Energy storage terminal remote security upgrading method and system based on end-to-end encryption
Through the methods of polymorphic malicious implantation detection and fusion, tampering feature traceability, purification processing and block encryption, the malicious implantation and tampering problems in remote upgrade of energy storage terminals are solved, and the credible, complete and confidential transmission of the upgraded task package is achieved, and the security and reliability are improved.
Patent Information
- Application Number
- CN202510641442.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-19
AI Technical Summary
It is difficult to detect and remove malicious implantation and tampering behaviors in a timely manner during the remote upgrade of existing energy storage terminals, resulting in data leakage and system intrusion risks in terminal upgrades.
Through polymorphic malicious implant detection and fusion, tampering feature traceability, purification processing, block encryption and risk chain-driven block security upgrade methods, we ensure that the upgrade task covers the entire process of trustworthy, complete and confidential transmission.
It realizes credible, complete and confidential transmission of the entire process of the upgrade task, improves the security and reliability of remote upgrades of energy storage terminals, and prevents data leakage and system intrusion risks.
Smart Images

Figure CN120342744A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of terminal upgrades, and specifically to a method and system for remote secure upgrade of energy storage terminals based on end-to-end encryption. Background Art
[0002] In the context of the energy structure transformation and the large-scale access of renewable energy to the power grid, as a core node of the smart grid and distributed energy systems, the security and reliability of the software system of energy storage terminals directly affect the stable operation of energy infrastructure. However, traditional firmware upgrade solutions generally face multiple security challenges: upgrade packages are vulnerable to man-in-the-middle attacks during transmission in an open network, resulting in malicious code injection; polymorphic attack methods render static feature detection technologies ineffective; and encryption transmission strategies in fragmented network environments are difficult to adapt to dynamic risk changes. Existing technologies mostly adopt one-way encryption verification or simple sharding transmission mechanisms, lacking the dynamic protection ability for the entire life cycle of upgrade packages, and unable to effectively cope with high-order threats such as APT attacks and data tampering faced by energy storage terminals in the industrial Internet environment. Once the upgrade process is compromised, it may trigger large-scale system paralysis or even power grid security incidents. Therefore, it is urgent to build an end-to-end security system covering the generation, transmission, and landing of upgrade packages, and through an intelligent risk prediction and adaptive defense mechanism, ensure the upgrade security of critical energy information infrastructure. Summary of the Invention
[0003] This application provides a method and system for remote secure upgrade of energy storage terminals based on end-to-end encryption, aiming to solve the technical problem that it is difficult to detect and remove malicious implantation and tampering behaviors in a timely manner during the remote upgrade process of existing energy storage terminals, resulting in risks of data leakage and system intrusion during terminal upgrades. The technical effect is achieved by malicious implantation detection fusion, tampering feature tracing, purification processing, block encryption, and risk-chain-driven block secure upgrade, realizing the trusted, complete, and confidential transmission of the entire process of upgrade task packages, and improving the security and reliability of remote upgrades of energy storage terminals.
[0004] In the first aspect disclosed in this application, a method for remote secure upgrade of an energy storage terminal based on end-to-end encryption is provided. The method includes: obtaining a first upgrade task package encrypted and sent by a trusted user to an upgrade management server; performing polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result; tracing the tampering characteristics of the first upgrade task package according to the task package source data to obtain a tampering characteristic tracing result; purifying the first upgrade task package according to the malicious implantation detection result and the tampering characteristic tracing result to obtain a second upgrade task package; performing block encryption processing on the second upgrade task package to obtain a third upgrade task package, and predicting the transmission security risk of the third upgrade task package to establish a transmission security risk chain; performing block secure upgrade on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server sends the fourth upgrade task package to the energy storage terminal.
[0005] In another aspect disclosed in this application, a system for remote secure upgrade of an energy storage terminal based on end-to-end encryption is provided. The system includes: a first upgrade package obtaining module 11: obtaining a first upgrade task package encrypted and sent by a trusted user to an upgrade management server; a malicious implantation detection module 12: performing polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result; a tampering characteristic tracing module 13: tracing the tampering characteristics of the first upgrade task package according to the task package source data to obtain a tampering characteristic tracing result; a second upgrade package obtaining module 14: purifying the first upgrade task package according to the malicious implantation detection result and the tampering characteristic tracing result to obtain a second upgrade task package; a third upgrade package obtaining module 15: performing block encryption processing on the second upgrade task package to obtain a third upgrade task package, and predicting the transmission security risk of the third upgrade task package to establish a transmission security risk chain; a fourth upgrade package obtaining module 16: performing block secure upgrade on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server sends the fourth upgrade task package to the energy storage terminal.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: The above-mentioned method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption sends the first upgrade task package encrypted by a trusted user into the upgrade management server. Subsequently, malicious implantation detection is performed on the task package, and combined with the source data of the task package, tampering feature tracing is carried out to analyze whether there are security threats. According to the detection and tracing results, the task package is purified to generate a second upgrade task package. After that, the second upgrade task package is encrypted in blocks to form a third upgrade task package, and the security risks during its transmission process are predicted to establish a risk chain. Finally, block-by-block secure upgrade is performed according to the risk chain to generate a fourth upgrade task package, and the upgrade management server securely distributes it to the energy storage terminal, thereby ensuring the security and integrity of the remote upgrade.
[0007] The above description is only an overview of the technical solution of the present application. In order to be able to more clearly understand the technical means of the present application, it can be implemented in accordance with the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically illustrates the specific embodiments of the present application. Description of the Drawings
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0009] Figure 1 It is a flowchart of the method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption in an embodiment.
