Trusted connection method, power distribution terminal, power distribution master station and trusted connection system
Hardware-level trusted boot and signature are achieved through the ESAM chip, and integrity measurement reports are generated, which solves the unreliability problem of the distribution terminal startup environment, ensures the secure access of the distribution terminal and the main station, and reduces the risk of illegal access and malicious attacks.
Patent Information
- Application Number
- CN202510753276.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-10-10
AI Technical Summary
In the existing technology, the trusted startup process of the power distribution terminal relies on software verification, which is vulnerable to attacks and difficult to ensure the authenticity and integrity of the terminal startup environment, resulting in unreliable access authentication and the risk of tampering or forgery.
The ESAM chip is used to implement hardware-level trusted boot, generate an integrity measurement report, and hardware-sign the report through the ESAM chip. The power distribution master station verifies the signature and allows access to ensure the legitimacy of the terminal identity and status.
It ensures the security of the terminal startup process from a physical level, reduces the risk of illegal access and malicious attacks, and ensures a secure and reliable connection between the terminal and the main station.
Smart Images

Figure CN120767997A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of trusted computing technology, and in particular to a trusted connection method, a power distribution terminal, a power distribution master station, and a trusted connection system. Background Art
[0002] Secure and trusted access to distribution terminals is a critical component in ensuring the stable operation of power systems. In existing technologies, the connection between distribution terminals and master distribution stations relies on the security of the terminal startup process and the reliability of access authentication. However, the trusted startup process of traditional distribution terminals often relies on software-level verification. However, this software verification mechanism is vulnerable to attacks and carries the risk of tampering or bypassing, making it difficult to ensure the authenticity and integrity of the terminal startup environment. Therefore, improving the trustworthiness of distribution terminals from startup to operation and achieving secure access between distribution terminals and master distribution stations has become a pressing technical issue. Summary of the Invention
[0003] The purpose of the embodiments of the present application is to provide a trusted connection method, a distribution terminal, a distribution master station and a trusted connection system, which can effectively improve the reliability of the distribution terminal from startup to operation and realize the secure access between the distribution terminal and the distribution master station.
[0004] To achieve the above objectives, a first aspect of an embodiment of the present application provides a trusted connection method, which is applied to a communication connection between a power distribution terminal and a power distribution master station, and the method includes:
[0005] The power distribution terminal completes trusted startup through the ESAM chip and generates an integrity measurement report;
[0006] The power distribution terminal initiates a connection request to the power distribution master station and submits a signature integrity measurement report signed by the ESAM chip;
[0007] The power distribution master station receives the signature integrity measurement report sent by the power distribution terminal;
[0008] The power distribution master station allows the power distribution terminal to access after verifying that the signature integrity measurement report is passed.
[0009] Compared with the prior art, the trusted connection method provided by the embodiment of the present application has the following beneficial effects: the distribution terminal implements hardware-level trusted startup and generates an integrity measurement report through the ESAM chip. Compared with the prior art solutions that rely on software verification or lack security verification in the startup phase, it can ensure from the physical layer that the terminal startup process has not been tampered with, and ensure that the initial operating environment is trustworthy; at the same time, the ESAM chip hardware signs the integrity measurement report, so that the distribution master station can quickly confirm the legitimacy of the terminal identity and status by verifying the signature. Only when the distribution master station confirms the legitimacy of the terminal identity and status is it allowed to access the distribution terminal, effectively solving the problem of unreliable access authentication and easy forgery or tampering in the prior art, realizing a secure and trusted connection between the terminal and the master station, and reducing the risk of illegal terminal access and malicious attacks.
[0010] In some embodiments, the power distribution terminal includes an ESAM chip and an MCU; the power distribution terminal completes trusted boot through the ESAM chip and generates an integrity measurement report, including:
[0011] After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip performs integrity measurement on the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result is passed, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program.
[0012] Performing integrity measurement on the operating system kernel and the initialized file system in the main Flash by using the U-Boot boot program to generate a second measurement result, and loading the operating system kernel if the second measurement result is a pass;
[0013] Running the init measurer to perform integrity measurement on the init process file, the inittab configuration file, the integrity detection module, and the configuration file of the integrity detection module in the operating system file based on the PCR value of the ESAM chip, generating a third measurement result, and starting the init process in the operating system file if the third measurement result is a pass;
[0014] The init process starts the integrity measurement module according to the inittab configuration file, and the integrity measurement module performs integrity measurement on the operating system to obtain an integrity measurement report.
[0015] In some embodiments, after the integrity measurement module performs integrity measurement on the operating system and obtains an integrity measurement report, the method further includes:
[0016] The power distribution terminal starts the risk identification and safety protection module. If the risk identification and safety protection module finds an abnormality, it encrypts the abnormality details and uploads them to the power distribution master station and decides whether to start the relevant application according to the preset configuration file.
[0017] In some embodiments, the method further comprises:
[0018] The power distribution terminal receives a dynamic credit value initialization instruction issued by the power distribution master station, and obtains an initial credit value of the control instruction according to the dynamic credit value initialization instruction;
[0019] During operation, the power distribution terminal updates the dynamic credit value of the control instruction in real time according to the historical normal operation times and the historical abnormal operation times of the power distribution terminal;
[0020] The power distribution terminal determines whether to allow the control instruction to be executed according to the dynamic credit value.
[0021] In some embodiments, the method further comprises:
[0022] After the power distribution terminal establishes a connection with the power distribution master station, the power distribution terminal generates a session key and a freshness factor through the ESAM chip;
[0023] The power distribution terminal performs encryption operation on the control instruction sent to the power distribution master station using the session key and embeds the freshness factor in the control instruction;
[0024] When receiving the response instruction returned by the power distribution master station, the power distribution terminal verifies the legitimacy of the freshness factor in the response instruction. If the verification fails, the control instruction is discarded and the abnormal behavior is recorded.
