Operation and maintenance method and system of wireless equipment, electronic device and storage medium
By using dynamic session keys and anomaly behavior database verification mechanisms, the problem of low security in wireless device operation and maintenance is solved, realizing dynamic verification of device identity and encrypted transmission, thereby improving the security and trustworthiness of wireless devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-03-27
AI Technical Summary
The operation and maintenance of wireless devices are characterized by low security. The single-key encryption mechanism is easily cracked or counterfeited, leading to risks of data leakage and unauthorized control.
A dynamic session key mechanism is adopted, which generates a root key through a certificate management platform and updates the session key at preset time intervals. Combined with an abnormal behavior database and a dynamic interception mechanism, the device identity is verified and information transmission is encrypted to ensure the security of device information.
It improves the security of wireless device operation and maintenance, reduces the risk of key cracking and imitation, and enhances the trustworthiness and security of device access.
Smart Images

Figure CN121751160A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular to methods, systems, electronic devices, and storage media for the operation and maintenance of wireless devices. Background Technology
[0002] Against the backdrop of the booming rise and rapid development of smart cities, the application fields of IoT smart wireless devices are constantly expanding and their application depth is continuously deepening, making them an indispensable key element in smart city construction. These wireless devices, through wireless communication technology, achieve real-time and accurate monitoring of the operating status of remote equipment. Whether it's key parameters such as temperature, humidity, and pressure, or dynamic information such as work progress and operating efficiency, everything can be captured and fed back immediately. Simultaneously, remote equipment can be controlled, and operating modes and parameter settings can be adjusted according to actual needs to ensure that the equipment is always in optimal operating condition, providing strong support for the intelligent operation of the city.
[0003] However, the entities connected to wireless devices in different areas of different cities are not static but dynamically changing. At the same time, the environments in which these wireless devices operate are complex, diverse, and constantly changing. Under these circumstances, there is an urgent need for a solution that is both highly reliable and easy to maintain, in order to meet the requirements for dynamic operation and maintenance configuration of the connected entities.
[0004] To address the security issues of wireless device access, the current main approach is to use a single-key encryption mechanism for wireless device authentication. However, this simple encryption and verification mechanism is easily cracked or counterfeited, resulting in poor trustworthiness of wireless device identities and security risks such as data leakage and unauthorized control.
[0005] There is currently no effective solution to the problem of low security during the operation and maintenance of wireless devices in related technologies. Summary of the Invention
[0006] This embodiment provides a method, system, electronic device, and storage medium for the operation and maintenance of wireless devices to address the problem of low security during the operation and maintenance of wireless devices in related technologies.
[0007] Firstly, this embodiment provides a method for the operation and maintenance of a wireless device, applied to a wireless device, the method comprising:
[0008] In response to the access request from the business platform, a current session key is generated, and device information is sent to the registration platform for registration based on the current session key; wherein, the current session key is generated at preset time intervals;
[0009] Upon receiving the IP address and port of the configuration management platform issued by the registration platform, and after logging into the configuration management platform, initiate registration with the configuration management platform;
[0010] After successfully registering with the configuration management platform, the system receives access information from the business platform issued by the configuration management platform.
[0011] Based on the access information of the business platform, access the business platform to conduct business interactions.
[0012] In some embodiments, the registration platform includes an abnormal behavior database used to verify whether the wireless device conforms to the registration specifications of the registration platform.
[0013] In some embodiments, the abnormal behavior database stores abnormal behaviors of the wireless device, including the number of login attempts exceeding a preset value within a preset time and the current geographical location of the wireless device not conforming to a preset location range.
[0014] In some embodiments, the device information includes the production batch code of the wireless device, the actual geographical location of the wireless device, and the serial number of the wireless device.
[0015] In some embodiments, the step of initiating login to the configuration management platform based on receiving the IP address and port of the configuration management platform issued by the registration platform includes:
[0016] Determine whether the current session key is within the specified time limit;
[0017] If so, log in to the configuration management platform using the current session key.
[0018] In some embodiments, the access information of the service platform includes: the IP address of the service platform, the port of the service platform, the username of the service platform, the password of the service platform, and the encryption method of the service platform.
