Substation active lockset control method and system based on WAPI network
The lock control method, which links WAPI network and operation counter, solves the security and flexibility problems of passive locks in substations, realizes intelligent lock control with high security and high reliability, adapts to the high-frequency operation requirements of substations, and has offline emergency synchronization capability.
Patent Information
- Application Number
- CN202511322948.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-11-25
AI Technical Summary
Existing passive locks in substations are inadequate in terms of security, intelligence, and flexibility. Furthermore, active locks are vulnerable to attacks in wireless communication environments, and their rigid key update mechanisms make them difficult to handle high-frequency operation scenarios.
An active lock control method based on WAPI network is adopted. Dynamic passwords are generated through a key management server. Combined with an operation counter and WAPI encrypted channel, the key and dynamic password are updated in a coordinated manner. In the event of network interruption, the system switches to offline emergency mode to ensure system availability and security.
It achieves high security and high reliability of substation equipment, adapts to high-frequency operation scenarios, has a closed-loop security link and high availability, prevents replay attacks, supports offline emergency synchronization, and improves the intelligence level of the system.
Smart Images

Figure CN121011027A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application provides a substation active lock control method and system based on a WAPI network, and belongs to the technical field of substation active lock control. BACKGROUND
[0002] At present, passive lock systems are mostly used in substations to control and manage the doors of substations, passageway doors, room doors and various equipment cabinet doors. The passive locks used do not require external power supply, and are completely dependent on the physical structure or passive technology of the lock to control locking or opening (such as mechanical keys, magnetic force, passive RFID). They have certain advantages in reliability and maintenance cost, but also have more disadvantages in the background of modern security needs and technological development, such as low security, vulnerable to physical attacks, physical mechanical keys easy to copy or misuse, especially when the key is lost or borrowed, there is a security risk. In addition, the physical lock has a single function, lacks intelligence, has no record and traceability function, cannot record the lock opening time, operator identity and other information, and when a security incident occurs, it will be difficult to trace the responsibility. Moreover, it does not support remote unlocking, temporary password generation or dynamic adjustment of permissions, has poor flexibility, and does not have functions such as anti-picking alarm and abnormal vibration detection, and cannot be linked with existing substation auxiliary control systems.
[0003] In view of the defects of the above-mentioned physical lock, it is proposed to apply active locks to smart grid construction to improve the intelligent level of equipment in substations. However, the active locks currently used have fixed passwords or dynamic password mechanisms that are updated periodically. The key update period is long in the traditional wireless communication (such as wifi) environment, the static key is easy to be brute-forced or replay attacked, and the dynamic password is usually updated based on time trigger, which is difficult to cope with high-frequency operation scenarios (such as intensive operation of substation operation and maintenance). The update mechanism is rigid and there is a risk of password reuse. In addition, the communication key and the unlocking password are generated independently, and there is a lack of linkage mechanism, which will cause the security link to be broken. SUMMARY
[0004] In order to solve the technical problems existing in the background art, the technical scheme adopted by the application is to provide a substation active lock control method based on a WAPI network, comprising the following control steps:
[0005] Step S1: deploying a key management server in the substation internal network, storing the lock unique identifier, permission policy and dynamic password algorithm parameters by the key management server, generating and issuing an initial key SK0 and a random salt value R0, synchronously initializing an emergency key pool, and pre-generating M groups of offline key-password pairs;
[0006] The lock terminal is started, a registration request is initiated to the key management server, lock identity and server legitimacy verification are performed, WAPI bidirectional authentication is completed, an initial session key SK0 and a random salt value R0 are obtained;
[0007] Step S2: The operator holds the mobile authorization terminal to verify the operator's identity through biological recognition, sends a lock opening request to the key management server, and the key management server calculates and generates a dynamic password, which is sent to the mobile authorization terminal through the WAPI encryption channel.
[0008] Step S3: The mobile authorization terminal sends a lock opening instruction to the lock terminal through a wireless network, and the lock terminal matches the lock opening instruction. If the matching is successful, the lock terminal drives the motor to open the lock and performs an update operation.
[0009] Step S4: When the number of lock terminal operations reaches a preset threshold K, the lock terminal sends a key update request to the key management server with the current operation counter N value, the key management server generates a new session key SK new and a salt value R new , and sends them to the lock terminal through the WAPI encryption channel.
[0010] The lock terminal updates the local SK current and the salt value R, so that SK current = SK new , R = R new , resets the emergency key pool, and synchronizes the operation counter N value to the key management server.
[0011] Step S5: When the lock terminal cannot establish a connection with the key management server, the system automatically switches to an offline mode, executes an offline emergency synchronization control method, uses the pre-generated emergency key pool to complete the lock opening operation, and synchronizes the operation records during the offline period after the network is restored, and updates the key state.
[0012] Step S6: The operation counter in the lock terminal is controlled to perform continuous verification, and the server and the lock terminal both record the N value, ensuring that the N value of each lock opening request strictly increases. If the N value received by the server deviates from the local record by more than a preset tolerance range, it is determined to be a potential replay attack or data tampering, and an anti-replay attack control is executed. The server immediately sends a security alarm to the operation and maintenance platform, and forcibly resets the session key of the lock terminal, so that the lock terminal enters a locked state.
[0013] The lock opening request data sent to the server in step S2 includes the lock ID and the operator's identity information.
