Repair packet transmission system

Through dynamic key generation and digital signature verification mechanisms, the tampering and forgery of repair packets during transmission is solved, ensuring the security and reliability of power equipment repair packets.

CN120378097APending Publication Date: 2025-07-25CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510554036.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

During the remote repair packet transmission of power equipment, the repair packet may be tampered with or forged, resulting in device failure or systemic security incidents. How to ensure the reliability of the repair packet.

Method used

The dynamic key generation module is used to encrypt the repair packet, generate a unique and unpredictable key, and generate an encrypted data packet through the digital signature generation module. It is transmitted to the power equipment using the digital signature transmission module. The power equipment verifies the authenticity and integrity of the data source through the data source verification module.

Benefits of technology

Ensure the security and reliability of the repair package during transmission, prevent tampering and forgery, and ensure the integrity and reliability of the repair package.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378097A_ABST
    Figure CN120378097A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a repair packet transmission system. Comprising a repair packet transmission end and power equipment, wherein the repair packet transmission end comprises a dynamic key generation module, an encrypted repair packet obtaining module, a digital signature generation module and a digital signature transmission module, and the power equipment comprises a data source verification module; the dynamic key generation module is used for generating a dynamic key; the encryption repair package obtaining module is used for obtaining an encryption repair package and an authentication label corresponding to the encryption repair package; the digital signature generation module is used for generating an encrypted data packet, calculating a first hash value and generating a digital signature based on the first hash value; the digital signature transmission module is used for transmitting a transmission packet associated with the encrypted data packet and the digital signature to the power equipment; and the data source verification module is used for verifying the data source of the encrypted data packet. According to the technical scheme of the embodiment of the invention, the reliability of the repair packet in the transmission process can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of data transmission, and in particular, to a repair package transmission system. Background Art

[0002] With the rapid development of information technology, especially in the construction of smart grids and distributed power systems, remote maintenance of power equipment has gradually become an important means to ensure the safe and stable operation of the power grid.

[0003] During the remote maintenance of power equipment, it is necessary to remotely obtain repair packages including firmware, configuration files, update programs, etc. of power equipment, and these files need to be transmitted to the power equipment through the network.

[0004] However, since the repair package may carry important system updates and repair programs, if it is tampered with or forged during transmission, it will cause the power equipment to malfunction, and may even trigger large-scale systemic security incidents. Therefore, how to ensure the reliability of the repair package during transmission is an urgent problem to be solved. Summary of the Invention

[0005] Embodiments of the present invention provide a repair package transmission system to ensure the reliability of the repair package during transmission.

[0006] According to an aspect of the present invention, there is provided a repair package transmission system, which may include: a repair package transmission end and a power equipment; wherein, the repair package transmission end includes a dynamic key generation module, an encrypted repair package obtaining module, a digital signature generation module, and a digital signature transmission module, and the power equipment includes a data source verification module; wherein,

[0007] The dynamic key generation module is configured to generate a dynamic key for the original repair package to be transmitted, based on the repair content in the original repair package and the device identifier of the power equipment to be repaired by the original repair package.

[0008] The encrypted repair package obtaining module is configured to encrypt the original repair package based on the device identifier and the dynamic key to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package.

[0009] The digital signature generation module is configured to generate an encrypted data packet based on the encrypted repair package, the authentication tag, and the dynamic key, calculate a first hash value based on the encrypted repair package, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value.

[0010] The digital signature transmission module is configured to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power equipment.

[0011] A data source verification module, which is used to verify the data source of the encrypted data packet by using the digital signature for the digital signature and the encrypted data packet obtained based on the transmission packet.

[0012] The technical solution of the embodiment of the present invention includes a repair packet transmission end and a power device; wherein, the repair packet transmission end includes a dynamic key generation module, an encrypted repair packet obtaining module, a digital signature generation module, and a digital signature transmission module, and the power device includes a data source verification module; wherein, the dynamic key generation module is used to generate a dynamic key for the original repair packet to be transmitted based on the repair content in the original repair packet and the device identifier of the power device to be repaired by the original repair packet. By using the dynamic key, each original repair packet has a unique and unpredictable key, which improves the security of the key and the difficulty of key replication; the encrypted repair packet obtaining module is used to encrypt the original repair packet based on the device identifier and the dynamic key to obtain an encrypted repair packet and an authentication tag corresponding to the encrypted repair packet. By encrypting the original repair packet and verifying the integrity of the data through the authentication tag, it can prevent the original repair packet from being tampered with during transmission, and detect the integrity by verifying the authentication tag, thereby ensuring the reliability of the original repair packet; the digital signature generation module is used to generate an encrypted data packet based on the encrypted repair packet, the authentication tag, and the dynamic key, calculate a first hash value based on the encrypted repair packet, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value. The digital signature can not only prevent the original repair packet from being forged and tampered with during transmission, but also verify whether the source of the original repair packet is reliable; the digital signature transmission module is used to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power device; the data source verification module is used to verify the data source of the encrypted data packet by using the digital signature for the digital signature and the encrypted data packet obtained based on the transmission packet, so as to prevent the encrypted data packet from being forged and tampered with during transmission, and determine whether the source of the encrypted data packet is reliable. The above technical solution ensures the reliability of the original repair packet during transmission by encrypting and verifying the original repair packet.