[0019] In some embodiments, when the wireless device becomes offline, the following is also included:
[0020] Determine whether the current session key is valid;
[0021] If so, the connection between the wireless device and the registration platform is restored based on the current session key;
[0022] Otherwise, the certificate management platform receives the reset session key for the current session key, and the system re-registers and logs in to the registration platform and the configuration management platform based on the reset session key to restore the connection with the business platform.
[0023] The certificate management platform is used to manage the session keys of the wireless device.
[0024] Secondly, this embodiment provides a wireless device operation and maintenance system, which applies the wireless device operation and maintenance method described in the first aspect above. The wireless device operation and maintenance system includes: a wireless device, a certificate management platform, a registration platform, a configuration management platform, and a service platform.
[0025] The wireless device is used to respond to the access request of the service platform and perform service interactions with the service platform;
[0026] The certificate management platform is used to distribute the root key of the wireless device and manage the session key of the wireless device;
[0027] The registration platform is used to verify the login and registration of the wireless device, and to send the IP address and port of the configuration management platform to the wireless device;
[0028] The configuration management platform is used to verify the login and registration of the wireless device, and to send the login information of the service platform to the wireless device, so that the wireless device can access the service platform according to the login information of the service platform and perform business interactions with the service platform.
[0029] Thirdly, this embodiment provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the operation and maintenance method of the wireless device described in the first aspect.
[0030] Fourthly, this embodiment provides a storage medium storing a computer program that, when executed by a processor, implements the operation and maintenance method of the wireless device described in the first aspect above.
[0031] Compared with related technologies, the wireless device operation and maintenance method provided in this embodiment generates a current session key in response to the access request of the service platform, and registers the device by sending device information to the registration platform based on the current session key; wherein, the current session key is generated at a preset time interval; after receiving the IP and port of the configuration management platform issued by the registration platform and logging into the configuration management platform, the method initiates registration with the configuration management platform; after successfully registering with the configuration management platform, the method receives the access information of the service platform issued by the configuration management platform; and according to the access information of the service platform, the method accesses the service platform for service interaction, thereby solving the problem of low security in the operation and maintenance of wireless devices and improving the security of wireless device operation and maintenance.
[0032] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0033] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0034] Figure 1 This is a hardware structure block diagram of the terminal of the wireless device operation and maintenance method in this embodiment.
[0035] Figure 2 This is a flowchart of the operation and maintenance method of the wireless device in this embodiment.
[0036] Figure 3 This is a flowchart of another wireless device operation and maintenance method in this embodiment.
[0037] Figure 4 This is an interactive flowchart of the operation and maintenance method of the wireless device according to a preferred embodiment.
[0038] Figure 5 This is a structural block diagram of the wireless device operation and maintenance system in this embodiment. Detailed Implementation
[0039] To better understand the purpose, technical solution, and advantages of this application, the application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0040] Unless otherwise defined, the technical or scientific terms used in this application shall have the general meaning understood by one of ordinary skill in the art to which this application pertains. Words such as “a,” “an,” “an,” “the,” “the,” and “these” used in this application do not indicate quantitative limitation and may be singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include steps or modules (units) not listed, or may include other steps or modules (units) inherent to these processes, methods, products, or devices. Words such as “connected,” “linked,” and “coupled” used in this application are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. Normally, the character " / " indicates that the objects before and after it are in an "or" relationship. The terms "first," "second," "third," etc., used in this application are merely to distinguish similar objects and do not represent a specific order of objects.
[0041] The method embodiments provided in this example can be executed on a terminal, computer, or similar computing device. For example, it can run on a terminal. Figure 1 This is a hardware structure block diagram of the terminal for the operation and maintenance method of the wireless device in this embodiment. For example... Figure 1 As shown, a terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 and a memory 104 for storing data are also included. The processor 102 may be, but is not limited to, a microprocessor (MCU) or a programmable logic device (FPGA). The terminal may also include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that… Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the terminal described above. For example, the terminal may also include components that are larger than... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown are illustrated.
[0042] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the wireless device operation and maintenance method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0043] The transmission device 106 is used to receive or send data via a network. This network includes a wireless network provided by the terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 can be a Radio Frequency (RF) module used for wireless communication with the Internet.
