Safety interaction control method of smart electric energy meter, smart electric energy meter and interaction system

By generating one-time access tokens and dynamic identification codes for near-field communication verification, combined with Bluetooth Low Energy communication, the system addresses the insufficient intelligence level of smart meters, payment security risks, and scenario adaptation issues, enabling instant and reliable payment and billing control, and supporting seamless payment for mobile users.

CN122372227APending Publication Date: 2026-07-10SHENZHEN CLOU ELECTRONICS +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN CLOU ELECTRONICS
Filing Date
2026-06-10
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing smart meters suffer from insufficient intelligence, significant security risks in payment and data interaction, and poor flexibility in adapting to different scenarios, making it impossible for users to achieve instant scanning and seamless payment.

Method used

By generating a one-time access token bound to a smart energy meter, performing near-field communication verification and data signing based on a dynamic identification code, and combining Bluetooth Low Energy communication, the system achieves synergy between dynamic token generation, near-field communication verification, and data signing, ensuring the security and flexibility of the payment chain.

Benefits of technology

It enhances the security of static QR codes, prevents replay attacks and illegal tampering, enables instant and reliable payment and billing control, supports automated settlement of prepaid and postpaid models, and adapts to mobile user scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372227A_ABST
    Figure CN122372227A_ABST
Patent Text Reader

Abstract

This application proposes a secure interactive control method for smart meters, a smart meter, and an interactive system, relating to the field of smart grid technology. The secure interactive control method includes: generating a one-time access token based on the smart meter's identity, dynamic factor, and key information; generating a dynamic identification code based on the one-time access token; refreshing the dynamic identification code according to the validity period of the one-time access token; receiving a near-field communication connection request, the connection request carrying a token to be verified parsed from the dynamic identification code; verifying whether the token to be verified matches the locally stored one-time access token; and, after successful verification, signing the current electricity consumption data and sending the signed current electricity consumption data to an external terminal via a near-field communication link; receiving business processing information and performing local billing status updates and / or power on / off control based on the business processing information. The dynamic identification code in this application ensures the security of the payment instruction source.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of smart grid technology, and more specifically, to a safe interactive control method for a smart energy meter, a smart energy meter, and an interactive system. Background Technology

[0002] In related technologies, with the popularization of the Internet of Things and mobile payment technologies, the intelligence of electricity meters has evolved from remote meter reading to user interaction and business model innovation. However, current electricity metering and billing solutions still have three major shortcomings:

[0003] First, the level of intelligence is insufficient. Traditional postpaid / remote fee control requires binding an account number for payment, which is cumbersome. Integrated circuit card prepaid payment requires offline top-up and cannot achieve real-time interaction of electricity consumption data and value-added services, resulting in low management efficiency.

[0004] Second, there are significant security risks associated with payment and data interaction. Existing static QR codes are easily tampered with and cloned, and lack near-field two-way authentication mechanisms, making them vulnerable to replay attacks and man-in-the-middle hijacking, thus compromising the security of funds and data.

[0005] Third, the system lacks flexibility in adapting to different scenarios. The fixed account number-based system cannot adapt to scenarios with mobile users such as leasing and sharing. The settlement of lease terminations relies on manual processes and it is difficult to support prepaid / postpaid switching and dynamic pricing strategies.

[0006] Therefore, there is an urgent need for a smart metering solution that integrates IoT identity recognition, secure payment, and flexible scenario adaptation to realize a new electricity consumption model for users that allows for "scan-to-use and seamless payment". Summary of the Invention

[0007] The present invention aims to solve the technical problems of insufficient intelligence, prominent security risks in payment and data interaction, and poor flexibility in scenario adaptation in existing or related technologies.

[0008] Therefore, the first aspect of the present invention proposes a safe interactive control method for smart energy meters.

[0009] A second aspect of the present invention provides a smart energy meter.

[0010] A third aspect of the present invention provides an interactive system for smart energy meters.

[0011] In view of this, a first aspect of the present invention provides a secure interactive control method for a smart energy meter, comprising: generating a one-time access token bound to the smart energy meter based on the smart energy meter's identity identifier, dynamic factor, and pre-stored key information, and generating a dynamic identification code based on the one-time access token; displaying the dynamic identification code and refreshing the dynamic identification code according to the validity period of the one-time access token; receiving a near-field communication connection request initiated by an external terminal based on the dynamic identification code, the connection request carrying a token to be verified parsed from the dynamic identification code; verifying whether the token to be verified matches the locally stored one-time access token, and after successful verification, signing the current electricity consumption data and sending the signed current electricity consumption data to the external terminal through a near-field communication link; receiving business processing information fed back by an external platform based on the current electricity consumption data, and performing local billing status updates and / or power on / off control according to the business processing information.

[0012] In this application, the smart meter includes a metering module, a main control and security module, a human-machine interaction module, a communication module, a data storage module, and a control module. The secure interactive control method for the smart meter includes: generating a one-time access token bound to the smart meter based on the smart meter's identity identifier, dynamic factor, and pre-stored key information, and generating a dynamic identification code based on the one-time access token; displaying the dynamic identification code and refreshing it according to the validity period of the one-time access token; receiving a near-field communication connection request initiated by an external terminal based on the dynamic identification code, the connection request carrying a token to be verified parsed from the dynamic identification code; verifying whether the token to be verified matches the locally stored one-time access token, and after successful verification, signing the current electricity consumption data and sending the signed current electricity consumption data to the external terminal through the near-field communication link; receiving business processing information fed back by the external platform based on the current electricity consumption data, and performing local billing status updates and / or power on / off control according to the business processing information.

[0013] This technical solution addresses the issues of static QR codes being easily tampered with or covered, the lack of proactive security authentication on the device side in the payment chain, and the inability to achieve one-click payment through direct device connection by the synergy of a series of technical features such as dynamic token generation, near-field communication verification, and data signature.

[0014] Specifically, the smart meter generates a one-time access token bound to it based on its own identity, dynamic factor, and pre-stored key information, and then generates a dynamic identification code based on the one-time access token. Because the token generation relies on the device's unique identity and dynamic factor, each generated identification code is different and cannot be predicted or reused, further reducing the security risks of static QR codes being easily tampered with and copied, and preventing replay attacks and unauthorized alteration. The smart meter refreshes the dynamic identification code according to the validity period of the one-time access token, ensuring the timeliness of the QR code. Even if the dynamic identification code is intercepted, it cannot be used after the expiration date, further enhancing security.

[0015] After an external terminal scans the dynamic identification code, it is not directly redirected to the payment page. Instead, it must first initiate a near-field communication connection request carrying a token to be verified. This step establishes the first layer of security authentication after scanning the code. Upon receiving the connection request, the smart meter's main control and security modules verify whether the token to be verified matches the locally stored one-time access token. Only after successful verification are subsequent steps executed. This mechanism of token verification on the device's local premises ensures that only legitimate external terminals that have scanned the genuine dynamic identification code can establish a connection with the target smart meter, effectively preventing unauthorized terminals or man-in-the-middle attacks.

[0016] After successful verification, the smart meter signs the current electricity consumption data and sends the signed data to the external terminal via a near-field communication link. The technical advantage here is that the bill data displayed to the user before payment is not platform-only data, but trusted data signed by the smart meter's security element. Only after the external terminal verifies the signature does it display a trusted payment interface, preventing data tampering during transmission and resolving the issue of bill information forgery that could result from man-in-the-middle attacks.

[0017] Finally, the smart meter receives business processing information from the external platform based on current electricity consumption data. This information includes payment confirmation results, balance changes, rate configuration parameters, and / or power on / off control commands. Based on this information, the smart meter performs local billing status updates and / or power on / off control. The action after payment is not simply remote accounting, but directly triggers a deterministic change in the smart meter's local state, such as balance updates, power on / off switching. This localized, deterministic control logic ensures the real-time performance, accuracy, and security of billing and power supply control, enabling correct actions based on locally stored states even after a brief communication interruption.

[0018] In some technical solutions of this application, the dynamic factor includes at least one of timestamp, random number and count value; the dynamic identification code is a dynamic QR code, and the dynamic identification code is updated when at least one of the following conditions is met: the refresh cycle expires, the one-time access token is used, and the number of token verification failures reaches a threshold.

[0019] The above technical solution further defines the generation factors and update mechanism of the dynamic identification code. Using timestamps, random numbers, and count values ​​as dynamic factors further enhances the unpredictability of the token and identification code. While a single random number might exhibit patterns when a pseudo-random algorithm is attacked, combining the ever-changing physical quantity of timestamps with the strictly increasing sequence of operations of count values ​​ensures that even if an attacker obtains the random number generation algorithm at a certain moment, they cannot deduce the next dynamic code, greatly enhancing anti-replay and anti-prediction capabilities. Multiple update conditions (periodic refresh, one-time password, anomaly locking) form a closed-loop token lifecycle management system. The use of one-time access tokens as a limiting condition implements the key security feature of "one-time password." Once any QR code is successfully scanned and verified, the corresponding token immediately becomes invalid, reducing the risk of payment codes being screenshotted and reused to some extent. The condition of "verification failure count reaching a threshold" provides proactive defense capabilities. When a brute-force attack attempt is detected, the smart meter immediately and proactively updates the dynamic QR code, completely invalidating the old code in the attacker's hands, thus ensuring the overall security resilience of the system.

