at least the second root key share quantity.
[0044] As an example, step 206 includes: based on the root key restoration operation triggered by the root key restorer, and based on the amount of the second root key shares required to restore the energy storage root key, locate multiple target storage areas required to restore the energy storage root key in all storage areas, where the multiple target storage areas correspond one-to-one with multiple root key authorities, and the root key authorities corresponding to different target storage areas may be the same or different.
[0045] Step 208, when it is detected that the root key restorer has the access right to access multiple target storage areas, restore the energy storage root key according to the target root key shares selected from the multiple target storage areas.
[0046] It should be noted that since multiple root key shares are physically isolated through different storage areas, the root key restorer does not have the ability to access all storage areas, that is, any root key restorer cannot have the ability to extract root key shares in the case of the area combination of all multiple target storage areas. Therefore, it is necessary to detect the access rights of multiple target storage areas in different area combinations for the root key restorer. For example, in an implementable manner, assume that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares for splitting the energy storage root key is 7, the root key splitting instruction synchronously indicates that the minimum number of shares required to restore the energy storage root key is 4, and the root key restorer is the management and control terminal. Among them, the root key restorer has the access right to access the root key share 1, root key share 2, and root key share 3 in its own storage area, and has the access right to access the root key share 7 in the cloud storage area. Then it is determined that the root key restorer has the access right to access multiple target storage areas. Among them, the access rights of the root key restorer to access different storage areas can be set in advance based on the identity information of the restorer. For example, when the root key restorer needs to access the storage area of a non-itself terminal, it can detect whether the root key restorer is in the access whitelist of the terminal to which the storage area to be accessed belongs based on the identity information of the root key restorer.
[0047] As an example, step 208 includes: when it is detected that the root key restorer has the access right to access multiple target storage areas, send the target root key shares selected from the multiple target storage areas to the hardware security module of the energy storage system, and control the hardware security module to restore the multiple target root key shares to obtain the energy storage root key.
[0048] For example, in an implementable manner, when the hardware security module executes the key splitting process, it can split the energy storage root key into multiple root key shares by constructing an m - 1 degree polynomial. Among them, a root key share can be understood as a fixed coordinate, where, The value is derived from the data of the local operation, operation and maintenance environment of the energy storage cabinet or the cloud interaction under the specified rules, that is, the share generation data of different root key shares. The value is obtained through polynomial calculation. Assuming m is 4, it means that only when the root key restoration party obtains 4 fixed coordinates and performs polynomial interpolation, the hardware security module can successfully execute the root key restoration process and restore the energy storage root key.
[0049] The above root key management method for the energy storage system. First, the control terminal of the energy storage system performs real-time detection on the energy storage system. After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares. Among them, the management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system. The management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively. The management authorities held by different root key authority parties are isolated from each other. The multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system. That is, it can be realized that the energy storage root key is split into multiple root key shares managed by at least two root key authority parties related to the energy storage system. Then, each root key share is stored in the storage area managed by its respective matching root key authority party. Among them, the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key. Thus, multiple root key shares are respectively stored in the storage areas with management authority by different root key authority parties. Then, according to the root key restoration operation triggered by the key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas. Finally, when it is detected that the key restoration party has the access authority to access multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas. Since the root key shares with management authority by multiple root key authority parties are isolated from each other, and the root key shares corresponding to the amount of root key shares that any root key authority party can manage cannot be used to separately restore the energy storage root key. Therefore, after receiving the root key restoration request, it is necessary to cooperate with at least two of the root key management object, the root key usage object, the control terminal, and the cloud to locate multiple target storage areas required to restore the energy storage root key. Finally, the energy storage root key can be restored by extracting multiple target root key shares from multiple target storage areas managed by root key authority parties. Thus, the situation of root key leakage caused by a single root key authority party being attacked is avoided, and the purpose of securely managing the root key at the software level can be achieved. Therefore, it overcomes the technical defects that the hardware cost is often relatively high, and at the same time, the root key relying on single hardware encryption is prone to leakage risks in the case of device attacks. Therefore, the management effect of the energy storage system root key management is improved from two dimensions of saving hardware costs and enhancing the security of root key management.
[0050] In one embodiment, as Figure 2 shown, the multiple root key shares include multiple root key management shares jointly managed by the control terminal and the root key management object and the root key usage shares used by the root key usage object; splitting the energy storage root key into multiple root key shares includes:
[0051] Step 302: Obtain the share configuration information jointly corresponding to the control terminal, the root key management object, and the root key usage object, and obtain the permission level information corresponding to the control terminal, the root key management object, and the root key usage object respectively. The share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key.
