A remote upgrade method, device, storage medium and program product for power distribution terminal
By introducing a communication architecture that separates business channels from management channels in the distribution terminal, the problems of low manual upgrade efficiency and real-time business interference in the existing technology are solved, and an efficient and stable remote upgrade method is implemented, which is suitable for large-scale distribution automation systems.
Patent Information
- Application Number
- CN202510812463.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-06-18
AI Technical Summary
The existing distribution terminal upgrade method relies on manual operation and is inefficient. In addition, real-time business communications are easily disturbed during the remote upgrade process, affecting system stability and efficiency.
A dual-channel communication architecture with separate business channels and management channels is adopted. Segmented transmission and integrity verification of upgrade files are performed through the management channel to ensure that real-time business communications are not interfered with, and program update operations are performed on the distribution terminal side.
It realizes efficient remote upgrade of distribution terminals, reduces manual operation and maintenance costs, ensures the real-time performance and stability of the system, and is suitable for centralized upgrade management of large-scale distribution automation systems.
Smart Images

Figure CN120335842B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of power equipment communication technology, and in particular to a method, device, storage medium and program product for remote upgrading of a power distribution terminal. Background Art
[0002] In recent years, with the large-scale construction and continued advancement of distribution automation systems, feeder terminal units (FTUs), as key intelligent devices in distribution network sites, have played an increasingly important role in power system operation monitoring, control execution, and data collection. To ensure the intelligence, security, and stability of system operations, FTUs require regular program version updates and functional upgrades.
[0003] Currently, FTU equipment upgrades primarily rely on manual on-site operations or remote program delivery, presenting numerous challenges that require urgent resolution. Given the massive scale of existing network equipment, manual, unit-by-unit upgrades are costly and inefficient, making them difficult to meet the demands of large-scale centralized upgrades. Furthermore, in the existing distribution network communication architecture, telemetry, telesignaling, and remote control services share the same communication channel as file transfer tasks. In concurrent communication scenarios, these services have a higher transmission priority, making file transfer messages susceptible to interruption, discarding, or retransmission, impacting terminal upgrade efficiency. Summary of the Invention
[0004] In response to the shortcomings of the existing technology, the present application provides a remote upgrade method, equipment, storage medium and program product for distribution terminals, which at least solve the problem in the existing technology that the distribution terminal upgrade process requires occupying business channels and easily interferes with real-time business communications.
[0005] In order to achieve the above objectives and other advantages, some embodiments of the present application provide the following aspects:
[0006] In a first aspect, some embodiments of the present application provide a method for remotely upgrading a power distribution terminal, comprising:
[0007] The power master station establishes communication connections with the power distribution terminal for a business channel and a management channel, respectively. The business channel is used to transmit high-priority real-time business data, and the management channel is used to transmit control instructions and data content of upgrade files. The business channel and the management channel operate independently of each other and do not interfere with each other's communication.
[0008] The power master station sends an upgrade activation instruction to the power distribution terminal through the management channel to start the remote upgrade process;
[0009] The power master station divides the program file to be upgraded into multiple data segments and sends them to the power distribution terminal through the management channel in sequence;
[0010] The power distribution terminal receives the multiple data segments and caches them. After all the data segments are received, the upgrade file is checked for integrity. If the check passes, the program update operation of the power distribution terminal is started.
[0011] In a second aspect, some embodiments of the present application further provide an electronic device, comprising:
[0012] One or more processors; and a memory storing computer program instructions, wherein when the computer program instructions are executed, the processor executes any one of the above-mentioned methods for remotely upgrading a power distribution terminal.
[0013] On the third aspect, some embodiments of the present application also provide a computer-readable storage medium on which a computer program and / or instructions are stored. When the computer program and / or instructions are executed by a processor, the remote upgrade method of the distribution terminal as described in any one of the above is implemented.
[0014] In a fourth aspect, some embodiments of the present application further provide a computer program product, comprising a computer program and / or instructions, which, when executed by a processor, implements the remote upgrade method for a power distribution terminal as described in any one of the above.
[0015] Compared with the related art, the solution provided in the embodiment of the present application adopts a dual-channel communication architecture with a separation of business channel and management channel, which can effectively avoid the upgrade process from occupying real-time communication resources and prevent interference with four remote services such as telemetry and telesignaling, thereby ensuring the real-time and stability of the operation of the distribution terminal system. During the upgrade process, the power master station sends an upgrade activation instruction through the management channel, and divides the program file to be upgraded into multiple data segments by frame, and transmits them to the distribution terminal in sequence, realizing the remote issuance and segmented transmission of the upgrade file, improving the overall transmission efficiency, and reducing manual operation and maintenance costs. The distribution terminal performs an integrity check after receiving all the data segments, and executes the program update operation only when the check is passed, ensuring the correctness of the upgrade file and the transmission reliability. This upgrade method realizes the high automation and intelligence of the remote upgrade process of the distribution terminal, and is suitable for centralized upgrade management in large-scale distribution automation systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other implementation methods can be obtained based on these drawings without paying any creative work.
[0017] Figure 1This is a flow chart of a method for remotely upgrading a power distribution terminal provided in an embodiment of the present application;
[0018] Figure 2 This is a processing flow chart of the power distribution terminal provided in an embodiment of the present application monitoring the service channel and the management channel respectively;
[0019] Figure 3 This is a timing diagram of the normal file transmission and integrity verification process provided by the embodiment of the present application;
[0020] Figure 4 This is a timing diagram of data recovery and transmission through a breakpoint resume mechanism after an interruption occurs during the transmission process provided by an embodiment of the present application;
[0021] Figure 5 It is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0023] First embodiment
[0024] The first embodiment of the present application relates to a method for remotely upgrading a power distribution terminal. Figure 1 As shown, the method may include the following steps:
[0025] Step S1: The power master station establishes communication connections for the business channel and the management channel with the distribution terminal respectively, wherein the business channel is used to transmit high-priority real-time business data, and the management channel is used to transmit the control instructions and data content of the upgrade file. The business channel and the management channel operate independently of each other, and their communication does not interfere with each other.