[0020] In some technical solutions of this application, a one-time access token is marked as used after successful verification to prevent the same one-time access token from being used again to establish a near-field communication connection; if the verification of the token to be verified does not match or the validity period expires, the current power consumption data is refused to be sent to the external terminal.

[0021] The above technical solution clearly defines the token state management and abnormal scenario handling logic. Marking a successfully verified token as used directly ensures that any intercepted or retained dynamic identification code cannot be used to initiate a connection again, thus defending against credential reuse attacks.

[0022] In some technical solutions of this application, the near-field communication link is established based on the Bluetooth Low Energy communication protocol; the current power consumption data includes at least one of the following: current cumulative power consumption, frozen power consumption, remaining balance, current execution rate, billing cycle identifier, and device verification information. The device verification information includes at least one of the following: device identity identifier, device certificate, device status code, current time information, and data digest; the signature processing includes performing digest calculation and signature operation using a secure element.

[0023] The above technical solution specifies the communication method and the content of the interactive data. The Bluetooth Low Energy communication protocol is selected, which ensures high-speed and secure data transmission over short distances while consuming extremely low power, having a negligible impact on the overall energy consumption of the smart meter. This makes it highly suitable for the long-term stable operation of IoT metering devices.

[0024] Some technical solutions in this application further strengthen the data source authentication and transmission anti-tampering mechanisms. Rich and explicit device verification information collectively constitutes a multi-layered trust credential, used by external terminals and platforms to verify the source and integrity of data. Device identity identifiers and device certificates constitute robust device identity authentication, proving that data originates from a specific legitimate device. Data digests provide the basis for data integrity verification; any modification to the data will result in a mismatch in the digest value. Furthermore, centralizing signature operations within an independent secure element achieves hardware-level protection for the physical isolation and computation of the private key, preventing attackers from stealing the private key to forge signatures even if they compromise the device's main control program. This hardware security design fundamentally establishes an end-to-end trusted data channel from the meter to the user terminal, ensuring that billing information is trustworthy at the source.

[0025] In some technical solutions of this application, the business processing information includes at least one of payment confirmation results, balance changes, rate configuration parameters, and power on / off control instructions; receiving business processing information from an external platform based on current electricity consumption data includes: verifying at least one of the platform signature, timestamp, transaction serial number, and data digest carried in the business processing information; after successful verification, performing local billing status update or power on / off control. Performing local billing status update based on the business processing information includes: parsing the balance change and updating the balance value; closing the power supply circuit if the updated balance value meets the power supply conditions; and disconnecting the power supply circuit or maintaining a power outage state if the power supply conditions are not met.

[0026] In the aforementioned technical solution, the smart meter of this application can enhance the credibility of its own data and further improve data security by requiring externally sent commands to verify their legitimacy. Upon receiving a command, the smart meter must first verify information such as the platform signature and timestamp to confirm that the command source is legitimate and that it is a fresh, unreplayed, real-time command, rather than a command forged or intercepted and replayed by an attacker, before executing a status update or power on / off action. This two-way security verification mechanism constitutes a complete end-to-end security closed loop, ensuring the absolute security of critical business operations such as payment and control.

[0027] In the above technical solution, updating the local billing status based on business processing information includes: parsing the balance change and updating the balance value; closing the power supply circuit if the updated balance value meets the power supply conditions; and disconnecting the power supply circuit or maintaining a power outage state if the power supply conditions are not met. This directly maps the commercial "payment result" to the deterministic physical control logic within the meter, achieving localized closed-loop management of the entire billing control process. The core technical problem it addresses is how to avoid post-payment meter response delays or control failures caused by network latency or platform failures. By parsing the balance change and updating the local balance value, the smart meter internally forms a platform-independent copy of the billing status that is updated synchronously with the payment action. Subsequently, the closing or opening of the power supply circuit is triggered instantly, entirely dependent on this locally updated balance value and preset power supply conditions (e.g., a balance greater than zero). This means that even if a communication interruption occurs momentarily after the update operation, the meter has already made the correct physical control decision based on the latest status, ensuring the absolute reliability and real-time nature of the prepaid "disconnect if not paid, connect if paid" logic, and protecting the core interests of both users and the power supplier.

[0028] In some technical solutions of this application, the smart meter supports both prepaid operation mode and postpaid settlement mode. The method further includes: responding to a billing cycle termination request initiated by an external terminal, generating a final settlement bill based on locally stored initial metering data, current metering data, and rate parameters, and sending it to the external terminal via a near-field communication link; receiving settlement completion information corresponding to the final settlement bill, updating the settlement history record, and resetting the current billing cycle status. Resetting the current billing cycle status includes: clearing or updating the current billing cycle identifier, recording new initial metering data, updating the temporary electricity session status, and displaying the settlement completion status.

[0029] In the aforementioned technical solution, the smart meter supports both prepaid operation mode and postpaid settlement mode. The method further includes: responding to a billing cycle termination request initiated by an external terminal, generating a final settlement bill based on locally stored initial metering data, current metering data, and rate parameters, and sending it to the external terminal via a near-field communication link; receiving settlement completion information corresponding to the final settlement bill, updating the settlement history, and resetting the current billing cycle status. This transforms the "lease termination settlement" business activity in a rental scenario into an automated metering and settlement process triggered by the explicit technical event of "billing cycle termination." Its key technology and effectiveness lie in the automation and localization of the process. The entire settlement process begins with a request initiated by the external terminal. The meter uses locally stored, precise initial and current metering data as an immutable benchmark, combined with locally configured rate parameters, to autonomously generate an objective and fair final settlement bill. This process eliminates the need for manual meter reading and calculation by the landlord or administrator, avoiding human error and disputes. Finally, based on the platform's settlement completion information, the meter automatically updates the settlement history and resets the billing cycle status, preparing for the start of the next cycle. This further avoids the high electricity management costs and inflexible settlement issues in scenarios such as short-term rentals and shared spaces.

[0030] In the aforementioned technical solution, resetting the current billing cycle status includes: clearing or updating the current billing cycle identifier, recording new initial metering data, updating the temporary electricity session status, and displaying the settlement completion status. This details the specific meaning of the "reset" technical means performed on the meter side after the end of a billing cycle. These operational steps together constitute a clean "initialization" process that is ready for the next user. Clearing or updating the billing cycle identifier marks the complete end of the previous rental period from a software logic perspective; recording new initial metering data sets the billing zero point for the next rental period; updating the temporary electricity session status allows the meter to flexibly respond to "scan-and-use" scenarios without a fixed account number, ready to establish a connection with new users at any time; and displaying the settlement completion status provides clear feedback on the physical device status on the human-machine interface.

[0031] In some technical solutions of this application, the smart meter establishes a temporary billing session based on the device identification and billing cycle identification. In the absence of a fixed electricity user number pre-bound to the external terminal, a corresponding electricity consumption interaction relationship is established with the smart meter based on the dynamic identification code.

[0032] In the aforementioned technical solution, the smart meter establishes a temporary billing session using device identification and billing cycle identifier. Even when an external terminal is not pre-bound to a fixed user account number, a corresponding electricity usage interaction relationship is established with the smart meter based on a dynamic identification code, realizing the technological cornerstone of the core user experience: "scan and use immediately, no account opening or binding required." The technical problem it solves is that traditional smart meters must be pre-bound to a fixed, real-name user account number, making it inflexible for mobile users. This solution revolutionizes the traditional model by dynamically establishing a "temporary billing session." Defining a session using only two elements—device identification and billing cycle identifier—transforms the user identification problem into the identification problem of the device and the electricity usage cycle. Any user, as long as they scan the device's dynamic identification code and pass authentication, can establish a clearly defined electricity usage interaction relationship with the smart meter within the current billing cycle.

[0033] In some technical solutions of this application, the secure interactive control method further includes: storing metering data, balance data, rate parameters, dynamic identification code refresh records and token verification records in a non-volatile storage area to restore the local billing status after the smart meter experiences an abnormal power outage or restart.

[0034] In the aforementioned technical solution, metering data, balance data, rate parameters, dynamic identification code refresh records, and token verification records are stored in a non-volatile storage area. This ensures the local billing state is restored after an abnormal power outage or restart of the smart meter, providing high reliability and disaster recovery capabilities for the entire smart meter system. As a critical infrastructure node involving funds and fees, the smart meter must be able to retain critical data even during power outages. Storing core billing information such as metering data, balance data, and rate parameters in a non-volatile storage area ensures that even in the event of an unexpected power outage or device restart, this data, which is crucial to user assets and the power company's revenue, is never lost or rolled back, guaranteeing absolute billing accuracy. Furthermore, storing security session-related data such as dynamic identification code refresh records and token verification records allows the device to immediately return to its pre-power-outage security state after power is restored, knowing which tokens were generated and whether they have been used, thus avoiding security vulnerabilities at the moment of restart and ensuring the continuity of the security mechanism.

[0035] In some technical solutions of this application, the business processing information includes rate update parameters, and the method also includes: synchronously updating the time-of-use electricity price configuration, package billing configuration or billing cycle configuration stored locally according to the rate update parameters.

