Encryption starting method for power fault diagnosis device
By employing a dual-end detection and bidirectional verification mechanism, the problem of unusable or modified keys due to damage or replacement of the encryption chip during startup of the power fault diagnosis device is solved, thus achieving secure and reliable startup of the encryption chip and validity of the certificate.
Patent Information
- Application Number
- CN202510340829.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-08-01
AI Technical Summary
When a power fault diagnosis device is started up, the encryption chip may be damaged or replaced, resulting in the key becoming unusable or being modified, which may cause the issued certificate to become invalid.
A dual-end detection mechanism and a two-way verification mechanism are adopted. Through the two-way detection and verification of the power fault diagnosis device and the cloud platform, it is determined whether the encryption chip needs to regenerate the key. If necessary, the key is generated and synchronized. The maintenance mapping table is combined with the old and new devices to obtain historical encryption parameters.
This ensures that the encryption chip's key is not modified after it is first used, preventing the issued certificate from becoming invalid and supporting normal startup after device maintenance, thus improving the system's security and reliability.
Smart Images

Figure CN120416007A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power fault diagnosis, and specifically, to an encryption startup method for a power fault diagnosis device. Background Art
[0002] With the rapid development of smart power grids, the requirements for data information security are getting higher and higher. Power devices are generally connected to the power grid through two methods: software encryption and hardware encryption, and the encryption is uniformly implemented using domestic encryption algorithms. For the two encryption methods, software encryption does not require additional peripherals, has low cost, and is simple to implement, but has a large amount of data operations and requires the system to have a certain amount of memory resources; hardware encryption requires a dedicated encryption chip, the system does not need to perform too much data processing, saving the system processor resources, but the power consumption and chip cost will increase to a certain extent.
[0003] For power fault diagnosis devices, considering the limited system resources, the hardware encryption method is adopted to connect to the power grid. Before the power fault diagnosis encryption device starts up and accesses the network, it is necessary to initialize the encryption chip. When the encryption chip leaves the factory, there is no key inside and it needs to be regenerated. Otherwise, the encryption chip cannot be used, but the chip key can only be generated once, and each time the system restarts, it is necessary to ensure that the key cannot be modified, otherwise the issued certificate will become invalid. During the operation of the encryption device of the power fault diagnosis device, there may be a situation where the materials are damaged, which requires maintenance of the equipment. And equipment maintenance may replace materials, such as replacing the encryption chip, central processing unit, memory, communication module, etc. When the device starts up, there may be problems such as the encryption chip being unavailable or the key being modified, and the issued certificate becoming invalid.
[0004] In order to solve the above problems, an encryption startup scheme needs to be proposed. Summary of the Invention
[0005] The purpose of the present invention is to provide an encryption startup method for a power fault diagnosis device in view of the deficiencies of the prior art.
[0006] In order to achieve the above purpose, the technical solution adopted by the present invention is: The first aspect of the present invention provides an encryption startup method for a power fault diagnosis device, including the following steps: Step 1: Determine whether the power fault diagnosis device is connected to the cloud platform. If so, proceed to the next step; otherwise, continue to determine. Step 2: According to the local key generation flag LEF of the power fault diagnosis device and the cloud key generation flag CEF of the cloud platform, the power fault diagnosis device and the cloud platform perform a dual-end detection to determine whether the encryption chip of the power fault diagnosis device needs to regenerate the key. If so, proceed to the next step; otherwise, proceed to Step 5. Step 3: Check whether the maintenance mapping table of the power failure diagnosis device is empty. If it is not empty, proceed to the next step; if it is empty, go to Step 6; Step 4: Obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therein, and based on the extracted historical encryption parameters, perform two-way verification between the power failure diagnosis device and the cloud platform to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, go to Step 6; otherwise, go to Step 7; Step 5: Obtain the encryption parameter table of the cloud platform and the encryption parameter table of the power failure diagnosis device, extract the encryption parameters therein, and based on the extracted encryption parameters, perform two-way verification between the power failure diagnosis device and the cloud platform to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, go to Step 6; otherwise, go to Step 7; Step 6: The encryption chip of the power failure diagnosis device regenerates the key; Step 7: The power failure diagnosis device synchronously updates the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform; Step 8: The encryption initialization is completed.