[0044] This embodiment provides a method for the operation and maintenance of wireless devices. Figure 2 This is a flowchart of the operation and maintenance method of the wireless device in this embodiment, as follows: Figure 2 As shown, the process includes the following steps:
[0045] Step S201: Respond to the access request from the service platform, generate the current session key, and send device information to the registration platform for registration based on the current session key; wherein, the current session key is generated at preset time intervals.
[0046] Specifically, in this embodiment, the wireless device can be a 3G wireless device, a 4G wireless device, or a 5G wireless device. During the wireless device manufacturing stage, the wireless device uses its own MAC address's SHA256 hash value and chip ID as the certificate source value, and submits the certificate source value to the certificate management platform through a secure channel (e.g., TLS 1.3). After verifying the certificate source value, the certificate management platform issues a root key and solidifies the root key certificate into the trusted execution partition hardware security zone of the wireless device. The root key is immutable, and session keys are dynamically generated based on the root key at preset time intervals. For example, the session key is automatically updated every 24 hours, thereby avoiding the risk of total security due to single-key leakage.
[0047] When a wireless device leaves the factory, it randomly generates an initial session key (such as a 256-bit symmetric key) through a Hardware Security Module (HSM) or Trusted Execution Environment (TEE). This initial session key is then used to encrypt device information before being sent end-to-end to the registration platform and configuration management platform. The registration platform and configuration management platform perform identity registration, parameter configuration, and other operations on the wireless device, assigning it a unique identifier to provide the foundation for subsequent session key protocols or authentication. Notably, the registration platform and configuration management platform only store the key hash value, never transmitting it in plaintext. This ensures that even if the transmission channel is intercepted, attackers cannot decrypt the key, or even if the platform database is compromised, attackers can only obtain the hash value and cannot use it for actual encryption or decryption. For the encryption algorithm, the Chinese national standard SM4 or the international standard AES-256 can be used to encrypt the initial session key, thereby reducing the risk of session key leakage.
[0048] In addition, during the manufacturing process of wireless devices, a registration platform address needs to be fixed to the wireless device. The domain name or IP address of the registration platform is written into the hardware security zone using a burning tool to ensure that the address cannot be tampered with, thereby preventing the device from being guided to a malicious platform. The root certificate of the wireless device issued by the certificate management platform is also fixed to prevent the wireless device from being tampered with.
[0049] Following this, the wireless device combines the device serial number and authentication key in a certain way to perform an "HMAC-SHA512" digital signature, and then transmits the digital signature and device serial number wirelessly to the registration platform. The combination of the device serial number and authentication key can be a fixed format such as "SN||AuthKey", or it can be combined using a key hash message authentication code (HMAC-SM3) based on the SM3 hash algorithm to generate an intermediate value, which is then used as input data for the "HMAC-SHA512" digital signature, thus forming a multi-dimensional identity transmission.
[0050] When a business platform needs to perform business through a wireless device, the wireless device encrypts its device information, including its serial number, using a current session key generated at preset time intervals based on the root key. For example, using algorithms such as HKDF (HMAC-based Key Derivation Function) or PBKDF2, a session key is dynamically generated using the root key as a seed, combined with parameters such as timestamps and random numbers. Key rotation is triggered every 24 hours, and time is synchronized via the TEE's internal clock or an external NTP service to ensure key timeliness. The encrypted device information is then submitted to the registration platform for registration. Upon receiving the device registration request, the registration platform first parses the device serial number (SN) in the request and queries the database for the device's pre-stored platform-side key information (such as PlatformKey). The PlatformKey can be a symmetric key shared with the device (such as an HMAC key) or the device's public key (if an asymmetric signature is used). Here, we assume the use of a symmetric key (HMAC-SHA512 scenario). The registration platform uses the retrieved platform-side key information (PlatformKey or SessionDerivedKey) to calculate an HMAC-SHA512 signature on key data (such as SN+Timestamp+GeoLocation) in the device registration request, generating a platform signature (PlatformSignature). The registration platform extracts the device-side HMAC-SHA512 signature (DeviceSignature) generated by the device from the device registration request and compares it with its own calculated platform signature (PlatformSignature). If DeviceSignature = PlatformSignature, it means the device holds the correct platform key information (PlatformKey) and the request has not been tampered with; verification passes. If they do not match, it may be a counterfeit device or the transmission may have been tampered with, and registration fails.