[0036] In the aforementioned technical solution, the locally stored time-of-use pricing configuration, package billing configuration, or billing cycle configuration is synchronously updated based on rate update parameters, enabling smart meters to possess dynamic and flexible remote rate configuration and synchronization capabilities. This transforms the update of electricity billing rules from an offline, manual, and delayed operation into an online, automated, and real-time process. Smart meters are no longer limited to a fixed, single billing model; instead, they can instantly synchronize and update time-of-use pricing periods and corresponding unit prices, package billing thresholds and discount rules, and the start and end dates of billing cycles via remotely distributed rate update parameters. This makes smart meters deployed on the user side a final execution node for flexible grid dispatching. Simultaneously, the method of locally storing the latest rates and performing local billing ensures that even during periods of communication interruption with the platform, the meter can still accurately bill according to the synchronized latest rates, ensuring the independence and accuracy of local billing.

[0037] A second aspect of the present invention provides a smart energy meter, comprising: a metering module for collecting sampling data and generating energy metering data; a main control and security module connected to the metering module for generating a one-time access token and a dynamic identification code based on device identity, dynamic factors, and key information, and performing consistency verification on the token carried in the near-field communication connection request; the main control and security module includes a microcontroller unit and a security element; the security element is used to store key information and perform signature processing on the current electricity consumption data and device verification information; a human-machine interaction module connected to the main control and security module for displaying and refreshing the dynamic identification code, and displaying electricity consumption data, balance status, or settlement status; a communication module connected to the main control and security module for establishing a near-field communication link with an external terminal and receiving business processing information from an external platform; a data storage module connected to the main control and security module for storing one-time access tokens, metering data, balance data, rate parameters, billing cycle status, and settlement records; and a control module connected to the main control and security module for performing power on / off operations based on business processing information.

[0038] This application provides a hardware device architecture for implementing the aforementioned secure interactive control method. The physical connections and functional divisions of the various functional modules of the device are defined, clearly demonstrating an intelligent hardware terminal integrating metering, security, display, communication, storage, and control. The technical problem it solves is how to integrate complex logic such as dynamic token generation, security authentication, data signing, and remote control into a compact, mass-producible smart energy meter. By assigning security operation tasks to independent or integrated "master control and security modules," data temporary storage and historical record tasks to "data storage modules," and physical operation tasks to "control modules," a modular design with functional decoupling is achieved. This design not only improves system reliability and facilitates individual upgrades or enhancements of certain modules (e.g., upgrading to higher-level security chips), but also provides convenience for manufacturing and maintenance. The collaborative work of all modules enables the smart energy meter to execute all the aforementioned secure interactive methods. This application defines the internal structure of the master control and security modules, emphasizing the hardware independence of security functions. Its core is to physically or logically distinguish the microcontroller unit responsible for general tasks from the independent security elements responsible for security operations.

[0039] In some of the technical solutions of this application, the smart energy meter adopts a rail-mounted structure for installation in a distribution box and for independent metering and billing control in distributed leasing scenarios.

[0040] The above technical solutions define the physical form and application scenarios of the product from a structural perspective. Adopting a rail-mounted structure, such as standard fixed-size rail installation, solves the problems of traditional wall-mounted meters being bulky, having limited installation locations, and being unsuitable for multi-circuit integration within compact distribution boxes, thus achieving precise metering of terminal power distribution.

[0041] A third aspect of this application provides a smart energy meter interaction system, including a smart energy meter as described in any of the above technical solutions; an external platform, communicatively connected to the smart energy meter, for receiving current electricity consumption data uploaded by an external terminal and processed by the smart energy meter's signature, and for feeding back business processing information to the smart energy meter; and a payment gateway, communicatively connected to the external platform, for processing payment requests and feeding back payment results to the external platform.

[0042] The smart meter interaction system provided in this application includes a smart meter as described in any of the above technical solutions; an external platform, which is communicatively connected to the smart meter and used to receive current electricity consumption data uploaded by external terminals and processed by the smart meter's signature, and to feed back business processing information to the smart meter; and a payment gateway, which is communicatively connected to the external platform and used to process payment requests and feed back payment results to the external platform. Therefore, the above technical solutions protect the complete interaction system composed of the smart meter, cloud platform, and payment gateway at the system level. It clearly defines the functions and interaction relationships of the three core components, solving the problem of multi-party collaborative work. The external platform, as a data relay and processing center, has the core function of receiving and verifying trusted current electricity consumption data signed by the smart meter and forwarded by external terminals, coordinating with the payment gateway to complete transactions based on this data, and finally feeding back the processing results to the smart meter in the form of business processing information. The payment gateway specifically handles the connection with financial systems such as banks and third-party payment platforms. This clear system architecture breaks down the complex payment business process into three independently evolving parts: trusted data collection on the device side, business scheduling on the platform side, and financial integration on the gateway side, making the development and operation of the entire system clearer and more reliable.

[0043] A fourth aspect of this application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the secure interactive control method of any of the above-described technical solutions. Therefore, the computer-readable storage medium possesses all the technical effects of the secure interactive control method of any of the above-described technical solutions.

[0044] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0045] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0046] Figure 1 This is a flowchart illustrating a safe interactive control method for a smart energy meter according to an embodiment of the present invention.

[0047] Figure 2 This is one of the schematic block diagrams of a smart energy meter according to an embodiment of the present invention;

[0048] Figure 3 This is a schematic block diagram of a main control and security module according to an embodiment of the present invention;

[0049] Figure 4 This is a second schematic block diagram of a smart energy meter according to an embodiment of the present invention;

[0050] Figure 5 This is a schematic block diagram of a smart energy meter interaction system according to an embodiment of the present invention;

[0051] Figure 6 This is a schematic diagram of the operation process of a smart meter during a user lease termination process according to an embodiment of the present invention.

[0052] Figure label:

[0053] 200 Smart energy meter, 210 Metering module, 220 Main control and security module, 222 Microcontroller unit, 224 Security element, 230 Human-machine interaction module, 240 Communication module, 250 Data storage module, 260 Control module, 300 Smart energy meter interaction system, 310 External platform, 320 External terminal, 330 Payment gateway. Detailed Implementation

[0054] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other.

[0055] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and therefore the scope of protection of the invention is not limited to the specific embodiments disclosed below.

[0056] The following reference Figures 1 to 6 This invention describes a safe interactive control method for smart meters, a smart meter, and an interactive system according to some embodiments of the present invention.

[0057] like Figure 1 As shown, an embodiment of this application provides a safe interactive control method for a smart energy meter, the steps of which include:

[0058] Step 102: Generate a one-time access token bound to the smart energy meter based on the smart energy meter's identity, dynamic factor, and pre-stored key information, and generate a dynamic identification code based on the one-time access token;

[0059] Step 104: Display the dynamic identification code and refresh it according to the validity period of the one-time access token;

[0060] Step 106: Receive a near-field communication connection request initiated by an external terminal based on a dynamic identification code. The connection request carries a token to be verified, which is parsed from the dynamic identification code.

[0061] Step 108: Verify whether the token to be verified matches the one-time access token stored locally. After the verification is successful, sign the current electricity consumption data and send the signed current electricity consumption data to the external terminal through the near-field communication link.

[0062] Step 110: Receive business processing information from an external platform based on current electricity consumption data, and perform local billing status updates and / or power on / off control according to the business processing information.

[0063] In this application, the smart meter includes a metering module, a main control and security module, a human-machine interaction module, a communication module, a data storage module, and a control module. The secure interactive control method for the smart meter includes: generating a one-time access token bound to the smart meter based on the smart meter's identity identifier, dynamic factor, and pre-stored key information, and generating a dynamic identification code based on the one-time access token; displaying the dynamic identification code and refreshing it according to the validity period of the one-time access token; receiving a near-field communication connection request initiated by an external terminal based on the dynamic identification code, the connection request carrying a token to be verified parsed from the dynamic identification code; verifying whether the token to be verified matches the locally stored one-time access token, and after successful verification, signing the current electricity consumption data and sending the signed current electricity consumption data to the external terminal through the near-field communication link; receiving business processing information fed back by the external platform based on the current electricity consumption data, and performing local billing status updates and / or power on / off control according to the business processing information.

[0064] This technical solution addresses the issues of static QR codes being easily tampered with or covered, the lack of proactive security authentication on the device side in the payment chain, and the inability to achieve one-click payment through direct device connection by the synergy of a series of technical features such as dynamic token generation, near-field communication verification, and data signature.

[0065] Specifically, the smart meter generates a one-time access token bound to it based on its own identity, dynamic factor, and pre-stored key information, and then generates a dynamic identification code based on the one-time access token. Because the token generation relies on the device's unique identity and dynamic factor, each generated identification code is different and cannot be predicted or reused, further reducing the security risks of static QR codes being easily tampered with and copied, and preventing replay attacks and unauthorized alteration. The smart meter refreshes the dynamic identification code according to the validity period of the one-time access token, ensuring the timeliness of the QR code. Even if the dynamic identification code is intercepted, it cannot be used after the expiration date, further enhancing security.

