A control method, system, electronic device and storage medium of a construction machine

By building and verifying a uniquely identified registry in the controller of construction machinery, the problem of users circumventing lockout is solved, achieving higher data security and equipment legitimacy.

CN120614116BActive Publication Date: 2026-07-07SUNWARD INTELLIGENT EQUIP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SUNWARD INTELLIGENT EQUIP CO LTD
Filing Date
2025-07-10
Publication Date
2026-07-07

AI Technical Summary

Technical Problem

Some users have been scraping legitimate data and sending it repeatedly or replacing the verification devices on construction machinery without authorization in order to circumvent the locking of the machinery, leading to data security issues.

Method used

By receiving anti-counterfeiting binding instructions from the IoT platform in the controller of the construction machinery, it determines whether the random number seed is stored in the instruction history list, constructs a registry containing the unique identifiers of the network terminal, controller, and engine, and performs verification. If the verification fails, the device is locked to prevent unauthorized device replacement or data tampering.

Benefits of technology

It effectively prevents attackers from unlocking devices by intercepting and resending commands, improves the data security of construction machinery, and prevents unauthorized device replacement and data tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614116B_ABST
    Figure CN120614116B_ABST
Patent Text Reader

Abstract

The application discloses an engineering machine control method, system, electronic equipment and storage medium, and belongs to the technical field of engineering machines. The engineering machine control method comprises the following steps: receiving an anti-fake binding instruction forwarded by a network terminal; judging whether a first random number seed is stored in an instruction history list; if yes, judging that the anti-fake binding instruction is abnormal, and not responding to the anti-fake binding instruction; if not, storing the first random number seed into the instruction history list, extracting a first identifier from the anti-fake binding instruction, and constructing a registration table comprising the first identifier, a second identifier and a third identifier; sending the registration table to the network terminal, so that the network terminal checks the first identifier in the registration table and returns a first check result to the controller; and if the first check result is failed, locking the engineering machine. The application can improve the data security of the engineering machine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of engineering machinery technology, and in particular to a control method, system, electronic device and storage medium for engineering machinery. Background Technology

[0002] Excavators, pile drivers, rock drilling equipment, and other construction machinery have become indispensable tools in engineering construction due to their powerful operating capabilities and high efficiency. Some users are required to pay fees on schedule after purchasing construction machinery; if a user fails to pay on time, the construction machinery must be locked according to the agreement.

[0003] Currently, some users are attempting to circumvent the locking of construction machinery by repeatedly sending legitimate data or by unauthorized replacement of the machinery's verification devices. These actions not only harm the manufacturers' interests but also easily lead to a series of data security issues.

[0004] Therefore, how to improve the data security of construction machinery is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of this application is to provide a control method, system, electronic device, and storage medium for construction machinery, which can improve the data security of construction machinery.

[0006] To address the aforementioned technical problems, this application provides a control method for construction machinery, applied to a controller of the construction machinery. The construction machinery further includes a network terminal and an engine. The control method for the construction machinery includes:

[0007] The system receives an anti-counterfeiting binding instruction forwarded by the network terminal; wherein the anti-counterfeiting binding instruction is sent from the IoT platform to the network terminal, and the anti-counterfeiting binding instruction contains a first identifier and a first random number seed, wherein the first identifier is a unique identifier of the network terminal stored in the IoT platform;

[0008] Determine whether the first random number seed is stored in the instruction history list;

[0009] If so, the anti-counterfeiting binding instruction is determined to be abnormal, and no response is given to the anti-counterfeiting binding instruction;

[0010] If not, the first random number seed is stored in the instruction history list, and the first identifier is extracted from the anti-counterfeiting binding instruction to construct a registry containing the first identifier, the second identifier, and the third identifier; wherein, the second identifier is the unique identifier of the controller, and the third identifier is the unique identifier of the engine;

[0011] The registry is sent to the network terminal so that the network terminal can verify the first identifier in the registry and return the first verification result to the controller;

[0012] If the first verification result is unsuccessful, the engineering machinery will be locked.

[0013] Optionally, after constructing the registry containing the first identifier, the second identifier, and the third identifier, the following steps are also included:

[0014] The network terminal and / or the engine are verified using the registry stored locally on the controller to obtain a second verification result;

[0015] If the second verification result is unsuccessful, then it is determined whether the controller enables anti-counterfeiting.

[0016] If so, then the engineering machinery will be locked.

[0017] Optionally, the network terminal is verified using the registry stored locally on the controller to obtain a second verification result, including:

[0018] A verification factor is periodically sent to the network terminal so that the network terminal can return a verification key to the controller; wherein the verification key is generated based on the registry stored locally by the network terminal.

[0019] If the verification key does not match the registry stored locally by the controller, a second verification result indicating failure is generated.

[0020] If the controller fails to return the verification key within a preset time, a second verification result indicating failure is generated.

[0021] Optional, also includes:

[0022] The system receives an anti-counterfeiting enable command forwarded by the network terminal; wherein the anti-counterfeiting enable command is sent from the IoT platform to the network terminal, and the anti-counterfeiting binding command includes the first identifier and the second random number seed.

[0023] Determine whether the second random number seed is stored in the instruction history list;

[0024] If so, the anti-counterfeiting enable command is determined to be abnormal, and no response is given to the anti-counterfeiting enable command.

[0025] If not, the second random number seed is stored in the instruction history list, and anti-counterfeiting is enabled;

[0026] The network terminal sends feedback information containing the first identifier to the network terminal, so that the network terminal verifies the first identifier in the feedback information and returns a third verification result to the controller;

[0027] If the third verification result is unsuccessful, the engineering machinery will be locked.

[0028] Optionally, after constructing the registry containing the first identifier, the second identifier, and the third identifier, the following steps are also included:

[0029] The registry key is used to generate a key for a symmetric encryption algorithm.

[0030] If an encrypted instruction is received from the IoT platform, the encrypted instruction is decrypted using the key to obtain a plaintext instruction; wherein the plaintext instruction contains an instruction frame identity identifier, which is generated based on the registry.

[0031] The identity of the instruction frame is verified using the registry stored locally on the controller to obtain a fourth verification result;

[0032] If the fourth verification result is successful, then the operation corresponding to the plaintext instruction is executed.

[0033] Optional, also includes:

[0034] If the current time reaches the preset alarm time, a countdown alarm will be displayed on the screen.

[0035] If the current time reaches the preset locking time, the construction machinery will be locked and a locking alarm will be displayed on the screen; wherein the preset alarm time is earlier than the preset locking time.

[0036] If the user enters the correct unlock password or receives the unlock command issued by the IoT platform, the construction machinery will be unlocked, and a delayed locking operation will be performed to extend the time of one vehicle locking cycle without locking the construction machinery.

[0037] Optional, also includes:

[0038] If an unlock password is received from the user, it is determined whether the unlock password is stored in the password pool and has not been used; wherein, the password pool stores multiple passwords generated based on the unique identifier of the engineering machinery;

[0039] If so, the user's entered unlock password is determined to be correct, and the password usage status of the password pool is updated;

[0040] If not, then determine whether the unlock password is a dynamic password that conforms to the preset verification rules; if the unlock password is a dynamic password that conforms to the preset verification rules, then determine that the unlock password entered by the user is correct; wherein, the dynamic password is generated based on the characteristic information of the engineering machinery.

