Data transmission system and method, electronic device, medium and program product
By encrypting and authenticating the data, the data leakage problem caused by the communication cabinet being vulnerable to network attacks is solved, and the stability of data transmission is achieved.
Patent Information
- Application Number
- CN202510726402.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
As an important intermediate node in the data transmission process, communication cabinets may lead to data leakage when subject to network attacks, affecting the stability of the data transmission process.
By encrypting the target data, encrypted data and identity authentication information are generated, and after identity authentication is performed through the communication cabinet, encrypted data is sent to the second device, and the second device decrypts it to realize data transmission. The communication cabinet is only used as an identity authentication transit node.
It avoids data leakage caused by network attacks on communication cabinets and improves the stability of the data transmission process.
Smart Images

Figure CN120263540A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data processing, and particularly to a data transmission system, method, electronic device, medium, and program product. Background Art
[0002] In the field of industrial Internet of Things communication technology, a data transmission communication architecture between an inverter and a master station usually needs to be constructed for a photovoltaic power generation system and an energy storage system.
[0003] For the related data transmission communication method between the inverter and the master station, the data transmission between the inverter and the communication cabinet is mainly completed through a fixed communication protocol (for example, the serial communication protocol Modbus), and the data transmission between the communication cabinet and the master station is completed through Internet communication or cloud communication to achieve the data transmission between the inverter and the master station.
[0004] However, as an important intermediate transmission node in the data transmission process, the communication cabinet may cause data leakage problems in the entire data transmission link when being attacked by the network, affecting the stability of the data transmission process. Summary of the Invention
[0005] Embodiments of this application provide a data transmission system, method, electronic device, medium, and program product, which improve the stability of the data transmission process through encrypted transmission during the data transmission process, and avoid data leakage problems caused by the communication cabinet being attacked by the network.
[0006] In a first aspect, embodiments of this application provide a data transmission system, including a first device, a second device, and a communication cabinet. The first device is one of an inverter and a master station, and the second device is the other of the inverter and the master station. Both the first device and the second device are communicatively connected to the communication cabinet;
[0007] The first device is configured to encrypt target data to obtain encrypted data, and send the encrypted data and first identity authentication information to the communication cabinet. The first identity authentication information is the identity authentication information of the first device;
[0008] The communication cabinet is configured to authenticate the identity of the first device based on the first identity authentication information, and send the encrypted data to the second device when the identity authentication of the first device passes;
[0009] The second device is configured to decrypt the encrypted data to obtain the target data.
[0010] In a possible implementation, the data transmission system includes a first transmission scheme, the first authentication information includes a first digital signature, and the encrypted data includes encrypted target data and an encryption key;
[0011] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first authentication information to the communication cabinet, it specifically is used for:
[0012] When the first transmission scheme is started, generate a symmetric key, determine the encrypted target data, the encryption key, and the first digital signature based on the symmetric key, and send them to the communication cabinet;
[0013] When the communication cabinet authenticates the first device based on the first authentication information and sends the encrypted data to the second device when the authentication of the first device passes, it specifically is used for:
[0014] Authenticate the first device based on the first digital signature, and when the authentication of the first device passes, send the encrypted target data and the encryption key to the second device;
[0015] When the second device decrypts the encrypted data to obtain the target data, it specifically is used for:
[0016] Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0017] In a possible implementation, when the first device generates a symmetric key, determines the encrypted target data, the encryption key, and the first digital signature based on the symmetric key, and sends them to the communication cabinet when the first transmission scheme is started, it specifically is used for:
[0018] When the first transmission scheme is started, generate a symmetric key, perform symmetric encryption on the target data based on the symmetric key to obtain the encrypted target data, perform asymmetric encryption on the symmetric key to obtain the encryption key; sign the first hash value of the encrypted target data to obtain the first digital signature, and send the encrypted target data, the encryption key, and the first digital signature to the communication cabinet;
[0019] When the communication cabinet authenticates the first device based on the first digital signature and sends the encrypted target data and the encryption key to the second device when the authentication of the first device passes, it specifically is used for:
[0020] Determine the second hash value of the first digital signature. When the first hash value matches the second hash value, determine that the identity authentication of the first device passes, and send the encrypted target data and the encryption key to the second device;
[0021] When the second device decrypts the encryption key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically used for:
[0022] Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0023] In a possible implementation manner, after the first hash value matches the second hash value, the communication cabinet is specifically further used for:
[0024] Add a first timestamp to the encrypted target data and the encryption key, and send the encrypted target data and the encryption key carrying the first timestamp to the second device;
[0025] When the second device decrypts the encryption key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically used for:
[0026] Obtain the current time. When the difference between the current time and the first timestamp is less than or equal to the first threshold, decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0027] In a possible implementation manner, the data transmission system further includes a second transmission scheme. The first identity authentication information includes a second digital signature, and the encrypted data includes the encrypted target data and the encryption key;
[0028] When the first device encrypts the target data to obtain the encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically further used for:
[0029] When the second transmission scheme is started, generate a symmetric key, determine the encrypted target data, the encryption key, and the second digital signature based on the symmetric key, and send the second digital signature to the communication cabinet;
[0030] When the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device passes, it is specifically used for:
[0031] Authenticate the first device based on the second digital signature, and when the authentication of the first device passes, send a first authentication passed message to the first device;
[0032] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically further uses:
[0033] When receiving the first authentication passed message, send the encrypted target data and the encrypted key to the communication cabinet;
[0034] When the communication cabinet authenticates the first device based on the first identity authentication information and, when the authentication of the first device passes, sends the encrypted data to the second device, it specifically further uses:
[0035] When the authentication of the first device passes, send the encrypted target data and the encrypted key to the second device;
[0036] When the second device decrypts the encrypted data to obtain the target data, it specifically uses:
[0037] Decrypt the encrypted key to obtain the symmetric key, and based on the symmetric key, decrypt the encrypted target data to obtain the target data.
[0038] In a possible implementation manner, when the second transmission scheme is started, the first device generates a symmetric key, determines the encrypted target data, the encrypted key, and the second digital signature based on the symmetric key, and when sending the second digital signature to the communication cabinet, it specifically uses:
[0039] Generate the symmetric key when the second transmission scheme is started;
[0040] Execute in parallel the operations of encrypting the target data based on the symmetric key to obtain the encrypted target data and asymmetrically encrypting the symmetric key based on the first public key to obtain the encrypted key;
[0041] Determine the third hash value of the encrypted key, encrypt the third hash value based on the first signature key to obtain the second digital signature, and send the second digital signature to the communication cabinet through the first communication link;
[0042] When the first device receives the first authentication passed message and sends the encrypted target data and the encrypted key to the communication cabinet, it specifically uses:
[0043] Upon receiving the first authentication passed information, send the encryption key to the communication cabinet via the first communication link, and send the encrypted target data to the communication cabinet via the second communication link.
[0044] In a possible implementation, the data transmission system further includes a third transmission scheme, the first identity authentication information includes a first identity certificate, and the encrypted data includes encrypted target data and an encryption key;
[0045] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is used for:
[0046] When the third transmission scheme is started, send the first identity certificate to the communication cabinet;
[0047] The second device is further used for:
[0048] When the third transmission scheme is started, send a second identity certificate to the communication cabinet; wherein, the second identity certificate is the identity certificate of the second device;
[0049] When the communication cabinet authenticates the first device based on the first identity authentication information and, when the identity authentication of the first device passes, sends the encrypted data to the second device, it specifically is used for:
[0050] When the third transmission scheme is started and both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, generate a second authentication passed information, and send the second authentication passed information to the first device and the second device;
[0051] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is further used for:
[0052] Upon receiving the second authentication passed information, generate a symmetric key, determine the encrypted target data and the encryption key based on the symmetric key, and send the encrypted target data and the encryption key to the communication cabinet;
[0053] When the communication cabinet authenticates the first device based on the first identity authentication information and, when the identity authentication of the first device passes, sends the encrypted data to the second device, it specifically is used for:
[0054] Send the encrypted target data and the encryption key to the second device;
[0055] When the second device decrypts the encrypted data to obtain the target data, it is specifically used for:
[0056] When receiving the second authentication passed information, decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0057] In a second aspect, an embodiment of the present application provides a data transmission method, which is applied to a first device. The first device is one of an inverter and a master station. The first device is communicatively connected to a communication cabinet. The data transmission method includes:
[0058] Perform an encryption process on the target data to obtain encrypted data and first identity authentication information;
[0059] Send the encrypted data and the first identity authentication information to the communication cabinet, so that the communication cabinet performs an identity authentication on the first device based on the first identity authentication information, and when the identity authentication of the first device passes, send the encrypted data to a second device; wherein, the second device is the other one of the inverter and the master station; the second device is communicatively connected to the communication cabinet.