[0010] Figure 2 It is an architecture diagram of the system for remotely and securely upgrading an energy storage terminal based on end-to-end encryption in an embodiment.
[0011] Description of the reference numerals: The first upgrade package acquisition module 11, the malicious implantation detection module 12, the tampering feature tracing module 13, the second upgrade package acquisition module 14, the third upgrade package acquisition module 15, the fourth upgrade package acquisition module 16. Detailed Embodiments
[0012] By providing a method and system for remotely and securely upgrading an energy storage terminal based on end-to-end encryption in the embodiments of the present application, the technical problem that it is difficult to timely detect and eliminate malicious implantation and tampering behaviors during the remote upgrade of the existing energy storage terminal, resulting in risks of data leakage and system intrusion during the terminal upgrade, is solved. The technical effect of achieving trusted, complete, and confidential transmission of the upgrade task package throughout the process through malicious implantation detection integration, tampering feature tracing, purification processing, block-by-block encryption, and risk chain-driven block-by-block secure upgrade, and improving the security and reliability of the remote upgrade of the energy storage terminal is achieved.
[0013] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without making creative efforts belong to the scope of protection of the present application.
[0014] It should be noted that the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products, or devices.
[0015] Embodiment 1, as Figure 1 shown, the present application provides a method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption, and the method includes: Obtaining a first upgrade task package encrypted and sent by a trusted user to an upgrade management server.
[0016] In the embodiments of the present application, first, the user is verified through a multi-authentication mechanism to ensure that the user is a trusted user. After the authentication is passed, an upgrade task request is generated in a predetermined format, and the request is encrypted using an encryption algorithm to ensure the data confidentiality and integrity during the transmission of the task package. The encrypted request is sent to the upgrade management server through a secure channel to obtain the required first upgrade task package. In summary, through the above process, it can be ensured that the data is not tampered with or stolen by an unauthorized third party during the data transmission process, thereby providing a reliable guarantee for the subsequent security detection and upgrade process.
[0017] Furthermore, the present application provides obtaining a first upgrade task package encrypted and sent by a trusted user to an upgrade management server, including: Obtaining a user's upgrade task request, where the upgrade task request includes an upgrade package name, an upgrade package file, an upgrade package version number, and an upgrade cabin code; performing multi-authentication on the user to obtain a composite authentication result; when the composite authentication result is passed, identifying the user as the trusted user, and encrypting and sending the upgrade task request to the upgrade management server to obtain the first upgrade task package.
[0018] Preferably, the user submits an upgrade task request to the upgrade management server. This upgrade task request includes necessary information such as the name, file, version number of the upgrade package, and the upgrade cabin code. These information jointly describe the specific content of the upgrade task and the target device. Subsequently, multiple authentications are performed on the user who submits the upgrade task request. Usually, identity verification is carried out through multiple methods (such as password verification, fingerprint recognition, dynamic verification codes, etc.) to ensure that the request comes from a legitimate user. After that, a composite authentication result is generated according to the multiple authentication results. If the composite authentication result is passed, the user is identified as a trusted user. After confirming that the user identity is correct, the upgrade task request is encrypted (such as symmetric encryption or asymmetric encryption algorithms) to ensure data security and privacy protection during the transmission of the task request. For example, the public key encryption method is adopted. Among them, the upgrade management server holds the private key, and the user device uses the public key to encrypt the data to ensure that the data cannot be interpreted by unauthorized third parties during the transmission process. The encrypted task request is sent to the upgrade management server, and the upgrade management server will decrypt and verify it. After decryption, the upgrade management server obtains the corresponding upgrade data (such as upgrade files, patches, etc.) from the database or storage system according to the information in the task request, and organizes these upgrade data into the first upgrade task package for subsequent security processing and task execution.
[0019] Furthermore, the present application provides that when the composite authentication result is not passed, a request rollback signal is generated, and the upgrade task request is rollback processed according to the request rollback signal.
[0020] Optionally, when the composite authentication result is not passed, a request rollback signal will be generated immediately, indicating that the user identity fails to pass the verification or there are other security issues. Subsequently, according to the generated request rollback signal, the upgrade task request will be rollback processed. Specifically, the upgrade task request initiated by the current user will be cancelled or revoked, and the relevant data will be marked as invalid or pending further review. This process ensures that only trusted users who have passed strict verification can perform upgrade operations, preventing unauthorized users from initiating unsafe upgrade tasks. In addition, the rollback process may also include sending warning or feedback information to the user to inform the reason for the authentication failure so that the user can take remedial measures in time.
[0021] Perform polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result.
[0022] In one embodiment, after obtaining the first upgrade task package, to ensure the security of the first upgrade task package, various types of malicious implantation detections are performed on the upgrade task package. These detections include static analysis and dynamic analysis, which respectively check whether there are known malicious implantations or potential security threats in the code, data, and behavioral characteristics of the task package. Among them, static analysis involves checking the structure, hash value, bytecode, etc. of the task package file to identify whether there is abnormal or malicious code; dynamic analysis simulates the execution process of the task package, observes its runtime behavior, and detects whether there are suspicious behaviors such as abnormal access, data tampering, or network communication. After completing various detections, a fusion mechanism integrates multiple detection results to form a comprehensive malicious implantation detection result. This fusion process ensures that potential threats discovered by different detection methods can be comprehensively evaluated, thereby improving the accuracy and coverage of malicious implantation detection. The obtained detection result will provide an important basis for subsequent task package processing (such as purification, encryption, etc.).