[0025] In some embodiments, the method further comprises:
[0026] In a system safety state, the power distribution terminal generates a reference snapshot library of the file system in a whitelist manner through the integrity detection module;
[0027] The power distribution terminal periodically triggers the integrity detection module to compare and verify the current file system status with the benchmark snapshot library;
[0028] If unauthorized file changes are detected in the current file system, the power distribution terminal determines that there is a security risk in the current file system and triggers a risk alarm.
[0029] To achieve the above-mentioned object, a second aspect of an embodiment of the present application provides a power distribution terminal, which is applied to the trusted connection method as described in the first aspect above, and the power distribution terminal includes:
[0030] Trusted boot module, used to complete trusted boot through ESAM chip and generate integrity measurement report;
[0031] The sending module is used to initiate a connection request to the power distribution master station and submit a signature integrity measurement report signed by the ESAM chip.
[0032] In some embodiments, the trusted startup module includes an ESAM chip and an MCU; the trusted startup module is specifically configured to:
[0033] After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip performs integrity measurement on the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result is passed, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program.
[0034] Performing integrity measurement on the operating system kernel and the initialized file system in the main Flash by using the U-Boot boot program to generate a second measurement result, and loading the operating system kernel if the second measurement result is a pass;
[0035] Running the init measurer to perform integrity measurement on the init process file, the inittab configuration file, the integrity detection module, and the configuration file of the integrity detection module in the operating system file based on the PCR value of the ESAM chip, generating a third measurement result, and starting the init process in the operating system file if the third measurement result is a pass;
[0036] The init process starts the integrity measurement module according to the inittab configuration file, and the integrity measurement module performs integrity measurement on the operating system to obtain an integrity measurement report.
[0037] To achieve the above-mentioned purpose, a third aspect of the embodiments of the present application provides a power distribution master station, which is applied to the trusted connection method described in the first aspect above. The power distribution master station includes:
[0038] A receiving module, configured to receive a signature integrity measurement report sent by the power distribution terminal;
[0039] A verification module is used to verify that the signature integrity measurement report is passed and then allow the power distribution terminal to access.
[0040] To achieve the above objectives, a fourth aspect of an embodiment of the present application proposes a trusted connection system, which includes: the power distribution terminal as described in the second aspect and the power distribution master station as described in the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 This is a flow chart of a trusted connection method provided by an embodiment of the present application;
[0042] Figure 2 yes Figure 1 A flowchart of step S101 in FIG.
[0043] Figure 3 This is a connection diagram between the ESAM chip and the MCU;
[0044] Figure 4 It is a startup flow chart of the trusted software system of the power distribution terminal;
[0045] Figure 5 This is a schematic diagram of the generation and verification of the snapshot library;
[0046] Figure 6 This is a structural diagram of a power distribution terminal in an embodiment of the present application;
[0047] Figure 7 This is a structural diagram of a power distribution master station provided in an embodiment of the present application;
[0048] Figure 8 This is a schematic diagram of the trusted connection system structure provided in an embodiment of the present application. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0050] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application.
[0051] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature specified as "first" or "second" may explicitly or implicitly include one or more of such features. Throughout this application, unless otherwise specified, "plurality" means two or more.
[0052] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal connections between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.
[0053] First, let’s analyze some of the terms used in this application:
[0054] Distribution terminals are core equipment installed at distribution network sites, such as feeder terminal units (FTUs) and distribution terminal units (DTUs). They are used to monitor line operating status in real time, collect data such as voltage and current, and perform operations such as remote opening and closing. They upload data to the distribution master station through the communication network and receive instructions from the master station to realize automatic control and fault handling of the distribution network, ensuring the safe and stable operation of the power grid.
[0055] The distribution master station is the core control center of the distribution network automation system. It is responsible for receiving and processing data uploaded by the distribution terminals and issuing control instructions to realize the monitoring and management of the distribution network.
[0056] Trusted Computing generally refers to ensuring the trustworthiness of a computing platform from startup to operation through hardware and software mechanisms, including measurement, verification, isolation and other technologies.
[0057] A trusted connection typically ensures the authenticity of both parties' identities, as well as the confidentiality and integrity of data, during communication. Trusted connections are an extension of trusted computing. Trusted computing ensures the trustworthiness of the terminal itself (e.g., no tampering or vulnerabilities), while trusted connections ensure the trustworthiness of the communication process between the terminal and the master station (e.g., preventing forged instructions and replay attacks).
[0058] Compared with power IoT devices, IoT devices on the user side of the distribution network have obvious differences in network security vulnerabilities due to their uneven security protection capabilities and the reliance of communication between components on the Internet. Specifically, the terminal backend may use heterogeneous components from different suppliers, resulting in increased risks of routing attacks, man-in-the-middle attacks, etc. The network connections between different components and services in the terminal need to go through a bridging device, which can easily lead to data tampering and abnormal actions. The allocation of low-power wireless network addresses does not follow universal standards, making malicious behavior difficult to track and privacy data easy to be stolen. Some terminals cannot afford high-intensity cryptographic algorithms due to limited computing resources, and the lack of key sharing and security verification mechanisms makes interactive information easy to forge or tamper with. The firmware lacks effective detection tools and has memory and logic vulnerabilities that can easily be implanted with malicious code. The IoT communication protocol stack has security access vulnerabilities. In addition, the back-end code of mobile applications is easy to be reverse-engineered due to the open source nature of the platform, manufacturer version compatibility issues and developers' focus on functionality rather than security.
