Electricity utilization information collection terminal with multi-layer security isolation
By issuing acceptance tokens in the electricity consumption information collection terminal to bind link fingerprint digests and object permission levels, a backup bearer security channel is established, which solves the synchronization problem of link status verification and access control under severe fluctuations in interference from multiple transmission media, and realizes stable and reliable electricity consumption information collection.
Patent Information
- Application Number
- CN202511870018.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-12-12
AI Technical Summary
In scenarios involving the coexistence of multiple transmission media and severe interference fluctuations in electricity consumption information collection, existing systems struggle to transform the objective facts of link status into verifiable evidence without reducing password and authentication strength, and to maintain synchronous constraints with object-level access control, link switching, and confirmation processes for high-risk writes. This leads to increased risks of timeouts, erroneous executions, and replays within the business time window.
By issuing acceptance tokens through a secure chip, the link fingerprint digest, object permission level, and minimum password strength threshold are bound together. A secure channel is established on the backup bearer to verify fingerprint consistency, token validity, and no degradation. Dual bearer consistency is performed on high-risk writes. The object gate is unlocked using the link fingerprint digest and sequence check root. Evidence objects are periodically sent to drive minimum access control and parameter tuning.
It improved meter reading stability, reduced switching latency, avoided degradation and miswriting, simplified operation and maintenance supervision and network access acceptance, and ensured the verifiability of link status and the synchronization of access control.
Smart Images

Figure CN121309228B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power utilization information collection, in particular to a power utilization information collection terminal with multi-layer security isolation. BACKGROUND
[0002] In typical applications of power utilization information collection systems, electric energy meters in residential buildings, old communities, public building parks and industrial parks are connected to various transmission media, including power line carrier, micro-power wireless, cellular and Ethernet, through collection terminals. The terminals then interact with the master station according to the object data model to read data, events and control instructions. To improve coverage, two or more types of bearers can be configured in parallel in the same area and automatically selected based on measurement results. To meet safety management requirements, encryption authentication, minimum access control and boundary isolation are implemented in the production control area and access area.
[0003] The above approach can meet the basic needs in most environments, but in scenarios with complex noise and significant load fluctuations in low-voltage distribution networks, the terminal is long-term exposed to strong non-Gaussian background, periodic pulse and narrowband occupation interference: the availability of power line carrier subcarriers changes rapidly over time, the conflict and error frame rate increases; the channel busy occupation ratio of micro-power wireless increases in building-intensive and late peak periods; the round-trip delay and error rate fluctuate significantly in weak coverage or deep indoor locations.
[0004] Since there is a fixed business time window for meter reading and control, when the link health (quantified by health components) drops significantly and triggers switching, the use of complete reconstruction handshake and authentication procedures often leads to timeouts and multiple retries; if the password strength is reduced or the authentication parameters are relaxed to ensure connectivity, the access will no longer comply with the security protection regulations and the Cybersecurity constraints. At the same time, the existing systems generally lack a link state trusted basis that can be verified by the master station and the access area, making it difficult to synchronize the link facts and object-level access permissions; high-risk writes (such as control instructions, demand and power limit settings, etc.) in interference states rely heavily on single-channel confirmation, which is prone to misexecution or delayed execution under conditions of jitter, congestion and repeated arrivals. The lack of unified constraints on transaction order and anti-replay in the link switching process also causes uncertainty in object duplication, missing reports or rollback, which in turn leads to an increase in estimated reading, distorted line loss assessment, increased on-site work orders and customer complaint risks, and makes it difficult for the access area to dynamically converge with the minimum permissions, forming an engineering contradiction that connectivity, timeliness and security strength are difficult to satisfy simultaneously.
[0005] Therefore, the technical problem currently faced is: in collection scenarios where multiple transmission media coexist and interference fluctuates dramatically, how to convert the objective facts of link state into a basis that can be verified by the system without reducing the strength of the password and authentication, and synchronize the object-level access control, link switching and high-risk write confirmation process to avoid timeouts, misexecution and replay risks within the business time window. SUMMARY
[0006] (I) Technical problems solved
[0007] In view of the deficiencies of the prior art, the present application provides a power utilization information acquisition terminal with multi-layer security isolation, which binds a link fingerprint digest, an object permission gear and a minimum password strength threshold by issuing a token by a security chip, pre-builds a security channel on a backup bearer, checks fingerprint consistency, token validity and non-downgrade, and performs double-bearer consistency on high-risk writing, and unlocks object gates with the link fingerprint digest and sequence check root in the token, and periodically uploads evidence objects to drive minimum access control and parameter setting, which improves copy stability, reduces switching delay, avoids downgrade and miswriting, and is more convenient for operation and maintenance supervision and network acceptance, and solves the technical problems described in the background art.
[0008] (II) Technical solutions
[0009] To achieve the above object, the present application is implemented by the following technical solutions:
[0010] The power utilization information acquisition terminal with multi-layer security isolation comprises the following steps: collecting link indicators on each bearer, determining interference categories, synthesizing a link fingerprint digest by combining a bitmap, each indicator, interference categories, bearer identification and window timestamp to form an evidence package, issuing a token by a security chip according to the evidence package, the token containing a link fingerprint digest, an object permission gear, a minimum password strength threshold, a valid time limit and a signature, pre-building a security channel on a backup bearer, verifying link fingerprint consistency, token validity and signature, session strength not lower than the minimum password strength threshold, and performing double-bearer consistency on high-risk writable objects to complete the token.
[0011] Further, the available bitmaps of the subcarriers of the power line carrier are scanned to obtain a bitmap sequence, the frame error rate, collision rate, signal-to-noise ratio and round-trip delay of each bearer are quantified, and the link fingerprint digest is generated by concatenating the bearer identification, window timestamp and fixed sequence.