[0041] This application also provides a control system for construction machinery, applied to the controller of the construction machinery, wherein the construction machinery further includes a network terminal and an engine, and the control system of the construction machinery includes:

[0042] The instruction receiving module is used to receive the anti-counterfeiting binding instruction forwarded by the network terminal; wherein the anti-counterfeiting binding instruction is sent from the Internet of Things platform to the network terminal, and the anti-counterfeiting binding instruction contains a first identifier and a first random number seed, wherein the first identifier is a unique identifier of the network terminal stored in the Internet of Things platform;

[0043] The duplicate detection module is used to determine whether the first random number seed is stored in the instruction history list; if yes, it determines that the anti-counterfeiting binding instruction is abnormal and does not respond to the anti-counterfeiting binding instruction; if no, it stores the first random number seed in the instruction history list, extracts the first identifier from the anti-counterfeiting binding instruction, and constructs a registry containing the first identifier, the second identifier, and the third identifier; wherein, the second identifier is the unique identifier of the controller, and the third identifier is the unique identifier of the engine;

[0044] The verification module is used to send the registry to the network terminal so that the network terminal can verify the first identifier in the registry and return the first verification result to the controller.

[0045] The locking module is used to lock the construction machinery if the first verification result is not passed.

[0046] This application also provides a storage medium on which a computer program is stored, wherein the computer program, when executed, implements the steps of the control method for the above-mentioned engineering machinery.

[0047] This application also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor invokes the computer program in the memory to implement the steps of the above-described control method for engineering machinery.

[0048] This application provides a control method for construction machinery, applied to a controller of the construction machinery, which also includes a network terminal and an engine. An IoT platform can send an anti-counterfeiting binding command to the network terminal. The anti-counterfeiting binding command contains a first identifier of the network terminal and a first random number seed. After the network terminal forwards the anti-counterfeiting binding command to the controller, the controller can determine whether the first random number seed in the anti-counterfeiting binding command is stored in the command history list. If the first random number seed is stored in the command history list, it indicates that the anti-counterfeiting binding command has already been received, and there may be a case of illegal copying of the command by a user. In this case, no response is given to the anti-counterfeiting binding command. In the above process, the controller verifies whether the random number seed in the anti-counterfeiting binding command is repeated by checking the command history list, effectively preventing attackers from unlocking the device by intercepting and resending commands. If the first random number seed is not stored in the command history list, the controller constructs a registry based on the unique identifier of the network terminal, the unique identifier of the controller, and the unique identifier of the engine. The controller sends the registry to the network terminal, which verifies the registry. If the verification fails, the device is locked, effectively preventing unauthorized device replacement or data tampering. Therefore, this application can improve the data security of construction machinery. This application also provides a control system for engineering machinery, a storage medium, and an electronic device, which have the aforementioned beneficial effects, and will not be elaborated further here. Attached Figure Description

[0049] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0050] Figure 1 A flowchart illustrating a control method for engineering machinery provided in an embodiment of this application;

[0051] Figure 2 This is a schematic diagram of the structure of a data security enhancement and control system for engineering machinery provided in an embodiment of this application;

[0052] Figure 3 A schematic diagram illustrating the generation principle of a feature code provided in an embodiment of this application;

[0053] Figure 4 This is a schematic diagram illustrating the data encryption and decryption principle provided in an embodiment of this application;

[0054] Figure 5 A schematic diagram of a data transmission path for engineering machinery provided in an embodiment of this application;

[0055] Figure 6A schematic diagram illustrating the alarm principle of an engineering machine provided in an embodiment of this application;

[0056] Figure 7 This is a schematic diagram of an instruction frame format provided in an embodiment of this application;

[0057] Figure 8 This is a schematic diagram illustrating the process from issuance to execution of an anti-counterfeiting binding instruction provided in an embodiment of this application.

[0058] Figure 9 A schematic diagram illustrating the process from issuance to execution of an anti-counterfeiting enable command provided in an embodiment of this application;

[0059] Figure 10 This is a schematic diagram of an instruction frame format and instruction history list provided in an embodiment of this application;

[0060] Figure 11 A flowchart illustrating the interaction verification process between an in-vehicle networking terminal, a controller, and an engine, provided in an embodiment of this application;

[0061] Figure 12 This is a schematic diagram of the structure of a device anomaly log provided in an embodiment of this application;

[0062] Figure 13 This is a schematic diagram of the control principle of engineering machinery provided in an embodiment of this application;

[0063] Figure 14 A schematic diagram illustrating the alarm and locking process of an engineering machine provided in an embodiment of this application;

[0064] Figure 15 This is a schematic diagram of a car locking software process provided in an embodiment of this application;

[0065] Figure 16 This is a schematic diagram of a password verification principle provided in an embodiment of this application;

[0066] Figure 17 This is a schematic diagram illustrating the implementation principle of an unlocking password pool provided in an embodiment of this application. Detailed Implementation

[0067] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0068] Please see below. Figure 1 , Figure 1 This is a flowchart illustrating a control method for engineering machinery provided in an embodiment of this application.

[0069] Specific steps may include:

[0070] S101: Receive the anti-counterfeiting binding instruction forwarded by the network terminal.

[0071] This embodiment can be applied to the controller of construction machinery, which also includes a network terminal (also known as a vehicle network terminal) and an engine. The network terminal can transmit data with the Internet of Things platform.

[0072] The IoT platform can send anti-counterfeiting binding commands to networked terminals, which can then forward the received commands to the controller. The IoT platform stores a unique identifier (first identifier) ​​for each networked terminal of the construction machinery. The platform generates anti-counterfeiting binding commands by: randomly generating a first random number seed; determining the first identifier of the networked terminal of the construction machinery requiring the command transmission; and constructing an anti-counterfeiting binding command that includes both the first random number seed and the first identifier. All commands sent by the IoT platform to the networked terminals contain a random number seed, and the random number seeds in any two commands sent by the networked terminal are different.

[0073] S102: Determine whether the first random number seed is stored in the instruction history list; if yes, proceed to S103; if no, proceed to S104.

[0074] In this embodiment, the controller can maintain an instruction history list, which stores the random number seeds of all received instructions. If the first random number seed is stored in the instruction history list, it means that the instruction containing the first random number seed (i.e., the anti-counterfeiting binding instruction) has been received; if the first random number seed is not stored in the instruction history list, it means that the instruction containing the first random number seed has not been received.

[0075] S103: Determine that the anti-counterfeiting binding instruction is abnormal, and do not respond to the anti-counterfeiting binding instruction.

[0076] This step relies on the fact that the first random number seed is already stored in the instruction history list. At this point, it can be determined that the anti-counterfeiting binding instruction is abnormal, and no response is given to the instruction, thus ending the process. As a feasible implementation, upon determining that the anti-counterfeiting binding instruction is abnormal, an abnormality alert can be uploaded via a network terminal, or the construction machinery can be directly locked.

[0077] S104: Store the first random number seed in the instruction history list, extract the first identifier from the anti-counterfeiting binding instruction, and construct a registry containing the first identifier, the second identifier, and the third identifier.

[0078] When the controller receives an anti-counterfeiting binding command forwarded by a networked terminal, it first checks whether the first random number seed in the command already exists in the command history list. If the first random number seed already exists in the command history list, it means that the command may have been processed, possibly an attack launched by an attacker by intercepting and retransmitting the command; in this case, the controller will ignore the command to prevent replay attacks. If the first random number seed does not exist in the command history list, it means that the command is a new, unprocessed command; in this case, the controller will store the first random number seed in the command history list for subsequent verification of other commands.