[0026] Specifically, regarding step S1, during the system initialization phase, the power master station establishes two independent communication connections with the distribution terminals: a business channel and a management channel. The business channel is established based on the IEC 60870-5-104 communication protocol (standard 104 protocol) and typically monitors port 2404. It is used to carry high-priority real-time business data such as telemetry, telesignaling, remote control, and remote regulation, ensuring the continuity and timeliness of the master station's online monitoring, control, and operational status acquisition of the distribution terminals. The management channel monitors port 2402 and communicates using the extended 104 communication protocol. It is primarily used for file transfer control during the remote upgrade process, including sending upgrade activation instructions, issuing program file data segments, exchanging version information, and confirming upgrade status.
[0027] The business channel and management channel are independent of each other in terms of physical links and logical processing, and the communication processes do not interfere with each other. They can complete parallel processing of upgrade operations while ensuring that real-time business communications are not interrupted.
[0028] Step S2: The power master station sends an upgrade activation instruction to the distribution terminal through the management channel to start the remote upgrade process.
[0029] For step S2, specifically, after successfully establishing the management channel connection, the power master station sends an upgrade activation instruction to the distribution terminal. The instruction belongs to a data frame of a specific function type defined in the 104 communication protocol, such as constructing a data frame with a function type of write file activation. The frame carries the necessary information for initializing the upgrade task (such as function code TI=210: representing function upgrade; transmission reason code COT=6: representing master station activation upgrade request), establishes an upgrade task between the master station and the terminal, and triggers the distribution terminal to enter the remote upgrade preparation state.
[0030] After receiving this activation command, the distribution terminal performs the following preprocessing: initializing internal storage space for caching the upgrade file, resetting the previous file reception status, and suspending non-critical business processing tasks unrelated to the upgrade to free up necessary processing and communication resources for the upgrade process. The distribution terminal then returns an upgrade activation confirmation frame to the power master station, indicating that it has successfully entered the upgrade standby state. Only after receiving this confirmation can the master station initiate the subsequent file data segment transmission process.
[0031] Step S3: The power master station divides the program file to be upgraded into multiple data segments and sends them to the power distribution terminal through the management channel in sequence.
[0032] Specifically, regarding step S3, upon receiving the upgrade activation confirmation from the distribution terminal, the power station initiates the program file distribution process. To meet the communication protocol's restrictions on encrypted frame length and improve transmission efficiency, the power station segments the complete program file to be upgraded into several ordered data segments according to a preset single-frame message length threshold (e.g., 1.5KB).
[0033] Each data segment generates a corresponding data segment transmission message, which can include the following key fields: data segment content: represents the valid data part of the segment file; data offset field: used to identify the starting byte position of the segment data in the complete program file, which is convenient for the terminal to reorganize the subsequent data and resume the transmission; simple check code: such as CRC value (cyclic redundancy check value), used to quickly check whether the segment data is damaged during the transmission process.
[0034] The power master station sends these data segments, frame by frame, to the distribution terminal via the management channel, in sequential order. Upon receiving each data segment, the distribution terminal immediately performs field parsing and data verification, and returns a write confirmation frame to the master station, providing feedback on the reception status of the data segment and confirming successful reception. If a frame fails to be received or verification fails, the power master station can initiate a retransmission based on the contents of the write confirmation frame until the data segment is successfully written to the distribution terminal's cache, ensuring reliable and consistent data transmission.
[0035] Step S4: The power distribution terminal receives multiple data segments and caches them. After all data segments are received, the upgrade file is checked for integrity. If the check passes, the program update operation of the power distribution terminal is started.
[0036] Specifically, regarding step S4, after the distribution terminal successfully receives and caches all upgrade data segments, it enters the upgrade file integrity verification phase. During the upgrade initialization phase, the power master station has already sent a digest of the target upgrade file to the distribution terminal. This digest value, calculated using the MD5 (Message Digest) algorithm or the SHA (Secure Hash Algorithm), uniquely identifies the integrity of the target file's content.
[0037] The distribution terminal will re-perform hash calculation on the cached complete upgrade file locally, and compare the locally calculated hash value with the summary information of the target upgrade file issued by the power master station.
[0038] If the comparison results are consistent, indicating that the upgrade file has not been damaged or tampered with during transmission, the distribution terminal will immediately execute the program update process. The update process includes writing the new version of the firmware to the running storage area. After the writing is complete, the terminal automatically restarts and loads the new program version for operation.
[0039] If the comparison fails, it indicates that the file content does not match the master's expectations, potentially indicating data loss, content tampering, or link interference. In this case, the distribution terminal will refuse to perform the upgrade and, based on pre-set policies, trigger one of the following error handling procedures: actively rolling back to the previous stable program image to ensure the continuity and security of terminal operation; or returning a verification failure status to the master, which will decide whether to resend the upgrade file or abort the upgrade task.
[0040] It is not difficult to find that compared with the relevant technologies, the solution provided by the embodiment of the present application adopts a dual-channel communication architecture with a separation of business channel and management channel, which can effectively avoid the upgrade process from occupying real-time communication resources and prevent interference with four remote services such as telemetry and telesignaling, thereby ensuring the real-time and stability of the operation of the distribution terminal system. During the upgrade process, the power master station sends an upgrade activation instruction through the management channel, and divides the program file to be upgraded into multiple data segments by frame, and transmits them to the distribution terminal in sequence, realizing the remote issuance and segmented transmission of the upgrade file, improving the overall transmission efficiency, and reducing the manual operation and maintenance costs. The distribution terminal performs an integrity check after receiving all the data segments, and only executes the program update operation under the premise of passing the check, ensuring the correctness of the upgrade file and the transmission reliability. This upgrade method realizes the high automation and intelligence of the remote upgrade process of the distribution terminal, and is suitable for centralized upgrade management in large-scale distribution automation systems.
[0041] Second embodiment
[0042] The second embodiment of the present application relates to a method for remote upgrading of a power distribution terminal. The second embodiment is an improvement based on the first embodiment, and the specific improvement is that: in the second embodiment of the present application, the management channel communicates based on the extended IEC 60870-5-104 communication protocol to improve the carrying capacity of single-frame data during large file transmission and meet the requirements of remote upgrades for efficient transmission performance. The extended IEC 60870-5-104 communication protocol includes: extending the length field used to indicate the total length of the application protocol data unit in the standard IEC60870-5-104 communication protocol from 1 byte to 2 bytes to support the transmission of no more than 65535 bytes of data content per frame message.
