Root key management method and device of energy storage system and energy storage system
By splitting the energy storage root key into multiple shares and managing them by multiple authorized parties, the problems of high cost and easy leakage under single hardware management are solved, and more secure and economical root key management is achieved.
Patent Information
- Application Number
- CN202510930142.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-10-03
AI Technical Summary
The root key management of existing energy storage systems relies on single hardware, resulting in high hardware costs and the risk of leakage due to vulnerability to attacks, and poor management effects.
The energy storage root key is split into multiple root key shares, which are managed and stored separately by multiple authorized parties. The management permissions held by each party are isolated from each other. The root key can only be restored with the cooperation of multiple authorized parties.
Through software-level management, hardware costs are reduced, the security of the root key is improved, the risk of leakage caused by attacks on a single authorized party is avoided, and management effectiveness is improved.
Smart Images

Figure CN120744901A_ABST
Abstract
Description
[0001] This case is a divisional application filed in response to application number: 2025105779231 (Root key management method, device and energy storage system for energy storage system, filing date: May 6, 2025). Technical Field
[0002] The present application relates to the field of information security technology, and in particular to a root key management method and device for an energy storage system, and an energy storage system. Background Art
[0003] With the continuous development of science and technology, energy storage systems have been widely used in many fields. To ensure the security of energy storage data in energy storage systems, a key protection system is usually set up for the energy storage system. In the key management protection system, the root key is used to derive encryption keys and integrity protection keys. Therefore, it is very necessary to securely manage the root key of the energy storage system.
[0004] Currently, root key management for energy storage systems typically involves storing the root key using physical hardware such as an HSM (Hardware Security Module) or an encrypted USB (Universal Serial Bus) disk. However, this hardware is often relatively expensive. Furthermore, relying on a single piece of hardware for root key management can lead to the risk of leakage if the device is attacked. Consequently, current root key management for energy storage systems is ineffective. Summary of the Invention
[0005] Based on this, it is necessary to provide a root key management method, device and energy storage system for energy storage systems to improve the management effect of root key management of energy storage systems in order to address the above technical problems.
[0006] In a first aspect, the present application provides a root key management method for an energy storage system, which is applied to a control terminal of the energy storage system, comprising:
[0007] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein a first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authorities of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the four: a root key management object that manages the energy storage system, a root key user object that uses the energy storage system, a management and control terminal of the energy storage system, and a cloud that provides cloud services for the energy storage system;
[0008] Storing each root key share in a storage area managed by a respective matching root key authority, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key;
[0009] According to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties in a one-to-one manner;
[0010] When it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored based on the target root key shares selected from the multiple target storage areas.
[0011] In a second aspect, the present application further provides a root key management device for an energy storage system, which is applied to a control terminal of the energy storage system, including:
[0012] a splitting module configured to, upon detecting that the energy storage system has generated an energy storage root key, split the energy storage root key into multiple root key shares, wherein a first management authority for the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, the multiple root key authority parties hold second management authorities for their respective corresponding root key shares, the multiple second management authorities being isolated from each other, and the multiple root key authority parties including at least two of a root key management object that manages the energy storage system, a root key user object that uses the energy storage system, a control terminal of the energy storage system, and a cloud that provides cloud services for the energy storage system;
[0013] A storage module, configured to store each root key share in a storage area managed by a respective matching root key authority, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key;
[0014] A determination module, configured to locate, in all storage areas, a plurality of target storage areas required for restoring the energy storage root key according to a root key restoration operation triggered by a root key restoration party, wherein the plurality of target storage areas correspond one-to-one to the plurality of root key authority parties;
[0015] The restoration module is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas.
[0016] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0017] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0018] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0019] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0020] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps:
[0021] After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least two of the root key management object that manages the energy storage system, the root key use object that uses the energy storage system, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system; each root key share is stored in Storage areas managed by respective matching root key authority parties, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key; according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; when it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored according to the target root key shares selected from the multiple target storage areas.
[0022] The above-mentioned root key management method, device and energy storage system of the energy storage system, the control terminal of the energy storage system first performs real-time detection on the energy storage system, and after detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and the management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively, and the management authority held by different root key authority parties is isolated from each other, and multiple root key authority parties include the root key management object that manages the energy storage system, the root key that uses the energy storage system, and the root key management object that uses the energy storage system. By using at least two of the four objects, the management and control terminal of the energy storage system, and the cloud providing the cloud service of the energy storage system, the energy storage root key can be split into multiple root key shares managed by at least two root key authority parties related to the energy storage system, and then each root key share is stored in a storage area managed by a respective matching root key authority party, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key, thereby storing the multiple root key shares respectively in storage areas where different root key authority parties have management authority, and then according to the root key restoration operation triggered by the key restoration party, The multiple target storage areas required for restoring the energy storage root key are located within all storage areas. Ultimately, if it is detected that the root key restorer has access to multiple target storage areas, the energy storage root key is restored based on target root key shares selected from the multiple target storage areas. Because the root key shares managed by multiple root key authority parties are isolated from each other, and the root key shares corresponding to the root key shares managed by any one root key authority party cannot be independently restored to obtain the energy storage root key, upon receiving a root key restoration request, collaboration with at least two of the root key management object, the root key user object, the control terminal, and the cloud is required to locate the multiple target storage areas required for restoring the energy storage root key. Ultimately, the energy storage root key is restored by extracting multiple target root key shares from multiple target storage areas managed by the root key authority parties. This prevents root key leakage from an attack on a single root key authority party, thus achieving secure root key management at the software level. This overcomes the technical drawbacks of relatively high hardware costs and the risk of root key leakage from relying on single hardware encryption. This improves the management effectiveness of energy storage system root key management. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 1 is a flow chart of a root key management method for an energy storage system according to an embodiment;
[0025] Figure 2 1 is a flow chart of a root key management method for an energy storage system according to another embodiment;
[0026] Figure 3 A schematic diagram of a process for splitting an energy storage root key in a root key management method for an energy storage system in another embodiment;
[0027] Figure 4 A schematic diagram of a scenario in which different root key restoration parties of a root key management method for an energy storage system perform energy storage root key restoration in another embodiment;
[0028] Figure 5 1 is a structural block diagram of a root key management device for an energy storage system in one embodiment;
[0029] Figure 6 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0031] First of all, it should be understood that an ESS (Energy Storage System) refers to a system that stores energy in a certain form through specific media or devices and releases it in a specific form when needed. To ensure the security of energy storage data in the energy storage system, a hardware security module is usually deployed in the energy storage system to store the root key. The root key is at the highest level in the key protection system and is used to generate and manage the next level of keys, such as the master key and working key. By setting the root key, each unit and battery pack within the energy storage system can be protected in advance, thereby ensuring the secure storage and management of the key. Currently, the root key is often stored in an HSM or a trusted execution environment. And it can be dynamically updated when necessary to serve scenarios such as data transmission, firmware update and status monitoring of energy storage systems. However, for the highly competitive energy storage industry, the use of hardware such as HSM to manage root keys often increases hardware costs. At the same time, since the root keys rely on a single hardware to manage them, they are still prone to the risk of leakage when the device is attacked. Therefore, whether from the perspective of management cost or management security, the current management effect of energy storage system root key management is not good. Therefore, there is an urgent need for a root key management method for energy storage systems that can improve the root key management effect of energy storage systems.