[0059] Secure and trusted access to distribution terminals is a critical component in ensuring the stable operation of power systems. In existing technologies, the connection between distribution terminals and master distribution stations relies on the security of the terminal startup process and the reliability of access authentication. However, the trusted startup process of traditional distribution terminals often relies on software-level verification. However, this software verification mechanism is vulnerable to attacks and carries the risk of tampering or bypassing, making it difficult to ensure the authenticity and integrity of the terminal startup environment. Therefore, improving the trustworthiness of distribution terminals from startup to operation and achieving secure access between distribution terminals and master distribution stations has become a pressing technical issue.
[0060] See also Figure 1 , Figure 1 This is an optional flowchart of the trusted connection method provided in the embodiment of the present application. Figure 1 The method is applied to the communication connection between the power distribution terminal and the power distribution master station, which may include but is not limited to steps S101 to S104.
[0061] Step S101: The power distribution terminal completes trusted startup through the ESAM chip and generates an integrity measurement report;
[0062] Step S102: The power distribution terminal initiates a connection request to the power distribution master station and submits a signature integrity measurement report signed by the ESAM chip;
[0063] Step S103: The power distribution master station receives the signature integrity measurement report sent by the power distribution terminal;
[0064] Step S104: The power distribution master station verifies the signature integrity measurement report and allows the power distribution terminal to access.
[0065] In steps S101 to S104 shown in the embodiment of the present application, the distribution terminal implements hardware-level trusted startup and generates an integrity measurement report through the ESAM chip. Compared with the existing technology that relies on software verification or lacks security verification in the startup phase, it can ensure that the terminal startup process has not been tampered with from the physical layer, and ensure that the initial operating environment is trustworthy; at the same time, the ESAM chip hardware signs the integrity measurement report, so that the distribution master station can quickly confirm the legitimacy of the terminal identity and status by verifying the signature. Only when the distribution master station confirms the legitimacy of the terminal identity and status will it allow the distribution terminal to access, effectively solving the problem of unreliable access authentication and easy forgery or tampering in the existing technology, realizing a secure and trusted connection between the terminal and the master station, and reducing the risk of illegal terminal access and malicious attacks.
[0066] In step S101 of some embodiments, the power distribution terminal includes an ESAM chip and an MCU; the ESAM chip (Embedded Secure Access Module) is an embedded security chip with a built-in national secret algorithm (such as SM2 / SM3 / SM4) and an unalterable key storage area for implementing hardware-level security protection. Trusted Boot can be a mechanism that verifies the integrity of system components (such as boot programs, kernels, and configuration files) step by step to ensure that the system has not been tampered with from startup to operation. The integrity measurement report can be a file that records the hash values of key system components, which is used to prove the credibility of the current state of the power distribution terminal.
[0067] See also Figure 2 In some embodiments, step S101 may include but is not limited to steps S201 to S204:
[0068] Step S201: After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip measures the integrity of the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result passes, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program.
[0069] Step S202: Perform integrity measurement on the operating system kernel and the initialized file system in the main Flash through the U-Boot bootloader to generate a second measurement result. If the second measurement result is passed, the operating system kernel is loaded;
[0070] Step S203, running the init meter, based on the PCR value of the ESAM chip, integrity measurement of the init process file in the operating system file, the inittab configuration file, the integrity detection module and the configuration file of the integrity detection module, generating the third measurement result, if the third measurement result is passed, starting the init process in the operating system file;
[0071] Step S204, the init process starts the integrity measurement module according to the inittab configuration file, and the integrity measurement module measures the integrity of the operating system to obtain the integrity measurement report.
[0072] In step S201 of some embodiments, the system refers to the power distribution terminal software system, the SPI Flash is a kind of serial peripheral interface flash, stores U-Boot and other start-up code.U-Boot (Universal Boot Loader) is the boot program of embedded system, responsible for loading operating system kernel.Integrity measurement refers to verifying whether it is tampered by calculating component hash value and comparing with reference value.
[0073] Specifically, after the power distribution terminal software system is powered on, the ESAM chip of the power distribution terminal first establishes a communication link with the SPIFlash through the SPI interface, actively reads the U-Boot boot program data stored in the SPIFlash. Then, the ESAM chip uses the built-in hash algorithm (such as SM3) to calculate the U-Boot boot program data, compares the obtained hash value with the U-Boot reference hash value stored in the chip in advance, completes the integrity measurement, and generates the first measurement result. If the two hash values are consistent, that is, the first measurement result is passed, the ESAM chip sends a power supply control signal to the power module, and the power module receives the signal and starts to supply power to the MCU, triggering the MCU to load the U-Boot boot program from the SPI Flash.
[0074] When the power distribution terminal software system starts, the ESAM chip first verifies the integrity of the U-Boot boot program, and only after the verification is passed, the power supply for the MCU is provided, to ensure that the MCU loads the U-Boot that has not been tampered with, and to guarantee the device startup security from the source. Realize the hardware level startup security protection, prevent the malicious tampered U-Boot program from being loaded and running, avoid the device being implanted with malicious code by hackers in the startup phase, and improve the ability of the device to resist attacks.
[0075] In step S202 of some embodiments, the main Flash is a large-capacity flash memory for storing a large amount of data such as an operating system kernel, an application program, a configuration file, etc., and is an important component for storing core data of the device. The operating system kernel is the core part of the operating system, responsible for managing system resources, providing a hardware abstraction layer, coordinating process running, and other key functions, and is the basis for the operation of the operating system. The initialization file system is a temporary file system (such as initramfs.img) used in the early stage of operating system kernel startup, containing necessary drivers, configuration files and startup scripts, assisting the kernel to complete initialization work, and mounting the real file system.