[0014] The specific method for the key management server to calculate the dynamic password in step S2 is as follows:
[0015] The key management server verifies the operator's permissions based on the current session key SK. current The dynamic password is calculated using the operation counter value N and the salt value R, and the calculation formula is as follows:
[0016] ;
[0017] in:
[0018] P current The newly generated dynamic password for the lock;
[0019] SK current The current WAPI session key;
[0020] N is the current value of the operation counter;
[0021] R is a random salt value, which is periodically distributed by the key management server;
[0022] This is an XOR operation;
[0023] Hash uses the SM3 national cryptographic hash algorithm;
[0024] Finally, the key management server transmits the newly generated lock dynamic password P through the WAPI encrypted channel. current Distribute to mobile devices.
[0025] In step S3, the unlocking command sent from the mobile authorization terminal to the lock terminal specifically includes the dynamic password P. current And the value of the operation counter N.
[0026] The specific method for matching the unlocking command by the lock terminal in step S3 is as follows:
[0027] The lock terminal first verifies whether the received operation counter N value is consistent with the local counter to prevent replay attacks. If the operation counter N value is consistent, then the locally stored SK is used. current Calculate dynamic password P using N and R local and the received P current Comparison.
[0028] The update operation performed in step S3 specifically includes:
[0029] Operation counter increments: N new =N+1, and set N new Upload to the key management server;
[0030] Linked update check: If N mod K=0, where K is the threshold for the number of operations, a key update request is triggered.
[0031] The specific method for step S5 is as follows:
[0032] Step S5.1: The control key management server calculates and generates M sets of emergency key pairs SK. emergency P emergency The calculation formula is:
[0033] ;
[0034] Each key pair is associated with a pre-generated virtual counter value N. i 预生成 To ensure the continuous logic of the counter when unlocking offline, the emergency key pair is pre-stored to the lock terminal via a secure link;
[0035] Step S5.2: The lock terminal continuously monitors the WAPI network connection status. If three consecutive handshakes fail, it is determined that the network is interrupted.
[0036] The operator executes the emergency unlocking procedure by selecting the offline unlocking mode through a mobile authorization terminal and verifying their identity by entering biometric data.
[0037] The lock terminal retrieves the currently available key pair SK from the key pool. emergency P emergency and the corresponding virtual counter value N i 预生成 The user enters a dynamic password. After the lock terminal verifies that the password matches, it performs the unlocking operation, marks the key pair as used, and updates the local virtual counter.
[0038] ;
[0039] Step S5.3: After the lock terminal detects that the network has been restored, it immediately encrypts and uploads the following data from the offline period to the key management server:
[0040] The emergency key used is index i, and the virtual counter sequence {N}. i 预生成 N i+1 预生成 ...}, unlocking time, operator identity;
[0041] The key management server checks the uploaded virtual counter value N. i 预生成 If the sequence matches the pre-generated sequence, update the online counter value as follows:
[0042] ;
[0043] in, N represents the number of offline operations;
[0044] The key management server generates a new emergency key pool, distributes and replaces the key pairs already in use in the lock terminal. If a conflict is detected, an alarm is triggered and the key is forced to reset.
[0045] Step S5.4: When an abnormal state is encountered, the following handling strategy shall be executed:
[0046] When the remaining unused key pairs fall below the threshold, the lock terminal sends an alert to the key management server, prompting the administrator to replenish them. If the key pool is completely exhausted and the network is not restored, the lock terminal enters a locked state, allowing only physical keys to unlock.
[0047] If the counters of the key management server and the lock terminal are inconsistent, the record of the key management server shall prevail, and the N of the lock terminal shall be forcibly synchronized. local If malicious tampering is detected, the key pool will be cleared and a system-wide key update will be triggered.
[0048] The specific method for step S6 is as follows:
[0049] Step S6.1: The mobile authorization terminal sends an unlocking request to the lock terminal or key management server, including the following parameters:
[0050] Lock ID (unique identifier), current operation counter value N, dynamic password P current ;
[0051] Step S6.2: The key management server queries the latest record of N for this lock terminal. last The value is used to verify whether the received N value satisfies the strict increasing relationship N=N last +1. If the verification fails, it is determined to be a potential replay attack, triggering a security alarm and sending a locking command to the lock terminal.
[0052] Dynamic password validity verification is performed by the key management server based on the locally stored SK. current N, R recalculate dynamic password P local Compare the received P current With P local If they match, unlocking is allowed, and the server-side N is updated. last =N, if they do not match, it is determined that the password has been tampered with or forged, triggering an alarm and locking the lock;
[0053] Step S6.3: The lock terminal performs a counter synchronization check. The N value received by the lock terminal must match the locally stored N value. local Strict consistency, if N≠N local If the lock fails to open immediately and an anomaly is reported, a dynamic password comparison will be performed. The lock terminal uses the local SK. current N, R recalculate dynamic password P local and with the received Pcurrent The comparison is performed, and the unlocking action is executed and the counter is incremented only if the two match:
[0054] N local =N local +1;
[0055] Step S6.4: Determine the replay attack scenario and execute corresponding response measures. The specific method is as follows:
[0056] A replay attack scenario is determined when one of the following two conditions is met:
[0057] An attacker intercepts historical unlocking commands containing old N values and retransmits them; the server detects that N≤N last This triggers an alarm;
[0058] The attacker forged a jump value for N, and the server detected that N > N. last +1, indicating illegal tampering;
[0059] If the above replay attack scenario occurs, the following response measures will be implemented, including:
[0060] Short-term response: Lock the lock terminal to prevent further operations;
[0061] Force update session key SK current With salt value R, clear the existing emergency key pool;
[0062] Log recording: Records attack characteristics for security auditing and policy optimization;
[0063] Step S6.5: In offline mode, perform the following anti-replay response measures:
[0064] Emergency Key Pool Verification: When unlocking offline, use the pre-stored emergency key to verify SK. i emergency P i emergency Each emergency key is associated with a virtual counter value N. i 预生成 This ensures that the N value for offline operations increases continuously.
