End-to-end encryption communication method and system for power load control service communication terminal
The end-to-end encryption method for power load control business communication terminals, which combines software and hardware, solves the problems of communication delay, high cost and complex key management in the existing technology, realizes safe and reliable communication of the power system, and adapts to the needs of different scenarios.
Patent Information
- Application Number
- CN202510770790.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-12
AI Technical Summary
Existing end-to-end encryption technology has problems in power load control business, such as communication delay, high cost, low portability, complex key management and slow encryption speed, which makes it difficult to meet the security and efficiency requirements of the power system.
By combining software and hardware, the authentication center and key management center are used to achieve end-to-end encryption of power load control business communication terminals, dynamically control the key life cycle, and adopt a two-way authentication mechanism and encrypted private network to ensure the security and stability of data during transmission.
It achieves the security and reliability of power load control business communications, reduces the risk of key cracking or leakage, adapts to different communication scenarios, reduces costs, and improves the operational reliability and safety of the power system.
Smart Images

Figure CN120639281A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of communication technology and relates to an end-to-end encrypted communication method and system for a power load control service communication terminal. Background Art
[0002] With economic development and improved living standards, electricity demand continues to grow. Power load management and control are crucial to the reliable operation and stable supply of power systems. The power load control service monitors and controls power system loads, achieving load optimization and improving energy efficiency. This is especially true during peak load periods. Through the load control service, power loads can be rationally managed and effectively controlled, with real-time monitoring and analysis of power loads. This allows for adjustments to power distribution strategies, avoiding grid overloads, ensuring power supply reliability, improving power system efficiency, reducing energy consumption and environmental impact, and enhancing power system flexibility. Therefore, the power load control service places high demands on the security of power data communications.
[0003] End-to-end encryption is currently widely used in instant messaging. It protects communications from being eavesdropped or tampered with, effectively preventing data leaks caused by man-in-the-middle attacks, and significantly improves communication security. Applying end-to-end encryption technology to power load control services can protect power data from attacks and influences during communication, ensuring the security of power data during power load control operations. This significantly improves the efficiency of power system load control and enables the rational allocation and sustainable development of power resources.
[0004] At present, the main methods of end-to-end encryption include encryption using hardware devices, encryption using software, symmetric encryption, asymmetric encryption, etc. However, these schemes have the following disadvantages when used in power systems. 1) Using general hardware devices for end-to-end encryption will lead to efficiency issues such as communication delays and frame jams in large-volume communications. Using powerful hardware devices for end-to-end encryption will be too costly and have low portability and scalability. 2) Using software for end-to-end encryption requires the communicating parties to agree on the key in advance, which has very limited application scenarios, and software encryption is difficult to prevent non-technical attacks. 3) When using symmetric encryption, a unique key unknown to others is required each time data is encrypted, which will result in an excessive number of keys that are difficult to manage. 4) When using asymmetric encryption, complex and large mathematical calculations are required, resulting in slow encryption and decryption speeds, and longer keys are required to ensure its security, which will affect the overall performance of the communication system. Summary of the Invention
[0005] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide an end-to-end encrypted communication method and system for power load control business communication terminals.
[0006] In order to achieve the above object, the present invention adopts the following technical solutions:
[0007] In a first aspect, the present invention provides an end-to-end encrypted communication method for a power load control business communication terminal, comprising: the sending power load control business communication terminal sends the data to be transmitted to the sending encryption terminal; the sending encryption terminal performs authentication registration with the authentication center, and obtains the end-to-end key from the key management center after the authentication registration is successful, and encrypts the data to be transmitted according to the end-to-end key to obtain encrypted data; the sending encryption terminal sends the encrypted data to the receiving encryption terminal through the base station; the receiving encryption terminal performs authentication registration with the authentication center, and obtains the end-to-end key from the key management center after the authentication registration is successful, and decrypts the encrypted data according to the end-to-end key to obtain the data to be transmitted, and sends the data to be transmitted to the receiving power load control business communication terminal.