[0032] In one embodiment, Figure 1As shown, a root key management method for an energy storage system is provided. This embodiment takes the application of this method to the control terminal of the energy storage system as an example. The control terminal of the energy storage system refers to a terminal deployed at the user end of the energy storage system, which can not only collect data at the user end of the energy storage system, but also interactively control the user end of the energy storage system. The user end of the energy storage system refers to the energy storage system deployment site on the user side, which can be specifically composed of an energy storage cabinet, an energy management system, communication equipment and the control terminal of the energy storage system. The control equipment of the energy storage system can be a personal computer, a laptop computer, a smart phone and a tablet computer. The control terminal of the energy storage system monitors the energy storage system. It can be understood that the operation and maintenance personnel perform energy storage system deployment at the control terminal of the energy storage system. During the deployment process, an energy storage root key will be dynamically generated in the hardware security module of the energy storage system, and then the encryption key and integrity protection key will be derived based on the energy storage root key. Finally, the above keys will be used to ensure the secure transmission and storage of relevant data of the energy storage system. The management and control terminal of the energy storage system includes a splitting module, a storage module, a determination module and a restoration module. The splitting module is used to split the energy storage root key into multiple root key shares after detecting that the energy storage system has generated an energy storage root key. Among them, the first management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and multiple root key authority parties hold the second management authority of their respective corresponding root key shares. The multiple second management authorities are isolated from each other, and the multiple root key authority parties include the root key of the energy storage system. At least two of the following four: a key management object, an object using the root key of the energy storage system, a control terminal of the energy storage system, and a cloud providing cloud services for the energy storage system; a storage module is used to store each root key share in a storage area managed by a respective matching root key authority party; wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key; a determination module is used to locate multiple target storage areas required to restore the energy storage root key in all storage areas according to a root key restoration operation triggered by a root key restoration party; wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one; and a restoration module is used to locate the root key restoration area according to the root key restoration operation triggered by the root key restoration party when it is detected that the root key restoration party has access rights to access the multiple target storage areas. The target root key shares selected from multiple target storage areas are restored to obtain the energy storage root key. It can be understood that in the process of root key management of the energy storage system, through the information interaction between the splitting module, the storage module, the determination module and the restoration module, first, after receiving the energy storage root key, the energy storage root key is split into multiple root key shares, and at least two of the four, the root key management object, the root key use object, the management and control terminal of the energy storage system and the cloud providing cloud services for the energy storage system, hold management permissions for different root key shares. Since the root key shares with management permissions of multiple root key authority parties are isolated from each other, and the root key shares corresponding to the amount of root key shares that can be managed by any root key authority party cannot be restored to obtain the energy storage root key alone,After receiving the root key restoration request, it is necessary to cooperate with at least two of the root key management object, the root key user object, the control terminal and the cloud to locate the multiple target storage areas required to restore the energy storage root key. Finally, by extracting multiple target root key shares from multiple target storage areas managed by the root key authority, the energy storage root key can be restored, thereby avoiding the situation where a single root key authority is attacked and the root key is leaked, thereby improving the root key management effect of the energy storage system. In this embodiment, the method includes the following steps 202 to 208. Among them:
[0033] Step 202: After detecting that the energy storage system has generated an energy storage root key, the energy storage root key is split into multiple root key shares, wherein a first management authority for the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority for their respective corresponding root key shares, the multiple second management authorities being isolated from each other, and the multiple root key authority parties include at least two of the following: a root key management object that manages the energy storage system, a root key user object that uses the energy storage system, a control terminal of the energy storage system, and a cloud provider that provides cloud services for the energy storage system.
[0034] It should be noted that the operation and maintenance personnel can complete the generation and splitting process of the energy storage root key through the interaction between the energy storage system's management and control terminal and the energy storage system. Specifically, the operation and maintenance personnel deploy the energy storage system through the energy storage system's management and control terminal. During the initialization phase of the energy storage system deployment, the energy storage system's hardware security module will generate the energy storage root key through its internal secure random number generator. The hardware security module can be integrated into the energy storage system's controller or gateway device. The energy storage root key is generated entirely in a secure hardware module such as an HSM or encrypted USB disk to prevent it from being maliciously stolen. However, the energy storage root key that relies on single hardware management is still prone to leakage after the device is attacked. Therefore, after the energy storage root key is generated, the key splitting technology can be used to split the energy storage root key into multiple root key shares, and multiple root key authorities hold the management authority of their respective corresponding root key shares, thereby increasing the difficulty for hackers to attack the energy storage cabinet and thus destroy the confidentiality of the system.
[0035] It should be noted that the management and control terminal of the energy storage system detects that the energy storage system generates an energy storage root key. Specifically, the management and control terminal of the energy storage system detects that the energy storage root key is generated in the hardware security module, and after the energy storage root key is generated, it issues a control instruction to split the energy storage root key into multiple root key shares. It can be understood that the execution subject of splitting the energy storage root key is the hardware security module in the energy storage system. The multiple root key shares can be 5, 6 or 7, etc. The share amount of the multiple root key shares can be specifically determined by the splitting instruction issued by the management and control terminal of the energy storage system. Among them, after the energy storage root key is split into multiple root key shares, the first management authority of the entire energy storage root key is jointly held by multiple root key authority parties who manage the energy storage root key. Different root key authority parties hold second management authority for their respective corresponding root key shares, and different second management authorities are isolated from each other. The root key authority party refers to an entity with management authority for the energy storage root key, which can be specifically an object, system or terminal, etc. The multiple root key authority parties include the root key management object that manages the energy storage system, the root key management object that uses the energy storage system, and the root key management object that uses the energy storage system. The key usage object, the management and control terminal of the energy storage system, and the cloud that provides cloud services for the energy storage system, wherein the root key management object for managing the energy storage system can be specifically the supplier, the root key usage object for using the energy storage system can be specifically the customer site manager, the management and control terminal of the energy storage system can be specifically a computer or mobile phone, etc., and the cloud can be specifically the cloud server. It can be understood that since different root key authority parties are independent of each other, the second management permissions of multiple root key shares are isolated from each other, and the amount of root key shares with management permissions of different root key authority parties can be the same or different. For example, in an implementable manner, the energy storage root key is split into root key share 1, root key share 2, root key share 3, root key share 4 and root key share 5, wherein the second management permission of root key share 1 can be held by the supplier operation and maintenance personnel, the second management permission of root key share 2 can be held by the customer site manager, the second management permission of root key share 3 and root key share 4 is held by the management and control terminal of the energy storage system, and the management permission of root key share 5 can be held by the cloud server.