[0012] Further, the health score is generated in a smooth manner at the end of the sliding time window, and the health score, interference categories, link fingerprint digest, bearer identification and window timestamp are frozen together as an evidence package for subsequent reference.
[0013] Further, the signature key is derived in the security chip according to the bearer identification and window timestamp.
[0014] Sign the token body, which includes the link fingerprint digest, object permission level, minimum password strength threshold, validity period and monotonic counter, to obtain the acceptance token.
[0015] Furthermore, the object permission levels include three levels: read-only, low-risk writable, and high-risk writable; the minimum password strength threshold is not lower than the current session strength, and the acceptance token is written when issuing the acceptance token.
[0016] Furthermore, when the difference between the health score of the target carrier and the current carrier reaches the difference threshold and the minimum dwell time has been met, a pre-establishment handshake is initiated; before the handshake is completed, early-sent service messages are discarded and early-sent service messages do not enter the object layer processing queue.
[0017] Furthermore, after the pre-establishment handshake is completed, the acceptance qualification is determined by the following: the acceptance token is verifiable and has not expired; the link fingerprint digest is consistent with the recalculated local end; the session strength is not lower than the minimum password strength threshold and meets the joint strength criterion. If the qualification is not established, the read-only level is maintained.
[0018] Furthermore, dual-bearer consistency is as follows: for high-risk writable objects, pre-commit is sent in parallel on two different physical bearers and acknowledgments are received separately. If both paths confirm within the set consistency time limit, then the commit is made; otherwise, it is revoked and the read-only level is maintained.
[0019] Furthermore, the terminal recursively obtains the local sequence check root within the acceptance window according to a fixed encoding, and carries the link fingerprint digest in the acceptance token in the first batch of messages; the access side recalculates the sequence check root and unlocks the object gate after comparing it with the link fingerprint digest.
[0020] Furthermore, evidence objects are submitted according to statistical periods. The evidence objects include at least the remaining token lifetime, the current level of the object gate, the dual-bearer consistency statistics and the switching delay quantile, and the parameters of the difference threshold, minimum residence time and consistency time limit are updated accordingly.
[0021] (III) Beneficial Effects
[0022] This invention provides an electricity consumption information collection terminal with multi-layer security isolation, which has the following beneficial effects:
[0023] By collecting link indicators from each bearer and forming health scores, interference categories, and link fingerprint summaries, spectral features and time windows are bound into evidence packages, providing verifiable input for subsequent token issuance and acceptance qualifications. This reduces misjudgments and rule conflicts caused by selecting the best based on a single indicator, and unifies the bearer criteria and collection time benchmark.
[0024] The security chip issues a takeover token based on the evidence package, which binds the link fingerprint digest, object permission level and minimum password strength threshold together, and can converge in the same direction as the minimum access control on the access side, thereby eliminating mismatch between permission allocation and strength constraints and keeping it only increasing and not decreasing. The token field can be externally verified.
[0025] A secure channel is first established on the backup bearer, and fingerprint consistency, token validity, and no degradation are used as the qualifications for acceptance. Dual bearer consistency is performed on high-risk writable objects to ensure that the submission is only made when both physically different bearers have confirmed the connection. This controls timeouts, replays, and duplicate arrivals during the handover process and avoids repeated session renegotiations.
[0026] The dual proof of the link fingerprint digest and sequence check root in the acceptance token is used as a prerequisite for unlocking the object gate. The acceptance qualification, joint strength and consistency criteria are encoded as evidence objects and sent up, so that the transaction order, source and timeliness can be recalculated and verified, which facilitates the formation of traceable and inspectable operation records and supports operation review and handover. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of the power consumption information collection terminal with multi-layer security isolation according to the present invention. Detailed Implementation
[0028] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0029] Please see Figure 1 This invention provides an electricity consumption information collection terminal with multi-layer security isolation, comprising:
[0030] Step 1: Transform the link status of each bearer into calculable and auditable quantitative evidence, and provide verifiable input for subsequent tokenized authorization and the "build first, then dismantle" handover through a unified evidence package.
[0031] In the end office area, the power line carrier suffers from the superposition of periodic pulses, non-periodic pulses and narrowband occupation. The channel busy ratio of the micro-power wireless in the building dense area increases, and the round-trip delay quantile of the cellular in the deep indoor location moves up. If only a single indicator (such as signal-to-noise ratio or bit error rate) is used to select the best one, it cannot describe the spectrum shape change of the subcarrier bitmap over time and the influence of the interference type on the availability structure. Therefore, it is necessary to combine the multi-source measurements to generate a health score that can be compared across bearers, compress the spectrum shape and interference type into a link fingerprint summary that can be aligned, and finally form an evidence package and keep a strong binding with the time window, so as to provide a determination input for the authorization layer.
[0032] The physical and link indicators of each bearer are collected in a sliding time window, and then scaled in the time domain, and then the interference category is distinguished in the spectrum shape-index joint space. Then the subcarrier bitmap, the index quantile, the interference category, the window timestamp and the bearer identifier are combined into a link fingerprint summary, and the smoothed and recursive health score is written into the evidence package. The evidence package is frozen at the end of the window and called by the authorization layer. Since the health score and the link fingerprint summary share the same batch of original measurements, they can be verified together in the subsequent steps, reducing cross-layer inconsistencies.
[0033] Among them, the measurement dimensions of different bearers are not consistent, and the subcarrier bitmap of the power line carrier contains strong structural information. If they are not processed jointly in the same scale, it will lead to different permission mappings of the authorization layer for bearers with the same health degree. Therefore, first complete the dimension scaling and define a unified health score, and then perform spatial discrimination of the interference category based on it.