[0051] Step S202: After receiving the IP address and port of the configuration management platform from the registration platform and logging into the configuration management platform, initiate registration with the configuration management platform.
[0052] Specifically, after a wireless device successfully registers with the registration platform, the platform returns the IP address and port of the configuration management platform to the wireless device after encrypting them with a session key. The wireless device initiates a login using the configuration management platform's IP address and port. If the current session key is still valid, the wireless device uses it to encrypt the MQTT connection request. If the current session key has expired, a newly generated session key is used to encrypt the MQTT connection request, and a secure channel is established via TLS 1.3. The configuration management platform decrypts the MQTT message through the TLS layer to verify the device's identity (e.g., certificate or PSK). If verification is successful, the wireless device is allowed to log in to the configuration management platform.
[0053] After successfully logging in as a wireless device, it initiates registration with the configuration management platform. The wireless device connects to the configuration management platform via MQTT overTLS 1.3, encrypting the CONNECT message using a pre-allocated dynamic session key. The configuration management platform decrypts the CONNECT message and verifies the validity of the dynamic session key and the timestamp. If the verification passes, it returns a CONNACK message (status code 0x00 indicates success), and the wireless device enters a logged-in but not registered state. After verifying the validity of the dynamic session key, the wireless device sends a registration request to the platform's specified topic (e.g., / device / register) via an MQTT PUBLISH message. The registration request includes the following key information:
[0054] Unique device identifier: such as serial number (SN), MAC address or IMEI (must be consistent with the information stored on the platform).
[0055] Equipment type and model: Used for platform allocation model configuration.
[0056] Digital signature: The device uses its private key (DevicePrivateKey) to calculate a signature (such as ECDSA-SHA256) on key fields of the registration request (such as SN + Timestamp) to prevent message tampering.
[0057] The configuration management platform queries pre-stored information (such as device public key, tenant, and authorization status) based on the device serial number (SN) to verify whether the device belongs to the legitimate whitelist. It then decrypts the Signature using the device's pre-stored public key to verify message integrity and sender identity. If the verification passes, the configuration management platform updates the wireless device status from "Logged in but not registered" to "Registered and online" and assigns MQTT subscription permissions (e.g., allowing subscription to the ` / device / SN123456 / command` topic). The platform then sends the registration result to the device via a PUBLISH MQTT message (topic such as ` / device / SN123456 / register / response`).
[0058] If registration is successful, the system returns {"Status":"Success","SessionID":"abc123"}, and the device can begin normal communication. If registration fails, the system returns an error code (e.g., {"Status":"Failed","ErrorCode":"0x01"}) and the reason (e.g., "Device not authorized" or "Signature verification failed"). After receiving a successful response, the wireless device records the current SessionID (for subsequent session management) and begins periodically sending heartbeat packets (e.g., publishing the / device / SN123456 / heartbeat topic every 5 minutes) to maintain its online status.
[0059] Step S203: After successfully registering with the configuration management platform, receive the access information of the business platform issued by the configuration management platform.
[0060] Specifically, the configuration platform reserves configuration interfaces and interfaces for access business platforms (access entities). These interfaces must include an "operation log auditing" function, automatically recording the operator, operation time, and content before and after each modification (such as changing IP or password). The logs must be immutable (e.g., written to a blockchain for evidence storage) to meet compliance and traceability requirements. The business platform (access entity) submits a registration request to the configuration management platform, including its unique identifier (e.g., business platform ID, organization code), digital certificate (for two-way TLS encryption authentication), and basic metadata (e.g., business platform name, business domain). After verifying the certificate's validity, the configuration management platform generates a temporary session token and returns a registration success response. Upon successful registration, the configuration management platform dynamically generates access information based on the business platform's permission policy (e.g., RBAC model), including:
[0061] Network parameters: Business platform IP (supports IPv4 / IPv6), port (distinguishing between service types, such as management port / data port), DNS resolution rules;
[0062] Authentication credentials: Username (supports multiple roles, such as administrator / operator), password (enforces a complexity policy), API key (short-term validity and can be rotated);
[0063] Security configuration: Encryption algorithm (such as AES-256, SM4), transport protocol (TLS 1.3), two-way authentication switch;
[0064] Service routing information: load balancer cluster address, circuit breaker threshold, and degradation strategy.