[0060] In a third aspect, an embodiment of the present application provides a data transmission method, which is applied to a communication cabinet. The communication cabinet is communicatively connected to a first device and a second device. The first device is one of an inverter and a master station. The second device is the other one of the inverter and the master station; the data transmission method includes:
[0061] When receiving the first identity authentication information and encrypted data sent by the first device, perform an identity authentication on the first device based on the first identity authentication information;
[0062] When the identity authentication of the first device passes, send the encrypted data to the second device, so that the second device performs a decryption process on the encrypted data to obtain the target data.
[0063] In a fourth aspect, an embodiment of the present application provides a data transmission method, which is applied to a second device. The first device is one of the inverter and the master station, and the second device is the other one of the inverter and the master station. The first device and the second device are both communicatively connected to the communication cabinet. The data transmission method includes:
[0064] When receiving the encrypted data, decrypt the encrypted data to obtain the target data; wherein, the encrypted data is sent when the communication cabinet passes the identity authentication of the first device based on the first identity authentication information, and the first identity authentication information is the identity authentication information of the first device.
[0065] In a fifth aspect, an embodiment of the present application provides an electronic device, including: a memory and a processor;
[0066] The memory stores computer-executable instructions;
[0067] The processor executes the computer-executable instructions stored in the memory, so that the processor executes various possible implementation manners in the second aspect, the third aspect, or the fourth aspect as described above.
[0068] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement various possible implementation manners in the second aspect, the third aspect, or the fourth aspect as described above.
[0069] In a seventh aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements various possible implementation manners in the second aspect, the third aspect, or the fourth aspect as described above.
[0070] A data transmission system, method, electronic device, medium, and program product provided by an embodiment of the present application realize data transmission between a first device, a communication cabinet, and a second device through a data encryption transmission method. The communication cabinet only serves as a transit node with an identity authentication function, thereby avoiding the problem of data leakage caused by the communication cabinet being attacked by the network and improving the stability of the data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The drawings here are incorporated into the description and form a part of this description, showing embodiments consistent with the present application, and are used together with the description to explain the principles of the present application.
[0072] Figure 1 It is a schematic application diagram of a related data transmission communication architecture;
[0073] Figure 2 It is a schematic structural diagram of a data transmission system provided by the present application;
[0074] Figure 3 It is one of the schematic data transmission diagrams provided by the present application;
[0075] Figure 4 It is a schematic application diagram of a first transmission scheme provided by the present application;
[0076] Figure 5 It is a second schematic data transmission diagram provided by the present application;
[0077] Figure 6 It is a schematic application diagram of a second transmission scheme provided by the present application;
[0078] Figure 7 The third schematic diagram of data transmission provided for this application;
[0079] Figure 8 The application schematic diagram of a third transmission scheme provided for this application;
[0080] Figure 9 One of the schematic flowcharts of a data transmission method provided for this application;
[0081] Figure 10 Two of the schematic flowcharts of a data transmission method provided for this application;
[0082] Figure 11 Three of the schematic flowcharts of a data transmission method provided for this application;
[0083] Figure 12 The structural schematic diagram of an electronic device provided for this application.
[0084] Through the above-mentioned drawings, the clear embodiments of this application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Description of the Embodiments
[0085] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. On the contrary, they are merely examples of devices and methods consistent with some aspects of this application as detailed in the appended claims.
[0086] First, the nouns involved in this application are explained:
[0087] An inverter refers to a power conversion device that converts direct current (DC) into alternating current (DC).
[0088] The master station refers to the core control device in a communication network (such as a photovoltaic power generation system, an energy storage system) that is responsible for initiating and managing data exchange.
[0089] A communication cabinet refers to a chassis cabinet used in the communication field, which can be used to protect internal communication devices and components.
[0090] Figure 1 The application schematic diagram of the relevant data transmission communication architecture provided for this application.
[0091] Such asFigure 1 As shown, the data transmission and communication method between the relevant inverter and the master station mainly completes the data transmission of the data to be transmitted between the inverter and the communication cabinet through a fixed communication protocol (such as Figure 1 the serial communication protocol Modbus shown), and completes the data transmission of the data to be transmitted between the communication cabinet and the master station through Internet communication or cloud communication, so as to realize the data transmission between the inverter and the master station.
[0092] Among them, as an important intermediate transmission node in the data transmission process, the communication cabinet may cause data leakage problems in the entire data transmission link when under cyber attacks, affecting the stability of the data transmission process.
[0093] To solve the above problems, the present application provides a data transmission system, method, electronic device, medium and program product. The first device encrypts the target data to obtain encrypted data, and sends the encrypted data and the first identity authentication information of the first device to the communication cabinet. The communication cabinet authenticates the first device based on the first identity authentication information, and when the identity authentication of the first device passes, sends the encrypted data to the second device. The second device decrypts the encrypted data to obtain the target data. In this way, the data transmission between the first device, the communication cabinet and the second device can be realized based on the data encryption transmission method. The communication cabinet only serves as a transfer node with an identity authentication function, thus avoiding the data leakage problem caused by the communication cabinet being under cyber attacks and improving the stability of the data transmission process.
[0094] The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.
[0095] Figure 2 is a schematic structural diagram of the data transmission system provided by the present application. As Figure 2 shown, the data transmission system 200 includes: a first device 201, a second device 202 and a communication cabinet 203. The first device 201 and the second device 202 are both communicatively connected to the communication cabinet 203.
[0096] The first device 201 is configured to encrypt the target data to obtain encrypted data, and send the encrypted data and the first identity authentication information to the communication cabinet 203; wherein, the first identity authentication information is the identity authentication information of the first device 201;
[0097] The communication cabinet 203 is used to authenticate the first device 201 based on the first identity authentication information, and when the identity authentication of the first device 201 passes, send the encrypted data to the second device 202;
[0098] The second device 202 is used to decrypt the encrypted data to obtain the target data.
[0099] Optionally, the first device 201 is one of an inverter and a master station, and the second device 202 is the other of the inverter and the master station.
[0100] Exemplarily, if the first device 201 is an inverter, then the second device 202 is a master station. Or, if the first device 201 is a master station, then the second device 202 is an inverter. The inverter embeds an encryption and decryption module to implement source - end encryption of uplink data (such as data to be processed) and terminal decryption of downlink instructions (such as control instructions); 2) The communication cabinet 203 embeds an authentication module to perform two - way identity authentication on both the inverter side and the master station side; 3) The master station side embeds an encryption and decryption module to implement terminal decryption of uplink data (such as data to be processed) and source - end encryption of downlink instructions (such as control instructions), realizing two - way secure transmission of data and instructions.
[0101] Exemplarily, the data transmission system 200 can be an inverter power station system, having a hierarchical two - way authentication and encryption system of inverter - communication cabinet - master station and master station - communication cabinet - inverter.
[0102] Optionally, the first device 201 is used to encrypt the target data to obtain encrypted data, and the way for the first device 201 to encrypt the target data includes at least one of symmetric encryption and asymmetric encryption. Correspondingly, the way for the second device 202 to decrypt the encrypted data includes at least one of symmetric encryption and asymmetric encryption.