[0076] After the MCU successfully loads the U-Boot boot program, the U-Boot boot program reads the operating system kernel and initialization file system data initramfs.img stored in the main Flash according to the preset configuration and instructions. U-Boot uses a hash algorithm (such as SHA-256) to calculate the hash of the read data, compares the obtained hash value with the corresponding reference hash value stored in advance, completes the integrity measurement, and generates a second measurement result. If the hash values match, i.e. the second measurement result is passed, U-Boot starts to perform the operation of loading the operating system kernel, loads the kernel code into memory and starts the kernel to run.
[0077] After the U-Boot boot program is verified to be safe, it further checks the integrity of the operating system kernel and the initialization file system, loads the operating system kernel after confirming that there is no error, and ensures the security of the operating environment of the operating system kernel. The embodiments of the present application can ensure that the operating system kernel running on the device has not been illegally modified or implanted with malicious code, avoid security problems such as system crash and data leakage caused by kernel vulnerabilities, and improve the stability and security of system operation.
[0078] Please refer to Figure 3 , Figure 3 is a connection diagram of the ESAM chip and the MCU, the ESAM chip, the gating chip and the U-Boot module (i.e. the U-Boot boot program, Figure 3The ESAM chip (not shown) is located on the SPIFlash, and the ESAM chip and the gating chip are connected in series. The MCU is located on the main Flash and is connected to the SPI Flash, ESAM chip, and gating chip via the SPI interface. The gating chip is connected between the ESAM chip and the MCU to control the connection direction and thus the access rights of the SPI Flash. After the power distribution terminal software system is powered on, the ESAM chip is connected to the SPI Flash. The ESAM chip is first started and used to measure the integrity of the U-Boot boot program. The power module (i.e., the GPIO control power module) is controlled by the ESAM chip and is used to supply power to the MCU. After the U-Boot boot program passes the measurement, the ESAM chip triggers the gating chip to switch to a state where the MCU and SPI Flash are connected, allowing the MCU to load the U-Boot boot program located on the SPI Flash.
[0079] In some embodiments of the present application, the ESAM chip primarily implements support for trusted technology through two core functions: first, adding a Platform Configuration Register (PCR) to record integrity measurement results at each stage of system startup to ensure that the information cannot be tampered with; second, providing a trusted signature service, using a built-in cryptographic algorithm to digitally sign key data to ensure the trustworthiness of the data source. During the startup phase, the ESAM chip's primary task is to measure the operating system kernel loader U-Boot (i.e., the aforementioned U-Boot boot loader). By calculating the hash value of the U-Boot boot loader and comparing it with a baseline value, a trusted startup starting point is established. The subsequent trusted measurement of the power distribution terminal software system is then completed by the trusted protection software.
[0080] From a hardware architecture perspective, the microcontroller unit (MCU) in the power distribution terminal connects to the SPI Flash and ESAM chip via the SPI interface, with the selector chip controlling the data connection direction. After the system is powered on, the ESAM security chip first boots up and establishes a connection with the SPI Flash, performing integrity measurements on the U-Boot module stored on the SPI Flash. If the measurements pass, the ESAM security chip controls the power module to supply power to the MCU, enabling the MCU to connect to the SPI Flash and load U-Boot. U-Boot then proceeds to measure the operating system kernel and the initialization file system (initramfs.img) on the main Flash. If verification passes, the kernel is loaded, triggering the execution of the trusted security software system. If the ESAM security chip fails to pass the U-Boot measurements, the MCU loses power, and the power distribution terminal boot process terminates.
[0081] In step S203 of some embodiments, the init measurer is a tool program specially used for integrity measurement of the operating system key files, which can ensure the security of the operating system key processes and configuration files. The PCR value refers to the value of the Platform Configuration Register stored in the ESAM chip, which is used to record the integrity measurement results of each stage in the system startup process and has the characteristics of accumulation and tamper resistance. The init process is the first user-level process (PID = 1) after the operating system is started, which is responsible for starting other system processes and services and is the basis for the normal operation of the system. The inittab configuration file is the configuration file of the init process, which defines key parameters such as processes to be started during system startup and run levels, and controls the system startup process. The integrity detection module is a software module used to detect whether the operating system files have been tampered with in real time or periodically, and is an important part of system security protection.
[0082] After the operating system kernel is started, the init measurer is triggered to run. The init measurer first reads the PCR value in the ESAM chip, and on this basis, uses a hash algorithm to calculate the hash value of the init process file, the inittab configuration file, the integrity detection module and its configuration file in the operating system file. The calculation result is compared with the reference hash value of the corresponding file to generate a third measurement result. If the measurement result shows that the file hash value is consistent with the reference value, i.e. the third measurement result is passed, the init measurer sends a command to the system to start the init process in the operating system file, and the init process then starts to start other system services and processes according to the configuration.