[0043] Specifically, the Extended 104 protocol, while adhering to the existing protocol framework, extends the length field in the Application Protocol Data Unit (APDU) structure at the field level. In the standard 104 protocol, the APDU's length field is 1 byte (8 bits), indicating a maximum message length of 255 bytes, limiting the upper limit of data that can be transmitted in a single frame. To overcome this limitation, the Extended 104 protocol extends the length field from 1 byte to 2 bytes (16 bits), increasing the theoretical maximum length of a single message frame to 65,535 bytes.
[0044] During implementation, the power master station dynamically negotiates and sets the transmission length of each data frame based on the encryption chip capabilities of the distribution terminal and the current network link stability. The recommended range is 1024 to 10,000 bytes. This length range significantly reduces the number of communication frames, shortens file transfer time, and improves the efficiency of remote file distribution while ensuring message encryption integrity and link reliability.
[0045] It should be noted that this extended communication protocol is only used in the management channel to carry control instructions and file data transmission during the upgrade process; the business channel continues to follow the standard IEC 60870-5-104 communication protocol to handle real-time telemetry, telesignaling, remote control and other data communication tasks. The two do not affect each other, thereby achieving logical separation and protocol compatibility between the management channel and the real-time business channel.
[0046] Third embodiment
[0047] The third embodiment of the present application relates to a method for remotely upgrading a power distribution terminal. The third embodiment is an improvement on the first embodiment. The specific improvement is that: in the third embodiment of the present application, a specific implementation of a dual-channel monitoring and encryption authentication mechanism is provided, that is, step S1 can further include the following steps:
[0048] Step S101: After the power distribution terminal is started, it acts as a server and monitors two physical ports simultaneously: port 2404 and port 2402. Port 2404 corresponds to a service channel based on the standard IEC 60870-5-104 communication protocol, and port 2402 corresponds to a management channel based on the extended IEC 60870-5-104 communication protocol.
[0049] Step S102: When any of the two physical ports monitors a connection request sent by the power master station, the power distribution terminal determines whether the corresponding channel has enabled an encrypted communication mode;
[0050] Step S103: If the channel enables encrypted communication mode, gateway encryption authentication is first performed, and gateway-level identity verification and initial key exchange are completed between the power distribution terminal and the power master station;
[0051] Step S104: After the gateway encryption authentication succeeds, the master station encryption authentication is continued. The power distribution terminal establishes a secure session with the power master station and negotiates to generate the master station encryption random number and the terminal encryption random number.
[0052] Step S105: After the master station encryption authentication is successful, the power distribution terminal stores the master station encryption random number and the terminal encryption random number respectively and binds them to the communication session of the corresponding port;
[0053] Step S106: If the encrypted communication mode is not enabled in the channel, the power distribution terminal skips the encryption authentication process after establishing the connection and directly enters the business interaction phase defined by the corresponding communication protocol.
[0054] Specifically, refer to Figure 2 As shown in the figure, after power-on or restart, the power distribution terminal acts as a server and simultaneously monitors two physical ports: port 2404 and port 2402. Port 2404 corresponds to the service channel and uses the standard IEC 60870-5-104 communication protocol. It is mainly used for high-priority real-time service transmission, such as telemetry, telesignaling, remote control, and remote adjustment data. Port 2402 corresponds to the management channel and uses the extended IEC 60870-5-104 communication protocol for transmitting non-real-time control data such as terminal upgrade packages and configuration files.
[0055] When a distribution terminal receives a connection request from the power master station on any port (port 2404 or port 2402), it first determines, based on pre-set communication parameters, whether the channel is configured for encrypted communication mode. If so, it initiates gateway encryption authentication. Gateway encryption authentication is the first line of defense for secure communication in the distribution system, verifying that both communicating parties are trusted. This process can be based on pre-deployed symmetric or asymmetric key mechanisms. Specifically, the distribution terminal performs an identity handshake with the power master station's encryption gateway, exchanging authentication request and response messages and completing initial key negotiation or verification. This process uses methods such as SM1 (symmetric encryption algorithm) / SM2 (asymmetric encryption algorithm) or EB-level authentication (EB-level authentication is a Class B certification for power system inter-device communication established by the State Grid Corporation of China, typically indicating higher-level bidirectional identity authentication and encrypted transmission requirements). If authentication succeeds, the terminal proceeds to the next stage of the master station-level encryption negotiation process. If authentication fails, the connection is rejected, terminating the current port communication session.
[0056] After the gateway completes encryption authentication, the distribution terminal proceeds to the master station encryption authentication process to establish the data encryption session key for the communication session. During the encryption handshake, the power master station and the distribution terminal negotiate and generate two sets of random numbers: a master station encryption random number (used to encrypt data sent from the power master station to the distribution terminal); and a terminal encryption random number (used to encrypt data sent from the distribution terminal to the power master station). After authentication, both parties establish a symmetric encryption communication session based on these random numbers, which is used for encryption and decryption of subsequent data segment messages.
[0057] If encryption authentication fails with the master station, the distribution terminal will refuse to enter the encrypted session, disconnect the current communication connection, discontinue subsequent encrypted data transmission, and not save the master station's random number and its associated key parameters. To facilitate subsequent troubleshooting or security audits, the terminal can log information related to the encryption authentication failure and indicate the cause of failure, such as authentication handshake timeout, inconsistent key digest, illegal random number format, or unregistered master station identity. The failure event can also be reported to the dispatch system or remote platform through the platform reporting mechanism.
[0058] After the master station completes encryption authentication, the power master station establishes connections with the distribution terminal via ports 2404 and 2402, respectively, forming two logically independent secure communication session environments. The distribution terminal persistently stores the random number information generated during the authentication process and binds it to the corresponding port, ensuring that the encryption state corresponds to the physical channel and operates independently of each other. For example, the distribution terminal stores the encrypted random number of power master station A and its own random number on port 2404 for encryption of four remote services; and stores the encrypted random number information of circuit master station B on port 2402 for encryption of file transfer channels. This prevents confusion in encryption status and supports multiple channels maintaining different encryption states simultaneously.