[0013] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Brief Description of the Drawings

[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0015] Figure 1 is a structural block diagram of a repair package transmission system provided according to an embodiment of the present invention;

[0016] Figure 2 is a structural block diagram of another repair package transmission system provided according to an embodiment of the present invention;

[0017] Figure 3 is a structural block diagram of yet another repair package transmission system provided according to an embodiment of the present invention;

[0018] Figure 4 is a repair package transmission flowchart of a specific example in yet another repair package transmission system provided according to an embodiment of the present invention. Detailed implementation manners

[0019] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0020] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. The same is true for "target", "original", etc., which will not be repeated here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0021] Figure 1 is a structural block diagram of a repair package transmission system provided according to an embodiment of the present invention. This embodiment is applicable to the situation of improving the reliability of the repair package during transmission. Refer to Figure 1 , the repair package transmission system of the embodiment of the present invention may include: a repair package transmission end 11 and a power device 12; wherein, the repair package transmission end 11 includes a dynamic key generation module 111, an encrypted repair package obtaining module 112, a digital signature generation module 113, and a digital signature transmission module 114, and the power device 12 includes a data source verification module 121; wherein,

[0022] A dynamic key generation module 111 is configured to generate a dynamic key for an original repair package to be transmitted, based on the repair content in the original repair package and the device identifier of the power device 12 to be repaired by the original repair package.

[0023] An encrypted repair package obtaining module 112 is configured to encrypt the original repair package based on the device identifier and the dynamic key, to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package.

[0024] A digital signature generation module 113 is configured to generate an encrypted data packet based on the encrypted repair package, the authentication tag, and the dynamic key, and calculate a first hash value based on the encrypted repair package, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value.

[0025] A digital signature transmission module 114 is configured to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power device 12.

[0026] A data source verification module 121 is configured to verify the data source of the encrypted data packet by using the digital signature for the digital signature and the encrypted data packet obtained based on the transmission packet.

[0027] Among them, the repair package transmitter 11 can be understood as a server that sends the original repair package to the power device 12, and can transmit the original repair package to the power device 12 in response to a repair request or a repair instruction of the power device 12.

[0028] The power device 12 can be understood as a power device 12 that can perform remote repair and software upgrade in the power system. Optionally, the power device 12 is located in a distributed power system.

[0029] The original repair package can be understood as an unencrypted data packet used for fault repair or software update of a target device.

[0030] The dynamic key generation module 111 can be understood as a module for generating a dynamic key for encrypting the original repair package. A dynamic key can be generated by using a message authentication code algorithm based on the repair content in the original repair package and the device identifier of the power device 12 to be repaired by the original repair package.

[0031] The encrypted repair package obtaining module 112 can be understood as a module for encrypting the original repair package to obtain an encrypted data packet. Optionally, the encrypted repair package obtaining module 112 can be used to encrypt the original repair package based on the obtained device identifier and the dynamic key, to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package for characterizing the integrity of the encrypted repair package.

[0032] A digital signature can be understood as a specific data string generated after the repair package transmitting end 11 encrypts the original repair package by using its own private key. The power device 12 can use the public key of the repair package transmitting end 11 to verify the authenticity of the signature, prevent the original repair package from being tampered with during transmission, and ensure the authenticity and integrity of the source of the original repair package.

[0033] The digital signature generation module 113 can be understood as a module that generates an encrypted data packet and a digital signature based on an encrypted repair package, an authentication tag, and a dynamic key. Optionally, the encrypted repair package, the authentication tag, and the dynamic key can be integrated into an encrypted data packet by the digital signature generation module 113, and a first hash value can be calculated based on the encrypted repair package, the authentication tag, and the dynamic key, and a digital signature can be generated based on the first hash value.