[0066] After an external terminal scans the dynamic identification code, it is not directly redirected to the payment page. Instead, it must first initiate a near-field communication connection request carrying a token to be verified. This step establishes the first layer of security authentication after scanning the code. Upon receiving the connection request, the smart meter's main control and security modules verify whether the token to be verified matches the locally stored one-time access token. Only after successful verification are subsequent steps executed. This mechanism of token verification on the device's local premises ensures that only legitimate external terminals that have scanned the genuine dynamic identification code can establish a connection with the target smart meter, effectively preventing unauthorized terminals or man-in-the-middle attacks.

[0067] After successful verification, the smart meter signs the current electricity consumption data and sends the signed data to the external terminal via a near-field communication link. The technical advantage here is that the bill data displayed to the user before payment is not platform-only data, but trusted data signed by the smart meter's secure element. Only after the external terminal verifies the signature does it display a trusted payment interface, ensuring that what you see is what you pay for, preventing data tampering during transmission, and resolving the problem of bill information forgery that could result from man-in-the-middle attacks.

[0068] Finally, the smart meter receives business processing information from the external platform based on current electricity consumption data. This information includes payment confirmation results, balance changes, rate configuration parameters, and / or power on / off control commands. Based on this information, the smart meter performs local billing status updates and / or power on / off control. The action after payment is not simply remote accounting, but directly triggers a deterministic change in the smart meter's local state, such as balance updates, power on / off switching. This localized, deterministic control logic ensures the real-time performance, accuracy, and security of billing and power supply control, enabling correct actions based on locally stored states even after a brief communication interruption.

[0069] In one embodiment, a user scans a dynamic identification code displayed on the human-machine interface module of a smart meter using a mobile payment app. The app parses the dynamic identification code to obtain the temporary device access token contained within, and automatically initiates a near-field communication connection request to the target smart meter via Bluetooth Low Energy (BLE). The smart meter's main control and security module verifies that the token to be verified in the request matches its own generated and stored one-time access token and is within its validity period, thus successfully completing the handshake. Subsequently, the smart meter obtains the current electricity consumption data generated by the metering module and signs the data and device verification information using the security element in the main control and security module. The signed data packet is sent to the user's mobile phone via the established Bluetooth link. The user's mobile app decrypts and verifies the signature, confirming that the data originates from the target meter and has not been tampered with, and clearly displays the current meter reading, remaining balance, rate, and outstanding bills to the user. After confirming everything is correct, the user clicks to pay, and the payment request is forwarded to the payment gateway via the cloud platform for processing. After successful payment, the cloud platform generates business processing information containing the platform signature and transaction serial number and sends it to the smart meter. After receiving the business processing information, the smart meter communication module first verifies the platform signature and transaction serial number. After the verification is successful, it updates the balance in the data storage module according to the information content. Based on the updated balance status, it drives the control module to close or open the built-in relay to realize the on / off control of the power supply circuit. The successful transaction and the current balance are displayed on the human-machine interaction module.

[0070] In some embodiments of this application, the dynamic factor includes at least one of timestamp, random number and count value; the dynamic identification code is a dynamic QR code, and the dynamic identification code is updated when at least one of the following conditions is met: the refresh cycle expires, the one-time access token is used, and the number of token verification failures reaches a threshold.

[0071] In the above embodiments, the generation factors and update mechanism of the dynamic identification code are further defined. Using timestamps, random numbers, and count values ​​as dynamic factors further enhances the unpredictability of the token and identification code. While a single random number might produce patterns when a pseudo-random algorithm is attacked, combining the ever-changing physical quantity of timestamps with the strictly increasing sequence of operations of count values ​​ensures that even if an attacker obtains the random number generation algorithm at a certain moment, they cannot deduce the next dynamic code, greatly enhancing anti-replay and anti-prediction capabilities. Multiple update conditions (periodic refresh, one-time password, anomaly locking) form a closed-loop token lifecycle management system. The use of one-time access tokens as a limiting condition implements the key security feature of "one-time password." Once any QR code is successfully scanned and verified, the corresponding token immediately becomes invalid, eliminating the risk of payment codes being screenshotted and reused. The condition of "verification failure count reaching a threshold" provides proactive defense capabilities. When a brute-force attack attempt is detected, the smart meter immediately and proactively updates the dynamic identification code, rendering the old code in the attacker's hands completely invalid, thereby ensuring the overall security resilience of the system.

[0072] In one embodiment, the smart meter system's timer triggers an interrupt every 60 seconds. The main control and security modules then read the current timestamp, a new random number generated by a hardware random number generator, and an incrementing counter value read from non-volatile memory. These three values ​​are combined with a key and hashed to generate a new one-time access token, which is then updated to display a new dynamic identification code. When the user successfully scans the code to pay, the token is marked as used, and the main control program immediately initiates a new token generation process, refreshing the QR code on the screen. Furthermore, if the security module detects five consecutive mismatches between the token to be verified and the local token within one minute, it determines there is a risk of brute-force attack, immediately and unconditionally initiates a refresh process, generates a new token and QR code, and records a security event to the data storage module.

[0073] In some embodiments of this application, a one-time access token is marked as used after successful verification to prevent the same one-time access token from being used again to establish a near-field communication connection; if the verification of the token to be verified does not match or the validity period has expired, the current power consumption data is refused to be sent to the external terminal.

[0074] In the above embodiments, the token state management and abnormal scenario handling logic are clearly defined. Marking a successfully verified token as used directly ensures that any intercepted or retained dynamic identification code cannot be used to initiate a connection again. The non-repeatability of the one-time access token can defend against credential reuse attacks, reducing the risk of theft or misuse. When the token is mismatched or expired, the smart meter not only refuses the connection, but more importantly, explicitly prohibits the transmission of any electricity consumption data, reducing the risk of data exposure. The smart meter can avoid sending data information to any requester who has not passed the first layer of authentication, improving security and protecting user privacy and device security.

[0075] In one embodiment, after the smart meter's master control and security module complete a token consistency verification and confirm a match, they will set the token status flag stored in the security element corresponding to this session from "valid" to "used". Subsequently, if the communication module receives another connection request carrying the same token, the master control and security module will discard the request directly after checking the status flag, without performing any data processing or communication response. If the received token to be verified does not match any valid token stored locally, or if the system time has exceeded the valid timestamp carried by the token, the master control and security module will also silently reject the request, not returning any message containing useful information to the requester, and only recording a failed attempt event in the log.

[0076] In some embodiments of this application, the near-field communication link is established based on the Bluetooth Low Energy communication protocol; the current power consumption data includes at least one of the following: current cumulative power consumption, frozen power consumption, remaining amount, current execution rate, billing cycle identifier, and device verification information.

[0077] In the above embodiments, specific limitations were made on the communication method and the content of the interactive data. The Bluetooth Low Energy (BLE) communication protocol was selected, ensuring high-speed and secure data transmission over short distances while consuming extremely low power, having a negligible impact on the overall energy consumption of the smart meter, making it very suitable for the long-term stable operation of IoT metering devices. The physical communication distance limitation of BLE requires the user to be near the meter to complete the interaction, thus eliminating the possibility of remote network attackers forging connections to a certain extent. The current electricity consumption data is limited to at least one of the following: current accumulated electricity consumption, frozen electricity, remaining balance, current applicable rate, billing cycle identifier, and device verification information. This allows a single interaction to provide the user and management platform with complete, multi-dimensional decision support information.

[0078] For example, in addition to providing "remaining amount" for payment determination, the system also provides "current applicable rate" and "billing cycle identifier," enabling the system to support complex time-of-use electricity pricing calculations and periodic settlements. Among these, the "frozen electricity" data, representing a specific time segment, provides an accurate and tamper-proof metering benchmark for rate switching and periodic settlements, resolving the technical root cause of billing disputes.

[0079] In one embodiment, the communication module of the smart meter includes a Bluetooth chip compliant with the BLE 5.0 standard. After successful token verification, the main control and security module reads the accumulated electricity consumption at the aforementioned time from the metering module via a serial peripheral interface. It then retrieves from the data storage module the "frozen electricity" data frozen at 24:00 on the last day of the previous month, the current "remaining balance," the activated "time-of-use pricing" rate table identifier, and the current "monthly" billing cycle identifier. These, along with the device's unique serial number and other device verification information, are combined into a data packet and sent to the external terminal's App via Bluetooth. Based on this, the App can accurately calculate the cost from the beginning of the month to the present and differentiate usage during different rate periods.

[0080] In some embodiments of this application, the device verification information includes at least one of device identity, device certificate, device status code, current time information, and data digest; the signature processing includes performing digest calculation and signature operation using a secure element.

[0081] In the above embodiments, the data source authentication and transmission anti-tampering mechanisms are further strengthened. Rich and explicit device verification information constitutes a multi-layered trust credential, used by external terminals and platforms to verify the source and integrity of data. Device identity identifiers and device certificates constitute robust device identity authentication, proving that data originates from a specific legitimate device. Data digests provide the basis for data integrity verification; any modification to the data will result in a mismatch in the digest value. Furthermore, centralizing signature operations within a separate secure element achieves hardware-level protection for the physical isolation and computation of the private key, preventing attackers from stealing the private key to forge signatures even if they compromise the device's main control program. This hardware security design fundamentally establishes an end-to-end trusted data channel from the meter to the user terminal, ensuring that the "what you see is what you pay for" billing information is trustworthy at the source.