[0059] For large file transfer scenarios, such as when a single-frame message is long (e.g., over 1KB), the power master station uses the EB90 encryption header structure, which complies with the "Definition of Security Messages for State Grid Power Distribution Terminals," for data encryption. This structure reserves dedicated fields in the message header for identifying the encryption algorithm flag, checksum, key number, etc., maximizing the data payload while being compatible with security authentication mechanisms, enabling efficient encrypted transmission. For short message communication scenarios (such as control messages like file write confirmation frames and upgrade activation frames), the power master station uses a full message encryption mechanism, completely encapsulating and encrypting the entire Application Protocol Data Unit (APDU) to ensure that critical control commands and task identification information cannot be intercepted or tampered with.
[0060] If encryption is not enabled for the communication channel in step S102, the distribution terminal will skip the aforementioned encryption authentication process and, after establishing a TCP connection with the power master station, directly enter the service interaction phase defined by the corresponding communication protocol. For connections to port 2404, the distribution terminal directly enters the standard four-remote service interaction process based on the IEC 60870-5-104 communication protocol, processing telemetry, telesignaling, remote control, and remote adjustment commands sent from the power master station. For connections to port 2402, the terminal enters the file management and upgrade data interaction process based on the extended 104 communication protocol, which handles file upgrade activation instructions, segmented data transmission, verification, and program updates.
[0061] Furthermore, both the business channel and the management channel adopt the TCP long connection mechanism actively initiated by the power master station. After the connection is established, the business channel and the management channel respectively maintain a continuous and stable connection with the distribution terminal, that is, both channels are long connection sessions, support the heartbeat mechanism and the abnormal reconnection mechanism, and ensure that the communication link is not interrupted throughout the life cycle. Specifically, when the power master station successfully establishes a communication connection with the distribution terminal through the management channel and completes the encryption authentication process, if the software upgrade task is not triggered at present, the management channel will enter the idle maintenance state. In order to maintain the continuity of the connection and the activity of the channel, the power master station will send heartbeat frames to the distribution terminal at a preset frequency. After receiving the heartbeat frame, the terminal returns a response, thereby realizing periodic confirmation of the link. Among them, the sending frequency of the heartbeat frame is a configurable parameter, which can be flexibly set according to the system deployment environment, link bandwidth or master station policy, and is not specifically limited in this embodiment.
[0062] It is not difficult to find that in the embodiment of the present application, by introducing a dual-channel monitoring mechanism and a separate encryption authentication process in the distribution terminal, each channel can determine whether to enable encrypted communication according to the preset strategy after establishing a connection, and execute the gateway encryption authentication and master station encryption authentication processes in sequence, and finally bind the encrypted random number and session information generated by the authentication to the corresponding port respectively. The distribution terminal can perform independent security control on the business data communication based on the IEC 60870-5-104 communication protocol and the upgrade file transmission based on the extended 104 communication protocol, respectively, and realize the complete decoupling of the business channel and the management channel in terms of communication path and security policy. This design not only improves the security and controllability of communication, but also enhances the system's adaptability to multi-channel and multi-task parallel scenarios, and supports the flexible execution of remote upgrade tasks under the premise of ensuring business real-time performance, thereby improving the overall operating efficiency, security level and deployment flexibility of the distribution terminal system.
[0063] It should be noted that the third embodiment of the present application may also be an improvement based on any one or more of the first to second embodiments.
[0064] Fourth embodiment
[0065] The fourth embodiment of the present application relates to a method for remotely upgrading a power distribution terminal. The fourth embodiment is an improvement on the first embodiment. The specific improvement is that: in the fourth embodiment of the present application, a specific implementation method of segmented transmission and segment-by-segment confirmation is provided, that is, step S3 can further include the following steps:
[0066] Step S301: The power master station segments the program file according to a preset per-frame message length threshold to form multiple data segment messages. Each data segment message contains at least a field identifying a data segment number and a check code. The data segment content is used to carry the actual data fragment at the corresponding position of the program file, and the check code is used to verify the integrity of the data segment message.
[0067] Step S302: The power master station sends each data segment message sequentially through the management channel. The distribution terminal immediately verifies the data segment message after receiving it and returns a write file confirmation frame for each data segment message. The write file confirmation frame includes the corresponding data segment number and a reception status indicating success or failure of reception.
[0068] Step S303: If the distribution terminal feedback data segment message is received successfully, the power master station continues to send the next data segment message. If the distribution terminal feedback reception fails or times out without confirmation, the power master station retransmits the current data segment message until it succeeds or the number of retries exceeds the limit.
[0069] Specifically, refer to Figure 3 The figure shows the standard process for the power master station to send upgrade files to the distribution terminal through the management channel, which includes four stages: write file activation, data segment transmission, transmission confirmation, and MD5 integrity check. The specific process is as follows:
[0070] During the file write activation phase, the power master station sends a file write activation request message to the distribution terminal. This message carries the "Type Identifier TI = 210 (indicating a file write command), the "Transmission Cause Code COT = 6 (indicating an activation request), and a task number with an Operation Identifier = 7." The Operation Identifier is an identifier used in the protocol to identify a specific interaction process or command category, such as the number of an operation step such as file write activation, data transmission request, or response frame confirmation. After receiving this command, the distribution terminal performs preprocessing, such as initializing the buffer area, and returns a file write activation confirmation message, which carries "TI = 210, COT = 7 (indicating approval of the activation request), and Operation Identifier = 8."
