Key filling system
Through the key placing system composed of authentication stick and loading terminal, the multi-key verification and information encryption processing are used to solve the problems of low efficiency and insufficient security in the key placing process, and an efficient and secure loading process is achieved.
Patent Information
- Application Number
- CN202510535219.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-08-15
AI Technical Summary
The existing key recharge process is inefficient and insufficient in security, especially in the modern society where the network is rapidly developing, it is difficult to meet the needs of rapid, stable and secure.
The key placing system consisting of an authentication stick, a placing terminal and a server device is adopted to transmit the first key information through the authentication stick, the placing terminal decrypts and sends the placing data, supporting multiple key verification and information encryption processing to ensure system security.
It improves the security performance of the filling terminal, reduces illegal equipment access, enhances system security, realizes automatic filling, and improves filling efficiency.
Smart Images

Figure CN120499663A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a key injection system. Background Art
[0002] Currently, manual offline security is the main method used in the key injection process. Technicians inject keys into devices manually or with special tools, which is a relatively inefficient method.
[0003] A prior art document (CN100468999C) discloses an encryption key setting system, wherein an encryption key used for encrypting wireless communication data transmitted by radio between an access point and a terminal having a device for connecting to a wireless local area network is set at the access point and the terminal. The terminal includes: a transmitting unit for transmitting an initialization packet containing information specific to the terminal by radio based on a predetermined command from the terminal; a setting unit for setting the encryption key used for communication with the access point to a predetermined value based on the information specific to the terminal after the transmitting unit transmits the initialization packet and before communicating with the access point; a terminal identifying unit for identifying the terminal that transmitted the initialization packet based on the information specific to the terminal when receiving the initialization packet transmitted from one of the terminals during execution of the restricted reception mode; and an encryption key setting unit for setting the encryption key used for communication with the terminal identified by the identifying unit to a value corresponding to the encryption key set using the information specific to the terminal at the terminal that transmitted the initialization packet before starting subsequent communication with the terminal identified by the identifying unit.
[0004] Currently, in related technologies, only the transmission information is encrypted, ignoring the security of the terminal during the recharging process. Summary of the Invention
[0005] The embodiments of the present application provide a key injection system to at least solve the problem in the related art of how to improve the security of a terminal during the injection process.
[0006] In a first aspect, an embodiment of the present application provides a key injection system, which is connected to a device to be injected and is used to inject data into the device to be injected, including: an authentication stick, an injection terminal, and a server device; wherein,
[0007] The server device is connected to the refueling terminal and is configured to generate refueling data and send the data to the refueling terminal;
[0008] The authentication stick is connected to the refueling terminal and is configured to transmit first key information to the refueling terminal;
[0009] The refueling terminal is also connected to the device to be refueled, and is configured to receive the refueling data and decrypt the refueling data; open the refueling terminal according to the first key information, and send the decrypted refueling data to the device to be refueled after opening.
[0010] Using the first key information of the authentication stick as a link to open the refueling terminal can improve the security performance of the refueling terminal, enhance system security, and prevent illegal equipment from accessing.
[0011] In some embodiments, the refueling terminal includes:
[0012] a communication control module, connected to the server device, and configured to receive and send the filling data;
[0013] an isolation module, connected to the communication control module, configured to receive the filling data, decrypt the filling data, and send it out after processing;
[0014] The main control module is connected to the isolation module and the device to be filled, and is configured to receive the decrypted filling data and send the decrypted filling data to the device to be filled.
[0015] The isolation module decrypts the injected data before sending it out, which can reduce the possibility of the injected data being stolen during transmission.
[0016] In some embodiments, the communication control module further includes a confidentiality unit, and the refueling terminal is further configured to determine whether the status of the confidentiality unit is normal during the opening process of the refueling terminal. If so, the refueling terminal continues to be opened; if not, the refueling terminal re-determines or closes.
[0017] By judging the status of the confidentiality unit, the system can be ensured to start in a safe and stable environment, avoiding security risks caused by abnormalities in the confidentiality unit.
[0018] In some embodiments, the isolation module further includes an authentication stick interface, and the authentication stick further includes a communication interface. The refueling terminal is further configured to determine whether the authentication stick interface and the communication interface are connected during the startup of the refueling terminal. If so, the first key information in the authentication stick is obtained, and the refueling terminal configures an interactive page. If not, the refueling terminal is re-judged or closed.