[0007] Based on the above, the method for the power failure diagnosis device and the cloud platform to perform dual-end detection is as follows: After the power failure diagnosis device is powered on, read the local key generation flag LEF of the power failure diagnosis device. After waiting for the power failure diagnosis device to connect to the cloud platform, read the cloud key generation flag CEF of the cloud platform; Determine whether the power failure diagnosis device needs to regenerate the key: (1) If it is determined that both LEF and CEF are 0xAABB, it means that the key has been generated and has been synchronized to the cloud platform, and there is no need to regenerate; (2) If it is determined that LEF is 0xAABB and CEF is 0xFFFF, it means that the key has been generated and there is no need to regenerate; however, since the device number of the power failure diagnosis device has been modified and the cloud platform has not been synchronized, set CEF to 0xAABB and synchronize it to the cloud platform; (3) If it is determined that LEF is 0xFFFF and CEF is 0xAABB, it means that the key has been generated and there is no need to regenerate; however, since the maintenance of the power failure diagnosis device causes LEF to be 0xFFFF, set LEF to 0xAABB and synchronize it to the encryption parameter table of the power failure diagnosis device; (4)Judge that both LEF and CEF are 0xFFFF, indicating that the key has not been generated and needs to be regenerated. Send a key generation instruction to the encryption chip of the power failure diagnosis device. After confirming the key generation, update both LEF and CEF to 0xAABB and synchronize them to the encryption parameter tables of the power failure diagnosis device and the cloud platform respectively.
[0008] Based on the above, the maintenance mapping table is used to extract historical encryption parameters and record the device maintenance history, including the device serial number SN after maintenance, the communication module serial number CID after maintenance, the original communication module serial number OCID before maintenance, the memory serial number SID, the central processing unit serial number UID, and the key KEY.
[0009] Based on the above, the method for the power failure diagnosis device and the cloud platform to perform two-way verification is as follows: Step 5.1: Read the key KEY in the encryption parameter table of the cloud platform and compare it with the key LKEY in the encryption parameter table of the power failure diagnosis device. If they are the same, it means that the key KEY of the power failure diagnosis device has not been modified and the issued certificate is available. Jump to step 5.6. If they are different, jump to step 5.2. Step 5.2: Read the random number DR and the ciphertext EDR of the random number DR in the encryption parameter table of the cloud platform, and call the encryption chip of the power failure diagnosis device to perform two-way verification of encryption and decryption. If the encryption and decryption operations fail, it means that the key KEY of the power failure diagnosis device is unavailable. Jump to step 5.5. If the encryption and decryption operations succeed, obtain the ciphertext LEDR after local encryption of the random number DR and the random number LDR after local decryption of the ciphertext EDR of the random number DR. Compare the random number DR with the random number LDR, and the ciphertext EDR with the ciphertext LEDR. If the matches are consistent, the key KEY of the power failure diagnosis device has not been modified and the issued certificate is available, but the key KEY has not been synchronized to the cloud platform. Jump to step 5.3. If they are inconsistent, it means that there is a key KEY inside the power failure diagnosis device, but the key KEY has been modified. Jump to step 5.4. Step 5.3: Synchronize the key KEY to the encryption parameter table of the cloud platform, no need to issue a certificate again. Jump to step 5.6. Step 5.4: Generate a new random number DR, re-encrypt to generate a new ciphertext EDR, synchronize the new random number DR, the new ciphertext EDR, and the new key KEY to the encryption parameter table of the cloud platform, and at the same time notify the cloud platform that the certificate has expired and a new certificate needs to be issued. Jump to step 5.6. Step 5.5: The encryption chip of the power failure diagnosis device regenerates a new key KEY, reads the new key KEY, generates a new random number DR, re-encrypts to generate a new ciphertext EDR, synchronizes the new random number DR, the new ciphertext EDR, and the new key KEY to the encryption parameter table of the cloud platform, and jumps to Step 5.6; Step 5.6: The encryption initialization is completed.