[0034] The digital signature transmission module 114 can be understood as a module that transmits a transmission packet associated with the encrypted data packet and the digital signature to the power device 12. Optionally, in order to improve the reliability of transmission, an encryption transmission can be performed during the transmission process by using a transmission protocol, such as the Transport Layer Security protocol, the Hypertext Transfer Protocol Secure protocol, and the Secure Shell protocol, etc.

[0035] The data source verification module 121 can be understood as a module in the power device 12 that determines the data source of the received transmission packet. Optionally, the encrypted data packet and the digital signature can be obtained based on the received transmission packet. Optionally, the encrypted data packet and the digital signature can be directly obtained through the transmission packet, or the encrypted data packet and the digital signature can be obtained after decrypting the transmission packet. Further, the digital signature can be used to verify whether the encrypted data packet comes from the repair package transmitting end 11, so as to prevent the transmission packet from being swapped or tampered with during the transmission process.

[0036] The dynamic key generation module 111 in the repair package transmitting end 11 generates a dynamic key based on the repair content in the original repair package and the device identifier of the power device 12; then, the encrypted repair package obtaining module 112 encrypts the original repair package based on the device identifier and the dynamic key to obtain an encrypted repair package and an authentication tag; thereafter, the digital signature generation module 113 combines the encrypted repair package, the authentication tag, and the dynamic key to generate an encrypted data packet, calculates the first hash value of the encrypted repair package, the authentication tag, and the dynamic key at the same time, and generates a digital signature based on the first hash value, and then transmits the transmission packet associated with the encrypted data packet and the digital signature to the power device 12 through the digital signature transmission module 114. The data source verification module 121 in the power device 12 uses the digital signature to verify the data source of the encrypted data packet for the digital signature and the encrypted data packet obtained based on the transmission packet, and ensures that the encrypted data packet is not swapped or tampered with during the transmission process.

[0037] The technical solution of the embodiment of the present invention includes a repair packet transmission end and a power device; wherein, the repair packet transmission end includes a dynamic key generation module, an encrypted repair packet obtaining module, a digital signature generation module, and a digital signature transmission module, and the power device includes a data source verification module; wherein, the dynamic key generation module is used to generate a dynamic key for the original repair packet to be transmitted based on the repair content in the original repair packet and the device identifier of the power device to be repaired by the original repair packet. The dynamic key ensures that each original repair packet has a unique and unpredictable key, improving the security of the key and the difficulty of key replication; the encrypted repair packet obtaining module is used to encrypt the original repair packet based on the device identifier and the dynamic key to obtain an encrypted repair packet and an authentication tag corresponding to the encrypted repair packet. By encrypting the original repair packet and verifying the integrity of the data through the authentication tag, it can prevent the original repair packet from being tampered with during transmission, and detect the integrity by verifying the authentication tag, thereby ensuring the reliability of the original repair packet; the digital signature generation module is used to generate an encrypted data packet based on the encrypted repair packet, the authentication tag, and the dynamic key, calculate a dy hash value based on the encrypted repair packet, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value. The digital signature can not only prevent the original repair packet from being forged and tampered with during transmission, but also verify whether the source of the original repair packet is reliable; the digital signature transmission module is used to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power device; the data source verification module is used to utilize the digital signature to verify the data source of the encrypted data packet for the digital signature and the encrypted data packet obtained based on the transmission packet, so as to prevent the encrypted data packet from being forged and tampered with during transmission, and determine whether the source of the encrypted data packet is reliable. The above technical solution ensures the reliability of the original repair packet during transmission by encrypting and verifying the original repair packet.

[0038] An alternative technical solution, the dynamic key generation module includes a random salt value obtaining sub-module, an input information construction sub-module, an encryption key construction sub-module, and a dynamic key generation sub-module; wherein, the random salt value obtaining sub-module is used to obtain the time stamp when the original repair packet is generated and obtain a random salt value for the original repair packet to be transmitted; the input information construction sub-module is used to construct input information based on the repair content in the original repair packet, the device identifier of the power device to be repaired by the original repair packet, the time stamp, and the random salt value; the encryption key construction sub-module is used to construct an encryption key based on a pre-configured key seed and the device identifier; the dynamic key generation sub-module is used to encrypt the input information based on the encryption key by using a message authentication code algorithm to generate a dynamic key.