[0034] First, project the original indicators to a unified scale to calculate the health score; the health score not only retains sensitivity to frame error rate, conflict rate and delay quantile, but also expresses the penalty for low signal-to-noise ratio through inverse quantization of signal-to-noise ratio; then, the interference category is distinguished on the spectrum shape-index joint vector, and the interference category and the health score are jointly input into the next sub-step as the input of the link fingerprint summary.
[0035] The index group composed of frame error rate, conflict rate, signal-to-noise ratio inverse, and round-trip delay quantile value is the core, which suppresses the undue dominance of extreme values on the health score through saturation mapping, while ensuring comparability of different bearers.
[0036] Among them, first map the original indicators to a unified scale, and then index the scaled comprehensive quantity to a health score; the higher the health score, the higher the link reliability in the time window, which is expressed as follows:
[0037]
[0038] In the formula: health score : The output dimensionless score, the value is , as the core strength indicator of the evidence package; weight : non-negative weight of the four indicators, taking values and satisfying , adjust the contribution of each indicator to the health score; indicator component , , , : respectively represent the frame error rate , , the collision rate , , the inverse of the signal-to-noise ratio (taking the inverse of the signal-to-noise ratio and normalizing to by the upper limit of the engineering), and the round-trip delay quantile value (normalized to in milliseconds);
[0039] scale constant : positive number, used to control the saturation speed of different orders of magnitude, ;
[0040] The mapping function adopts logarithmic saturation + exponential decay to avoid single indicator dominance. The frame error rate and the collision rate are obtained by dividing the link layer frame count and the backoff / collision counter by the total number of frames in the window; the inverse of the signal-to-noise ratio is obtained by first truncating the physical layer signal-to-noise ratio (to avoid zero or negative) and then taking the inverse and normalizing; the round-trip delay quantile is obtained by sampling the probe packet-acknowledgment in the window and using the quantile loss minimization method or quantile.
[0041] Through the superposition of logarithmic saturation and exponential decay, the marginal change of the health score to the indicators shows gradually weakened sensitivity, avoiding the jump of the score caused by a single abnormal indicator; at the same time, it ensures that different bearers can be compared after the same mapping.
[0042] Further, discrimination is performed on the spectrum-index joint vector, so that the interference category can reflect the structural difference of the subcarrier bitmap and the coupling change of the indicators.
[0043] Construct a joint vector containing the subcarrier occupation ratio, low-dimensional embedding quantity of the available bitmap, frame error rate, collision rate, inverse of signal-to-noise ratio, and delay quantile value, and define a generalized distance with a symmetric positive definite weight matrix, select the category with the minimum distance as the interference category number, represented as follows:
[0044]
[0045] In the formula: generalized distance : the input vector to the distance to the class center, taking values as the criterion of class selection; joint vector : column vector obtained by concatenating the spectrum shape and the index, taking values ; class center vector : the center of the class in the joint space, taking values , representing the balanced pattern of the class;
[0046] weight matrix : symmetric positive definite matrix, taking values from the set of real symmetric matrices under semi-definite constraints, The acquisition method is offline training + online fine-tuning. Offline, the intra-class covariance is calculated with labeled samples and a diagonal approximation is made to obtain the initial value ; online, the residual energy of the sliding window is diagonally scaled to ensure positive definiteness. The class center is updated by exponential moving average, and the initial value comes from the offline clustering center.
[0047] The importance of each component is adjusted by the weight matrix, and the discrimination result can distinguish between the unusable subcarriers caused by periodic pulses and the strip-shaped occupation area caused by narrowband interference.
[0048] As an example: in the corridor meter box of an old community, the terminal accesses a special transformer meter and several single-phase meters, the subcarrier available bitmap obtained by power line carrier reading presents periodic gaps, the backoff count reported by the micro-power wireless increases, and the round-trip delay quantile value of the cellular increases. The terminal opens a sliding time window based on the corridor, inputs the frame error rate, conflict rate, signal-to-noise ratio, and round-trip delay quantile value into the health score mapping to obtain the health score; then the subcarrier occupation and the index vector are combined to calculate the generalized distance to the periodic pulse class center, which is smaller than that of other classes, and the output interference class is periodic pulse. When the window ends, the health score and the interference class are fixed as part of the subsequent link fingerprint summary.
[0049] Further, the authorized layer needs a reviewable fact summary that can stabilize the matching in two calls and provide quick verification to the outside. Storing the original bitmap and the index separately not only occupies resources but also is not conducive to interface standardization, so it is necessary to compress them into a link fingerprint summary while maintaining consistent binding with the time window and the bearer identifier.
[0050] The subcarrier available bitmap is scanned by row to obtain a bitmap sequence, the index quantile group is quantized to an integer sequence, and the interference class number, window timestamp, and bearer identifier are used as additional quantities; the above four types of quantities are mixed by weighting and taken modulo to obtain a fixed-length link fingerprint summary, which is then written into an evidence package together with the smoothed health score and the interference class; the evidence package is handed over to the authorized layer as the direct input for token issuance.
[0051] With bitmap sequence, quantization index sequence, interference category number, window timestamp as input, adopt weighted summation and modulus to generate fixed length digest. Four kinds of input are spliced in the order and weighted superposition with group weighting factor, and finally take modulus to get integer digest, as link fingerprint digest, as follows:
[0052]
[0053] Link fingerprint digest : output fixed length integer, value , as the matching key of evidence package and token verification; modulus : select large prime number; weighting factor : from The sequence is relatively prime to And screened by the greatest common divisor of 1; bitmap component : length prefix + big-end concatenation coding with quantization index component ;
[0054] Bitmap component : the first Bit obtained by scanning the subcarrier available bitmap, value , reflecting the subcarrier availability; quantization index component : the first Integer after quantization of each index component, non-negative integer, providing amplitude information; interference category number : category number, non-negative integer, indicating the interference form; window timestamp : time label at the end of the window, non-negative integer, binding the time window;
[0055] Weighting factor , , , : positive integer, value in modulus Below and relatively prime to each other, increase the distinguishability of different inputs to the digest; modulus : large integer, limit the digest range and enhance uniformity.