[0103] Optionally, the first device 201 is used to send the encrypted data and the first identity authentication information to the communication cabinet 203. The encrypted data can also be called an encrypted data packet, and the encrypted data includes but is not limited to encrypted target data and an encrypted key. Among them, the encrypted target data is the data obtained by encrypting the target data based on the key, and the encrypted key is the data obtained by encrypting the key.
[0104] Optionally, the communication cabinet 203 is configured to authenticate the first device 201 based on the first identity authentication information. The first identity authentication information is the identity authentication information of the first device 201, and the first identity authentication information includes, but is not limited to, the digital signature of the first device 201 or the identity certificate of the first device 201. Among them, the identity certificate refers to a document or digital credential used to prove personal or institutional identity information, including types such as physical certificates (such as ID cards) and digital certificates (such as SSL certificates). In the embodiments of the present application, the main type of identity certificate mainly includes the digital credential type. The communication cabinet 203 is further configured to send encrypted data to the second device 202 when the identity authentication of the first device 201 is passed, so that the second device 202 can decrypt the encrypted data to obtain the target data.
[0105] Exemplarily, the method for authenticating the first device 201 based on the first identity authentication information includes, but is not limited to: performing digital signature authentication on the digital signature of the first device 201; or determining whether the identity certificate of the first device 201 exists in a pre-stored whitelist. The pre-stored whitelist is used to indicate devices that are pre-stored in the communication cabinet 203, have passed identity authentication, and can perform data transmission, such as an inverter and / or a master station that have passed identity authentication.
[0106] Exemplarily, when the digital signature authentication of the digital signature of the first device 201 is passed, it is determined that the identity authentication of the first device 201 is passed; also exemplarily, when the identity certificate of the first device 201 exists in the pre-stored whitelist, it is determined that the identity authentication of the first device 201 is passed.
[0107] Optionally, the target data includes, but is not limited to, data to be processed (such as current data, etc.) or control instructions.
[0108] Exemplarily, when the first device 201 is an inverter and the second device 202 is a master station, the target data includes data to be processed. The inverter sends the encrypted data to be processed to the master station so that after the master station decrypts the encrypted data to be processed, it can process the data to be processed. For example, the processing methods include, but are not limited to, at least one of deletion, modification, storage, etc.
[0109] Also exemplarily, when the first device 201 is a master station and the second device 202 is an inverter, the target data includes control instructions. The master station sends the encrypted control instructions to the inverter so that after the inverter decrypts the encrypted control instructions, it can perform corresponding control operations based on the control instructions. For example, the control instructions include at least one of a pause control instruction, a start control instruction, etc.
[0110] It can be understood that the first identity authentication information is only used to authenticate the first device 201 through the communication cabinet 203. Therefore, when the identity authentication of the first device 201 is passed, the communication cabinet 203 may not send the first identity authentication information to the second device 202, reducing redundant data in the data transmission process, thereby improving the data transmission efficiency.
[0111] In some specific embodiments, the data transmission system includes a first transmission scheme, the first identity authentication information includes a first digital signature, and the encrypted data includes encrypted target data and an encryption key;
[0112] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically used for:
[0113] When the first transmission scheme is started, a symmetric key is generated, and based on the symmetric key, the encrypted target data, the encryption key, and the first digital signature are determined and sent to the communication cabinet.
[0114] Specifically, the data transmission system includes a first transmission scheme. The first transmission scheme refers to a transmission scheme in which the first device directly sends encrypted data and the first identity authentication information to the communication cabinet. When the communication cabinet passes the identity authentication of the first device based on the first identity authentication information, it sends the encrypted data to the second device.
[0115] Specifically, the first device is used to generate a symmetric key when the first transmission scheme is started, perform a primary encryption process on the target data based on the symmetric key to obtain encrypted target data, and after performing a secondary encryption process on the encrypted target data and the symmetric key, obtain an encryption key and a first digital signature, and send the encrypted target data, the encryption key, and the first digital signature to the communication cabinet.
[0116] Optionally, the symmetric key can be a randomly generated key, which can ensure that a unique random key is used for each data transmission, effectively avoiding problems such as replay attacks and key leakage. The first device can perform symmetric encryption processing on the target data based on the symmetric key through a symmetric encryption algorithm to obtain encrypted target data.
[0117] Among them, the symmetric encryption (Symmetric Key Encryption) algorithm refers to an encryption method using a single-key cryptosystem. The same key can be used for both encryption and decryption of information at the same time. This encryption method is called symmetric encryption, also known as single-key encryption. Symmetric encryption algorithms include, but are not limited to, the data symmetric encryption (Data Encryption Standard, DES) algorithm and the advanced symmetric encryption (Advanced Encryption Standard, AES) algorithm.
[0118] Optionally, when the communication cabinet authenticates the first device based on the first authentication information and sends the encrypted data to the second device when the authentication of the first device is passed, it is specifically configured to:
[0119] Authenticate the first device based on the first digital signature, and when the authentication of the first device is passed, send the encrypted target data and the encrypted key to the second device.
[0120] Specifically, the communication cabinet is configured to authenticate the first device based on the first digital signature of the first device when the first transmission scheme is started, and when the authentication of the first device is passed, send the encrypted target data and the encrypted key to the second device.
[0121] Optionally, when the second device decrypts the encrypted data to obtain the target data, it is specifically configured to:
[0122] Decrypt the encrypted key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0123] Specifically, the second device is configured to first perform symmetric decryption on the encrypted key to obtain the symmetric key when the first transmission scheme is started, so as to perform secondary decryption on the encrypted target data based on the symmetric key to obtain the target data.
[0124] In some specific embodiments, when the first device generates a symmetric key at the start of the first transmission scheme, determines the encrypted target data, the encrypted key, and the first digital signature based on the symmetric key, and sends them to the communication cabinet, it is specifically configured to:
[0125] At the start of the first transmission scheme, generate a symmetric key, perform symmetric encryption on the target data based on the symmetric key to obtain the encrypted target data, perform asymmetric encryption on the symmetric key to obtain the encrypted key; sign the first hash value of the encrypted target data to obtain the first digital signature, and send the encrypted target data, the encrypted key, and the first digital signature to the communication cabinet.
[0126] Specifically, when the first transmission scheme is activated, the first device is used to randomly generate a symmetric key, symmetrically encrypt the target data based on the symmetric key to obtain the encrypted target data, asymmetrically encrypt the symmetric key with the public key of the second device stored in advance to obtain the encrypted key, determine the first hash value of the encrypted target data, and sign the first hash value with the signature private key of the first device to obtain the first digital signature of the first device. When the above processing is completed, the encrypted target data, the encrypted key, and the first digital signature are sent to the communication cabinet. The first digital signature is used to indicate the data obtained after signing the encrypted target data.
[0127] It can be understood that, for the convenience of the second device to perform asymmetric decryption on the encrypted key, the first device can asymmetrically encrypt the symmetric key with the public key of the second device. The first device can pre-store the public key of the second device in the storage space of the first device, and the second device can pre-store the private key of the second device in the storage space of the second device. Exemplarily, when the first device is an inverter, the public key of the second device is the public key of the master station, and the private key of the second device is the private key of the master station; also exemplarily, when the first device is the master station, the public key of the second device is the public key of the inverter, and the private key of the second device is the private key of the inverter. Similarly, for the convenience of the communication cabinet to decrypt the first digital signature to obtain the first hash value, the communication cabinet can also pre-obtain the signature public key of the first device and store it in the storage space of the communication cabinet, and the first device can pre-store the signature private key of the first device in the storage space of the first device.
[0128] Among them, the transmission scheme in the data transmission system can be specifically set according to user needs. Exemplarily, the user can start (or close) the corresponding transmission scheme by clicking, dragging, or pressing the display screen or external buttons of the first device, the second device, and the communication cabinet; or the user sends a transmission scheme control instruction to the first device, the second device, and the communication cabinet through the user terminal to start (or close) the corresponding transmission scheme. For example, the user sends a first transmission scheme start control instruction to the first device, the second device, and the communication cabinet through the user terminal to start the first transmission scheme.
[0129] Table 1 exemplarily provides a key storage table.