[0039] Among them, a sub-module can be obtained using a random salt value, the timestamp when the original repair package to be transmitted is generated can be obtained, and a random salt value can be obtained. The random salt value can be a randomly generated string. A sub-module can be constructed through the input information later. When combining the repair content in the original repair package, the device identifier of the power device to be repaired by the original repair package, the timestamp, and the random salt value, the security of the constructed input information can be increased. Optionally, when constructing the input information, each component can be combined in sequence into a long string as the input information. The encryption key construction sub-module can be understood as a module that constructs an encryption key for encrypting the input information. An encryption key can be constructed based on a pre-configured key seed and the device identifier. For example, the key seed and the device identifier can be combined to obtain the encryption key. Finally, through the dynamic key generation sub-module, using a message authentication code algorithm, such as the Hash-based Message Authentication Code (HMAC) algorithm based on a hash function, the input information is encrypted based on the encryption key to generate a dynamic key.

[0040] In the above technical solution, a dynamic key is generated using a message authentication code algorithm, which can make the encryption and decryption keys different each time the original repair package is transmitted, improving the security of the original repair package.

[0041] In another alternative technical solution, the encrypted repair package obtaining module includes an initialization vector construction sub-module and an encrypted repair package obtaining sub-module; among them, the initialization vector construction sub-module is used to obtain a randomly generated byte sequence and construct an initialization vector based on the byte sequence and the device identifier; the encrypted repair package obtaining sub-module is used to encrypt the original repair package based on the initialization vector and the dynamic key to generate an encrypted repair package and an authentication tag corresponding to the encrypted repair package.

[0042] Among them, the initialization vector construction sub-module can first obtain a randomly generated byte sequence, and then construct an initialization vector based on the byte sequence and the device identifier. For example, the byte sequence and the device identifier can be combined to generate the initialization vector. After that, the encrypted repair package obtaining sub-module encrypts the original repair package based on the initialization vector and the dynamic key to generate an encrypted repair package and an authentication tag corresponding to the encrypted repair package. Optionally, the encrypted repair package obtaining sub-module can be encrypted through AES-GCM, using the original repair package, the dynamic key, and the initialization vector as the input of AES-GCM, and outputting the encrypted repair package and the authentication tag corresponding to the encrypted repair package after encryption.

[0043] In the above technical solution, an encrypted repair package and an authentication tag are obtained through encryption, which can not only ensure the confidentiality of the original repair package, but also ensure the integrity and correctness of the encrypted repair package through the authentication tag. In addition, by constructing an initialization vector with a randomly generated byte sequence, the repeated use of the initialization vector can be avoided, improving the security of encryption.

[0044] On this basis, optionally, the digital signature generation module includes an encrypted data packet generation sub-module, a first hash value obtaining sub-module, and a digital signature generation sub-module; among them, the encrypted data packet generation sub-module is used to generate an encrypted data packet based on the encrypted repair package, the authentication tag, the dynamic key, and the initialization vector; the first hash value obtaining sub-module is used to perform hashing on the encrypted data packet to obtain a first hash value; the digital signature generation sub-module is used to obtain the private key of the repair package transmission end and sign the first hash value based on the private key to generate a digital signature.

[0045] Among them, the encrypted data packet generation sub-module can be understood as a module that generates an encrypted data packet based on the encrypted repair package, the authentication tag, the dynamic key, and the initialization vector. Optionally, the encrypted repair package, the dynamic key, the initialization vector, and the authentication tag can be spliced together in a preset order to form a complete encrypted data packet.

[0046] The first hash value obtaining sub-module can be understood as a module that performs hash value calculation, and can perform hashing on each component in the encrypted data packet to obtain a first hash value.

[0047] The digital signature generation sub-module can be understood as a module that generates a digital signature through the first hash value. Optionally, the private key of the repair package transmission end obtained can be used to sign the first hash value to generate a digital signature.

[0048] In the above technical solution, by generating a digital signature, it is possible to prevent the encrypted data packet from being forged and tampered with during the transmission process.

[0049] Figure 2 It is a structural block diagram of another repair package transmission system provided by an embodiment of the present invention. This embodiment is optimized based on the above technical solutions. In this embodiment, optionally, the digital signature transmission module is specifically used to encrypt the encrypted data packet and the digital signature into a transmission packet based on the transport layer security protocol and transmit the transmission packet to the power device. The explanations of the same or corresponding terms as those in the above embodiments are not repeated here.