[0056] By relatively prime weighting and taking modulus, the digest of different spectrum and index combinations can be ensured not to be easily collided without revealing the original bitmap and index plaintext.
[0057] Furthermore, the instantaneous health score is recursively smoothed over time and linked to the rise / fall threshold and minimum dwell time to ensure the evidence package is frozen in a stable state. At the end of the current window, the health score is recursively smoothed once. If the smoothed health score is lower than the fall threshold and meets the dwell time requirement, it is marked as a downgraded state; otherwise, the current state is maintained. The evidence package is written with the smoothed health score and the state flag, as follows:
[0058]
[0059] where: smooth health score : No. The smoothing value for each window. Reduce instantaneous fluctuations; smooth historical health scores The smoothing value of the previous window, taking various values. Instant Health Score Current window health score, range is This reflects the current window quality; smoothness coefficient. : It is used to adjust the weights of historical and current periods.
[0060] By using recursive smoothing and state triggering, the evidence package is frozen only when the state is stable, avoiding frequent changes during the edge jitter stage; as an equivalent embodiment, the smoothing coefficient can take different values during the day and night, while still maintaining the same recursive form.
[0061] Step 2: Convert the evidence package output in Step 1 into a pass token that can be verified by the system and can directly constrain the object's permissions and password strength. Make the pass token the sole basis for switching qualifications and opening the object gate in the subsequent build-then-dismantle process.
[0062] Step one has already provided a smooth health score. Link fingerprint digest Interference category number The system must include a bearer identifier and a window timestamp. If access permissions are determined solely by the password strength already achieved in the current session and a static whitelist, the risk differences of interference categories and the time-varying nature of health scores cannot be incorporated into the same decision. Similarly, if access control is only implemented on the network side, the terminal side still lacks independently verifiable authorization credentials. Therefore, the mapping from link facts to object permissions to the minimum password strength threshold needs to be encapsulated as a pass token, signed by a security chip, and then released externally, thereby strictly linking authorization, authentication, and subsequent pass acceptance.
[0063] The permission decision must embody two kinds of constraints simultaneously: one is that the object permission level is graded according to the coupling change of health score and interference category, and the other is that the minimum password strength threshold cannot be lower than the level that has been reached in the current session, and triggers the promotion under the high-risk interference category. If the two are dispersed in decision-making, it will produce a fault that the permission has been relaxed but the password strength is still low, or a contradiction that the password strength has been promoted but the object is still unreachable. Therefore, the two quantities need to be determined simultaneously in the same formula system and written into the same token.
[0064] The smooth health score is inputted, and the object permission level (corresponding to the integer of read-only level, low-risk writable level, and high-risk writable level) and the minimum password strength threshold are obtained in the unified scoring field, both of which are written into the token content to ensure the consistency of authorization and strength.
[0065] First, the availability of the health score is measured by the saturation mapping, and then the caution degree brought by the interference is measured by the category penalty term, and the highest score among the three candidate permissions is selected as the object permission level , and the minimum password strength threshold is determined according to the same input and the current strength , taking the maximum value to form a strength constraint that does not decrease, and the specific way is as follows:
[0066]
[0067] In the formula, the object permission level : the output permission level, taking the value set , corresponding to the read-only level, low-risk writable level, and high-risk writable level; the weight coefficient : the positive weight of the first permission, taking the value , adjusting the response to availability; the penalty coefficient : the non-negative weight of the first permission, taking the value interval , adjusting the inhibition to caution;
[0068] The saturation mapping function : a monotonic saturation transformation is performed on the input, taking the specific form , where is a positive parameter; the category penalty function : maps the interference category to a non-negative caution, taking the specific form , where is a fixed non-negative quantity of the category;
[0069] The smooth health score : score from step one, taking values , representing the overall quality of the window; minimum password strength threshold : output threshold level, taking values from a discrete level in non-decreasing order, constraining the subsequent algorithm family and minimum key length; current achieved strength : current session actual strength level, taking values as above, ensuring only non-decreasing.
[0070] In use, the object permission and the minimum password strength are consistently adjudicated at the same time by the availableness-caution tradeoff within the same score field, eliminating the mismatch risk caused by independent determination.
[0071] The token body and the signature material are strictly distinguished, and the signature key is derived from the device root key according to the bearer identifier and the window timestamp, avoiding key reuse between different bearers or different windows. Assemble the token body (including link fingerprint digest , object permission gear , minimum password strength threshold , bearer level, valid time limit, monotonic counter), input into the key derivation function with the device root key , bearer identifier , window timestamp , to obtain the signature key ; then the token body is signed by the secure chip in the restricted execution environment, and the token is output, as follows:
[0072]
[0073] In the formula: signature key : the key output by the derivation function, taking values belonging to the key space, valid only under the given bearer and time window; device root key : the root key saved in the secure chip, taking values belonging to the key space, the root of key derivation; bearer identifier : a discrete quantity marking the current bearer, from a finite set; window timestamp : the time when the evidence package is frozen, a non-negative integer;
[0074] derivation function : a collision-resistant key derivation function, which can be a composite mapping of round-by-round compression and mixing, to obtain the signature key from the root key; taking the derivation based on the salted message authentication code (root key , concatenated bearer identifier , window timestamp , counter c_{#} compressed by multiple rounds);
[0075] Token body : structured bit string to be signed, taking value as a column of bits in space : signature of token body, taking value as a column of bits in space
[0076] Signature function : unforgeable signature mapping, taking specific form as elliptic curve class or national cryptographic algorithm implemented in secure chip : taking national cryptographic algorithm / elliptic curve signature; both are completed in secure chip, and peripheral only receives signature result and public parameter, meeting the requirement of key not out of chip
[0077] In use, through double-part field derivation of bearing and time window, token cannot be reused under wrong bearing or expired window; token body and signature material are separated, facilitating subsequent expansion of token field without changing signature strategy.