[0036] It should be noted that after the hardware security module of the energy storage system receives the splitting instruction issued by the control terminal of the energy storage system, the hardware security module can generate multiple root key shares based on the preset splitting algorithm running internally. The preset splitting algorithm can be specifically the Shamir polynomial difference algorithm. The shares obtained by splitting can be expressed as 、 、 , where n represents the total number of root key shares. After splitting to obtain multiple root key shares, the management and control terminal of the energy storage system can establish a mapping relationship between different root key shares and different root key authority parties, so that different root key authority parties have the second management authority of their respective corresponding root key shares. Specifically, based on the share identification information of the root key share and the authority identity information of the root key authority party, a mapping relationship between different key shares and different root key authority parties can be established, where the share identification information can specifically be a share number, and the authority identity information can specifically be object identity information or terminal number information, etc. It can be understood that there are at least two root key authority parties with the second management authority, and multiple root key authority parties with the second management authority jointly hold the first management authority of the energy storage root key. For example, in an implementable manner, the multiple root key authority parties can be a root key management object and a root key user object, a root key management object and the management and control terminal of the energy storage system, a management and control terminal of the energy storage system and the cloud, or a root key management object, a root key user object and the management and control terminal of the energy storage system, etc.
[0037] As an example, step 202 includes: after determining that the hardware security module of the energy storage system generates an energy storage root key based on the root key generation progress information fed back by the energy storage system, generating a root key splitting instruction, and according to the root key splitting instruction, controlling the hardware security module to split the energy storage root key into multiple root key shares, wherein the root key generation progress information is used to characterize the generation progress of the energy storage root key generated by the hardware security module of the energy storage system, and the root key splitting instruction is used to instruct the splitting of the energy storage root key.
[0038] In one practicable manner, it is assumed that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 4, then the hardware security module splits the energy storage root key into 、 、 and .
[0039] Step 204: Store each root key share in a storage area managed by the corresponding root key authority, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key;
[0040] It should be noted that after the hardware security module completes the splitting of the energy storage root key and obtains multiple root key shares, in order to achieve physical isolation of different root key shares when they are managed by multiple root key authority parties, the management and control terminal of the energy storage system can control the distribution and storage of multiple root key shares in the storage area managed by the root key authority party. For example, in one feasible method, assuming that the energy storage root key is split into 4 root key shares, the root key management object, the root key use object, the management and control terminal and the cloud each have a second management authority for a root key share, then the root key share 1 can be stored in the first preset of the first associated terminal associated with the root key management object. Storage area, storing the root key share 2 in the second preset storage area of the second associated terminal associated with the root key user object, storing the root key share 3 in the third preset storage area of the management and control terminal, and storing the root key share 4 in the fourth preset storage area of the cloud. Among them, the first associated terminal that has an associated relationship with the root key management object can be a mobile phone terminal held by the root key management object, and the second associated terminal that has an associated relationship with the root key user object can be a mobile phone terminal held by the root key user object. In this way, since the storage space of different terminals has independent storage media, it is possible to achieve real isolation of different root key shares from a physical level.
[0041] It should be noted that in order to avoid the leakage of the energy storage root key caused by a single root key authority, it can be set that the root key share that each root key authority can manage cannot be restored to obtain the energy storage root key, and the energy storage root key can only be restored by the collaboration of two or more root key authority parties. That is, the first root key share stored in any storage area is set to be smaller than the second root key share required to restore the energy storage root key. For example, in one feasible method, assuming that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, and the root key splitting instruction simultaneously indicates that the minimum number of shares for restoring the energy storage root key is 4. Then, in the process of establishing a mapping relationship between the root key shares and the root key authority to distribute the root key shares to different storage areas for storage, the number of root key shares stored in any depository area is less than 4.
[0042] As an example, step 204 includes: extracting share allocation strategy information from the root key splitting instruction, determining the root key share allocation amount corresponding to each of the multiple root key authority parties based on the share allocation strategy information, and receiving a mapping relationship between multiple root key shares and multiple root key authority parties, and according to the root key share allocation amount and the mapping relationship, controlling the hardware security module to store the multiple root key shares in the respective matching root key authority parties, wherein the root key share allocation amount is used to characterize the number of root key shares allocated to different root key authority parties.
[0043] Step 206: Based on the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties on a one-to-one basis.
[0044] It should be noted that the root key restoration party refers to the entity that performs energy storage root key restoration, which can be a role, object or terminal. It can be understood that the root key restoration operation can be manually triggered by a role, such as a supplier operation and maintenance personnel, a customer site administrator or a hacker, etc., or it can be automatically triggered by a terminal, such as a management terminal or a cloud, etc. After receiving the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key can be located in all storage areas. That is, the multiple root key shares of the combination of multiple target storage areas can meet the minimum root key share required to restore the energy storage root key, and the multiple target storage areas and the multiple root key authority parties are one-to-one corresponding. For example, in one feasible method, it is assumed that the energy storage root key generated by the hardware security module is , the root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, and the root key splitting instruction synchronously indicates that the minimum number of shares for restoring the energy storage root key is 4, wherein the 7 root key shares are respectively stored in the storage areas of their respective matching root key authority parties, specifically, root key share 1 is stored in the first storage area of the control terminal, root key share 2 is stored in the second storage area of the control terminal, root key share 3 is stored in the third storage area of the control terminal, root key share 4 is stored in the fourth storage area of the cloud, root key share 5 is stored in the fifth storage area of the cloud, root key share 6 is stored in the sixth storage area of the cloud, and root key share 7 is stored in the first storage area of the first associated terminal associated with the root key management object. If there are seven storage areas, the multiple target storage areas can be the first storage area, the second storage area, the third storage area and the fourth storage area, or the first storage area, the second storage area, the third storage area and the seventh storage area, or the first storage area, the second storage area, the fourth storage area and the fifth storage area, or the first storage area, the second storage area, the third storage area, the fourth storage area and the sixth storage area, etc. Therefore, without considering the access rights of the root key restorer to all storage areas, there can be multiple combinations of the multiple target storage areas, as long as the root key share of the multiple target storage areas after combination reaches at least the second root key share.
[0045] As an example, step 206 includes: according to the root key restoration operation triggered by the root key restoration party, based on the amount of the second root key share required to restore the energy storage root key, locating multiple target storage areas required to restore the energy storage root key in all storage areas, wherein the multiple target storage areas correspond to the multiple root key authority parties one-to-one, and the root key authority parties corresponding to different target storage areas may be the same or different.
[0046] Step 208 : When it is detected that the root key restorer has access rights to multiple target storage areas, the energy storage root key is restored based on the target root key shares selected from the multiple target storage areas.