[0082] In one embodiment, the security element of the smart meter pre-installs a unique certificate and corresponding private key for the device. Before sending data, the security element first calculates a hash value as a data digest for all current electricity consumption data to be sent, including accumulated electricity consumption, frozen electricity consumption, and rate identifiers, as well as information such as device identity, device certificate serial number, and current timestamp. Next, the security element uses its internally stored private key to perform a signature operation on the above data digest, generating a signature value. Finally, the main control unit packages all the original data, device verification information, and generated signature values ​​together into a data structure and sends it to the communication module. After receiving the data packet, the mobile app first uses the CA (Certificate Authority) public key to verify the legality of the device certificate chain, then extracts the device public key from the certificate, calculates the digest for the data in the data packet according to the same rules, and decrypts the received signature value using the device public key. It then compares the two digest values ​​to see if they match, thus completing the dual verification of the authenticity of the data source and the integrity of the data.

[0083] In some embodiments of this application, the business processing information includes at least one of payment confirmation result, balance change, rate configuration parameters, and power on / off control instructions; receiving business processing information fed back by an external platform based on current electricity consumption data includes: verifying at least one of platform signature, timestamp, transaction serial number, and data digest carried in the business processing information; after verification, performing local billing status update or power on / off control.

[0084] In the above embodiments, this application constructs a secure authentication system for downlink commands from the platform to the meter. By broadly defining the content of business processing information, the method is not limited to processing payment results but can also support diverse management commands such as rate configuration and remote control. Simultaneously, the verification requirements for downlink information establish a trust relationship symmetrical to the uplink data signature. In other words, the smart meter defined in this application not only improves data credibility but also requires externally sent commands to prove their legitimacy, further enhancing security. Upon receiving a command, the smart meter must first verify the platform signature, timestamp, and other information to confirm that the command source is legitimate and that it is a fresh, unreplayed, real-time command, not a command forged or intercepted and replayed by an attacker, before executing a status update or power on / off action. This two-way security verification mechanism constitutes a complete end-to-end security closed loop, ensuring the absolute security of critical business operations such as payment and control.

[0085] In one embodiment, after the payment gateway confirms successful user payment, the cloud platform generates a business processing message, which includes: a payment confirmation status code, the amount paid by the user (balance change), the current transaction serial number, and a timestamp indicating the generation of this message. The platform uses its private key to calculate a signature on the above information and then sends the entire message packet to the smart meter. Upon receiving the message, the smart meter's communication module first obtains the current local time, compares it with the timestamp, and confirms that the message was generated within an acceptable short delay (e.g., 30 seconds) to prevent replay. Then, the main control and security module uses a pre-stored platform public key to verify the signature and recalculates the data digest for comparison. Only after all verifications pass does the smart meter finally confirm the payment result is genuine and valid, and then update its local balance.

[0086] In some embodiments of this application, performing a local billing status update based on business processing information includes: parsing the balance change and updating the balance value; closing the power supply circuit if the updated balance value meets the power supply conditions; and disconnecting the power supply circuit or maintaining a power-off state if the power supply conditions are not met.

[0087] In the above embodiments, updating the local billing status based on business processing information includes: parsing the balance change and updating the balance value; closing the power supply circuit if the updated balance value meets the power supply conditions; and disconnecting the power supply circuit or maintaining a power outage state if the power supply conditions are not met. This directly maps the commercial "payment result" to the deterministic physical control logic within the meter, achieving localized closed-loop management of the entire billing control process. The core technical problem it addresses is how to avoid post-payment meter response delays or control failures caused by network latency or platform failures. By parsing the balance change and updating the local balance value, the smart meter forms a platform-independent copy of the billing status that is updated synchronously with the payment action. Subsequently, the closing or opening of the power supply circuit is triggered instantly, entirely dependent on this locally updated balance value and preset power supply conditions (e.g., a balance greater than zero). This means that even if a communication interruption occurs momentarily after the update operation, the meter has already made the correct physical control decision based on the latest status, ensuring the absolute reliability and real-time nature of the prepaid "disconnect if not paid, connect if paid" logic, and protecting the core interests of both users and the power supplier.

[0088] Specifically, when a tenant's electricity meter balance was about to run out, the user paid 20 yuan for electricity by scanning a QR code. After successful payment, the balance change in the business processing information received by the smart meter was "+20.00". The main control program parses the above field, reads the current balance (e.g., 0.50 yuan) from the data storage module, calculates the new balance as 20.50 yuan, and immediately updates and writes it to the storage module. After the update, the program determines that the new balance is greater than 0. If the meter was already in a state of disconnected power supply due to previous arrears, the main control and safety modules will immediately drive the relay of the control module to close, restoring power supply; if it was already in a state of power supply, the relay will remain closed to achieve smooth power replenishment.

[0089] In some embodiments of this application, the smart meter supports a prepaid operation mode and a postpaid settlement mode. The method further includes: in response to a billing cycle termination request initiated by an external terminal, generating a final settlement bill based on locally stored initial metering data, current metering data, and rate parameters, and sending it to the external terminal via a near-field communication link; receiving settlement completion information corresponding to the final settlement bill, updating the settlement history record, and resetting the current billing cycle status.

[0090] In the above embodiments, the smart meter supports both prepaid operation mode and postpaid settlement mode. The method further includes: responding to a billing cycle termination request initiated by an external terminal, generating a final settlement bill based on locally stored initial metering data, current metering data, and rate parameters, and sending it to the external terminal via a near-field communication link; receiving settlement completion information corresponding to the final settlement bill, updating the settlement history record, and resetting the current billing cycle status. This transforms the "lease termination settlement" business activity in a rental scenario into an automated metering and settlement process triggered by the explicit technical event of "billing cycle termination." Its key technology and effectiveness lie in the automation and localization of the process. The entire settlement process begins with a request initiated by the external terminal. The meter uses locally stored, precise initial and current metering data as an immutable benchmark, combined with locally configured rate parameters, to autonomously generate an objective and fair final settlement bill. This process eliminates the need for manual intervention by landlords or administrators in meter reading and calculation, avoiding human error and disputes. Finally, based on the platform's settlement completion information, the meter automatically updates the settlement history record and resets the billing cycle status, preparing for the start of the next cycle. This further avoids the technical problems of high electricity management costs and inflexible settlement in scenarios such as short-term rentals and shared spaces.

[0091] In some embodiments of this application, resetting the current billing cycle status includes: clearing or updating the current billing cycle identifier, recording new starting metering data, updating the temporary electricity session status, and displaying the settlement completion status.

[0092] In the above embodiments, resetting the current billing cycle status includes: clearing or updating the current billing cycle identifier, recording new starting metering data, updating the temporary electricity session status, and displaying the settlement completion status. This details the specific meaning of the "reset" technique performed by the meter after the end of a billing cycle. These steps together constitute a clean "initialization" process, ready for the next user. Clearing or updating the billing cycle identifier logically marks the complete end of the previous rental period; recording new starting metering data sets the billing zero point for the next rental period; updating the temporary electricity session status allows the meter to flexibly handle "scan-and-use" scenarios without a fixed account number, ready to establish a connection with new users at any time; displaying the settlement completion status provides clear feedback on the physical device status on the human-machine interface. For example, immediately after receiving and verifying the "settlement completion information" in the above embodiments, the meter performs the following status reset action: the main control program updates the billing cycle identifier field representing the "current tenant" in the storage module, displaying that the device is idle. Subsequently, the smart meter resets the current billing cycle status. For example, the data corresponding to the current meter reading is officially written to the storage location of "New Cycle Start Meter Data," overwriting the previous value. Next, the token status of the temporary electricity session established with the user's app is cleared. Finally, the LCD screen controlling the human-machine interface switches from the previous bill display interface to a "Settlement Completed" interface containing a green "√" symbol.

[0093] In some embodiments of this application, the smart meter establishes a temporary billing session using the device identification and billing cycle identification. In the absence of a fixed electricity user number pre-bound to the external terminal, a corresponding electricity consumption interaction relationship is established with the smart meter based on the dynamic identification code.

[0094] In the above embodiments, the smart meter establishes a temporary billing session using device identification and billing cycle identification. Even when an external terminal is not pre-bound to a fixed user account number, a corresponding electricity usage interaction relationship is established with the smart meter based on a dynamic identification code, realizing the technological cornerstone of the core user experience of "scan and use immediately, no account opening or binding required." The technical problem it solves is that traditional smart meters must be pre-bound to a fixed, real-name user account number, making it inflexible for mobile users. This solution revolutionizes the traditional model by dynamically establishing a "temporary billing session." Defining a session using only two elements—device identification and billing cycle identification—transforms the user identification problem into the identification problem of the device and the electricity usage cycle. Any user, as long as they scan the device's dynamic identification code and pass authentication, can establish a clearly defined electricity usage interaction relationship with the smart meter within the current billing cycle.

[0095] In a shared office space, a rail-mounted smart electricity meter is installed at a workstation. The meter's internal firmware is configured to operate in "temporary billing session" mode. When a new user, A, first arrives at the workstation, their phone scans the dynamic QR code displayed on the meter. After the verification token is successful, the meter internally creates a new billing session. The session's identity is generated by combining the meter's unique device identity and the billing cycle identifier composed of the current date. The meter doesn't care who user A is, but it accurately records all electricity consumption data and transaction records from the session's establishment to its termination. When user A leaves and "checks out," the session ends. Subsequently, user B arrives and scans the code again; a new session is established based on the same device identity and a new billing cycle identifier, and the process restarts. The entire process requires no administrator configuration of user identities.