[0078] As an example: in concentrator cabinet of power distribution room in park, maintenance personnel retrieve evidence package of last window through local human-machine interface. Screen displays smooth health score, interference category and bearing identifier by substation. Maintenance personnel select to issue token, and terminal calls secure chip: first generate token body containing link fingerprint digest, object permission gear, minimum password strength threshold, valid time limit and monotonic counter, and then return signed token with signature by secure chip. Object list of read-only level unlocked, low-risk writable level pending bearing and high-risk writable level pending consistency of double bearing appears on screen. Maintenance personnel do not make any parameter adjustment, and token issuance is completed and stored in pending queue.
[0079] Further, bearing token needs to be reliably checked at access end or host station end, and form a same direction closed loop with bearing level, object gate, and network side minimum access control. If checking only does signature verification without comparing link fingerprint digest, token may be misappropriated across window or across bearing; if only comparing digest without considering valid time limit, token may be misused after expiration; if only restricting object at terminal side while network side still retains wide range, it is easy to be used horizontally. Therefore, token checking must meet three types of criteria at one time, and checking result is synchronized to boundary device.
[0080] Taking consistent digest, valid time limit and strength not reduced as three criteria that must be met at the same time, any one not meeting is rejected for bearing and maintaining read-only level. In access end, token body and signature are analyzed, after verifying signature, link fingerprint digest , current time and current session strength are read from local cache, according to which remaining life is calculated and joint criterion is constructed, only when joint criterion is true, object gate is promoted from read-only level to object permission gear in token , wherein:
[0081]
[0082] Remaining lifetime : Time to live minus current time, interval [0, ∞) , determine whether the token is within the valid period; Time to live : Time determined by token lifetime and window timestamp, non-negative integer, define the token invalid boundary; Current time : Current time read by the access end, non-negative integer, construct lifetime; Joint criterion : Boolean value, value set is , as the final criterion for qualification; Indicator function : Function that takes 1 if the condition is true, otherwise 0, combine multiple conditions into a single criterion; Local digest : Link fingerprint digest cached by the access end, value set is the same as in the token ; Current session strength : Session strength level measured by the access end, from a discrete level set; Minimum password strength threshold : Strength lower limit from the token body, value is the same as above.
[0083] In use, the joint criterion couples the digest consistency, time limit validity, and strength non-decrease three elements at once, avoiding the race window brought by item-by-item release; The bearer binding is implicitly guaranteed by digest consistency + bearer identifier consistency, and the same token cannot be reused on different bearers.
[0084] Further, the object permissions on the terminal side are consistent with the minimum access control on the network side. After the joint criterion is established, the access end maps the object permission level in the token to the minimum access control rule set on the network side, and binds the rule set with the bearer level; When the token expires or any criterion is false, the network side rules are automatically recycled to the read-only level, and the write request is limited and discarded. To avoid inconsistent rules between different devices, the access end generates deterministic rule key values according to the bearer identifier and object category, so that the same object set gets the same rule performance on different devices.
[0085] The object permissions are consistent on the terminal side and the network side, and the write path is limited to the object set allowed by the token; When the bearer switches or the token is invalid, the network side rules are recycled in time to avoid lagging wide range.
[0086] Step three, establish a secure channel on the standby bearer and maintain the password and authentication strength of only upgrade, determine whether to undertake the existing session through token verification and link fingerprint comparison, then perform double-bearer consistency on high-risk writing, and finally complete smooth migration without destroying object gate and transaction order in the way of building first and dismantling later.
[0087] The second step outputs the undertaking token, which has given the object permission level and the minimum password strength threshold , and is verified by the link fingerprint summary and signature value . The implementation source and integrity are verifiable. However, if the link is directly disconnected and then reconnected, it is easy to cause timeout and repeated arrival within the business time window; if the algorithm family and key length negotiated are not subject to the only upgrade hard criterion, the security will be weakened for connectivity.
[0088] Therefore, the evidence package and the undertaking token are needed as the common basis to establish a secure channel on the standby bearer, and the qualification-strength-object unidirectional constraint is applied throughout the whole process of the handshake until the object gate is controllable. For high-risk writing, double-bearer consistency is added to make the reachable redundancy rise to a safe confirmation semantic.
[0089] The decision should consider the health improvement amplitude of the target bearer compared to the current bearer and the minimum length of time the current bearer has been resident to prevent link shaking back and forth.
[0090] The terminal reads the smooth health score of the current window and the last window at the end of each observation window and the smooth health score of the candidate bearer , calculates whether the difference between the two exceeds the difference threshold, and calculates whether the resident length of the current bearer reaches the minimum resident length . If both conditions are met, the pre-build handshake of the standby bearer is triggered:
[0091]
[0092] In the formula: trigger criterion : the value is or 1, which triggers pre-building when ; smooth health score , : the scores of the current bearer and the target bearer at time , respectively, ranging from to 100, coming from the first step and used in the second step;
[0093] Difference threshold : a positive number, giving the minimum health improvement required for triggering; resident length : current bearer's continuous residence time since last switch, in seconds; residence duration accumulated by monotonic timer; bearer health score : taken from step one's window output, time-aligned to the window's end time; minimum residence duration : positive number, to ensure not to be triggered frequently in short time.
[0094] In use, the criterion combines health gain and residence stability into a single Boolean, to avoid both invalid switch and long-term stay on already degraded bearer.
[0095] In the handshake phase of pre-built channel, three rigid checks are done: one is whether the negotiated algorithm family and key length are not lower than the minimum password strength threshold ; two is whether the token taken is not expired and signature verifiable; three is to prohibit early business message of zero round trip from participating in any business write.