[0047] It should be noted that, since multiple root key shares are physically isolated through different storage areas, the root key restorer does not have the ability to access all storage areas, that is, any root key restorer cannot have the ability to extract root key shares in all combinations of multiple target storage areas. Therefore, it is necessary to detect the access rights of multiple target storage areas in different combinations of areas for the root key restorer. For example, in one practicable method, assuming that the energy storage root key generated by the hardware security module is The root key splitting instruction indicates that the number of shares of the energy storage root key split is 7, and the root key splitting instruction simultaneously indicates that the minimum number of shares for restoring the energy storage root key is 4. The root key restoring party is the management and control terminal, wherein the root key restoring party has access rights to root key share 1, root key share 2, and root key share 3 of its own storage area, and has access rights to root key share 7 of the cloud storage area. It is then determined that the root key restoring party has access rights to multiple target storage areas, wherein the access rights of the root key restoring party to different storage areas can be pre-set based on the restorer identity information of the root key restoring party. For example, when the root key restoring party needs to access a storage area other than its own terminal, it can be detected based on the identity information of the root key restoring party whether the root key restoring party is in the access whitelist of the terminal to which the storage area to be accessed belongs.
[0048] As an example, step 208 includes: when it is detected that the root key restoration party has access rights to multiple target storage areas, the target root key shares selected from the multiple target storage areas are sent to the hardware security module of the energy storage system, and the hardware security module is controlled to restore the multiple target root key shares to obtain the energy storage root key.
[0049] For example, in one practicable manner, when executing the key splitting process, the hardware security module can construct an m-1 degree polynomial to split the energy storage root key into multiple root key shares, wherein a root key share can be understood as a fixed Coordinates, where The value of comes from the data of local operation of the energy storage cabinet, operation and maintenance environment or cloud interaction under the specified rules, that is, the share generation data of different root key shares, The value of is calculated by polynomial. Assuming m is 4, it means that only when the root key is restored, 4 fixed After the coordinates are obtained and polynomial interpolation is performed, the hardware security module can successfully execute the root key recovery process and restore the energy storage root key.
[0050] In the above-mentioned root key management method for the energy storage system, the control terminal of the energy storage system first performs real-time detection on the energy storage system, and after detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein the management authority of the energy storage root key is jointly held by multiple root key authority parties who manage the energy storage system, and the management authority of the root key shares split from the energy storage root key is held by different root key authority parties respectively, and the management authority held by different root key authority parties is isolated from each other. The multiple root key authority parties include the root key management object that manages the energy storage system, the root key user object that uses the energy storage system, and the control and management of the energy storage system. At least two of the four parties, namely, the terminal and the cloud providing the energy storage system cloud service, can realize splitting the energy storage root key into multiple root key shares managed by at least two root key authority parties related to the energy storage system, and then storing each root key share in a storage area managed by the respective matching root key authority party, wherein the amount of the first root key share stored in any storage area is less than the amount of the second root key share required to restore the energy storage root key, thereby storing the multiple root key shares in storage areas respectively managed by different root key authority parties, and then locating and restoring the energy storage root key in all storage areas according to the root key restoration operation triggered by the key restoration party The energy storage root key is restored based on the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas. Since the root key shares managed by the multiple root key authority parties are isolated from each other, and the root key shares corresponding to the root key shares managed by any one root key authority party cannot be independently restored to obtain the energy storage root key, upon receiving the root key restoration request, it is necessary to collaborate with at least two of the root key management object, the root key user object, the control terminal, and the cloud to locate the multiple target storage areas required to restore the energy storage root key. Ultimately, the energy storage root key is restored by extracting multiple target root key shares from the multiple target storage areas managed by the root key authority parties. This prevents the root key from being leaked due to an attack on a single root key authority party, thus achieving the purpose of securely managing the root key at the software level. This overcomes the technical drawbacks of relatively high hardware costs and the risk of leaking the root key when the device is attacked due to relying on single hardware encryption. Therefore, the management effect of the energy storage system root key management is improved from two dimensions: saving hardware costs and improving the security of root key management.
[0051] In one embodiment, Figure 2 As shown, the multiple root key shares include multiple root key management shares jointly managed by the control terminal and the root key management object and root key usage shares used by the root key usage object; the energy storage root key is split into multiple root key shares, including:
[0052] Step 302: Obtain the share configuration information corresponding to the control terminal, the root key management object, and the root key usage object, as well as the permission level information corresponding to each of the control terminal, the root key management object, and the root key usage object. The share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key.
[0053] It should be noted that in a process where only the control terminal, the root key management object and the root key management user object are involved as root key authority parties and jointly participate in the root key authority management, the control terminal can simultaneously set the total amount of root key shares required to split the energy storage root key when generating the key splitting instruction, and set in detail the amount of root key shares that can be managed by different root key authority parties.
[0054] As an example, step 302 includes: extracting the share configuration information commonly required by the management and control terminal, the root key management object and the root key usage object in the root key splitting instruction, and extracting the authority level information corresponding to the management and control terminal, the root key management object and the root key usage object in the root key splitting instruction, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key.
[0055] Step 304: Split the energy storage root key into multiple preset root key shares according to the share configuration information;
[0056] As an example, step 304: control the hardware security module to split the energy storage root key into multiple preset root key shares identified by the share configuration information using a preset key splitting algorithm, wherein the share configuration information can specifically be 7, 8 or 9, etc. It can be understood that the preset root key share refers to the root key share that has not yet established a mapping relationship with any root key authority.
[0057] Step 306: Divide the multiple preset root key shares according to the share mapping relationship between the multiple preset root key shares and the authority level information to obtain multiple root key management shares and root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority under the total root key share amount.
[0058] It should be noted that, due to the different security capabilities of different root key authority parties, different authority levels can be set for different root key authority parties based on different root key authority parties, and a share mapping relationship between different authority levels and preset root key shares can be established, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority under the total root key share, that is, different authority levels correspond to different numbers of root key shares obtained by splitting. For example, in one feasible method, all root key authority parties include the management and control terminal, the supplier who manages the energy storage root key, and the customer site administrator who uses the energy storage root key, wherein the authority levels corresponding to the management and control terminal and the customer site administrator are both identified as level 2, and the authority level corresponding to the supplier who manages the energy storage root key is identified as 3, then the 7 root key shares are configured in the order of 2, 3 and 2 to the management and control terminal, the supplier and the customer site administrator.
[0059] As an example, step 306 includes: according to the share mapping relationship between multiple preset root key shares and authority level information, a preset number of preset root key shares are divided for the management and control terminal, the root key management object and the root key usage object, to obtain multiple root key management shares and root key usage shares.
[0060] In this embodiment, in an application scenario involving the participation of a control terminal, a root key management object, and a root key user in energy storage root key management, if the control terminal is required to control the hardware security module to execute the energy storage root key splitting process, the total number of root key shares required to be divided for the energy storage root key can be determined based on the share configuration information generated by the control terminal, thereby splitting the energy storage root key into multiple preset root key shares. Furthermore, considering the different security protection capabilities of different root key authority holders, a share mapping relationship can be established between the permission level information of different root key authority holders generated by the control terminal and the multiple preset root key shares to clarify the root key share components of the second management authority that different root key authority holders should have. This can achieve the purpose of sequentially allocating the multiple preset root key shares, taking security into consideration, for the purpose of permission management by different root key authority holders. Therefore, while improving the management effectiveness of the root key management of the energy storage system, the security of the root key management of the energy storage system is further improved.