[0065] Furthermore, all information is sent through encrypted channels (such as SFTP or HTTPS) and accompanied by digital signatures to ensure integrity.
[0066] After receiving the access information, the business platform automatically triggers the configuration synchronization process:
[0067] Parse the access parameters and write them to the local configuration library (such as Consul or Zookeeper).
[0068] Generate a local service certificate (issued by the configuration management platform CA);
[0069] Start the health check interface (e.g., / healthz) and report the status to the configuration management platform;
[0070] If the configuration fails, an alarm will be triggered and the system will roll back to the previous stable version.
[0071] After the business platform and the configuration management platform are successfully connected, the configuration management platform sends the access information of the business platform to the wireless devices.
[0072] Step S204: Based on the access information of the business platform, access the business platform to conduct business interactions.
[0073] Specifically, after the wireless device obtains the access information of the business platform issued by the configuration management platform, it establishes a connection with the business platform according to the access information of the business platform. The wireless device collects business data (such as sensor readings and status information), encapsulates it in the format required by the business platform (such as JSON and Protobuf), adds metadata (such as timestamps and device IDs), encrypts the data and transmits it to the business platform. The business platform records the operation log.
[0074] Through steps S201 to S204 above, in response to the access request from the service platform, a current session key is generated, and device information is sent to the registration platform for registration based on the current session key. The current session key is generated at preset time intervals. After receiving the IP address and port of the configuration management platform from the registration platform and logging into the configuration management platform, registration is initiated with the configuration management platform. After successful registration with the configuration management platform, access information from the service platform is received from the configuration management platform. Based on the access information from the service platform, the device accesses the service platform for service interaction. Compared with the single-key encryption mechanism used in existing technologies for wireless device authentication, this embodiment generates a dynamic key by generating a session key at preset time intervals. The wireless device uses the dynamic key to log in and register with the registration platform and configuration management platform, reducing the risk of key cracking and imitation, and improving the security of wireless device operation and maintenance.
[0075] In some embodiments, the registration platform includes an abnormal behavior database used to verify whether wireless devices comply with the registration platform's registration specifications. The database stores abnormal behaviors of wireless devices, including exceeding a preset number of login attempts within a preset time period and the wireless device's current geographical location not conforming to a preset location range.
[0076] Specifically, in this embodiment, the registration platform also includes an abnormal behavior database and a dynamic interception mechanism. The abnormal behavior database records suspicious behaviors of wireless devices during the registration process. Abnormal behaviors include high-frequency registration, abnormal geographical location, and high signature failure rate. High-frequency registration refers to wireless devices with the same SN initiating registration requests exceeding a threshold (e.g., 3 times) within a short period (e.g., within 10 minutes). Abnormal geographical location refers to a significant deviation between the initial registration location of the wireless device and its production location (e.g., cross-provincial or cross-border location differences). High signature failure rate refers to multiple consecutive signature verification failures by wireless devices with the same SN. The dynamic interception mechanism detects abnormal behaviors in the database. When any abnormal behavior in the database is detected, the registration platform rejects the wireless device's registration request and returns an error code or retry delay. Simultaneously, the security administrator is notified via email, SMS, or WeChat, along with device information (SN, GeoLocation, timestamp) and the type of abnormality. The administrator can manually query the device's historical registration records to decide whether to permanently ban the SN or adjust the interception rules. By setting up an abnormal behavior database and a dynamic interception mechanism, the security of wireless device access can be further improved.
[0077] In another embodiment, the device information includes the production batch code of the wireless device, the actual geographical location of the wireless device, and the serial number of the wireless device.
[0078] Specifically, wireless devices send encrypted device information to the registration platform for registration. This information includes the device's production batch code, actual geographical location, and serial number. The serial number verifies the device's identity, the production batch code indicates its designated usage area, and the actual geographical location at the time of registration confirms whether the device's registration location matches the area specified at the time of manufacture. If not, registration is rejected, thus improving the security of wireless device access.
[0079] In some embodiments, based on receiving the IP address and port of the configuration management platform from the registration platform, a login is initiated to the configuration management platform, including:
[0080] Determine whether the current session key is within its specified validity period;
[0081] If so, log in to the configuration management platform using the current session key.