[0008] Optionally, the authentication registration to the authentication center includes: the encryption terminal generates a request registration signaling and sends it to the base station, the base station responds to the request registration signaling and sends a request signaling to the authentication center, the authentication center generates an authentication parameter in response to the request signaling and sends it to the base station, the base station generates an authentication challenge signaling based on the authentication parameter and the base station identity authentication code and sends it to the encryption terminal, the encryption terminal authenticates the base station based on the authentication challenge signaling, and sends the encryption terminal identity authentication code to the base station after successful authentication, the base station authenticates the encryption terminal based on the encryption terminal identity authentication code, and sends the base station identity confirmation code to the encryption terminal after successful authentication; wherein, the encryption terminal is a sending encryption terminal or a receiving encryption terminal.
[0009] Optionally, the registration request signaling includes the encryption terminal identifier and the power load control service communication terminal identifier of the power load control service communication terminal connected to the encryption terminal.
[0010] Optionally, the sending party encryption terminal sends encrypted data to the receiving party encryption terminal through the base station, including: when the data to be transmitted is a short message, the sending party encryption terminal sends a short message sending request signaling to the base station, the base station sends a short message response signaling to the sending party encryption terminal based on the short message sending request signaling, the sending party encryption terminal sends encrypted data to the base station based on the short message response signaling, the base station receives the encrypted data and feeds back a reception confirmation signaling to the sending party encryption terminal, and sends the encrypted data to the receiving party encryption terminal.
[0011] Optionally, sending the encrypted data to the receiving encryption terminal includes: sending the encrypted data to the receiving encryption terminal in a unicast manner, and the receiving encryption terminal generates a reception completion signaling and sends it to the base station; or sending the encrypted data to the receiving encryption terminal in a multicast manner.
[0012] Optionally, the sending encryption terminal sends encrypted data to the receiving encryption terminal through the base station, and the base station also includes: when the data to be transmitted is a packet message, the sending encryption terminal sends a packet message sending request signaling to the base station, and the base station sends a channel maintenance signaling to the sending encryption terminal based on the packet message sending request signaling, and the sending encryption terminal sends the encrypted data to the base station through the channel specified by the channel maintenance signaling based on the channel maintenance signaling, and the base station receives the encrypted data and feeds back a reception confirmation signaling to the sending encryption terminal, and sends the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling.
[0013] Optionally, sending the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling includes: sending the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling in a unicast manner, the receiving encryption terminal generating a correct reception confirmation signaling or a selective confirmation retransmission signaling to the base station based on the reception result, and the base station retransmitting the encrypted data specified by the selective confirmation retransmission signaling based on the selective confirmation retransmission signaling; or, sending the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling in a multicast manner repeatedly for a preconfigured number of times.
[0014] Optionally, it also includes: the key management center monitors the key life cycle of the end-to-end key in real time, and generates an updated end-to-end key and sends it to the encryption terminal when the key life cycle of the end-to-end key expires, and the encryption terminal updates the current end-to-end key based on the updated end-to-end key; wherein the encryption terminal is the sender's encryption terminal or the receiver's encryption terminal.
[0015] According to a second aspect of the present invention, there is provided an end-to-end encrypted communication system for a power load control business communication terminal, comprising a sending encryption terminal, a receiving encryption terminal, an authentication center and a key management center; the sending encryption terminal is used to receive data to be transmitted sent by the sending power load control business communication terminal; and to perform authentication registration with the authentication center, and obtain an end-to-end key from the key management center after successful authentication registration, and encrypt the data to be transmitted according to the end-to-end key to obtain encrypted data; and to send the encrypted data to the receiving encryption terminal through the base station; the receiving encryption terminal is used to perform authentication registration with the authentication center, and obtain an end-to-end key from the key management center after successful authentication registration, and decrypt the encrypted data according to the end-to-end key to obtain the data to be transmitted, and send the data to be transmitted to the receiving power load control business communication terminal.