[0065] Synchronous recovery verification: After the network is restored, the lock terminal uploads the N value sequence during the offline period. The key management server verifies whether the N sequence is continuous and without repetition. If there is a conflict, the relevant key pair is marked as invalid.
[0066] A substation active interlocking control system based on a WAPI network includes an interlocking terminal, a key management server, and a mobile authorization terminal, wherein:
[0067] The lock terminal integrates a WAPI communication module, a dynamic password generator, and an operation counter.
[0068] The key management server is specifically deployed on the substation's intranet and is responsible for WAPI two-way authentication and key distribution.
[0069] The mobile authorization terminal is specifically a handheld device for maintenance personnel, which supports receiving dynamic passwords through a WAPI encrypted channel;
[0070] The lock terminal, key management server, and mobile authorization terminal all achieve secure unlocking and dynamic access control through encrypted communication via the WAPI network.
[0071] The present invention has the following advantages over the prior art:
[0072] I. The active lock control scheme for substations based on WAPI networks proposed in this invention can achieve full-process security control from identity authentication and dynamic password generation to key management, meeting the high security and high reliability requirements of the power industry for smart locks; it has the following characteristics: a) Closed-loop security link: WAPI encrypted communication, dynamic password algorithm, and operation counter linkage form a multi-layer protection; b) High-frequency scenario adaptation: Key update mechanism based on operation count adapts to the intensive operation and maintenance needs of substations; c) High availability design: Through emergency key pool and offline synchronization, the system availability is guaranteed in extreme environments.
[0073] II. Effectively enhances system security: The dynamic password provided by this invention is updated based on the number of operations, avoiding the regularity vulnerabilities of time-based dynamic passwords; the WAPI key is strongly associated with the dynamic password, so a single leak does not affect the overall system security;
[0074] Third, in high-frequency operation scenarios (such as substation maintenance period), the control method adopted by this invention can adaptively shorten the key update cycle and support offline emergency mode to ensure availability under extreme conditions.
[0075] Fourth, the lock control method provided by this invention has undergone rigorous mathematical logic and cryptographic design, which can realize strong correlation update between the key and the dynamic password, and can meet the dual requirements of high-frequency operation and high security in substation scenarios. Attached Figure Description
[0076] The present invention will be further described below with reference to the accompanying drawings:
[0077] Figure 1 This is a schematic diagram of the substation active interlock control system based on WAPI network of the present invention;
[0078] Figure 2 This is a flowchart illustrating the steps involved in information interaction between the lock terminal, server, and mobile terminal in the substation active lock control system of the present invention.
[0079] Figure 3 This is a flowchart illustrating the steps of the offline emergency synchronization control mechanism of the substation active interlock control system of the present invention.
[0080] Figure 4 This is a flowchart illustrating the steps of the substation active interlock control system to resist replay attacks according to the present invention. Detailed Implementation
[0081] like Figures 1 to 4 As shown, this invention addresses the problem of low security in existing active lock control systems for substations by providing a WAPI network-based active lock control scheme. It employs a collaborative update mechanism combining the WAPI communication protocol and a dynamic cryptographic algorithm. By triggering the linked update of the key and dynamic password through a certain number of operations, the security of substation equipment access is improved. Furthermore, this operation-triggered update mechanism addresses the high-frequency, high-security access control requirements in substation scenarios, achieving intelligent security management of the substation system.
[0082] The active lock control system for substations based on a WAPI network provided by this invention includes a lock terminal, a key management server, and a mobile authorization terminal, wherein:
[0083] Lock terminal: integrates WAPI communication module, dynamic password generator, operation counter, and electromagnetic shielding shell;
[0084] Key management server: Deployed in the substation intranet, responsible for WAPI two-way authentication and key distribution;
[0085] Mobile Authorization Terminal: A handheld device for maintenance personnel that supports receiving dynamic passwords via a WAPI encrypted channel;
[0086] The aforementioned lock terminal, key management server, and mobile authorization terminal are all connected via a WAPI network.
[0087] This system consists of three parts: a lock terminal, a key management server, and a mobile authorization terminal. It achieves secure unlocking and dynamic access control through WAPI encrypted communication. The control method employed includes the following steps:
[0088] Step S1: System Initialization and Two-Way Authentication: The key management server is deployed on the substation intranet, storing the unique identifier of the lock, permission policies, and dynamic password algorithm parameters. It generates and distributes the initial key SK0 and random salt value R0, synchronously initializes the emergency key pool, and pre-generates M sets of offline key-password pairs. The lock terminal has a built-in WAPI communication module, dynamic password generator, operation counter (initial value N=0), and electromagnetic shielding hardware. When the lock terminal starts up, it sends a registration request to the key management server to verify the lock's identity and the server's legitimacy, completes WAPI two-way authentication, and obtains the initial session key SK0 and random salt value R0.