[0082] Specifically, after a wireless device successfully registers with the registration platform, it receives the IP address and port of the configuration management platform from the registration platform. Before initiating login to the configuration management platform, the wireless device first verifies the validity of the current session key, determining whether the current session key is within the specified time limit (e.g., within 24 hours of its generation). If so, it encrypts the device information using the current session key and initiates registration with the configuration management platform. Otherwise, it regenerates the session key, uses the newly generated session key to encrypt the device information, and transmits the encrypted device information to the configuration management platform for registration. By using a real-time generated session key to encrypt the device information before registering with the platform, the security of wireless device access can be improved.
[0083] In another embodiment, the access information of the business platform includes: the IP address of the business platform, the port of the business platform, the username of the business platform, the password of the business platform, and the encryption method of the business platform.
[0084] Specifically, the service platform identifies its network location (supporting IPv4 / IPv6 and primary / backup IPs) through its IP address and port, and specifies the service listening port (such as HTTP 80, MQTT 1883) to avoid port conflicts. The service platform's username identifies the accessed platform. The security of service data transmitted from wireless devices to the service platform is ensured through the service platform's password and encryption method.
[0085] In some embodiments, when the wireless device becomes offline, the following is also included:
[0086] Determine if the current session key is valid;
[0087] If so, then restore the connection between the wireless device and the registration platform based on the current session key;
[0088] Otherwise, the system receives the reset session key from the certificate management platform and re-registers and logs in to the registration platform and configuration management platform based on the reset session key to restore the connection with the business platform; the certificate management platform is used to manage the session keys of wireless devices.
[0089] Specifically, when a wireless device interacts with a service platform, and the connection between the wireless device and the registration platform is interrupted, the system first checks if the wireless device's current session key is still valid. This is done by comparing the wireless device's offline duration with the validity period of the current session key. If the offline duration is less than the validity period, the session key is still valid, and a reconnection request is initiated to the registration platform using the valid session key. After verifying the key's validity, the registration platform restores the connection between the wireless device and the registration platform, restoring the wireless device's session state. If the offline duration is greater than or equal to the validity period of the current session key, the wireless device sends a key reset request to the certificate management platform. After verifying the wireless device's identity (e.g., through a pre-shared key or challenge-response mechanism), the certificate management platform generates a new session key, signs it, and distributes it to both the wireless device and the registration platform. The wireless device uses the new key to re-authenticate, and upon successful authentication, resumes the connection with the registration platform, restores its device metadata, and re-establishes a secure channel with the service platform based on the new session key, re-subscribing to the service entity or API endpoint. When a wireless device loses connection, and the current session key is invalid, the certificate management platform resets the wireless device's session key. The new session key then reconnects the wireless device to the registration platform, thus restoring business interaction between the wireless device and the service platform. The dynamic password generation mechanism enhances the security of wireless device access. The certificate management platform is used to distribute the root key and root certificate of the wireless device, and to manage the session key of the wireless device.
[0090] This embodiment also provides a method for the operation and maintenance of wireless devices. Figure 3 This is a flowchart of another wireless device operation and maintenance method in this embodiment, such as... Figure 3 As shown, the process includes the following steps:
[0091] Step S301: The wireless device responds to the access request from the service platform, generates a current session key, and sends device information to the registration platform for registration based on the current session key; wherein, the current session key is generated at preset time intervals; the device information includes the production batch code of the wireless device, the actual geographical location of the wireless device, and the serial number of the wireless device;
[0092] Step S302: Determine whether the wireless device has been successfully registered on the registration platform. If yes, proceed to step S303; otherwise, proceed to step 310.
[0093] Step S303: Register the IP address and port of the configuration management platform issued by the registration platform to the wireless device;
[0094] Step S304: Determine whether the current session key of the wireless device is within the specified time limit. If yes, proceed to step S305; otherwise, proceed to step S311.
[0095] Step S305: The wireless device logs into the configuration management platform according to the current session key;
[0096] Step S306: Determine whether the wireless device has successfully logged into the configuration management platform. If yes, proceed to step S307; otherwise, proceed to step S312.
[0097] Step S307: The wireless device initiates registration with the configuration management platform;
[0098] Step S308: Determine whether the wireless device registration configuration management platform is successful. If yes, proceed to step S309; otherwise, proceed to step S313.