[0079] Based on the premise that the first random number seed does not exist in the instruction history list, the controller can extract the first identifier from the anti-counterfeiting binding instruction. This first identifier is the unique identifier of the networked terminal stored in the IoT platform. The controller can also obtain its own unique identifier, i.e., the second identifier; the controller can also obtain the engine's unique identifier, i.e., the third identifier, by interacting with the engine. Based on obtaining the first, second, and third identifiers, the controller can construct a registry containing the first, second, and third identifiers. The aforementioned unique identifier of the engine can be the unique identifier of the engine's Electronic Control Unit (ECU), i.e., the ECU ID.

[0080] The identification information in the registry is used to verify whether the various key components of the construction machinery belong to the same equipment. Verifying the first identifier in the registry via a network terminal ensures the legitimacy of the network terminal's identity. Binding unique identifiers to the network terminal, controller, and engine prevents unauthorized equipment replacement. If any identifier does not match, the registry verification will fail, and the construction machinery will be locked (also known as vehicle locking).

[0081] S105: The registry is sent to the network terminal so that the network terminal verifies the first identifier in the registry and returns the first verification result to the controller.

[0082] The controller can send a registry containing unique identifiers for the network terminal, controller, and engine to the network terminal, allowing the network terminal to verify the information in the registry. Specifically, the network terminal can verify whether the first identifier in the registry matches the identifier stored locally on the network terminal to ensure the network terminal's identity is legitimate (i.e., meets the requirements). If they match, the first identifier in the registry is legitimate, and a first verification result indicating success can be generated. If they do not match, the first identifier in the registry is invalid, and a first verification result indicating failure can be generated.

[0083] The networked terminal can send the first verification result back to the controller, so that the controller can decide whether to lock the construction machinery based on the first verification result. If the first verification result is successful, it means that the first identifier in the registry is valid, and the controller allows the construction machinery to operate normally.

[0084] The phrase "generated content is a first verification result that passes" means that a first verification result is generated and that the first verification result passes the verification. The phrase "generated content is a first verification result that fails" means that a first verification result is generated and that the first verification result fails the verification.

[0085] S106: If the first verification result is not passed, the engineering machinery is locked.

[0086] In this embodiment, the IoT platform can send an anti-counterfeiting binding command to the networked terminal. This command includes the networked terminal's first identifier and a first random number seed. After the networked terminal forwards the anti-counterfeiting binding command to the controller, the controller can determine whether the first random number seed in the command is stored in the command history list. If the first random number seed is stored in the command history list, it indicates that the anti-counterfeiting binding command has already been received, potentially indicating that a user has illegally copied the command. In this case, no response is given to the anti-counterfeiting binding command. During this process, the controller verifies whether the random number seed in the anti-counterfeiting binding command is repeated by checking the command history list, effectively preventing attackers from unlocking the device by intercepting and resending commands. If the first random number seed is not stored in the command history list, the controller constructs a registry based on the networked terminal's unique identifier, the controller's unique identifier, and the engine's unique identifier. The controller sends the registry to the networked terminal, which verifies the registry. If the verification fails, the device is locked, effectively preventing unauthorized device replacement or data tampering. Therefore, this embodiment improves the data security of construction machinery.

[0087] As for Figure 1As further described in the corresponding embodiment, after the registry is generated, the construction machinery can upload the registry to the Internet of Things (IoT) platform via a network terminal. The IoT platform, the network terminal, and the controller all store the registry. This embodiment can use the locally stored registry to perform periodic verification of the network terminal, and also to perform periodic verification of the engine.

[0088] Specifically, after constructing a registry containing the first identifier, the second identifier, and the third identifier, the registry can be used for verification. The specific process is as follows: the network terminal and / or the engine are verified using the registry stored locally by the controller to obtain a second verification result; if the second verification result is unsuccessful, it is determined whether the controller has enabled anti-counterfeiting; if so (i.e., anti-counterfeiting is enabled), the construction machinery is locked. If the second verification result is successful, verification is performed again after a preset delay.

[0089] During the above process, the controller verifies the identity of the networked terminal and / or engine using the locally stored registry. If the verification fails, meaning the identifier of the networked terminal or engine does not match the record in the registry, the controller further determines whether to enable the anti-counterfeiting function. If anti-counterfeiting is enabled, it indicates that the system is in a strict security mode. In this case, the controller will lock the construction machinery to prevent unauthorized use or replacement, ensuring the safety and legitimacy of the construction machinery. This mechanism effectively prevents unauthorized equipment replacement or data tampering, protecting the normal operation of the construction machinery and the interests of the manufacturer.

[0090] The controller can periodically obtain the engine's unique identifier and determine whether the currently obtained engine's unique identifier matches the third identifier in the registry. If they match, the verification passes; otherwise, a second verification result indicating failure is generated. "Generate a second verification result indicating success" means that a second verification result is generated and that the verification passes. "Generate a second verification result indicating failure" means that a second verification result is generated and that the verification fails.

[0091] Furthermore, this embodiment can verify the network terminal in the following way: periodically sending a verification factor to the network terminal so that the network terminal returns a verification key to the controller; wherein, the verification key is generated based on the registry stored locally by the network terminal; if the verification key does not match the registry stored locally by the controller, a second verification result of failure is generated; if the controller does not return the verification key within a preset time, a second verification result of failure is generated.

[0092] Specifically, the controller can periodically send verification factors to the networked terminal. The verification factor is dynamically generated data used to trigger the networked terminal to generate a verification key. Upon receiving the verification factor, the networked terminal can generate a verification key by combining it with its locally stored registry. After receiving the verification key, the controller compares the verification key with its locally stored registry. If the verification key matches the information in the registry, a successful second verification result is generated; if the verification key does not match the information in the registry, a failed second verification result is generated. After the controller sends the verification factor, a timer can be started to wait for the networked terminal to return the verification key. If the networked terminal does not return the verification key within a preset time (e.g., 30 seconds), the controller considers the networked terminal unresponsive and generates a failed second verification result. This process, through dynamic verification and timeout handling, effectively prevents unauthorized equipment replacement and communication failures, improving the safety and reliability of the construction machinery.

[0093] Furthermore, the IoT platform can control whether the construction machinery activates the anti-counterfeiting enable function. The specific process is as follows: It receives an anti-counterfeiting enable command forwarded by the networked terminal; wherein the anti-counterfeiting enable command is issued by the IoT platform to the networked terminal, and the anti-counterfeiting binding command contains the first identifier and the second random number seed; it determines whether the second random number seed is stored in the command history list; if so, it determines that the anti-counterfeiting enable command is abnormal and does not respond to the anti-counterfeiting enable command; if not, it stores the second random number seed in the command history list and enables anti-counterfeiting; it sends feedback information containing the first identifier to the networked terminal, so that the networked terminal verifies the first identifier in the feedback information and returns a third verification result to the controller; if the third verification result is unsuccessful, it locks the construction machinery. This embodiment effectively prevents replay attacks and illegal device replacement by verifying the random number seed and identifier information, ensuring the safety and legality of the construction machinery.

[0094] As a feasible implementation method, after constructing a registry containing the first identifier, the second identifier, and the third identifier, a key can be generated using the registry to improve the security of data transmission. The specific process is as follows:

[0095] The registry is used to generate a key for a symmetric encryption algorithm. If an encrypted command is received from the IoT platform, the encrypted command is decrypted using the key to obtain a plaintext command. The command frame identity is verified using the registry stored locally on the controller to obtain a fourth verification result. If the fourth verification result is successful, the operation corresponding to the plaintext command is executed. The plaintext command includes a command frame identity, which is generated based on the registry. The encrypted command can be any command other than anti-counterfeiting binding and anti-counterfeiting enabling commands. This scheme effectively prevents command tampering and unauthorized command execution, ensuring the safety and reliability of the construction machinery. In this embodiment, the IoT platform can add a command frame identity identifier to each command sent to the construction machinery. The command frame identity identifier is generated based on the registry. After receiving the command, the controller first verifies the command frame identity identifier. If the verification fails, no response is given to the command; if the verification succeeds, the operation corresponding to the command is executed.