[0096] In some embodiments of this application, the secure interactive control method further includes storing metering data, balance data, rate parameters, dynamic identification code refresh records, and token verification records in a non-volatile storage area to restore the local billing status after the smart meter experiences an abnormal power outage or restart.

[0097] In the above embodiments, metering data, balance data, rate parameters, dynamic identification code refresh records, and token verification records are stored in a non-volatile storage area. This ensures the local billing state is restored after an abnormal power outage or restart of the smart meter, providing high reliability and disaster recovery capabilities for the entire smart meter system. As a critical infrastructure node involving funds and fees, the smart meter must have the ability to retain critical data even during power outages. Storing core billing information such as metering data, balance data, and rate parameters in a non-volatile storage area ensures that even in the event of an unexpected power outage or device restart, this data, which is crucial to user assets and the power company's revenue, is never lost or rolled back, guaranteeing absolute billing accuracy. Furthermore, storing security session-related data such as dynamic identification code refresh records and token verification records allows the device to immediately return to its pre-power outage security state after power is restored, knowing which tokens were generated and whether they have been used, thus avoiding security vulnerabilities at the moment of restart and ensuring the continuity of the security mechanism.

[0098] For example, smart meters use ferroelectric memory or static random access memory with a backup battery as the non-volatile storage area. Within 100 milliseconds of any event such as a change in balance, generation of new metering data, rate update, dynamic code refresh, or token verification, the main control program writes the latest relevant data and corresponding timestamps to the aforementioned storage area. One day, the device experiences a sudden power outage due to line maintenance. When power is restored and the device restarts, the first task of the main control program is to read all saved data from the non-volatile storage area, including the balance, accumulated electricity consumption, the most recently generated token and its status, etc., at the last moment before the power outage. This fully restores the entire billing state and security session state to the moment before the power outage, ensuring that the continuity and accuracy of electricity billing are not affected.

[0099] In some embodiments of this application, the service processing information includes rate update parameters, and the method further includes: synchronously updating the locally stored time-of-use electricity price configuration, package billing configuration, or billing cycle configuration according to the rate update parameters.

[0100] In the above embodiments, the locally stored time-of-use pricing configuration, package billing configuration, or billing cycle configuration is synchronously updated according to the rate update parameters, enabling smart meters to have dynamic and flexible remote rate configuration and synchronization capabilities. This transforms the update of electricity billing rules from an offline, manual, and delayed operation into an online, automated, and real-time process. Smart meters are no longer limited to a fixed, single billing mode; instead, they can instantly synchronize and update the time-of-use pricing period and corresponding unit price, package billing thresholds and discount rules, and the start and end dates of the billing cycle through remotely distributed rate update parameters. Simultaneously, the method of storing the latest rates locally and performing local billing accordingly ensures that even during periods of communication interruption with the platform, the meter can still accurately bill according to the synchronized latest rates, ensuring the independence and accuracy of local billing.

[0101] In one embodiment, the power company needs to implement a new peak electricity pricing policy before the summer. Maintenance personnel edit a new rate configuration file in the cloud management platform interface: setting 14:00-15:00 and 19:00-21:00 daily as peak periods with a rate of 1.5 yuan / kWh; and a rate of 0.6 yuan / kWh for other times. The platform, via narrowband IoT, sends this configuration file as a "rate update parameter" to all bound smart meters. After the smart meters receive the information and verify the platform's signature, the main control and security modules parse the message, extract the new time periods and rate information, and write it all into the rate configuration area of ​​the data storage module, overwriting the old configuration. The billing task loop within the main control program will begin using the new rate parameters to accumulate electricity charges in the next millisecond cycle, achieving a seamless hot-swap of rates.

[0102] like Figure 2 , Figure 3 and Figure 4 As shown in the embodiments of this application, a smart energy meter 200 is provided, including: a metering module 210, used to collect sampling data and generate energy metering data; a main control and security module 220, connected to the metering module 210, used to generate a one-time access token and a dynamic identification code according to the device identity, dynamic factor and key information, and to perform consistency verification on the token carried in the near-field communication connection request; the main control and security module 220 includes a microcontroller unit 222 and a security element 224; the security element 224 is used to store key information and perform signature processing on the current electricity consumption data and device verification information; and a human-machine interaction module 230. The main control and security module 220 is connected to the main control and security module 220 and is used to display and refresh the dynamic identification code, as well as display electricity consumption data, balance status, or settlement status; the communication module 240 is connected to the main control and security module 220 and is used to establish a near-field communication link with the external terminal 320 and receive business processing information from the external platform 310; the data storage module 250 is connected to the main control and security module 220 and is used to store one-time access tokens, metering data, balance data, rate parameters, billing cycle status, and settlement records; the control module 260 is connected to the main control and security module 220 and is used to perform power on / off operations according to business processing information.

[0103] This application provides a hardware device architecture for implementing the aforementioned secure interactive control method. The device is defined by the physical connection and functional division of each module, clearly demonstrating an intelligent hardware terminal integrating metering, security, display, communication, storage, and control. The technical problem it solves is how to integrate complex logic such as dynamic token generation, security authentication, data signing, and remote control into a compact, mass-producible smart meter 200. By assigning security operation tasks to the independent or integrated "main control and security module 220," data temporary storage and historical record tasks to the "data storage module 250," and physical operation tasks to the "control module 260," a modular design with functional decoupling is achieved. This design not only improves system reliability and facilitates individual upgrades or enhancements of a module (e.g., upgrading to a higher-level security chip), but also provides convenience for manufacturing and maintenance. The collaborative work of all modules enables the smart meter 200 to execute all the aforementioned secure interactive methods.

[0104] The hardware implementation of a smart energy meter 200 is as follows: The metering module 210 uses an A-type metering chip, combined with peripheral voltage and current sampling circuits, to output pulse signals in real time and provide digital energy metering data through a serial peripheral interface. The core of the main control and safety module 220 is a B-type microcontroller, which integrates a C-type main core for application processing, a D-type core dedicated to running the E-type protocol stack, and has a built-in security element 224 function. The human-machine interaction module 230 is an LCD screen connected to the main control chip via an interface. The communication module 240, in addition to the onboard BLE, connects to an external module via a universal asynchronous transceiver for remote communication. The data storage module 250 uses an F-type chip for firmware and logs, and a G-type chip for frequently updated critical billing data. The control module 260 consists of a 5V magnetic latching relay and its drive circuit, controlled by a pin of the main control chip.

[0105] In the above embodiments, this application defines the internal structure of the main control and security module 220, emphasizing the hardware independence of security functions. Its core is to physically or logically distinguish the microcontroller unit 222 responsible for general tasks from the independent security element 224 responsible for security operations. The technical problem solved is that if all operations (including security operations) are executed by a single general-purpose MCU (controller), and an attacker exploits a vulnerability in the MCU's firmware, the keys and signing process stored within could be stolen or hijacked. By introducing an independent security element 224 to specifically store key information and perform signature processing, physical isolation of the keys and secure isolation of the computing environment are achieved. The main control unit can only send the data to be signed to the security element 224 and obtain the signed result from the security element 224; it can never directly read or export the private key stored inside the security element 224. This design achieves financial payment-level hardware security standards, thoroughly guaranteeing the security foundation of device identity and data signing.

[0106] In one embodiment, the main control and security module 220 employs a dual-chip solution. The microcontroller unit 222 is responsible for running the main process, the Bluetooth protocol stack, and general functions such as communication with all peripherals. The independent "security element 224" uses a separate chip and is connected to the microcontroller unit 222 via a bus. The device's unique private key and certificate are burned into and permanently locked in the security element 224 during factory manufacturing. When signature processing is required, the microcontroller unit 222 sends the power data message to be signed to the security element 224 via the integrated circuit bus. The security element 224 internally performs a digest calculation on the message, completes the signature using its internally stored private key, and finally returns the generated signature value to the microcontroller unit 222 via the integrated circuit bus. Throughout the entire process, the private key never leaves the security element 224.

[0107] In some embodiments of this application, the smart energy meter 200 is packaged with a rail-mounted structure for installation in a distribution box and for independent metering and billing control in distributed leasing scenarios.

[0108] In the above embodiments, the physical form and application scenarios of the product are defined at the structural level. The use of a rail-mounted structure, such as standard rail mounting, solves the problems of traditional wall-mounted meters being large, having limited installation space, and being unsuitable for multi-circuit integration in compact distribution boxes, thus achieving precise metering of terminal power distribution.

[0109] like Figure 4 As shown, Figure 4 The power supply module provides power to the voltage and current sampling, metering chip, and microcontroller processing unit. The voltage and current sampling collects electrical signals and sends them to the metering chip. The metering chip processes the data to generate metering data and then sends it to the microcontroller processing unit. The microcontroller processing unit interacts with the human-machine interface, pulse output, data storage, communication module, and control module to realize information interaction, metering output, data storage, data communication, and power control functions.