[0010] The second aspect of the present invention provides a power failure diagnosis device encryption startup system, including: A second processing module, configured to perform dual-end detection of the power failure diagnosis device and the cloud platform according to the local key generation flag LEF of the power failure diagnosis device and the cloud key generation flag CEF of the cloud platform, and determine whether the encryption chip of the power failure diagnosis device needs to regenerate a key; A third processing module, configured to traverse the maintenance mapping table of the power failure diagnosis device and determine whether the maintenance mapping table is empty; A fourth processing module, configured to obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therein, and perform two-way verification of the power failure diagnosis device and the cloud platform according to the extracted historical encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate a key; A fifth processing module, configured to obtain the encryption parameter table of the cloud platform and the encryption parameter table of the power failure diagnosis device, extract the encryption parameters therein, and perform two-way verification of the power failure diagnosis device and the cloud platform according to the extracted encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate a key; A sixth processing module, configured to cause the encryption chip to regenerate a key when the fourth processing module and the fifth processing module determine that a key needs to be regenerated; A seventh processing module, configured to synchronously update the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform when the fourth processing module and the fifth processing module determine that a key does not need to be regenerated, and after the encryption chip regenerates a key; An eighth processing module, configured to complete the encryption initialization.
[0011] The third aspect of the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the power failure diagnosis device encryption startup method as described above.
[0012] The fourth aspect of the present invention provides a computer-readable storage medium, on which a computer program / instructions are stored, and when the computer program / instructions are executed by a processor, the power failure diagnosis device encryption startup method as described above is implemented.
[0013] The fifth aspect of the present invention provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the encrypted startup method of the power failure diagnosis device as described above.
[0014] The present invention has prominent substantive features and remarkable progress compared with the prior art. Specifically: (1) Through a dual-end detection mechanism, when the device is normally started, it not only satisfies the generation of a key for the first use, but also when it is not started for the first time, the key will not be modified, preventing the issued certificate from becoming invalid; (2) Through a two-way verification mechanism, it is used for the maintenance of damaged encryption chips to prevent the encryption chips from being unusable due to the failure to generate keys, and makes supplementary revisions to the dual-end detection mechanism; (3) Create a maintenance mapping table to associate new and old devices, realize the acquisition of old encryption parameters, and make supplementary revisions to the dual-end detection mechanism; (4) The encrypted startup method of the present invention can be extended to other ICs, products or industries, which is of great significance. Description of the Drawings
[0015] Figure 1 It is a system block diagram relied on by the present invention.
[0016] Figure 2 It is the overall implementation flowchart of the method of the present invention.
[0017] Figure 3 It is the implementation flowchart of the dual-end detection mechanism of the present invention.
[0018] Figure 4 It is the implementation flowchart of the two-way verification mechanism of the present invention.
[0019] Figure 5 It is the implementation flowchart of the maintenance mapping table of the present invention. Detailed Embodiments
[0020] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the protection scope of the present application.
[0021] The terms "including" and "having" and any variations thereof in the specification and claims of the present application and the above-mentioned drawings are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units that are not listed.
[0022] The method, system, medium, and product provided by the embodiments of the present application will be described in detail below in conjunction with the accompanying drawings through some embodiments and their application scenarios.
[0023] The system relied on by the present invention is as Figure 1 shown, including a power failure diagnosis device and a cloud platform. The power failure diagnosis device includes a central processing unit, an encryption chip, a memory, a communication module, and a power supply module.