[0052] It should be noted that in the process where only the control terminal, the root key management object, and the root key management and usage object participate in the root key permission management as root key permission parties, when generating the key splitting instruction, the control terminal can synchronously set the total amount of root key shares required to be split from the energy storage root key and specifically set the amount of root key shares that different root key permission parties can manage.
[0053] As an example, step 302 includes: extracting the share configuration information jointly required by the control terminal, the root key management object, and the root key usage object from the root key splitting instruction, and extracting the permission level information corresponding to the control terminal, the root key management object, and the root key usage object from the root key splitting instruction. The share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key.
[0054] Step 304: Split the energy storage root key into multiple preset root key shares according to the share configuration information.
[0055] As an example, step 304: Control the hardware security module to split the energy storage root key into multiple preset root key shares identified by the share configuration information using a preset key splitting algorithm. The share configuration information can specifically be 7, 8, or 9, etc. It can be understood that the preset root key share refers to the root key share that has not established a mapping relationship with any root key permission party.
[0056] Step 306: Divide the multiple preset root key shares according to the share mapping relationship between the multiple preset root key shares and the permission level information to obtain multiple root key management shares and root key usage shares. The share mapping relationship is used to represent the root key share component allocated to any root key permission party under the total amount of root key shares.
[0057] It should be noted that, due to the different security capabilities of different root key authority parties, different permission levels can be set for different root key authority parties based on different root key authority parties, and a share mapping relationship between different permission levels and preset root key shares can be established. Among them, the share mapping relationship is used to represent the root key share component obtained by any root key authority party under the total amount of root key shares. That is, different permission levels correspond to different numbers of split root key shares. For example, in an implementable manner, all root key authority parties include a control terminal, a supplier managing the energy storage root key, and a customer site administrator using the energy storage root key. Among them, the permission levels corresponding to the control terminal and the customer site administrator are both labeled as level 2, and the permission level corresponding to the supplier managing the energy storage root key is labeled as 3. Then, 7 root key shares are sequentially configured for the control terminal, the supplier, and the customer site administrator in the configuration order of 2, 3, and 2.
[0058] As an example, step 306 includes: according to the share mapping relationship between multiple preset root key shares and permission level information, dividing a preset number of preset root key shares for the control terminal, the root key management object, and the root key usage object respectively, to obtain multiple root key management shares and root key usage shares.
[0059] In this embodiment, in an application scenario where the control terminal, the root key management object, and the root key usage object are involved in the management of the energy storage root key, if the control terminal needs to control the hardware security module to execute the splitting process of the energy storage root key, the total amount of root key shares required for the energy storage root key can be determined first based on the share configuration information generated by the control terminal, so as to split the energy storage root key into multiple preset root key shares. Further, considering the different security protection capabilities of different root key authority parties, a share mapping relationship can be established between the permission level information of different root key authority parties generated by the control terminal and multiple preset root key shares, so as to clarify the root key share component corresponding to the second management permission that different root key authority parties should have. Thus, the purpose of sequentially allocating multiple preset root key shares under the consideration of the security dimension for different root key authority parties to perform permission management can be achieved. Therefore, while improving the management effect of the root key management of the energy storage system, the security of the root key management of the energy storage system is further improved.
[0060] In one embodiment, multiple root key management shares include the first root key management share managed by the control terminal; according to the share mapping relationship between the preset root key shares and the permission level information, dividing the multiple preset root key shares to obtain root key management shares and multiple root key usage shares, including:
[0061] Determine the first root key management share component corresponding to the control terminal according to the share mapping relationship; obtain the system authentication information and system installation information generated by the control terminal during the process of managing the energy storage system; extract the first share generation data from the system authentication information, and extract the second share generation data from the system installation information; according to the first root key management share component, the first share generation data and the second share generation data, divide the multiple preset root key shares to obtain the first root key management share.
[0062] It should be noted that the first root key management share managed by the control terminal can be completely stored locally on the control terminal, or a part of the first root key management share can be stored locally on the control terminal, and another part of the first root key management share can be stored in the cloud, and the part of the first root key management share can be obtained through the interaction between the control terminal and the cloud. At this time, both the control terminal and the cloud are root key authority parties, that is, the multiple root key authority parties include the control terminal, the cloud, the root key management object, and the root key usage object.
[0063] It should be noted that through the share mapping relationship, the first root key management share component managed by the control terminal can be queried, specifically by identifying the specific fields in the root key split secret instruction. For example, in an implementable manner, assuming that the identified field is 2, the first root key management share component managed by the control terminal is 2. Among them, the system authentication information is used to represent the relevant content during the cloud authentication process when the energy storage system is first launched. The first share generation data can specifically be the first random value generated during the first launch. The system installation information is used to represent the relevant content during the installation process of the energy storage system, specifically, it can be the system installation log, and the second share generation data can specifically be the installation time in the system installation log.