[0083] Specifically, after the system is powered on, the ESAM chip immediately starts to perform an integrity measurement on the U-Boot file in the SPI Flash. It calculates the hash value of U-Boot and compares it with a pre-stored baseline hash value to determine if it has been tampered with. If the measurement passes, the MCU begins loading U-Boot. If not, the MCU loses power and the boot process terminates. After U-Boot is loaded, the MCU performs an integrity measurement on the operating system kernel and initramfs.img in the main Flash. Similarly, a hash comparison is used to confirm that the kernel and initramfs.img have not been illegally modified. If the measurement passes, the MCU loads the operating system kernel and initramfs.img. The initramfs.img serves as a temporary root file system, providing a user-mode runtime environment for the kernel. Within this environment, the actual operating system file system on the main Flash is mounted to the / mnt directory. The system then starts the init meter. Based on the measurement results recorded by the ESAM chip's PCR, the init meter verifies the init process file, the inittab configuration file, and the integrity check module and its configuration file within the actual operating system files. If all checks pass, the system will switch to the real file system root directory through the chroot command, start the init process, and start subsequent system programs according to the configuration to ensure the security of the service startup link; if the checks fail, the system will decide whether to stop the startup or continue the execution based on the preset configuration file options to flexibly respond to different security risk scenarios.
[0084] The embodiments of the present application can prevent key configuration files and process files of the operating system from being maliciously tampered with, prevent hackers from gaining control or disrupting system operation by modifying system configuration, and ensure that the system starts and runs safely as expected.
[0085] In step S204 of some embodiments, the integrity measurement report is a file that records information such as key files, process hash values, and measurement time of the operating system, and can be used to intuitively display the current integrity status of the system. After the init process is started, the integrity measurement module is found and started according to the instructions pre-set in the inittab configuration file. After being activated, the integrity measurement module traverses the key directories and files of the operating system according to the preset scanning rules, and hashes these files using a hash algorithm. The hash value, file path, measurement time, and other information of each file are integrated to finally generate an integrity measurement report, which can be stored locally on the device or uploaded to the power distribution master station.
[0086] The init process starts the integrity measurement module, which performs a comprehensive scan and measurement of the operating system, generating a detailed integrity measurement report that provides a basis for verifying the integrity of the power distribution terminal software system. By generating an integrity measurement report, the present embodiment of the application enables comprehensive monitoring of the operating system's operating status, facilitating the timely detection of security issues such as file tampering, providing strong support for subsequent security incident tracing and system repair, and further improving the system's security protection level.
[0087] Please refer to Figure 4 , Figure 4 This is a startup flow chart of the trusted software system of the power distribution terminal. In some embodiments, after the power distribution terminal software system is powered on, the ESAM chip first measures U-Boot, then loads U-Boot and uses it to measure the kernel and initramfs.img (i.e., initramfs) in the main Flash. After verification, the kernel and the temporary root file system initramfs.img are loaded. In the user-mode environment provided by initramfs.img, the system mounts the real file system to the / mnt directory, then starts the init measurer, verifies the init process, inittab configuration file, and integrity detection module based on the PCR value of the ESAM chip, switches to the root directory of the real file system, and starts the init process after passing. After the init process is started, the serial startup integrity measurement module is configured according to / etc / initab, the system integrity measurement is completed, and an integrity measurement report is generated. The ESAM chip signs the integrity measurement report and reports it to the power distribution master station.
[0088] In some embodiments, after the integrity measurement module performs integrity measurement on the operating system and obtains an integrity measurement report, the method also includes: the distribution terminal starts the risk identification and safety protection module. If the risk identification and safety protection module finds an abnormality, the abnormality details are encrypted and uploaded to the distribution master station and a decision is made whether to start the relevant application based on a preset configuration file.
[0089] Specifically, the risk identification and security protection module determines whether there are any abnormalities based on the integrity measurement report. If no abnormality is found (such as the file integrity check passes, the dynamic credit value is higher than the threshold), the system continues to start the application according to the preset process to ensure business continuity; if an abnormality is found, the abnormality details (such as abnormal file path, behavioral characteristics, credit decay value, etc.) are immediately encrypted and uploaded to the power distribution master station, and a decision is made based on the configuration whether to start the changed application, ultimately achieving trusted startup of the power distribution terminal software system. For example, the risk identification and security protection module can decide whether to start the relevant application based on the local pre-configured security policy (such as a mapping table of risk levels and disposal actions): if the abnormality risk is low (such as non-critical file modification), some applications are allowed to start, but sensitive operations are restricted; if the risk is high (such as core components are tampered with), the relevant program is refused to start, and the system isolation mechanism is triggered.
[0090] In step S102 of some embodiments, the connection request refers to an access request proactively sent by the distribution terminal to the distribution master station. The signed integrity measurement report can be a file generated by the ESAM chip during system startup and digitally signed by the integrity measurement report. The integrity measurement report records the hash values of key components such as the operating system and configuration files, verifying the authenticity of the system startup status. The digital signature ensures that the report has not been tampered with during transmission and originates from a legitimate terminal.
[0091] Specifically, after the distribution terminal completes the trusted startup and generates the integrity measurement report, it initiates a connection request to the distribution master station through a secure communication protocol (such as the TLS-encrypted TCP / IP protocol), and the request message carries the terminal identity. At the same time, the ESAM chip can call the built-in SM2 algorithm, use the private key stored in the chip to digitally sign the integrity measurement report, generate a signed integrity measurement report, and attach it to the connection request and send it. After receiving the request, the distribution master station first extracts the signed integrity measurement report, decrypts the signature using the pre-stored public key corresponding to the terminal ESAM chip, and obtains the report hash value. Then, the master station uses the same hash algorithm (such as SM3) to recalculate the hash value of the report content and compare the two hash values. If the two are consistent, and the hash value of each component in the report matches the terminal baseline hash value stored in the distribution master station, the verification is determined to be successful and the distribution terminal is allowed to access; if the hash value is inconsistent or there is an abnormality, the distribution master station denies access and records the security incident.
[0092] After the distribution terminal completes the trusted startup, the ESAM chip signs the integrity measurement report and sends it to the distribution master station along with the connection request.