[0110] like Figure 5 As shown, embodiments of this application provide a smart energy meter interaction system 300, including a smart energy meter 200 as described in any of the above embodiments; an external platform 310, communicatively connected to the smart energy meter 200, for receiving current electricity consumption data uploaded by an external terminal 320 and processed by the smart energy meter 200, and for feeding back business processing information to the smart energy meter 200; and a payment gateway 330, communicatively connected to the external platform 310, for processing payment requests and feeding back payment results to the external platform 310.

[0111] The smart meter interaction system 300 provided in this application includes a smart meter 200 as described in any of the above embodiments; an external platform 310, communicatively connected to the smart meter 200, for receiving current electricity consumption data uploaded by an external terminal 320 and processed by the smart meter 200 after signature, and for feeding back business processing information to the smart meter 200; and a payment gateway 330, communicatively connected to the external platform 310, for processing payment requests and feeding back payment results to the external platform 310. Therefore, the above technical solution protects the complete interaction system composed of the smart meter 200, the cloud platform, and the payment gateway 330 at the system level. It clearly defines the functions and interaction relationships of the three core components, solving the problem of multi-party collaborative work. The external platform 310, as a data relay and processing center, has the core function of receiving and verifying trusted current electricity consumption data signed by the smart meter 200 and forwarded by the external terminal 320, and coordinating the payment gateway 330 to complete the transaction based on this data, ultimately feeding back the processing results to the smart meter 200 in the form of business processing information. The Payment Gateway 330 is specifically designed for interfacing with financial systems such as banks and third-party payment platforms. This clear system architecture breaks down the complex payment business process into three independently evolving parts: trusted data collection on the device side, business scheduling on the platform side, and financial interfacing on the gateway side. This makes the development and maintenance of the entire system clearer and more reliable.

[0112] Embodiments of this application provide a computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements the secure interactive control method as described in any of the above embodiments. Therefore, the computer-readable storage medium possesses all the technical effects of the secure interactive control method as described in any of the above embodiments.

[0113] like Figure 6 As shown, the user scans the QR code 410, then performs security authentication 420, then confirms and pays 430, then executes and provides feedback 440, and finally completes the lease termination settlement 450.

[0114] The smart meter uses a DIN rail-mounted design and is installed on a standard DIN rail inside the distribution box of a rental apartment. The hardware components of the smart meter include a metering module, a main control and security module, a human-machine interface module, a communication module, a data storage module, a control module, and a power supply module. The main control and security module includes a microcontroller unit and an independent security element connected via an integrated circuit bus. The security element pre-installs and latches the smart meter's unique device identifier, private key, and digital certificate. The communication module includes a Bluetooth Low Energy communication unit and a remote communication unit, used for near-field communication and remote communication, respectively. The human-machine interface module is an LCD display. The control module includes a magnetically latched relay, whose contacts are connected in series on the live wire of the user's load power supply circuit.

[0115] At present, the smart meter is in normal operation. Its data storage module stores the current balance, current tariff parameters, accumulated metering data, and the current billing cycle identifier. The smart meter establishes a temporary billing session using the device identifier and the current billing cycle identifier. This temporary billing session allows an external terminal to establish a corresponding electricity usage interaction relationship with the smart meter based on a dynamic identification code, even if a fixed electricity user number is not pre-bound to it.

[0116] First, the main control and security module of the smart meter performs the dynamic identification code generation operation. The microcontroller unit in the main control and security module reads the device identification from the security element, obtains the current timestamp from the system clock, obtains a random number from the hardware random number generator, and reads an auto-incrementing counter value from the data storage module, using the timestamp, random number, and counter value as dynamic factors. The microcontroller unit combines the device identification and dynamic factors and sends them to the security element. The security element internally calls the pre-stored key information, generates a one-time access token bound to the smart meter through hash calculation, and sends the token back to the microcontroller unit. The microcontroller unit encodes the one-time access token, token validity information, and near-field communication connection parameters to generate a dynamic identification code. Subsequently, the microcontroller unit controls the LCD screen of the human-machine interface module to display the dynamic identification code and initiates a timed refresh according to the validity period of the one-time access token. A new dynamic identification code is automatically generated and displayed when the refresh cycle expires. Simultaneously, after a one-time access token is successfully verified and used, the main control and security modules immediately mark the token as used and trigger a new round of dynamic identification code generation and refresh. When the number of failed token verifications reaches a threshold within a preset time window, the main control and security modules also immediately initiate the dynamic identification code refresh process to resist possible brute-force attacks. The non-volatile storage area of ​​the data storage module is also used to store each dynamic identification code refresh record and token verification record, ensuring that the complete token lifecycle state can be restored after an abnormal power outage or restart of the smart meter.

[0117] The tenant uses their smartphone as the user terminal, opens a mobile payment application, and selects the QR code scanning function. The smartphone's camera scans the dynamic identification code displayed on the smart meter's LCD screen. The smartphone application parses the dynamic identification code, extracting the verification token and Bluetooth Low Energy connection parameters. Based on the connection parameters, the application initiates a near-field communication connection request to the smart meter via the smartphone's Bluetooth module. This connection request carries the verification token extracted from the dynamic identification code.

[0118] The Bluetooth Low Energy communication unit in the communication module of the smart meter receives the aforementioned near-field communication connection request and passes the token to be verified in the request to the master control and security module. The master control and security module reads the locally stored one-time access token and its validity period from the data storage module and performs a verification operation. The master control and security module first determines whether the token to be verified has expired. If it has expired, it directly rejects the connection request and does not send any current electricity consumption data to the external terminal. If it is within the validity period, the master control and security module further compares the token to be verified with the locally stored one-time access token bit by bit. If the token to be verified does not match, the master control and security module also rejects the connection request, does not send any data to the external terminal, and only records this failure event in the log of the data storage module. After the verification is successful and the token to be verified is confirmed to match the locally stored one-time access token, the master control and security module changes the status flag of the one-time access token in the data storage module from "valid" to "used" to prevent the same one-time access token from being used again to establish a near-field communication connection, thus implementing one-time password.

[0119] After successful verification, the main control and security module obtains the current electricity consumption data from the metering module via the serial peripheral interface bus. The metering module collects analog signals through voltage and current sampling circuits, which are then converted into digital quantities by the metering chip to generate electricity metering data. The main control and security module obtains the current cumulative electricity consumption and frozen electricity from the metering module, and reads the remaining amount, current applicable rate, billing cycle identifier, and device verification information including device identity identifier, device certificate, device status code, and current time information from the data storage module, which together constitute the current electricity consumption data. Subsequently, the main control and security module performs signature processing on the above current electricity consumption data and device verification information. The specific process of signature processing is as follows: the microcontroller unit sends the current electricity consumption data and device verification information to the security element via the integrated circuit bus; the security element first calculates a hash value as a data digest internally, and then performs an elliptic curve digital signature operation on the above data digest using the internally stored device private key to generate a signature value, and then sends the signature value back to the microcontroller unit. After the signature processing is completed, the main control and security modules send the current power consumption data after signature processing to the smartphone through the established near-field communication link via the Bluetooth Low Energy communication unit of the communication module.

[0120] After receiving the signed current electricity usage data, the smartphone application verifies the signature to confirm the authenticity and integrity of the data source, ensuring what you see is what you pay for and preventing man-in-the-middle attacks. Once verified, the application displays the bill information to the tenant on the phone screen, including current electricity consumption, amount due, and current rate. After confirming the bill is correct, the tenant clicks the payment button to initiate a payment request. The payment request is then sent from the smartphone to the cloud platform via the mobile network.

[0121] After receiving a payment request, the cloud platform forwards it to the payment gateway. The payment gateway completes the financial transaction processing with the bank or third-party payment system and then sends a successful payment result back to the cloud platform. Upon confirming successful payment, the cloud platform generates a transaction processing record. This record includes the payment confirmation result, balance change, current transaction serial number, and generation timestamp. Optionally, the transaction processing record may also include rate configuration parameters and / or power on / off control commands. The cloud platform signs the transaction processing record using its private key and then sends the signed record to the smart meter via the mobile network.

[0122] After receiving business processing information from the cloud platform, the remote communication unit in the smart meter's communication module transmits it to the main control and security module. The main control and security module first verifies the business processing information: it verifies the platform signature carried in the information using a pre-stored cloud platform public key, compares the timestamp to confirm the information is within the allowed latency range, and verifies the transaction serial number and data digest to prevent replay attacks and forged instructions. After successful verification, the main control and security module executes local billing status updates and / or power on / off control based on the specific content of the business processing information.

[0123] In this embodiment, the business processing information includes the payment confirmation result and the balance change. The main control and security module parses the balance change, reads the current balance value from the data storage module, adds the two to calculate the updated balance value, and immediately writes the updated balance value into the non-volatile storage area of ​​the data storage module. Subsequently, the main control and security module determines whether the updated balance value meets the preset power supply conditions—that is, a balance value greater than zero meets the power supply conditions, and a balance value less than or equal to zero does not meet the power supply conditions. Previously, due to insufficient balance, the magnetic latching relay contacts of the smart meter's control module were in an open state, and the power supply circuit was cut off. Since the updated balance value is greater than zero, the power supply conditions are met, and the main control and security module sends a positive pulse signal to the control module through a pin. The control module's drive circuit receives the signal, drives the coil of the magnetic latching relay to generate a positive pulse, closes the contacts and holds them in a conducting state, the power supply circuit is restored, and power is restored to the tenant's room. At the same time, the main control and security module controls the LCD screen of the human-machine interaction module to update the display, showing the tenant the updated balance information and power restoration status. The entire billing status update and power on / off control process is completed locally on the smart meter, without relying on continuous communication with the cloud platform. From the moment the business processing information is verified and the new balance is written to the non-volatile storage area, even if a network interruption occurs immediately, the meter has already made the correct physical control decision based on the latest status, ensuring the determinism and real-time nature of the control.