[0023] Further, the present application provides polymorphic malicious implantation detection fusion for the first upgrade task package to obtain a malicious implantation detection result, including: Performing static malicious implantation detection on the first upgrade task package to obtain a static malicious implantation detection result; performing dynamic malicious implantation detection on the first upgrade task package to obtain a dynamic malicious implantation detection result; fusing the static malicious implantation detection result and the dynamic malicious implantation detection result to generate the malicious implantation detection result.
[0024] Preferably, first, perform static malicious implantation detection on the first upgrade task package. During this process, byte feature scanning and analysis are performed on the file content in the first task package, and a static malicious implantation detector is used to search for any suspicious features or known malicious code. For example, it will check whether the files in the task package contain known malicious signatures, whether there are abnormal file permissions, or whether there are illegal embedded scripts. Through these static analysis methods, potential malicious implantation risks in the task package can be identified, and a static malicious implantation detection result is generated. At the same time, dynamic malicious implantation detection is also performed on the first upgrade task package. This step is different from static analysis. It monitors the behavior and actions of the task package by simulating its execution process. During the simulation, the first upgrade task package is simulated and run in a controlled environment, and its behavior is monitored in real time to see if it meets the expectations. Dynamic detection may capture risks that cannot be detected by static detection. For example, the task package may attempt to modify the system configuration, initiate unauthorized network requests, or exhibit other abnormal behaviors when executed. Based on these dynamic monitoring results, a dynamic malicious implantation detection result is generated. Finally, the static malicious implantation detection result and the dynamic malicious implantation detection result are fused. The fusion process combines the results of these two detection methods to obtain a malicious implantation detection result. This fusion result can effectively improve the accuracy of malicious implantation detection, ensure that security threats in the first upgrade task package are comprehensively identified, and provide a reliable basis for subsequent purification processing and security upgrades.
[0025] Furthermore, the present application provides static malicious implantation detection for the first upgrade task package to obtain a static malicious implantation detection result, including: Perform byte feature scanning on the first upgrade task package to obtain multiple byte feature vectors; use the byte feature vector sample set as input information and the static malicious implantation detection sample set as output information to train the first static malicious detection model, the second static malicious detection model, and the third static malicious detection model; use the first static malicious detection model and the second static malicious detection model as base learners to perform output feedback learning on the third static malicious detection model to generate a static malicious implantation detector; input the multiple byte feature vectors into the static malicious implantation detector to generate the static malicious implantation detection result.
[0026] Optionally, first, read the byte stream of the first upgrade task package byte by byte, and decompose the byte sequence in the first upgrade task package into individual independent bytes (usually 8 bits) for subsequent analysis. Then, parse the header of the first upgrade task package. The file header usually contains information about the file format, version, and other metadata. This step helps determine whether the first upgrade task package conforms to the expected format. Subsequently, scan the byte stream of the first upgrade task package to identify potential patterns or repeated byte sequences. For example, certain specific byte patterns (such as 0x90, 0xFF, etc.) may indicate the presence of malicious code. This step can be based on regular expressions or other pattern matching techniques to identify. Next, calculate the occurrence frequency of each byte in the file and the byte distribution characteristics. For example, check whether there are specific bytes that appear frequently (such as 0x00, which is usually used to fill blank areas), or judge the regularity of certain byte segments in the file. Based on the above scanning processes, multiple byte feature vectors will be extracted. These vectors usually include data such as specific byte sequences extracted from the byte stream, repeated byte sequences, file structure information, byte frequency statistics, and file header parsing results. After that, use the pre-prepared byte feature vector sample set as the input information and the static malicious implantation detection sample set as the output information to start training the static malicious detection model. Among them, the static malicious detection sample set contains task package samples that have been marked as malicious or normal. These samples can help the model learn and distinguish the differences between malicious task packages and normal task packages. By inputting the byte feature vector sample set into the static malicious detection first model constructed based on the multi-layer perceptron (MLP) (other model algorithms can also be used, such as deep neural networks, decision trees, etc.), a possible static malicious implantation detection result is predicted through forward propagation. Use the cross-entropy loss function to calculate the error between the prediction result and the static malicious implantation detection sample, and then use the backpropagation algorithm to optimize the weights and biases of the model so that the model can classify the task package according to the input byte feature vector. Similarly, input the byte feature vector sample set into the static malicious detection second model constructed based on other model algorithms (such as deep neural networks), and through the same training process as above, adjust the model parameters to improve the detection accuracy of the model for malicious implantation. Then, use the outputs of the previously trained static malicious detection first model and second model as base learners, and use their outputs as inputs to train the static malicious detection third model constructed based on deep neural networks and ensemble learning algorithms (such as weighted voting, stacking models, etc.). Then, through the backpropagation algorithm, feedback the error of the third model to the base learners, and use optimization algorithms (such as the Adam optimizer or SGD) to adjust their weights and biases to reduce the value of the loss function and ensure that the output of the third model matches the actual malicious implantation detection label as much as possible.After the optimization of output feedback learning, an enhanced and adjusted static malicious implant detector is formed, which can output malicious implant detection results based on the input byte feature vector. Preferably, the multiple byte feature vectors extracted previously are input into the trained static malicious implant detector, and the detector analyzes these byte feature vectors based on the learned model to generate the final static malicious implant detection result, which indicates whether the task package has malicious implant behavior and provides a basis for subsequent processing steps.