[0064] As an example, query the first root key management share component managed by the control terminal in the share mapping table constructed based on the share mapping relationship; obtain the system installation information generated by the control terminal during the installation process of the energy storage system, and obtain the system authentication information sent by the cloud during the authentication process of the control terminal to the cloud for the energy storage system; extract the installation time as the first share generation data from the system installation information, and extract the random value as the second share generation data from the system authentication information; according to the first root key management share component, the first share generation data and the second share generation data, divide the multiple preset root key shares to obtain the first root key management share.
[0065] In this embodiment, during the process of dividing the first root key management share managed by the control terminal, the divided first root key management share is divided into a first part root key management share and a second part root key management share. Among them, the management authority of the first part root key management share is held by the control terminal, and the management authority of the second part root key management share is held by the cloud. That is, the first root key management share managed by the control terminal is further divided into root key shares jointly managed by the control terminal and the cloud, and different operation information of the energy storage system is used to generate share generation data respectively, so as to ensure the accurate division of the first root key management share managed by the control terminal. Therefore, it lays a foundation for improving the management effect of the root key management of the energy storage system.
[0066] In one embodiment, the multiple root key management shares include a second root key management share managed by the root key management object; according to the share mapping relationship between the preset root key shares and the permission level information, the multiple preset root key shares are divided to obtain root key management shares and multiple root key usage shares, including:
[0067] According to the share mapping relationship, determine the second root key management share component corresponding to the root key management object; obtain the system hard-coded information set by the root key management object on the energy storage system; extract the third share generation data from the system hard-coded information; according to the first query information input by the root key management object, query to obtain the fourth share generation data; according to the second root key management share component, the third share generation data and the fourth share generation data, divide the multiple preset root key shares to obtain the second root key management share.
[0068] It should be noted that through the share mapping relationship, the second root key management share component managed by the root key management object can be queried. The system hard-coded information is used to represent sensitive parameters in the source code, which can specifically be passwords or configuration parameters, etc. The first query information is used to query non-public technical files stored in the control terminal. It can be understood that both the system hard-coded information and the first query information have independent storage rules set by the root key management object, and they have privacy and cannot be known by other objects. Furthermore, in the stage of obtaining the share generation data corresponding to the second root key management share, only the root key management object can obtain specific third share generation data and fourth share generation data. Among them, the third share generation data can specifically be a hard-coded value, and the fourth share generation data can specifically be a second random value stored in the non-public technical file.
[0069] As an example, query the second root key management share component managed by the root key management object in the share mapping table constructed based on the share mapping relationship; obtain the system hard-coded information set by the root key management object on the energy storage system; use the hard-coded value stored in the system hard-coded information as the third share generation data; use the first query information input by the root key management object as an index to locate the non-public technical document, and use the second random value stored in the non-public technical document as the fourth share generation data, where the first query information can specifically be the query path information for querying the second random value; according to the second root key management share component, the third share generation data, and the fourth share generation data, divide the second root key management share from multiple preset root keyshares.
[0070] In this embodiment, during the process of dividing the second root key management share managed by the root key management object, the divided second root key management share is divided into a third part root key management share and a fourth part root key management share. Among them, the third share generation data for generating the third part root key management share is hard-coded by the root key management object in the source code and cannot be directly read during the actual operation of the energy storage system. It can only be returned after being accessed by the root key management object through a specific access interface. The fourth share generation data for generating the fourth part root key management share is known only to the root key management object about the query path information for querying the second random value. Therefore, both the third share generation data and the fourth share generation data are private, thus ensuring the accurate division of the second root key management share managed by the root key management object. Therefore, it lays a foundation for improving the management effect of the root key management of the energy storage system.
[0071] In one embodiment, according to the share mapping relationship between the preset root key shares and the permission level information, divide the multiple preset root key shares to obtain the root key management share and multiple root key usage shares, including:
[0072] According to the share mapping relationship, determine the root key usage share component corresponding to the root key usage object; obtain the system login information set by the root key usage object on the energy storage system; extract the fifth share generation data from the system login information; according to the key generation time of the energy storage root key, query the target battery state information associated with the key generation time in the battery state information of the energy storage system; generate the sixth share generation data according to the target battery state information; according to the root key usage share component, the fifth share generation data, and the sixth share generation data, divide the root key usage share from multiple preset root key shares.
