Off-line safety operation method and terminal based on metering communication authentication module
By generating key pairs through the metering communication authentication module and transmitting them offline, combined with random number authentication and data encryption signature, the problems of data security and identity authentication in offline operation of power equipment are solved, the security and integrity of data transmission are achieved, and the reliability of power equipment management is improved.
Patent Information
- Application Number
- CN202511256991.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-04
- Publication Date
- 2025-12-02
AI Technical Summary
The lack of data security protection mechanisms and weak equipment authentication during offline operation of power equipment pose risks of data tampering and unauthorized access, threatening power data security and system stability.
The metering communication authentication module generates a master key pair and an auxiliary key pair, which are transmitted to the mobile terminal and the management terminal through a physical medium. A secure connection is established by combining random number authentication, and the data is encrypted and signed in offline mode. The management terminal verifies the data integrity online.
It ensures the security and integrity of data transmission, prevents tampering, improves the confidentiality and reliability of data during offline operation of power equipment, and provides efficient and secure data management protection.
Smart Images

Figure CN121056867A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power automation and information security, and more specifically, to the secure transmission, storage, and system design of data during offline operation of power equipment. It describes a method and terminal for ensuring the security of power meter reading data throughout the entire process by using a metering communication authentication module. Background Technology
[0002] In the process of intelligent and digital development of power systems, offline operation of power equipment is a crucial link in ensuring the stable operation of the power grid. It is widely used in complex scenarios such as inspection, meter reading, and fault diagnosis, and is particularly suitable for areas with insufficient network coverage, harsh environments, or where reliance on real-time networks needs to be reduced. By collecting equipment data and executing task instructions through offline operation terminals, and transmitting the data back to the management terminal when conditions permit, it can flexibly respond to diverse operational needs and improve the efficiency of power operation and maintenance.
[0003] However, current offline operation of power equipment faces challenges in terms of data security and system reliability. On the one hand, data such as equipment parameters, operating status, and meter readings generated during operation lack effective protection mechanisms during terminal storage and offline transmission, making them highly susceptible to malicious tampering and theft. On the other hand, equipment authentication mechanisms are weak, and there is a lack of reliable identity verification methods between the operation terminal and the management terminal, posing a risk of unauthorized equipment access to the system and falsified data uploads, seriously threatening power data security and stable system operation.
[0004] Therefore, there is an urgent need to develop a mobile terminal and method for offline operation of power equipment based on a metering communication authentication module. Through cryptographic technology and optimized system design, the security and reliability of offline operation data can be ensured, thereby promoting the safe and efficient development of power operation and maintenance services. Summary of the Invention
[0005] The purpose of this invention is to address the problems of data security and system reliability when power equipment is operating offline, and to propose an offline safe operation method and terminal based on a metering communication authentication module.
[0006] The technical solution of this invention is:
[0007] This invention provides an offline secure operation method based on a metering communication authentication module, comprising: S1, a mobile terminal sends a key acquisition command to a key distribution device using the metering communication authentication module; the key distribution device generates a master key pair and an auxiliary key pair; and transmits the master key public key and the auxiliary key pair to the metering communication module offline and stores them in a secure storage unit; simultaneously, the key distribution device transmits the master key private key and the auxiliary key private key to the management terminal.
[0008] S2. Users authenticate their identity using a mobile phone and mobile terminal, establish a secure connection based on random numbers and key negotiation, and send work order instructions to the mobile terminal via the mobile phone to drive the mobile terminal to collect power equipment data or meter reading data.
[0009] S3. When the mobile terminal is operating online, it collects power equipment data or meter reading data and communicates with the management terminal to transmit data.
[0010] S4. When the mobile terminal is working offline, the power equipment data or meter reading data is used as the data to be transmitted. The metering communication module uses the auxiliary key to sign the data to be transmitted, and uses the master key to encrypt the signed data to be transmitted, generating an encrypted data packet and storing it in the secure storage unit.
[0011] Once the mobile terminal is online, it uploads the encrypted data packet to the management terminal, which then verifies and stores the data.