[0089] Step S2: Unlock Request and Dynamic Password Generation: The operator, using a handheld mobile authorization terminal, verifies their identity via biometrics (e.g., fingerprint) and sends an unlock request (carrying the lock ID and operator identity information) to the server. The key management server verifies the operator's permissions and generates a dynamic password based on the current session key SK. current Calculate the dynamic password using the operation counter value N and the salt value R:
[0090] ;in:
[0091] P current The newly generated dynamic password for the lock;
[0092] SK current : Current WAPI session key;
[0093] N: Current value of the operation counter;
[0094] R: Random salt value (issued periodically by the server);
[0095] XOR operation;
[0096] Hash: SM3 national cryptographic hash algorithm;
[0097] The key management server transmits the newly generated dynamic password P for the lock via a WAPI encrypted channel. current Distribute to mobile devices;
[0098] Step S3: Command Transmission and Unlock Execution: The mobile authorization terminal sends an unlock command (including the dynamic password P) to the lock terminal via NFC or WAPI wireless link. current The lock terminal first verifies whether the received N value matches the local counter to prevent replay attacks. If the N value matches, it uses the locally stored SK. current Calculate dynamic password P using N and R local and the received P current If the match is successful, the drive motor will unlock and perform the following operations: 1) Increment the operation counter: N new =N+1, and set N new 1) Upload to the key management server; 2) Linked update check: If N mod K = 0 (K is the operation count threshold), trigger a key update request;
[0099] Step S4: Key and password linked update: When the number of operations reaches a preset threshold K, the lock terminal sends a key update request to the server with the current N value, and the server generates a new session key SK. new and salinity R newThe data is sent to the lock terminal via a WAPI encrypted channel, and the lock terminal updates its local SK. current With R, SK current =SK new R=R new Reset the emergency key pool and synchronize the N value to the server.
[0100] Step S5: Offline Emergency Synchronization Mechanism: The offline emergency synchronization mechanism aims to address the availability issues of WAPI-based smart lock systems during network outages or communication failures, while ensuring security and data consistency. When the lock terminal cannot establish a connection with the key management server, the system automatically switches to offline mode, uses a pre-generated emergency key pool to complete the unlocking operation, and synchronizes the operation records during the offline period and updates the key status after the network is restored to prevent security vulnerabilities.
[0101] The specific process is as follows:
[0102] Step S5.1: Generation and Pre-storage of Emergency Key Pool: The key management server pre-generates M sets of emergency key pairs (SK). emergency P emergency The calculation formula is:
[0103] ;
[0104] Each key pair is associated with a pre-generated virtual counter value N. i 预生成 To ensure the continuity of the counter logic when unlocking offline, the emergency key pair is pre-stored to the lock terminal via a secure link.
[0105] Step S5.2: Offline Mode Switching and Unlocking Process: The lock terminal continuously monitors the WAPI network connection status. If three consecutive handshakes fail (timeout set to 5 seconds), it is determined to be a network interruption. The operator executes the emergency unlocking procedure, selects the offline unlocking mode via a mobile terminal (pre-authorization required), and verifies identity by inputting biometric features (such as fingerprint); the lock terminal retrieves the currently available key pair (SK) from the key pool. emergency P emergency ) and the corresponding N i 预生成 The user enters a dynamic password. After the lock terminal verifies that the password matches, it unlocks the lock, marks the key pair as "used," and updates the local virtual counter.
[0106] ;
[0107] Step S5.3: Data Synchronization After Network Recovery: After the lock terminal detects network recovery, it immediately encrypts and uploads the following data from the offline period to the server: the emergency key pair index i, the virtual counter sequence {N}. i预生成 N i +1 预生成 ...}, unlocking time, operator identity; the server checks the uploaded N i 预生成 Check if it matches the pre-generated sequence to prevent forgery, and update the online counter value:
[0108] ;
[0109] ( N is the number of offline operations);
[0110] The server generates a new emergency key pool, distributes and replaces the key pairs already in use in the lock terminal. If a conflict is detected (such as a key being reused), an alarm is triggered and the key is forced to reset.
[0111] Step S5.4: Anomaly Handling and Disaster Recovery: a) When the remaining unused key pairs fall below a threshold (e.g., 10 pairs), the lock terminal sends an alert to the server, prompting the administrator to replenish them; if the key pool is completely exhausted and the network has not recovered, the lock terminal enters a locked state, allowing only physical keys to unlock. b) If the counters of the server and the lock terminal are inconsistent, the server's record shall prevail, and the N counter of the lock terminal shall be forcibly synchronized. local If malicious tampering is detected (such as offline logs being forged), the key pool will be cleared and a system-wide key update will be triggered.
[0112] Step S6: Anti-replay attack design: A continuous counter verification is performed. Both the server and the lock terminal record the N value, ensuring that N strictly increments with each unlocking request. If the N value received by the server deviates from the locally recorded value beyond the tolerance range (e.g., ΔN>1), it is determined to be a potential replay attack or data tampering. The server immediately sends a security alarm to the operation and maintenance platform and forcibly resets the lock terminal's session key. The lock terminal enters a locked state, requiring manual intervention from the administrator to unlock. The dynamic password is valid only once. After successful unlocking, the current password immediately expires, and the next operation requires a new password generated based on the updated N value. The core verification logic for anti-replay attacks is through continuous verification of the operation counter (N value) and the dynamic password (P... current A one-time effective mechanism to prevent malicious attackers from intercepting and reusing historical unlocking commands.