[0016] Optionally, the key management center is also used to monitor the key life cycle of the end-to-end key in real time, and generate an updated end-to-end key and send it to the encryption terminal when the key life cycle of the end-to-end key expires; the encryption terminal is also used to update the current end-to-end key based on the updated end-to-end key; wherein the encryption terminal is the sender encryption terminal or the receiver encryption terminal.
[0017] Compared with the prior art, the present invention has the following beneficial effects:
[0018] The end-to-end encryption communication method for the power load control business communication terminal of the present invention, without changing the existing power load control business system, establishes an encrypted private network by adding a small amount of encryption equipment, thereby realizing end-to-end encryption of the power load control business communication terminal, effectively protecting the security and stability of power data when conducting load control business, and the transmission data can only be decrypted by the receiver after being encrypted by the sender, ensuring that the third-party communication equipment and network equipment in the middle cannot decrypt the transmission data. At the same time, it realizes the dynamic control of the end-to-end key, solves the problems of key staticization and key reuse risks in traditional end-to-end encryption communication methods, and can apply for and update the end-to-end key at any time as needed to adapt to different communication scenarios and needs, while reducing the risk of the key being cracked or leaked. The method of the present invention adopts a combination of software and hardware to realize full-process communication encryption of the power load control business, realizes safe and reliable communication while being cost-controllable and easy to use and manage, protects data from attacks and influences during communication, and further improves the operational reliability and security of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 This is a flow chart of the end-to-end encrypted communication method for power load control service communication terminals according to an embodiment of the present invention.
[0020] Figure 2 This is a structural block diagram of the end-to-end encrypted communication system of the power load control service communication terminal according to an embodiment of the present invention. DETAILED DESCRIPTION
[0021] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0022] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0023] The present invention is described in further detail below with reference to the accompanying drawings:
[0024] See also Figure 1 In one embodiment of the present invention, an end-to-end encrypted communication method for a power load control business communication terminal is provided to ensure the security and stability of power data communication when the power system performs power load control business.
[0025] Specifically, the present invention comprises the following steps:
[0026] S1: The sender's power load control business communication terminal sends the data to be transmitted to the sender's encryption terminal.
[0027] S2: The sender's encryption terminal registers for authentication with the authentication center, and obtains the end-to-end key from the key management center after successful authentication and registration, and encrypts the data to be transmitted according to the end-to-end key to obtain encrypted data.
[0028] S3: The sending encryption terminal sends the encrypted data to the receiving encryption terminal through the base station.
[0029] S4: The receiving encryption terminal performs authentication registration with the authentication center, and obtains the end-to-end key from the key management center after successful authentication registration, decrypts the encrypted data according to the end-to-end key to obtain the data to be transmitted, and sends the data to be transmitted to the receiving power load control business communication terminal.
[0030] The end-to-end encryption communication method for the power load control business communication terminal of the present invention, without changing the existing power load control business system, establishes an encrypted private network by adding a small amount of encryption equipment, thereby realizing end-to-end encryption of the power load control business communication terminal, effectively protecting the security and stability of power data when conducting load control business, and the transmission data can only be decrypted by the receiver after being encrypted by the sender, ensuring that the third-party communication equipment and network equipment in the middle cannot decrypt the transmission data. At the same time, it realizes the dynamic control of the end-to-end key, solves the problems of key staticization and key reuse risks in traditional end-to-end encryption communication methods, and can apply for and update the end-to-end key at any time as needed to adapt to different communication scenarios and needs, while reducing the risk of the key being cracked or leaked. The method of the present invention adopts a combination of software and hardware to realize full-process communication encryption of the power load control business, realizes safe and reliable communication while being cost-controllable and easy to use and manage, protects data from attacks and influences during communication, and further improves the operational reliability and security of the power system.