[0012] Furthermore, in S1,
[0013] After generating a master key pair and an auxiliary key pair, the key distribution device uses the master key private key to encrypt the auxiliary key pair, generating an encrypted auxiliary key pair. The encrypted auxiliary key pair and the master key public key are then transmitted to the metering communication module offline.
[0014] The metering communication module decrypts the encrypted auxiliary key pair based on the master key public key to obtain the decrypted auxiliary key pair.
[0015] Furthermore, the offline method refers to transmission that does not rely on a network connection, but uses a physical medium for transmission, such as a USB flash drive, external hard drive, or optical disc.
[0016] Furthermore, S2 includes:
[0017] S21. The mobile terminal sends an initial Bluetooth connection command through the metering communication module, and attaches the encrypted Bluetooth PIN code to the broadcast message;
[0018] S22. The user uses a mobile phone to parse the broadcast message, enters the plaintext PIN code to decrypt it, and establishes connection information between the mobile phone and the mobile terminal.
[0019] S23. The mobile terminal stores pairing information and sends a status acquisition command to perform authentication.
[0020] Furthermore, in S23, the authentication includes:
[0021] The mobile phone generates a random number R1 and sends a key negotiation start command to the mobile terminal. The mobile terminal calls the metering communication module to verify the random number R1 and returns a response message to the mobile phone.
[0022] The mobile phone generates a random number R2 and sends a negotiation end command to the mobile terminal. The mobile terminal calls the metering communication module to verify the random number R2. If the verification is successful, the identity authentication is completed.
[0023] Further, in S4, generating the encrypted data packet includes:
[0024] S41. The metering communication module performs digital digest calculation on the data to be transmitted, generates a digital digest, and merges the digital digest with the data to be transmitted to generate a data packet;
[0025] S42. The metering communication module uses the auxiliary key public key to sign the data packet and generate a signed data packet; it uses the master key public key to encrypt the signed data packet and generate an encrypted data packet.
[0026] Furthermore, in S4, the data stored after verification by the management end includes:
[0027] The management terminal receives encrypted data packets and decrypts them using the master key and private key; it then uses the auxiliary key and private key to sign and verify the decrypted data packets; finally, it performs an integrity check on the data to ensure that the data has not been tampered with; after the check passes, the management terminal stores the decrypted data.
[0028] Furthermore, in S3, when the mobile terminal is operating online;
[0029] The mobile terminal receives work order instructions, acquires power equipment data or meter reading data through the data acquisition unit, encrypts and signs the data through the metering communication module, and uploads it online to the management terminal; the management terminal decrypts and verifies the data before storing it.
[0030] An offline secure operation mobile terminal based on a metering communication authentication module is disclosed. The mobile terminal includes a metering communication authentication module for realizing full lifecycle security management of offline operation data. When the mobile terminal is offline, it performs two-way authentication with a key distribution device through the metering communication authentication module to obtain and store a key for encrypted data transmission during offline operations.
[0031] Furthermore, the two-way authentication between the metering communication authentication module and the key distribution device includes: the mobile terminal sending a key acquisition command to the key distribution device using the metering communication authentication module; the key distribution device generating a master key pair and an auxiliary key pair; encrypting the auxiliary key pair using the master key's private key to generate an encrypted auxiliary key pair; and transmitting the encrypted auxiliary key pair and the master key's public key to the metering communication module offline; the metering communication module decrypting the encrypted auxiliary key pair based on the master key's public key to obtain the decrypted auxiliary key pair.
[0032] The beneficial effects of this invention are:
[0033] This invention proposes an offline secure operation method and terminal based on a metering communication authentication module. A key distribution device is designed to generate a master key pair and an auxiliary key pair, which are then distributed to the metering communication module and the management terminal to ensure the security of data encryption and signing. The mobile terminal and phone establish a secure Bluetooth connection through two-way authentication based on random numbers, ensuring the reliability of command and data interaction. During online operation, the metering communication module encrypts and signs the collected data before uploading it directly. During offline operation, encrypted data packets are generated and stored in a secure storage unit, to be uploaded when online. The management terminal uses the master key and private key to decrypt and verify data integrity, ensuring data security and integrity.