[0050] Specifically, refer to Figure 2, the repair package transmission system of this embodiment includes: a repair package transmission end 21 and a power device 22; wherein, the repair package transmission end 21 includes a dynamic key generation module 211, an encrypted repair package obtaining module 212, a digital signature generation module 213, and a digital signature transmission module 214, and the power device 22 includes a data source verification module 221; wherein,

[0051] The dynamic key generation module 211 is used to generate a dynamic key for the original repair package to be transmitted based on the repair content in the original repair package and the device identifier of the power device 22 to be repaired by the original repair package;

[0052] The encrypted repair package obtaining module 212 is used to encrypt the original repair package based on the device identifier and the dynamic key to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package;

[0053] The digital signature generation module 213 is used to generate an encrypted data packet based on the encrypted repair package, the authentication tag, and the dynamic key, calculate a first hash value based on the encrypted repair package, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value;

[0054] The digital signature transmission module 214 is used to encrypt the encrypted data packet and the digital signature into a transmission packet based on the Transport Layer Security (TLS) protocol and transmit the transmission packet to the power device 22;

[0055] The data source verification module 221 is used to verify the data source of the encrypted data packet using the digital signature for the digital signature and the encrypted data packet obtained based on the transmission packet.

[0056] Wherein, the digital signature transmission module 214 can encrypt the encrypted data packet and the digital signature into a transmission packet based on the Transport Layer Security (TLS) protocol and transmit the transmission packet to the power device 22.

[0057] In the technical solution of the embodiment of the present invention, during the transmission process, the encrypted data packet and the digital signature are encrypted and transmitted through the Transport Layer Security protocol, which can further enhance the security during the data transmission process.

[0058] An optional technical solution is that the digital signature transmission module includes a session key determination sub-module and an encrypted transmission sub-module; wherein, the session key determination sub-module is used to establish a transmission connection with the power device in response to a handshake request for the Transport Layer Security protocol initiated by the power device and determine a session key for encrypted transmission; the encrypted transmission sub-module is used to encrypt the encrypted data packet and the digital signature based on the session key to obtain a transmission packet and transmit the transmission packet to the power device based on the transmission connection.

[0059] Among them, the session key determination sub-module can be understood as a sub-module that determines the session key for encrypted transmission between the repair package transmission end and the power device. Optionally, first, the session key determination sub-module responds to the handshake request of the power device regarding the transport layer security protocol and establishes a transport connection with the power device; then, the session key determination sub-module and the power device exchange session key materials using an asymmetric encryption algorithm, such as the public key of the repair package transmission end sent by the power device, the certificate and key exchange parameters sent by the repair package transmission end, etc.; finally, the repair package transmission end and the power device generate a session key for encrypted transmission using the negotiated key exchange algorithm. After that, using the encrypted transmission sub-module, the encrypted data packet and the digital signature are encrypted based on the session key to obtain a transmission packet, and the transmission packet is transmitted to the power device based on the transport connection.

[0060] In the above technical solution, by encrypting and transmitting the encrypted data packet and the digital signature based on the session key obtained through handshake exchange between the repair package transmission end and the power device, the security during the transmission process can be improved.

[0061] On this basis, optionally, the power device further includes: a first decryption module, configured to decrypt the transmission packet based on the session key to obtain the encrypted data packet and the digital signature, and send the encrypted data packet and the digital signature to the data source verification module.

[0062] Among them, after receiving the transmission packet for encrypted transmission, the power device can, based on the first decryption module, decrypt the transmission packet using the session key to obtain the encrypted data packet and the digital signature, and send the encrypted data packet and the digital signature to the data source verification module.

[0063] In the above technical solution, the transmission packet can be decrypted through the session key to obtain the encrypted data packet and the digital signature.

[0064] Figure 3 It is a structural block diagram of another repair package transmission system provided by an embodiment of the present invention. This embodiment is optimized based on the above technical solutions. In this embodiment, optionally, the data source verification module includes a second hash value obtaining sub-module and a digital signature verification sub-module; among them, the second hash value obtaining sub-module is configured to perform hashing on the encrypted data packet for the digital signature and the encrypted data packet obtained based on the transmission packet to obtain a second hash value; the digital signature verification sub-module is configured to verify the digital signature based on the public key of the repair package transmission end obtained in advance and the second hash value, and determine whether the data source of the encrypted data packet is the repair package transmission end according to the result of whether the digital signature verification is successful. Among them, the explanations of the same or corresponding terms as those in the above embodiments are not elaborated here.