[0024] Central processing unit: The core processor is used to implement functions such as system startup, encrypted data interaction, storage data reading and writing, and cloud platform data interaction. Encryption chip: Realize functions such as data encryption and decryption, certificate import and export. Memory: Used to store system parameters and encryption-related parameters. Communication module: The communication medium between the system and the cloud platform is used to realize data interaction and communication with the cloud platform. Power supply module: Supply power to the encryption device. Cloud platform: Used to display system parameters and read and write configuration of encryption parameters, etc.
[0025] In a first aspect, the embodiments of the present application provide an encryption startup method for a power failure diagnosis device, including the following steps, as Figure 2 shown: Step 1: Determine whether the power failure diagnosis device is connected to the cloud platform. If so, proceed to the next step; otherwise, continue to determine. Step 2: Generate a local key generation flag LEF of the power failure diagnosis device and a cloud key generation flag CEF of the cloud platform. The power failure diagnosis device and the cloud platform perform double-end detection to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to the next step; otherwise, proceed to Step 5. Step 3: Check whether the maintenance mapping table of the power failure diagnosis device is empty (not every power failure diagnosis device has information in the maintenance mapping table. Only the power failure diagnosis devices that have been maintained will have records. If the power failure diagnosis device has not been maintained, the information corresponding to this power failure diagnosis device in the cloud platform's maintenance mapping table cannot be queried and is empty). If it is not empty, proceed to the next step; if it is empty, proceed to Step 6. Step 4: Obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therein, and perform two-way verification between the power failure diagnosis device and the cloud platform based on the extracted historical encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to Step 6; otherwise, proceed to Step 7. Step 5: Obtain the encryption parameter tables of the cloud platform and the power failure diagnosis device, extract the encryption parameters therein, and based on the extracted encryption parameters, perform two-way verification between the power failure diagnosis device and the cloud platform to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to Step 6; otherwise, proceed to Step 7; Step 6: The encryption chip of the power failure diagnosis device regenerates the key; Step 7: The power failure diagnosis device synchronously updates the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform; Step 8: The encryption initialization is completed.
[0026] When the encryption chip is used for the first time, the key needs to be generated once. After the key is generated, it cannot be updated again, otherwise the certificate will become invalid. The present invention proposes a dual-end detection mechanism, that is, the key generation flag EF (encryption flag) is stored in the power failure diagnosis device (equipment) and the cloud platform respectively.
[0027] As Figure 3 shown, the method for the power failure diagnosis device and the cloud platform to perform dual-end detection is as follows: After the power failure diagnosis device is powered on, read the local key generation flag LEF of the power failure diagnosis device. After waiting for the power failure diagnosis device to connect to the cloud platform, then read the cloud key generation flag CEF of the cloud platform; Determine whether the power failure diagnosis device needs to regenerate the key: (1) If it is determined that both LEF and CEF are 0xAABB, it means the key has been generated and has been synchronized to the cloud platform, and there is no need to regenerate; (2) If it is determined that LEF is 0xAABB and CEF is 0xFFFF, it means the key has been generated and there is no need to regenerate; however, since the device number of the power failure diagnosis device has been modified and the cloud platform has not been synchronized, set CEF to 0xAABB and synchronize it to the cloud platform; (3) If it is determined that LEF is 0xFFFF and CEF is 0xAABB, it means the key has been generated and there is no need to regenerate; however, since the maintenance of the power failure diagnosis device causes LEF to be 0xFFFF, set LEF to 0xAABB and synchronize it to the encryption parameter table of the power failure diagnosis device; (4) If it is determined that both LEF and CEF are 0xFFFF, it means the key has not been generated and needs to be regenerated; send a key generation instruction to the encryption chip of the power failure diagnosis device. After confirming that the key is generated, update both LEF and CEF to 0xAABB and synchronize them to the encryption parameter tables of the power failure diagnosis device and the cloud platform respectively.
[0028] If the encryption chip is damaged and replaced, a new key needs to be generated before it can be used. However, since the key generation flags stored locally in the power failure diagnosis device and on the cloud platform have both been set, if only the dual-end detection mechanism is relied on, the encryption chip will not generate a new key, resulting in the encryption chip being unavailable. To address this issue, an encryption + decryption two-way verification mechanism is proposed.
