Encryption module for realizing secure transmission based on secure encryption chip
By introducing the encryption module of a secure encryption chip into the negative control terminal, the problem that existing terminals do not support secure transmission is solved, efficient and secure data communication is achieved, and replacement costs and resource waste are reduced.
Patent Information
- Application Number
- CN202410085134.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-20
- Publication Date
- 2025-07-29
AI Technical Summary
Existing negative control terminals do not support secure encrypted transmission, resulting in high replacement costs, waste of resources and low information security.
The encryption module based on the security encryption chip is adopted to encrypt and decrypt the data through the main control chip and the security encryption chip to achieve end-to-end secure communication.
It improves the security of data transmission, reduces the time and labor cost of replacing terminals, and reduces maintenance difficulties and resource waste.
Smart Images

Figure CN120390212A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of secure wireless communication transmission, and particularly to an encryption module for secure transmission implemented based on a secure encryption chip. Background Art
[0002] In the current power consumption information acquisition system, the communication between the acquisition master station and the terminal is mainly achieved through a wireless remote communication module, and this method is essential as a data transmission channel.
[0003] However, in contrast, most of the current negative control terminals in operation do not support communication in a secure encryption transmission manner due to the limitations of their own hardware. For this situation, currently, only new specification terminals can be replaced, or plaintext interaction can be directly used. The former requires huge costs. On the one hand, the number of negative control terminals used on-site is large, the replacement operation steps are numerous and the process is complex, and the specific implementation also has relatively high requirements for staff. This method is inefficient, and it is difficult to quickly implement the requirements for power control security in practice. On the other hand, replacing new terminals increases the workload of maintenance, and the large number of previously purchased and inventoried devices that cannot be used also causes waste of resources. The latter, however, has great potential safety hazards in terms of security and will cause the risk of information leakage. In the plaintext transmission method, the security of information cannot be guaranteed during the transmission process, and it is often maliciously eavesdropped and modified, and the system will also be severely attacked accordingly.
[0004] Therefore, an encryption module for secure transmission implemented based on a secure encryption chip proposed by the present invention can effectively solve the problems of low security of the current power consumption information transmission method, easy data leakage, and difficult maintenance and inventory waste caused by high human and time costs for replacing terminals through the upgrade and iteration of the communication module. Summary of the Invention
[0005] In view of the deficiencies and defects of the prior art, the present invention provides an encryption module for secure transmission implemented based on a secure encryption chip. On the basis of the original remote communication module, the encryption communication module expands its functions and provides a new service processing mode. Through the preprocessing of the received information by the main control program of the encryption module, as an information transfer medium, the message is encrypted or decrypted before being received by the target, and is converted into plaintext or ciphertext that conforms to the business logic of the current entire system. The main control chip of the encryption communication module selects different processing methods for the received data content by calling the secure encryption chip according to different service types, and finally performs plaintext or ciphertext transmission according to the target address, thereby realizing end-to-end secure communication between the acquisition master station and the terminal.
[0006] The object of the present invention can be achieved by the following technical solutions:
[0007] An encryption module that realizes secure transmission based on a secure encryption chip, characterized in that the business system framework involved in this method includes: an encryption communication module, a main station for collecting electricity consumption information, an encryption server, a negative control terminal, and a key console. Among them:
[0008] The encryption communication module mainly includes a main control chip part, a power supply part, a secure encryption chip part, and a pluggable SIM card part. It has the ability to establish a secure connection with the collection main station, process data as needed, and perform data sending and receiving. It can encrypt and decrypt the sent and received data and then send it to the upstream or downstream devices;
[0009] The encryption server has the function of decrypting or encrypting the commands received or sent by the collection main station. After receiving the plaintext command, key, and certificate information provided by the collection main station, it forms an encrypted message and returns it to the collection main station as an encrypted command to be sent to the terminal. After receiving the ciphertext response and decryption information provided by the collection main station, it forms a plaintext message and returns it to the collection main station as a data record;
[0010] The negative control terminal has the functions of processing plaintext data and executing control commands, responding to the received plaintext request commands, or executing the received plaintext control commands;
[0011] The key console has the functions of key distribution and update. Taking the terminal as the channel, it distributes key information, updates security authentication information, and encryption and decryption methods to the module;
[0012] The main station for collecting electricity consumption information, on the one hand, requests data from the negative control terminal or sends encrypted control commands by calling the encryption server to convert the plaintext request into an encrypted message; on the other hand, it decrypts the upstream message sent by the negative control terminal and encrypted by the encryption module through calling the encryption server, including the reply to the terminal that sent the request and the confirmation response after the terminal executes the command.