[0073] It should be noted that through the share mapping relationship, the root key usage share components managed by the root key management object can be queried. Among them, the system login information is used to represent the login content of the client system logging in to the energy storage system, which may specifically include the login password, login welcome message, etc. It can be understood that the system login information is usually used to prevent the system service from being counterfeited and is a measure for users to identify the authenticity of the service. The system login information is entered and stored in the database by the root key usage object in the account management. The fifth share generation data can specifically be the first fixed value set in the system login information. The battery status information is used to represent the operating status of the battery, which may specifically be the health degree of the battery cluster or the average voltage of the battery cluster, etc. Since the battery status information changes over time, but has a definite value at a certain point in time, this characteristic can be utilized to incorporate the battery status information of the energy storage system into the root key splitting process and serve as part of the generation data for the root key shares. During the process of splitting the energy storage root key to obtain the root key usage shares, the control terminal first obtains the State of Health (SOH) curve of a specific battery cluster in the energy storage system. Although the battery health status curve may show certain differences with different algorithms, no matter in the aging curve look-up or real-time correction query, there must be only one value for the same cell or corresponding cluster statistical information at the same time. Therefore, by setting a specific association relationship between the generation time of the energy storage root key and the battery health status curve, the target battery status information with uniqueness can be queried, and then the generation of the sixth share generation data depends on the target battery status information. For example, in an implementable manner, assume that the key generation time point A is later than the first acquisition time of the battery SOH curve, and the battery status information is the SOH value collected at each acquisition time point on the SOH curve. Then, it can be defaulted that the SOH value corresponding to the acquisition time point closest to the key generation time A is used as the target battery status information, and the sixth share generation data is generated based on the SOH value according to the preset rules. For example, in another implementable manner, assume that the key generation time point is B, then the average voltage of the battery cluster in the real-time curve collected at the key generation time point B can be used as the battery status information, and the sixth share generation data is generated based on the average voltage according to the preset rules. It can be understood that the preset rules for generating the sixth share generation data based on the target battery status information can be pre-coded as source code in the database in advance or stored in the database.
[0074] As an example, query the third root key management share component used by the root key usage object in the share mapping table constructed based on the share mapping relationship; obtain the system login information set by the root key usage object on the energy storage system; extract the second fixed value in the system login information as the fifth share generation data; obtain multiple information collection time points of the battery state information of the energy storage system, calculate the differences between the multiple information collection time points and the key generation time point respectively to obtain multiple time differences, and use the battery state information corresponding to the information collection time point with the smallest time difference among the multiple time differences as the target battery state information; extract the third fixed value in the target battery state information as the sixth share generation data; and obtain the root key usage share by dividing the root key share among multiple preset root key shares according to the root key usage share component, the fifth share generation data, and the sixth share generation data.
[0075] In this embodiment, during the process of dividing the root key usage share managed by the root key usage object, the divided root key usage share is divided into the first part of the root key usage share and the second part of the root key usage share. Among them, the fifth share generation data for generating the first part of the root key usage share is obtained by extracting from the system login information independently set by the root key usage object, and the sixth share generation data for generating the second part of the root key usage share is finally generated by the root key usage object alone after knowing the preset query rule and generation rule in combination with the uniqueness of the battery state information at a single time point. Therefore, both the fifth share generation data and the sixth share generation data have privacy, thus ensuring the accurate division of the root key usage share managed by the root key usage object, and laying a foundation for improving the management effect of the root key management of the energy storage system.
[0076] In an implementable manner, refer to Figure 3 , Figure 3Schematic diagram of the splitting process of the energy storage root key. Among them, the root key shares obtained by splitting the energy storage root key can specifically be root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6, and root key share x7. Combining the above embodiments, the first share generation data of root key share x1 is obtained by cloud transmission when the hardware first goes online. Among them, the cloud persists and stores it in the database. The first share generation data can be extracted from the system authentication information in the way specified by the cloud according to the device identifier, or it can be an ordered number automatically calculated according to time; the second share generation data of root key share x2 is extracted from the installation time of the system installation information, and it can only be obtained locally. It can be understood that it can be obtained when the customer site administrator has local file reading permission. The security time is usually stored in the installation log file or the database, and the installation time is usually tried to be obtained during the operation and maintenance stage for positioning; the third root key share generation data of root key share x3 is hard-coded in the source code and held by the root key management object, and only supports returning after accessing a specific interface through the key splitting process; the fourth root key share generation data of root key share x4 and root key share x5 can both be extracted from different files in the non-public technology folder, and the query path is only known to the root key management object; the sixth share generation data of root key share x6 is obtained in combination with the battery status information of the energy storage system, and the seventh share generation data of root key share x7 is set in the system login information of the energy storage system by the root key usage object. The acquisition methods are only known to the root key usage object. In this way, the energy storage root key can be split into 7 root key shares, stored in the storage areas of different terminals, and managed by their respective corresponding root key permission parties.