[0019] Only when the authentication stick is connected normally can the first key information be obtained for power-on authentication of the refueling terminal, further increasing the security of the system.
[0020] In some embodiments, the refueling terminal is further configured to obtain a network access mode from the interactive page, configure communication channel parameter information and IP information according to the network access mode, and interact with the server device according to the communication channel parameter information and the IP information.
[0021] The system supports multiple network access modes, can adapt to different network environments, and expands its scope of application.
[0022] In some embodiments, the refueling terminal is further configured to obtain user information and password from the interactive page, perform network-side authentication based on the user information and the password, and if the authentication is successful, obtain second key information from the network side, and the refueling terminal interacts with the device to be refueled. If the authentication fails, the refueling terminal re-performs network-side authentication or is shut down.
[0023] The obtained second key information is subsequently used to open the refueling terminal, further enhancing the security performance of the system.
[0024] In some embodiments, the refueling terminal has a built-in third key information, and the refueling terminal is further configured to perform combined verification based on the first key information, the second key information and the third key information. If the combined verification passes, the refueling terminal performs refueling; if the combined verification fails, the refueling terminal re-performs combined verification or closes.
[0025] Through the combined verification of triple key information, the system security performance is greatly improved and the occurrence of illegal injection is reduced.
[0026] In some embodiments, the main control unit is further configured to obtain request information from the device to be refueled and send it to the isolation module; the isolation module is further configured to receive the request information and encrypt the request information, and send it to the communication control module after encryption; the communication control module is further configured to send the encrypted request information to the server device.
[0027] Information feedback is realized between the device to be filled and the server device, so that the server device can adjust the filling data according to the request information.
[0028] In some embodiments, the refueling terminal further comprises:
[0029] A filling interface, connected to the device to be filled;
[0030] A filling cable, connecting the filling interface and the device to be filled, with multiple built-in channels adapted to various types of communication protocols;
[0031] The switch matrix is configured to control the filling interface to connect to at least one path in the filling cable according to the filling data, and send the filling data to the device to be filled.
[0032] Multiple paths adapted to different communication protocols are configured in the filling cable, which can meet the communication needs of different devices to be filled during the information transmission process.
[0033] In some embodiments, the refueling terminal further comprises:
[0034] The destruction module is configured to power off the refilling terminal and destroy the information in the refilling terminal when the key refilling system is in an abnormal state.
[0035] When the key injection system is in an abnormal state, information can be destroyed in time to prevent important data leakage.
[0036] Compared with related technologies, the key refilling system provided in the embodiment of the present application optimizes the startup process and refilling process of the refilling terminal, reduces manual refilling operations, realizes automated refilling, and improves refilling efficiency.
[0037] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0039] Figure 1 is a structural block diagram of a key injection system according to an embodiment of the present application;
[0040] Figure 2 is a structural block diagram of a key injection system according to an embodiment of the present application;
[0041] Figure 3 is a flow chart of a method for opening a filling terminal according to an embodiment of the present application;
[0042] Figure 4 This is a structural diagram of a refueling cable in a key refueling system according to an embodiment of the present application.
[0043] In the figure: 101, server device; 102, filling terminal; 103, authentication stick; 104, device to be filled; 201, main control unit; 202, isolation unit; 203, communication control unit. DETAILED DESCRIPTION
[0044] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is described and illustrated below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely used to explain this application and are not intended to limit this application. Based on the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without making any creative efforts are within the scope of protection of this application.
[0045] Obviously, the drawings described below are merely examples or embodiments of the present application. Those skilled in the art can, without inventive effort, apply the present application to other similar scenarios based on these drawings. Furthermore, it is also understood that, although the effort involved in such a development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, changes in design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as an insufficiency of the content disclosed in this application.
[0046] References to "embodiments" in this application mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it refer to independent or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described in this application may be combined with other embodiments unless there is a conflict.
[0047] Unless otherwise defined, the technical or scientific terms used in this application should have the ordinary meaning understood by a person of ordinary skill in the technical field to which this application belongs. The words "one", "a", "the" and the like used in this application do not indicate a limit on quantity and may indicate the singular or plural. The terms "include", "comprise", "have" and any variations thereof used in this application are intended to cover non-exclusive inclusions; for example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units that are not listed, or may also include other steps or units that are inherent to these processes, methods, products or devices. The words "connect", "connected", "coupled" and the like used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The word "multiple" used in this application refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can mean: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0048] The commonly used key injection methods in the existing technology are mainly manual offline security methods. Technicians use manual or special tools to inject keys into the equipment. This security efficiency cannot meet the needs of certain special scenarios, such as emergency project needs. Secondly, the injection interface standards of various devices are not unified, and the equipment that needs to be injected is widely distributed and scattered, which increases the difficulty of key injection security. In addition, the use of manual offline injection is prone to the risk of key loss and leakage. In the modern society with rapidly developing networks and the pursuit of speed, stability and security, the above-mentioned key injection methods have long been unable to meet the needs.