[0031] In one possible implementation, the authentication registration to the authentication center includes: the encryption terminal generates a request registration signaling and sends it to the base station, the base station responds to the request registration signaling and sends a request signaling to the authentication center, the authentication center generates an authentication parameter in response to the request signaling and sends it to the base station, the base station generates an authentication challenge signaling based on the authentication parameter and the base station identity authentication code and sends it to the encryption terminal, the encryption terminal authenticates the base station based on the authentication challenge signaling, and sends the encryption terminal identity authentication code to the base station after successful authentication, the base station authenticates the encryption terminal based on the encryption terminal identity authentication code, and sends the base station identity confirmation code to the encryption terminal after successful authentication; wherein, the encryption terminal is a sending encryption terminal or a receiving encryption terminal.
[0032] For explanatory purposes, encryption terminals must first complete authentication registration when performing end-to-end encryption for power load control communications. The authentication registration process is the same for both the sending and receiving encryption terminals. Bidirectional authentication between the encryption terminal and the base station ensures that both are legitimate devices. This bidirectional authentication mechanism not only effectively prevents unauthorized devices from accessing the network, ensuring the security of the communication process, but also prevents legitimate devices from impersonating or tampering with information, thereby maintaining the stability and reliability of the entire communication system.
[0033] After successful authentication, the encryption terminal requests the key from the key management center for an end-to-end encryption key. The key management center then sends the key to the encryption terminal in UDT format. After receiving the key, the encryption terminal stores it in the encryption chip to encrypt and decrypt subsequent power load control data.
[0034] In a possible implementation manner, the registration request signaling includes the encryption terminal identifier and the power load control service communication terminal identifier of the power load control service communication terminal connected to the encryption terminal.
[0035] For example, the encryption terminal identifier uses a length of 32 bits, and the power load control service communication terminal identifier uses a length of 47 bits, which can fully represent different devices.
[0036] In one possible implementation, when the encryption terminal fails authentication more than a specified number of times, it will be required to synchronize the authentication sequence number. Specifically, the base station initiates a synchronization challenge, and the encryption terminal returns a synchronization token and authentication sequence number, and re-enters the authentication registration process.
[0037] In a possible implementation, the sending encryption terminal sends encrypted data to the receiving encryption terminal through the base station, including: when the data to be transmitted is a short message, the sending encryption terminal sends a short message sending request signaling to the base station, the base station sends a short message response signaling to the sending encryption terminal based on the short message sending request signaling, the sending encryption terminal sends encrypted data to the base station based on the short message response signaling, the base station receives the encrypted data and feeds back a reception confirmation signaling to the sending encryption terminal, and sends the encrypted data to the receiving encryption terminal.
[0038] For clarification, short messages generally refer to text data within the power load control system. A sending power load control communication terminal composes a short message and sends it via serial communication to a connected encryption terminal. The encryption terminal receives the plaintext message and transmits it to a security chip for encryption. After encryption, the security chip returns the encrypted data, which the sending terminal then sends over the air interface to the receiving encryption terminal.
[0039] Illustratively, encrypted data includes end-to-end encrypted data and ciphertext short message data. Ciphertext short message data refers to the data obtained by encrypting a plaintext short message. End-to-end encrypted data refers to the data returned by the encryption device when encrypting the plaintext. This data is required during decryption to correctly decrypt the ciphertext short message data into a plaintext short message.
[0040] In one possible implementation, sending the encrypted data to the receiving encryption terminal includes: sending the encrypted data to the receiving encryption terminal in a unicast manner, and the receiving encryption terminal generates a reception completion signaling and sends it to the base station; or, sending the encrypted data to the receiving encryption terminal in a multicast manner.
[0041] Explanatory note: The receiving encryption terminal generates a reception completion signaling and sends it to the base station, indicating successful reception of the encrypted data. Upon receiving the encrypted data, the receiving encryption terminal determines whether the service is a short message transmission task or a packet information transmission task. Upon confirming the short message transmission task, the receiving encryption terminal receives the encrypted data frame by frame. After receiving the entire packet, the encrypted data is sent to the security chip for decryption, resulting in the plaintext short message for the service. This is then transmitted via serial communication to the receiving power load control service communication terminal, completing the end-to-end encrypted short message transmission service.