[0077] In an implementable manner, in one embodiment, storing each root key share in the storage area managed by its respective matching root key permission party includes:
[0078] Selection step: Select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in the storage area managed by the root key permission party identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0079] As an example, the selection step: Randomly select any root key share from multiple root key shares as the target root key share; according to the share identification information of the target root key share, determine the storage area managed by the root key permission party storing the target root key share, and store the target energy storage root key share in the storage area, and return to execute the step: Randomly select any root key share from multiple root key shares as the target root key share.
[0080] In this embodiment, by means of the share identification information corresponding to different root key shares, the root key authorities managing different root key shares and their storage areas are determined, and all root key shares are stored in the corresponding storage areas one by one. In the subsequent scenario of restoring the energy storage root key, different root key restoration parties can extract the corresponding root key shares based on their access rights to restore the energy storage root key. Therefore, it further lays a foundation for improving the management effect of the root key management of the energy storage system.
[0081] In one embodiment, according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, including:
[0082] Extracting the identity information of the root key restoration party in the root key restoration operation; determining the first target storage area storing the first root key management share in all storage areas; generating the share path information of the target root key usage share required for restoring the energy storage root key according to the identity information; determining the second target storage area storing the target root key usage share in all storage areas according to the share path information; and taking the first target storage area and the second target storage area together as the multiple target storage areas.
[0083] It should be noted that through the identity information of the root key restoration party, a part of the root key shares that the root key restoration party can restore can be determined, and then the share path information for restoring this part of the root key shares can be further generated to extract this part of the root key shares from the specified storage area for restoring the energy storage root key. By combining another part of the root key shares managed by the control terminal, the energy storage root key can be successfully restored. For example, in an implementable manner, assume that the energy storage root key generated by the hardware security module is , the number of shares indicated by the root key splitting instruction for splitting the energy storage root key is 4. Among them, two root key shares are stored in the storage area of the first associated terminal associated with the root key management object, and three root key shares are stored in the storage area of the control terminal. Then, four root key shares can be randomly selected from these five root key shares to restore the energy storage root key. Among them, the share path information is used to identify different paths for storing different root key shares in the storage area of the first associated terminal. The root key restoration operation can be manually triggered or automatically triggered by the root key restoration party.
[0084] As an example, in the root key restoration operation, the identity information of the root key restorer is extracted; based on the root key restoration operation, a query is automatically triggered for the first target storage area that stores the first root key management share in all storage areas; according to the identity information and the restoration information input by the root key restorer, the share path information of the target root key usage share required to restore the energy storage root key is generated; using the share path information as an index, a query is made for the second target storage area that stores the target root key usage share in all storage areas; the first target storage area and the second target storage area are jointly used as multiple target storage areas.
[0085] In this embodiment, through the cooperation of the management and control terminal and the root key restorer, the first target storage area and the second target storage area of the root key shares required to restore the energy storage root key are located in all storage areas, so that after the root key restorer triggers the root key restoration operation, the purpose of accurately locating the target storage area where the energy storage root key can be restored can be achieved. Therefore, it lays a foundation for accurately restoring the energy storage root key subsequently.
[0086] In an implementable manner, referring to Figure 4 , Figure 4 FIG. is a schematic diagram showing scenarios for different root key restorers to restore the energy storage root key. Among them, (a) is a schematic diagram of the root key management object restoring the root key, (b) is a schematic diagram of the root key usage object restoring the root key, and (c) is a schematic diagram of the root key stealing object restoring the root key. Assume that the energy storage root key is split into 7 root key shares, namely root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6, and root key share x7 as shown in Figure 3 Since the root key management object can successfully restore 5 out of the 7 root key shares (root key share x1, root key share x2, root key share x3, root key share x4, and root key share x5), the root key management object can accurately restore the energy storage root key; since the root key usage object can successfully restore 4 out of the 7 root key shares (root key share x1, root key share x2, root key share x6, and root key share x7), the root key usage object can accurately restore the energy storage root key; since the root key stealing object can neither obtain root key share x3, root key share x4, and root key share x5, nor obtain root key share x6 and root key share x7, and even cannot invade the cloud to obtain root key share x1, thus not having the access permission to access the storage area of 4 root key shares, it cannot successfully restore the energy storage root key.
[0087] In one embodiment, determining a second target storage area for storing the usage shares of the target root key in all storage areas according to the share path information includes:
[0088] Querying the restoration level information of the root key restorer according to the identity information; determining the second target storage area for storing the usage shares of the target root key in all storage areas according to the restoration level information.