[0027] Furthermore, the present application provides a method of performing dynamic malicious implantation detection on the first upgrade task package to obtain a dynamic malicious implantation detection result, including: The energy storage terminal is simulated upgraded according to the first upgrade task package to obtain a simulated upgrade log; malicious behavior detection is performed according to the simulated upgrade log to obtain an upgraded malicious behavior detection result; and the first upgrade task package is associated and identified according to the upgraded malicious behavior detection result to generate the dynamic malicious implantation detection result.
[0028] Optionally, the energy storage terminal is simulated upgraded according to the first upgrade task package. During the simulation process, the system will run the upgrade task package in a controlled environment and simulate the upgrade operation of the energy storage terminal. Through the simulation, the actual execution effect of the task package on the energy storage terminal can be understood, various behaviors and events in the upgrade process can be recorded, and a simulated upgrade log can be generated. The log includes all system responses, file operations, network communications and other detailed information during the execution of the task package. Subsequently, malicious behavior detection is performed on the obtained simulated upgrade log. Malicious behavior detection is to analyze each operation and event in the simulated upgrade log through a pre-trained malicious behavior model (based on a deep neural network, and the training method is the same as the above) to identify possible abnormal or malicious behaviors, such as whether there is abnormal file access, unauthorized network requests, or attempts to tamper with the system configuration, thereby generating an upgrade malicious behavior detection result and marking potential malicious activities. Finally, based on the generated upgrade malicious behavior detection result, the first upgrade task package is associated and identified. This process is to correspond the detection result with the relevant features in the first upgrade task package, and identify the content or operation in the first upgrade task package involved in the upgrade malicious behavior detection result. This association identification helps determine whether the task package contains malicious implants or potential security threats. Based on the results of the association identification, a dynamic malicious implant detection result is generated to evaluate the security of the task package. It can effectively reveal abnormal or unsafe elements in the task package, thereby preventing these potential risks from causing damage to the terminal during the upgrade process.
[0029] The first upgrade task package is subjected to tampering feature tracing according to the task package source data to obtain a tampering feature tracing result.
[0030] In one embodiment, to determine whether there is malicious tampering with the first upgrade task package, the source data of the task package is extracted, which generally includes the original files, version information, source code, metadata, and other relevant verification data of the first upgrade task package. The task package source data is used to determine the basic structure and content of the first upgrade task package when it is generated, as well as the possible modifications or tampering that the task package may have suffered during storage and transmission. Subsequently, these task package source data are compared with the actual content of the first upgrade task package. Specifically, when performing data integrity verification, the current content of the first upgrade task package is compared with the data of the task package source data to check for data loss, modification, or illegal addition. This process can use methods such as hash values and checksums to verify the integrity of the data; when performing version checking, it is checked whether the version information of the first upgrade task package conforms to the predetermined specifications. If the version information of the first upgrade task package does not match the source data record, there may be a risk of tampering; when comparing the source code and metadata, if the first upgrade task package contains source code or configuration files, these files are compared to check for code modifications, insertions, or deletions, and to identify whether there are unexpected changes; during all comparison processes, all tampering characteristics are extracted, such as data offsets, anomalies in the file headers or file tails, and the positions of changed file blocks, etc., as the basis for the existence of tampering behavior. Finally, by summarizing the identified tampering bases, a tampering feature traceability result is generated, which details any changes or anomalies that occurred during the generation, storage, and transmission of the first upgrade task package. These traceability results provide a basis for subsequent security processing, helping to determine whether the task package has been maliciously tampered with, as well as the nature and extent of the tampering.
[0031] According to the malicious implantation detection result and the tampering feature traceability result, the first upgrade task package is purified to obtain a second upgrade task package.
[0032] In one embodiment, first, based on the malicious implantation detection results, potential malicious codes, viruses, Trojans, or other malicious implantations in the first upgrade task package are identified, and all parts with malicious implantations in the first upgrade task package are marked. Similarly, based on the tampering feature tracing results, possible tampered parts in the task package are identified and marked. These tamperings may include data tampering, file changes, version inconsistencies, etc. Through the above process, illegally modified content can be accurately identified and removed. Subsequently, according to the malicious implantation detection results and tampering feature tracing results marked in the first upgrade task package, the first upgrade task package will be purified. Specifically, all parts marked as malicious codes will be deleted or isolated, and the backup security version or source data will be used to recover and repair the content marked as tampered, ensuring that the file is consistent with the original design. After the purification process is completed, a new upgrade task package, namely the second upgrade task package, will be generated. This second upgrade task package will not contain any malicious implantations or illegal tamperings, avoiding security risks brought by malicious implantations or tamperings and providing security guarantees for subsequent upgrade operations.
[0033] Perform chunk encryption processing on the second upgrade task package to obtain a third upgrade task package, and predict the transmission security risk of the third upgrade task package to establish a transmission security risk chain.