[0034] This invention solves the problem of integrating secure data transmission and trusted identity verification in online and offline scenarios through a unified key management and dynamic identity authentication mechanism, significantly improving the confidentiality, integrity and reliability of power data acquisition, and providing efficient and secure technical support for power equipment management.
[0035] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0036] The above and other objects, features and advantages of the present invention will become more apparent from the more detailed description of exemplary embodiments of the invention in conjunction with the accompanying drawings, wherein the same reference numerals generally represent the same components in the exemplary embodiments of the invention.
[0037] Figure 1 A flowchart of the offline security operation method based on the metering communication authentication module of the present invention is shown. Detailed Implementation
[0038] Preferred embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While preferred embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein.
[0039] Figure 1 A flowchart of the offline security operation method based on the metering communication authentication module of the present invention is shown.
[0040] like Figure 1 As shown, the present invention provides an offline security operation method based on a metering communication authentication module, comprising:
[0041] S1. The mobile terminal sends a key acquisition command to the key distribution device through the metering communication authentication module. The key distribution device generates a master key pair and an auxiliary key pair, and transmits the master key public key and the auxiliary key pair to the metering communication module offline and stores them in the secure storage unit. At the same time, the key distribution device transmits the master key private key and the auxiliary key private key to the management terminal.
[0042] Specifically, after the key distribution device generates a master key pair and an auxiliary key pair, it encrypts the auxiliary key pair using the master key private key to generate an encrypted auxiliary key pair. The encrypted auxiliary key pair and the master key public key are then transmitted offline to the metering communication module. The metering communication module decrypts the encrypted auxiliary key pair based on the master key public key to obtain the decrypted auxiliary key pair.
[0043] The offline method refers to transmission that does not rely on a network connection and uses a physical medium for transmission, such as a USB flash drive, external hard drive, or optical disc.
[0044] When the key distribution device transmits the encrypted auxiliary key pair and the master key public key to the metering communication module via USB flash drive, the use of this physical medium avoids network dependence. After receiving the data, the metering communication module uses the master key public key to decrypt it. The decryption process involves inputting the encrypted data into the decryption algorithm to recover the original auxiliary key pair, which is then stored in a secure storage unit. Physical transmission reduces online attack vectors and enhances the authentication capabilities of mobile terminals in the absence of a network. For example, in remote power equipment sites, the module can process data independently without real-time connection.
[0045] S2. Users authenticate their identity using a mobile phone and mobile terminal, establish a secure connection based on random numbers and key negotiation, and send work order instructions to the mobile terminal via the mobile phone to drive the mobile terminal to collect power equipment data or meter reading data.
[0046] Specifically, the process includes: S21, the mobile terminal sends an initial Bluetooth connection command through the metering communication module, attaching an encrypted Bluetooth PIN code to the broadcast message; S22, the user uses a mobile phone to parse the broadcast message, enters the plaintext PIN code, decrypts it, and establishes connection information between the mobile phone and the mobile terminal; S23, the mobile terminal stores pairing information and sends a status acquisition command to perform identity authentication; the mobile phone generates a random number R1 and sends a key negotiation start command to the mobile terminal, the mobile terminal calls the metering communication module to verify the random number R1, and returns a response message to the mobile phone; the mobile phone generates a random number R2 and sends a negotiation end command to the mobile terminal, the mobile terminal calls the metering communication module to verify the random number R2, and if the verification is successful, identity authentication is completed.
[0047] The metering communication module first retrieves a preset encryption key from the secure storage unit and encrypts the plaintext PIN code to form an encrypted Bluetooth PIN code. This encryption prevents broadcast messages from being intercepted during transmission, thereby improving connection security. After receiving the broadcast message, the mobile phone extracts the encrypted Bluetooth PIN code using a built-in parsing algorithm. The user enters the plaintext PIN code as the decryption key, and the mobile phone combines the two to reconstruct the original PIN code value and generate a connection. This ensures that only users with the correct plaintext PIN code can establish a connection, effectively preventing unauthorized access.