[0042] In a possible embodiment, the sending encryption terminal sends encrypted data to the receiving encryption terminal through the base station, and the base station sends a packet message sending request signaling to the base station. The base station sends a channel maintenance signaling to the sending encryption terminal based on the packet message sending request signaling. The sending encryption terminal sends the encrypted data to the base station through the channel specified by the channel maintenance signaling based on the channel maintenance signaling. The base station receives the encrypted data and feeds back a reception confirmation signaling to the sending encryption terminal, and sends the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling.
[0043] For clarification, packet messages generally refer to power load control service data, such as general call, remote control, telemetering, and telesignaling, and are typically binary data. The process for sending a packet message is essentially the same as sending a short message, differing in that the packet message is transmitted over a dedicated data service channel. The sending power load control service communication terminal edits the packet message and sends the plaintext packet message via a serial port to a connected sending encryption terminal. The sending encryption terminal then transmits the plaintext packet data to a security chip for encryption, generating encrypted data. The system then allocates a dedicated data service channel for transmitting the packet message to the sending and receiving encryption terminals. The sending and receiving encryption terminals then transmit the encrypted data over this service channel.
[0044] In one possible embodiment, the sending of the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling includes: using a unicast method to send the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling, the receiving encryption terminal generates a correct reception confirmation signaling or a selective confirmation retransmission signaling to the base station based on the reception result, and the base station retransmits the encrypted data specified by the selective confirmation retransmission signaling based on the selective confirmation retransmission signaling; or, using a multicast method to send the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling repeatedly for a preconfigured number of times.
[0045] Explanatory, the receiving encryption terminal receives the channel maintenance signaling sent by the base station, switches the current channel to the channel specified by the channel maintenance signaling, and determines whether the current service is an end-to-end encryption service based on specific fields such as the E2EE field. Then, after receiving the service, the receiving encryption terminal determines that the service is a packet message transmission task, and then receives the encrypted data frame by frame, sends the encrypted data to the security chip for decryption, obtains the plaintext packet message, and then sends it to the receiving power load control service communication terminal via serial communication.
[0046] In a possible embodiment, the end-to-end encrypted communication method of the power load control business communication terminal also includes: the key management center monitors the key life cycle of the end-to-end key in real time, and generates an updated end-to-end key and sends it to the encryption terminal when the key life cycle of the end-to-end key expires, and the encryption terminal updates the current end-to-end key based on the updated end-to-end key; wherein the encryption terminal is a sender encryption terminal or a receiver encryption terminal.
[0047] To explain, after registering with a base station, an encryption terminal proactively requests an end-to-end key from the base station's key management center and updates its local key database. The key management center is responsible for maintaining the key lifecycle of each encryption terminal, ensuring that the end-to-end key remains valid. When the key management center detects that the lifecycle of an encryption terminal's end-to-end key has expired, it proactively generates an updated end-to-end key and distributes it to the encryption terminal. The encryption terminal then updates its current end-to-end key based on the updated end-to-end key, ensuring the real-time and security of the end-to-end key. By dynamically updating the end-to-end key, the risk of the end-to-end key being cracked or leaked is reduced.
[0048] When the power system uses the power load control business system for communication, it needs to transmit power data in real time. When the power load control business is carried out, the power data is communicated in plain text in the power load control business system, which poses a great security risk. The end-to-end encryption technology of the power load control business communication terminal is used in the power system, which can effectively solve the problem of data leakage in the power load control business communication terminal in the power load control business system.
[0049] The following are device embodiments of the present invention, which can be used to perform the method embodiments of the present invention. For details not disclosed in the device embodiments, please refer to the method embodiments of the present invention.
[0050] See also Figure 2 In another embodiment of the present invention, an end-to-end encrypted communication system for a power load control business communication terminal is provided, which can be used to implement the above-mentioned end-to-end encrypted communication method for a power load control business communication terminal. Specifically, the end-to-end encrypted communication system for a power load control business communication terminal includes a sender encryption terminal, a receiver encryption terminal, an authentication center, and a key management center.