[0071] Data segment transmission phase: After receiving the upgrade activation confirmation from the distribution terminal, the power master station first divides the program file to be upgraded into equal lengths or as needed according to the preset per-frame message length, generating several data segments. Each data segment is encapsulated as a write file data segment message frame transmitted via the management channel. Each frame message contains at least the following key fields: data segment content and data checksum. The data segment content field stores the actual data payload content of the segment, which is a byte sequence intercepted at the current offset position of the program file and is usually fixed-length or variable-length at the end. The data segment content can use segment sequence numbers (e.g., segment 1, segment 2, segment 3, etc.) to indicate the relative position of the segment data in the complete upgrade file. This is used by the distribution terminal to correctly cache and reorganize the upgrade file structure, and can also serve as a basis for breakpoint resumption or retransmission positioning. The data check code field verifies the integrity of the current data segment. It can be CRC16 (16-bit cyclic redundancy check), CRC32 (32-bit cyclic redundancy check), or a simple checksum. Upon receiving the data, the terminal verifies the data segment based on this field to determine whether a retransmission is required. A frame control field may also be included, containing control bits such as whether this is the last frame, whether an acknowledgment is required, and a retransmission flag. This message carries "TI = 210, COT = 5 (indicating a file data segment write), and Operation Flag = 9."
[0072] During the file write confirmation phase, the distribution terminal uses a single-frame confirmation mechanism to confirm receipt of the data segments of the upgrade file sent by the power master station. Specifically, after the power master station sends a data segment message to the distribution terminal, the terminal successfully receives and completes the structural analysis and integrity verification of the data segment and immediately returns a file write confirmation message as a confirmation of successful receipt of the data segment. This message carries "TI = 210, COT = 5, Operation ID = 10."
[0073] Distribution terminals can also use a multi-frame acknowledgment mechanism to respond in batches to data segments sent by the power master station. This means the master station can continuously send multiple data segment messages (for example, n segments) without waiting for acknowledgment of each segment. After receiving n data segments, the distribution terminal returns a single write file acknowledgment message to confirm receipt of the batch. This message carries "TI = 210, COT = 5, Operation Flag = 10." This mechanism offers higher transmission efficiency than frame-by-frame acknowledgment, significantly reducing message exchanges, lowering link load, and improving the master station's continuous transmission capacity. It is particularly suitable for communication environments with relatively stable links or limited bandwidth. Preferably, n is a configurable parameter that can be dynamically set based on the master station's delivery policy, terminal load capacity, or task type. For example, the terminal can configure a preset acknowledgment period of every four or eight frames, flexibly balancing real-time performance and transmission efficiency.
[0074] If the write file confirmation frame returned by the distribution terminal indicates that the data segment failed to be received (e.g., failed verification, format error, etc.), or if the power master station does not receive any confirmation response within the set confirmation waiting time (e.g., 10 seconds) (deemed to be a timeout and unconfirmed), the power master station will deem the data segment transmission a failure and immediately trigger the retransmission mechanism for the current data segment. Under the retransmission mechanism, the master station will reconstruct and resend the failed data segment message and wait for confirmation from the distribution terminal again. The power master station can set a maximum retransmission threshold (e.g., setting a timeout and retransmission retry count of 1 to 3). If the number of retries exceeds this threshold and still fails to receive a successful confirmation, the power master station can implement one of the following handling strategies: abort the current upgrade task and report a failure status; roll back the transmitted data and notify the terminal to release the cache; or initiate an upgrade retry after renegotiating the transmission parameters.
[0075] Integrity Verification Phase: After confirming that all data segments have been sent, the master station sends an MD5 verification request message to the terminal. This message carries "TI=212, COT=6," requesting the distribution terminal to perform a hash check on the upgrade. The distribution terminal locally calculates the MD5 value of the upgrade file and compares it with the value preset by the power master station. If the verification is successful, the distribution terminal returns an integrity verification confirmation message carrying "TI=212, COT=7," indicating that the data is complete and the upgrade can proceed. If the verification fails, the power master station can retransmit some data segments or the entire upgrade file, or the terminal can trigger a rollback mechanism.
[0076] It is not difficult to find that in the embodiments of the present application, by introducing a data segment-based frame transmission mechanism and a segment-by-segment confirmation and retransmission control strategy during the remote upgrade process, the reliability of the upgrade file distribution and the system's fault tolerance are effectively improved. At the same time, by setting up a reception confirmation and retransmission mechanism, the master station can promptly initiate a retransmission when the terminal fails to successfully receive a certain segment of data, avoiding the interruption of the overall upgrade due to a single point of failure. In addition, this mechanism also supports on-demand configuration of single-frame or multi-frame confirmation, taking into account transmission efficiency and link stability, and is suitable for complex and changing distribution communication network environments.
[0077] It should be noted that the fourth embodiment of the present application may also be an improvement based on any one or more of the first to third embodiments.
[0078] Fifth embodiment
[0079] The fifth embodiment of the present application relates to a method for remotely upgrading a power distribution terminal. The fifth embodiment is an improvement on the first embodiment. The specific improvement is that: in the fifth embodiment of the present application, a specific implementation of a breakpoint resume mechanism based on data offset is provided, that is, step S3 can also include the following steps:
[0080] During the data transmission process, after successfully receiving each data segment message, the power distribution terminal extracts and records the corresponding data offset from the data segment message;
[0081] When file transmission is interrupted, the distribution terminal retains the offset of the most recently successfully received data;
[0082] After re-establishing the communication link, the power distribution terminal sends the recorded data offset to the power master station via a write file confirmation frame;
[0083] After the power master station receives the write file confirmation frame and confirms that it is consistent with the current task to be resumed, it determines the breakpoint position according to the data offset and continues to transmit the remaining untransmitted data segment message from the breakpoint position to realize breakpoint resumption of program files.
[0084] Specifically, refer to Figure 4 The figure illustrates the complete process of resuming file transfers based on data offsets after a communication interruption during file transfer. The broken line in the figure indicates a link interruption during data transmission, preventing the master station from receiving subsequent confirmation frames. In this case, the distribution terminal does not clear its current buffer but instead retains the data offset corresponding to the most recently received data segment as the breakpoint for the current upgrade task. After the communication link is reestablished between the master station and the distribution terminal, the master station resends a resume activation message carrying "TI = 210, COT = 6, Operation ID = 9." The distribution terminal responds to the resume activation by sending a resume activation confirmation message to the master station. This message carries "TI = 210, COT = 7, Operation ID = 10." The confirmation frame also carries the previously retained data offset and the current upgrade task ID, notifying the master station of the breakpoint location and resuming the transfer.