[0034] In one embodiment, after obtaining the second upgrade task package, the second upgrade task package will be divided into multiple smaller chunks. Each chunk contains a part of the data of the second upgrade task package. These data chunks can be evenly divided according to the size, structure, and encryption requirements of the task package. The purpose of chunking is to improve the flexibility of the encryption and transmission processes and make the processing of each data chunk more efficient. Subsequently, each data chunk is encrypted. Generally, a symmetric encryption algorithm (such as AES) is used to encrypt each data chunk to generate encrypted data chunks. During the encryption process, a unified key can be used to encrypt all chunks, or a separate key for each data chunk can be used. The encryption operation ensures that the task package cannot be read or tampered with by unauthorized third parties during transmission. After all data chunks are encrypted, these encrypted data chunks are recombined to generate a third upgrade task package, which includes multiple encrypted data chunks. Then, the transmission security risk of the third upgrade task package is predicted. This step involves using the issued transmission model to simulate the transmission process of the third upgrade task package, understanding the possible security threats, and quantifying the transmission security risk coefficient of each encrypted data chunk. Then, according to the results of the transmission security risk prediction, a transmission security risk chain is constructed. This transmission security risk chain reflects the security risks of each link from the sending to the receiving of the third upgrade task package, ensuring the secure transmission of the third upgrade task package and avoiding various types of network attacks or data damages.
[0035] Further, the present application provides for predicting the transmission security risk of the third upgrade task package and establishing a transmission security risk chain, including: Construct a delivery transmission path model based on the upgrade management server and the energy storage terminal, and perform network feature rendering on the delivery transmission path model to generate a delivery transmission model; perform simulated transmission on the third upgrade task package according to the delivery transmission model to obtain a delivery transmission simulation data set; perform transmission security risk evaluation on each encrypted block in the third upgrade task package according to the delivery transmission simulation data set to obtain a plurality of transmission security risk coefficients; construct the transmission security risk chain according to the plurality of transmission security risk coefficients.
[0036] Preferably, first, according to the communication network environment between the upgrade management server and the energy storage terminal, a download transmission path model is constructed. This model reflects the transmission path from the server to the terminal, including key network characteristics such as network topology, transmission protocol, connection method and bandwidth between nodes, and possible attack methods. The construction of this model is usually based on network configuration data, such as routers, switches, link quality, etc., aiming to simulate in detail the data transmission route and the performance of each link. After constructing the download transmission path model, network feature rendering is performed on the model. The rendering process involves embedding actual network characteristics (such as bandwidth, latency, packet loss rate, traffic load, etc.) into the transmission path model to form a download transmission model. This process helps to accurately reflect the impact of the actual network environment on data transmission and provides a basis for subsequent risk prediction and optimization. Subsequently, based on the download transmission model, the third upgrade task package is simulated for transmission. By simulating the transmission of the task package in the network, the performance of the task package in the actual network environment can be emulated. During the simulation transmission process, key information such as the integrity of communication packets, the existence of abnormal connection requests, unauthorized access behaviors during communication, and abnormal header information will be tracked in real time, and this information will be recorded in the download transmission simulation data set to provide data support for subsequent analysis. After that, based on the download transmission simulation data set, a transmission security risk assessment is carried out for each encrypted block in the third upgrade task package. In this process, the number of packets whose checksum matches the expected checksum is divided by the total number of packets, and then 1 minus the calculated quotient is used to obtain the integrity risk coefficient; the number of connection requests from abnormal IPs or with abnormal frequencies within a short period of time is divided by the total number of all connection requests to obtain the abnormal connection risk coefficient; the number of access attempts from unauthorized devices or IPs is divided by the total number of all access requests to obtain the unauthorized access risk coefficient; the number of packets with abnormal header information is divided by the total number of all packets to obtain the packet anomaly risk coefficient; the jitter value of the network link is subtracted from the maximum allowable jitter value, and then the difference is divided by the maximum allowable jitter value to obtain the link stability risk coefficient. After that, the integrity risk coefficient, abnormal connection risk coefficient, unauthorized access risk coefficient, packet anomaly risk coefficient and link stability risk coefficient of each encrypted block are weighted and summed to obtain the transmission security risk coefficient of each encrypted block, which reflects the potential risks faced by the encrypted block during transmission. The higher the coefficient, the greater the risk. Then, all the transmission security risk coefficients are arranged in the transmission order of the encrypted blocks to form a continuous risk chain, that is, the transmission security risk chain. This transmission security risk chain represents all the security risks during the transmission process from the first encrypted block to the last encrypted block, providing a decision-making basis for subsequent security processing and optimization.In summary, the core purpose of the entire process is to comprehensively simulate and conduct a security assessment on the transmission process of the third upgrade task package, ensuring that potential security risks are avoided as much as possible during the transmission of the third upgrade task package, and ensuring the security and integrity when it is finally transmitted to the energy storage terminal.
[0037] Perform block-by-block security upgrades on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server distributes the fourth upgrade task package to the energy storage terminal.
[0038] In one embodiment, according to the transmission security risk chain, first analyze the security risks of each encrypted block during the transmission process, identify the high-risk parts, and adjust security parameters such as the encryption method, transmission path, and transmission protocol of the corresponding encrypted block to reduce the security risks during the transmission process. For example, for high-risk encrypted blocks, redundant transmission may be increased, the encryption intensity may be improved, or the transmission path may be changed. After these security optimizations and adjustments, a fourth upgrade task package is generated. This fourth upgrade task package contains encrypted blocks that have been security fortified, ensuring that potential attacks or security vulnerabilities can be effectively avoided during the transmission process, and improving the transmission security of the entire task package. Finally, the upgrade management server distributes the fourth upgrade task package that has undergone block-by-block security upgrades to the energy storage terminal. During the distribution process, the upgrade management server will transmit through a secure communication channel to avoid any possible man-in-the-middle attacks or data tampering, ensuring that the task package can be delivered to the target energy storage terminal completely and correctly, and providing guarantee for the terminal to perform security upgrades.