[0093] In steps S103 and S104 of some embodiments, the distribution master station can decrypt the received signature integrity measurement report using the public key paired with the ESAM chip, recalculate the hash value of the signature integrity measurement report, compare it with the hash value obtained after decryption, and allow the distribution terminal to access after determining that the signature integrity measurement report is authentic and complete, thereby achieving secure access between the distribution terminal and the distribution master station.
[0094] The distribution master station verifies the authenticity and integrity of the report through public and private key decryption and hash comparison, and decides whether to allow the terminal access, thus achieving two-way identity authentication and data security verification. The embodiment of the present application can achieve strong identity authentication, data tamper-proofing and secure access control for the distribution terminal through the ESAM chip digital signature and master station hash verification mechanism, ensuring that only legitimate distribution terminals can access, the transmitted data is authentic and reliable, effectively preventing illegal equipment counterfeiting and malicious data tampering, avoiding "sick" distribution terminals from threatening the distribution network security, and significantly improving the overall security and operational stability of the system.
[0095] Furthermore, in malware attacks like Mirai, IoT devices on the user side of the distribution network face dual security threats: First, the brute force login phase generates a massive amount of abnormal behavior, such as frequent login credential verification failures; second, the control command forgery phase triggers security verification failures, including missing freshness factors, failure to pass random number verification, and abnormal operation patterns that violate user behavior profiles. These abnormal behaviors form the core basis for dynamic control command credit assessment, accurately quantifying the trustworthiness of commands in networked environments. The device abnormal behavior assessment system covers a three-tier architecture: terminal, cloud, and mobile application. The terminal layer monitors events such as command verification failures and abnormal firmware loading; the cloud layer tracks illegal API calls and data tampering; and the mobile application layer identifies risks such as unauthorized operations and abnormal logins. After a user successfully registers, the system assigns an initial credit value to their control commands. The security management system then uses a dynamic weighting algorithm to update the credit score in real time based on historical operation data. It is worth noting that when building botnets, attackers often use the same or nearby DNS gateways to spread malicious programs, resulting in spatial clustering of infected devices. Therefore, dynamic credit assessment requires the introduction of a group correlation analysis model to calculate the correlation between the credit of a single instruction and the overall credit of the system. For example, Bayesian networks or graph neural network algorithms can be used to comprehensively consider local abnormal behavior and the global security situation, and intelligently correct dynamic credit values. This will build a multi-level, adaptive instruction trust evaluation mechanism to effectively defend against automated attack threats.
[0096] In some embodiments, the distribution terminal receives a dynamic credit value initialization instruction issued by the distribution master station, and obtains the initial credit value of the control instruction based on the dynamic credit value initialization instruction; during operation, the distribution terminal updates the dynamic credit value of the control instruction in real time based on the historical normal operation times and historical abnormal operation times of the distribution terminal; the distribution terminal decides whether to allow the control instruction to be executed based on the dynamic credit value.
[0097] Specifically, after the distribution terminal completes trusted startup and successfully connects to the distribution master station, it receives a dynamic credit value initialization command from the master station, obtains the initial credit value of the control command, and updates the dynamic credit value in real time based on historical operation data during operation. This sequential setup further enhances the security of control command execution through a dynamic credit assessment mechanism, while ensuring terminal trustworthiness, and prevents illegal or abnormal commands from posing a threat to the distribution system.
[0098] In some embodiments, after the distribution terminal establishes a connection with the distribution master station, the distribution terminal generates a session key and a freshness factor through the ESAM chip; for the control instructions sent to the distribution master station, the distribution terminal uses the session key to perform encryption operations and embeds the freshness factor in the control instructions; when receiving the response instructions returned by the distribution master station, the distribution terminal verifies the legitimacy of the freshness factor in the response instructions. If the verification fails, the control instructions are discarded and the abnormal behavior is recorded.
[0099] After the distribution terminal completes trusted startup, passes master station access verification, and completes dynamic credit value initialization, to defend against threats such as forged control instructions and replay attacks in malware attacks such as Mirai, the terminal and the distribution master station establish a connection and rely on the hardware security capabilities of the ESAM chip to generate a session key and freshness factor. The control instructions sent to the master station are encrypted using the session key and embedded with the freshness factor to ensure the timeliness of the instructions. When receiving the master station's response instructions, the legitimacy of the freshness factor is strictly verified. If the verification fails, the instruction is immediately discarded and the abnormal behavior is recorded. The abnormal behavior data will be directly incorporated into the dynamic credit evaluation system and used as a historical abnormal operation count to participate in the real-time update of the dynamic credit value of the control instruction. If the freshness verification fails collectively on multiple terminals under the same DNS gateway, the system will identify potential attack risks through a group association analysis model and adjust the dynamic credit value of each control instruction based on the global security situation, thereby realizing a full-chain security protection closed loop from trusted access, secure communication to dynamic evaluation.
[0100] Most intrusion attacks, especially latent viruses, modify files in the system to allow malicious code to hide. The integrity detection module detects whether files in the system have been illegally modified and determines whether there is suspicious code or hacker intrusion. Figure 5 , Figure 5 This is a schematic diagram of the generation and verification of a snapshot library, wherein the file system is connected to the integrity detection module. In some embodiments, the method further includes: when the system is in a secure state, the power distribution terminal generates a baseline snapshot library for the file system using the integrity detection module in a whitelist manner; the power distribution terminal periodically triggers the integrity detection module to compare and verify the current file system status with the baseline snapshot library; if unauthorized file changes are detected in the current file system, the power distribution terminal determines that the current file system presents a security risk and triggers a risk alarm.