[0096] The terminal attaches the token header to the target bearer side along with the handshake at the same time of initiating the handshake; the access end or master station compares the validity period by comparing the current time with the expiration time after verifying the signature, and compares the strength with the session strength level returned by the handshake, all three of which must be met to return the acceptable token; early business message flag is true, then directly discarded, until the complete handshake is completed to allow entering the object layer, wherein:
[0097]
[0098] In the formula: joint strength criterion : take value or , when , it means that the encryption and authentication strength negotiated by both sides of the handshake are not lower than the threshold; the negotiation strength , : the session strength level confirmed by both sides of the handshake, from the handshake return, using the same measurement scale as ; the negotiation strength and the current strength are mapped from the algorithm family + key length returned by the handshake to discrete levels, and the mapping table (for example, mapping the algorithm family sequence and key length dictionary sequence to integers) is consistent between the terminal and the access end; the minimum password strength threshold : from step two, the non-decreasing threshold.
[0099] Through joint comparison, any side's strength rollback will immediately make the joint strength criterion , the handshake continues but the acceptance is denied; at the same time, the early business message is directly discarded, avoiding the replay injection when the handshake is not completed.
[0100] Combine all the prerequisites in step three into a single acceptance qualification value, and at the instant the qualification is established, raise the object gate from read-only level to the object permission level indicated in the acceptance token. Otherwise, it will remain read-only.
[0101] After completing signature verification, the access point recalculates the link fingerprint digest for the current window. Link fingerprint digest carried by the terminal Compare and read the current time at the same time. With token expiration time Compare whether it is still within the validity period, and then use the current session strength. With minimum password strength threshold Perform a non-downgraded comparison. If all three conditions are met, then the joint strength criterion from the previous step is added. Upon obtaining the qualification value, if the qualification is valid, the object sequence window and retransmission buffer are copied, and the process proceeds to the switch point of "build first, then dismantle":
[0102]
[0103] Where: Qualification value : Values or When the value is 1, acceptance is allowed; Link fingerprint digest Local summary value : Fixed-length bit string, obtained from the second step of issuance and recalculation at the local end respectively; Expiration time Current time : Non-negative integer, comparison validity period; current session strength The strength level confirmed by this end after the handshake, and the measurement scale. Consistency; minimum password strength threshold From step two; Joint strength criterion See above.
[0104] The overall qualification criterion consists of four necessary conditions in parallel, in product form; failure to meet any one of them will immediately disqualify the candidate. To avoid a competitive situation caused by releasing each item one by one; the raising of the object gate must be strictly delayed after the qualification is established, ensuring that qualification comes first and then authority comes later.
[0105] Furthermore, reachability redundancy is elevated to a security confirmation semantic. This applies when the object permission level... When a high-risk writable object is indicated, the terminal will only perform the final commit after both physically different bearers return pre-commit confirmations within the time limit; otherwise, it will roll back and maintain the read-only level. At the same time, in the convergence phase of the build-then-tear phase, the old bearer waits for the new bearer to complete the object window alignment before being dismantled to ensure that the object sequence numbers are continuous.
[0106] After the new bearer passes the eligibility criteria, the terminal sends the same object's pre-commit on both bearers in parallel, records the return time on both sides and compares whether they both fall within the consistency time limit If yes, it sends the commit to the master station and marks the old bearer as pending removal after confirmation; if either bearer times out or returns a negative acknowledgement, it broadcasts rollback, the object gate is returned to read-only level, and waits for the next window to retry, wherein:
[0107]
[0108] In the formula: consistency criteria : take the value of or 1, which allows the final commit when 1; return duration 、 : the return duration of the same pre-commit on two physically different bearers; consistency time limit : positive number, set according to the characteristics of the substation and the bearer.
[0109] When used, only when both bearers meet the criteria at the same time, high-risk write is allowed, and accidental jitter of a single link will not be amplified into misexecution; the convergence of building first and removing later is aligned with the object window, avoiding duplication or omission.
[0110] As an example: in the underground power distribution room of an office building, the terminal detects that the smooth health score of the micro-power wireless is continuously higher than that of the power line carrier, and the current bearer has been resident for more than the minimum residence time, prompting the user to prepare to pre-build on the micro-power wireless. After the pre-build handshake is sent, the access end reads the acceptance token, displays that the signature is valid, and returns that the negotiation strength is not lower than the threshold. After the terminal receives the acceptance mark, the object gate is raised from the read-only level to the low-risk writable level. At this time, the master station issues a fee control write instruction, and the terminal sends the write on the power line carrier and the micro-power wireless simultaneously, both of which return confirmation within the time limit, and the master station returns that the commit has been recorded, and the terminal removes the old bearer immediately. The entire process does not accept any early business message, and the object list on the screen only displays write records with consecutive numbers.
[0111] Step four, in the business stage after the acceptance is completed, the ordered unlocking of the object gate is driven by the double proof of the link fingerprint digest and the sequence verification root as the precondition, and the key criteria in the acceptance process are solidified as evidence objects uploaded, and then the evidence is used to realize the same direction convergence of the minimum access control and parameter threshold on the access side and the substation side, forming the closed loop of object transaction-evidence-policy.
[0112] The third step has given the acceptance eligibility value , joint strength criterion , consistency criterion and object permission level If the link fingerprint digest is directly written after the completion of the takeover, it is easy to cause transaction sequence number jump and replay during the window boundary or cache playback; if it only depends on the token without checking the sequence state of the local cache, it cannot prove the continuity of the first batch of objects after the takeover and the cache queue before the takeover on the time axis.