[0113] The specific process is as follows:
[0114] Step S6.1: Unlock Request Submission: The mobile authorized terminal sends an unlock request to the lock terminal or server, including the following parameters: unique lock identifier (Lock ID), current operation counter value N, and dynamic password P. current .
[0115] Step S6.2: Server-side verification logic: The key management server performs a counter continuity check. First, the server queries the latest record N for the lock. last The value is used to verify whether the received N satisfies a strictly increasing relationship N=N last +1. If the verification fails, it is considered a potential replay attack (an attacker may intercept and repeatedly send historical N values), triggering a security alarm and sending a locking command to the lock terminal. Afterwards, dynamic password validity verification is performed, with the server using the locally stored SK... current N, R recalculate dynamic password P local Compare the received P current With P local If they match: allow unlocking, update server-side N. last =N; If they do not match: it is determined that the password has been tampered with or forged, triggering an alarm and locking the lock.
[0116] Step S6.3: Local verification of the lock terminal: The lock terminal first performs a counter synchronization check. The N received by the lock terminal must match the N stored locally. local Strict consistency, if N≠N local If the lock fails to open immediately, an anomaly will be reported; if the password matches, a dynamic password comparison will be performed, and the lock terminal will use the local SK. current N, R recalculate dynamic password P local and with the received P current The two are compared; if they match, the unlocking action is performed and the counter (N) is incremented. local =N local +1).
[0117] Step S6.4: Anomaly Handling and Defense Upgrade: Replay attack detection scenarios are divided into the following two types: a) The attacker intercepts historical unlocking commands (including old N values) and resends them, and the server detects that N≤N last a) The attacker forges a jump value for N (e.g., N=N) last +5), the server detected N>N last +1 indicates unauthorized tampering. If the above replay attack scenario occurs, corresponding response measures will be taken, including: a) Short-term response: locking the lock terminal to block subsequent operations; b) Forced update of the session key SK. current c) Clear the existing emergency key pool with salt value R; c) Log recording: Record attack characteristics (such as abnormal N value, source IP) for security auditing and policy optimization.
[0118] Step S6.5: Anti-replay design in offline mode: a) Emergency key pool verification: When unlocking offline, a pre-stored emergency key pair (SK) is used. i emergency P iemergency Each emergency key is associated with a virtual counter value N. i 预生成 a) Ensure that the N value increases continuously during offline operation; b) Synchronous recovery verification: After the network is restored, the lock terminal uploads the N value sequence during the offline period. The server verifies whether the N sequence is continuous and without repetition. If there is a conflict, the relevant key pair is marked as invalid.
[0119] like Figure 2 As shown, in an embodiment of the present invention, a substation active interlocking control method based on a WAPI network is provided, comprising the following control steps:
[0120] S1: System Initialization and Two-Way Authentication. Upon initial power-on, the lock terminal sends a registration request to the server, containing a unique identifier (such as a MAC address) and a digital certificate. The server verifies the certificate's validity, completes WAPI two-way authentication, generates an initial session key SK0="A1B2C3" and a random salt value R0="X9Y8Z7", and distributes it to the lock terminal. An emergency key pool (50 sets) is pre-generated and encrypted, stored in the lock terminal. The lock terminal stores SK0 and R0, and initializes the operation counter N=0.
[0121] S2: Unlock Request and Dynamic Password Generation. The operator sends an unlock request to the server using a mobile terminal. The server verifies the operator's unlocking authorization and calculates a dynamic password based on the current parameters.
[0122] ;
[0123] P1 is sent to the mobile terminal via a WAPI encrypted channel;
[0124] S3: Command transmission and unlocking execution. The mobile terminal sends commands to the lock via NFC or WAPI wireless link. The lock terminal verifies whether N=1 is consecutive (current N). local =0, satisfying 1=0+1), calculate the local password:
[0125] ;
[0126] Compare P local If the received P="D4E5F6" matches, the lock is unlocked and the record is uploaded to the server;
[0127] S4: Key and password linked update. When the lock terminal successfully unlocks, the counter N=1 is updated. Since 1 mod 10 ≠ 0, no key update is triggered. After the 10th unlock, N=10, and since 10 mod 10 = 0, the lock terminal sends a key update request to the server. The server generates a new session key SK. new =“M3N4O5”, new salt value R new="P6Q7R8" and calculate the dynamic password for the next cycle:
[0128] ;
[0129] SK is sent via WAPI encrypted channel new R new P 11 .
[0130] Lock terminal update local storage SK current =“M3N4O5”, R=“P6Q7R8”, reset the emergency key pool, pre-store the new key group (51-100), and synchronize the counter N=10 to the server.
[0131] S5: This embodiment of the invention also provides a method for offline emergency synchronization control of a system, such as... Figure 3 As shown, the method includes the following steps:
[0132] S5.1: Generation and pre-storage of emergency key pools. The key management server generates 50 emergency key pairs (SK) daily. 1 -50 emergency P 1-50 emergency Each group of associated virtual counters: N i 预生成 =1000+i (e.g., N=1001 for group 1, N=1002 for group 2); the key is encrypted and then sent to the hardware security module of the lock terminal. The mobile terminal is pre-loaded with the range of emergency passwords available for the day (P). 1-10 emergency ).