[0039] Furthermore, the present application provides a method for performing block-by-block security upgrades on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, including: Traverse the third upgrade task package to extract the first encrypted block; according to the transmission security risk chain, match the first transmission security risk coefficient corresponding to the first encrypted block; if the first transmission security risk coefficient is greater than or equal to the transmission security risk threshold, enhance the encryption configuration of the first encrypted block to obtain a set of encryption configuration enhancement schemes; perform iterative optimization on the set of encryption configuration enhancement schemes according to the transmission security risk threshold to obtain an encryption configuration enhancement strategy; perform security upgrades on the third upgrade task package according to the encryption configuration enhancement strategy to obtain the fourth upgrade task package.
[0040] Preferably, first, traverse the third upgrade task package to extract the first encrypted block, which contains part of the data of the third upgrade task package. Then, according to the previously generated transmission security risk chain, search for and match the first transmission security risk coefficient corresponding to the first encrypted block. This coefficient quantifies the security risk that the first encrypted block may face during transmission. Subsequently, compare the first transmission security risk coefficient with the transmission security risk threshold. If the first transmission security risk coefficient is greater than or equal to the preset transmission security risk threshold, it indicates that the encrypted block faces a relatively high risk. Therefore, encryption configuration enhancement is required. At this time, obtain the encryption configuration enhancement scheme set, which contains a variety of pre-configured enhancement strategies, such as stronger encryption algorithms, more complex key management strategies, etc. These enhancement strategies will be used to enhance the encryption configuration of the first encrypted block. After that, traverse the enhancement strategies in the encryption configuration enhancement scheme set through iterative optimization. In each traversal, use the current enhancement strategy to encrypt the first encrypted block and simulate the encrypted and enhanced first encrypted block using the issued transmission model to calculate a new first transmission security risk coefficient. If this new first transmission security risk coefficient is less than the transmission security risk threshold, it indicates that the current enhancement strategy can effectively reduce the transmission risk. Therefore, the current enhancement strategy will be used as the encryption configuration enhancement strategy. Otherwise, continue the traversal to ensure the best security and transmission efficiency. Once the optimal encryption configuration enhancement strategy is determined, apply this strategy to safely upgrade the corresponding encrypted block in the third upgrade task package to ensure that each encrypted block can provide sufficient security during transmission. After this security upgrade, a fourth upgrade task package is generated. At this time, the riskier encrypted blocks in the fourth upgrade task package have been optimized to cope with possible network security risks and ensure the integrity and confidentiality of the task package during actual transmission are effectively guaranteed.
[0041] Furthermore, the present application provides that the upgrade management server issues the fourth upgrade task package to the energy storage terminal, including: Obtain real-time issuance monitoring data, perform anomaly detection on the real-time issuance monitoring data to obtain an issuance anomaly detection result; perform a security risk assessment based on the issuance anomaly detection result to obtain an issuance security risk coefficient; if the issuance security risk coefficient is greater than or equal to the issuance security risk threshold, perform issuance security enhancement based on the issuance anomaly detection result.
[0042] Optionally, obtain real-time monitoring data related to the transmission of the fourth upgrade task package. This data includes various real-time information during the entire transmission process from the upgrade management server to the energy storage terminal, such as the integrity of communication packets, whether there are abnormal connection requests, unauthorized access behaviors during communication, and whether there are abnormal header information in data packets. Subsequently, using the same calculation method as above, quantify the risk of the data in the download anomaly detection result to obtain the download security risk coefficient. If the download security risk coefficient is greater than or equal to the set download security risk threshold, it is considered that the risk level of the transmission process is relatively high, which may affect the security of the task package. In this case, based on the download anomaly detection result, take security enhancement measures, for example, increase the redundancy of transmission, optimize the transmission path, adjust the encryption algorithm, strengthen the authentication mechanism, or temporarily switch to a more secure communication protocol to reduce potential risks. Through these enhancement measures, the secure transmission of the task package can be ensured, and the possibility of being attacked or tampered with can be reduced.
[0043] In summary, the embodiments of the present application have at least the following technical effects: The embodiments of the present application first obtain the first upgrade task package encrypted and sent by a trusted user to the upgrade management server; subsequently, perform polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result; then, trace the tampering characteristics of the first upgrade task package according to the task package source data to obtain a tampering characteristic tracing result; further, perform purification processing on the first upgrade task package according to the malicious implantation detection result and the tampering characteristic tracing result to obtain a second upgrade task package; then, perform block encryption processing on the second upgrade task package to obtain a third upgrade task package, and predict the transmission security risk of the third upgrade task package to establish a transmission security risk chain; finally, perform block security upgrades on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server sends the fourth upgrade task package to the energy storage terminal. These technical effects together solve the technical problem that it is difficult to detect and remove malicious implantations and tampering behaviors in a timely manner during the remote upgrade process of the existing energy storage terminal, resulting in risks of data leakage and system intrusion during terminal upgrades, and achieve the technical effect of realizing the trusted, complete, and confidential transmission of the upgrade task package throughout the process through malicious implantation detection fusion, tampering characteristic tracing, purification processing, block encryption, and risk chain-driven block security upgrades, and improving the security and reliability of the remote upgrade of the energy storage terminal.