[0096] As a feasible implementation method, the controller of the construction machinery can also achieve timed locking of the construction machinery through the following scheme: if the current time reaches the preset alarm time, a countdown alarm is displayed on the screen; if the current time reaches the preset locking time, the construction machinery is locked, and a locking alarm is displayed on the screen; wherein, the preset alarm time is earlier than the preset locking time; if the unlock password entered by the user is correct or an unlock command is received from the IoT platform, the construction machinery is unlocked, and a delayed locking operation is performed to extend the locking period by one cycle without locking the construction machinery. The above process can extend the locking period by one cycle after the equipment is unlocked, and only one cycle can be extended at a time.

[0097] The above method enables timed locking of construction machinery, ensuring proper locking and unlocking control even in environments without a network connection. This improves the safety and reliability of the machinery and effectively prevents unauthorized use and potential safety risks. Simultaneously, this solution provides users with flexible operation, ensuring normal operation of the equipment under legitimate user control, enhancing management efficiency and user experience. After unlocking, the preset alarm time and preset locking time can be updated to promptly remind users to unlock.

[0098] To achieve an adaptive security strategy, this application further extends this aspect by automatically adjusting the duration of the preset alarm time based on the current network environment (such as network signal strength and whether connected to a trusted network) and operational scenario (such as work area and current time). For example, in areas without network access or in remote locations, the preset alarm time is shortened to remind the user to enter the unlock password as early as possible, preventing losses due to device locking.

[0099] Furthermore, in this embodiment, multiple passwords can be generated based on the unique identifier of the construction machinery, and these passwords can be stored in a password pool. If an unlock password is received from the user, it is determined whether the unlock password is stored in the password pool and has not been used.

[0100] If the unlock password is stored in the password pool and has not been used, then the unlock password entered by the user is determined to be correct, and the password usage status of the password pool is updated.

[0101] If the unlock password is not stored in the password pool or has already been used, it is determined whether the unlock password is a dynamic password that conforms to the preset verification rules; if the unlock password is a dynamic password that conforms to the preset verification rules, it is determined that the unlock password entered by the user is correct; wherein, the dynamic password is generated based on the characteristic information of the engineering machinery.

[0102] The above methods can prevent the reuse of passwords in the password pool, thereby improving device security.

[0103] The process described in the above embodiments is illustrated below through examples in practical applications.

[0104] Construction machinery is generally equipped with unlocking systems that send control commands to onboard terminals via an IoT platform. These terminals then forward the commands to the controller for execution, enabling debt management of the machinery. Some users unable to repay their debts may attempt to keep their machinery unlocked by installing jammers or simulators in the control system, evading remote monitoring by the manufacturer and causing incalculable losses. Construction machinery often operates in uninhabited areas, making the stability and reliability of network signals a critical vulnerability for unlocking systems. In construction environments without network signals, manufacturers are unable to remotely monitor their machinery, leading to problems such as lost equipment and difficulties in unlocking.

[0105] Among related technologies, there are vehicle monitoring methods that use local locking to address the management of claims on construction machinery in environments without network connectivity. However, these technologies have the following drawbacks:

[0106] (1) It is not suitable for use in areas where smartphones and network signals are not widespread. When construction machinery enters uninhabited areas for construction and there is no mobile phone signal, if the vehicle is locked, the unlocking command cannot be sent to the user in time, which will greatly increase the after-sales service cost of construction machinery manufacturers.

[0107] (2) When construction machinery is locked, it can only be unlocked by entering an unlock command locally. The unlock command is sent to the user via a verification code. The user needs to participate in the process. For users who are not familiar with the operation of the vehicle instrument, manual service is still required.

[0108] (3) Locking the vehicle with a fixed locking cycle cannot effectively cover the scenarios in actual use of construction machinery. For example, the locking cycle can be set to a longer cycle for customers with good credit, and a shorter cycle for customers with poor credit. However, the above-mentioned patent has a fixed locking time, which cannot cover the needs of the above scenarios.

[0109] To address the technical problems existing in the aforementioned related technologies, this embodiment provides a data security enhancement and control solution for engineering machinery. Please refer to [link / reference]. Figure 2 , Figure 2 This is a schematic diagram of the structure of a data security enhancement and control system for engineering machinery provided in an embodiment of this application.

[0110] The aforementioned system comprises an IoT platform and an electronic control system. The IoT platform includes an APP (Application) terminal and a WEB (Web) terminal. The electronic control system for the construction machinery includes a display screen, an in-vehicle network terminal, and a controller. The system software functions include data security enhancement and control methods. The data security enhancement process addresses the issue of construction machinery being lost due to unauthorized replacement of the in-vehicle network terminal or controller, as well as the problem of construction machinery not locking due to malicious installation of jammers or simulators that tamper with or simulate bus data. The control methods address the locking and unlocking issues of construction machinery when operating in areas with insufficient or no smartphone and network signal coverage.

[0111] In the data security enhancement solution, the operations performed on the APP side include issuing anti-counterfeiting binding commands; the operations performed on the WEB side include issuing anti-counterfeiting binding commands, registering in the registry, and issuing anti-counterfeiting enable commands; the operations performed on the display screen include issuing anti-counterfeiting binding abnormal vehicle locking alarm prompts and unlocking password input; the operations performed on the vehicle-mounted network terminal include anti-counterfeiting binding, forwarding uplink and downlink enable commands, full lifecycle verification with the controller, and registry packet assembly; the operations performed on the controller include anti-counterfeiting binding, parsing downlink enable commands and encrypting uplink commands, full lifecycle verification of the vehicle-mounted network terminal, and registry packet assembly.

[0112] In the control method, the APP terminal performs the operation of obtaining the unlock password; the WEB terminal performs the operation of issuing unlock commands, querying vehicle lock status, issuing lock enable commands, and configuring controller parameters; the display screen performs the operation of locking alarm prompts, querying basic vehicle information, issuing an alarm for impending vehicle lock, and inputting the unlock password; the vehicle network terminal performs the operation of bidirectional data transmission according to the specified protocol; and the controller performs the operation of downlink command parsing, unlock password verification, uplink operating condition data transmission, and uplink status feedback.

[0113] The data security enhancement solution provided in this embodiment includes the mutual binding of electronic control system components, data encryption, and solutions to problems such as the loss of construction machinery due to the installation of simulators. An unlock password pool is created and generated using the unique identifier of each construction machine, ensuring that different machines have N different and fixed unlock passwords. This pool is stored in the controller using a mapping table, achieving black-box operation of the algorithm module. The control method provided in this embodiment operates throughout the entire lifecycle of the construction machinery without relying on other peripherals of the controller, supporting early unlocking to ensure the customer's construction progress. With the addition of a vehicle-mounted network terminal, the IoT platform can automatically manage receivables.

[0114] The display screen has a factory configuration mode, allowing users to select the control method for the construction machinery at the factory. This allows for the combination of the construction machinery control methods and systems described in this technical solution with other control methods based on actual needs. It can also determine whether the construction machinery needs to be equipped with a vehicle-mounted network terminal. This embodiment allows for factory mode switching via the display screen. Users can configure the locking cycle and imminent locking alarm time via the display screen, and it has the ability to input unlock passwords. The display screen has alarm functions for imminent locking and locking, reminding customers to make timely repayments.