[0051] Among them, the sender's encryption terminal is used to receive the data to be transmitted sent by the sender's power load control business communication terminal; and to perform authentication registration with the authentication center, and obtain the end-to-end key from the key management center after the authentication registration is successful, and encrypt the data to be transmitted according to the end-to-end key to obtain encrypted data; and send the encrypted data to the receiver's encryption terminal through the base station; the receiver's encryption terminal is used to perform authentication registration with the authentication center, and obtain the end-to-end key from the key management center after the authentication registration is successful, and decrypt the encrypted data according to the end-to-end key to obtain the data to be transmitted, and send the data to be transmitted to the receiver's power load control business communication terminal.
[0052] In one possible implementation, the key management center is also used to monitor the key lifecycle of the end-to-end key in real time, and generate an updated end-to-end key and send it to the encryption terminal when the key lifecycle of the end-to-end key expires; the encryption terminal is also used to update the current end-to-end key based on the updated end-to-end key; wherein the encryption terminal is the sender encryption terminal or the receiver encryption terminal.
[0053] All relevant contents of each step involved in the embodiment of the above-mentioned end-to-end encrypted communication method of the power load control business communication terminal can be referred to the functional description of the functional module corresponding to the end-to-end encrypted communication system of the power load control business communication terminal in the embodiment of the present invention, and will not be repeated here.
[0054] The module division in the embodiments of the present invention is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in various embodiments of the present invention may be integrated into a single processor, exist physically as separate modules, or two or more modules may be integrated into a single module. The integrated modules may be implemented in either hardware or software functional modules.
[0055] In another embodiment of the present invention, a computer device is provided, comprising a processor and a memory, wherein the memory is used to store a computer program, the computer program including program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the end-to-end encrypted communication method of the power load control service communication terminal.
[0056] In another embodiment of the present invention, the present invention further provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It is understandable that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space that stores the terminal's operating system. In addition, the storage space also stores one or more instructions suitable for being loaded and executed by the processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the end-to-end encrypted communication method for the power load control service communication terminal in the above embodiment.
[0057] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0058] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0059] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0060] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0061] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.
Claims
1. A method for end-to-end encrypted communication of a power load control service communication terminal, characterized in that: include: The power load control business communication terminal of the sender sends the data to be transmitted to the encryption terminal of the sender; The sender's encryption terminal registers for authentication with the authentication center, obtains the end-to-end key from the key management center after successful authentication and registration, and encrypts the data to be transmitted according to the end-to-end key to obtain encrypted data; The sender encryption terminal sends the encrypted data to the receiver encryption terminal through the base station; The receiving encryption terminal performs authentication registration with the authentication center, and obtains the end-to-end key from the key management center after successful authentication registration, decrypts the encrypted data according to the end-to-end key to obtain the data to be transmitted, and sends the data to be transmitted to the receiving power load control business communication terminal.
2. The end-to-end encrypted communication method for power load control business communication terminals according to claim 1, characterized in that: The authentication registration with the authentication center includes: The encryption terminal generates a registration request signaling and sends it to the base station. The base station responds to the registration request signaling and sends a request signaling to the authentication center. The authentication center responds to the request signaling and generates authentication parameters and sends them to the base station. The base station generates an authentication challenge signaling based on the authentication parameters and the base station identity authentication code and sends it to the encryption terminal. The encryption terminal authenticates the base station based on the authentication challenge signaling and sends the encryption terminal identity authentication code to the base station after successful authentication. The base station authenticates the encryption terminal based on the encryption terminal identity authentication code and sends the base station identity confirmation code to the encryption terminal after successful authentication. The encryption terminal is a sending encryption terminal or a receiving encryption terminal.
3. The end-to-end encrypted communication method for power load control business communication terminals according to claim 2, characterized in that: The registration request signaling includes the encryption terminal identifier and the power load control service communication terminal identifier of the power load control service communication terminal connected to the encryption terminal.