[0113] Therefore, it is necessary to take the matching of the link fingerprint digest and the continuous recursion of the sequence verification root as sufficient and necessary conditions for unlocking, and to encapsulate the operation quantity such as whether to downgrade, whether to expire, whether to achieve consistency, and switching delay quantization into evidence objects; the access area recycles or relaxes the network side access control, and the station area adjusts the switching difference threshold , the minimum residence time , and the consistency time limit according to the evidence, so as to convert the takeover quality into a self-consistent strategy on the operation side.
[0114] In order to prove the time and sequence number continuity of the first batch of objects after the takeover and the cache queue before the takeover, it is necessary to maintain the sequence verification root in a local irreversible compression mapping.
[0115] The terminal merges the object identifier, object sequence number, window timestamp, and message authentication value of each object record into a record segment , concatenates it with the last round verification root at the window boundary in row sequence, and then sends it to the anti-collision compression mapping to obtain a new verification root ; when the takeover is successful and the joint strength criterion is true, the of the current window is frozen as the takeover window verification root, and its digest is taken out with the first batch of business messages:
[0116]
[0117] In the formula: sequence verification root : a fixed-length bit string with a value range of compression mapping, proving the continuity and integrity of the object sequence; last round verification root : the verification root frozen in the last time window, a bit string, as a recursive input; record segment : a bit string obtained by splicing the object identifier, object sequence number, window timestamp, and message authentication value, a limited-length bit string;
[0118] Anti-collision compression mapping : a monotonic and deterministic hash function, the input is an arbitrary length bit string, and the output is a fixed-length bit string; The fixed-length splicing of the object identifier, object sequence number, window timestamp, and message authentication value, each field with a 16-bit length prefix, is an anti-collision hash; and the concatenation symbol Concatenate the content according to the prefix without ambiguity;
[0119] Parallel symbol : Binary string concatenation operator, used to concatenate the previous check root. With Recording Fragments Serial connection.
[0120] When used, it is generated through recursion. If any object record is deleted or inserted after acceptance, the verification root will be changed, and the access end can reject or roll back accordingly.
[0121] Furthermore, the four criteria of link fingerprint digest matching, sequence check root matching, validity period not expired, and acceptance qualification are combined into a single unlocking criterion to eliminate the gap of only verifying the token and not the sequence or only verifying the sequence and not the token.
[0122] After receiving the first batch of object messages, the access end calculates the local sequence check root for the current window. Link fingerprint digest Each is different from the terminal carrying with the message. and Compare and read the current time at the same time. With expiration time Compare the validity periods, and finally add up the qualification value. When all four conditions are met, the object gate is raised from read-only to read-only. The indicated gear level; if any condition is not met, it will revert to read-only level, where:
[0123]
[0124] Where: Unlocking criterion : Boolean value, taking values Or 1, for Time allows press Unlock; Link fingerprint digest Local summary value : Fixed-length bit strings, derived from the second-step issuance and the recalculation at the access end, proving the token's binding to the window; sequence check root. Local sequence check root Fixed-length bit strings, derived from terminal recursion and access recursion respectively, prove that the object sequences are consistent;
[0125] Expiry date Current time : A non-negative integer, used to verify the token's validity period; qualification value. As mentioned above, ensure that eligibility to accept the task is unlocked before it is granted.
[0126] In use, the Boolean structure of the four-condition product ensures that any mismatch cannot be unlocked, avoiding the transfer of power based on one-sided evidence; if the access end runs in a restricted environment and cannot recalculate , the boundary isolation device can be used to recursively pass and return the comparison results, but the four conjuncts do not change.
[0127] As an example: an industrial control screen next to a concentrator in the park, the operation and maintenance personnel observe that the completion is accepted, and only read-level prompts are allowed. Then the master station issues a read-write combination message for a group of objects, and the terminal generates a new sequence check root for each record segment in the local cache, and puts the check root and the link fingerprint digest into the first batch of uploaded messages. After receiving it, the access end displays that the link fingerprint digest is consistent, the sequence check root is consistent, it is not expired, and the qualification is true, and the object gate is immediately upgraded from the read-only level to the low-risk writable level; one of the high-risk write in the same batch is confirmed in the report because the third step has performed double-bearer consistency. The object list on the screen is displayed continuously by serial number without skipping and repeating.
[0128] Further, to achieve verifiable policy convergence on the access side and the park side, key operating quantities need to be encoded into fixed-length fields and formed into digests to reduce message size.
[0129] The qualification value , the joint strength criterion , the consistency criterion , the object permission level , the link fingerprint digest , the expiration time , the current time , the switching delay fraction number , the unlocking criterion are arranged in a vector in the order of agreement, then linearly mixed with coprime weighting factors and taken modulo a large modulus to obtain evidence digest , which is uploaded together with the evidence object:
[0130]
[0131] where: evidence digest : fixed-length integer, value , used to quickly verify the consistency of the fields of the evidence object; mixed weight : positive integer, coprime with modulus , amplifying the discrimination of different fields; field component : mapped to the integer domain by one by one, as the mixed input; modulus : large integer, limiting the digest range and enhancing uniformity; field number : positive integer, equal to the number of encoded fields.
[0132] In use, through a coprime-weighted modulo condensation method, the evidence object can still be preserved even after fragmentation and merging at the transport layer. Fast verification of overall consistency; where hybrid substitution is equivalent to taking the remainder of a convolutional polynomial over an irreducible polynomial, summary. The length remains unchanged.
[0133] To ensure long-term stability of service quality, it is necessary to set a switching difference threshold based on the evidence. Consistency time limit Minimum stay duration Make small, directional adjustments, and simultaneously reflect the object permission level in the minimum access control rules on the network side.