[0029] As Figure 4 shown, the method for the power failure diagnosis device to perform two-way verification with the cloud platform is as follows: Step 5.1: Read the key KEY in the encryption parameter table of the cloud platform and compare it with the key LKEY in the encryption parameter table of the power failure diagnosis device; If they are the same, it indicates that the key KEY of the power failure diagnosis device has not been modified and the issued certificate is available. Jump to Step 5.6; If they are different, jump to Step 5.2; Step 5.2: Read the random number DR and the ciphertext EDR of the random number DR in the encryption parameter table of the cloud platform, and call the encryption chip of the power failure diagnosis device to perform two-way verification of encryption and decryption; If the encryption and decryption operations fail, it indicates that the key KEY of the power failure diagnosis device is unavailable. Jump to Step 5.5; If the encryption and decryption operations succeed, obtain the ciphertext LEDR after local encryption of the random number DR and the random number LDR after local decryption of the ciphertext EDR of the random number DR; Compare the random number DR with the random number LDR, and the ciphertext EDR with the ciphertext LEDR; If they match, it means that the key KEY of the power failure diagnosis device has not been modified and the issued certificate is available, but the key KEY has not been synchronized to the cloud platform. Jump to Step 5.3; If they are inconsistent, it indicates that there is a key KEY inside the power failure diagnosis device, but the key KEY has been modified. Jump to Step 5.4; Step 5.3: Synchronize the key KEY to the encryption parameter table of the cloud platform, and there is no need to issue a new certificate. Jump to Step 5.6; Step 5.4: Generate a new random number DR, re-encrypt to generate a new ciphertext EDR, synchronize the new random number DR, the new ciphertext EDR, and the new key KEY (the new key KEY refers to the key KEY in the encryption chip, which is new relative to the cloud platform, not the key newly generated by the encryption chip) to the encryption parameter table of the cloud platform, and at the same time notify the cloud platform that the certificate has expired and a new certificate needs to be issued. Jump to Step 5.6; Step 5.5: The encryption chip of the power fault diagnosis device regenerates a new key KEY, reads the new key KEY, generates a new random number DR, re-encrypts the generated new ciphertext EDR, synchronizes the new random number DR, new ciphertext EDR, and new key KEY to the encryption parameter table of the cloud platform, and then jumps to step 5.6; Step 5.6: Encryption initialization completed.
[0030] The encryption parameter header format of the cloud platform is as follows: Table 1 Cloud platform encryption parameter header SN UID CID KEY DR EDR CEF SN: represents the device number, which is composed of UID and CID. It is consistent with the device and synchronized with online registration. If the CID changes, the SN will also be updated and a new encryption parameter table will be created. UID: represents the unique number of the online device CPU; CID: indicates the communication module number of the online device; KEY: Chip encryption key after maintenance, automatically filled and updated after the device is online; DR: Cloud platform random number, used for two-way verification; EDR: Cloud platform random number ciphertext, used for two-way verification; CEF: Cloud platform key generation flag. 0xAABB indicates the key has been generated, and other values indicate it has not been generated. This flag is used by the dual-end detection mechanism.
[0031] The encrypted parameter header format of the power fault diagnosis device is as follows: Table 2 Encrypted parameter header of power fault diagnosis device SN UID CID KEY LEF SN: indicates the device number, which is composed of UID and CID. UID: represents the unique number of the central processing unit; CID: indicates the current communication module number; KEY: Device encryption chip key, synchronized to the cloud platform after the device is online, and synchronized to the maintenance mapping table after maintenance; LEF: Device local key generation flag, 0xAABB means the key has been generated, other values mean it has not been generated, used by the dual-end detection mechanism.