[0049] To solve the above problems, this embodiment provides a key injection system. Figure 1 is a structural block diagram of a key injection system according to an embodiment of the present application, such as Figure 1 As shown, the system is connected to the device to be filled 104 and is used to fill data into the device to be filled 104 , and includes: an authentication stick 103 , a filling terminal 102 and a server device 101 .
[0050] The server device 101 is connected to the refueling terminal 102 and is configured to generate refueling data and send the data to the refueling terminal 102 .
[0051] The filling data is a noun, and the filling data includes but is not limited to: data sent to the device to be filled 104 by the server device 101 and resource data that needs to be injected into the device to be filled 104 actively obtained by the user.
[0052] The authentication stick 103 is connected to the refueling terminal 102 and is configured to transmit first key information to the refueling terminal 102 .
[0053] The refueling terminal 102 is also connected to the device to be refueled 104 and is configured to receive refueling data, decrypt the refueling data, open the refueling terminal 102 according to the first key information, and send the decrypted refueling data to the device to be refueled 104 after opening.
[0054] After receiving the first key information, the filling terminal 102 calls the dedicated shared object library interface for verification. If the verification is successful, the filling terminal 102 can be successfully opened.
[0055] Server device 101 generates the refueling data required by device 104 to be refueled over the network and sends it to refueling terminal 102. After further verifying the security and confidentiality of the current environment using authentication wand 103, refueling terminal 102 transmits the refueling data to device 104 to be refueled. Using the first key information from authentication wand 103 as a step in unlocking refueling terminal 102 improves the security of refueling terminal 102, enhances system security, and prevents unauthorized access.
[0056] In some embodiments, such as Figure 2 As shown, the filling terminal 102 includes:
[0057] The communication control module 203 is connected to the server device 101 and is configured to receive and send the filling data;
[0058] The isolation module 202 is connected to the communication control module 203 and is configured to receive the injection data, decrypt the injection data, and send it out after processing;
[0059] The main control module 201 is connected to the isolation module 202 and the device to be refilled 104 , and is configured to receive the decrypted refilling data and send the decrypted refilling data to the device to be refilled 104 .
[0060] The refueling terminal 102 is divided into various modules: the communication control module 203, the isolation module 202, and the main control module 201. This clearly divides the work, improving the efficiency and accuracy of data processing. The isolation module 202 decrypts the refueling data before sending it, which can reduce the possibility of the refueling data being stolen during transmission.
[0061] The main control module 201 includes but is not limited to: a main control processor, a touch screen interface, a key interface, and a charging management unit.
[0062] The main control processor is used for data processing, coordination and control of the operation of the main control module.
[0063] The touch screen interface is used to connect a touch screen to achieve human-computer interaction.
[0064] The key interface is used to connect external keys to provide users with another form of operation and transmit user needs through keys.
[0065] The charge management unit is used to manage the battery that supplies power to ensure that the battery can operate safely.
[0066] The isolation module 202 includes but is not limited to: an isolation processor, an FPGA, a random number chip, and a micro-electric protection SRAM.
[0067] The isolated processor is used to manage functions such as filtering and forwarding of the channel serial port (SPI) protocol, power-on authentication channel, device management control, and security management configuration.
[0068] The FPGA collects random numbers from the random number chip for dedicated processing, enabling encryption and decryption of non-bypassable business data between the main control unit and the communication control unit.
[0069] The micro-electric protection SRAM stores some system startup files of the isolation module 202, which can be destroyed by power-off in an emergency.
[0070] The isolation module 202 is connected to the main control module 201 and the communication control module 203 and is used to perform encryption and decryption processing during the transmission of the refueling data.
[0071] The communication control module 203 includes but is not limited to: a communication control processor, a 4G communication module, a network port chip, and a PSTN communication module.
[0072] The communication control processor is used to manage the information transmission process and process, analyze and forward the transmitted data.
[0073] The 4G communication module is used to connect to the 4G mobile communication network for data transmission and communication.