[0115] The controller stores a unique identifier for each device and creates an unlock password pool with N different, fixed passwords based on this identifier. The controller can generate a dynamic unlock password, which is generated using a feature code containing the construction machinery's characteristic information as a calculation factor. This feature code has a certain degree of time-sensitivity and anti-cracking capability. Upon receiving the correct unlock password, the controller can extend the locking period by one cycle, and only one cycle can be extended at a time. The construction machinery's characteristic information includes the machine number, operating hours, unlock type, and unlock algorithm version, which are obfuscated using a specific algorithm to obtain the feature code.

[0116] If the device is not locked beforehand, the unlock password can be used to unlock it in advance, extending the locking cycle by one time based on the current operation time. If the remaining unlock-free time is longer than the locking cycle, further extension is not allowed. If the device is already locked, the unlock password can be used to unlock it, extending the locking cycle by one time.

[0117] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating the generation principle of a feature code provided in an embodiment of this application. The feature code is obtained by processing three sets of engineering machinery feature information (first, second, third, and fourth) using a conversion algorithm. The feature code is one or more character sequences of length N. The feature code can be sent by the controller to a display screen for display.

[0118] The IoT platform features include offline functions for issuing anti-counterfeiting binding, unlocking commands, and control function enable commands. It also allows online configuration of the locking cycle and imminent locking time. All commands sent from the IoT platform to the electronic control system are encrypted. The platform provides imminent locking / locking alerts and can automatically send SMS reminders and unlocking commands based on customer repayment status. It supports online application for unlocking passwords. Furthermore, the platform can send unlocking passwords or commands to the controller for execution offline via Bluetooth, Wi-Fi, or other communication methods through the accompanying app.

[0119] Please see Figure 4 , Figure 4 This is a schematic diagram illustrating the data encryption and decryption principle provided in an embodiment of this application. The operations performed by the IoT platform include creating a key in the registry, generating an instruction frame identification ID (identifier) ​​in the registry, assembling instruction frames, and symmetric encryption of instruction frames. The instruction frames sent by the IoT platform to construction machinery A are in encrypted form, including other data and the instruction frame identification ID; the instruction frames sent by the IoT platform to construction machinery B are also in encrypted form, including other data and the instruction frame identification ID. Due to the existence of the instruction frame identification ID, the two instructions have the same function, but the bus message display is different. The operations performed by the controller include creating a key in the registry, decrypting instruction frames, verifying the instruction frame identification ID, and executing the instruction frame content.

[0120] The vehicle-mounted connected terminal can forward data between the controller and the IoT platform. It supports one or more local area communication methods, such as Bluetooth and Wi-Fi. The vehicle-mounted connected terminal can establish a full lifecycle binding relationship with the controller.

[0121] Please see Figure 5 , Figure 5This is a schematic diagram of a data transmission path for construction machinery provided in an embodiment of this application. There is data interaction between the Internet of Things platform and the vehicle-mounted network terminal of the construction machinery, data interaction between the vehicle-mounted network terminal and the controller, and data interaction between the controller and the engine ECU (Electronic Control Unit).

[0122] The data security enhancement process is used to bind four parts: the Internet of Things platform, the vehicle network terminal, the controller, and the engine ECU.

[0123] This embodiment uses the controller as the core control component of the system. The controller actively verifies the entire lifecycle of the vehicle network terminal and engine ECU. If unauthorized replacement is detected, the controller will lock the vehicle. The IoT platform monitors the legality of the registry. When it detects that the controller or engine ECU is illegitimate, it proactively alerts the construction machinery manufacturer to promptly identify problems and protect the company's interests.

[0124] After powering on, the controller determines whether to bind the vehicle network terminal and engine ECU based on the presence of an "anti-counterfeiting binding" command. Upon completion of binding, registry entries are created in both the controller and the vehicle network terminal. The controller uses these registry entries to verify the legitimacy of the vehicle network terminal and engine ECU. If verification fails, and "anti-counterfeiting enable" is active, the vehicle will be locked, and an alarm will be sent to the vehicle network terminal. The controller can perform full lifecycle legitimacy verification on the vehicle network terminal. This verification requires the registry entry as a seed to generate the verification key. If the registry entries stored in the network terminal and the controller are inconsistent, the verification key returned by the vehicle network terminal to the controller will be incorrect. The controller will then determine that the network terminal is an illegitimate terminal, triggering the vehicle locking logic.

[0125] The aforementioned registry may include: a unique identifier for the vehicle-mounted network terminal, a unique identifier for the controller, and a unique identifier for the engine ECU. A copy of this registry is stored in the IoT platform, the vehicle-mounted network terminal, and the controller.

[0126] Please see Figure 6 , Figure 6 The schematic diagram of the alarm principle of engineering machinery provided in this application embodiment is as follows:

[0127] After the controller is powered on, it checks whether there is an anti-counterfeiting binding instruction;

[0128] If an anti-counterfeiting binding command exists, the unique identifier of the vehicle network terminal and the unique identifier of the engine ECU are obtained, a registry is established, and the registry is returned to the vehicle network terminal.

[0129] If no anti-counterfeiting binding command exists, then determine whether a valid registry already exists.

[0130] If a valid registry already exists, the system will proceed with the normal workflow, periodically verifying the legitimacy of the vehicle network terminal and engine ECU; if the verification is successful, the system will proceed to determine if there is an anti-counterfeiting binding instruction.

[0131] If the verification fails or a valid registry entry is missing, the system checks if anti-counterfeiting is enabled. If it is disabled, an alarm is sent to the vehicle's connected terminal. If enabled, the system locks the vehicle and sends an alarm to the connected terminal. After sending an alarm to the connected terminal, the system checks for the presence of an anti-counterfeiting binding command. In the diagram, "Yes" indicates the presence of the command, and "No" indicates that it is not.

[0132] During the command issuance process, the IoT platform uses variable-length data for issuing anti-counterfeiting binding commands and anti-counterfeiting enable commands. This data contains the unique identifier of the vehicle-mounted connected terminal and a random number seed. After being encrypted using a special algorithm, it is sent to the vehicle-mounted connected terminal and forwarded to the controller for execution. The command frame format is as follows: Figure 7 As shown, Figure 7 This is a schematic diagram of an instruction frame format provided in an embodiment of this application. The instruction frame format includes: a frame header, other data, a unique identifier for the vehicle networking terminal, a random number seed, other data, and a frame trailer.

[0133] Please see Figure 8 , Figure 8 This application provides a schematic diagram illustrating the process of issuing and executing an anti-counterfeiting binding instruction. The specific process is as follows: The IoT platform issues an anti-counterfeiting binding instruction to the vehicle-mounted network terminal, which then forwards the instruction to the controller. The controller performs operations including verifying the instruction's legality, parsing and executing the instruction, obtaining the engine ECU's unique identifier from the engine ECU, forming a registry, and forwarding the registry to the vehicle-mounted network terminal. The controller then forwards the registry to the IoT platform, which registers the registry.

[0134] Please see Figure 9 , Figure 9 This illustration shows the process of issuing and executing an anti-counterfeiting enable command, as provided in this embodiment. The IoT platform issues the anti-counterfeiting enable command, and the vehicle-mounted network terminal forwards the command to the controller. The controller performs operations including verifying the command's validity, parsing and executing the command, enabling / disabling the command, and forwarding the execution result to the vehicle-mounted network terminal. The vehicle-mounted network terminal forwards the execution result to the IoT platform, which then displays the result.