[0061] In one embodiment, the multiple root key management shares include a first root key management share managed by the management and control terminal; the multiple preset root key shares are divided according to a share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the multiple root key usage shares, including:
[0062] According to the share mapping relationship, the first root key management share component corresponding to the control terminal is determined; the system authentication information and system installation information generated by the control terminal in the process of managing the energy storage system are obtained; the first share generation data is extracted from the system authentication information, and the second share generation data is extracted from the system installation information; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is divided into multiple preset root key shares to obtain.
[0063] It should be noted that the first root key management share managed by the control terminal can be completely stored locally in the control terminal, or part of the first root key management share can be stored locally in the control terminal, and the other part of the first root key management share can be stored in the cloud, and the first root key management share of this part can be obtained through the interaction between the control terminal and the cloud. At this time, the control terminal and the cloud both serve as root key authority parties, that is, multiple root key authority parties include the control terminal, the cloud, the root key management object and the root key user object.
[0064] It should be noted that, through the share mapping relationship, the first root key management share component managed by the control terminal can be queried, which can be obtained by identifying the specific field in the root key splitting instruction. For example, in one implementable method, assuming that the identified field is 2, the first root key management share component managed by the control terminal is 2, wherein the system authentication information is used to represent the relevant content of the cloud authentication process when the energy storage system goes online for the first time. The first share generation data can specifically be the first random value generated for the first time online. The system installation information is used to represent the relevant content of the energy storage system during the installation process, which can specifically be the system installation log. The second share generation data can specifically be the installation time in the system installation log.
[0065] As an example, the first root key management share component managed by the control terminal is queried in a share mapping table constructed based on the share mapping relationship; the system installation information generated by the control terminal during the installation of the energy storage system is obtained, and the system authentication information sent by the cloud to the control terminal during the authentication of the energy storage system to the cloud is obtained; the installation time is extracted from the system installation information as the first share generation data, and the random value is extracted from the system authentication information as the second share generation data; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is divided into multiple preset root key shares to obtain.
[0066] In this embodiment, in the process of dividing the first root key management share managed by the control terminal, the divided first root key management share is divided into a first root key management share and a second root key management share, wherein the management authority of the first root key management share is held by the control terminal, and the management authority of the second root key management share is held by the cloud. That is, the first root key management share managed by the control terminal is further divided into root key shares jointly managed by the control terminal and the cloud, and share generation data is generated respectively using different operating information of the energy storage system, thereby ensuring the accurate division of the first root key management share managed by the control terminal. Therefore, it lays the foundation for improving the management effect of the root key management of the energy storage system.
[0067] In one embodiment, the plurality of root key management shares include a second root key management share managed by a root key management object; the plurality of preset root key shares are divided according to a share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the plurality of root key usage shares, including:
[0068] According to the share mapping relationship, the second root key management share component corresponding to the root key management object is determined; the system hard-coded information set by the root key management object on the energy storage system is obtained; the third share generation data is extracted from the system hard-coded information; according to the first query information input by the root key management object, the fourth share generation data is queried and obtained; according to the second root key management share component, the third share generation data and the fourth share generation data, the second root key management share is divided into multiple preset root key shares.
[0069] It should be noted that, through the share mapping relationship, the second root key management share component managed by the root key management object can be queried and obtained. The system hard-coded information is used to characterize sensitive parameters in the source code, which can be passwords or configuration parameters, etc. The first query information is used to query the non-public technical files stored in the management and control terminal. It can be understood that both the system hard-coded information and the first query information are independently set by the root key management object. The storage rules are private and cannot be known by other objects. Then, in the share generation data acquisition stage corresponding to the second root key management share, only the root key management object can obtain specific third share generation data and fourth share generation data, where the third share generation data can be a hard-coded value, and the fourth share generation data can be a second random value stored in the non-public technical file.
[0070] As an example, a second root key management share component managed by a root key management object is queried in a share mapping table constructed based on a share mapping relationship; system hard-coded information set by the root key management object on the energy storage system is obtained; the hard-coded value stored in the system hard-coded information is used as the third share generation data; the first query information input by the root key management object is used as an index to locate the non-public technical file, and the second random value stored in the non-public technical file is used as the fourth share generation data, wherein the first query information can specifically be query path information for querying the second random value; according to the second root key management share component, the third share generation data and the fourth share generation data, the second root key management share is obtained by dividing the plurality of preset root key shares.
[0071] In this embodiment, in the process of dividing the second root key management share managed by the root key management object, the divided second root key management share is divided into a third root key management share and a fourth root key management share. The third share generation data for generating the third root key management share is hard-coded in the source code by the root key management object and cannot be directly read during the actual operation of the energy storage system. It can only be returned by the root key management object after being accessed through a specific access interface to generate the fourth share generation data for the fourth root key management share. The query path information for querying the second random value is solely known by the root key management object. Therefore, both the third share generation data and the fourth share generation data are private, thereby ensuring the precise division of the second root key management share managed by the root key management object. Therefore, it lays the foundation for improving the management effect of the root key management of the energy storage system.
[0072] In one embodiment, based on the share mapping relationship between the preset root key shares and the permission level information, multiple preset root key shares are divided to obtain a root key management share and multiple root key usage shares, including:
[0073] According to the share mapping relationship, the root key usage share component corresponding to the root key usage object is determined; the system login information set by the root key usage object on the energy storage system is obtained; the fifth share generation data is extracted from the system login information; according to the key generation time of the energy storage root key, the target battery status information associated with the key generation time is queried in the battery status information of the energy storage system; according to the target battery status information, the sixth share generation data is generated; according to the root key usage share component, the fifth share generation data and the sixth share generation data, the root key usage share is divided into multiple preset root key shares to obtain.
[0074] It should be noted that, through the share mapping relationship, the root key usage share component managed by the root key management object can be queried, wherein the system login information is used to represent the login content of the client system logging into the energy storage system, which may specifically include the login password and login welcome message, etc. It can be understood that the system login information is usually used to prevent the system service from being counterfeited, and is a measure for users to identify the authenticity of the service. The system login information is entered by the root key usage object in the account management and stored in the database. The fifth share generation data can be specifically the first fixed value set in the system login information. The battery status information is used to represent the operating status of the battery, which may specifically be the health of the battery cluster or the average voltage of the battery cluster. Since the battery status information will change over time, it has a certain value at a certain point in time. This feature can be used to combine the battery status information of the energy storage system with the root key splitting process, which is responsible for generating data as part of the root key share. In the process of splitting the energy storage root key, in order to split the root key usage share, the management and control terminal will first obtain the battery health status (State of Health (SOH) curve, and although the battery health status curve will have certain differences with different algorithms, no matter in the aging curve lookup table or real-time correction query, there must be only one value for the same battery cell or corresponding cluster statistical information at the same time. Therefore, by setting a specific correlation between the generation time of the energy storage root key and the battery health status curve, the query can obtain the unique target battery status information, and then rely on the target battery status information to generate the sixth share generation data. For example, in an implementable method, assuming that the key generation time point A is later than the first collection time of the battery SOH curve, the battery status information is the value of the battery status information on the SOH curve at each time point. The SOH value collected at the collection time point can then be used as the target battery status information by default for the SOH value corresponding to the collection time point closest to the key generation time A, and the sixth share generation data can be generated based on the SOH value according to the preset rules. For example, in another feasible method, assuming that the key generation time point is B, the average voltage of the battery cluster in the real-time curve collected at the key generation time point B can be used as the battery status information, and the sixth share generation data can be generated based on the average voltage according to the preset rules. It can be understood that the preset rules for generating the sixth share generation data based on the target battery status information can be hard-coded in the database or stored in the database in advance as source code.