[0133] S5.2: Offline Mode Switching and Unlocking Procedure. If the lock terminal fails to perform three consecutive WAPI handshakes (with a 5-second interval), a network interruption is determined. The lock terminal's LED indicator turns red, and the buzzer sounds once to indicate entry into offline mode. The operator uses a mobile terminal to approach the lock, triggering NFC communication. The mobile terminal verifies the operator's identity via fingerprint and displays the currently available emergency password P. 5 emergency =“A3F9B7” (corresponding to N) 5 预生成 =1005), the operator enters this password, and the lock terminal performs verification:
[0134] ;
[0135] Verification passed, lock unlocked, perform the following operations: a) Mark SK 5 emergency b) Update the local virtual counter: N local=1005+1=1006.
[0136] If the operator needs to enter another area to unlock the door, they must use P. 6 emergency (N=1006) Unlocked, unlocked successfully, N local =1007.
[0137] S5.3: Data Synchronization After Network Recovery. The lock terminal detects WAPI network recovery and automatically triggers the synchronization process. Server-side verification and synchronization include: a) Server verification N... 5 预生成 =1005、N 6 预生成 b) Check if 1006 matches the pre-stored sequence; Update the online counter: N online =1006+2=1008; c) Generate a new emergency key pool (index 51-100) and distribute it to the lock terminal to replace the used keys; d) If a conflict is detected (e.g., N=1005 in the log has been used by another lock), trigger an alarm and force a key reset. Lock terminal status update includes: a) Clearing used key pairs (index 5-6); b) Synchronizing N local =1008, consistent with the server; c) The LED indicator returns to green, and the buzzer sounds once to indicate that synchronization is complete.
[0138] S5.4: Anomaly Handling and Disaster Recovery.
[0139] 1. Emergency key pool exhausted: The lock terminal triggers a continuous alarm with a buzzer and the LED flashes red; it automatically switches to the physical backup key slot, requiring the administrator to manually unlock the lock by inserting a mechanical key.
[0140] 2. Data synchronization conflict: The server finds that N=1005 in the offline log has been used by another lock. The server marks the conflict and sends an alarm, forcibly resetting all keys that have used the lock with N=1005 and generating a brand new emergency pool.
[0141] S6: As Figure 4 As shown, this embodiment of the invention also provides a method for resisting replay attacks. The system successfully blocks the attack based on the continuity verification of the operation counter (N value) and the one-time validity mechanism of the dynamic password. The following is a detailed implementation example:
[0142] The system components and initial states are defined as follows:
[0143] Lock terminal: a) Current session key SK current =“A1B2C3”; b) Operation counter N=15 (15 successful unlocks); c) Random salt value R=“X9Y8Z7”.
[0144] Key management server: stores the N locks last =15;
[0145] S201: Unlock request submitted. An unlock request is initiated via mobile terminal, with identity verified through biometrics.
[0146] S202: Server-side authentication logic. Server generates dynamic password:
[0147] ;
[0148] Password P 16 The data is encrypted and sent to the mobile terminal via WAPI.
[0149] S203: Local verification of the lock terminal. The lock terminal verifies whether N=16 is consecutive (16=15+1) and calculates the local password:
[0150] ;
[0151] Password matches, lock unlocked successfully, N=16 updated.
[0152] S204: Anomaly Handling and Defense Upgrades.
[0153] Attacker launches replay attack: a) Attacker sends intercepted old commands (N=10) to lock terminal, lock terminal verifies N=10, local current N local =16, if 10 < 16 is detected, it is determined to be an expired request, the lock terminal refuses to unlock, records the abnormal log, and triggers a low-level alarm; b) The attacker forges the instruction N=17 and attempts to skip the current N=16. The lock terminal verifies N=17, and the local N=16. If 17 ≠ 16 is detected, it is determined to be an illegal jump, the lock terminal refuses to unlock, triggers a high-level alarm (red indicator light stays on, buzzer alarm sounds), and sends a security event to the server.
[0154] After receiving an alarm from the lock terminal, the server performs the following operations: a) Forcefully reset the lock's session key and generate an SK. new =“M3N4O5”, R new =“P6Q7R8” and distribute to the lock terminal; b) clear the original emergency key pool, regenerate 50 sets of offline keys and distribute them to the lock terminal.
[0155] The lock terminal received the SK sent by the server. new =“M3N4O5”, R new =“P6Q7R8”, updates local storage, resets operation counter N=0, restarts counting, clears alarm status, and restores normal operation mode (green indicator light).
[0156] In summary, as can be seen from the above embodiments, the present invention has the following advantages:
[0157] (1) The control system adopts a linkage update control mechanism, which has the following advantages:
[0158] a) Dynamic adaptability: The operation number triggering mechanism matches the key update frequency with the actual usage intensity, avoiding security redundancy or insufficiency in fixed-period updates;
[0159] b) End-to-end synchronization: The WAPI encrypted channel ensures strict synchronization of the key, password, and counter among the lock terminal, server, and mobile terminal;
[0160] c) Anti-prediction and anti-replay: The random salt value R is combined with the hash algorithm to prevent the prediction of future passwords through historical data;
[0161] d) Counter continuity verification blocks replay attacks.