[0135] Currently, there is a situation where construction machinery is lost due to the installation of simulators. After actual sampling and research, the working principle of the simulators is basically to capture legitimate data from the construction machinery bus, copy it, and then periodically send it on the bus.

[0136] In this embodiment, the anti-counterfeiting binding and anti-counterfeiting enabling commands are variable-length data packets. To prevent the commands from being illegally copied, this embodiment adopts the following solution:

[0137] A random number seed is added to each frame of command issued by the IoT platform. This seed is used by the controller to form a command history list. If a newly received command seed already exists in the command history list, it is identified as abnormal, and the command is not executed. Data is encrypted when the IoT platform issues commands, using symmetric encryption algorithms such as AES or DES. The vehicle-mounted IoT terminal verifies the unique identifier of the vehicle-mounted terminal in the anti-counterfeiting binding and anti-counterfeiting enable commands received from the controller. If the verification fails, the controller will encounter an error in verifying the vehicle-mounted network terminal, thereby triggering vehicle locking.

[0138] Please see Figure 10 , Figure 10 This is a schematic diagram of an instruction frame format and instruction history list provided in an embodiment of this application. The instruction frame format includes: frame header, other data, unique identifier of vehicle networking terminal, random number seed (Seed), other data and frame tail; the instruction history list includes random number seeds Seed0, Seed1, Seed2, Seed3, ..., Seedn from the received instructions.

[0139] In this embodiment, the following solution is proposed to address the security concerns of other fixed-length instructions:

[0140] This embodiment designs a symmetric encryption algorithm. The key for this algorithm is generated using the registry as a factor, and the algorithm is deployed in the IoT platform and controller. Since the registry entries for different construction machines are inconsistent, the generated keys are also inconsistent. When the IoT platform sends the same function command frame to different construction machines, the encrypted data exhibits inconsistent behavior on the buses of different construction machines. A new command frame identification ID (identifier) ​​is added to each command frame. This ID is also generated using the registry as a creation factor and serves as a unique identifier for a single construction machine's fixed-length command frame. The command frame identification ID is created by the controller and the IoT platform based on the registry content. Since the registry entry for each device is unique, the command frame identification ID is also unique. When the IoT platform sends a command to the controller, the controller verifies the command frame identification ID. Only if the verification passes is the command considered valid and can be parsed.

[0141] The controller performs full-lifecycle interactive verification between the vehicle network terminal and the engine ECU. If verification fails or verification data is not received within 2 minutes, the vehicle will be locked. The controller periodically sends a verification factor to the vehicle network terminal, which generates a verification key in response based on the verification factor. The generation of this key is related to the registry. If the returned verification key is abnormal (i.e., verification error or no response for a long time), the vehicle will be locked.

[0142] Please see Figure 11 , Figure 11 This is a flowchart illustrating the interaction and verification process between an in-vehicle network terminal, a controller, and an engine, provided in an embodiment of this application. The controller sends a verification factor to the in-vehicle network terminal, the in-vehicle network terminal generates a verification key and replies with the verification key to the controller, and the controller verifies the verification key. The controller can obtain the engine ECU ID and can verify the engine ECU ID.

[0143] The controller internally generates a device anomaly log for any abnormal events that occur. This log can be read externally when necessary via a special protocol, which is helpful for evidence collection in case of disputes. Please refer to [link / reference]. Figure 12 , Figure 12 This is a schematic diagram of the structure of a device anomaly log provided in an embodiment of this application. The device anomaly log may include: the time of the vehicle network terminal anomaly and the engine ECU anomaly, the working hours, the number of anomalies, the incorrect verification key, and the anomaly type.

[0144] The data security enhancement method proposed in this embodiment achieves full lifecycle binding of vehicle-mounted network terminals, controllers, and engine ECUs, effectively eliminating the problems of simulators and illegal replacements on the market, improving the data security of the construction machinery Internet of Things system, and helping to protect the rights and interests of construction machinery manufacturers.

[0145] To implement the engineering machinery control method proposed in this technical solution, the system should include at least one controller and a display screen; the vehicle-mounted network terminal is an optional accessory. Please refer to [link to relevant documentation]. Figure 13 , Figure 13 This is a schematic diagram of the control principle of engineering machinery provided in an embodiment of this application. The controller can perform mode configuration, configure dynamic password, provide unlock password pool and implement control algorithm. The controller can be connected to the vehicle network terminal (optional) and the vehicle display screen respectively.

[0146] In terms of functional design, the control method proposed in this technical solution is independent of other software functions in the controller, and the implementation process is as follows: Figure 14 As shown, Figure 14The diagram below illustrates the alarm and locking process of an engineering machine provided in this application embodiment. The process is as follows: After the equipment starts up, it is determined whether the control method has been activated; if not, other tasks are executed; if activated, the alarm and locking process is performed.

[0147] During the alarm and vehicle locking process, it checks whether the alarm time has been reached. If so, the display module alarms. If the alarm time has not been reached, it checks whether the vehicle locking time has been reached. If so, it performs the vehicle locking operation and controls the display module to alarm. If neither the alarm time nor the vehicle locking time has been reached, it checks whether an on-board network terminal is installed. If so, the alarm time and vehicle locking time are uploaded to the remote monitoring platform. Otherwise, it re-enters the process of checking whether the alarm time has been reached.

[0148] During the alarm and vehicle locking process, if a remote unlock command is received, the vehicle will remain unlocked for one additional locking cycle. If no remote unlock command is received, the system will determine if the user has entered the correct unlock password. If the correct unlock password is entered, the vehicle will remain unlocked for one additional locking cycle. If the correct unlock password is not entered, the system will proceed to determine if the alarm time has been reached.

[0149] When this control method is enabled on the display screen, it will continuously check whether the current working time has reached the preset alarm time and preset locking time. When the preset alarm time is reached, a countdown alarm should be displayed on the screen; when the preset locking time is reached, the vehicle should be locked and a locking alarm should be displayed on the screen. The vehicle will not be locked for another cycle until a correct unlock password is entered or an unlock command is received from the IoT platform.

[0150] When construction machinery is equipped with an onboard network terminal, it automatically uploads the alarm time and locking time to the IoT platform. The IoT platform can analyze the uploaded data and proactively send relevant SMS notifications to customers to remind them to repay their loans. If the customer repays on time, the IoT platform will automatically issue an unlocking command to unlock the vehicle if the onboard terminal is online. The solution provided in this embodiment can also be used for local unlocking by entering an unlocking password on the display screen. If the user has settled their debt, the vehicle can be permanently locked via remote control enable command or permanent password removal.

[0151] Please see Figure 15 , Figure 15This is a schematic diagram of a vehicle locking software process provided in an embodiment of this application. After the software starts, it determines whether the construction machinery is about to reach its locking time. If it is about to reach the locking time, it determines whether the construction machinery is currently online. If the locking time has not yet reached or the construction machinery is currently offline, it can determine again whether the construction machinery is about to reach its locking time. If the construction machinery is currently online, it determines whether the debt has been settled. If it has been settled, it issues a locking function deactivation command and ends the process. If it has not been settled, it determines whether the payment has been made on time. If the payment has been made on time, it issues an unlocking command; if the payment has not been made on time, it sends a collection reminder SMS. After issuing the unlocking command or sending the collection reminder SMS, it can determine again whether the construction machinery is about to reach its locking time.