[0130] Table 1 Key Storage Table
[0131]
[0132] As can be seen from Table 1, the inverter keys for implementing asymmetric encryption and decryption include a first inverter public key and a first inverter private key. Among them, the first inverter public key is stored in the master station and is used to perform asymmetric encryption on the symmetric key of the master station. The first inverter private key is stored in the inverter and is used to perform asymmetric decryption on the encrypted key of the master station. Correspondingly, the master station keys for implementing asymmetric encryption and decryption include a first master station public key and a first master station private key. Among them, the first master station public key is stored in the inverter and is used to perform asymmetric encryption on the symmetric key of the inverter. The first master station private key is stored in the master station and is used to perform asymmetric decryption on the encrypted key of the inverter. The signature keys of the inverter include an inverter signature public key and an inverter signature private key. Among them, the inverter signature public key is stored in the communication cabinet and is used to authenticate the identity of the inverter based on the first digital signature of the inverter. The inverter signature private key is stored in the inverter and is used to sign the encrypted target data to obtain the first digital signature of the inverter. The signature keys of the master station include a master station signature public key and a master station signature private key. Among them, the master station signature public key is stored in the communication cabinet and is used to authenticate the identity of the master station based on the first digital signature of the master station. The master station signature private key is stored in the master station and is used to sign the encrypted target data to obtain the first digital signature of the master station.
[0133] Figure 3 One of the data transmission schematic diagrams provided by the embodiments of this application.
[0134] See Figure 3 , the first device can be used to generate a symmetric key, encrypt the target data and the symmetric key to obtain encrypted data (including encrypted target data and an encrypted key), sign the encrypted target data to obtain a first digital signature, and send the encrypted data and the first digital signature to the communication cabinet. The communication cabinet is used to perform identity authentication based on the first digital signature, and when the identity authentication of the first device passes, add a timestamp to the encrypted data and send it to the second device. The second device is used to decrypt the encrypted key and decrypt the encrypted target data based on the encrypted key to obtain the target data.
[0135] In some embodiments, the second device can also encrypt and transmit the target data to the first device. In this way, the second device is also used to generate a symmetric key, encrypt the target data and the symmetric key to obtain encrypted data (including encrypted target data and an encrypted key), sign the encrypted target data to obtain a first digital signature, and send the encrypted data and the first digital signature to the communication cabinet. The first device can also be used to decrypt the encrypted key and decrypt the encrypted target data based on the encrypted key to obtain the target data.
[0136] Optionally, both the first device and the second device include a Digital Signal Processor (DSP), and the inverter further includes an Advanced RISC Machine (ARM).
[0137] Exemplarily, when the first device is an inverter, the inverter reads the target data in the Digital Signal Processor (DSP) through the Advanced RISC Machine (ARM) to encrypt the target data through an encryption processing method.
[0138] Optionally, the second device can also verify the integrity of the target data. Exemplarily, when the first device sends the encrypted data, it carries data information such as the occupied space size of the target data. The second device verifies whether the decrypted target data is complete according to the above data information, and processes the target data when it determines that the target data is complete.
[0139] For example, when the second device determines that the target data is complete, it can send the target data to the Digital Signal Processor (DSP) for processing.
[0140] Figure 4 It is a schematic diagram of the application of a first transmission scheme provided by an embodiment of the present application.
[0141] See Figure 4 , when the first transmission scheme is started, the first device generates a symmetric key, symmetrically encrypts the target data based on the symmetric key to obtain encrypted target data, asymmetrically encrypts the symmetric key to obtain an encrypted key, determines the first hash value of the encrypted target data, signs the first hash value to obtain a first digital signature, and sends the encrypted target data, the encrypted key, and the first digital signature to the communication cabinet. The communication cabinet decrypts the first digital signature to obtain the first hash value of the encrypted target data, determines the second hash value of the encrypted target data and whether the first hash value and the second hash value match. When the first hash value and the second hash value match, a first timestamp is added to the encrypted target data and the encrypted key, and they are sent to the second device. The second device determines the current time and whether the difference between the current time and the first timestamp is less than or equal to a first threshold. When the difference between the current time and the first timestamp is less than or equal to the first threshold, the encrypted key is symmetrically decrypted to obtain the symmetric key, and the encrypted target data is decrypted based on the symmetric key to obtain the target data, completing the secure transmission loop. When the first hash value and the second hash value do not match or the difference between the current time and the first timestamp is greater than the first threshold, the data transmission system suspends data transmission.
[0142] When the first transmission scheme is started, each data packet uploaded by the first device contains the encrypted target data, encryption key, and digital signature of the communication. The communication cabinet verifies the digital signature in each data packet, providing relatively high security.
[0143] It can be understood that the communication method between the inverter, communication cabinet, and master station can be specifically selected according to the actual situation. Exemplarily, for example, the remote weighing data acquisition method 485 of the communication interface, the multi-master serial communication bus (Controller Area Network, CAN), the power line communication (Programmable Logic Controller, PLC) technology, etc. can be selected between the inverter and the communication cabinet to achieve communication. Also exemplarily, a wireless Wi-Fi network, an Internet Ethernet network, etc. can be selected between the communication cabinet and the master station to achieve communication.
[0144] In the embodiment of the present application, a double-layer encryption mechanism combining dynamic random symmetric keys (independently generated for each communication) and asymmetric encryption is used to double-encrypt the target data and the symmetric key, realizing encrypted data transmission between the first device, the communication cabinet, and the master station. The encryption and decryption operations are completely pre-positioned to the terminal devices (including the first device and the second device), effectively defending against data theft, tampering, and replay attacks. It avoids the problems of system paralysis and data leakage caused by the attack on the communication cabinet. Even if some terminal devices are attacked, the system can quickly isolate abnormal nodes through the real-time authentication mechanism of the communication cabinet, ensuring the communication security of other devices, greatly improving the system's fault tolerance and reliability, and enhancing the security during data transmission.
[0145] It can be understood that the embodiment of the present application adopts a hierarchical architecture of "terminal encryption + relay authentication" to achieve hierarchical encrypted transmission. The communication cabinet only undertakes the functions of protocol conversion and authentication, and does not need to process encryption and decryption operations. Even if the communication cabinet node is attacked, it can only intercept the encrypted target data and the encryption key, and cannot crack the original data, avoiding the problem of full-link leakage caused by the attack on the intermediate node. As an independent authentication node, the communication cabinet conducts two-way identity verification on the inverter and the master station respectively. Through the digital signature and pre-stored whitelist mechanism, it ensures the identity legality of the device, prevents forged terminals from accessing or network attacks, realizes the separation of device authentication and data transmission, establishes multiple trust barriers at the protocol layer, and improves the overall security of the data transmission system. At the same time, it can support a combination of multiple encryption algorithms, and can defend against replay attacks through the timestamp mechanism, with high flexibility and applicability to various application scenarios.
[0146] Optionally, when the communication cabinet authenticates the first device based on the first digital signature and sends the encrypted target data and the encryption key to the second device when the identity authentication of the first device passes, it is specifically used for:
[0147] Determine the second hash value of the first digital signature. When the first hash value matches the second hash value, determine that the identity authentication of the first device passes, and send the encrypted target data and the encryption key to the second device.
[0148] Specifically, when the first transmission scheme is started, the communication cabinet is used to decrypt the first digital signature of the first device through the signature public key of the first device to obtain the first hash value of the encrypted target data of the first device. And perform a hash operation on the encrypted target data to obtain the second hash value of the first digital signature of the first device. When the first hash value and the second hash value match, determine that the identity authentication of the first device passes, and send the encrypted target data and the encryption key to the second device.
[0149] In the embodiment of the present application, the first device is authenticated by digital signature, and the encrypted data is transmitted only when the identity authentication passes, which can improve the security during the data transmission process. And the communication cabinet is only used to implement the identity authentication of the device and does not encrypt or decrypt the data, thereby improving the stability of the data transmission process.