[0099] Step S309: Configure the access information of the service platform issued by the configuration management platform to the wireless device; the wireless device accesses the service platform to perform service interaction based on the access information of the service platform.
[0100] In step S310, the registration platform rejects the registration of the wireless device.
[0101] Step S311: The wireless device generates a new session key at a preset time interval, uses the new session key as the current session key, and returns to execute step S305.
[0102] Step S312: Configure the management platform to deny login from wireless devices.
[0103] Step S313: The configuration management platform rejects the registration of wireless devices.
[0104] Through steps S301 to S313, when a wireless device initiates registration with the registration platform, or initiates login and registration with the configuration management platform, a dynamic session key generated at a preset time interval is used for encryption. This prevents a single key from being stolen and malicious wireless devices from connecting to the service platform. Furthermore, the production batch code and actual geographical location of the wireless device are added to the device information, increasing the complexity of the encrypted device information and thus improving the security of the registration platform's verification, thereby enhancing the security of wireless device access.
[0105] The present embodiment will now be described and illustrated through preferred embodiments.
[0106] Figure 4 This is an interactive flowchart of the operation and maintenance method of the wireless device according to this preferred embodiment. Figure 4 As shown, the operation and maintenance of the wireless device in this embodiment includes a registration platform, a configuration management platform, the wireless device, and a service platform. The wireless device initiates a registration request to the registration platform. Upon receiving the registration request, the registration platform verifies the device information of the wireless device. If the verification is successful, it returns the IP and port information of the configuration management platform to the wireless device. The wireless device uses the obtained configuration management platform information to log in to the configuration management platform via the MQTT protocol. The configuration management platform verifies the login information of the wireless device. If the verification is successful, it returns a login success message. After successful login, the wireless device initiates a registration request to the configuration management platform. The registration platform determines whether the wireless device has already registered with the registration platform. If not, it performs the registration operation and returns a registration success response to the wireless device. After successful registration, the wireless device enters a loop, periodically sending heartbeat requests to the configuration management platform. Upon receiving the heartbeat request, the configuration management platform sets access subject information for the wireless device, and the wireless device returns a response result to the configuration management platform. This process is repeated cyclically to maintain the connection between the wireless device and the configuration management platform. While maintaining a heartbeat connection, the wireless device communicates normally with the service platform based on the access subject information provided by the configuration management platform. The service platform returns a normal communication result to the wireless device. The service platform can configure cloud management hosting by sending a cloud management hosting request to the wireless device. The wireless device processes the cloud management hosting request and returns a hosting response to the service platform. If the service platform chooses not to host, the configuration management platform will disconnect the cloud management connection to ensure customer privacy. Throughout this process, all data is encrypted using a dynamic session key generated by the wireless device at preset time intervals.
[0107] This embodiment also provides a wireless device operation and maintenance system, which applies the wireless device operation and maintenance methods described in the above embodiments. Figure 5 This is a structural block diagram of the wireless device operation and maintenance system in this embodiment, as shown below. Figure 5 As shown, the wireless device operation and maintenance system includes: wireless device 51, certificate management platform 52, registration platform 53, configuration management platform 54, and service platform 55;
[0108] Wireless device 51 is used to respond to access requests from service platform 55 and perform service interactions with service platform 55;
[0109] Certificate management platform 52 is used to distribute the root key of wireless device 51 and manage the session key of wireless device 51;
[0110] Registration platform 53 is used to verify the login and registration of wireless device 51, and to send the IP address and port of configuration management platform 54 to wireless device 51;
[0111] The configuration management platform 54 is used to verify the login and registration of the wireless device 51, and to send the login information of the service platform 55 to the wireless device 51, so that the wireless device 51 can access the service platform 55 according to the login information of the service platform 55 and perform business interactions with the service platform 55.
[0112] This embodiment also provides an electronic device including a memory and a processor, the memory storing a computer program and the processor being configured to run the computer program to perform the steps in any of the above method embodiments.
[0113] Optionally, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.
[0114] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:
[0115] S1, responding to the access request from the business platform, generates the current session key, and sends device information to the registration platform for registration based on the current session key; wherein, the current session key is generated at preset time intervals;
[0116] S2, after receiving the IP address and port of the configuration management platform from the registration platform and logging into the configuration management platform, initiates registration with the configuration management platform;
[0117] S3, after successfully registering with the configuration management platform, receives access information from the business platform issued by the configuration management platform;
[0118] S4, based on the access information of the business platform, accesses the business platform to conduct business interactions.