[0162] (2) The anti-replay attack design of the control system has two major advantages:
[0163] a) The dual defense layers include:
[0164] Transport layer: WAPI encryption prevents commands from being eavesdropped on or tampered with;
[0165] Application layer: The counter is bound to a dynamic password to ensure the uniqueness of instructions;
[0166] It has real-time performance: the latest N and P values must be obtained for each unlocking operation. current Historical data cannot be reused;
[0167] b) Fault tolerance and recovery:
[0168] Occasional network latency can cause N to be temporarily out of sync (e.g., setting a tolerance ΔN=1), but the number of consecutive anomalies is strictly limited.
[0169] (3) The "request-verification-response" closed-loop verification process adopted by the control system achieves the following objectives:
[0170] a) Blocking replay attack: based on the strict incrementality of the counter and the one-time validity of dynamic passwords;
[0171] b) Real-time threat awareness: Instant alerts triggered by anomaly counters or passwords;
[0172] c) Seamless online / offline integration: The counter logic continuity is still guaranteed in emergency mode to avoid security vulnerabilities.
[0173] This invention, based on the WAPI network, employs linked updates of keys and dynamic passwords, anti-replay attack control, and offline emergency synchronization control to construct an intelligent lock system that meets the high security requirements of substations. Combining hardware anti-interference, multi-level software verification, and scalable access control, it achieves a closed-loop system covering the entire chain from communication security to physical protection, providing reliable technical support for the intelligent upgrading of the power industry.
[0174] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A substation active interlock control method based on WAPI network, characterized in that: The control steps include the following: Step S1: Deploy the key management server in the substation intranet. The key management server stores the unique identifier of the lock, the permission policy, the dynamic password algorithm parameters, generates and distributes the initial key SK0 and the random salt value R0, synchronously initializes the emergency key pool, and pre-generates M sets of offline key-password pairs. Start the lock terminal, initiate a registration request to the key management server, verify the lock's identity and the server's legitimacy, complete WAPI two-way authentication, and obtain the initial session key SK0 and random salt value R0; Step S2: The operator uses a handheld mobile authorization terminal to verify their identity through biometrics and sends an unlocking request to the key management server. The key management server calculates and generates a dynamic password and sends the newly generated lock dynamic password to the mobile authorization terminal through the WAPI encrypted channel. Step S3: The mobile authorization terminal sends an unlocking command to the lock terminal via the wireless network. The lock terminal matches the unlocking command. If the match is successful, the lock terminal drives the motor to unlock and performs an update operation. Step S4: When the number of operations of the lock terminal reaches the preset threshold K, the lock terminal sends a key update request to the key management server with the current operation counter N value. The key management server generates a new session key SK. new and salinity R new It is sent to the lock terminal through the WAPI encrypted channel; Lock terminal update local SK current With the salinity R, SK current =SK new R=R new Reset the emergency key pool and synchronize the operation counter N value to the key management server; Step S5: When the lock terminal cannot establish a connection with the key management server, the system automatically switches to offline mode, executes the offline emergency synchronization control method, uses the pre-generated emergency key pool to complete the unlocking operation, and synchronizes the operation records during the offline period and updates the key status after the network is restored; Step S6: Control the operation counter inside the lock terminal to perform continuous verification. Both the server and the lock terminal record the N value to ensure that N strictly increases for each unlocking request. If the N value received by the server deviates from the local record by more than the preset fault tolerance range, it is determined to be a potential replay attack or data tampering. Anti-replay attack control is then executed. The server immediately sends a security alarm to the operation and maintenance platform and forcibly resets the session key of the lock terminal, causing the lock terminal to enter the locked state.
2. The substation active interlock control method based on WAPI network according to claim 1, characterized in that: The unlocking request data sent to the server in step S2 includes the lock ID and the operator's identity information.
3. The substation active interlock control method based on WAPI network according to claim 2, characterized in that: The specific method by which the key management server calculates the dynamic password in step S2 is as follows: The key management server verifies the operator's permissions based on the current session key SK. current The dynamic password is calculated using the operation counter value N and the salt value R, and the calculation formula is as follows: ; in: P current The newly generated dynamic password for the lock; SK current The current WAPI session key; N is the current value of the operation counter; R is a random salt value, which is periodically distributed by the key management server; This is an XOR operation; Hash uses the SM3 national cryptographic hash algorithm; Finally, the key management server transmits the newly generated lock dynamic password P through the WAPI encrypted channel. current Distribute to mobile devices.
4. The substation active interlock control method based on WAPI network according to claim 3, characterized in that: In step S3, the unlocking command sent from the mobile authorization terminal to the lock terminal specifically includes the dynamic password P. current And the value of the operation counter N.
5. The substation active interlock control method based on WAPI network according to claim 4, characterized in that: The specific method for matching the unlocking command by the lock terminal in step S3 is as follows: The lock terminal first verifies whether the received operation counter N value is consistent with the local counter to prevent replay attacks. If the operation counter N value is consistent, then the locally stored SK is used. current Calculate dynamic password P using N and R local and the received P current Comparison.
6. The substation active interlock control method based on WAPI network according to claim 5, characterized in that: The update operation performed in step S3 specifically includes: Operation counter increments: N new =N+1, and set N new Upload to the key management server; Linked update check: If N mod K=0, where K is the threshold for the number of operations, a key update request is triggered.