[0150] Optionally, when the second device decrypts the encryption key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically used for:
[0151] Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0152] Specifically, when the first transmission scheme is started, the second device is used to perform asymmetric decryption on the received encryption key based on the second device private key to obtain the symmetric key, and perform symmetric decryption on the encrypted target data based on the symmetric key to obtain the target data transmitted by the first device.
[0153] It can be understood that when the target data transmitted by the first device is data to be processed, the second device can perform corresponding processing operations on the target data. When the target data transmitted by the first device is a control instruction, the second device can perform corresponding control operations based on the target data.
[0154] In some specific implementation manners, after the first hash value matches the second hash value, the communication cabinet is specifically further used for:
[0155] Add a first timestamp to the encrypted target data and the encryption key, and send the encrypted target data and the encryption key carrying the first timestamp to the second device;
[0156] When the second device decrypts the encrypted key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically configured to:
[0157] Obtain the current time. When the difference between the current time and the first timestamp is less than or equal to the first threshold, decrypt the encrypted key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0158] Specifically, when the first transmission scheme is started and the first hash value of the first digital signature matches the second hash value, the communication cabinet can add the first timestamp to the encrypted target data and the encrypted key, and send the encrypted target data and the encrypted key carrying the first timestamp to the second device. Here, the timestamp is a digital form of recording time in a computer system, usually in seconds or milliseconds, and calculates the duration from the UNIX epoch (January 1, 1970 00:00:00 UTC) to the current moment.
[0159] In this way, when the first transmission scheme is started and the second device receives the encrypted target data and the encrypted key carrying the first timestamp, the second device can obtain the current time, calculate the difference between the current time and the first timestamp, and when the difference between the current time and the first timestamp is less than or equal to the first threshold, determine that the encrypted key and the encrypted target data are trusted data, perform asymmetric decryption on the encrypted key based on the public key of the second device to obtain the symmetric key, and thus perform symmetric decryption on the encrypted panel data based on the symmetric key to obtain the target data. Here, the first threshold can be specifically set according to the actual situation. For example, the first threshold is 1 s; or for another example, the first threshold is 3 s.
[0160] It can be understood that when the difference between the current time and the first timestamp is greater than the first threshold, the second device can determine that the encrypted key and the encrypted target data are not trusted data, that is, the transmission process of the encrypted key and the encrypted target data received by the second device takes a long time, and there may be problems such as being tampered with or having poor timeliness.
[0161] In the embodiment of the present application, by adding timestamps to the encrypted target data and the encrypted key by the communication cabinet, it is convenient for the second device to verify the validity (or trustworthiness) of the received encrypted data, and improves the security of the data transmission process.
[0162] In some specific implementation manners, the data transmission system further includes a second transmission scheme, the first identity authentication information includes a second digital signature, and the encrypted data includes encrypted target data and an encrypted key;
[0163] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically further used for:
[0164] When the second transmission scheme is started, generate a symmetric key, determine the encrypted target data, the encryption key, and the second digital signature based on the symmetric key, and send the second digital signature to the communication cabinet.
[0165] Specifically, the data transmission system further includes a second transmission scheme, which refers to a transmission scheme in which the first device first sends the first identity authentication information to the communication cabinet, and when the communication cabinet authenticates the first device based on the first identity authentication information and passes the authentication, the first device sends the encrypted data to the communication cabinet to send the encrypted data to the second device through the communication cabinet.
[0166] Specifically, the first device is used to generate a symmetric key when the second transmission scheme is started, symmetrically encrypt the target data based on the symmetric key to obtain target encrypted data, asymmetrically encrypt the symmetric key to obtain an encryption key. Sign the third hash value of the encryption key to obtain a second digital signature, and send the second digital signature to the communication cabinet. Among them, the second digital signature is used to indicate the data obtained after signing the encryption key.
[0167] Optionally, when the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the authentication of the first device passes, it is specifically used for:
[0168] Authenticate the first device based on the second digital signature, and when the authentication of the first device passes, send the first authentication passed information to the first device.
[0169] Specifically, the communication cabinet is used to authenticate the first device based on the second digital signature of the first device when the second transmission scheme is started, and when the authentication of the first device passes, send the first authentication passed information to the first device, and the first authentication passed information is used to indicate that the authentication of the first device passes.
[0170] Optionally, when the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically further used for:
[0171] When receiving the first authentication passed information, send the encrypted target data and the encryption key to the communication cabinet.
[0172] Specifically, when the second transmission scheme is started and the first device receives the first authentication passed information sent by the communication cabinet, the first device is used to send the encrypted target data and the encryption key to the communication cabinet.
[0173] Optionally, when the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device is passed, it is specifically further used for:
[0174] When the identity authentication of the first device is passed, send the encrypted target data and the encryption key to the second device.
[0175] Specifically, the communication cabinet is used to send the encrypted target data and the encryption key of the first device to the second device when the second transmission scheme is started and the identity authentication of the first device is passed.
[0176] Optionally, when the second device decrypts the encrypted data to obtain the target data, it is specifically used for:
[0177] Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
[0178] Specifically, the second device is used to perform asymmetric decryption on the encryption key when the second transmission scheme is started and the encrypted target data and the encryption key of the first device are received, obtain the symmetric key, and perform symmetric decryption on the encrypted target data based on the symmetric key to obtain the target data.
[0179] Exemplarily, for the specific implementation manners of the second device to determine the symmetric key and the encrypted target data based on the encryption key, reference may be made to the description of the above first transmission scheme, which will not be elaborated herein.
[0180] In some specific implementation manners, when the second transmission scheme is started, the first device generates a symmetric key, determines the encrypted target data, the encryption key, and the second digital signature based on the symmetric key, and when sending the second digital signature to the communication cabinet, it is specifically used for:
[0181] Generate the symmetric key when the second transmission scheme is started;
[0182] Parallelly execute the operations of encrypting the target data based on the symmetric key to obtain the encrypted target data and asymmetrically encrypting the symmetric key based on the first public key to obtain the encryption key;
[0183] Determine the third hash value of the encryption key, encrypt the third hash value based on the first signature key to obtain a second digital signature, and send the second digital signature to the communication cabinet through the first communication link.
[0184] Specifically, when the second transmission scheme is started, the first device is used to generate a symmetric key, and concurrently execute operations of symmetrically encrypting target data based on the symmetric key to obtain encrypted target data, and asymmetrically encrypting the symmetric key based on the first public key (which can also be referred to as the public key of the second device) to obtain an encryption key. Perform a hash operation on the encryption key to determine the third hash value of the encryption key, encrypt the third hash value of the encryption key based on the first signature key (which can also be referred to as the signature key of the first device) to obtain the second digital signature of the first device, and send the second digital signature to the communication cabinet through the first communication link.
[0185] In this way, the communication cabinet can authenticate the first device based on the second digital signature of the first device when the second transmission scheme is started, and when the authentication of the first device passes, send the first authentication passed information to the first device through the first communication link.
[0186] Optionally, the first device includes a first communication link and a second communication link. Among them, the first communication link is used to transmit the first digital signature, the authentication passed information of the first device, and the encryption key. The second communication link is used to transmit the encrypted target data.
[0187] Exemplarily, for the specific implementation manner of the communication cabinet to authenticate the first device based on the second digital signature of the first device, reference can be made to the relevant description of the above first transmission scheme, which will not be elaborated here.
[0188] Optionally, when the first device receives the first authentication passed information and sends the encrypted target data and the encryption key to the communication cabinet, it specifically is used for:
[0189] When receiving the first authentication passed information, send the encryption key to the communication cabinet through the first communication link, and send the encrypted target data to the communication cabinet through the second communication link.
[0190] Specifically, when the first device receives the first authentication passed information through the first communication link, it sends the encryption key to the communication cabinet through the first communication link and sends the encrypted target data to the communication cabinet through the second communication link.
[0191] Exemplarily, when the communication cabinet receives the encrypted target data and the encryption key, it can add a second timestamp to the encrypted target data and the encryption key, and send the encrypted target data and the encryption key carrying the second timestamp to the second device, facilitating the second device to perform validity verification on the encrypted target data and the encryption key based on the second timestamp.