[0032] If both the communication module and the memory are damaged, and the LEF and CEF readings are both 0, through the dual - end detection mechanism, the encryption chip will regenerate a key and re - issue the certificate again. However, the actual encryption chip is not damaged, which is a misoperation. To address this issue, considering the communication module ID CID, which can be obtained not only through instruction interaction but also through silk - screening or barcode scanning, the cloud platform adds a maintenance mapping table to establish an association between the CID of the communication module after maintenance (new version) and the OCID of the communication module before maintenance (old version). (Here, the maintenance personnel need to update and add it. This is mainly because the power failure diagnosis device is uncertain when or whether it has been maintained, so various numbers cannot be automatically synchronized to the maintenance mapping table and can only be updated by the maintenance personnel. The update method can be manual input of information or the cloud platform adding a button for one - key import.) Through the OCID, historical encryption parameters can be extracted, and then according to the two - way verification mechanism, if the keys are consistent, there is no need to generate a key again, but the LEF and CEF need to be updated to 0xAABB and synchronized to the memory and the cloud platform respectively.
[0033] The header format of the maintenance mapping table is as follows: Table 1 Maintenance Mapping Table Header SN CID OCID SID UID KEY Among them, SN: represents the device number after maintenance, which is composed of UID and CID spliced together; CID: represents the communication module number after maintenance; OCID: represents the communication module number before maintenance, which is used to index historical encryption parameters; SID: represents the memory number, which can be obtained through silk - screening; UID: represents the unique number of the central processing unit, which is automatically filled and updated after the device goes online; KEY: the encryption chip key after maintenance, which is automatically filled and updated after the device goes online; The maintenance mapping table is not only used for the device to extract historical encryption parameters but also for recording the device maintenance history, which has a certain auxiliary effect on the tracking and analysis of batch device problems, facilitating quick problem location and improving work efficiency.
[0034] The implementation process of the maintenance mapping table is as Figure 5 shown, which is used to associate new and old devices, obtain old - version encryption parameters, and is a supplementary revision to the dual - end detection mechanism.
[0035] In the second aspect, the embodiment of the present application provides an encryption startup system for a power failure diagnosis device, including: The first processing module is used to determine whether the power failure diagnosis device is connected to the cloud platform; A second processing module, configured to generate a local key generation flag LEF of the power failure diagnosis device and a cloud key generation flag CEF of the cloud platform according to local keys, perform double - end detection between the power failure diagnosis device and the cloud platform, and determine whether the encryption chip of the power failure diagnosis device needs to regenerate keys; A third processing module, configured to traverse the maintenance mapping table of the power failure diagnosis device and determine whether the maintenance mapping table is empty; A fourth processing module, configured to obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therein, and perform two - way verification between the power failure diagnosis device and the cloud platform according to the extracted historical encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate keys; A fifth processing module, configured to obtain the encryption parameter table of the cloud platform and the encryption parameter table of the power failure diagnosis device, extract the encryption parameters therein, and perform two - way verification between the power failure diagnosis device and the cloud platform according to the extracted encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate keys; A sixth processing module, configured to cause the encryption chip to regenerate keys when the fourth processing module and the fifth processing module determine that key regeneration is required; A seventh processing module, configured to synchronously update the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform when the fourth processing module and the fifth processing module determine that key regeneration is not required, and after the encryption chip regenerates keys; An eighth processing module, configured to complete encryption initialization.
[0036] It should be noted that the system embodiment is similar to the method embodiment, so the description is relatively simple. For related parts, refer to the method embodiment.
[0037] The embodiment of the present application further provides an electronic device, including: a memory and a processor, where the memory and the processor are communicatively connected through a bus, and a computer program is stored in the memory. The computer program can run on the processor, thereby implementing the steps in the power failure diagnosis device encryption startup method disclosed in the embodiment of the present application.
[0038] The embodiment of the present application further provides a computer - readable storage medium, on which a computer program / instructions are stored. It is characterized in that when the computer program / instructions are executed by a processor, the steps in the power failure diagnosis device encryption startup method disclosed in the embodiment of the present application are implemented.