[0124] When the business processing information includes rate update parameters, the main control and security module is also used to synchronously update the time-of-use electricity price configuration, package billing configuration or billing cycle configuration stored locally in the data storage module according to the rate update parameters, and use the new rate parameters to calculate the electricity bill accumulation at the beginning of the next billing calculation cycle, thereby realizing remote dynamic configuration and seamless hot switching of rates.

[0125] Several months later, the tenant's lease expires and settlement is required. The tenant opens the smartphone application, approaches the smart meter, and clicks the "Settle" button. The smartphone sends a billing cycle termination request to the smart meter via the established Bluetooth Low Energy (BLE) near-field communication link. Upon receiving the request, the Bluetooth Low Energy communication unit in the smart meter's communication module forwards it to the main control and security module. Responding to the billing cycle termination request, the main control and security module reads the initial metering data recorded at the start of the billing cycle from the data storage module, retrieves the current metering data from the metering module, and reads the current applicable rate parameter from the data storage module. The main control and security module subtracts the initial metering data from the current metering data to obtain the total electricity consumption for the cycle, multiplies it by the applicable rate, calculates the total electricity bill payable, and generates a final settlement bill containing electricity consumption details and the total amount payable. The main control and security module then sends this final settlement bill to the tenant's smartphone via the Bluetooth Low Energy (BLE) near-field communication link in the communication module.

[0126] After viewing and confirming the final settlement bill on their smartphones, tenants complete the payment through the cloud platform and payment gateway. Upon successful payment, the cloud platform generates a settlement completion message corresponding to the aforementioned final settlement bill, which, after being signed, is sent to the smart meter via narrowband IoT.

[0127] After receiving the settlement completion information, the remote communication unit of the smart meter transmits it to the main control and security module. The main control and security module verifies the platform signature and timestamp in the information, and executes the post-settlement processing flow after successful verification. The main control and security module appends the details and total amount of the above settlement to the settlement history area in the non-volatile storage area of ​​the data storage module; subsequently, the main control and security module clears or updates the current billing cycle identifier stored in the data storage module, writes the current metering data of the metering module as the new starting metering data to the data storage module, and updates the temporary electricity session status to "idle," awaiting the next tenant to scan the code to activate a new electricity interaction relationship. Finally, the main control and security module controls the LCD screen of the human-machine interaction module to display the settlement completion status with a green confirmation symbol. The entire process requires no intervention from the landlord or administrator for meter reading and calculation; the system automatically completes all operations from bill generation to status reset, achieving adaptation to the highly mobile short-term rental scenario.

[0128] In the claims, description, and accompanying drawings of this invention, the term "plural" refers to two or more. Unless otherwise explicitly defined, the terms "upper," "lower," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and simplifying the descriptive process, and are not intended to indicate or imply that the device or element referred to must have the described specific orientation, or be constructed and operated in a specific orientation. Therefore, these descriptions should not be construed as limiting the invention. The terms "connected," "installed," "fixed," etc., should be interpreted broadly. For example, "connected" can be a fixed connection between multiple objects, a detachable connection between multiple objects, or an integral connection; it can be a direct connection between multiple objects or an indirect connection between multiple objects through an intermediate medium. For those skilled in the art, the specific meaning of the above terms in this invention can be understood based on the specific circumstances of the above data.

[0129] In the claims, description, and accompanying drawings of this invention, the terms "one embodiment," "some embodiments," "specific embodiment," etc., refer to specific features, structures, materials, or characteristics described in connection with the above embodiments or examples, which are included in at least one embodiment or example of the invention. In the claims, description, and accompanying drawings of this invention, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0130] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A safe interactive control method for a smart energy meter, characterized in that, include: Based on the smart meter's identity identifier, dynamic factor, and pre-stored key information, a one-time access token bound to the smart meter is generated, and a dynamic identification code is generated based on the one-time access token. Display the dynamic identification code and refresh the dynamic identification code according to the validity period of the one-time access token; Receive a near-field communication connection request initiated by an external terminal based on the dynamic identification code, the connection request carrying a verification token parsed from the dynamic identification code; The system verifies whether the token to be verified matches the one-time access token stored locally. After the verification is successful, the system signs the current electricity consumption data and sends the signed current electricity consumption data to the external terminal via a near-field communication link. Receive service processing information from an external platform based on the current electricity consumption data, and perform local billing status updates and / or power on / off control according to the service processing information.

2. The secure interactive control method according to claim 1, characterized in that, The dynamic factor includes at least one of timestamp, random number, and count value; The dynamic identification code is a dynamic QR code, and the dynamic identification code is updated when at least one of the following conditions is met: the refresh cycle expires, the one-time access token is used, or the number of token verification failures reaches a threshold.

3. The secure interactive control method according to claim 1, characterized in that, The one-time access token is marked as used after successful verification to prevent the same one-time access token from being used again to establish a near-field communication connection; if the verification of the token to be verified does not match or the validity period has expired, the current power consumption data will not be sent to the external terminal.

4. The secure interactive control method according to claim 1, characterized in that, The near-field communication link is established based on the Bluetooth Low Energy communication protocol; The current electricity consumption data includes at least one of the following: current cumulative electricity consumption, frozen electricity consumption, remaining amount, current applicable rate, billing cycle identifier, and device verification information; The device verification information includes at least one of the following: device identity identifier, device certificate, device status code, current time information, and data digest; The signature processing includes performing digest calculations and signature operations using secure elements.

5. The secure interactive control method according to claim 1, characterized in that, The business processing information includes at least one of the following: payment confirmation result, balance change, rate configuration parameters, and power on / off control command; The receiving of service processing information from an external platform based on the current electricity consumption data includes: Verify at least one of the following carried in the business processing information: platform signature, timestamp, transaction serial number, and data digest; After the verification is successful, the local billing status update or the power on / off control is executed. The step of performing a local billing status update based on the business processing information includes: Analyze the change in balance and update the balance value; If the updated balance value meets the power supply conditions, close the power supply circuit; If the power supply conditions are not met, disconnect the power supply circuit or keep the power off.

6. The secure interactive control method according to claim 1, characterized in that, The smart energy meter supports both prepaid operation mode and postpaid settlement mode, and the method further includes: In response to a billing cycle termination request initiated by an external terminal, a final settlement bill is generated based on the locally stored initial metering data, current metering data, and rate parameters, and sent to the external terminal via a near-field communication link. Receive settlement completion information corresponding to the final settlement bill, update the settlement history and reset the current billing cycle status; The reset of the current billing cycle status includes: clearing or updating the current billing cycle identifier, recording new starting metering data, updating the temporary electricity session status, and displaying the settlement completion status.

7. The secure interactive control method according to any one of claims 1 to 6, characterized in that, The smart meter establishes a temporary billing session using the device identification and billing cycle identification. In the absence of a fixed electricity user number pre-bound to the external terminal, a corresponding electricity consumption interaction relationship is established with the smart meter based on the dynamic identification code. The secure interactive control method further includes storing metering data, balance data, rate parameters, dynamic identification code refresh records, and token verification records in a non-volatile storage area to restore the local billing status after the smart energy meter experiences an abnormal power outage or restart. The business processing information includes rate update parameters, and the secure interaction control method further includes: The local storage of time-of-use electricity pricing configuration, package billing configuration, or billing cycle configuration is updated synchronously according to the rate update parameters.

8. A smart energy meter, characterized in that, include: The metering module is used to collect sampling data and generate electricity metering data; The main control and security module, connected to the metering module, is used to generate a one-time access token and a dynamic identification code based on the device identity, dynamic factor and key information, and to perform consistency verification on the token carried in the near-field communication connection request. The main control and security module includes a microcontroller unit and a security element, wherein the security element is used to store key information and perform signature processing on the current power consumption data and device verification information. The human-computer interaction module is connected to the main control and security module and is used to display and refresh the dynamic identification code, as well as display electricity consumption data, balance status or settlement status. The communication module, connected to the main control and security module, is used to establish a near-field communication link with an external terminal and to receive service processing information from an external platform. The data storage module, connected to the main control and security module, is used to store the one-time access token, metering data, balance data, rate parameters, billing cycle status, and settlement records. The control module, connected to the main control and security module, is used to perform power on / off operations based on the business processing information.

9. The smart energy meter according to claim 8, characterized in that, The smart energy meter adopts a rail-mounted structure for installation in a distribution box and is used for independent metering and billing control in distributed leasing scenarios.

10. A smart energy meter interaction system, characterized in that, include: The smart energy meter as described in claim 8 or 9; An external platform, which is communicatively connected to the smart meter, is used to receive current electricity consumption data uploaded by an external terminal and processed by the smart meter's signature, and to feed back business processing information to the smart meter. The payment gateway communicates with the external platform and is used to process payment requests and report payment results back to the external platform.