[0075] As an example, the third root key management share component used by the root key usage object is queried in a share mapping table constructed based on the share mapping relationship; the system login information set by the root key usage object on the energy storage system is obtained; the second fixed value is extracted from the system login information as the fifth share generation data; multiple information collection time points of the battery status information of the energy storage system are obtained, and the multiple information collection time points are respectively subtracted from the key generation time point to obtain multiple time difference values, and the battery status information corresponding to the information collection time point with the smallest time difference value among the multiple time difference values is used as the target battery status information; the third fixed value is extracted from the target battery status information as the sixth share generation data; according to the root key usage share component, the fifth share generation data and the sixth share generation data, the root key usage share is obtained by dividing the multiple preset root key shares.
[0076] In this embodiment, in the process of dividing the root key usage share managed by the root key usage object, the divided root key usage share is divided into a first part of the root key usage share and a second part of the root key usage share, wherein the fifth share generation data of the first part of the root key usage share is generated by extracting the system login information independently set by the root key usage object, and the sixth share generation data of the second part of the root key usage share is generated by combining the uniqueness of the battery status information at a single point in time and finally generated after the root key usage object alone knows the preset query rules and generation rules. Therefore, the fifth share generation data and the sixth share generation data are both private, thereby ensuring the precise division of the root key usage share managed by the root key usage object, thereby laying the foundation for improving the management effect of the root key management of the energy storage system.
[0077] In one practicable manner, referring to Figure 3 , Figure 3This is a schematic diagram of the process of splitting the energy storage root key, wherein the root key shares obtained by splitting the energy storage root key can specifically be root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6 and root key share x7. In combination with the above embodiment, the first share generation data of the root key share x1 is obtained by cloud transmission when the hardware is first put on the cloud, wherein the cloud is persistently stored in the database, and the first share generation data extracted from the system authentication information can be extracted in accordance with the cloud-specified rules based on the device identification, or it can be an ordered number automatically calculated based on time; the second share generation data of the root key share x2 is extracted at the installation time of the system installation information, which can only be obtained locally. It can be understood that it can be obtained when the customer site administrator has local file read permission, and the security time is usually saved in the installation log file Or in the database, the operation and maintenance phase usually attempts to obtain the installation time for positioning; the third root key share generation data of root key share x3 is hard-coded in the source code and held by the root key management object. It only supports returning after accessing a specific interface through the key splitting process; the fourth root key share generation data of root key share x4 and root key share x5 can be extracted from different files in the non-public technical folder, and the query path is only known to the root key management object; the sixth share generation data of root key share x6 is obtained in combination with the battery status information of the energy storage system, and the seventh share generation data of root key share x7 is set by the root key user object in the system login information of the energy storage system. The acquisition method is only known to the root key user object. In this way, the energy storage root key can be split into 7 root key shares, stored in the storage area of different terminals, and managed by the corresponding root key authority.
[0078] In one practicable manner, in one embodiment, storing each root key share in a storage area managed by a corresponding root key authority includes:
[0079] Selection step: select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in a storage area managed by the root key authority identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0080] As an example, the selection step is: randomly selecting any one root key share from multiple root key shares as the target root key share; determining the storage area managed by the root key authority that stores the target root key share based on the share identification information of the target root key share, and storing the target root key share in the storage area, and returning to the execution step: randomly selecting any one root key share from multiple root key shares as the target root key share.
[0081] In this embodiment, the root key authority and storage area that manages different root key shares are determined through the share identification information corresponding to each root key share, and all root key shares are stored in a one-to-one corresponding storage area. In the subsequent energy storage root key restoration scenario, different root key restoration parties can extract the corresponding root key shares based on their access rights to restore the energy storage root key. This further lays the foundation for improving the management effect of the root key management of the energy storage system.
[0082] In one embodiment, according to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required for restoring the energy storage root key are located in all storage areas, including:
[0083] Extract the identity information of the root key restorer in the root key restore operation; determine the first target storage area in all storage areas that stores the first root key management share; generate the share path information of the target root key usage share required to restore the energy storage root key based on the identity information; determine the second target storage area in all storage areas that stores the target root key usage share based on the share path information; and use the first target storage area and the second target storage area together as multiple target storage areas.
[0084] It should be noted that, through the identity information of the root key restorer, a part of the root key share that can be restored by the root key restorer can be determined, so that the share path information for restoring the part of the root key share can be further generated, so as to extract the part of the root key share from the designated storage area for restoring the energy storage root key, and in combination with the other part of the root key share managed by the control terminal, the energy storage root key can be successfully restored. For example, in one practicable method, it is assumed that the energy storage root key generated by the hardware security module is The root key splitting instruction indicates that the number of shares of the energy storage root key to be split is 4, among which the storage area of the first associated terminal associated with the root key management object stores two root key shares, and the storage area of the control terminal stores three root key shares. Then, four root key shares are randomly selected from these five root key shares to restore the energy storage root key. Among them, the share path information is used to identify different paths in the storage area of the first associated terminal that store different root key shares. The root key restoration operation can be manually triggered or automatically triggered by the root key restoration party.
[0085] As an example, the identity information of the root key restorer is extracted in the root key restoration operation; based on the root key restoration operation, a query is automatically triggered for the first target storage area storing the first root key management share in all storage areas; based on the identity information and the restoration information input by the root key restorer, the share path information of the target root key usage share required to restore the energy storage root key is generated; using the share path information as an index, the second target storage area storing the target root key usage share in all storage areas is queried; and the first target storage area and the second target storage area are collectively regarded as multiple target storage areas.
[0086] In this embodiment, through the collaboration between the management and control terminal and the root key restoration party, the first target storage area and the second target storage area of the root key share required to restore the energy storage root key are located in all storage areas. This can achieve the purpose of accurately locating the target storage area where the energy storage root key can be restored after the root key restoration party triggers the root key restoration operation, thereby laying the foundation for the subsequent accurate restoration of the energy storage root key.