[0074] The network port chip is used to connect to the Ethernet network and can send and receive signals or data.
[0075] The PSTN communication module is used to communicate through telephone lines and realize low-speed data transmission.
[0076] When the filling terminal 102 receives data, the data obtained through the communication control module 203 is encrypted data, which is decrypted by the isolation module 202 and then transmitted to the main control module 201 for processing.
[0077] During the data transmission process, the encryption terminal exchanges data with the server device 101 . The data sent by the main control module 201 is encrypted by the isolation module 202 and then sent to the server device 101 through the communication control unit.
[0078] In some embodiments, the communication control module 203 also includes a confidentiality unit, and the refueling terminal 102 is further configured to determine whether the status of the confidentiality unit is normal during the startup of the refueling terminal 102. If so, the refueling terminal 102 continues to be turned on; if not, the refueling terminal 102 re-determines or closes.
[0079] During the startup process of refueling terminal 102, the security unit status is assessed. If the security unit is operating normally, the system continues to boot. This ensures that the system boots up in a safe and stable environment, avoiding security risks caused by security unit anomalies. By reassessing or shutting down refueling terminal 102 in the event of an anomaly, it facilitates the identification and resolution of potential safety hazards, improving maintenance efficiency.
[0080] In some embodiments, the isolation module 202 also includes an authentication stick 103 interface, and the authentication stick 103 also includes a communication interface. The refueling terminal 102 is further configured to determine whether the authentication stick 103 interface and the communication interface are connected during the startup of the refueling terminal 102. If so, the first key information in the authentication stick 103 is obtained, and the refueling terminal 102 configures an interactive page. If not, the refueling terminal 102 re-judges or closes.
[0081] When the refueling terminal 102 starts up, it checks whether the authentication wand 103 interface on the isolation module 202 is connected to the communication interface on the authentication wand 103. If the connection is successful, the system performs a check, queries and retrieves the first key information from the authentication wand 103, and then configures the interactive interface. If the connection fails, the system re-evaluates or closes the system. Only when the authentication wand 103 is properly connected can the first key information be retrieved for power-on authentication of the refueling terminal 102, further enhancing system security. After the connection is successful, the interactive interface is configured to facilitate subsequent human-computer interaction with the user.
[0082] The communication interface of the authentication stick 103 can be set as a bidirectional synchronous serial bus interface, which consists of two signal lines, one is a serial data line (SDA) for transmitting data; the other is a serial clock line (SCL) for synchronizing the clock signal of data transmission.
[0083] The communication interface of the authentication stick 103 may be configured as an air plug.
[0084] In some embodiments, the refueling terminal 102 is further configured to obtain a network access mode from the interactive page, configure communication channel parameter information and IP information according to the network access mode, and interact with the server device 101 according to the communication channel parameter information and IP information.
[0085] The refill terminal 102 obtains the network access mode from the interactive page, configures communication channel parameters and IP information based on this mode, and then uses this information to interact with the server device 101. The system supports multiple network access modes, adapting to different network environments and expanding its applicability. By configuring communication channel parameters and IP information, the accuracy of information interaction with the server device 101 is further improved.
[0086] You can select the current network access mode on the interactive page. Network access modes include but are not limited to 4G, Ethernet, and PSTN networks.
[0087] When 4G is selected as the network access mode, the communication channel parameter information that needs to be further set includes the APN account and password.
[0088] When Ethernet is selected as the network access mode, the communication channel parameter information that needs to be further set includes IP, subnet mask and gateway.
[0089] When the PSTN network is selected as the network access mode, the communication channel parameter information that needs to be further set includes the account number and password.
[0090] After configuring the communication channel parameters, the IP address of the server device 101 is further configured to interact with the server device 101.
[0091] In some embodiments, the refueling terminal 102 is further configured to obtain user information and password from the interactive page, perform network-side authentication based on the user information and password, and if the authentication is successful, obtain the second key information from the network side, and the refueling terminal 102 performs data exchange with the device to be refueled 104; if the authentication fails, the refueling terminal 102 re-authenticates on the network side or is closed.
[0092] Refill terminal 102 obtains user information and password from the interactive page and performs network-side authentication. This network-side authentication ensures that the user who can access the refill data is legitimate. The obtained second key information is subsequently used to activate refill terminal 102, further enhancing system security.