[0192] Exemplarily, when the second transmission scheme is started, the key storage tables of the first device and the second device can refer to Table 1 above.
[0193] Figure 5 This is the second schematic diagram of data transmission provided by the embodiments of the present application.
[0194] See Figure 5 , the first device can be used to generate a symmetric key, and perform operations of encrypting the target data in parallel to obtain the encrypted target data, encrypting the symmetric key to obtain the encryption key, and signing the encryption key to obtain the second digital signature, and send the second digital signature to the communication cabinet. The communication cabinet is used to perform identity authentication based on the second digital signature, and when the identity authentication of the first device passes, send the first authentication passed information to the first device. The first device is also used to send encrypted data (including the encrypted target data and the encryption key) to the communication cabinet. The communication cabinet is also used to add a timestamp to the encrypted data and send it to the second device. The second device is used to decrypt the encryption key and decrypt the encrypted target data based on the encryption key to obtain the target data.
[0195] In some embodiments, the second device can also encrypt and transmit the target data to the first device. In this way, the second device is also used to generate a symmetric key, and perform operations of encrypting the target data in parallel to obtain the encrypted target data, encrypting the symmetric key to obtain the encryption key, and signing the encryption key to obtain the second digital signature, and send the second digital signature to the communication cabinet. The second device is also used to send encrypted data (including the encrypted target data and the encryption key) to the communication cabinet. The first device is also used to decrypt the encryption key and decrypt the encrypted target data based on the encryption key to obtain the target data.
[0196] Figure 6 This is an application schematic diagram of a second transmission scheme provided by the embodiments of the present application.
[0197] See Figure 6, when the second transmission scheme is started, the first device generates a symmetric key, symmetrically encrypts the target data based on the symmetric key to obtain encrypted target data, asymmetrically encrypts the symmetric key to obtain an encrypted key, and determines the third hash value of the encrypted key, signs the third hash value to obtain a second digital signature. At this time, the first device sends the second digital signature to the communication cabinet, the communication cabinet decrypts the second digital signature to obtain the third hash value of the encrypted target data, determines the fourth hash value of the encrypted target data and whether the third hash value and the fourth hash value match, and when the third hash value and the fourth hash value match, sends the first authentication passed information to the first device. The first device sends the encrypted target data and the encrypted key to the communication cabinet, and the communication cabinet adds a second timestamp to the encrypted target data and the encrypted key and sends them to the second device. The second device determines the current time and whether the difference between the current time and the second timestamp is less than or equal to the first threshold. When the difference between the current time and the second timestamp is less than or equal to the first threshold, the second device symmetrically decrypts the encrypted key to obtain the symmetric key, and decrypts the encrypted target data based on the symmetric key to obtain the target data. When the third hash value and the fourth hash value do not match or the difference between the current time and the second timestamp is greater than the first threshold, the data transmission system suspends data transmission.
[0198] When the second transmission scheme is started, the first device can perform the encryption operations on the encrypted data and the symmetric key in parallel, reducing the encryption processing delay, and transmitting the encrypted data and the digital signature through different communication links to achieve the physical separation transmission of the encrypted data and the encrypted key. Moreover, each data packet uploaded by the first device to the second device only contains the encrypted target data of this communication, improving the overall security of the data transmission system.
[0199] In some specific embodiments, the data transmission system further includes a third transmission scheme, the first identity authentication information includes a first identity certificate, and the encrypted data includes encrypted target data and an encrypted key;
[0200] When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is used for:
[0201] When the third transmission scheme is started, sending the first identity certificate to the communication cabinet;
[0202] The second device is further used for:
[0203] When the third transmission scheme is started, sending a second identity certificate to the communication cabinet; wherein, the second identity certificate is the identity certificate of the second device;
[0204] When the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device is passed, it specifically is used for:
[0205] When the third transmission scheme is started and both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, generate second authentication passed information and send the second authentication passed information to the first device and the second device.
[0206] Specifically, the data transmission system further includes a third transmission scheme. The third transmission scheme means that the first device first sends first identity authentication information to the communication cabinet, and the second device sends second identity authentication information to the communication cabinet. When the communication cabinet authenticates the first device based on the first identity authentication information and passes the authentication, and authenticates the second device based on the second identity authentication information and passes the authentication, the first device sends encrypted data to the communication cabinet to send the encrypted data to the second device through the communication cabinet. Among them, the first identity certificate is the identity certificate of the first device, and the second identity certificate is the identity certificate of the second device.
[0207] Specifically, the first device is used to send the first identity certificate to the communication cabinet when the third transmission scheme is started, and the second device is used to send the second identity certificate to the communication cabinet when the third transmission scheme is started. In this way, the communication cabinet can match the first identity certificate, the second identity certificate with the identity certificates in the pre-stored whitelist when the third transmission scheme is started. When the first identity certificate, the second identity certificate match the identity certificates in the pre-stored whitelist, it is determined that both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, generate second authentication passed information. The second authentication passed information is used to indicate that the identity authentications of both the first device and the second device are passed. At this time, the communication cabinet sends the second authentication passed information to the first device and the second device.
[0208] Optionally, when the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is further used for:
[0209] When receiving the second authentication passed information, generate a symmetric key, determine the encrypted target data and the encrypted key based on the symmetric key, and send the encrypted target data and the encrypted key to the communication cabinet.
[0210] Specifically, the first device is used to generate a symmetric key when the third transmission scheme is started and the second authentication passed information is received, symmetrically encrypt the target data based on the symmetric key to obtain encrypted target data, and asymmetrically encrypt the symmetric key to obtain an encrypted key, and send the encrypted target data and the encrypted key to the communication cabinet.
[0211] Optionally, when the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device is passed, it is specifically configured to:
[0212] Send the encrypted target data and the encryption key to the second device.
[0213] Specifically, the communication cabinet is configured to send the encrypted target data and the encryption key of the first device to the second device when the third transmission scheme is started and both the first identity certificate and the second identity certificate exist in the pre-stored whitelist.
[0214] Exemplarily, when the communication cabinet receives the encrypted target data and the encryption key, it may add a third timestamp to the encrypted target data and the encryption key, and send the encrypted target data and the encryption key carrying the third timestamp to the second device, facilitating the second device to perform validity verification on the encrypted target data and the encryption key based on the third timestamp.
[0215] Table 2 exemplarily provides the second key storage table.
[0216] Table 2 The Second Key Storage Table
[0217]
[0218] It can be seen from Table 2 that the inverter keys for implementing asymmetric encryption and decryption include a second inverter public key and a second inverter private key. Among them, the second inverter public key is stored in the master station and is used to perform asymmetric encryption on the symmetric key of the master station, and the second inverter private key is stored in the inverter and is used to perform asymmetric decryption on the encryption key of the master station. Correspondingly, the master station keys for implementing asymmetric encryption and decryption include a second master station public key and a second master station private key. Among them, the second master station public key is stored in the inverter and is used to perform asymmetric encryption on the symmetric key of the inverter, and the second master station private key is stored in the master station and is used to perform asymmetric decryption on the encryption key of the inverter.
[0219] Figure 7 This is the third data transmission schematic diagram provided by the embodiments of the present application.
[0220] See Figure 7, the first device can be used to send a first identity certificate to the communication cabinet, the second device can be used to send a second identity certificate to the communication cabinet, the communication cabinet can be used to authenticate the first device based on the first identity certificate and authenticate the second device based on the second identity certificate, and when both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, send a second authentication passed message to the first device and the second device. The first device is also used to generate a symmetric key, encrypt the target data and the symmetric key to obtain encrypted data (including encrypted target data and encrypted key), and send the encrypted data to the communication cabinet. The communication cabinet is also used to add a timestamp to the encrypted data and send it to the second device. The second device is used to decrypt the encrypted key and decrypt the encrypted target data based on the encrypted key to obtain the target data.