[0085] The power master station first performs a consistency check on the task identifier contained in the confirmation frame to ensure that the current resumed transmission operation belongs to the same previous upgrade task. If the task identifier is inconsistent with the master station's current task context, the power master station can choose to abort the resumed transmission, reactivate the task, or request the terminal to realign its state. Assuming the task identifier is consistent, the power master station locates the starting position of the unfinished transmission in the upgrade file based on the feedback data offset, and reorganizes and sends the remaining data segment message using this offset as the starting point. The organizational structure of each data segment is consistent with the initial transmission stage and is still sent frame by frame through the management channel. The distribution terminal continues to execute the reception and confirmation process.
[0086] The above-mentioned retransmission process will continue until the entire program file is transferred, and the final integrity verification step confirms that the upgrade file transfer is successful, and then enters the program writing and version upgrade stage.
[0087] It is not difficult to find that the embodiments of this application introduce a breakpoint resume mechanism to address file transfer interruptions caused by communication interruptions, link anomalies, or system restarts during the actual remote upgrade process. By recording the data offset on the distribution terminal side and transmitting this information back to the power master station after the link is restored, the power master station can locate the unfinished part based on the breakpoint information and resume transmitting the remaining file data from the interrupted position, avoiding repeated transmissions and upgrade interruptions, significantly improving the system's robustness and upgrade success rate in unstable network environments.
[0088] Furthermore, the power master station segments the program file according to a preset per-frame message length threshold to form multiple data segment messages, and may further include the following steps:
[0089] During the initialization phase of the upgrade task, the maximum encrypted message length supported by the encryption machine configured at the power master station and the encryption chip integrated in the power distribution terminal are obtained, and the minimum value of the two is taken as the single-frame message length threshold;
[0090] The single-frame message length threshold is used as the basis for data segmentation, and the program file is divided into multiple data segment messages in sequence from the starting byte according to the single-frame message length threshold. The length of each data segment message does not exceed the single-frame message length threshold, and the data offset field compared to the starting position in the complete upgrade file is recorded in each data segment message.
[0091] Specifically, the power master station first obtains the maximum encryptable message length supported by its configured encryption device (such as a national encryption machine), for example, 1.5KB. Simultaneously, the master station also obtains the maximum decryptable message length supported by the encryption chip integrated into the target distribution terminal, for example, 2.0KB, through the device registry, terminal capability query, or negotiation. The smaller of these two values is determined as the single-frame message length threshold for this upgrade task (for example, 1.5KB), which serves as the upper limit for subsequent upgrade file segmentation and message construction. This threshold ensures that each data segment message, when transmitted over a secure link, will not exceed encryption capabilities, resulting in transmission failure, data loss, or decryption errors.
[0092] Based on this message length threshold, the master station sequentially divides the file contents into multiple data segment messages, starting from the starting byte of the upgrade program file. The actual length of each data segment does not exceed this threshold, forming several independent upgrade data frames, which are then sent frame by frame to the terminal via the management channel. Within each data segment message, the master station also embeds a data offset field (e.g., an offset value in bytes). This field indicates the starting position of the current data segment within the complete upgrade file. This field is used to identify the starting point for resuming transmission after a communication anomaly. It can also guide data segment sorting and integrity verification during local file caching and reconstruction on the terminal.
[0093] It should be noted that the fifth embodiment of the present application may also be an improvement based on any one or more of the first to fourth embodiments.
[0094] Sixth embodiment
[0095] The sixth embodiment of the present application relates to a method for remotely upgrading a power distribution terminal. The sixth embodiment is an improvement on the first embodiment. The specific improvement is that: in the sixth embodiment of the present application, a specific implementation method for integrity verification of upgrade files and a safe rollback strategy is provided. That is, the integrity verification of the upgrade file in step S4 may further include the following steps:
[0096] After all data segments of the upgrade file are transmitted, the power master station sends a verification instruction containing the summary information of the target upgrade file to the distribution terminal. The summary information is the hash check value generated by the power master station for the upgrade file.
[0097] After receiving the complete upgrade file, the distribution terminal performs local hash calculation and compares the calculation result with the hash check value issued by the power master station.
[0098] If the comparison is consistent, the file integrity check is considered to have passed, and the power distribution terminal will execute the program writing and version replacement operations, and automatically restart to load the new version of the program;
[0099] If the comparison fails, it is considered that there is an error in the file transfer. The distribution terminal refuses to execute the program update operation and triggers at least one of the following processing flows: actively rolls back to the stable version of the program before the upgrade to resume operation; or feedbacks the verification failure status to the power master station, and the power master station re-initiates the upgrade file transfer process.
[0100] Specifically, after the distribution terminal completes receiving all upgrade data segments, the power master station proactively sends a verification request to the terminal. This request includes a summary of the corresponding upgrade file, such as a file hash value generated using MD5, SHA-256, or other hashing algorithms, which represents the original integrity characteristics of the file recorded by the master station. After the distribution terminal completes the reorganization of the upgrade file in its cache, it immediately performs a local hash calculation to generate the hash value of the actual received complete file.
[0101] The terminal then compares this locally calculated value bit by bit with the target hash value issued by the master. If the hash values match, the file has not been tampered with or lost during transmission, the file integrity check passes, and the next step in the program update process can be entered. If the hash values do not match, it indicates that anomalies such as packet loss, tampering, or incorrect overwriting may have occurred during the data reception process, making the file content unreliable. If the integrity check fails, the upgrade process is automatically aborted and the failure response process is initiated.
[0102] When the verification passes, the distribution terminal executes the program writing process, burns the new version program file to the running storage area, and automatically completes the restart operation to load the new version firmware and enter normal working state; when the verification fails, the distribution terminal refuses to execute the program update operation and triggers at least one of the following processing methods: Active rollback mechanism: The terminal loads the stable version program before the upgrade from the internal backup area or the reserved area, and resets the boot flag to ensure that the terminal can still be restored to an operational state without completing the security upgrade, ensuring that the power distribution function is not affected. Failure reporting mechanism: The distribution terminal sends an upgrade failure status frame or a feedback message with an error code to the power master station through the management channel to inform the power master station of the cause and status of the upgrade failure. The power master station can use this to determine whether to restart the complete upgrade process, or locate the erroneous data segment based on the breakpoint information and retransmit it.