4. The end-to-end encrypted communication method for power load control business communication terminals according to claim 1, characterized in that: The sending encryption terminal of the sending party sends the encrypted data to the receiving party encryption terminal through the base station, including: When the data to be transmitted is a short message, the sender's encryption terminal sends a short message sending request signaling to the base station, the base station sends a short message response signaling to the sender's encryption terminal based on the short message sending request signaling, the sender's encryption terminal sends encrypted data to the base station based on the short message response signaling, the base station receives the encrypted data and feeds back a reception confirmation signaling to the sender's encryption terminal, and sends the encrypted data to the receiver's encryption terminal.
5. The end-to-end encrypted communication method for power load control business communication terminals according to claim 4, characterized in that: The sending of the encrypted data to the receiving encryption terminal includes: The encrypted data is sent to the receiving encryption terminal in a unicast manner, and the receiving encryption terminal generates a reception completion signaling and sends it to the base station; or, the encrypted data is sent to the receiving encryption terminal in a multicast manner.
6. The end-to-end encrypted communication method for power load control business communication terminals according to claim 4, characterized in that: The sending encryption terminal of the sending party sends the encrypted data to the receiving party encryption terminal through the base station, further comprising: When the data to be transmitted is a packet message, the sender encryption terminal sends a packet message sending request signaling to the base station. The base station sends a channel maintenance signaling to the sender encryption terminal based on the packet message sending request signaling. The sender encryption terminal sends encrypted data to the base station through the channel specified by the channel maintenance signaling based on the channel maintenance signaling. The base station receives the encrypted data and feeds back a reception confirmation signaling to the sender encryption terminal, and sends the encrypted data to the receiver encryption terminal through the channel specified by the channel maintenance signaling.
7. The end-to-end encrypted communication method for power load control business communication terminals according to claim 6, characterized in that: The sending of the encrypted data to the receiving encryption terminal through the channel specified by the channel maintenance signaling includes: The encrypted data is sent to the receiving encryption terminal through the channel specified by the channel maintenance signaling in unicast mode. The receiving encryption terminal generates a correct reception confirmation signaling or a selective confirmation retransmission signaling to the base station based on the reception result, and the base station retransmits the encrypted data specified by the selective confirmation retransmission signaling based on the selective confirmation retransmission signaling; or, the encrypted data is sent to the receiving encryption terminal through the channel specified by the channel maintenance signaling in multicast mode repeatedly for a preconfigured number of times.
8. The end-to-end encrypted communication method for power load control business communication terminals according to claim 1, characterized in that: Also includes: The key management center monitors the key lifecycle of the end-to-end key in real time, and generates an updated end-to-end key when the key lifecycle of the end-to-end key expires and sends it to the encryption terminal. The encryption terminal updates the current end-to-end key based on the updated end-to-end key; among them, the encryption terminal is the sender's encryption terminal or the receiver's encryption terminal.
9. An end-to-end encrypted communication system for power load control business communication terminals, characterized in that: It includes the sender encryption terminal, the receiver encryption terminal, the authentication center and the key management center; The sender encryption terminal is used to receive the data to be transmitted sent by the sender's power load control business communication terminal; and to register for authentication with the authentication center, and obtain the end-to-end key from the key management center after the authentication registration is successful, and encrypt the data to be transmitted according to the end-to-end key to obtain encrypted data; and sending the encrypted data to the receiving encryption terminal via the base station; The receiving encryption terminal is used to register for authentication with the authentication center, and obtain the end-to-end key from the key management center after successful authentication registration, and decrypt the encrypted data according to the end-to-end key to obtain the data to be transmitted, and send the data to be transmitted to the receiving power load control business communication terminal.
10. The end-to-end encrypted communication system for power load control business communication terminals according to claim 9, characterized in that: The key management center is also used to monitor the key life cycle of the end-to-end key in real time, and generate an updated end-to-end key and issue it to the encryption terminal when the key life cycle of the end-to-end key expires; The encryption terminal is further used to update the current end-to-end key based on the updated end-to-end key; wherein the encryption terminal is a sender encryption terminal or a receiver encryption terminal.