[0093] In some embodiments, the refilling terminal 102 has a built-in third key information, and the refilling terminal 102 is further configured to perform a combined verification based on the first key information, the second key information, and the third key information. If the combined verification passes, the refilling terminal 102 performs refilling; if the combined verification fails, the refilling terminal 102 re-performs a combined verification or is closed.
[0094] The refill terminal 102 performs combined verification on the first key information, the second key information and the third key information by calling a dedicated shared object library interface. The combined verification method includes but is not limited to: identity authentication, data integrity verification and authority verification.
[0095] The key information includes the account, password and token. It verifies whether the account and password are consistent, then communicates with the external server and performs secondary verification based on the token.
[0096] You can also use hash value verification to decrypt the key information, obtain the actual hash value, compare the actual hash value with the expected hash value, and determine whether they are consistent. If they are consistent, the verification is successful.
[0097] The key information can also be used to determine whether the user has the right to add annotations, and to determine the user's identity information and the role to which he or she belongs.
[0098] The authentication wand 103, the network, and the refill terminal 102 each obtain corresponding key information for combined verification, ensuring security and reliability across the network environment, transmission path, and data reception. This triple key information combined verification significantly improves system security and reduces the risk of illegal refills.
[0099] If the combination verification passes, you can enter the application homepage of the filling terminal 102 to fill data. If the combination verification fails, the interactive page will display the failure result, and you can choose to re-verify or close the filling terminal 102.
[0100] In some embodiments, the main control unit is further configured to obtain request information from the device to be refueled 104 and send it to the isolation module 202. The isolation module 202 is further configured to receive the request information, encrypt the request information, and send the encrypted request information to the communication control module 203. The communication control module 203 is further configured to send the encrypted request information to the server device 101.
[0101] When the device 104 to be refueled transmits information to the server 101 via the refueling terminal 102, the isolation module 202 encrypts the information to be transmitted before sending it to the server 101. This enables information feedback between the device 104 to be refueled and the server 101, allowing the server 101 to adjust the refueling data based on the requested information. Encrypting the refueling information also ensures the security of information transmission.
[0102] In some embodiments, the refueling terminal 102 further includes:
[0103] The filling interface is connected to the device 104 to be filled.
[0104] The filling cable connects the filling interface and the device to be filled 104, and has multiple built-in channels that are compatible with various types of communication protocols.
[0105] The switch matrix is configured to control the filling interface to connect to at least one path in the filling cable according to the filling data, and send the filling data to the device to be filled 104.
[0106] Multiple paths adapted to different communication protocols are configured within the refueling cable to meet the communication needs of different refueling devices 104 during information transmission. The switch matrix can flexibly select paths based on refueling data, improving the flexibility and efficiency of data transmission.
[0107] Filling cable structure Figure 4 As shown, the traditional multiple cables are optimized into one filling cable, the passage structure is optimized, and the filling operation is simplified.
[0108] The refueling terminal 102 is compatible with various transmission interfaces of the device 104 to be refueled, and supports automatic identification of the transmission interface of the device 104 to be refueled. The refueling terminal 102 supports multiple refueling interface protocols. Before refueling, it determines the specific interface to be used by the device 104 to be refueled, such as RS232, TTL, or RS422 / 485, based on refueling information sent from the network. The refueling terminal 102 has an integrated switch matrix, and refueling is performed using dedicated refueling cables, which automatically adapt to the cable connection through the switch matrix.
[0109] In some embodiments, the refueling terminal 102 further includes:
[0110] The destruction module is used to power off the refill terminal 102 and destroy the information in the refill terminal 102 when the key refill system is in an abnormal state.
[0111] In the event that the key injection system is in an abnormal state, information can be destroyed in a timely manner to prevent important data leakage. The injection terminal 102 is powered off to prevent the system from continuing to operate in an abnormal state, reducing potential security risks and protecting system security.
[0112] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0113] This embodiment also provides a method for opening a refill terminal 102 adapted to the key refill system. Figure 3 is a flow chart of a method for opening a filling terminal 102 according to an embodiment of the present application, such as Figure 3As shown, the process includes the following steps:
[0114] Step S301, determine whether the status of the security unit is normal, if normal, proceed to the next step, if abnormal, re-determine or close the filling terminal 102.
[0115] Step S302 , determining whether the connection is established with the authentication stick 103 , if so, configuring an interactive page and obtaining the first key information from the authentication stick 103 , if not, re-determining or closing the refill terminal 102 .
[0116] Step S303 , obtaining the network access mode from the interaction page, configuring the communication channel parameter information and IP information according to the network access mode, and performing information interaction with the server device 101 according to the communication channel parameter information and IP information.