[0089] It should be noted that different root key restorers have different restoration capabilities. The more root key shares are used for the restoration of the energy storage root key, although it does not necessarily mean an increase in the restoration ability, it can improve the robustness of restoring the energy storage root key to a certain extent. For example, the root key restorer y1 can only obtain four root key shares, while the root key restorer y2 can obtain six root key shares. Therefore, even if the root key restorer y2 cannot obtain any two of the six root key shares, it can still ensure the share level of the energy storage root key. Therefore, considering the identities of different root key restorers, different restoration levels can be opened for different root key restorers. For example, in an implementable manner, a root key restorer with a higher permission level can know all the second target storage areas for storing the usage shares of the target root key, while a root key restorer with a lower permission level can only know some of the second target storage areas for storing the usage shares of the target root key.
[0090] As an example, using the identity information as an index, query the root key restoration level information; according to the restoration level information, all the storage areas selected for storing the usage shares of the target root key are used as the second target storage areas.
[0091] In this embodiment, in the process of determining the second target storage area for storing the usage shares of the target root key, different restoration levels can be appropriately configured for the root key restorer based on the identity of the root key restorer, so that the amount of root key shares that the root key restorer can obtain for restoring the energy storage root key is different, so as to realize the dynamic control of the restoration permissions of different root key restorers. Therefore, the management flexibility of the root key management of the energy storage system is improved.
[0092] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0093] Based on the same inventive concept, an embodiment of the present application also provides a root key management device for an energy storage system for implementing the root key management method of the energy storage system involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the root key management device for the energy storage system provided below can refer to the limitations on the root key management method of the energy storage system in the above text, and will not be repeated here.
[0094] In an exemplary embodiment, as Figure 5 shown, a root key management device for an energy storage system is provided, which is applied to a control terminal of the energy storage system and includes: a splitting module 401, a storage module 402, a determination module 403, and a restoration module 404, where:
[0095] The splitting module 401 is configured to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates the energy storage root key. Among them, the first management right of the energy storage root key is jointly held by multiple root key authorities that manage the energy storage system. Multiple root key authorities hold the second management rights corresponding to their respective root key shares, and the multiple second management rights are isolated from each other. The multiple root key authorities include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system.
[0096] The storage module 402 is configured to store each root key share in the storage area managed by the respective matching root key authority, where the quantity of the first root key shares stored in any storage area is less than the quantity of the second root key shares required to restore the energy storage root key.
[0097] The determination module 403 is configured to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restoration party, where the multiple target storage areas correspond one-to-one with the multiple root key authorities.
[0098] A reduction module 404, configured to, when it is detected that the root key reduction party has the access right to access multiple target storage areas, restore the energy storage root key according to the selected target root key shares in the multiple target storage areas.
[0099] In one embodiment, the multiple root key shares include multiple root key management shares jointly managed by the control terminal and the root key management object and root key usage shares used by the root key usage object; the splitting module 401 is further configured to:
[0100] Obtain the share configuration information jointly corresponding to the control terminal, the root key management object, and the root key usage object, and obtain the permission level information corresponding to the control terminal, the root key management object, and the root key usage object respectively, where the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; split the energy storage root key into multiple preset root key shares according to the share configuration information; divide the multiple preset root key shares according to the share mapping relationship between the multiple preset root key shares and the permission level information to obtain multiple root key management shares and root key usage shares, where the share mapping relationship is used to represent the root key share component allocated by any root key permission party under the total amount of root key shares.
[0101] In one embodiment, the multiple root key management shares include a first root key management share managed by the control terminal; the splitting module 401 is further configured to:
[0102] Determine the first root key management share component corresponding to the control terminal according to the share mapping relationship; obtain the system authentication information and system installation information generated by the control terminal during the management of the energy storage system; extract first share generation data from the system authentication information, and extract second share generation data from the system installation information; divide the multiple preset root key shares according to the first root key management share component, the first share generation data, and the second share generation data to obtain the first root key management share.
[0103] In one embodiment, the multiple root key management shares include a second root key management share managed by the root key management object; the splitting module 401 is further configured to:
[0104] Determine the second root key management share component corresponding to the root key management object according to the share mapping relationship; obtain the system hard coding information set by the root key management object on the energy storage system; extract third share generation data from the system hard coding information; query and obtain fourth share generation data according to the first query information input by the root key management object; divide the multiple preset root key shares according to the second root key management share component, the third share generation data, and the fourth share generation data to obtain the second root key management share.
[0105] In one embodiment, the splitting module 401 is further configured to:
[0106] According to the share mapping relationship, determine the root key usage share component corresponding to the root key usage object; obtain the system login information set by the root key usage object on the energy storage system; extract the fifth share generation data from the system login information; according to the key generation time of the energy storage root key, query the target battery state information associated with the key generation time in the battery state information of the energy storage system; generate the sixth share generation data according to the target battery state information; and obtain the root key usage share by dividing the root key usage share according to the root key usage share component, the fifth share generation data, and the sixth share generation data among multiple preset root key shares.