[0101] Specifically, when the system is in a secure state, the integrity detection module uses a whitelist mechanism to generate a baseline snapshot of the established file system and stores it in a baseline snapshot library, which serves as the basis for determining the file system's security status. This module automatically runs at system startup and, by comparing the current file system with the baseline snapshot library, detects whether programs and their configuration files have been illegally modified during the startup phase. If file changes are found to be outside the whitelist range, the module blocks the relevant program from starting based on the configuration file and sends an exception notification to the master station, thereby ensuring the security and reliability of the system startup process. Furthermore, the integrity detection module supports periodic automatic operation or can be triggered on demand by risk identification and security protection programs, monitoring file status changes in real time during system operation. Once unauthorized additions, deletions, or modifications are detected in the current file system, the system is determined to be at risk of security intrusion and an alarm mechanism is immediately triggered. Because the integrity detection module is capable of independent operation and does not rely on the ESAM security chip, it significantly reduces the cost of porting trusted protection software between different devices and improves the versatility and flexibility of security protection solutions.
[0102] To ensure the security of the integrity detection module, a dual-key system is used to build a defense-in-depth mechanism. During the system initialization phase, the administrator enters the policy configuration key and snapshot library key through a secure channel. Among them, the policy configuration key implements fully confidential storage of the module's configuration files, whitelist lists, and detection policy files to ensure the confidentiality of sensitive policy data during static storage and transmission; the snapshot library key digitally signs the file system's baseline snapshot library files to achieve tamper-proof protection and trusted verification of file checksums. The dual-key mechanism uses cryptographic means to build an access control barrier. Without authorization, attackers cannot decrypt and obtain whitelist rules and detection policy logic, nor can they forge or tamper with file hash checksums in the snapshot library, thereby ensuring the confidentiality, integrity, and non-repudiation of the core data of the integrity detection module, and effectively resisting security threats such as malicious code injection and configuration file tampering.
[0103] In summary, this invention, through systematic innovation, builds a highly reliable security protection system adapted to the characteristics of power distribution terminals. At the trusted boot level, relying on a three-level chained integrity measurement mechanism ("power on boot - kernel loading - application execution"), combined with the hardware-level verification capabilities of the ESAM chip, verifies the legitimacy of program images throughout their entire lifecycle, strengthening terminal security. During runtime, a dynamic risk assessment process based on sensitive file changes and network behavior enables terminals to proactively detect intrusion threats and promptly synchronize risk status to the master station, enabling proactive defense against security incidents. In terms of architectural design, a user-mode application architecture is employed, enabling compatibility with a variety of power distribution terminals through a modular design without modifying the operating system kernel, significantly improving the solution's versatility. In terms of performance optimization, through hash algorithm hardware acceleration, incremental measurement, and differential snapshot storage, system load is strictly controlled to less than 10%, effectively addressing the performance bottleneck of trusted computing in resource-constrained environments. Ultimately, this forms a complete security solution encompassing boot security, dynamic monitoring, flexible deployment, and efficient operation.
[0104] See also Figure 6 , Figure 6 It is a structural diagram of a distribution terminal in an embodiment of the present application, which is applied to the above-mentioned trusted connection method; the distribution terminal includes: a trusted startup module 601, which is used to complete the trusted startup through the ESAM chip and generate an integrity measurement report; a sending module 602, which is used to initiate a connection request to the distribution master station and submit a signature integrity measurement report signed by the ESAM chip, so that the distribution master station allows the distribution terminal to access after verifying that the signature integrity measurement report is passed.
[0105] The trusted boot module includes an ESAM chip and an MCU. The trusted boot module is specifically used to:
[0106] After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip performs integrity measurement on the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result is a pass, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program. The U-Boot boot program performs integrity measurement on the operating system kernel and the initialization file system in the main Flash and generates a second measurement result. If the second measurement result is a pass, the operating system kernel is loaded. The init measurer is run and, based on the PCR value of the ESAM chip, performs integrity measurement on the init process file, inittab configuration file, integrity detection module, and configuration file of the integrity detection module in the operating system file and generates a third measurement result. If the third measurement result is a pass, the init process in the operating system file is started. The init process starts the integrity measurement module according to the inittab configuration file. The integrity measurement module performs integrity measurement on the operating system and obtains an integrity measurement report.
[0107] The power distribution terminal applies a trusted connection method, and its specific implementation method is basically the same as the specific embodiment of the trusted connection method described above, which will not be repeated here.
[0108] See also Figure 7 , Figure 7 It is a structural diagram of the distribution master station provided in an embodiment of the present application. The distribution master station is applied to the above-mentioned trusted connection method; the distribution master station includes: a receiving module 701, which is used to receive the signature integrity measurement report sent by the distribution terminal; a verification module 702, which is used to verify that the signature integrity measurement report is passed and then allow the distribution terminal to access.
[0109] The power distribution master station applies a trusted connection method, and its specific implementation method is basically the same as the specific embodiment of the trusted connection method mentioned above, which will not be repeated here.
[0110] See also Figure 8 , Figure 8 This is a schematic diagram of the structure of the trusted connection system provided by an embodiment of the present application. In some embodiments, the power distribution terminal completes trusted boot through the ESAM chip and generates an integrity measurement report; the power distribution terminal signs the integrity measurement report through the ESAM chip; and the power distribution master station accesses the power distribution terminal based on the signed integrity measurement report.
[0111] Those skilled in the art will appreciate that embodiments of the application can be readily used as software, hardware, or a combination of software and hardware. In a software embodiment, the methods can be tangibly embodied in a machine-readable storage medium with instructions to implement the embodiments of the methods of the present application. Alternatively, in a hardware embodiment, hardware including custom
[0112] The present application is described in reference to the flowchart and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing system or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0113] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0114] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.