[0103] It is not difficult to find that in the embodiment of the present application, by introducing a hash digest-based integrity verification mechanism into the remote upgrade process, combined with an automated processing strategy for upgrade success and failure, the data security and system stability of the distribution terminal during the program version update process are significantly improved. On the one hand, by sending the hash verification value from the master station and the terminal recalculating and comparing it locally, the integrity of the file is guaranteed from the source; on the other hand, when the verification fails, the terminal can automatically trigger the version rollback mechanism to restore to the stable program before the upgrade, or return the failure status to the master station to support subsequent differential retransmission, ensuring that the system has good self-recovery and remote diagnosis capabilities.
[0104] The step division of the above various methods is only for the purpose of clear description. During implementation, they can be combined into one step or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this application; adding insignificant modifications or introducing insignificant designs to the algorithm or process without changing the core design of the algorithm and process are all within the scope of protection of this application.
[0105] In addition, some embodiments of the present application further provide an electronic device. The electronic device may be various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, etc. The electronic device may also be various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices.
[0106] The electronic device includes: one or more processors; and a memory storing computer program instructions, wherein when the computer program instructions are executed, the processor executes a method for remotely upgrading a power distribution terminal as provided in any one or more of the above embodiments. Figure 5An exemplary structural diagram of the electronic device is disclosed. The electronic device includes: one or more processors 1101, a memory 1102, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the electronic device, including instructions stored in or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some other embodiments, if necessary, multiple processors and / or multiple buses can be used with multiple memories and multiple memories. Similarly, multiple electronic devices can be connected, with each device providing some of the necessary operations. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or required herein.
[0107] The electronic device may further include: an input device 1103 and an output device 1104. The processor 1101, the memory 1102, the input device 1103 and the output device 1104 may be connected via a bus or other means. Figure 5 The bus connection is taken as an example.
[0108] Input device 1103 can receive input digital or character information and generate key signal input related to user settings and function control of the electronic device. Examples include a touch screen, keypad, mouse, trackpad, touchpad, pointing stick, one or more mouse buttons, trackball, joystick, and other input devices. Output device 1104 may include a display device, auxiliary lighting devices (e.g., LEDs), and tactile feedback devices (e.g., vibration motors). The display device may include, but is not limited to, a liquid crystal display, a light emitting diode display, and a plasma display. In some embodiments, the display device may be a touch screen.
[0109] To provide user interaction, the electronic device may be a computer. The computer includes a display device (e.g., a cathode ray tube or LCD monitor) for displaying information to the user, and a keyboard and pointing device (e.g., a mouse) through which the user can provide input to the computer. Other types of devices may also be used to provide user interaction; for example, feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback), and input from the user may be received in any form (e.g., voice input or tactile input).
[0110] In embodiments of the present application, a computer-readable medium stores a computer program / instructions. When executed by a processor, the computer program / instructions implement a method for remotely upgrading a power distribution terminal provided in any one or more of the aforementioned embodiments. The computer-readable medium may be included in the electronic device described in the aforementioned embodiments, or it may exist independently and not be incorporated into the device. The computer-readable medium carries one or more computer-readable instructions.
[0111] The memory 1102 can be used as a non-transitory computer-readable storage medium to store non-transitory software programs, non-transitory computer executable programs, and modules. The processor 1101 executes the non-transitory software programs, instructions, and modules stored in the memory 1102 to execute various functional applications and data processing of the server, thereby implementing the program instructions / modules corresponding to the method provided in any one or more of the above embodiments of the present application.
[0112] The memory 1102 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and applications required for at least one function; the data storage area may store data created based on the use of the electronic device, etc. In addition, the memory 1102 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory 1102 may optionally include a memory remotely located relative to the processor 1101, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0113] It should be noted that the computer-readable medium described in this application may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above. Computer-readable media may be, for example, but not limited to: electrical, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or device.
[0114] Computer-readable media includes both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory, static random access memory, dynamic random access memory, other types of random access memory, read-only memory, electrically erasable programmable read-only memory, flash memory or other memory technology, compact discs, digital versatile discs or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information that can be accessed by a computing device.
[0115] Computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as C or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network or a wide area network, or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0116] In the above embodiments, all or part of the steps or functions of the present invention may be implemented using software, hardware, firmware, or any combination thereof. For example, implementation may be achieved using a dedicated integrated circuit, a general-purpose computer, or any other similar hardware device. In some embodiments, the software program of the present application may be executed by a processor to implement the above steps or functions. Similarly, the software program of the present application (including related data structures) may be stored in a computer-readable recording medium, such as a RAM memory, a magnetic or optical drive, a floppy disk, or the like. In addition, some steps or functions of the present application may be implemented using hardware, for example, as a circuit that cooperates with a processor to perform the various steps or functions.
[0117] The computer program product provided in the embodiments of the present application includes one or more computer programs / instructions that, when executed by a processor, fully or partially produce the processes or functions described in accordance with the embodiments of the present application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0118] The flowcharts or block diagrams in the accompanying drawings illustrate the possible architectures, functions and operations of the devices, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment or part of code, and the module, program segment or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-specific system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0119] The scope of this application is defined by the appended claims rather than the foregoing description and is therefore intended to encompass within this application all changes that come within the meaning and range of equivalents of the claims. Any reference signs in the claims should not be construed as limiting the claims to which they relate. In addition, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices stated in a device claim may also be implemented by one unit or device through software or hardware. Words such as "first" and "second" are only used to distinguish the description and do not indicate any particular order, nor should they be understood as indicating or implying relative importance.
[0120] The above descriptions are merely specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art may easily propose variations or substitutions within the technical scope disclosed in the present application, and such variations or substitutions shall be encompassed within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be subject to the scope of protection of the claims, and the above descriptions shall be regarded as exemplary and non-limiting.