[0044] Embodiment 2, based on the same inventive concept as the method for remote secure upgrade of an energy storage terminal based on end-to-end encryption in the foregoing embodiment, as Figure 2As shown in the figure, the present application provides an energy storage terminal remote security upgrade system based on end-to-end encryption. The system includes: a first upgrade package acquisition module 11: acquiring a first upgrade task package encrypted and sent by a trusted user to an upgrade management server; a malicious implantation detection module 12: performing polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result; a tampering feature tracing module 13: tracing the tampering features of the first upgrade task package according to the task package source data to obtain a tampering feature tracing result; a second upgrade package acquisition module 14: purifying the first upgrade task package according to the malicious implantation detection result and the tampering feature tracing result to obtain a second upgrade task package; a third upgrade package acquisition module 15: performing block encryption processing on the second upgrade task package to obtain a third upgrade task package, and predicting the transmission security risk of the third upgrade task package to establish a transmission security risk chain; a fourth upgrade package acquisition module 16: performing block security upgrade on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server sending the fourth upgrade task package to the energy storage terminal.
[0045] Further, the first upgrade package acquisition module 11 is further configured to execute the following method: Acquiring an upgrade task request of a user, where the upgrade task request includes an upgrade package name, an upgrade package file, an upgrade package version number, and an upgrade cabin code; performing multiple authentications on the user to obtain a composite authentication result; when the composite authentication result is passed, identifying the user as the trusted user, and encrypting and sending the upgrade task request to the upgrade management server to obtain the first upgrade task package.
[0046] Further, the first upgrade package acquisition module 11 is further configured to execute the following method: When the composite authentication result is not passed, generating a request rollback signal, and performing a rollback process on the upgrade task request according to the request rollback signal.
[0047] Further, the malicious implantation detection module 12 is further configured to execute the following method: Performing static malicious implantation detection on the first upgrade task package to obtain a static malicious implantation detection result; performing dynamic malicious implantation detection on the first upgrade task package to obtain a dynamic malicious implantation detection result; fusing the static malicious implantation detection result and the dynamic malicious implantation detection result to generate the malicious implantation detection result.
[0048] Further, the malicious implantation detection module 12 is further configured to execute the following method: Perform byte feature scanning on the first upgrade task package to obtain multiple byte feature vectors; use the byte feature vector sample set as input information and the static malicious implantation detection sample set as output information to train the first static malicious detection model, the second static malicious detection model, and the third static malicious detection model; use the first static malicious detection model and the second static malicious detection model as base learners to perform output feedback learning on the third static malicious detection model to generate a static malicious implantation detector; input the multiple byte feature vectors into the static malicious implantation detector to generate the static malicious implantation detection result.
[0049] Further, the malicious implantation detection module 12 is further configured to execute the following method: Perform a simulated upgrade on the energy storage terminal according to the first upgrade task package to obtain a simulated upgrade log; perform malicious behavior detection based on the simulated upgrade log to obtain an upgrade malicious behavior detection result; perform associated identification on the first upgrade task package according to the upgrade malicious behavior detection result to generate the dynamic malicious implantation detection result.
[0050] Further, the third upgrade package obtaining module 15 is further configured to execute the following method: Construct a distribution transmission path model based on the upgrade management server and the energy storage terminal, and perform network feature rendering on the distribution transmission path model to generate a distribution transmission model; perform simulated transmission on the third upgrade task package according to the distribution transmission model to obtain a distribution transmission simulation data set; perform transmission security risk evaluation on each encrypted block in the third upgrade task package according to the distribution transmission simulation data set to obtain multiple transmission security risk coefficients; construct the transmission security risk chain according to the multiple transmission security risk coefficients.
[0051] Further, the fourth upgrade package obtaining module 16 is further configured to execute the following method: Traverse the third upgrade task package to extract the first encrypted block; match the first transmission security risk coefficient corresponding to the first encrypted block according to the transmission security risk chain; if the first transmission security risk coefficient is greater than or equal to the transmission security risk threshold, perform encryption configuration enhancement on the first encrypted block to obtain an encryption configuration enhancement plan set; perform iterative optimization on the encryption configuration enhancement plan set according to the transmission security risk threshold to obtain an encryption configuration enhancement strategy; perform a security upgrade on the third upgrade task package according to the encryption configuration enhancement strategy to obtain the fourth upgrade task package.
[0052] Further, the fourth upgrade package obtaining module 16 is further configured to execute the following method: Obtain the real-time issued monitoring data, perform anomaly detection on the real-time issued monitoring data, and obtain the issued anomaly detection result; perform a security risk assessment based on the issued anomaly detection result to obtain the issued security risk coefficient; if the issued security risk coefficient is greater than or equal to the issued security risk threshold, perform issued security enhancement based on the issued anomaly detection result.
[0053] It should be noted that the above-mentioned order of the embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above describes specific embodiments of this specification. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0054] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
[0055] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and variations.
Claims
1. A method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption, characterized in that, The method includes: Obtaining a first upgrade task package encrypted and sent by a trusted user to an upgrade management server; Performing polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result; Tracing the tampering characteristics of the first upgrade task package according to the task package source data to obtain a tampering characteristic tracing result; Performing purification processing on the first upgrade task package according to the malicious implantation detection result and the tampering characteristic tracing result to obtain a second upgrade task package; Performing block encryption processing on the second upgrade task package to obtain a third upgrade task package, and predicting the transmission security risk of the third upgrade task package to establish a transmission security risk chain; Performing block-by-block secure upgrade on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server distributes the fourth upgrade task package to the energy storage terminal.
2. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 1, wherein Performing polymorphic malicious implantation detection fusion on the first upgrade task package to obtain a malicious implantation detection result, including: Performing static malicious implantation detection on the first upgrade task package to obtain a static malicious implantation detection result; Performing dynamic malicious implantation detection on the first upgrade task package to obtain a dynamic malicious implantation detection result; Fusing the static malicious implantation detection result and the dynamic malicious implantation detection result to generate the malicious implantation detection result.
3. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 2, wherein, Performing static malicious implantation detection on the first upgrade task package to obtain a static malicious implantation detection result, including: Performing byte feature scanning on the first upgrade task package to obtain multiple byte feature vectors; Using the byte feature vector sample set as input information and the static malicious implantation detection sample set as output information to train the first static malicious detection model, the second static malicious detection model, and the third static malicious detection model; Using the first static malicious detection model and the second static malicious detection model as base learners to perform output feedback learning on the third static malicious detection model to generate a static malicious implantation detector; Inputting the multiple byte feature vectors into the static malicious implantation detector to generate the static malicious implantation detection result.
4. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 2, wherein, Performing dynamic malicious implantation detection on the first upgrade task package to obtain a dynamic malicious implantation detection result, including: Performing simulated upgrade on the energy storage terminal according to the first upgrade task package to obtain a simulated upgrade log; Performing malicious behavior detection according to the simulated upgrade log to obtain an upgrade malicious behavior detection result; Performing associated identification on the first upgrade task package according to the upgrade malicious behavior detection result to generate the dynamic malicious implantation detection result.
5. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 1, wherein Predicting the transmission security risk of the third upgrade task package to establish a transmission security risk chain, including: Constructing a distribution transmission path model according to the upgrade management server and the energy storage terminal, and performing network feature rendering on the distribution transmission path model to generate a distribution transmission model; Performing simulated transmission on the third upgrade task package according to the distribution transmission model to obtain a distribution transmission simulation data set; Perform a transmission security risk assessment on each encrypted block in the third upgrade task package according to the issued transmission simulation data set to obtain multiple transmission security risk coefficients; Construct the transmission security risk chain according to the multiple transmission security risk coefficients.
6. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 1, wherein Perform a block-by-block security upgrade on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, including: Traverse the third upgrade task package to extract the first encrypted block; Match the first transmission security risk coefficient corresponding to the first encrypted block according to the transmission security risk chain; If the first transmission security risk coefficient is greater than or equal to the transmission security risk threshold, enhance the encryption configuration of the first encrypted block to obtain an encryption configuration enhancement scheme set; Perform iterative optimization on the encryption configuration enhancement scheme set according to the transmission security risk threshold to obtain an encryption configuration enhancement strategy; Perform a security upgrade on the third upgrade task package according to the encryption configuration enhancement strategy to obtain the fourth upgrade task package.
7. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 1, wherein The upgrade management server issues the fourth upgrade task package to the energy storage terminal, including: Obtain real-time issuance monitoring data and perform anomaly detection on the real-time issuance monitoring data to obtain an issuance anomaly detection result; Perform a security risk assessment according to the issuance anomaly detection result to obtain an issuance security risk coefficient; If the issuance security risk coefficient is greater than or equal to the issuance security risk threshold, perform issuance security enhancement according to the issuance anomaly detection result.
8. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 1, wherein Obtain a first upgrade task package encrypted and sent by a trusted user to the upgrade management server, including: Obtain the user's upgrade task request, where the upgrade task request includes an upgrade package name, an upgrade package file, an upgrade package version number, and an upgrade cabin code; Perform multiple authentication on the user to obtain a composite authentication result; When the composite authentication result is passed, identify the user as the trusted user and encrypt and send the upgrade task request to the upgrade management server to obtain the first upgrade task package.
9. The method for remotely and securely upgrading an energy storage terminal based on end-to-end encryption according to claim 8, wherein When the composite authentication result is not passed, generate a request rollback signal and perform a rollback process on the upgrade task request according to the request rollback signal.
10. An energy storage terminal remote security upgrade system based on end-to-end encryption, characterized in that, The system is used to execute the end-to-end encryption-based remote security upgrade method for an energy storage terminal according to any one of claims 1-9. The system includes: A first upgrade package acquisition module: obtain a first upgrade task package encrypted and sent by a trusted user to the upgrade management server; A polymorphic malicious implantation detection and fusion module: perform polymorphic malicious implantation detection and fusion on the first upgrade task package to obtain a malicious implantation detection result; A tampering feature tracing module: trace the tampering features of the first upgrade task package according to the task package source data to obtain a tampering feature tracing result; A second upgrade package acquisition module: perform a purification process on the first upgrade task package according to the malicious implantation detection result and the tampering feature tracing result to obtain a second upgrade task package; A third upgrade package acquisition module: perform block-by-block encryption processing on the second upgrade task package to obtain a third upgrade task package, and perform a transmission security risk prediction on the third upgrade task package to establish a transmission security risk chain; Fourth Upgrade Package Acquisition Module: Perform chunked security upgrades on the third upgrade task package according to the transmission security risk chain to obtain a fourth upgrade task package, and the upgrade management server distributes the fourth upgrade task package to the energy storage terminal.
Citation Information
Patent Citations
Data encryption transmission method
CN108881276A
Embedded equipment upgrading method and device, equipment and storage medium
CN119004478A
Firmware upgrade package verification method and device, terminal and storage medium
CN119128887A
Security and privacy enhancements for security devices
US20060288407A1
Cyber threat information processing apparatus, cyber threat information processing method, and storage medium storing cyber threat information processing program
US20240214396A1
Cited By
Traceable file watermark generation method and device, computer equipment and medium
CN120541040A