[0115] Those skilled in the art will appreciate that implementing all or part of the methods in the above embodiments can be accomplished by way of computer program instructions, which can be stored in a computer-readable storage medium, which cause a computer or other programmable apparatus to perform a series of operations to produce the steps of the above-described embodiments. The storage medium can be magnetic, optical, Read-Only Memory (ROM), Random Access Memory (RAM), or the like.
[0116] The above is a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications are also considered to be within the scope of protection of the present application.
Claims
1. A trusted connection method, characterized in that: Applied to the communication connection between the power distribution terminal and the power distribution master station, the method includes: The power distribution terminal completes trusted startup through the ESAM chip and generates an integrity measurement report; The power distribution terminal initiates a connection request to the power distribution master station and submits a signature integrity measurement report signed by the ESAM chip; The power distribution master station receives the signature integrity measurement report sent by the power distribution terminal; The power distribution master station allows the power distribution terminal to access after verifying that the signature integrity measurement report is passed.
2. The method according to claim 1, wherein The power distribution terminal includes an ESAM chip and an MCU; the power distribution terminal completes trusted boot through the ESAM chip and generates an integrity measurement report, including: After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip performs integrity measurement on the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result is passed, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program. Performing integrity measurement on the operating system kernel and the initialized file system in the main Flash by using the U-Boot boot program to generate a second measurement result, and loading the operating system kernel if the second measurement result is a pass; Running the init measurer to perform integrity measurement on the init process file, the inittab configuration file, the integrity detection module, and the configuration file of the integrity detection module in the operating system file based on the PCR value of the ESAM chip, generating a third measurement result, and starting the init process in the operating system file if the third measurement result is a pass; The init process starts the integrity measurement module according to the inittab configuration file, and the integrity measurement module performs integrity measurement on the operating system to obtain an integrity measurement report.
3. The method according to claim 2, wherein After the integrity measurement module performs integrity measurement on the operating system and obtains an integrity measurement report, the method further includes: The power distribution terminal starts the risk identification and safety protection module. If the risk identification and safety protection module finds an abnormality, it encrypts the abnormality details and uploads them to the power distribution master station and decides whether to start the relevant application according to the preset configuration file.
4. The method according to claim 1, wherein The method further comprises: The power distribution terminal receives a dynamic credit value initialization instruction issued by the power distribution master station, and obtains an initial credit value of the control instruction according to the dynamic credit value initialization instruction; During operation, the power distribution terminal updates the dynamic credit value of the control instruction in real time according to the historical normal operation times and the historical abnormal operation times of the power distribution terminal; The power distribution terminal determines whether to allow the control instruction to be executed according to the dynamic credit value.
5. The method according to claim 1, wherein The method further comprises: After the power distribution terminal establishes a connection with the power distribution master station, the power distribution terminal generates a session key and a freshness factor through the ESAM chip; The power distribution terminal performs encryption operation on the control instruction sent to the power distribution master station using the session key and embeds the freshness factor in the control instruction; When receiving the response instruction returned by the power distribution master station, the power distribution terminal verifies the legitimacy of the freshness factor in the response instruction. If the verification fails, the control instruction is discarded and the abnormal behavior is recorded.
6. The method according to claim 1, wherein The method further comprises: In a system safety state, the power distribution terminal generates a reference snapshot library of the file system in a whitelist manner through the integrity detection module; The power distribution terminal periodically triggers the integrity detection module to compare and verify the current file system status with the benchmark snapshot library; If unauthorized file changes are detected in the current file system, the power distribution terminal determines that there is a security risk in the current file system and triggers a risk alarm.
7. A power distribution terminal, applied to the trusted connection method according to any one of claims 1 to 6, characterized in that: The power distribution terminal includes: Trusted boot module, used to complete trusted boot through ESAM chip and generate integrity measurement report; The sending module is used to initiate a connection request to the power distribution master station and submit a signature integrity measurement report signed by the ESAM chip.
8. The power distribution terminal according to claim 7, wherein: The trusted startup module includes an ESAM chip and an MCU; the trusted startup module is specifically used to: After the system is powered on, the ESAM chip of the power distribution terminal establishes a communication connection with the SPI Flash. The ESAM chip performs integrity measurement on the U-Boot boot program in the SPI Flash and generates a first measurement result. If the first measurement result is passed, the ESAM chip controls the power module to supply power to the MCU, triggering the MCU to load the U-Boot boot program. Performing integrity measurement on the operating system kernel and the initialized file system in the main Flash by using the U-Boot boot program to generate a second measurement result, and loading the operating system kernel if the second measurement result is a pass; Running the init measurer to perform integrity measurement on the init process file, the inittab configuration file, the integrity detection module, and the configuration file of the integrity detection module in the operating system file based on the PCR value of the ESAM chip, generating a third measurement result, and starting the init process in the operating system file if the third measurement result is a pass; The init process starts the integrity measurement module according to the inittab configuration file, and the integrity measurement module performs integrity measurement on the operating system to obtain an integrity measurement report.
9. A power distribution master station, applied to the trusted connection method according to any one of claims 1 to 6, characterized in that: The power distribution master station includes: A receiving module, configured to receive a signature integrity measurement report sent by the power distribution terminal; A verification module is used to verify that the signature integrity measurement report is passed and then allow the power distribution terminal to access.
10. A trusted connection system, characterized in that: The system comprises: the power distribution terminal according to any one of claims 7 to 8 and the power distribution master station according to claim 9.
Citation Information
Cited By
Power distribution terminal key management method and system based on trusted computing
CN121690575A