[0221] In some embodiments, the second device can also encrypt and transmit the target data to the first device. In this way, the second device can also be used to generate a symmetric key, encrypt the target data and the symmetric key to obtain encrypted data (including encrypted target data and encrypted key), and send the encrypted data to the communication cabinet. The first device can also be used to decrypt the encrypted key and decrypt the encrypted target data based on the encrypted key to obtain the target data.
[0222] Figure 8 It is a schematic application diagram of a third transmission scheme provided by an embodiment of the present application.
[0223] See Figure 8 , when the third transmission scheme is started, the first device sends a first identity certificate to the communication cabinet, and the second device sends a second identity certificate to the communication cabinet. The communication cabinet receives the first identity certificate and the second identity certificate, and determines whether both the first identity certificate and the second identity certificate exist in the pre-stored whitelist. When both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, send a second authentication passed message to the first device and the second device. The first device generates a symmetric key, symmetrically encrypts the target data based on the symmetric key to obtain encrypted target data, asymmetrically encrypts the symmetric key to obtain an encrypted key, and sends the encrypted target data and the encrypted key to the communication cabinet. The communication cabinet adds a third timestamp to the encrypted target data and the encrypted key and sends it to the second device. The second device determines the current time and whether the difference between the current time and the third timestamp is less than or equal to a first threshold. When the difference between the current time and the third timestamp is less than or equal to the first threshold, symmetrically decrypt the encrypted key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data. When the first identity certificate and / or the second identity certificate does not exist in the pre-stored whitelist, or the difference between the current time and the third timestamp is greater than the first threshold, the data transmission system suspends data transmission.
[0224] When the third transmission scheme is started, the first device only needs to perform identity authentication with the communication cabinet at the beginning of communication to establish communication. Each uploaded data packet contains the encrypted target data and the encryption key for this communication. During the encrypted data transmission process, the communication cabinet does not perform identity authentication on each received data packet, reducing the identity authentication delay of the communication cabinet.
[0225] Optionally, when the second device decrypts the encrypted data to obtain the target data, it is specifically used for:
[0226] When receiving the second authentication passed information, decrypt the encryption key to obtain the symmetric key, and based on the symmetric key, decrypt the encrypted target data to obtain the target data.
[0227] Specifically, when the second device starts the third transmission scheme and receives the second authentication passed information, it performs asymmetric decryption on the encryption key to obtain the symmetric key, and based on the symmetric key, performs symmetric decryption on the encrypted target data to obtain the target data.
[0228] Exemplarily, the specific implementation manners of the second device for determining the symmetric key and the encrypted target data based on the encryption key can refer to the relevant descriptions of the above first transmission scheme, which will not be elaborated here.
[0229] The data transmission system provided by the embodiments of the present application encrypts the target data through the first device to obtain encrypted data, and sends the encrypted data and the first identity authentication information of the first device to the communication cabinet. The communication cabinet authenticates the first device based on the first identity authentication information, and when the identity authentication of the first device passes, sends the encrypted data to the second device. The second device decrypts the encrypted data to obtain the target data. In this way, data transmission between the first device, the communication cabinet, and the second device can be realized based on the data encryption transmission method. The communication cabinet only serves as a transit node with an identity authentication function, avoiding data leakage problems caused by network attacks on the communication cabinet and improving the stability of the data transmission process.
[0230] Figure 9 It is one of the flow diagrams of a data transmission method provided by the embodiments of the present application. Refer to Figure 9 , the data transmission method includes:
[0231] S901. Encrypt the target data to obtain encrypted data and the first identity authentication information;
[0232] S902. Send the encrypted data and the first identity authentication information to the communication cabinet, so that the communication cabinet authenticates the first device based on the first identity authentication information, and when the identity authentication of the first device passes, send the encrypted data to the second device; wherein, the second device is the other one of the inverter and the master station; the second device is communicatively connected to the communication cabinet.
[0233] It can be understood that the above steps S901 and S902 can be applied to the first device 201 in the above data transmission system 200. The first device 201 transmits data to the second device 202 through the communication cabinet 203 in a data encryption transmission manner. The communication cabinet 203 only serves as a transit node with an identity authentication function, avoiding the problem of data leakage caused by the communication cabinet 203 being attacked by the network and improving the stability of the data transmission process.
[0234] Figure 10 This is the second flowchart of a data transmission method provided by an embodiment of the present application, which is applied to a communication cabinet. Refer to Figure 10 , the data transmission method includes:
[0235] S1001. When receiving the first identity authentication information and the encrypted data sent by the first device, authenticate the first device based on the first identity authentication information;
[0236] S1002. When the identity authentication of the first device passes, send the encrypted data to the second device, so that the second device decrypts the encrypted data to obtain the target data.
[0237] It can be understood that the above steps S1001 and S1002 can be applied to the communication cabinet 203 in the above data transmission system 200. The first device 201 transmits data to the second device 202 through the communication cabinet 203 in a data encryption transmission manner. The communication cabinet 203 only serves as a transit node with an identity authentication function, avoiding the problem of data leakage caused by the communication cabinet 203 being attacked by the network and improving the stability of the data transmission process.
[0238] Figure 11 This is the third flowchart of a data transmission method provided by an embodiment of the present application, which is applied to a second device. Refer to Figure 11 , the data transmission method includes:
[0239] S1101. When receiving the encrypted data, decrypt the encrypted data to obtain the target data; wherein, the encrypted data is sent by the communication cabinet when the identity authentication of the first device passes based on the first identity authentication information, and the first identity authentication information is the identity authentication information of the first device.
[0240] It can be understood that the above steps S1101 and S1102 can be applied to the second device 202 in the above data transmission system 200. The second device 202 receives the data transmitted by the first device 201 through the communication cabinet 203 in the data encryption transmission mode. The communication cabinet 203 only serves as a transit node with an identity authentication function, avoiding the data leakage problem caused by the communication cabinet 203 being attacked by the network and improving the stability of the data transmission process.
[0241] For the implementation principle and technical effects of the data transmission method provided in this embodiment, reference can be made to the data transmission system provided in the above method embodiment, and details are not described here in this embodiment.
[0242] Figure 12 It is a schematic structural diagram of an electronic device provided in this application. The electronic device can be the first device, the second device, or the communication cabinet. As Figure 12 shown, the electronic device provided in this embodiment includes: at least one processor 1201 and a memory 1202. Optionally, the electronic device further includes a communication component 1203. Among them, the processor 1201, the memory 1202, and the communication component 1203 are connected through a bus.
[0243] In the specific implementation process, at least one processor 1201 executes the computer execution instructions stored in the memory 1202, so that at least one processor 1201 executes the above data transmission method.
[0244] For the specific implementation process of the processor 1201, reference can be made to the above method embodiment, and its implementation principle and technical effects are similar, and details are not described here in this embodiment.
[0245] In the above embodiment, it should be understood that the processor can be a central processing unit (English: Central Processing Unit, abbreviated: CPU), and can also be other general-purpose processors, digital signal processors (English: Digital Signal Processor, abbreviated: DSP), application-specific integrated circuits (English: Application Specific Integrated Circuit, abbreviated: ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0246] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0247] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0248] This application also provides a computer program product, including a computer program, which implements the above data transmission method when executed by a processor.
[0249] This application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the above data transmission method is implemented.
[0250] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic memory, a flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0251] An exemplary readable storage medium is coupled to the processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0252] The division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in an electrical, mechanical, or other forms.
[0253] The unit described as a separate component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0254] In addition, in each embodiment of the present invention, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0255] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.
[0256] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When this program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes: ROM, RAM, magnetic disks, or optical discs, etc., which can store program codes.
[0257] Finally, it should be noted that: After considering the specification and practicing the invention disclosed herein, those skilled in the art will easily think of other implementation schemes of the present invention. The present invention aims to cover any variations, uses, or adaptive changes of the present invention. These variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the exact structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A data transmission system, characterized in that, It includes a first device, a second device, and a communication cabinet. The first device is one of an inverter and a master station, and the second device is the other of the inverter and the master station. Both the first device and the second device are communicatively connected to the communication cabinet. The first device is configured to encrypt target data to obtain encrypted data and send the encrypted data and first authentication information to the communication cabinet. The first authentication information is the authentication information of the first device. The communication cabinet is configured to authenticate the first device based on the first authentication information and, when the authentication of the first device passes, send the encrypted data to the second device. The second device is configured to decrypt the encrypted data to obtain the target data.