[0013] Furthermore, the main control chip part, which is the part with the main functions in the module, undertakes the basic functions of the module. The main control chip first supports remote wireless communication functions, supports receiving downstream information from the main station and sending upstream information from the terminal. Through the judgment of the received information, it has the ability to judge the encryption status and call the secure encryption chip, which is used to perform key encryption and decryption work; secondly, the main control chip will save the source of the received information to ensure the accuracy of end-to-end transmission during data transmission; in addition, the main control chip enables the encryption module to have the ability to upgrade the module itself compared with traditional remote modules, no longer relying on terminal forwarding. The module firmware needs to meet the technical specification requirements such as SGP.02, SGP.21, SGP.21, etc. in the GSMA standard.
[0014] Further, for the pluggable SIM card part, the pluggable SIM card is a traditional pluggable SIM card in the industry, including Mini-SIM card, Micro-SIM card, Nano-SIM card, etc., and supports major operators.
[0015] Further, for the security encryption chip part, it is used to store key information and security authentication certificate information for encryption and decryption use. The security encryption chip is called by the main control chip to process the data transmitted from the terminal or the master station to the main control chip, decrypt the encrypted information, and encrypt the plaintext information.
[0016] The beneficial technical effects of the present invention: An encryption module that realizes secure transmission based on a security encryption chip is proposed. When it is necessary to transmit load control commands or request data information, the encrypted communication module can directly encrypt, decrypt or directly process responses for the transmitted data information according to the application scenario, ensuring that in the entire communication process, the end-to-end information transmission is in a secure protection state in the form of ciphertext. On the one hand, it improves the security of the data transmission channel. On the other hand, by replacing the encrypted communication module to solve security problems, compared with directly replacing a new terminal, it also greatly reduces the time and labor costs. In addition, the encrypted communication module has a main control program and supports independent upgrade and iteration, which can also avoid usage and update problems caused by the terminal not supporting module upgrade. Description of the Drawings
[0017] Figure 1 is the framework diagram of the present invention.
[0018] Figure 2 is the flow chart of the present invention. Detailed Embodiments
[0019] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and do not limit the present invention.
[0020] As Figure 1 shown, an overall framework diagram of the practical application of an encryption module that realizes secure transmission based on a security encryption chip mainly involves the communication process between the acquisition master station and the on-site user-side terminal, as well as the process of using the key platform to update the key and security certificate information to the module through the terminal as a medium. The overall working flow chart of the module is as Figure 2 shown, and its specific implementation process is as follows:
[0021] The encryption communication module is equipped with a secure encryption chip inside. When the module receives data information, the main control chip will first record several flag bits of the received message, judge the sending target of the message, and whether encryption or decryption processing is required. For the content that needs to be processed, after the encryption and decryption operations are performed, the processed message will be sent to the corresponding object.
[0022] The working scenarios and logics of the module can be roughly divided into the following situations:
[0023] 1) The acquisition master station and the encryption module perform identity authentication to establish a session connection. Before performing identity authentication, the key information, terminal certificate, and master station certificate are first sent to the encryption module through the platform. The master station sends a request command to the encryption module to obtain the terminal security certificate and key information. After receiving the request information, the main control chip of the encryption module obtains the relevant information from the secure encryption chip and returns it to the acquisition master station. The acquisition master station calls the encryption server to generate a ciphertext command through the key, generates a signature through the master station certificate, and combines them into a composite ciphertext and sends it to the encryption module. After receiving the message, the main control chip of the module decrypts the content. The main control chip calls the previously saved key information and master station certificate, and sends them together with the ciphertext to the secure encryption chip for decryption verification. If the verification fails, an error code will be returned to the acquisition master station. After the verification passes, the secure encryption chip will call the key information and terminal certificate to generate another composite ciphertext and send it to the acquisition master station. After receiving it, the acquisition master station will send the ciphertext and the terminal certificate to the encryption server for decryption verification. After the verification passes, the acquisition master station will call the encryption server to send a ciphertext command to confirm the establishment of the session connection to the encryption module through the key. After receiving it, the secure encryption chip of the module uses the key to verify the ciphertext. After the verification, the master station and the encryption module successfully establish an encrypted communication channel. Before performing symmetric key update, terminal certificate update, master station certificate update, setting the offline counter, transferring encryption authorization, and issuing tasks to a batch of terminals, identity authentication is required to verify the identity legality of the master station and the terminal.