7. The substation active interlock control method based on WAPI network according to claim 6, characterized in that: The specific method for step S5 is as follows: Step S5.1: The control key management server calculates and generates M sets of emergency key pairs SK. emergency P emergency The calculation formula is: ; Each key pair is associated with a pre-generated virtual counter value N. i 预生成 To ensure the continuous logic of the counter when unlocking offline, the emergency key pair is pre-stored to the lock terminal via a secure link; Step S5.2: The lock terminal continuously monitors the WAPI network connection status. If three consecutive handshakes fail, it is determined that the network is interrupted. The operator executes the emergency unlocking procedure by selecting the offline unlocking mode through a mobile authorization terminal and verifying their identity by entering biometric data. The lock terminal retrieves the currently available key pair SK from the key pool. emergency P emergency and the corresponding virtual counter value N i 预生成 The user enters a dynamic password. After the lock terminal verifies that the password matches, it performs the unlocking operation, marks the key pair as used, and updates the local virtual counter. ; Step S5.3: After the lock terminal detects that the network has been restored, it immediately encrypts and uploads the following data from the offline period to the key management server: The emergency key used is index i, and the virtual counter sequence {N}. i 预生成 N i+1 预生成 ...}, unlocking time, operator identity; The key management server checks the uploaded virtual counter value N. i 预生成 If the sequence matches the pre-generated sequence, update the online counter value as follows: ; in, N represents the number of offline operations; The key management server generates a new emergency key pool, distributes and replaces the key pairs already in use in the lock terminal. If a conflict is detected, an alarm is triggered and the key is forced to reset. Step S5.4: When an abnormal state is encountered, the following handling strategy shall be executed: When the remaining unused key pairs fall below the threshold, the lock terminal sends an alert to the key management server, prompting the administrator to replenish them. If the key pool is completely exhausted and the network is not restored, the lock terminal enters a locked state, allowing only physical keys to unlock. If the counters of the key management server and the lock terminal are inconsistent, the record of the key management server shall prevail, and the N of the lock terminal shall be forcibly synchronized. local If malicious tampering is detected, the key pool will be cleared and a system-wide key update will be triggered.
8. A substation active interlock control method based on a WAPI network according to claim 7, characterized in that: The specific method for step S6 is as follows: Step S6.1: The mobile authorization terminal sends an unlocking request to the lock terminal or key management server, including the following parameters: Lock ID (unique identifier), current operation counter value N, dynamic password P current ; Step S6.2: The key management server queries the latest record of N for this lock terminal. last The value is used to verify whether the received N value satisfies the strict increasing relationship N=N last +1. If the verification fails, it is determined to be a potential replay attack, triggering a security alarm and sending a locking command to the lock terminal. Dynamic password validity verification is performed by the key management server based on the locally stored SK. current N, R recalculate dynamic password P local Compare the received P current With P local If they match, unlocking is allowed, and the server-side N is updated. last =N, if they do not match, it is determined that the password has been tampered with or forged, triggering an alarm and locking the lock; Step S6.3: The lock terminal performs a counter synchronization check. The N value received by the lock terminal must match the locally stored N value. local Strict consistency, if N≠N local If the lock fails to open immediately and an anomaly is reported, a dynamic password comparison will be performed. The lock terminal uses the local SK. current N, R recalculate dynamic password P local and with the received P current The comparison is performed, and the unlocking action is executed and the counter is incremented only if the two match: N local =N local +1; Step S6.4: Determine the replay attack scenario and execute the corresponding response measures; Step S6.5: In offline mode, perform the following anti-replay response measures: Emergency Key Pool Verification: When unlocking offline, use the pre-stored emergency key to verify SK. i emergency P i emergency Each emergency key is associated with a virtual counter value N. i 预生成 This ensures that the N value for offline operations increases continuously. Synchronous recovery verification: After the network is restored, the lock terminal uploads the N value sequence during the offline period. The key management server verifies whether the N sequence is continuous and without repetition. If there is a conflict, the relevant key pair is marked as invalid.
9. A substation active interlock control method based on a WAPI network according to claim 8, characterized in that: The specific method for step S6.4 is as follows: A replay attack scenario is determined when one of the following two conditions is met: An attacker intercepts historical unlocking commands containing old N values and retransmits them; the server detects that N≤N last This triggers an alarm; The attacker forged a jump value for N, and the server detected that N > N. last +1, indicating illegal tampering; If the above replay attack scenario occurs, the following response measures will be implemented, including: Short-term response: Lock the lock terminal to prevent further operations; Force update session key SK current With salt value R, clear the existing emergency key pool; Log recording: Records attack characteristics for security auditing and policy optimization.
10. The control system used to implement the substation active interlock control method based on a WAPI network as described in any one of claims 1-9, characterized in that: This includes lock terminals, key management servers, and mobile authorization terminals, among which: The lock terminal integrates a WAPI communication module, a dynamic password generator, and an operation counter. The key management server is specifically deployed on the substation's intranet and is responsible for WAPI two-way authentication and key distribution. The mobile authorization terminal is specifically a handheld device for maintenance personnel, which supports receiving dynamic passwords through a WAPI encrypted channel; The lock terminal, key management server, and mobile authorization terminal all achieve secure unlocking and dynamic access control through encrypted communication via the WAPI network.
Citation Information
Patent Citations
Access control system generated and verified on the basis of dynamic password and authentication method thereof
CN101593380A
Secure communication method based on intelligent door lock system and intelligent door lock system
CN107038777A
Intelligent lock unlocking method, intelligent lock, terminal, server and system
CN109905235A
Unlocking method, equipment for achieving unlocking and computer readable medium
CN110473318A
Bicycle intelligent supervision anti-theft system and method based on Internet of Things technology
CN114360111A