[0107] In one embodiment, the storage module 402 is further configured to:
[0108] Selection step: select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in the storage area managed by the root key authority identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0109] In one embodiment, the determination module 403 is further configured to:
[0110] Extract the identity information of the root key restoration party during the root key restoration operation; determine the first target storage area storing the first root key management share among all storage areas; generate the share path information of the target root key usage share required for restoring the energy storage root key according to the identity information; determine the second target storage area storing the target root key usage share among all storage areas according to the share path information; and use the first target storage area and the second target storage area together as multiple target storage areas.
[0111] In one embodiment, the determination module 403 is further configured to:
[0112] Query the restoration level information of the root key restoration party according to the identity information; and determine the second target storage area storing the target root key usage share among all storage areas according to the restoration level information.
[0113] Each module in the above root key management device of the energy storage system can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0114] In an exemplary embodiment, an energy storage system is provided. The energy storage system includes a management and control terminal of the energy storage system. The internal structure diagram of the management and control terminal of the energy storage system may be as shown in Figure 6 . The management and control terminal of the energy storage system includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus. The communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the management and control terminal of the energy storage system is used to provide computing and control capabilities. The memory of the management and control terminal of the energy storage system includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the management and control terminal of the energy storage system is used to exchange information between the processor and external devices. The communication interface of the management and control terminal of the energy storage system is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it realizes a root key management method for an energy storage system. Those skilled in the art can understand that Figure 6 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the management and control terminal of the energy storage system to which the solution of the present application is applied. The specific management and control terminal of the energy storage system may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0115] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0116] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0117] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A root key management method for an energy storage system, characterized in that, A control terminal applied to an energy storage system, the method comprising: After detecting that the energy storage system generates an energy storage root key, splitting the energy storage root key into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold the second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other. The multiple root key authority parties include at least two of a root key management object that manages the energy storage system, a root key usage object that uses the energy storage system, the control terminal of the energy storage system, and a cloud that provides cloud services for the energy storage system; Storing each root key share in a storage area managed by its respective matching root key authority party, wherein the amount of the first root key shares stored in any storage area is less than the amount of the second root key shares required to restore the energy storage root key; According to a root key restoration operation triggered by a root key restoration party, locating multiple target storage areas required to restore the energy storage root key in all storage areas, wherein the multiple target storage areas correspond one-to-one with the multiple root key authority parties; When it is detected that the root key restoration party has the access authority to access the multiple target storage areas, restoring the energy storage root key according to the target root key shares selected from the multiple target storage areas; The multiple root key shares include multiple root key management shares jointly managed by the control terminal and the root key management object and a root key usage share used by the root key usage object; the splitting of the energy storage root key into multiple root key shares includes: Obtaining the share configuration information jointly corresponding to the control terminal, the root key management object, and the root key usage object, and obtaining the respective corresponding permission level information of the control terminal, the root key management object, and the root key usage object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; splitting the energy storage root key into multiple preset root key shares according to the share configuration information; and dividing the multiple preset root key shares according to the share mapping relationship between the multiple preset root key shares and the permission level information to obtain the multiple root key management shares and the root key usage share, wherein the share mapping relationship is used to represent the root key share component allocated by any root key authority party under the total amount of root key shares; The multiple root key management shares include a first root key management share managed by the control terminal; the dividing of the multiple preset root key shares according to the share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the multiple root key usage shares includes: Determine the first root key management share component corresponding to the control terminal according to the share mapping relationship; obtain the system authentication information and system installation information generated by the control terminal during the process of managing the energy storage system; extract the first share generation data from the system authentication information, and extract the second share generation data from the system installation information; divide the multiple preset root key shares according to the first root key management share component, the first share generation data, and the second share generation data to obtain the first root key management share.
2. The method according to claim 1, wherein The multiple root key management shares include a second root key management share managed by the root key management object; the dividing the multiple preset root key shares according to the share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the multiple root key usage shares includes: Determine the second root key management share component corresponding to the root key management object according to the share mapping relationship; Obtain the system hard-coded information set by the root key management object on the energy storage system; Extract the third share generation data from the system hard-coded information; Query and obtain the fourth share generation data according to the first query information input by the root key management object; Divide the multiple preset root key shares according to the second root key management share component, the third share generation data, and the fourth share generation data to obtain the second root key management share.