[0152] The unlock password pool is crucial for enabling construction machinery to unlock normally in offline environments. It is generated from the unique identifier of the machinery using a specific algorithm, and consists of N distinct and fixed passwords. Each password can only be used successfully once, and its usage is stored in memory using a mapping table. The software module only provides the verification status of the currently entered password and the status of the mapping table usage, thus implementing black-box encapsulation and enhancing the confidentiality of the software system during development.

[0153] Please see Figure 16 , Figure 16 This is a schematic diagram of a password verification principle provided in an embodiment of this application. The password unlocking pool is encapsulated in a black box. The password unlocking pool can contain N different passwords. The input parameters of the password unlocking pool can be the unique identifier of the engineering machinery and the password entered by the user. The password unlocking pool can provide password verification status feedback and password pool usage mapping services.

[0154] Please see Figure 17 , Figure 17 This is a schematic diagram illustrating the implementation principle of an unlock password pool provided in this application embodiment. The passwords in the unlock password pool can be used to create N different fixed passwords based on the unique identifier of the engineering machinery and sorted using an algorithm. Password verification status feedback is provided based on the password entered by the user, and the usage status is mapped to a cache. The mapping table can contain multiple status bits (bit0, bit01, bit2, ..., bitN) to store the usage status of the N different fixed passwords.

[0155] The solution proposed in this embodiment allows construction machinery to be configured with relevant parameters at the factory based on actual usage scenarios, enabling the same program to meet the needs of more business scenarios and reducing the difficulty of program version management for enterprises. When construction machinery is equipped with an onboard network terminal, and under good network signal conditions, automated management of vehicle unlocking can be achieved, greatly reducing manual intervention and contributing to cost reduction, efficiency improvement, and standardized management of construction machinery. Even when construction machinery is not equipped with an onboard network terminal or is operating in areas with insufficient smartphone and network signal coverage, the equipment can still achieve timely locking and unlocking. The existence of an advance unlocking mechanism ensures the smooth progress of customer construction. The locking time can be dynamically adjusted to meet the needs of more business scenarios.

[0156] This embodiment can improve the data communication security of the construction machinery Internet of Things system. This embodiment can realize the full life cycle binding between the vehicle-mounted network terminal and the construction machinery. This embodiment provides a solution for effectively locking and quickly unlocking the construction machinery when the vehicle-mounted network terminal is not installed. When working in places such as uninhabited areas where there is no mobile phone signal, this embodiment can effectively ensure the continuity of debt management. This embodiment can meet the needs of multiple usage scenarios, including both those with and without vehicle-mounted network terminals.

[0157] This embodiment achieves four-way binding between the vehicle-mounted network terminal, controller, engine ECU, and IoT platform. All key system command data is encrypted, and the commands are resistant to copying and modification, greatly enhancing the security of the construction machinery IoT system. The control method does not rely on other peripherals of the controller and can operate throughout the entire lifecycle of the construction machinery, or be permanently shut down as needed. It supports early unlocking based on repayment status, ensuring normal construction operations for customers. With an unlocking password pool, it fundamentally solves the problem of difficult locking and unlocking of construction machinery in environments without network connectivity. Furthermore, by adding a vehicle-mounted network terminal and configuring parameters such as lock alarm time and lock cycle, it can meet the needs of various usage scenarios. This embodiment combines the data analysis capabilities of the remote monitoring platform and the communication capabilities of the vehicle-mounted network terminal to achieve systematic and automated debt management, improving reliability and security, and significantly reducing the pressure on enterprises in debt management.

[0158] This application provides a control system for construction machinery, applied to the controller of the construction machinery. The construction machinery further includes a network terminal and an engine. The control system for the construction machinery includes:

[0159] The instruction receiving module is used to receive the anti-counterfeiting binding instruction forwarded by the network terminal; wherein the anti-counterfeiting binding instruction is sent from the Internet of Things platform to the network terminal, and the anti-counterfeiting binding instruction contains a first identifier and a first random number seed, wherein the first identifier is a unique identifier of the network terminal stored in the Internet of Things platform;

[0160] The duplicate detection module is used to determine whether the first random number seed is stored in the instruction history list; if yes, it determines that the anti-counterfeiting binding instruction is abnormal and does not respond to the anti-counterfeiting binding instruction; if no, it stores the first random number seed in the instruction history list, extracts the first identifier from the anti-counterfeiting binding instruction, and constructs a registry containing the first identifier, the second identifier, and the third identifier; wherein, the second identifier is the unique identifier of the controller, and the third identifier is the unique identifier of the engine;

[0161] The verification module is used to send the registry to the network terminal so that the network terminal can verify the first identifier in the registry and return the first verification result to the controller.

[0162] The locking module is used to lock the construction machinery if the first verification result is not passed.

[0163] This embodiment provides a control method for construction machinery, applied to a controller of the construction machinery, which also includes a network terminal and an engine. An IoT platform can send an anti-counterfeiting binding command to the network terminal. This command includes a first identifier of the network terminal and a first random number seed. After the network terminal forwards the anti-counterfeiting binding command to the controller, the controller can determine whether the first random number seed in the command is stored in the command history list. If the first random number seed is stored in the command history list, it indicates that the anti-counterfeiting binding command has already been received, and there may be a case of illegal copying of the command by a user. In this case, no response is given to the anti-counterfeiting binding command. During this process, the controller verifies whether the random number seed in the anti-counterfeiting binding command is repeated by checking the command history list, effectively preventing attackers from unlocking the device by intercepting and resending commands. If the first random number seed is not stored in the command history list, the controller constructs a registry based on the unique identifier of the network terminal, the unique identifier of the controller, and the unique identifier of the engine. The controller sends the registry to the network terminal, which verifies the registry. If the verification fails, the device is locked, effectively preventing unauthorized device replacement or data tampering. Therefore, this embodiment can improve the data security of construction machinery.

[0164] Furthermore, the verification module is also used to verify the network terminal and / or the engine using the registry stored locally by the controller to obtain a second verification result; it is also used to determine whether the controller enables anti-counterfeiting if the second verification result is unsuccessful; if so, it locks the construction machinery.

[0165] Furthermore, the process by which the verification module verifies the network terminal using the registry stored locally by the controller includes: periodically sending a verification factor to the network terminal so that the network terminal returns a verification key to the controller; wherein, the verification key is generated based on the registry stored locally by the network terminal; if the verification key does not match the registry stored locally by the controller, a second verification result indicating failure is generated; if the controller fails to return the verification key within a preset time, a second verification result indicating failure is generated.

[0166] Furthermore, it also includes:

[0167] The anti-counterfeiting enable control module is used to receive an anti-counterfeiting enable command forwarded by the network terminal; wherein the anti-counterfeiting enable command is issued by the IoT platform to the network terminal, and the anti-counterfeiting binding command includes the first identifier and the second random number seed; it is also used to determine whether the second random number seed is stored in the command history list; if so, it is determined that the anti-counterfeiting enable command is abnormal and no response is given to the anti-counterfeiting enable command; if not, the second random number seed is stored in the command history list and anti-counterfeiting is enabled; it is also used to send feedback information containing the first identifier to the network terminal, so that the network terminal can verify the first identifier in the feedback information and return a third verification result to the controller; it is also used to lock the construction machinery if the third verification result is unsuccessful.

[0168] Furthermore, it also includes:

[0169] The security management module is used to generate a key for a symmetric encryption algorithm using the registry; it is also used to decrypt an encryption command issued by the IoT platform using the key to obtain a plaintext command; wherein the plaintext command contains a command frame identity identifier, which is generated based on the registry; it is also used to verify the command frame identity identifier using the registry stored locally on the controller to obtain a fourth verification result; and it is also used to execute the operation corresponding to the plaintext command if the fourth verification result is successful.