[0087] In one practicable manner, referring to Figure 4 , Figure 4 The following are schematic diagrams showing the scenarios of energy storage root key restoration by different root key restoration parties, where (a) is a schematic diagram of the scenario of root key restoration by the root key management object, (b) is a schematic diagram of the scenario of root key restoration by the root key use object, and (c) is a schematic diagram of the scenario of root key restoration by the root key theft object. Assuming that the energy storage root key is Figure 3 As shown, there are 7 root key shares, namely root key share x1, root key share x2, root key share x3, root key share x4, root key share x5, root key share x6 and root key share x7. Since the root key management object can successfully restore 5 of the 7 root key shares (root key share x1, root key share x2, root key share x3, root key share x4 and root key share x5), the root key management object can accurately restore the energy storage root key; since the root key usage object can successfully restore the 7 root keys The four root key shares in the share (root key share x1, root key share x2, root key share x6 and root key share x7) are included in the share. Therefore, the root key user can accurately restore the energy storage root key. Since the root key theft object can neither obtain root key share x3, root key share x4 and root key share x5, nor can it obtain root key share x6 and root key share x7, and cannot even invade the cloud to obtain root key share x1, it cannot have access to the storage area of the four root key shares, and therefore cannot successfully restore the energy storage root key.
[0088] In one embodiment, determining, based on the share path information, the second target storage area storing the target root key usage share among all storage areas includes:
[0089] According to the identity information, the restoration level information of the root key restoration party is queried; and according to the restoration level information, a second target storage area storing the target root key usage share is determined among all storage areas.
[0090] It should be noted that different root key restorers have different restoration capabilities. Although more root key shares used for energy storage root key restoration does not mean an increase in restoration capability, it can improve the robustness of restoring the energy storage root key to a certain extent. For example, root key restorer y1 can only obtain four root key shares, while root key restorer y2 can obtain six root key shares. Therefore, even if root key restorer y2 cannot obtain any two of the six root key shares, it can still guarantee the share level of the energy storage root key. Therefore, considering the identities of different root key restorers, different restoration levels can be opened for different root key restorers. For example, in one feasible method, a root key restorer with a high authority level can know all second target storage areas that store the target root key usage share, while a root key restorer with a low authority level can only know part of the second target storage areas that store the target root key usage share.
[0091] As an example, the root key restoration level information is queried using the identity information as an index; based on the restoration level information, all storage areas selected to store the target root key usage share are used as the second target storage area.
[0092] In this embodiment, in the process of determining the second target storage area for storing the target root key usage share, different restoration levels can be appropriately configured for the root key restorer based on the identity of the root key restorer, so that the root key restorer can obtain different amounts of root key shares for energy storage root key restoration, thereby realizing dynamic control of the restoration authority of different root key restorers, thereby improving the management flexibility of the root key management of the energy storage system.
[0093] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0094] Based on the same inventive concept, embodiments of the present application also provide a root key management device for an energy storage system for implementing the aforementioned root key management method for an energy storage system. The solution provided by this device is similar to the solution described in the aforementioned method. Therefore, the specific limitations of one or more embodiments of the root key management device for energy storage systems provided below can be found in the aforementioned limitations of the root key management method for energy storage systems, and will not be further elaborated here.
[0095] In an exemplary embodiment, Figure 5 As shown, a root key management device for an energy storage system is provided, which is applied to a control terminal of the energy storage system, including: a splitting module 401, a storage module 402, a determination module 403 and a restoration module 404, wherein:
[0096] A splitting module 401 is configured to, upon detecting that an energy storage system has generated an energy storage root key, split the energy storage root key into multiple root key shares, wherein a first management authority for the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority for their respective corresponding root key shares, the multiple second management authorities being isolated from each other, and the multiple root key authority parties including at least two of the following: a root key management object that manages the energy storage system, a root key user object that uses the energy storage system, a control terminal of the energy storage system, and a cloud provider that provides cloud services for the energy storage system;
[0097] A storage module 402 is configured to store each root key share in a storage area managed by a respective matching root key authority, wherein the amount of first root key shares stored in any storage area is less than the amount of second root key shares required to restore the energy storage root key;
[0098] A determination module 403 is configured to locate, in all storage areas, multiple target storage areas required for restoring the energy storage root key according to the root key restoration operation triggered by the root key restoration party, wherein the multiple target storage areas correspond one-to-one to the multiple root key authority parties;
[0099] The restoration module 404 is configured to restore the energy storage root key based on target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to multiple target storage areas.
[0100] In one embodiment, the multiple root key shares include multiple root key management shares jointly managed by the management and control terminal and the root key management object and root key usage shares used by the root key usage object; the splitting module 401 is further used to:
[0101] Obtain the share configuration information corresponding to the management and control terminal, the root key management object, and the root key usage object, as well as the authority level information corresponding to the management and control terminal, the root key management object, and the root key usage object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; according to the share configuration information, split the energy storage root key into multiple preset root key shares; according to the share mapping relationship between the multiple preset root key shares and the authority level information, divide the multiple preset root key shares to obtain multiple root key management shares and root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any root key authority under the total amount of root key shares.
[0102] In one embodiment, the plurality of root key management shares include a first root key management share managed by the management and control terminal; and the splitting module 401 is further configured to:
[0103] According to the share mapping relationship, the first root key management share component corresponding to the control terminal is determined; the system authentication information and system installation information generated by the control terminal in the process of managing the energy storage system are obtained; the first share generation data is extracted from the system authentication information, and the second share generation data is extracted from the system installation information; according to the first root key management share component, the first share generation data and the second share generation data, the first root key management share is divided into multiple preset root key shares to obtain.
[0104] In one embodiment, the plurality of root key management shares include a second root key management share managed by a root key management object; and the splitting module 401 is further configured to:
[0105] According to the share mapping relationship, the second root key management share component corresponding to the root key management object is determined; the system hard-coded information set by the root key management object on the energy storage system is obtained; the third share generation data is extracted from the system hard-coded information; according to the first query information input by the root key management object, the fourth share generation data is queried and obtained; according to the second root key management share component, the third share generation data and the fourth share generation data, the second root key management share is divided into multiple preset root key shares.
[0106] In one embodiment, the splitting module 401 is further configured to:
[0107] According to the share mapping relationship, the root key usage share component corresponding to the root key usage object is determined; the system login information set by the root key usage object on the energy storage system is obtained; the fifth share generation data is extracted from the system login information; according to the key generation time of the energy storage root key, the target battery status information associated with the key generation time is queried in the battery status information of the energy storage system; according to the target battery status information, the sixth share generation data is generated; according to the root key usage share component, the fifth share generation data and the sixth share generation data, the root key usage share is divided into multiple preset root key shares to obtain.
[0108] In one embodiment, the storage module 402 is further configured to:
[0109] Selection step: select a target root key share from multiple root key shares; obtain the share identification information of the target root key share; store the target root key share in a storage area managed by the root key authority identified by the share identification information, and return to execute the selection step until all root key shares are selected.
[0110] In one embodiment, the determining module 403 is further configured to:
[0111] Extract the identity information of the root key restorer in the root key restore operation; determine the first target storage area in all storage areas that stores the first root key management share; generate the share path information of the target root key usage share required to restore the energy storage root key based on the identity information; determine the second target storage area in all storage areas that stores the target root key usage share based on the share path information; and use the first target storage area and the second target storage area together as multiple target storage areas.