[0024] 2) The key and security certificate information of the frustum update module. Since the current negative control terminal does not carry security encryption-related information, the command is continuously forwarded downward by the terminal to the encryption module. The encryption module replaces the terminal to execute the relevant work. The frustum of the key sends commands to the terminal through Ethernet or a 485 port to update the key and certificate information. In this scenario, the terminal does not process the relevant information and directly sends the information to the module. The encryption module is jointly processed by the main control chip and the security encryption chip to achieve the update of the module key and security certificate. Before the update, the frustum first sends a request command to authenticate with the encryption module and establish a session. The specific process of the authentication is roughly the same as that described in scenario 1), except that the communication method changes from wireless remote communication to using the terminal as a relay. The data interaction of the whole process is achieved by the frustum forwarding to the encryption module through the terminal. After establishing the session, the frustum starts to send the updated key information downward. The terminal receives it and forwards it to the module. After the main control chip of the module receives the new key information, it calls the security encryption chip to save the new key and returns an acknowledgment response. The terminal returns the response to the frustum. After the frustum receives the response, it re-performs the security authentication. After passing the authentication with the new key, it then sequentially issues the new master station certificate and terminal certificate information again. The frustum sends them to the terminal, and the terminal forwards them to the encryption module. The main control chip of the module updates the stored security certificate information by calling the security encryption chip, and finally realizes the update of the key and certificate information of the module;
[0025] 3) When the acquisition master station sends a ciphertext command such as closing or opening a switch, and the terminal needs to execute the relevant command, the acquisition master station calls the encryption server to first authenticate with the encryption module and establish a session connection. After passing the verification, it sends the key information and the plaintext command to the encryption server. The encryption server encrypts the command and returns it to the acquisition master station. The acquisition master station sends an encrypted message downward. After the main control chip of the encryption communication module receives the message sent by the acquisition master station, it makes a judgment based on the content of the message. If it is confirmed that the currently received message needs to be decrypted and then sent to the terminal for the terminal to execute the control command, the main control chip will record the source and encryption status of the message, and then transmit the message to the security encryption chip. The security encryption chip calls the key and the master station certificate information to process the encrypted message, decrypts the message into plaintext and returns it to the main control chip. The main control chip sends it to the user terminal through the serial port, and the terminal executes the control command from the master station. After the terminal executes, it returns a response and sends it to the encryption module through the serial port. After the main control chip in the module receives the plaintext message from the terminal, it determines whether the response returned by the terminal needs to be encrypted and replied according to the stored source and status records. If it is confirmed that the received message needs to be encrypted again and sent back according to the source, the main control chip will call the security encryption chip, send the data to the security encryption chip, and the security encryption chip calls the key information and the terminal certificate to encrypt the message. After the processing, it returns to the main control chip, and then the main control chip sends the ciphertext response to the acquisition master station. The acquisition master station then calls the encryption server to decrypt the received message through the terminal certificate and the key information and record it; if it is judged that the terminal reply is an acknowledgment frame for executing the command and does not need to be encrypted and replied, the main control chip directly packs the information and sends the information back to the acquisition master station for response according to the recorded source, without encrypting the content again. The encryption module ensures the security and accuracy of the entire communication process through the judgment and processing of the received information;
[0026] 4) When the acquisition master station sends a ciphertext request command such as data polling, the terminal needs to receive the command and respond. The acquisition master station calls the encryption server to first authenticate with the encryption module and establish a session connection. After successful verification, it sends the key information and plaintext request to the encryption server. The server encrypts the command and returns it to the acquisition master station. The acquisition master station sends the encrypted message downward. After the main control chip of the encryption communication module receives the message sent by the acquisition master station, it makes a judgment based on the content of the message. If it is confirmed that the currently received message needs to be decrypted and then sent to the terminal for the terminal to make a response reply, the main control chip will record the source and encryption status of the message, and then transmit the message to the security encryption chip. The security encryption chip calls the key and the master station certificate information to process the encrypted message, decrypts the message into plaintext and returns it to the main control chip. The main control chip sends it to the user terminal through the serial port. The terminal executes the