[0065] Specifically, refer to Figure 3, the repair package transmission system of this embodiment includes: a repair package transmission end 31 and a power device 32; among them, the repair package transmission end 31 includes a dynamic key generation module 311, an encrypted repair package obtaining module 312, a digital signature generation module 313, and a digital signature transmission module 314, and the power device 32 includes a data source verification module 321, where the data source verification module 321 includes a second hash value obtaining sub-module 3211 and a digital signature verification sub-module 3212; among them,

[0066] The dynamic key generation module 311 is used to generate a dynamic key for the original repair package to be transmitted based on the repair content in the original repair package and the device identifier of the power device 32 to be repaired by the original repair package;

[0067] The encrypted repair package obtaining module 312 is used to encrypt the original repair package based on the device identifier and the dynamic key to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package;

[0068] The digital signature generation module 313 is used to generate an encrypted data packet based on the encrypted repair package, the authentication tag, and the dynamic key, calculate a hash value based on the encrypted repair package, the authentication tag, and the dynamic key, and generate a digital signature based on the hash value;

[0069] The digital signature transmission module 314 is used to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power device 32;

[0070] The second hash value obtaining sub-module 3211 is used to hash the encrypted data packet for the digital signature and the encrypted data packet obtained based on the transmission packet to obtain a second hash value;

[0071] The digital signature verification sub-module 3212 is used to verify the digital signature based on the public key of the repair package transmission end 31 obtained in advance and the second hash value, and determine whether the data source of the encrypted data packet is the repair package transmission end 31 according to the result of whether the digital signature verification is successful.

[0072] Among them, the second hash value obtaining sub-module 3211 can be understood as a sub-module in the power device 32 that calculates the second hash value of the encrypted data packet. Optionally, the obtained encrypted data packet can be hashed by the second hash value obtaining sub-module 3211 to obtain a second hash value.

[0073] The digital signature verification sub-module 3212 can verify the digital signature based on the public key of the repair package transmission end 31 obtained in advance and the second hash value. For example, use the public key to sign the second hash value, compare the signature result with the digital signature, and verify whether the digital signature has been tampered with. And according to the result of whether the digital signature verification is successful, determine whether the data source of the encrypted data packet is the repair package transmission end 31. If the verification is successful, determine that the data source of the encrypted data packet is the repair package transmission end 31. If the verification fails, it means that the data source of the encrypted data packet is incorrect, and the encrypted data packet is discarded.

[0074] Through the above technical solution, by verifying the digital signature, the source of the encrypted data packet can be determined, and the reliability of the encrypted data packet during transmission can be improved.

[0075] An optional technical solution is that the encrypted data packet includes an encrypted repair package, a dynamic key, and an initialization vector constructed based on the device identifier. The power device further includes: a second decryption module, configured to decrypt the encrypted repair package based on the received dynamic key and initialization vector to obtain the original repair package when the digital signature verification is successful, and repair the power device based on the original repair package.

[0076] Among them, the encrypted data packet includes an encrypted repair package, a dynamic key, and an initialization vector constructed based on the device identifier. When the digital signature verification is successful, the second decryption module can use the dynamic key and initialization vector to decrypt the encrypted repair package to obtain the original repair package, and repair the power device based on the original repair package.

[0077] Through the above technical solution, through the decryption process, a secure original repair package can be obtained, and the security of power device repair can be improved.

[0078] To better understand the above technical solutions as a whole, the following combines specific examples to illustrate them exemplarily. In this specific example, the repair package transmission flow chart is as Figure 4 shown, and the specific steps are as follows:

[0079] Step 1: When generating the original repair package, generate a dynamic key based on the content of the repair package and the device identifier of the power device through the HMAC-SHA512 (Hash-based Message Authentication Code--SHA512) algorithm;

[0080] 1. Concatenate the original repair package, device identifier, timestamp, and random salt value into an input message M, and use M as the input of the HMAC-SHA512 algorithm:

[0081] M = content||device id||timestamp||salt

[0082] Among them, content represents the original repair package, including the repair data to be transmitted; device id represents the device identifier; timestamp represents the timestamp when the original repair package is generated; salt represents a randomly generated random salt value.

[0083] Through the splicing operation, each part in the formula is combined in order to form the input information M, which is used as the input of the HMAC-SHA512 algorithm;

[0084] 2. Construct an encryption key K, which is composed of the key seed key seed in the system configuration and the device identifier device id combined as follows:

[0085] K = key seed ||device id

[0086] Among them, key seed represents the key seed, which is a fixed-length random byte sequence; device id represents the device identifier.