[0119] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementations, and will not be repeated in this embodiment.
[0120] Furthermore, in conjunction with the wireless device operation and maintenance methods provided in the above embodiments, this embodiment can also provide a storage medium for implementation. The storage medium stores a computer program; when executed by a processor, the computer program implements any of the wireless device operation and maintenance methods described in the above embodiments.
[0121] It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. All other embodiments derived by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0122] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0123] Obviously, the accompanying drawings are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar situations based on these drawings without any creative effort. Furthermore, it is understood that although the work done in this development process may be complex and lengthy, for those skilled in the art, certain design, manufacturing, or production modifications made based on the technical content disclosed in this application are merely conventional technical means and should not be considered as insufficient disclosure of this application.
[0124] The term "embodiment" in this application refers to a specific feature, structure, or characteristic described in connection with an embodiment that may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily imply the same embodiment, nor does it imply that it is mutually exclusive with or independent of other embodiments. It will be clearly or implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0125] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0126] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of patent protection. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the appended claims.
Claims
1. A method for the operation and maintenance of a wireless device, applied to a wireless device, characterized in that, The method includes: In response to the access request from the business platform, a current session key is generated, and device information is sent to the registration platform for registration based on the current session key; wherein, the current session key is generated at preset time intervals; Upon receiving the IP address and port of the configuration management platform issued by the registration platform, and after logging into the configuration management platform, initiate registration with the configuration management platform; After successfully registering with the configuration management platform, the system receives access information from the business platform issued by the configuration management platform. Based on the access information of the business platform, access the business platform to conduct business interactions.
2. The operation and maintenance method for wireless devices according to claim 1, characterized in that, The registration platform includes an abnormal behavior database, which is used to verify whether the wireless device complies with the registration specifications of the registration platform.
3. The operation and maintenance method for wireless devices according to claim 2, characterized in that, The abnormal behavior database stores the abnormal behaviors of the wireless device, including the number of login attempts exceeding a preset value within a preset time and the current geographical location of the wireless device not conforming to a preset location range.
4. The operation and maintenance method for wireless devices according to claim 1, characterized in that, The device information includes the production batch code of the wireless device, the actual geographical location of the wireless device, and the serial number of the wireless device.
5. The operation and maintenance method for wireless devices according to claim 1, characterized in that, The step of initiating a login to the configuration management platform after receiving the IP address and port number of the configuration management platform issued by the registration platform includes: Determine whether the current session key is within the specified time limit; If so, log in to the configuration management platform using the current session key.
6. The operation and maintenance method for wireless devices according to claim 1, characterized in that, The access information of the business platform includes: the IP address of the business platform, the port of the business platform, the username of the business platform, the password of the business platform, and the encryption method of the business platform.
7. The operation and maintenance method for wireless devices according to claim 1, characterized in that, When the wireless device becomes offline, the method further includes: Determine whether the current session key is valid; If so, the connection between the wireless device and the registration platform is restored based on the current session key; Otherwise, the certificate management platform receives the reset session key for the current session key, and the system re-registers and logs in to the registration platform and the configuration management platform based on the reset session key to restore the connection with the business platform. The certificate management platform is used to manage the session keys of the wireless device.
8. A wireless device operation and maintenance system, employing the wireless device operation and maintenance method according to any one of claims 1 to 7, characterized in that, The operation and maintenance system for the wireless device includes: wireless device, certificate management platform, registration platform, configuration management platform, and service platform; The wireless device is used to respond to the access request of the service platform and perform service interactions with the service platform; The certificate management platform is used to distribute the root key of the wireless device and manage the session key of the wireless device; The registration platform is used to verify the login and registration of the wireless device, and to send the IP address and port of the configuration management platform to the wireless device; The configuration management platform is used to verify the login and registration of the wireless device, and to send the login information of the service platform to the wireless device, so that the wireless device can access the service platform according to the login information of the service platform and perform business interactions with the service platform.
9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to perform the operation and maintenance method of the wireless device according to any one of claims 1 to 6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the operation and maintenance method for the wireless device according to any one of claims 1 to 6.