[0117] Step S304: In the interactive page, network-side authentication is performed based on the user information and password. If the authentication is successful, the second key information is obtained. If the authentication fails, network-side authentication is performed again or the refilling terminal 102 is closed.
[0118] Step S305: Obtain the third key information from the refueling terminal 102, and perform combined verification based on the first key information, the second key information, and the third key information. If the combined verification passes, the refueling terminal 102 completes startup and enters the application homepage of the refueling terminal 102. If the combined verification fails, re-combination verification is performed or the refueling terminal 102 is closed.
[0119] Through the above steps, it is possible to ensure that the refueling terminal 102 is started in a safe and stable environment. Multiple key information verification improves the security performance of the refueling terminal 102 and avoids the leakage of important information and illegal device access during the refueling process.
[0120] It should be noted that the steps shown in the above process or the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0121] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0122] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.
Claims
1. A key injection system, connected to a device to be injected, for injecting data into the device to be injected, characterized in that: include: Authentication stick, filling terminal and server equipment; among which, The server device is connected to the refueling terminal and is configured to generate refueling data and send the data to the refueling terminal; The authentication stick is connected to the refueling terminal and is configured to transmit first key information to the refueling terminal; The refueling terminal is also connected to the device to be refueled, and is configured to receive the refueling data and decrypt the refueling data; The refueling terminal is opened according to the first key information, and after opening, the decrypted refueling data is sent to the device to be refueled.
2. The key injection system according to claim 1, characterized in that: The refueling terminal comprises: a communication control module, connected to the server device, and configured to receive and send the filling data; an isolation module, connected to the communication control module, configured to receive the filling data, decrypt the filling data, and send it out after processing; The main control module is connected to the isolation module and the device to be filled, and is configured to receive the decrypted filling data and send the decrypted filling data to the device to be filled.
3. The key injection system according to claim 2, characterized in that: The communication control module also includes a confidentiality unit, and the refueling terminal is further configured to determine whether the status of the confidentiality unit is normal during the opening process of the refueling terminal. If so, the refueling terminal continues to be opened; if not, the refueling terminal re-determines or closes.
4. The key injection system according to claim 2, characterized in that: The isolation module also includes an authentication stick interface, and the authentication stick also includes a communication interface. The refueling terminal is further configured to determine whether the authentication stick interface and the communication interface are connected during the refueling terminal startup process. If so, the first key information in the authentication stick is obtained, and the refueling terminal configures an interactive page. If not, the refueling terminal is re-judged or closed.
5. The key injection system according to claim 4, characterized in that: The refueling terminal is further configured to obtain a network access mode from the interactive page, configure communication channel parameter information and IP information according to the network access mode, and interact with the server device according to the communication channel parameter information and the IP information.
6. The key injection system according to claim 4, characterized in that: The refueling terminal is further configured to obtain user information and a password from the interactive page, perform network-side authentication based on the user information and the password, obtain second key information from the network side if the authentication is successful, and perform data exchange between the refueling terminal and the device to be refueled; if the authentication fails, the refueling terminal re-performs network-side authentication or is shut down.
7. The key injection system according to claim 6, characterized in that: The refueling terminal has a built-in third key information, and is further configured to perform combined verification based on the first key information, the second key information, and the third key information. If the combined verification passes, the refueling terminal performs refueling; if the combined verification fails, the refueling terminal re-combines verification or closes.
8. The key injection system according to claim 2, characterized in that: The main control unit is further configured to obtain request information from the device to be refilled and send it to the isolation module; the isolation module is further configured to receive the request information and encrypt the request information, and then send it to the communication control module after encryption; The communication control module is further configured to send the encrypted request information to the server device.
9. The key injection system according to any one of claims 1 to 8, characterized in that: The refueling terminal further comprises: A filling interface, connected to the device to be filled; A filling cable, connecting the filling interface and the device to be filled, with multiple built-in channels adapted to various types of communication protocols; The switch matrix is configured to control the filling interface to connect to at least one path in the filling cable according to the filling data, and send the filling data to the device to be filled.
10. The key injection system according to any one of claims 1 to 8, characterized in that: The refueling terminal further comprises: The destruction module is configured to power off the refilling terminal and destroy the information in the refilling terminal when the key refilling system is in an abnormal state.
Citation Information
Patent Citations
Access point, terminal and encryption key configuration system, method and program
CN100468999C