[0039] The embodiments of the present application further provide a computer program product, including computer programs / instructions, which, when executed by a processor, implement the steps in the power failure diagnosis device encryption startup method disclosed in the embodiments of the present application.
[0040] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0041] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the embodiments of the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0042] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, systems, storage media, and program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the specified functions in one Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0043] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that it is still possible to modify the specific implementation manners of the present invention or perform equivalent replacements for some technical features. Without departing from the spirit of the technical solutions of the present invention, they should all be covered within the scope of the technical solutions claimed by the present invention.
Claims
1. A method for encrypting and starting a power failure diagnosis device, characterized in that, It includes the following steps: Step 1: Determine whether the power failure diagnosis device is connected to the cloud platform. If so, proceed to the next step; otherwise, continue to determine; Step 2: Generate the local key generation flag LEF of the power failure diagnosis device and the cloud key generation flag CEF of the cloud platform. The power failure diagnosis device and the cloud platform perform double - end detection to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to the next step; otherwise, proceed to Step 5; Step 3: Traverse whether the maintenance mapping table of the power failure diagnosis device is empty. If it is not empty, proceed to the next step; if it is empty, proceed to Step 6; Step 4: Obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therein, and based on the extracted historical encryption parameters, the power failure diagnosis device and the cloud platform perform two - way verification to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to Step 6; otherwise, proceed to Step 7; Step 5: Obtain the encryption parameter table of the cloud platform and the encryption parameter table of the power failure diagnosis device, extract the encryption parameters therein, and based on the extracted encryption parameters, the power failure diagnosis device and the cloud platform perform two - way verification to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key. If so, proceed to Step 6; otherwise, proceed to Step 7; Step 6: The encryption chip of the power failure diagnosis device regenerates the key; Step 7: The power failure diagnosis device synchronously updates the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform; Step 8: The encryption initialization is completed.
2. The power failure diagnosis device encryption startup method according to claim 1, characterized in that The method for the power failure diagnosis device and the cloud platform to perform double - end detection is as follows: After the power failure diagnosis device is powered on, read the local key generation flag LEF of the power failure diagnosis device. After waiting for the power failure diagnosis device to connect to the cloud platform, then read the cloud key generation flag CEF of the cloud platform; Determine whether the power failure diagnosis device needs to regenerate the key: (1) If it is determined that both LEF and CEF are 0xAABB, it means the key has been generated and has been synchronized to the cloud platform, and there is no need to regenerate; (2) If it is determined that LEF is 0xAABB and CEF is 0xFFFF, it means the key has been generated and there is no need to regenerate; however, since the device number of the power failure diagnosis device has been modified and the cloud platform has not been synchronized, set CEF to 0xAABB and synchronize it to the cloud platform; (3) If it is determined that LEF is 0xFFFF and CEF is 0xAABB, it means the key has been generated and there is no need to regenerate; however, since the maintenance of the power failure diagnosis device causes LEF to be 0xFFFF, set LEF to 0xAABB and synchronize it to the encryption parameter table of the power failure diagnosis device; (4) If it is determined that both LEF and CEF are 0xFFFF, it means the key has not been generated and needs to be regenerated; send a key generation instruction to the encryption chip of the power failure diagnosis device. After confirming the key generation, update both LEF and CEF to 0xAABB and synchronize them to the encryption parameter tables of the power failure diagnosis device and the cloud platform respectively.
3. The encryption startup method of the power failure diagnosis device according to claim 1, characterized in that: A maintenance mapping table is used to extract historical encryption parameters and record the device maintenance history, including the device serial number SN after maintenance, the communication module serial number CID after maintenance, the original communication module serial number OCID before maintenance, the memory serial number SID, the central processor serial number UID, and the key KEY.