2. The data transmission system according to claim 1, wherein, The data transmission system includes a first transmission scheme. The first authentication information includes a first digital signature, and the encrypted data includes encrypted target data and an encrypted key. When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and first authentication information to the communication cabinet, it is specifically configured to: When the first transmission scheme is started, generate a symmetric key, determine the encrypted target data, the encrypted key, and the first digital signature based on the symmetric key, and send them to the communication cabinet. When the communication cabinet authenticates the first device based on the first authentication information and, when the authentication of the first device passes, sends the encrypted data to the second device, it is specifically configured to: Authenticate the first device based on the first digital signature and, when the authentication of the first device passes, send the encrypted target data and the encrypted key to the second device. When the second device decrypts the encrypted data to obtain the target data, it is specifically configured to: Decrypt the encrypted key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
3. The data transmission system according to claim 2, wherein When the first device generates a symmetric key, determines the encrypted target data, the encrypted key, and the first digital signature based on the symmetric key, and sends them to the communication cabinet when the first transmission scheme is started, it is specifically configured to: When the first transmission scheme is started, generate a symmetric key, perform symmetric encryption on the target data based on the symmetric key to obtain the encrypted target data, and perform asymmetric encryption on the symmetric key to obtain the encrypted key. Sign the first hash value of the encrypted target data to obtain the first digital signature, and send the encrypted target data, the encrypted key, and the first digital signature to the communication cabinet. When the communication cabinet authenticates the first device based on the first digital signature and, when the authentication of the first device passes, sends the encrypted target data and the encrypted key to the second device, it is specifically configured to: Determine the second hash value of the first digital signature. When the first hash value matches the second hash value, determine that the identity authentication of the first device passes, and send the encrypted target data and the encryption key to the second device; When the second device decrypts the encryption key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically used for: Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
4. The data transmission system according to claim 3, wherein After the first hash value matches the second hash value, the communication cabinet is specifically further used for: Add a first timestamp to the encrypted target data and the encryption key, and send the encrypted target data and the encryption key carrying the first timestamp to the second device; When the second device decrypts the encryption key to obtain the symmetric key and decrypts the encrypted target data based on the symmetric key to obtain the target data, it is specifically used for: Obtain the current time. When the difference between the current time and the first timestamp is less than or equal to the first threshold, decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
5. The data transmission system according to claim 1, wherein The data transmission system further includes a second transmission scheme. The first identity authentication information includes a second digital signature, and the encrypted data includes the encrypted target data and the encryption key; When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically further used for: When the second transmission scheme is started, generate a symmetric key, determine the encrypted target data, the encryption key, and the second digital signature based on the symmetric key, and send the second digital signature to the communication cabinet; When the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device passes, it is specifically used for: Authenticate the first device based on the second digital signature, and send a first authentication passed message to the first device when the identity authentication of the first device passes; When the first device encrypts the target data to obtain encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it is specifically further used for: When receiving the first authentication passed message, send the encrypted target data and the encryption key to the communication cabinet; When the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device passes, it is specifically further used for: When the identity authentication of the first device passes, send the encrypted target data and the encryption key to the second device; When the second device decrypts the encrypted data to obtain the target data, it specifically is used for: Decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
6. The data transmission system according to claim 5, wherein When the first device generates a symmetric key at the start of the second transmission scheme, determines the encrypted target data, the encryption key, and the second digital signature based on the symmetric key, and sends the second digital signature to the communication cabinet, it specifically is used for: Generate the symmetric key at the start of the second transmission scheme; Parallelly execute the operations of encrypting the target data based on the symmetric key to obtain the encrypted target data, and asymmetrically encrypting the symmetric key based on the first public key to obtain the encryption key; Determine the third hash value of the encryption key, encrypt the third hash value based on the first signature key to obtain the second digital signature, and send the second digital signature to the communication cabinet through the first communication link; When the first device receives the first authentication passed information and sends the encrypted target data and the encryption key to the communication cabinet, it specifically is used for: When receiving the first authentication passed information, send the encryption key to the communication cabinet through the first communication link, and send the encrypted target data to the communication cabinet through the second communication link.
7. The data transmission system according to claim 1, wherein The data transmission system further includes a third transmission scheme, the first identity authentication information includes a first identity certificate, and the encrypted data includes the encrypted target data and the encryption key; When the first device encrypts the target data to obtain the encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is used for: Send the first identity certificate to the communication cabinet at the start of the third transmission scheme; The second device is further used for: Send a second identity certificate to the communication cabinet at the start of the third transmission scheme; wherein, the second identity certificate is the identity certificate of the second device; When the communication cabinet authenticates the first device based on the first identity authentication information and sends the encrypted data to the second device when the identity authentication of the first device passes, it specifically is used for: When the third transmission scheme starts and both the first identity certificate and the second identity certificate exist in the pre-stored whitelist, generate a second authentication passed information, and send the second authentication passed information to the first device and the second device; When the first device encrypts the target data to obtain the encrypted data and sends the encrypted data and the first identity authentication information to the communication cabinet, it specifically is further used for: When receiving the second authentication passed information, generate a symmetric key, determine the encrypted target data and the encryption key based on the symmetric key, and send the encrypted target data and the encryption key to the communication cabinet; When the communication cabinet authenticates the first device based on the first authentication information and sends the encrypted data to the second device when the authentication of the first device passes, it is specifically configured to: Send the encrypted target data and the encryption key to the second device; When the second device decrypts the encrypted data to obtain the target data, it is specifically configured to: When receiving the second authentication passed information, decrypt the encryption key to obtain the symmetric key, and decrypt the encrypted target data based on the symmetric key to obtain the target data.
8. A data transmission method, characterized in that, Applied to a first device, the first device is one of an inverter and a master station, the first device is communicatively connected to a communication cabinet, and the data transmission method includes: Perform encryption processing on target data to obtain encrypted data and first authentication information; Send the encrypted data and the first authentication information to the communication cabinet, so that the communication cabinet authenticates the first device based on the first authentication information, and when the authentication of the first device passes, send the encrypted data to a second device; wherein, the second device is the other of the inverter and the master station; the second device is communicatively connected to the communication cabinet.
9. A data transmission method, characterized in that, Applied to a communication cabinet, the communication cabinet is communicatively connected to a first device and a second device, the first device is one of an inverter and a master station, and the second device is the other of the inverter and the master station; The data transmission method includes: When receiving the first authentication information and the encrypted data sent by the first device, authenticate the first device based on the first authentication information; When the authentication of the first device passes, send the encrypted data to the second device, so that the second device performs decryption processing on the encrypted data to obtain the target data.
10. A data transmission method, characterized in that Applied to a second device, the first device is one of the inverter and the master station, the second device is the other of the inverter and the master station, and both the first device and the second device are communicatively connected to the communication cabinet. The data transmission method includes: When receiving the encrypted data, decrypt the encrypted data to obtain the target data; wherein, the encrypted data is sent when the communication cabinet passes the authentication of the first device based on the first authentication information, and the first authentication information is the authentication information of the first device.
11. An electronic device, characterized in that, Includes: A memory, a processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor executes the method according to claim 8 when the electronic device is the first device, executes the method according to claim 9 when the electronic device is the communication cabinet, and executes the method according to claim 10 when the electronic device is the second device.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to claim 8, 9 or 10.
13. A computer program product, characterized in that, Comprising a computer program which, when executed by a processor, implements the method according to claim 8, 9 or 10.
Citation Information
Patent Citations
Anti-pollution network coding method based on digital signature
CN103746813A
Anonymous attestation
CN110300972A
Method and device for designing secure interaction protocol in energy internet scene
CN115118756A
Networking interconnection communication method and system for electric energy meters in metering box
CN115913602A
Distribution network data transmission method and device, equipment and storage medium
CN116155568A