control command from the master station, and after the execution, it returns the polling result and sends it to the encryption module through the serial port. After the main control chip in the module receives the plaintext message from the terminal, it judges whether the response returned by the terminal needs to be encrypted and replied according to the stored source and status records. If it is confirmed that the received message needs to be encrypted again and sent back according to the source, the main control chip will call the security encryption chip. The security encryption chip encrypts the data by calling the key information and the terminal certificate, and after the processing, it returns to the main control chip. Then the main control chip sends the ciphertext response to the acquisition master station. The acquisition master station then calls the encryption server to decrypt the received message through the terminal certificate and key information and records it;
[0027] 5) When the acquisition master station sends ciphertext, the module can directly process it, usually a request command for reading encrypted information. The acquisition master station first conducts identity authentication and establishes a session connection with the encryption module, and then sends the plaintext command, key, and certificate information to the encryption server. The server returns the ciphertext. The acquisition master station sends a ciphertext request command downward. After the encryption communication module receives the ciphertext request command sent by the master station, the main control chip makes a judgment based on the content of the message. If it is confirmed that the received command should be directly processed and responded by the encryption module, the main control chip calls the security encryption chip to decrypt the received encrypted message, and records the source and encryption status of this command. Then, according to the obtained request command, the corresponding information is obtained, and the response data is encrypted again through the security encryption chip, and then the returned data is responded. In a secure encryption manner, it is directly sent to the master station through the main control chip. The acquisition master station decrypts the reply content through the encryption server, and the entire process does not require the terminal to intervene in the processing;
[0028] 6) The acquisition master station sends a plaintext request, which requires the terminal to execute or respond. The acquisition master station directly sends the plaintext request downward. The main control chip of the encryption module receives the plaintext data sent by the master station. After judging according to the content of the message, it is confirmed that decryption processing is not required and can be directly sent to the terminal. The main control chip records the source and encryption status of the message. After recording, the main control chip directly sends the plaintext to the terminal. After receiving the plaintext, the terminal processes it according to the content. After processing, the terminal sends the response data to the encryption module through the serial port or USB. The main control chip of the encryption module matches the message with the previous record. After correspondence, it is confirmed that the content does not require encryption processing. The main control chip directly sends the data to the master station, realizing the plaintext wireless transmission between the acquisition master station and the user-side terminal.
[0029] The above embodiments are illustrative of the specific implementation manners of the present invention, rather than limitations on the present invention. Those skilled in the relevant technical fields can make various transformations and changes without departing from the spirit and scope of the present invention to obtain corresponding equivalent technical solutions. Therefore, all equivalent technical solutions should be included in the patent protection scope of the present invention.
Claims
1. An encryption module for secure transmission implemented based on a secure encryption chip, characterized in that, The system framework includes an encrypted communication module, a main station for collecting power consumption information, an encryption server, a negative control terminal, and a key console.
2. The encryption module for secure transmission implemented based on a secure encryption chip according to claim 1, wherein The encrypted communication module mainly includes a main control chip part, a power supply part, an encryption chip part, and a pluggable SIM card part.
3. The master control chip part according to claim 2, characterized in that, It supports remote wireless communication functions, has the ability to judge the encryption status and call the encryption chip; it has enhanced the ability to upgrade the module itself, no longer relying on terminal forwarding, and the module firmware needs to meet the technical specification requirements of SGP.02, SGP.21, and SGP.21 in the GSMA standard.
4. The encryption chip part according to claim 2, wherein It stores key information and security authentication certificate information for encryption and decryption. The encryption chip is called by the main control chip to process the data transmitted from the terminal or the main station to the main control chip, decrypt the encrypted information, and encrypt the plaintext information.
5. The power supply part according to claim 2, characterized in that, The power supply part provides power for the module. The power supply can provide a load capacity of 2A / 1ms transient and 1A normal state to ensure that the power supplied to the module is stable under any circumstances.
6. The encryption module for secure transmission implemented based on a secure encryption chip according to claim 1, characterized in that, The encryption server has the function of decrypting or encrypting the commands transmitted by the collection main station according to the provided key and security certificate information.
7. An encryption module for secure transmission implemented based on a secure encryption chip according to claim 1, characterized in that, The main station for collecting power consumption information exchanges data with the encrypted communication module.