[0048] After the connection is established, the secure storage unit on the mobile terminal stores the information. The mobile terminal sends a status acquisition command to trigger the authentication process. At this time, the mobile phone generates a first random number R1, such as a 128-bit random sequence, and sends it to the mobile terminal along with a key negotiation start command. The mobile terminal calls the metering communication module to verify the first random number R1 and generates a first response message, which is transmitted to the mobile phone. The mobile phone verifies its integrity. If it matches, it generates a second random number R2 and sends a key negotiation end command. The mobile terminal calls the metering communication module to perform a similar verification on the second random number R2, generates a second response message, and completes the identity authentication. This two-way random number verification mechanism effectively supports security and ensures the confidentiality of subsequent data transmission.
[0049] S3. When the mobile terminal is operating online, it acquires power equipment data or meter reading data through the data acquisition unit, encrypts and signs the data through the metering communication module, and uploads it online to the management terminal; the management terminal decrypts and verifies the data before storing it.
[0050] S4. When the mobile terminal is working offline, the power equipment data or meter reading data is used as the data to be transmitted. The metering communication module uses the auxiliary key public key to sign the data to be transmitted, and uses the master key public key to encrypt the signed data to be transmitted, generating an encrypted data packet and storing it in the secure storage unit.
[0051] Once the mobile terminal is online, it uploads the encrypted data packet to the management terminal, which then verifies and stores the data.
[0052] Specifically, in step S41, the metering and communication module performs digital digest calculation on the data to be transmitted, generates a digital digest, and merges the digital digest with the data to be transmitted to generate a data packet; in step S42, the metering and communication module uses the auxiliary key public key to sign the data packet, generating a signed data packet; and uses the master key public key to encrypt the signed data packet, generating an encrypted data packet and storing it in a secure storage unit.
[0053] Once the mobile terminal is online, it uploads the encrypted data packet to the management terminal. The management terminal receives the encrypted data packet and decrypts it using the master key and private key. It then uses the private key of the retained auxiliary key to sign and verify the data packet after decryption. Finally, it performs an integrity check on the data to ensure that it has not been tampered with. After the check passes, the management terminal stores the decrypted data.
[0054] When offline, the auxiliary public key is used to sign data packets, and the signed data packets are immediately encrypted with the master public key for double protection. When online, the decryption process verifies the correctness of the encryption, avoids invalid transmission, and ensures that the management terminal only stores reliable information.
[0055] This invention provides an offline secure operation mobile terminal based on a metering communication authentication module. The mobile terminal includes a metering communication authentication module for realizing full lifecycle security management of offline operation data. When the mobile terminal is offline, it performs two-way authentication with a key distribution device through the metering communication authentication module to obtain and store a key for encrypted data transmission during offline operations.
[0056] Furthermore, the two-way authentication between the metering communication authentication module and the key distribution device includes: the mobile terminal sending a key acquisition command to the key distribution device using the metering communication authentication module; the key distribution device generating a master key pair and an auxiliary key pair; encrypting the auxiliary key pair using the master key's private key to generate an encrypted auxiliary key pair; and transmitting the encrypted auxiliary key pair and the master key's public key to the metering communication module offline; the metering communication module decrypting the encrypted auxiliary key pair based on the master key's public key to obtain the decrypted auxiliary key pair.
[0057] The various embodiments of the present invention have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments.
Claims
1. An offline safety operation method based on a metering communication authentication module, characterized in that... include: S1. The mobile terminal sends a key acquisition command to the key distribution device through the metering communication authentication module. The key distribution device generates a master key pair and an auxiliary key pair, and transmits the master key public key and the auxiliary key pair to the metering communication module offline and stores them in the secure storage unit. At the same time, the key distribution device transmits the master key private key and the auxiliary key private key to the management terminal. S2. Users authenticate their identity using a mobile phone and mobile terminal, establish a secure connection based on random numbers and key negotiation, and send work order instructions to the mobile terminal via the mobile phone to drive the mobile terminal to collect power equipment data or meter reading data. S3. When the mobile terminal is operating online, it collects power equipment data or meter reading data and communicates with the management terminal to transmit data. S4. When the mobile terminal is working offline, the power equipment data or meter reading data is used as the data to be transmitted. The metering communication module uses the auxiliary key to sign the data to be transmitted, and uses the master key to encrypt the signed data to be transmitted, generating an encrypted data packet and storing it in the secure storage unit. Once the mobile terminal is online, it uploads encrypted data packets to the management terminal, which then verifies and stores the data.