Claims
1. A remote upgrade method for a power distribution terminal, characterized in that: include: The power master station establishes communication connections with the power distribution terminal for a business channel and a management channel, respectively. The business channel is used to transmit high-priority real-time business data, and the management channel is used to transmit control instructions and data content of upgrade files. The business channel and the management channel operate independently of each other and do not interfere with each other's communication. The steps of establishing communication connections of a service channel and a management channel between the power master station and the power distribution terminal respectively include: After startup, the power distribution terminal acts as a server and monitors two physical ports simultaneously: port 2404 and port 2402. Port 2404 corresponds to a service channel based on the standard IEC 60870-5-104 communication protocol, and port 2402 corresponds to a management channel based on the extended IEC 60870-5-104 communication protocol. When any of the two physical ports monitors a connection request sent by the power master station, the power distribution terminal determines whether the corresponding channel enables an encrypted communication mode; If the channel uses encrypted communication mode, gateway encryption authentication is first performed, and gateway-level identity verification and initial key exchange are completed between the distribution terminal and the power master station; After the gateway encryption authentication succeeds, the master station encryption authentication proceeds, the power distribution terminal establishes a secure session with the power master station, and negotiates to generate the master station encryption random number and the terminal encryption random number; After the master station encryption authentication is successful, the power distribution terminal stores the master station encryption random number and the terminal encryption random number respectively and binds them to the communication session of the corresponding port; If the encrypted communication mode is not enabled on the channel, the distribution terminal will skip the encryption authentication process after establishing the connection and directly enter the business interaction phase defined by the corresponding communication protocol; The extended IEC 60870-5-104 communication protocol includes: extending the length field used to indicate the total length of the application protocol data unit in the standard IEC 60870-5-104 communication protocol from 1 byte to 2 bytes to support the transmission of a maximum of 65535 bytes of data content per frame; The power master station sends an upgrade activation instruction to the power distribution terminal through the management channel to start the remote upgrade process; The power master station divides the program file to be upgraded into a plurality of data segments and sends them to the power distribution terminal in sequence through the management channel; The power distribution terminal receives the multiple data segments and caches them. After all the data segments are received, the upgrade file is checked for integrity. If the check passes, the program update operation of the power distribution terminal is started.
2. The remote upgrade method for power distribution terminals according to claim 1, characterized in that: The step of the power master station dividing the program file to be upgraded into a plurality of data segments and sending the data segments to the power distribution terminal through the management channel in sequence includes: The power master station segments the program file according to a preset per-frame message length threshold to form a plurality of data segment messages, each of which contains at least a field for data segment content and a check code, wherein the data segment content is used to carry the actual data fragment at the corresponding position of the program file, and the check code is used to verify the integrity of the data segment message; The power master station sends each data segment message through the management channel in sequence. The power distribution terminal immediately verifies the data segment message after receiving it and returns a write file confirmation frame for each data segment message. The write file confirmation frame includes the corresponding data segment number and a reception status indicating success or failure of reception. If the distribution terminal feedbacks that the data segment message is received successfully, the power master station continues to send the next data segment message. If the distribution terminal feedbacks that the reception fails or there is no confirmation after timeout, the power master station retransmits the current data segment message until it succeeds or the number of retries exceeds the limit.
3. The remote upgrade method for power distribution terminals according to claim 2, characterized in that: Each data segment message also includes a field for identifying a data offset. The power master station divides the program file to be upgraded into multiple data segments and sequentially sends them to the power distribution terminal through the management channel, further comprising: During the data transmission process, after successfully receiving each data segment message, the power distribution terminal extracts and records the corresponding data offset from the data segment message; When file transmission is interrupted, the distribution terminal retains the offset of the most recently successfully received data; After re-establishing the communication link, the power distribution terminal sends the recorded data offset to the power master station via a write file confirmation frame; After the power master station receives the write file confirmation frame and confirms that it is consistent with the current task to be resumed, it determines the breakpoint position according to the data offset and continues to transmit the remaining untransmitted data segment message from the breakpoint position to achieve breakpoint resumption of program files.
4. The remote upgrade method for power distribution terminals according to claim 2, characterized in that: The power master station segments the program file according to a preset per-frame message length threshold to form a plurality of data segment messages, including: During the initialization phase of the upgrade task, the maximum encrypted message length supported by the encryption machine configured at the power master station and the encryption chip integrated in the power distribution terminal are obtained, and the minimum value of the two is taken as the single-frame message length threshold; Taking the single-frame message length threshold as the basis for data segmentation, the program file is divided into multiple data segment messages in order from the starting byte according to the single-frame message length threshold, the length of each data segment message does not exceed the single-frame message length threshold, and the data offset field compared to the starting position in the complete upgrade file is recorded in each data segment message.
5. The remote upgrade method for power distribution terminals according to claim 1, characterized in that: The step of performing integrity verification on the upgrade file includes: After all data segments of the upgrade file are transmitted, the power master station sends a verification instruction containing summary information of the target upgrade file to the power distribution terminal. The summary information is a hash verification value generated by the power master station for the upgrade file. After receiving the complete upgrade file, the distribution terminal performs local hash calculation and compares the calculation result with the hash check value issued by the power master station. If the comparison is consistent, the file integrity check is considered to have passed, and the power distribution terminal will execute the program writing and version replacement operations, and automatically restart to load the new version of the program; If the comparison fails, it is considered that there is an error in the file transfer. The distribution terminal refuses to execute the program update operation and triggers at least one of the following processing flows: actively rolls back to the stable version of the program before the upgrade to resume operation; or feedbacks the verification failure status to the power master station, and the power master station re-initiates the upgrade file transfer process.
6. An electronic device, characterized in that: The electronic device comprises: One or more processors; and a memory storing computer program instructions, wherein when the computer program instructions are executed, the processor executes the remote upgrade method for a power distribution terminal according to any one of claims 1 to 5.
7. A computer-readable storage medium having a computer program and / or instructions stored thereon, characterized in that: When the computer program and / or instructions are executed by a processor, the remote upgrade method for a power distribution terminal according to any one of claims 1 to 5 is implemented.
8. A computer program product comprising a computer program and / or instructions, characterized in that When the computer program and / or instructions are executed by a processor, the remote upgrade method for a power distribution terminal as described in any one of claims 1 to 5 is implemented.