[0134] The proportion of failed projects attributed to ineligibility within the previous statistical period is statistically analyzed. Percentile of consistency timeouts The ratio of switching frequency to dwelling breach , and their respective target references , , A bias vector is constructed; the bias is linearly mapped using a diagonal gain matrix to obtain a parameter update vector, which is then written back after being bounded by upper and lower limits; on the network side, object permission levels are used. The current unlock result is written to or reclaimed in the minimum access control, where:
[0135]
[0136] Where: parameter vector : Column vector, elements are as follows Three thresholds to be adjusted; updated parameter vector : Column vector, representing the new threshold after tuning in this period; gain matrix A diagonal matrix, where the elements on the main diagonal are positive step sizes. Adjust the convergence speed of the three thresholds; bias vector : Column vector, elements are as follows The difference between actual operation and target reference is injected into the update; The results are divided into three components, which are obtained by subtracting the target value from the percentage of insufficient acceptance qualifications, the target value from the consistency timeout percentile, and the target value from the percentage of short-stay switching. It is a diagonal matrix, with the main diagonal being the step size. and use upper and lower boundaries to define It is clamped within the allowable range of the project.
[0137] Switching the difference threshold : positive number, corresponding to the difference threshold in the third step trigger criterion; consistency time limit : positive number, corresponding to the time limit of the third step consistency criterion; minimum residence duration : positive number, corresponding to the residence constraint before the third step trigger; failure ratio : target ratio : real number between and , measuring the occurrence intensity of insufficient qualifications; timeout percentile : target percentile : non-negative real number, unit: second, quantile comparison of consistency return duration; residence breach ratio : target ratio : real number between and , measuring the frequency of short residence switching.
[0138] When in use, the parameter updates operate in a small step linear law, avoiding oscillation and converging in the direction indicated by the evidence; the network side minimum access control and object permission level are recycled and relaxed at the same pace, and the terminal side and the access side form a same direction strategy. Among them, the gain matrix may be replaced by a diagonal segmented gain matrix, which changes the step size when the bias crosses the threshold, but the vector form remains unchanged.
[0139] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0140] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0141] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiment is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0142] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0143] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A power consumption information collection terminal with multi-layer security isolation, characterized in that: include, For each bearer collecting link indicators, the interference category is determined, and the bitmap, each indicator quantile, interference category, bearer identifier and window timestamp are combined into a link fingerprint digest to form an evidence package; The security chip issues a handover token based on the evidence package. The handover token includes a link fingerprint digest, object permission level, minimum password strength threshold, validity period and signature. In the pre-built secure channel of the backup bearer, the handshake verifies that the link fingerprint digest is consistent, the acceptance token is valid and verifiable, and the session strength is not lower than the minimum password strength threshold. After performing dual bearer consistency on high-risk writable objects, the acceptance is completed. After acceptance, the first batch of messages carries the link fingerprint digest in the acceptance token and the local sequence check root; if they match and are within the validity period, the object gate is unlocked according to the object permission level, and the evidence object is periodically sent up. The subcarriers of the power line carrier can be scanned to obtain a bitmap sequence. The frame error rate, collision rate, signal-to-noise ratio inverse and round-trip delay of each bearer are uniformly quantized and then concatenated with the bearer identifier and window timestamp in a fixed order to generate a link fingerprint digest. At the end of the sliding time window, a health score is generated in a smooth manner, and the health score, interference category, link fingerprint summary, bearer identifier and window timestamp are frozen together as an evidence package for subsequent reference.
2. The power consumption information collection terminal with multi-layer security isolation according to claim 1, characterized in that: A signature key is derived within the security chip based on the bearer identifier and the window timestamp. Sign the token body, which includes the link fingerprint digest, object permission level, minimum password strength threshold, validity period and monotonic counter, to obtain the acceptance token.
3. The power consumption information collection terminal with multi-layer security isolation according to claim 2, characterized in that: The object permission levels include three levels: read-only, low-risk writable, and high-risk writable. The minimum password strength threshold is no less than the current session strength, and the acceptance token is written when issuing the acceptance token.
4. The power consumption information collection terminal with multi-layer security isolation according to claim 3, characterized in that: When the difference between the health score of the target carrier and the current carrier reaches the difference threshold and the minimum dwell time has been met, a pre-establishment handshake is initiated; before the handshake is completed, early-sent service messages are discarded and early-sent service messages do not enter the object layer processing queue.
5. The power consumption information collection terminal with multi-layer security isolation according to claim 4, characterized in that: After the pre-establishment handshake is completed, the acceptance qualification is determined by the following: the acceptance token can be verified and has not expired, the link fingerprint digest is consistent with the recalculated local end, the session strength is not lower than the minimum password strength threshold and the joint strength criterion is met. If the qualification is not met, it is kept at the read-only level.
6. The power consumption information collection terminal with multi-layer security isolation according to claim 5, characterized in that: Dual-bearer consistency means that for high-risk writable objects, pre-commit is sent in parallel on two different physical bearers and acknowledgments are received separately. If both paths confirm within the set consistency time limit, then the commit is made; otherwise, it is revoked and the read-only level is maintained.
7. The power consumption information collection terminal with multi-layer security isolation according to claim 6, characterized in that: The terminal recursively obtains the local sequence check root within the acceptance window according to a fixed encoding, and carries the link fingerprint digest in the acceptance token in the first batch of messages; the access side recalculates the sequence check root and unlocks the object gate after comparing it with the link fingerprint digest.
8. The power consumption information collection terminal with multi-layer security isolation according to claim 7, characterized in that: Evidence objects are submitted according to the statistical period. The evidence objects include at least the remaining token lifetime, the current level of the object gate, the dual-bearer consistency statistics and the switching latency quantile, and the parameters of the difference threshold, minimum residence time and consistency time limit are updated accordingly.
Citation Information
Patent Citations
Semantic fingerprint adaptive training method for teaching service robot
CN120653994A
Detection method and detection system for digital output synchronism of mutual inductor
CN121037252A