3. The method according to claim 1, characterized in that, The dividing the multiple preset root key shares according to the share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the multiple root key usage shares includes: Determine the root key usage share component corresponding to the root key usage object according to the share mapping relationship; Obtain the system login information set by the root key usage object on the energy storage system; Extract the fifth share generation data from the system login information; Query the target battery state information associated with the key generation time in the battery state information of the energy storage system according to the key generation time of the energy storage root key; Generate the sixth share generation data according to the target battery state information; Divide the multiple preset root key shares according to the root key usage share component, the fifth share generation data, and the sixth share generation data to obtain the root key usage share.
4. The method according to claim 1, wherein The storing each root key share into the storage area managed by the respective matching root key authority party includes: Selection step: select a target root key share from the multiple root key shares; Obtain the share identification information of the target root key share; Store the target root key share into the storage area managed by the root key authority party identified by the share identification information, and return to execute the selection step until all root key shares are selected.
5. The method according to claim 1, characterized in that The locating and restoring the multiple target storage areas required for restoring the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restoration party includes: Extract the identity information of the root key restoration party during the root key restoration operation; Determine a first target storage area among all the storage areas that stores the first root key management share; Generate share path information of the target root key usage share required to restore the energy storage root key according to the identity information; Determine a second target storage area among all the storage areas that stores the target root key usage share according to the share path information; Use the first target storage area and the second target storage area together as the multiple target storage areas.
6. The method according to claim 5, characterized in that The step of determining a second target storage area among all the storage areas that stores the target root key usage share according to the share path information includes: Query the restoration level information of the root key restoration party according to the identity information; Determine a second target storage area among all the storage areas that stores the target root key usage share according to the restoration level information.
7. A root key management device for an energy storage system, characterized in that, Applied to the control terminal of the energy storage system, the device includes: A splitting module, configured to split the energy storage root key into multiple root key shares after detecting that the energy storage system generates the energy storage root key. Among them, the first management right of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system. The multiple root key authority parties hold the second management rights corresponding to their respective root key shares, and the multiple second management rights are isolated from each other. The multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key usage object that uses the energy storage system, the control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; A storage module, configured to store each root key share in the storage area managed by the respective matching root key authority party, where the quantity of the first root key shares stored in any storage area is less than the quantity of the second root key shares required to restore the energy storage root key; A determination module, configured to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to the root key restoration operation triggered by the root key restoration party, where the multiple target storage areas correspond one-to-one to the multiple root key authority parties; A restoration module, configured to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when detecting that the root key restoration party has the access right to access the multiple target storage areas; The multiple root key shares include multiple root key management shares jointly managed by the control terminal and the root key management object and the root key usage shares used by the root key usage object; the splitting module is further configured to: Obtain the share configuration information jointly corresponding to the control terminal, the root key management object, and the root key usage object, and obtain the permission level information corresponding to the control terminal, the root key management object, and the root key usage object respectively, where the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; according to the share configuration information, split the energy storage root key into multiple preset root key shares; according to the share mapping relationship between the multiple preset root key shares and the permission level information, divide the multiple preset root key shares to obtain the multiple root key management shares and the root key usage shares, where the share mapping relationship is used to represent the root key share component allocated by any root key authority under the total amount of root key shares; The multiple root key management shares include a first root key management share managed by the control terminal; the splitting module is further configured to: Determine the first root key management share component corresponding to the control terminal according to the share mapping relationship; obtain the system authentication information and system installation information generated by the control terminal during the management of the energy storage system; extract first share generation data from the system authentication information, and extract second share generation data from the system installation information; according to the first root key management share component, the first share generation data, and the second share generation data, divide the multiple preset root key shares to obtain the first root key management share.
8. The device according to claim 7, characterized in that The multiple root key management shares include a second root key management share managed by the root key management object; the splitting module is further configured to: Determine the second root key management share component corresponding to the root key management object according to the share mapping relationship; obtain the system hard coding information set by the root key management object on the energy storage system; Extract third share generation data from the system hard coding information; Query and obtain fourth share generation data according to the first query information input by the root key management object; According to the second root key management share component, the third share generation data, and the fourth share generation data, divide the multiple preset root key shares to obtain the second root key management share.
9. The device according to claim 7, characterized in that, The splitting module is further configured to: Determine the root key usage share component corresponding to the root key usage object according to the share mapping relationship; obtain the system login information set by the root key usage object on the energy storage system; Extract fifth share generation data from the system login information; Query the target battery state information associated with the key generation time in the battery state information of the energy storage system according to the key generation time of the energy storage root key; generate sixth share generation data according to the target battery state information; According to the root key usage share component, the fifth share generation data, and the sixth share generation data, divide the multiple preset root key shares to obtain the root key usage share.
10. An energy storage system, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Root key management system, backup method, recovery method, device and electronic equipment
CN115549907A
Secure storage method and device of power grid privilege access credential and storage medium
CN119358003A