[0112] In one embodiment, the determining module 403 is further configured to:
[0113] According to the identity information, the restoration level information of the root key restoration party is queried; and according to the restoration level information, a second target storage area storing the target root key usage share is determined among all storage areas.
[0114] Each module in the root key management device of the energy storage system can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0115] In an exemplary embodiment, an energy storage system is provided, which includes a management and control terminal of the energy storage system. The internal structure diagram of the management and control terminal of the energy storage system can be as follows: Figure 6 As shown. The management and control terminal of the energy storage system includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. The processor of the management and control terminal of the energy storage system is used to provide computing and control capabilities. The memory of the management and control terminal of the energy storage system includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the management and control terminal of the energy storage system is used to exchange information between the processor and external devices. The communication interface of the management and control terminal of the energy storage system is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, it realizes a root key management method for an energy storage system. Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the control terminal of the energy storage system to which the solution of the present application is applied. The control terminal of a specific energy storage system may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0116] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.
[0117] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0118] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A root key management method for an energy storage system, characterized in that: A control terminal applied to an energy storage system, the method comprising: After detecting that the energy storage system generates an energy storage root key, the energy storage root key is split into multiple root key shares, wherein a first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least a root key management object that manages the energy storage system, a root key usage object that uses the energy storage system, and the management and control terminal, and the multiple root key shares include multiple root key management shares jointly managed by the management and control terminal and the root key management object and root key usage shares used by the root key usage object, and the multiple root key management shares and the root key usage shares are different; Store each root key share in a storage area managed by its corresponding root key authority; According to the root key restoration operation triggered by the root key restoration party, multiple target storage areas required to restore the energy storage root key are located in all storage areas; When it is detected that the root key restoration party has access rights to the multiple target storage areas, the energy storage root key is restored based on the target root key shares selected from the multiple target storage areas.
2. The method according to claim 1, characterized in that Splitting the energy storage root key into multiple root key shares includes: Obtaining the share configuration information corresponding to the control terminal, the root key management object, and the root key usage object, as well as obtaining the permission level information corresponding to each of the control terminal, the root key management object, and the root key usage object, wherein the share configuration information is used to identify the total amount of root key shares obtained by splitting the energy storage root key; Splitting the energy storage root key into a plurality of preset root key shares according to the share configuration information; According to the share mapping relationship between the multiple preset root key shares and the authority level information, the multiple preset root key shares are divided to obtain the multiple root key management shares and the root key usage shares, wherein the share mapping relationship is used to characterize the root key share components allocated to any of the root key authority parties under the total amount of the root key shares.
3. The method according to claim 2, characterized in that The multiple root key management shares include a first root key management share managed by the control terminal; and the dividing the multiple preset root key shares according to the share mapping relationship between the preset root key share and the permission level information to obtain the root key management share and the multiple root key usage shares includes: Determine, according to the share mapping relationship, a first root key management share component corresponding to the control terminal; Obtaining system authentication information and system installation information generated by the control terminal in the process of managing the energy storage system; extracting first share generation data from the system authentication information, and extracting second share generation data from the system installation information; The first root key management share is obtained by dividing the plurality of preset root key shares according to the first root key management share component, the first share generation data and the second share generation data.
4. The method according to claim 2, characterized in that The multiple root key management shares include a second root key management share managed by the root key management object; and dividing the multiple preset root key shares according to the share mapping relationship between the preset root key share and the permission level information to obtain the root key management share and the multiple root key usage shares includes: Determining, according to the share mapping relationship, a second root key management share component corresponding to the root key management object; Obtaining system hard-coded information set by the root key management object on the energy storage system; extracting third share generation data from the system hard-coded information; querying and obtaining fourth share generation data according to the first query information input by the root key management object; The second root key management share is obtained by dividing the plurality of preset root key shares according to the second root key management share component, the third share generation data and the fourth share generation data.
5. The method according to claim 2, characterized in that The dividing the plurality of preset root key shares according to the share mapping relationship between the preset root key shares and the permission level information to obtain the root key management share and the plurality of root key usage shares includes: Determine, according to the share mapping relationship, a root key usage share component corresponding to the root key usage object; Obtaining system login information set by the root key usage object on the energy storage system; Extracting fifth share generation data from the system login information; According to the key generation time of the energy storage root key, querying the battery status information of the energy storage system for target battery status information associated with the key generation time; generating sixth share generation data according to the target battery status information; The root key usage share is obtained by dividing the root key usage share among the multiple preset root key shares according to the root key usage share component, the fifth share generation data and the sixth share generation data.
6. The method according to claim 1, wherein Storing each root key share in a storage area managed by a corresponding root key authority includes: Selecting step: selecting a target root key share from the plurality of root key shares; Obtaining share identification information of the target root key share; The target root key share is stored in a storage area managed by the root key authority identified by the share identification information, and the selection step is returned to be executed until all root key shares are selected.
7. The method according to claim 3, characterized in that The root key restoration operation triggered by the root key restoration party locates multiple target storage areas required for restoring the energy storage root key in all storage areas, including: Extracting the identity information of the root key restoration party during the root key restoration operation; Determine a first target storage area among all the storage areas for storing the first root key management share; Generate, based on the identity information, share path information of the target root key usage share required to restore the energy storage root key; Determine, according to the share path information, a second target storage area storing the target root key usage share in all the storage areas; The first target storage area and the second target storage area are collectively referred to as the plurality of target storage areas.
8. The method according to claim 7, characterized in that The determining, according to the share path information, a second target storage area in all the storage areas for storing the target root key usage share includes: Querying the restoration level information of the root key restoration party based on the identity information; A second target storage area storing the target root key usage share is determined among all the storage areas according to the restoration level information.
9. A root key management device for an energy storage system, characterized in that: A control terminal for an energy storage system, comprising: a splitting module for splitting the energy storage root key into multiple root key shares after detecting that the energy storage system generates an energy storage root key, wherein the first management authority of the energy storage root key is jointly held by multiple root key authority parties that manage the energy storage system, and the multiple root key authority parties hold second management authority of their respective corresponding root key shares, and the multiple second management authorities are isolated from each other, and the multiple root key authority parties include at least a root key management object that manages the energy storage system, a root key usage object that uses the energy storage system, and the management and control terminal; the multiple root key shares include multiple root key management shares jointly managed by the management and control terminal and the root key management object, and root key usage shares used by the root key usage object, and the multiple root key management shares and the root key usage shares are different; A storage module, configured to store each root key share in a storage area managed by the respective matching root key authority; A determination module, configured to locate, in all storage areas, a plurality of target storage areas required for restoring the energy storage root key according to a root key restoration operation triggered by a root key restoration party; The restoration module is used to restore the energy storage root key according to the target root key shares selected from the multiple target storage areas when it is detected that the root key restoration party has access rights to the multiple target storage areas.
10. An energy storage system comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.