2. The offline security operation method based on the metering communication authentication module as described in claim 1, characterized in that... In S1, After generating a master key pair and an auxiliary key pair, the key distribution device uses the master key private key to encrypt the auxiliary key pair, generating an encrypted auxiliary key pair. The encrypted auxiliary key pair and the master key public key are then transmitted to the metering communication module offline. The metering communication module decrypts the encrypted auxiliary key pair based on the master key public key to obtain the decrypted auxiliary key pair.
3. The offline safe operation method based on the metering communication authentication module as described in claim 1, characterized in that... The offline method refers to transmission that does not rely on a network connection and uses a physical medium for transmission, such as a USB flash drive, external hard drive, or optical disc.
4. The offline safe operation method based on the metering communication authentication module as described in claim 1, characterized in that S2 include: S21. The mobile terminal sends an initial Bluetooth connection command through the metering communication module, and attaches the encrypted Bluetooth PIN code to the broadcast message; S22. The user uses a mobile phone to parse the broadcast message, enters the plaintext PIN code to decrypt it, and establishes connection information between the mobile phone and the mobile terminal. S23. The mobile terminal stores pairing information and sends a status acquisition command to perform authentication.
5. The offline safe operation method based on the metering communication authentication module as described in claim 4, characterized in that... In S23, the authentication includes: The mobile phone generates a random number R1 and sends a key negotiation start command to the mobile terminal. The mobile terminal calls the metering communication module to verify the random number R1 and returns a response message to the mobile phone. The mobile phone generates a random number R2 and sends a negotiation end command to the mobile terminal. The mobile terminal calls the metering communication module to verify the random number R2. If the verification is successful, the identity authentication is completed.
6. The offline security operation method based on the metering communication authentication module as described in claim 1, characterized in that... In S4, generating the encrypted data packet includes: S41. The metering communication module performs digital digest calculation on the data to be transmitted, generates a digital digest, and merges the digital digest with the data to be transmitted to generate a data packet; S42. The metering communication module uses the auxiliary key public key to sign the data packet and generate a signed data packet; it uses the master key public key to encrypt the signed data packet and generate an encrypted data packet.
7. The offline safe operation method based on the metering communication authentication module as described in claim 1, characterized in that... In S4, the data stored after verification by the management terminal includes: The management terminal receives encrypted data packets and decrypts them using the master key and private key; it then uses the auxiliary key and private key to sign and verify the decrypted data packets. Then, the data integrity is verified to ensure that it has not been tampered with; after the verification is successful, the management terminal stores the decrypted data.
8. The offline safe operation method based on the metering communication authentication module as described in claim 1, characterized in that... In S3, when the mobile terminal is operating online; The mobile terminal receives work order instructions, acquires power equipment data or meter reading data through the data acquisition unit, encrypts and signs the data through the metering communication module, and uploads it online to the management terminal; the management terminal decrypts and verifies the data before storing it.
9. An offline safety operation mobile terminal based on a metering communication authentication module, characterized in that... The mobile terminal includes a metering communication authentication module for realizing full lifecycle security management of offline operation data; when the mobile terminal is offline, it performs two-way authentication with the key distribution device through the metering communication authentication module to obtain and store the key for encrypted data transmission during offline operations.
10. The offline security operation mobile terminal based on the metering communication authentication module according to claim 1, characterized in that, The two-way authentication between the metering communication authentication module and the key distribution device includes: the mobile terminal sending a key acquisition command to the key distribution device using the metering communication authentication module; the key distribution device generating a master key pair and an auxiliary key pair; encrypting the auxiliary key pair using the master key private key to generate an encrypted auxiliary key pair; and transmitting the encrypted auxiliary key pair and the master key public key to the metering communication module offline; the metering communication module decrypting the encrypted auxiliary key pair based on the master key public key to obtain the decrypted auxiliary key pair.