[0087] 3. Based on the constructed encryption key K and the message M, use the HMAC-SHA512 algorithm to calculate to obtain the dynamic key dynamic key . The HMAC-SHA512 algorithm encrypts the message M using the secret key K and returns a 512-bit hash value as the dynamic key dynamic key .

[0088] dynamic key = HMAC-SHA512(K, M)

[0089] Step 2: Based on the AES-GCM encryption algorithm, use the dynamic key as the encryption key to encrypt the original repair package and generate an authentication tag;

[0090] 1. Combine the device id of the power device and the randomly generated byte sequence to generate a unique initialization vector:

[0091]

[0092] Among them, random value represents a randomly generated byte sequence of n bytes, is the first m bytes of the unique identifier of the target device, where m + n = 12.

[0093] 2. Use the dynamic key and the generated iv to perform AES-GCM encryption on the original repair package, and output the encrypted repair package and the authentication tag:

[0094] ciphertext, tag = AES-GCM(dynamic key , content, iv)

[0095] Among them, tag represents the authentication tag; ciphertext represents the encrypted repair package.

[0096] 3. Concatenate the encrypted repair package, the initialization vector, and the authentication tag together in the specified order to form a complete encrypted data packet.

[0097] Step 3: The encrypted data packet is digitally signed with the private key, and the power device can verify whether the encrypted data packet is sent by the repair package transmitter based on the digital signature.

[0098] 1. Calculate the hash value based on the repair package content, the dynamic key, and the authentication tag:

[0099] H(c) = Hash(ciphertext||dynamic key ||tag)

[0100] Among them, ciphertext is the encrypted repair package, dynamic key is the dynamic key, and tag is the authentication tag.

[0101] 2. Package the digital signature signature and the encrypted data packet together.

[0102] Step 4: When the digital signature and the encrypted data packet are transmitted over the network, the TLS protocol is used for encryption; before transmission, the power device and the repair package transmitter exchange the session key through the TLS handshake.

[0103] 1. The power device initiates a TLS handshake request, and the repair package transmitter responds, and both negotiate to establish a secure connection and generate the session key. The session key generation formula is as follows (assuming the use of RSA key exchange):

[0104]

[0105] Among them, represents the session key encrypted by the public key of the repair package transmitter used by the power device; represents the private key of the repair package transmitter; session key represents the session key used by both parties in the TLS connection.

[0106] 2. The power equipment and the repair package transmission end respectively send a "Finished" message to confirm that both sides have generated the same session key and the communication channel has been encrypted;

[0107] 3. The repair package transmission end encrypts the content of the repair package using the generated session key. Here, a symmetric encryption algorithm is used, and the encryption formula is as follows:

[0108] encrypted data =AES-GCM(session key ,date,iv)

[0109] Among them, session key represents the session key; date represents the data to be encrypted (including the encrypted repair package, initialization vector, authentication tag, and digital signature); iv represents the initialization vector; encrypted data represents the encrypted transmission package.

[0110] 4. The encrypted transmission package is securely transmitted through the TLS protocol;

[0111] Step 5: The power equipment decrypts through the TLS protocol to obtain the encrypted data packet and the digital signature, and verifies the digital signature.

[0112] The power equipment uses the negotiated session key to decrypt the transmission package to obtain the encrypted data packet and the digital signature. The decryption formula is as follows:

[0113] decrypted data =AES-GCM -1 (session key ,encrypted data ,iv,tag′)

[0114] Among them, AES-GCM -1 represents the decryption process of AES-GCM; encrypted data represents the received transmission package.

[0115] Step 6: The power equipment verifies the digital signature obtained after decrypting the repair package, and verifies whether the signature is valid through the public key of the repair package transmission end. If the signature verification passes, it determines the integrity of the content of the encrypted data packet and the legality of the source. Otherwise, it discards the encrypted data packet.

[0116] Step 7: The encrypted repair package verified by the digital signature is decrypted using the dynamic key to obtain the original repair package. After decryption is completed, the content of the original repair package is applied to the target device.

[0117] In the above specific example, a reliable repair package transmission environment is constructed through a multi-layer encryption and verification mechanism.