[0170] Furthermore, it also includes:

[0171] The alarm module is used to display a countdown alarm on the screen if the current time reaches the preset alarm time.

[0172] The locking module is also used to lock the construction machinery if the current time reaches the preset locking time, and to display a locking alarm on the display screen; wherein the preset alarm time is earlier than the preset locking time.

[0173] The unlocking module is used to unlock the construction machinery if the unlocking password entered by the user is correct or if an unlocking command is received from the IoT platform, and to perform a delayed locking operation to extend the time of one locking cycle without locking the construction machinery.

[0174] Furthermore, it also includes:

[0175] The password verification module is used to determine whether, upon receiving an unlock password input by a user, the unlock password is stored in a password pool and has not been used; wherein, the password pool stores multiple passwords generated based on the unique identifier of the construction machinery; if yes, the unlock password input by the user is determined to be correct, and the password usage status of the password pool is updated; if no, it determines whether the unlock password is a dynamic password that conforms to preset verification rules; if the unlock password is a dynamic password that conforms to preset verification rules, the unlock password input by the user is determined to be correct; wherein, the dynamic password is generated based on the characteristic information of the construction machinery.

[0176] Since the embodiments of the system part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the system part, and they will not be repeated here.

[0177] This application also provides a storage medium on which a computer program is stored, which, when executed, can perform the steps provided in the above embodiments. The storage medium may include various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0178] This application also provides an electronic device that may include a memory and a processor. The memory stores a computer program, and when the processor calls the computer program in the memory, it can implement the steps provided in the above embodiments. Of course, the electronic device may also include various network interfaces, power supplies, and other components.

[0179] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.

[0180] It should also be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A control method for engineering machinery, characterized in that, A controller for use in construction machinery, the construction machinery also including a network terminal and an engine, and the control method for the construction machinery includes: The system receives an anti-counterfeiting binding instruction forwarded by the network terminal; wherein the anti-counterfeiting binding instruction is sent from the IoT platform to the network terminal, and the anti-counterfeiting binding instruction contains a first identifier and a first random number seed, wherein the first identifier is a unique identifier of the network terminal stored in the IoT platform; Determine whether the first random number seed is stored in the instruction history list; If so, the anti-counterfeiting binding instruction is determined to be abnormal, and no response is given to the anti-counterfeiting binding instruction; If not, the first random number seed is stored in the instruction history list, and the first identifier is extracted from the anti-counterfeiting binding instruction to construct a registry containing the first identifier, the second identifier, and the third identifier; wherein, the second identifier is the unique identifier of the controller, and the third identifier is the unique identifier of the engine; The registry is sent to the network terminal so that the network terminal can verify the first identifier in the registry and return the first verification result to the controller; If the first verification result is unsuccessful, the engineering machinery will be locked.

2. The control method for engineering machinery according to claim 1, characterized in that, After constructing the registry containing the first identifier, the second identifier, and the third identifier, the process also includes: The network terminal and / or the engine are verified using the registry stored locally on the controller to obtain a second verification result; If the second verification result is unsuccessful, then it is determined whether the controller enables anti-counterfeiting. If so, then the engineering machinery will be locked.

3. The control method for engineering machinery according to claim 2, characterized in that, The network terminal is verified using the registry stored locally on the controller to obtain a second verification result, including: A verification factor is periodically sent to the network terminal so that the network terminal can return a verification key to the controller; wherein the verification key is generated based on the registry stored locally by the network terminal. If the verification key does not match the registry stored locally by the controller, a second verification result indicating failure is generated. If the controller fails to return the verification key within a preset time, a second verification result indicating failure is generated.

4. The control method for engineering machinery according to claim 2, characterized in that, Also includes: The system receives an anti-counterfeiting enable command forwarded by the network terminal; wherein the anti-counterfeiting enable command is sent from the IoT platform to the network terminal, and the anti-counterfeiting binding command includes the first identifier and the second random number seed. Determine whether the second random number seed is stored in the instruction history list; If so, the anti-counterfeiting enable command is determined to be abnormal, and no response is given to the anti-counterfeiting enable command. If not, the second random number seed is stored in the instruction history list, and anti-counterfeiting is enabled; The network terminal sends feedback information containing the first identifier to the network terminal, so that the network terminal verifies the first identifier in the feedback information and returns a third verification result to the controller; If the third verification result is unsuccessful, the engineering machinery will be locked.

5. The control method for engineering machinery according to claim 1, characterized in that, After constructing the registry containing the first identifier, the second identifier, and the third identifier, the process also includes: The registry key is used to generate a key for a symmetric encryption algorithm. If an encrypted instruction is received from the IoT platform, the encrypted instruction is decrypted using the key to obtain a plaintext instruction; wherein the plaintext instruction contains an instruction frame identity identifier, which is generated based on the registry. The identity of the instruction frame is verified using the registry stored locally on the controller to obtain a fourth verification result; If the fourth verification result is successful, then the operation corresponding to the plaintext instruction is executed.

6. The control method for engineering machinery according to claim 1, characterized in that, Also includes: If the current time reaches the preset alarm time, a countdown alarm will be displayed on the screen. If the current time reaches the preset locking time, the construction machinery will be locked and a locking alarm will be displayed on the screen; wherein the preset alarm time is earlier than the preset locking time. If the user enters the correct unlock password or receives the unlock command issued by the IoT platform, the construction machinery will be unlocked, and a delayed locking operation will be performed to extend the time of one vehicle locking cycle without locking the construction machinery.

7. The control method for engineering machinery according to claim 6, characterized in that, Also includes: If an unlock password is received from the user, it is determined whether the unlock password is stored in the password pool and has not been used; wherein, the password pool stores multiple passwords generated based on the unique identifier of the engineering machinery; If so, the user's entered unlock password is determined to be correct, and the password usage status of the password pool is updated; If not, then determine whether the unlock password is a dynamic password that conforms to the preset verification rules; if the unlock password is a dynamic password that conforms to the preset verification rules, then determine that the unlock password entered by the user is correct; wherein, the dynamic password is generated based on the characteristic information of the engineering machinery.

8. A control system for engineering machinery, characterized in that, A controller for use in construction machinery, the construction machinery also including a network terminal and an engine, the control system of the construction machinery including: The instruction receiving module is used to receive the anti-counterfeiting binding instruction forwarded by the network terminal; wherein the anti-counterfeiting binding instruction is sent from the Internet of Things platform to the network terminal, and the anti-counterfeiting binding instruction contains a first identifier and a first random number seed, wherein the first identifier is a unique identifier of the network terminal stored in the Internet of Things platform; The duplicate detection module is used to determine whether the first random number seed is stored in the instruction history list; if yes, it determines that the anti-counterfeiting binding instruction is abnormal and does not respond to the anti-counterfeiting binding instruction; if no, it stores the first random number seed in the instruction history list, extracts the first identifier from the anti-counterfeiting binding instruction, and constructs a registry containing the first identifier, the second identifier, and the third identifier; wherein, the second identifier is the unique identifier of the controller, and the third identifier is the unique identifier of the engine; The verification module is used to send the registry to the network terminal so that the network terminal can verify the first identifier in the registry and return the first verification result to the controller. The locking module is used to lock the construction machinery if the first verification result is not passed.

9. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor, when calling the computer program in the memory, implements the steps of the control method for the engineering machinery as described in any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium stores computer-executable instructions, which, when loaded and executed by a processor, implement the steps of the control method for engineering machinery as described in any one of claims 1 to 7.