4. The power failure diagnosis device encryption startup method according to claim 1, characterized in that The method for the two-way verification between the power failure diagnosis device and the cloud platform is as follows: Step 5.1: Read the key KEY in the encryption parameter table of the cloud platform and compare it with the key LKEY in the encryption parameter table of the power failure diagnosis device; If they are the same, it means that the key KEY of the power failure diagnosis device has not been modified, the issued certificate is available, and jump to step 5.6; If they are different, jump to step 5.2; Step 5.2: Read the random number DR and the ciphertext EDR of the random number DR in the encryption parameter table of the cloud platform, and call the encryption chip of the power failure diagnosis device to perform two-way verification of encryption and decryption; If the encryption and decryption operations fail, it means that the key KEY of the power failure diagnosis device is unavailable, and jump to step 5.5; If the encryption and decryption operations are successful, obtain the ciphertext LEDR after local encryption of the random number DR and the random number LDR after local decryption of the ciphertext EDR of the random number DR; Compare the random number DR with the random number LDR, and the ciphertext EDR with the ciphertext LEDR; If they match, the key KEY of the power failure diagnosis device has not been modified, the issued certificate is available, but the key KEY has not been synchronized to the cloud platform, and jump to step 5.3; If they are inconsistent, it means that there is a key KEY inside the power failure diagnosis device, but the key KEY has been modified, and jump to step 5.4; Step 5.3: Synchronize the key KEY to the encryption parameter table of the cloud platform, no need to issue a certificate again, and jump to step 5.6; Step 5.4: Generate a new random number DR, re-encrypt to generate a new ciphertext EDR, synchronize the new random number DR, the new ciphertext EDR, and the new key KEY to the encryption parameter table of the cloud platform, and at the same time notify the cloud platform that the certificate has expired and a new certificate needs to be issued, and jump to step 5.6; Step 5.5: The encryption chip of the power failure diagnosis device regenerates a new key KEY, reads the new key KEY, generates a new random number DR, re-encrypts to generate a new ciphertext EDR, and synchronizes the new random number DR, the new ciphertext EDR, and the new key KEY to the encryption parameter table of the cloud platform, and jump to step 5.6; Step 5.6: The encryption initialization is completed.
5. A power failure diagnosis device encryption startup system, characterized in that, Including: The first processing module is used to judge whether the power failure diagnosis device is connected to the cloud platform; The second processing module is used to generate a local key generation flag LEF of the power failure diagnosis device and a cloud key generation flag CEF of the cloud platform, perform two-end detection between the power failure diagnosis device and the cloud platform, and judge whether the encryption chip of the power failure diagnosis device needs to regenerate the key; The third processing module is used to traverse the maintenance mapping table of the power failure diagnosis device and judge whether the maintenance mapping table is empty; The fourth processing module is used to obtain the maintenance mapping table of the cloud platform, the encryption parameter table of the cloud platform, and the encryption parameter table of the power failure diagnosis device, extract the historical encryption parameters therefrom, and perform two-way verification between the power failure diagnosis device and the cloud platform based on the extracted historical encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key; The fifth processing module is used to obtain the encryption parameter table of the cloud platform and the encryption parameter table of the power failure diagnosis device, extract the encryption parameters therefrom, and perform two-way verification between the power failure diagnosis device and the cloud platform based on the extracted encryption parameters to determine whether the encryption chip of the power failure diagnosis device needs to regenerate the key; The sixth processing module is used to cause the encryption chip to regenerate the key when the fourth processing module and the fifth processing module determine that the key needs to be regenerated; The seventh processing module is used to synchronously update the encryption parameters, the local key generation flag LEF, and the cloud key generation flag CEF to the cloud platform when the fourth processing module and the fifth processing module determine that the key does not need to be regenerated, and after the encryption chip regenerates the key; The eighth processing module is used to complete the encryption initialization.
6. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, wherein the processor executes the computer program to implement the power failure diagnosis device encryption startup method according to any one of claims 1 to 4.
7. A computer-readable storage medium having computer programs / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, the power failure diagnosis device encryption startup method according to any one of claims 1 to 4 is implemented.
8. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, the power failure diagnosis device encryption startup method according to any one of claims 1 to 4 is implemented.