[0118] The above specific implementation manners do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A repair package transmission system, characterized in that, Comprising: A repair package transmission end and a power device; wherein, the repair package transmission end includes a dynamic key generation module, an encrypted repair package obtaining module, a digital signature generation module, and a digital signature transmission module, and the power device includes a data source verification module; wherein, The dynamic key generation module is configured to generate a dynamic key for an original repair package to be transmitted, based on the repair content in the original repair package and the device identifier of the power device to be repaired by the original repair package; The encrypted repair package obtaining module is configured to encrypt the original repair package based on the device identifier and the dynamic key to obtain an encrypted repair package and an authentication tag corresponding to the encrypted repair package; The digital signature generation module is configured to generate an encrypted data packet based on the encrypted repair package, the authentication tag, and the dynamic key, calculate a first hash value based on the encrypted repair package, the authentication tag, and the dynamic key, and generate a digital signature based on the first hash value; The digital signature transmission module is configured to transmit a transmission packet associated with the encrypted data packet and the digital signature to the power device; The data source verification module is configured to verify the data source of the encrypted data packet by using the digital signature for the digital signature and the encrypted data packet obtained based on the transmission packet.

2. The system according to claim 1, wherein The dynamic key generation module includes a random salt value obtaining sub-module, an input information constructing sub-module, an encryption key constructing sub-module, and a dynamic key generation sub-module; wherein, The random salt value obtaining sub-module is configured to obtain a timestamp when the original repair package is generated and obtain a random salt value for the original repair package to be transmitted; The input information constructing sub-module is configured to construct input information based on the repair content in the original repair package, the device identifier of the power device to be repaired by the original repair package, the timestamp, and the random salt value; The encryption key constructing sub-module is configured to construct an encryption key based on a pre-configured key seed and the device identifier; The dynamic key generation sub-module is configured to encrypt the input information based on the encryption key by using a message authentication code algorithm to generate a dynamic key.

3. The system according to claim 1, wherein, The encrypted repair package obtaining module includes an initialization vector constructing sub-module and an encrypted repair package obtaining sub-module; wherein, The initialization vector constructing sub-module is configured to obtain a randomly generated byte sequence and construct an initialization vector based on the byte sequence and the device identifier; The encrypted repair package obtaining sub-module is configured to encrypt the original repair package based on the initialization vector and the dynamic key to generate an encrypted repair package and an authentication tag corresponding to the encrypted repair package.

4. The system according to claim 3, wherein The digital signature generation module includes an encrypted data packet generation sub-module, a first hash value obtaining sub-module, and a digital signature generation sub-module; wherein, The encrypted data packet generation sub-module is configured to generate an encrypted data packet based on the encrypted repair package, the authentication tag, the dynamic key, and the initialization vector; The first hash value obtaining sub-module is used to perform hashing on the encrypted data packet to obtain a first hash value; The digital signature generating sub-module is used to obtain the private key of the repair packet transmitting end, and sign the first hash value based on the private key to generate a digital signature.

5. The system according to claim 1, wherein The digital signature transmission module is specifically used to encrypt the encrypted data packet and the digital signature into a transmission packet based on the transport layer security protocol, and transmit the transmission packet to the power device.

6. The system according to claim 5, wherein The digital signature transmission module includes a session key determination sub-module and an encryption transmission sub-module; wherein, The session key determination sub-module is used to establish a transmission connection with the power device in response to a handshake request for the transport layer security protocol initiated by the power device, and determine a session key for encrypted transmission; The encryption transmission sub-module is used to encrypt the encrypted data packet and the digital signature based on the session key to obtain a transmission packet, and transmit the transmission packet to the power device based on the transmission connection.

7. The system according to claim 6, wherein The power device further includes: The first decryption module is used to decrypt the transmission packet based on the session key to obtain the encrypted data packet and the digital signature, and send the encrypted data packet and the digital signature to the data source verification module.

8. The system according to claim 1, wherein The data source verification module includes a second hash value obtaining sub-module and a digital signature verification sub-module; wherein, The second hash value obtaining sub-module is used to perform hashing on the encrypted data packet for the digital signature and the encrypted data packet obtained based on the transmission packet to obtain a second hash value; The digital signature verification sub-module is used to verify the digital signature based on the pre-obtained public key of the repair packet transmitting end and the second hash value, and determine whether the data source of the encrypted data packet is the repair packet transmitting end according to the result of whether the digital signature verification is successful.

9. The system according to claim 8, wherein The encrypted data packet includes the encrypted repair packet, the dynamic key, and an initialization vector constructed based on the device identifier. The power device further includes: The second decryption module is used to decrypt the encrypted repair packet based on the received dynamic key and the initialization vector in the case where the digital signature verification is successful to obtain the original repair packet, and repair the power device based on the original repair packet.

10. The system according to any one of claims 1-9, characterized in that, The power device is located in a distributed power system.